Commission Delegated Regulation (EU) 2022/439 of 20 October 2021 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards for the specification of the assessment methodology competent authorities are to follow when assessing the compliance of credit institutions and investment firms with the requirements to use the Internal Ratings Based Approach (Text with EEA relevance)

Type Delegated Regulation
Publication 2021-10-20
Last updated 2026-04-15
State In force
Department European Commission, FISMA
Source EUR-Lex
articles 85
Reform history JSON API

COMMISSION DELEGATED REGULATION (EU) 2022/439 of 20 October 2021 supplementing Regulation (EU) No 575/2013 of the European Parliament and of the Council with regard to regulatory technical standards for the specification of the assessment methodology competent authorities are to follow when assessing the compliance of credit institutions and investment firms with the requirements to use the Internal Ratings Based Approach (Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (1), and in particular the third subparagraph of Article 144(2), the third subparagraph of Article 173(3) and the third subparagraph of Article 180(3) thereof,

Whereas:

(1) The requirement in Regulation (EU) No 575/2013 that competent authorities assess the compliance of an institution with the requirements to use the Internal Ratings Based (IRB) Approach relates to all of the requirements for the use of the IRB Approach, irrespective of their degree of materiality, and concerns compliance with the requirements at all times. As a result, that requirement does not only relate to the assessment of the initial application of an institution for the permission to use the rating systems for the purpose of the calculation of own funds requirements, but also to: the assessment of any additional applications of an institution for the permission to use the rating systems implemented according to the institution’s approved plan of sequential implementation of the IRB Approach; the assessment of the application for material changes to the internal approaches that the institution has received permission to use in accordance with Article 143(3) of that Regulation and Commission Delegated Regulation (EU) No 529/2014 (2); changes to the IRB Approach that require notification in accordance with Article 143(4) of Regulation (EU) No 575/2013 and Delegated Regulation (EU) No 529/2014; the ongoing review of the IRB Approach that the institution has received permission to use in accordance with Article 101(1) of Directive 2013/36/EU of the European Parliament and of the Council (3); the assessment of applications for permission to return to the use of less sophisticated approaches in accordance with Article 149 of Regulation (EU) No 575/2013. Competent authorities should apply the same criteria to all of these particular aspects of the assessment of compliance with the requirements to use the IRB Approach. The rules that set out that assessment methodology should therefore apply to all of those cases, in order to ensure harmonisation of assessment methodologies by competent authorities and avoid the risk of regulatory arbitrage.

(2) The assessment methodology should consist in methods to be used by the competent authorities, either as optional or mandatory, and provide for criteria that are subject to the verification by the competent authorities.

(3) In order to ensure a consistent assessment of compliance with the requirements to be fulfilled for using the IRB Approach throughout the Union, it is necessary that competent authorities apply the same methods for that assessment. As a result, it is necessary to lay down a set of methods to be applied by all competent authorities. However, given the nature of the model assessment and the diversity and particularities of the models, competent authorities should also apply their supervisory discretion in the application of those methods with regard to the specific models under examination. The assessment methodology in this Regulation should specify the minimum criteria for competent authorities to verify compliance with the requirements to use the IRB Approach and lay down an obligation for the competent authorities to verify any other relevant criteria necessary for that purpose. Furthermore, in certain cases where the competent authority has carried out recent assessments for similar rating systems in the same class of exposures, it is appropriate to allow use of the results of such assessments, rather than the competent authority having to repeat them, if the competent authority after applying its discretion finds that those remain materially unchanged. This should avoid complexity, unnecessary burdens and duplication of work.

(4) Where the competent authorities are to assess the compliance of an institution with the requirements to use the IRB Approach for other purposes than the initial application for permission, competent authorities should only apply those rules that are relevant to the scope of the assessment for those other purposes and should in each case use the conclusions from the previous assessments as the starting point.

(5) Where the assessment relates to applications for the permissions referred to in Article 20(1)(a) of Regulation (EU) No 575/2013, the implementing technical standards referred to in paragraph 8 of that Article in relation to the joint decision process apply.

(6) Competent authorities are required to verify compliance of institutions with the specific regulatory requirements for the use of the IRB Approach, as well as evaluate the overall quality of the solutions, systems and approaches implemented by an institution, and request constant improvements and adaptations to changed circumstances in order to achieve continuous compliance with those requirements. Such an assessment requires, to a large extent, that the competent authorities exercise their discretion. Rules for the assessment methodology should, on the one hand, allow the competent authorities to exercise their discretion by carrying out additional checks to those specified in this Regulation, as necessary, and should, on the other hand, ensure harmonisation and comparability of supervisory practices across different jurisdictions. For the same reasons, competent authorities should have the necessary flexibility to apply the most appropriate optional method or any other method necessary for verifying particular requirements, having regard, among others, to the materiality of the types of exposures covered by each rating system, the complexity of the models, the particularities of the situation, the specific solution implemented by the institution, the quality of evidence provided by the institution, the resources available to the competent authorities themselves. Furthermore, for the same reasons competent authorities should be able to carry out additional tests and verifications necessary in case of doubts regarding the fulfilment of the requirements of the IRB Approach in accordance with the principle of proportionality, having regard to the nature, size and complexity of an institution’s business and structure.

(7) In order to ensure consistency and comprehensiveness of the assessment of the overall IRB Approach, in the case of subsequent requests for permission on the basis of the approved sequential implementation plan of an institution, competent authorities should base their assessment at least on the rules on the use and experience test, assignment to grades or pools, rating systems and risk quantification, as these aspects of the assessment relate to every individual rating system of the IRB Approach.

(8) In order to assess the adequacy of the application of the IRB Approach all rating systems and related processes should be verified where an institution has delegated tasks, activities or functions relating to the design, implementation and validation of rating systems to a third party or has obtained a rating system or pooled data from a third party vendor. In particular, it should be verified that adequate controls have been implemented at the institution and that full documentation is available. Furthermore, as the management body of the institution is ultimately responsible for the delegated processes and the performance of rating systems obtained from a third party vendor, it should be verified that the institution should has sufficient in-house understanding of the delegated processes and purchased rating systems. All tasks, activities and functions that have been delegated and the rating systems obtained from the third party vendors should therefore be assessed by the competent authorities in a manner similar to where the IRB Approach has been developed fully via internal processes of the institution.

(9) In order to prevent the institutions from only partially completing the sequential implementation of the IRB Approach for an extended period of time, the competent authorities should verify the appropriateness of the time limit for the implementation of the so-called ‘roll-out plan’, compliance with this deadline and the necessity of changes to the roll-out plan. It should be verified that all exposures covered by the roll-out plan have a defined and reasonable maximum timeframe for implementation of the IRB Approach.

(10) It is important to assess the robustness of the validation function and so the independence from the credit risk control unit, the completeness, frequency and adequacy of the methods and procedures and the soundness of the reporting process in order to verify that an objective assessment of the rating systems takes place and that there is a limited incentive to disguise the model deficiencies and weaknesses. When verifying whether an adequate level of independence of the validation function is in place, the competent authorities should take into account the size and complexity of the institution.

(11) As the rating systems are the core of the IRB Approach, and their quality may impact significantly the level of own funds requirements, the performance of the rating systems should be regularly reviewed. Given that estimates of risk parameters have to be subject to review at least annually and that rating systems should be regularly assessed by competent authorities and by the internal audit function, and given that, in order for this task to be performed, input from the validation function is necessary, it is appropriate to verify that the validation of the performance of the rating systems covering material portfolios and back-testing of all other rating systems is performed at least annually.

(12) All areas of the IRB Approach are to be effectively covered by internal audits. Nevertheless, it should be verified that the internal audit resources are used efficiently with focus on the most risky areas. Some flexibility is important particularly in the case of institutions that use numerous rating systems. As a consequence, competent authorities should verify that annual reviews are performed in order to determine areas that require more thorough reviews during the year.

(13) In order to ensure a minimum level of harmonisation in relation to the scope of use of the rating systems (the so-called ‘use test’), competent authorities should verify that the rating systems are incorporated in the relevant processes of the institution within the broader processes of risk management, credit approval and decision-making processes, internal capital allocation, and corporate governance functions. These are basic areas where internal processes require the use of risk parameters, therefore if there are differences between the risk parameters used in those areas and those used for the purpose of the calculation of own funds requirements, it should be verified that they are justified.

(14) In relation to experience test requirements, while assessing whether the rating systems used by the institution prior to the application to use the IRB Approach were ‘broadly in line’ with the IRB requirements, competent authorities should verify in particular that during at least three years before the use of the IRB Approach, the rating system has been used in the internal risk measurement and management processes of the institution and that it has been subject to monitoring, internal validation and internal audit. Such specification of the assessment methodology is necessary to ensure a minimum level of harmonisation. Competent authorities should verify that rating systems have been implemented in at least the most basic areas of use to ensure that the rating systems have been effectively used by the institution and that both the personnel and the management are accustomed to those parameters and understand well their meaning and weaknesses. Finally, monitoring, validation and internal audit during the experience period should show that the rating systems were compliant with the basic requirements of the IRB Approach and that they were gradually improved during that time.

(15) Independence of the process of assignment of exposures to grades or pools is required for non-retail exposures because the application of human judgement is typically necessary in the process. In the case of retail exposures the assignment process is usually fully automatic, based on objective information about the obligor and his transactions. The correctness of the assignment process is ensured by proper implementation of the rating system in the institution’s IT systems and procedures. Nevertheless if overrides are allowed, human judgement has to be applied in the rating process. As a result, and given that those responsible for origination or renewal of exposures are typically inclined to assign better ratings in order to increase sales and volumes of credits, where overrides are used, including in the case of retail exposures, it should be verified that the assignment has been approved by an individual or by a committee independent from the persons responsible for the origination or renewal of exposures.

(16) Where ratings are older than 12 months or where the review of the assignment has not been performed in due time according to the institution’s policy, the competent authorities should verify that conservative adjustments have been performed in terms of the risk-weighted assets calculation. The reasons for that are multiple. If the rating is outdated or based on outdated information the risk assessment might not be accurate. In particular, if the situation of the obligor has deteriorated during the last 12 months it is not reflected in the rating, and the risk is underestimated. In addition, according to the general rule relating to the estimation of the risk parameters, where the estimation of risk parameters is based on insufficient data or assumptions, a wider margin of conservatism should be adopted. The same rule should apply to the process of assignment of exposures to grades or pools, i.e. where insufficient information has been taken into account in the assignment process, additional conservatism should be adopted in the calculation of risk weights. The method of applying additional conservatism in the calculation of risk weights should not be specified as the institution may adjust either the rating, the risk parameter estimation or the risk weight directly. The adjustment should be proportional to the length of the period during which the rating or the information underlying the rating is out-of-date.

(17) The institutions are required to document the specific definitions of default and loss used internally and ensure consistency with the definitions set out in Regulation (EU) No 575/2013. When assessing this consistency, the competent authorities should verify that institutions have clear policies that specify when an obligor or facility is classified as being in default. These policies need to be consistent with the general principles regarding the identification of default. The EBA has adopted Guidelines on the application of the definition of default under Article 178 of Regulation (EU) No 575/2013. These policies should also be embedded into the institutions’ risk management processes and systems since Regulation (EU) No 575/2013 requires in particular that internal ratings, i.e. including the assignment to a default rating grade, play an essential role in the risk management and other internal processes of an institution, which should also be the subject of verification by the competent authorities.

(18) The information on the performance of an obligor and on the exposures in default and those not in-default, is the basis for the institution’s internal processes, for the quantification of risk parameters and for the calculation of own funds requirements. Therefore, not only the identification of defaulted obligors but also the process of reclassification of defaulted obligors to non-defaulted status need to be robust and effective. The competent authorities should verify that the prudent reclassification process ensures that obligors are not reclassified to a non-defaulted status where the institution expects that the exposure will probably return to default in a short period of time.

(19) In order to provide competent authorities with a consistent and accurate overview of the rating systems that the institution has been using as well as the improvement of the rating systems over time, it is necessary for competent authorities to assess the completeness of the register of the current and historical versions of rating systems used by the institution (‘register of rating systems’). Having regard to the fact that the requirements of the experience test relate to the preceding three years from the time of consideration of an application for approval of an internal model, and that the competent authorities are to carry out an overall review of the internal model on a regular basis, and at least every three years, it is appropriate for competent authorities to verify that such a register of rating systems covers at least the versions of the internal models used by the institution over the three preceding years.

(20) Human judgement is applied at various stages of the development and use of rating systems. Reasonable application of human judgement can increase the quality of the model and the accuracy of its predictions. Nevertheless, since human judgement changes the estimates based on prior experience in a subjective manner, the application of human judgement should be subject to control. The competent authorities should therefore verify that the application of human judgement is justified by its positive contribution to the accuracy of predictions. Thus, a large number of overrides of the results of the model might indicate that some important information is not included in the rating system. Therefore, competent authorities should verify that the number of overrides and their justification are regularly analysed by the institutions and that any detected weaknesses of the model are adequately addressed in the model review.

(21) In all cases, the competent authorities should assess whether the institution has adopted sufficient margin of conservatism in their estimates of risk parameters. This margin of conservatism should take into account any identified deficiencies in data or methods used in the risk quantification and increased uncertainty that might result for example from the changes in the lending or recovery policies. Where an institution ceases to comply with the requirements for the IRB Approach, the competent authorities should verify whether it fulfils the requirement that the rating systems are corrected in a timely manner. The application of the margin of conservatism should not be used as an alternative to correcting the models and ensuring their full compliance with the requirements of Regulation (EU) No 575/2013.

(22) With regard to risk quantification, it is desirable that the PD estimates are relatively stable over time in order to avoid the excessive cyclicality of own funds requirements. Competent authorities should verify that the PD estimates are based on the long-run average of yearly default rates. In addition, as the own funds should help institutions survive in a time of stress, the risk estimates should take into account the possible deterioration in the economic conditions even in the times of prosperity. Finally, whenever there is an increased uncertainty that results from insufficient data, competent authorities should verify that an additional margin of conservatism has been adopted. If the length of available time series does not encompass the expected variability of default rates, appropriate methods should be adopted to account for the missing data.

(23) The LGD estimation is based on the average realised LGDs weighted by the number of defaults. If the exposure value is a relevant risk driver, it should be considered among other potential risk drivers for the segregation or risk differentiation of LGD in order to ensure that the parameter is calculated for homogenous pools or facility grades. Competent authorities should verify that this approach is adequately applied, as it ensures consistency with the calculation of the PD parameter and a meaningful application of the risk weight formula. Regulation (EU) No 575/2013 distinguishes the method of estimating LGD for individual exposures for the purpose of risk-weighted exposure amounts from the average of LGD estimates calculated at the portfolio level. Differently from the individual LGD estimation, the LGD floor for retail exposures secured by immovable property, applied at the overall portfolio level, is defined as an exposure-weighted average LGD. In order to ensure adequate levels of risk parameters for exposures secured by immovable property competent authorities should verify that the LGD floors are applied correctly.

(24) Defaulted exposures that, after the return to non-defaulted status, are reclassified as defaulted within a short period of time should be treated as defaulted from the first moment when the default occurred, as the temporary reclassification to non-defaulted status is most likely performed on the basis of incomplete information about the real situation of the obligor. As a result, the treatment of multiple defaults as a single default better represents the real default experience. Competent authorities should therefore verify that in the estimation of risk parameters multiple defaults of the same obligor within a short period of time are treated as a single default. Furthermore, the treatment of multiple defaults by the same obligor as separate defaults might lead to significant errors in risk parameter estimates, because higher default rates would lead to higher PD estimates. On the other hand the LGD would be underestimated, because the first defaults by the obligor would be treated as cure cases with no loss related to them, whereas the institution did suffer a loss. Additionally, due to the link between PD and LGD estimates and in order to ensure realistic estimation of expected loss, the treatment of multiple defaults should be consistent for the purpose of PD and LGD estimation.

(25) The scope of information available to the institution with regard to defaulted exposures is significantly different from that regarding performing exposures. In particular, two additional risk drivers are available for the defaulted exposures, namely the time in-default and realised recoveries. Therefore, the estimation of LGD carried out before the default is not sufficient, because the risk estimates should take into account all significant risk drivers. Additionally, for defaulted exposures it is already known what the economic conditions were at the moment of default. Furthermore, LGD for defaulted exposures should reflect the sum of expected loss under current economic circumstances and possible unexpected loss that might occur during the recovery period. Therefore, competent authorities should verify that the LGD for defaulted exposures (‘LGD in-default’) is estimated either directly or as a sum of best estimate of expected loss (‘ELBE’) and an add-on that captures the unexpected loss that might occur during the recovery period. Irrespective of the approach applied the estimation of the LGD in-default should take into account the information on the time in-default and recoveries realised until the time of estimation and consider a possible adverse change in economic conditions during the expected length of the recovery process.

(26) In the case of institutions using own-LGD estimates internal requirements for collateral management should be generally consistent with the requirements of Section 3, Chapter 4, Title II in Part three of Regulation (EU) No 575/2013. Competent authorities should focus on the requirements of collateral valuation and legal certainty because it is important to ensure regular and reliable valuation of collateral, and that the valuation reflects the real market value under current market conditions. The frequency and character of revaluation should be adjusted to the type of collateral, as outdated or inaccurate evaluation might lead to the underestimation of risk relating to the credit exposures. It is also crucial to ensure that the collateral is legally effective and enforceable in all relevant jurisdictions. In the contrary case, the exposure should be treated as unsecured; if such collateral is recognised in the risk quantification, it may lead to the underestimation of risk.

(27) Competent authorities should verify that for the purpose of the advanced IRB Approach, i.e. where own-LGD estimates are used, guarantors are considered eligible where they are rated using a rating system approved under the IRB Approach; other guarantors may also be eligible, provided that they are classified as an institution, a central government or central bank, or a corporate entity that has a credit assessment by an ECAI, and the guarantee meets the requirements set out in Section 3, Chapter 4, Title II in Part Three of Regulation (EU) No 575/2013, which are also applicable for the Standardised Approach.

(28) In the assessment of the process of assignment of exposures to exposure classes, specific requirements should be laid down for the verification by the competent authorities for the assignment of exposures to retail exposures because of their preferential treatment in terms of risk-weighted exposure amounts calculation. Some exposure classes are defined on the basis of the characteristics of the transaction and others on the basis of the type of obligor; as a result, there may be exposures that fulfil the criteria of more than one exposure class. Competent authorities should therefore verify that the institution applies the correct sequencing of classification in order to ensure a consistent and unequivocal assignment of exposures to exposure classes.

(29) The competent authorities should verify that the results of the stress tests are taken into account in the risk and capital management processes, because the integration of the stress tests results in the decision-making processes ensures that the scenarios and their impact on own funds requirements are developed and performed in a meaningful manner and that forward-looking aspects of own funds requirements are taken into account in the management of the institution.

(30) Institutions that use own-LGD and own conversion factors estimates should calculate effective maturity of the exposures under the IRB Approach for the purpose of the calculation of own funds requirements. In the case of revolving exposures, an institution is at risk for a longer period than the repayment date of the current drawing, given that the borrower may redraw additional amounts. Therefore, competent authorities should verify that the calculation of effective maturity of revolving exposures is based on the expiry date of the facility.

(31) The calculation of the difference between expected loss amounts on the one hand and credit risk adjustments, additional value adjustments and other own funds reductions on the other hand (‘IRB shortfall‘) should be performed on an aggregate level separately for the portfolio of defaulted exposures and the portfolio of exposures that are not in default. The separation between defaulted and non-defaulted exposures is necessary in order to ensure that the negative amounts resulting from the calculation performed for the defaulted portfolio are not used to offset the positive amounts resulting from the calculation performed for the portfolio of exposures that are not in default. Apart from that the overall calculation is in line with the general concept of own funds, according to which the own funds should be fully available to cover unexpected losses in case of insolvency of the institution. Since the amounts of credit risk adjustments, additional value adjustments and other own funds reductions included in the calculation of the IRB shortfall have already been deducted from own funds to cover the expected losses (‘EL’), their excess part on the total EL is fully available to cover losses identified on all defaulted exposures. Therefore, competent authorities should verify that the adjustments to own funds based on the IRB shortfall are calculated and applied correctly.

(32) Unreliable, inaccurate, incomplete or outdated data may lead to errors in the risk estimation and in the calculation of own funds requirements. Furthermore, when used in the risk management processes of the institution such data may also lead to poor credit and management decisions. In order to ensure the reliability and a high quality of data the infrastructure and procedures relating to the collection and storing of data should be well documented and contain a full description of the characteristics and the sources of data in order to ensure their proper use in the internal processes and the processes for the calculation of own funds requirements. Hence competent authorities should verify the quality and documentation of data used in the process of estimation of risk parameters, in the assignment of exposures to grades or pools and in the calculation of own funds requirements.

(33) The quality of data, the accuracy of risk estimation and the correctness of calculation of own funds requirements are highly dependent on the reliability of the IT systems used for the purpose of the IRB Approach. Furthermore, the continuity and consistency of the risk management processes and the calculation of own funds requirements can only be ensured when the IT systems used for those purposes are safe, secure and reliable and the IT infrastructure is sufficiently robust. It is therefore necessary that competent authorities also verify the reliability of the institution’s IT systems and the robustness of the IT infrastructure.

(34) Competent authorities should verify that as far as possible non-overlapping observations of returns on equity exposures are used both for the development and validation of internal models for equity exposures. Non-overlapping observations ensure higher quality of predictions, given that all observations are assigned the same weight and the observations are not closely correlated to each other.

(35) The use of the IRB Approach requires the approval of the competent authorities, and any material changes to that approach have to be approved. As a result, competent authorities should verify that the internal process of management and in particular the internal process of approving such changes ensure that only changes that are in accordance with Regulation (EU) No 575/2013 and Delegated Regulation (EU) No 529/2014 are implemented and, in that context, that the classification of changes is consistent in order to avoid any regulatory arbitrage.

(36) The provisions of this Regulation are closely linked, since they all deal with aspects of the assessment methodology that competent authorities are to apply when assessing the compliance of an institution with the IRB Approach. To ensure coherence between those provisions, which should enter into force at the same time, and to facilitate a comprehensive view and compact access to them by persons subject to them, it is desirable to include all of the regulatory technical standards relating to the assessment methodology of the IRB Approach required by Regulation (EU) No 575/2013 in a single regulation.

(37) This Regulation is based on the draft regulatory technical standards submitted to the Commission by the European Banking Authority.

(38) The European Banking Authority has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential related costs and benefits and requested the opinion of the Banking Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1093/2010 of the European Parliament and of the Council (4),

HAS ADOPTED THIS REGULATION:

CHAPTER 1

GENERAL PROVISIONS ON THE ASSESSMENT METHODOLOGY

Article 1
Assessment of compliance with requirements to use the Internal Ratings Based Approach
1.

Competent authorities shall apply this Regulation for the assessment of the compliance of an institution with the requirements to use the Internal Ratings Based Approach (‘IRB Approach’) as follows:

(a) for the purposes of assessing initial applications for permission to use the IRB Approach as provided for in Article 144 of Regulation (EU) No 575/2013, competent authorities shall apply all provisions of this Regulation;

(b) for the purposes of assessing applications for permission to extend the IRB Approach in accordance with the approved sequential implementation plan as provided for in Article 148 of Regulation (EU) No 575/2013, competent authorities shall apply Chapters 4, 5, 7 and 8 and any other part of this Regulation that is relevant to that request;

(c) for the purposes of assessing applications for prior permission to carry out changes as referred to in Article 143(3) of Regulation (EU) No 575/2013, competent authorities shall apply all parts of this Regulation that are relevant to those changes;

(d) for the purposes of assessing changes to rating systems and internal models approaches to equity exposures which have been notified in accordance with Article 143(4) of Regulation (EU) No 575/2013, competent authorities shall apply all parts of this Regulation that are relevant to those changes;

(e) for the purposes of conducting ongoing reviews of the use of the IRB Approach pursuant to Article 101 of Directive 2013/36/EU, competent authorities shall apply all parts of this Regulation that are relevant to that review;

(f) for the purposes of assessing applications for permission to revert to the use of less sophisticated approaches in accordance with Article 149 of Regulation (EU) No 575/2013, competent authorities shall apply Articles 6 to 8 of this Regulation.

2.

In addition to the criteria laid down in the provisions of this Regulation referred to in paragraph 1, the competent authorities shall verify any other relevant criteria necessary for the assessment of the compliance with the requirements to use the IRB Approach.

Article 2
Methods to be applied by competent authorities
1.

For the purposes of assessing initial applications for permission to use the IRB Approach, competent authorities shall apply all compulsory methods set out in this Regulation. They may also apply other methods set out in this Regulation in accordance with paragraph 7 and any other methods in accordance with paragraph 8.

2.

For the purposes of assessing applications for permission to extend the IRB Approach in accordance with a sequential implementation plan, competent authorities shall apply all compulsory methods set out in Chapters 4, 5, 7 and 8. They may also apply other methods set out in this Regulation in accordance with paragraph 7 and any other methods in accordance with paragraph 8.

3.

For the purposes of assessing applications for prior permission to carry out changes to the IRB Approach, competent authorities shall review the documents required to be submitted by institutions with regards to the change in accordance with Article 8 of Delegated Regulation (EU) No 529/2014. They may also apply any methods set out in this Regulation in accordance with paragraphs 7 and any other methods in accordance with paragraph 8.

4.

For the purposes of assessing changes to rating systems and internal models approaches to equity exposures which have been notified, competent authorities shall review the documents required to be submitted by institutions with regard to the change in accordance with Article 8 of Delegated Regulation (EU) No 529/2014 and may apply any methods set out in this Regulation in accordance with paragraph 7 and any other methods in accordance with paragraph 8.

5.

For the purposes of conducting ongoing reviews of the use of the IRB Approach, competent authorities may apply any methods set out in this Regulation in accordance with paragraph7 and any other methods in accordance with paragraph 8.

6.

For the purposes of assessing the applications to revert to the use of less sophisticated approaches, competent authorities may apply any of the methods set out in Chapter 2 of this Regulation in accordance with paragraph 7 and any other methods in accordance with paragraph 8.

7.

Where this Regulation provides for optional use of methods, the competent authorities may apply any of those methods which are suitable and appropriate to the nature, size and degree of complexity of the institution’s business and organisational structure, taking into account:

(a) the materiality of the types of exposures covered by rating systems;

(b) the complexity of the rating models and risk parameters and their implementation.

8.

In addition to the methods set out in this Regulation, competent authorities may use other methods, which are suitable and appropriate to the nature, size and degree of complexity of the institution's business and organisational structure, where this is necessary for the assessment of compliance with the requirements to use the IRB Approach.

9.

When applying the methods set out in this Regulation, competent authorities may take into account results from recent assessments made by themselves or by other competent authorities, if those assessments fulfil both of the following conditions:

(a) the assessment was based wholly or in part on the compulsory methods;

(b) the subject of the assessment included the same or a similar rating system in the same class of exposures.

Article 3
Quality of documentation
1.

In order to verify the compliance of the institution with the documentation requirement set out in point (e) of Article 144(1) of Regulation (EU) No 575/2013, competent authorities shall verify that the documentation of the rating systems as defined in point (1) of Article 142(1) of Regulation (EU) No 575/2013 (‘rating systems’):

(a) is sufficiently detailed and accurate for it to be efficiently used;

(b) is approved at the appropriate management level of the institution;

(c) contains, with regard to each document, at least a record of the type of document, the author, the reviewer, the authorising agent, the owner, the dates of development and of approval, the version number and the history of changes to the document;

2.

For the purposes of paragraph 1, the competent authority shall verify that the institution has in place policies outlining specific standards for documentation ensuring:

(a) that the internal documentation is sufficiently detailed and accurate;

(b) that specific persons or units are assigned responsibility to ensure that the documentation is complete, consistent, accurate, updated, approved as appropriate and secure;

(c) that the institution adequately documents its policies, procedures and methodologies relating to the application of the IRB Approach.

Article 4
Third party involvement
1.

In order to assess compliance with the requirement regarding the soundness and the integrity of the rating systems laid down in Article 144(1) of Regulation (EU) No 575/2013 where an institution has delegated tasks, activities or functions relating to the design, implementation and validation of its rating systems to a third party, or has purchased a rating system or pooled data from a third party, the competent authority shall verify that that delegation or purchase does not hinder the application of this Regulation and shall verify that:

(a) senior management of the institution as defined in point (9) of Article 3(1) of Directive 2013/36/EU (‘senior management’) as well as the management body of the institution or the committee designated by that management body are actively involved in the supervision and decision-making regarding the tasks, activities or functions delegated to the third party or regarding the rating systems obtained from third parties;

(b) the staff of the institution has sufficient knowledge and understanding of the tasks, activities or functions delegated to third parties and of the structure of data and rating systems obtained from third parties;

(c) continuity of the outsourced functions or processes is ensured, including by means of appropriate contingency planning;

(d) internal audit or other control of the tasks, activities and functions delegated to third parties is not limited or inhibited by the involvement of the third party;

(e) the competent authority is granted full access to all relevant information.

2.

Where a third party is involved in the tasks of developing a rating system and risk estimation for an institution, the competent authority shall verify that:

(a) points (a) to (e) of paragraph 1 are satisfied;

(b) the validation activities with regard to those rating systems and those risk estimates are not performed by that third party;

(c) the third party provides the institution with the information necessary for those validation activities to be performed.

3.

Where, for the purposes of developing a rating system and risk parameter estimation, the institution uses data that is pooled across institutions, and a third party develops the rating system, the third party may assist the institution in its validation activities by performing those tasks of validation which require access to the pooled data.

4.

For the purposes of applying paragraphs 1, 2 and 3, competent authorities shall apply all of the following methods:

(a) review the agreements with the third party and other relevant documents which specify the tasks of the third party;

(b) obtain written statements from or interview the relevant staff of the institution or the third party to whom the task, activity or function is delegated;

(c) obtain written statements from or interview senior management or the management body of the institution or the third party to whom the task, activity or function is delegated, or the committee of the institution designated by the management body;

(d) review other relevant documents of the institution or of the third party, where necessary.

Article 5
Temporary non-compliance with the requirements of the IRB Approach

For the purposes of the application of Article 146(a) of Regulation (EU) No 575/2013, the competent authority shall:

(b) monitor on a regular basis the progress in the realisation of the institution’s plan for a timely return to compliance;

(c) verify the institution’s compliance with the relevant requirements after the implementation of the plan, by applying the assessment methodologies laid down in this Regulation.

CHAPTER 2

ASSESSMENT METHODOLOGY FOR SEQUENTIAL IMPLEMENTATION PLANS AND PERMANENT PARTIAL USE OF THE STANDARDISED APPROACH

Article 6
General
1.

In order to assess the compliance of an institution with the conditions for implementing the IRB Approach laid down in Article 148 of Regulation (EU) No 575/2013 and the conditions for permanent partial use laid down in Article 150 of that Regulation, competent authorities shall verify both of the following:

(a) that the institution’s initial coverage and plan for sequential implementation of the IRB Approach are adequate, in accordance with Article 7;

(b) that the exposure classes, types of exposures or business units where the Standardised Approach is applied are eligible for permanent exemption from the IRB Approach.

2.

For the purposes of the verification under paragraph 1, competent authorities shall apply all of the following methods:

(a) review the institution’s plan for sequential implementation of the IRB Approach;

(b) review the institution’s relevant internal policies and procedures, including the calculation methods for the share of exposures to be covered by the sequential implementation of the IRB Approach and the permanent exemption from the IRB Approach;

(c) review the roles and responsibilities of the units and management bodies involved in the assignment of individual exposures to the IRB Approach or the Standardised Approach;

(d) review the relevant minutes of meetings of the institution’s internal bodies, including the management body, or committees;

(e) review the relevant findings of the internal audit function or of other control functions of the institution;

(f) review the relevant progress reports on the effort made by the institution to correct shortcomings and mitigate risks detected during audits;

(g) obtain written statements from the relevant staff and senior management of the institution or interview them.

3.

For the purposes of the verification under paragraph 1, competent authorities may:

(a) review the functional documentation of the IT systems used in the process of the assignment of individual exposures to the IRB Approach or the Standardised Approach;

(b) conduct sample testing and review documents relating to the characteristics of the obligors and to the origination and maintenance of the exposures included in the sample;

(c) review other relevant documents of the institution.

Article 7
Sequential implementation of the IRB Approach
1.

When assessing the initial coverage and the institution’s plan for sequential implementation of the IRB Approach in accordance with Article 148 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(b) the sequential implementation plan comprises all exposures of the institution, and, where applicable, its parent undertaking, and all exposures of the subsidiaries of the institution, unless the exposures are assessed in accordance with Article 8;

(c) the implementation is planned to be performed in accordance with the second and third subparagraphs of Article 148(1) of Regulation (EU) No 575/2013;

(d) where the institution is permitted to use the IRB Approach for any exposure class, that it uses the IRB Approach for equity exposures except in the cases specified in Article 148(5) of Regulation (EU) No 575/2013;

(e) the sequence and time periods of the implementation of the IRB Approach are specified on the basis of the real capabilities of the institution, having regard to the availability of data, rating systems and experience periods as referred to in Article 145 of Regulation (EU) No 575/2013 and are not used selectively for the purpose of achieving reduced own funds requirements;

(f) the sequence of the implementation of the IRB Approach ensures that implementation with regard to the credit exposures relating to the institution’s core business is given priority;

(g) a definite time limit for the implementation of the IRB Approach is set for each type of exposures and business units and is reasonable on the basis of the nature and scale of the institution’s activities.

2.

Competent authorities shall determine whether the time limit referred to in point (g) of paragraph 1 is reasonable based on all of the following:

(a) the complexity of the institution’s operations, including those of the parent undertaking and its subsidiaries;

(b) the number of business units and business lines within the institution, and, where applicable, its parent undertaking and the subsidiaries of the institution;

(c) the number and complexity of the rating systems to be implemented by all entities covered by the sequential implementation plan;

(d) the plans to implement rating systems in subsidiaries located in third countries where significant legal or other difficulties for the approval of IRB models exist;

(e) the availability of accurate, appropriate and complete time series;

(f) the institution’s operational capability to develop and implement the rating systems;

(g) the institution’s prior experience in managing specific types of exposures.

3.

When assessing the institution’s compliance with the plan for sequential implementation of the IRB Approach, which has been subject to permission of the competent authorities in accordance with Article 148 of Regulation (EU) No 575/2013, competent authorities may consider changes to the sequence and time period appropriate only if one or more of the following conditions are met:

(a) there are significant changes in the business environment and in particular changes in strategy, mergers and acquisitions;

(b) there are significant changes in the relevant regulatory requirements;

(c) material weaknesses in the rating systems have been identified by the competent authority, or by the internal audit or the validation function;

(d) the elements referred to in paragraph 2 have changed significantly, or any of the elements referred to in paragraph 2 were not taken into account adequately in the plan for sequential implementation of the IRB Approach which was approved.

Article 8
Conditions for permanent partial use
1.

When assessing the institution’s compliance with the conditions for permanent partial use of the Standardised Approach in relation to the exposures referred to in points (a) and (b) of Article 150(1) of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) the availability of external data for representative counterparties is assessed and taken into account by the institution;

(b) the cost to the institution of developing a rating system for the counterparties in the relevant exposure class is assessed taking into account the size of the institution and the nature and scale of its activities;

(c) the operational capability of the institution to develop and implement a rating system is assessed taking into account the nature and scale of the institution’s activity.

2.

When assessing the institution’s compliance with the conditions for permanent partial use of the Standardised Approach in relation to the exposures referred to in point (c) of Article 150(1) of Regulation (EU) No 575/2013, competent authorities shall verify that the institution has verified and taken into account at least one of the following:

(a) that the exposures, including the number of separately managed portfolios and business lines are not homogenous enough to allow the development of a robust and reliable rating system;

(b) that the risk-weighted exposure amount calculated in accordance with the Standardised Approach is significantly higher than the expected risk-weighted exposure amount calculated in accordance with the IRB Approach;

(c) that the exposures relate to a business unit or business line of the institution which is planned to be discontinued;

(d) that the exposures include portfolios subject to proportional consolidation of partly-owned subsidiaries, in accordance with Article 18 of Regulation (EU) No 575/2013.

3.

When assessing the institution’s compliance with the conditions for permanent partial use of the Standardised Approach, competent authorities shall verify that the institution monitors compliance with the requirements of Article 150 of Regulation (EU) No 575/2013 on a regular basis.

CHAPTER 3

ASSESSMENT METHODOLOGY FOR THE FUNCTION OF VALIDATION OF INTERNAL ESTIMATES AND OF THE INTERNAL GOVERNANCE AND OVERSIGHT OF AN INSTITUTION

SECTION 1

General provisions

Article 9
General
1.

In order to assess whether an institution is compliant with the requirements on internal governance, including requirements on senior management and management body, internal reporting, credit risk control and internal audit, oversight and validation, competent authorities shall verify all of the following:

2.

For the purposes of the verification under paragraph 1, competent authorities shall apply all of the following methods:

(a) review the relevant internal policies and procedures of the institution;

(b) review the relevant minutes of the institution’s internal bodies, including the management body, or committees;

(c) review the relevant reports relating to the rating systems, as well as any conclusions and decisions taken on the basis of those reports;

(d) review the relevant reports on the activities of the credit risk control, internal audit, oversight and validation functions prepared by the staff responsible for each of those functions or by any other control function of the institution, as well as the conclusions, findings and recommendations of those functions;

(e) obtain written statements from or interview the relevant staff and senior management of the institution.

3.

For the assessment of the validation function, in addition to the methods referred to in paragraph 2, competent authorities shall apply all of the following methods:

(a) review the roles and responsibilities of all staff involved in the validation function;

(b) review the adequacy and appropriateness of the annual validation work plan;

(c) review the validation manuals used by the validation function;

(d) review the process of categorisation of the findings and the relevant recommendations in accordance with their materiality;

(e) review the consistency of the conclusions, findings and recommendations of the validation function;

(f) review the role of the validation function in the internal approval procedure of rating systems and all related changes;

(g) review the action plan of each relevant recommendation, also in terms of its follow-up, as approved by the appropriate management level.

4.

For the assessment of the credit risk control unit, referred to in point (c) of Article 144(1) and Article 190 of Regulation (EU) No 575/2013, in addition to the requirements referred to in paragraph 2, competent authorities shall apply all of the following methods:

(a) review the roles and responsibilities of all relevant staff and senior management of the credit risk control unit;

(b) review the relevant reports submitted by the credit risk control unit and the senior management, to the management body or to the designated committee thereof.

5.

For the assessment of the internal audit or another comparable independent auditing unit as referred to in Article 191 of Regulation (EU) No 575/2013 in addition to the requirements referred to in paragraph 2, competent authorities shall apply all of the following methods:

(a) review the relevant roles and responsibilities of all relevant staff involved in the internal audit;

(b) review the adequacy and appropriateness of the annual internal audit work plan;

(c) review the relevant auditing manuals and work programs and the findings and recommendations included in the relevant audit reports;

(d) review the action plan of each relevant recommendation, also in terms of its follow-up, as approved at the appropriate management level.

6.

In addition to the methods listed in paragraph 2, competent authorities may review other relevant documents of the institution for the purposes of the verification under paragraph 1.

SECTION 2

Methodology for assessing the validation function

Article 10
Independence of the validation function
1.

When assessing the independence of the validation function for the purposes of Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that the unit responsible for the validation function or, where there is no separate unit dedicated only to the validation function, the staff performing the validation function fulfils all of the following:

(a) the validation function is independent from the personnel and management function responsible for originating or renewing exposures and for the model design or development;

(b) the staff performing the validation function is different from the staff responsible for the design and development of the rating system, and from the staff responsible for the credit risk control function;

(c) it reports directly to senior management.

2.

For the purposes of paragraph 1, where the unit responsible for the validation function is organisationally separate from the credit risk control unit and each unit reports to different members of the senior management, competent authorities shall verify, both of the following:

(a) that the validation function has adequate resources, including experienced and qualified personnel to perform its tasks;

(b) that the remuneration of the staff and senior managers responsible for the validation function is not linked to the performance of the tasks relating to either credit risk control or to originating or renewing exposures.

3.

For the purposes of paragraph 1, where the unit responsible for the validation function is organisationally separate from the credit risk control unit, and both units report to the same member of the senior management, competent authorities shall verify all of the following:

(a) that the validation function has adequate resources, including experienced and qualified personnel to perform its tasks;

(b) that the remuneration of the staff and senior managers responsible for the validation function is not linked to the performance of the tasks relating to either credit risk control or to originating or renewing exposures;

(c) that there is a decision-making process in place to ensure that the conclusions, findings and recommendations of the validation function are properly taken into account by the senior management of the institution;

(d) that no undue influence is exercised on the conclusions, findings and recommendations of the validation function;

(e) that all necessary corrective measures to address the conclusions, findings and recommendations of the validation function are decided and implemented in a timely manner;

(f) that internal audit regularly assesses the fulfilment of the conditions referred to in points (a) to (e).

4.

For the purposes of paragraph 1, where there is no separate unit responsible for the validation function, competent authorities shall verify all of the following:

(a) that the validation function has adequate resources, including experienced and qualified personnel to perform its tasks;

(b) that the remuneration of the staff and senior managers responsible for the validation function is not linked to the performance of the tasks relating to either credit risk control or to originating or renewing exposures;

(c) that there is a decision-making process in place to ensure that the conclusions, findings and recommendations of the validation function are properly taken into account by the senior management of the institution;

(d) that no undue influence is exercised on the conclusions, findings and recommendations of the validation function;

(e) that all necessary corrective measures to address the conclusions, findings and recommendations of the validation function are decided and implemented in a timely manner;

(f) that internal audit regularly assesses the fulfilment of the conditions referred to in points (a) to (e);

(g) that there is effective separation between the staff performing the validation function and the staff performing the other tasks;

(h) that the institution is not a global or other systemically important institution in the meaning of Article 131 of Directive 2013/36/EU.

5.

When assessing the independence of the validation function, competent authorities shall also assess whether the choice of the institution with regard to the organisation of the validation function as referred to in paragraphs 2, 3 and 4 is adequate, taking into account the nature, size and scale of the institution and the complexity of the risks inherent in its business model.

Article 11
Completeness and frequency of the validation process
1.

When assessing the completeness of the validation function for the purposes of the requirements laid down in Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) the institution has defined and documented a complete validation process for all rating systems;

(b) the institution performs the validation process referred to in point (a) with an adequate frequency.

2.

When assessing the completeness of the validation process as referred to in paragraph 1(a), competent authorities shall verify that the validation function:

(a) critically reviews all the aspects of the specification of the internal ratings and risk parameters, including the procedures for data collection and data cleansing, the choices of the methodology and model structure, and the process for the selection of the variables;

(b) verifies the adequacy of the implementation of internal ratings and risk parameters in IT systems and that grade and pool definitions are consistently applied across departments and geographic areas of the institution;

(c) verifies the performance of the rating systems taking into account at least risk differentiation and quantification and the stability of the internal ratings and risk parameters and the model specifications;

(d) verifies all changes relating to internal ratings and risk parameters and their materiality in accordance with the Delegated Regulation (EU) No 529/2014 and that it consistently follows up on its own conclusions, findings and recommendations.

3.

When assessing whether the frequency of the validation process referred to in paragraph 1(b) is adequate, competent authorities shall verify that the validation process is performed regularly for all rating systems of the institution following an annual work plan and that:

(a) for all rating systems the processes required by Article 185(b) and Article 188(c) of Regulation (EU) No 575/2013 (‘back-testing’) are performed at least once annually;

(b) for the rating systems covering material types of exposures, the verification of the performance of the rating systems as referred to in paragraph 2(c), takes place at least once annually.

4.

Where an institution applies for permission to use the internal ratings and risk parameters of a rating system or for any material changes to internal ratings and risk parameters of a rating system, competent authorities shall verify that the institution performs the validation referred to in paragraph 2(a), (b) and (c) before the rating system is used for the calculation of own funds requirements and for internal risk management purposes.

Article 12
Adequacy of the methods and procedures of the validation function

When assessing the adequacy of the validation methods and procedures for the purposes of the requirements laid down in Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that those methods and procedures allow for a consistent and meaningful assessment of the performance of the internal rating and risk estimation systems, and shall verify that:

(a) the validation methods and procedures are appropriate for assessing the accuracy and consistency of the rating system;

(b) the validation methods and procedures are appropriate to the nature, degree of complexity and range of application of the institution’s rating systems and data availability;

(c) the validation methods and procedures clearly specify the validation objectives, standards and limitations, contain a description of all validation tests, data sets, and data cleansing processes, set out data sources and reference time periods, and set the fixed targets and tolerances for defined metrics, for the initial and regular validation respectively;

(d) the validation methods used, and in particular the tests performed, the reference data set used for the validation and the respective data cleansing, are applied consistently over time;

(e) the validation methods include back-testing, and benchmarking as set out in Article 185(c) and Article 188(d) of Regulation (EU) No 575/2013;

(f) the validation methods take account of the way business cycles and the related systematic variability in default experience are considered in the internal ratings and risk parameters, especially regarding PD estimation.

Article 13
Soundness of the reporting process and the process for addressing the validation conclusions, findings and recommendations

When assessing the soundness of the reporting process and the process to address the validation conclusions, findings and recommendations, for the purposes of the requirements laid down Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) the validation reports identify and describe the validation methods used, the tests performed, the reference data set used and the respective data cleansing processes and include the results of those tests, the conclusions of the validation, the findings and the respective recommendations;

(b) the conclusions, findings and recommendations of the validation reports are directly communicated to senior management and to the management body of the institution or to the committee designated by it;

(c) the conclusions, findings and recommendations of the validation reports are reflected in changes and improvements in the design of internal ratings and risk estimates, including in the situations described in the first sentence of Article 185(e) and Article 188(e) of Regulation (EU) No 575/2013;

(d) the decision-making process of the institution takes place at the appropriate management level.

SECTION 3

Methodology for assessing internal governance and oversight

Article 14
The role of senior management and management body

When assessing the institution’s corporate governance as referred to in Article 189 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) the decision-making process of the institution, its hierarchy, reporting lines- and levels of responsibility are clearly laid down in the internal documentation of the institution and consistently reflected in the minutes of its internal bodies;

(c) the management body or the committee designated by it sets an appropriate organisational structure for the sound implementation of the rating systems by way of a formal decision;

(d) the management body or the committee designated by it approves by way of a formal decision the specification of the acceptable level of risk, taking into account the internal rating system scheme of the institution;

(e) the senior management has a good understanding of all rating systems of the institution, of their design and operation, of the requirements for the IRB Approach and of the institution’s approach to meeting those requirements;

(f) the senior management notifies the management body or the committee designated by it of material changes to or exceptions from established policies that materially impact the operations of the institution’s rating systems;

(g) the senior management is in a position to ensure on an ongoing basis the good functioning of the rating systems;

(h) the senior management takes relevant measures where weaknesses of the rating systems are identified by the credit risk control, the validation, the internal audit or any other control function.

Article 15
Management reporting

When assessing the adequacy of the management reporting as referred to in Article 189 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(b) the form and the frequency of management reporting are adequate having regard to the significance and the type of the information and to the level the recipient occupies in the hierarchy, taking into account the institution’s organisational structure;

(c) the management reporting facilitates the senior management’s monitoring of the credit risk in the overall portfolio of exposures covered by the IRB Approach;

(d) the management reporting is proportionate to the nature, size, and degree of complexity of the institution’s business and organisational structure.

Article 16
Credit risk control unit
1.

When assessing the internal governance and oversight of the institution in relation to the credit risk control unit referred to in Article 190 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) the credit risk control unit or units are separate and independent of the personnel and management functions responsible for originating or renewing exposures;

(b) the credit risk control unit or units are functional and adequate for their tasks.

2.

For the purposes of the verification under paragraph 1(a), competent authorities shall verify that:

(a) the credit risk control unit or units are distinct organisational structures within the institution;

(b) the head of the credit risk control unit or the heads of such units are part of the senior management;

(c) the credit risk management function is organised taking into account the principles set out in Article 76(5) of Directive 2013/36/EU;

(d) the staff and the senior management responsible for the credit risk control unit or units are not responsible for originating or renewing exposures;

(e) senior managers of the credit risk control unit or units and of units responsible for originating or renewing exposures report to different members of the management body of the institution or of the committee designated by it;

(f) the remuneration of the staff and senior management responsible for the credit risk control unit or units is not linked to the performance of the tasks relating to originating or renewing exposures.

3.

For the purposes of the verification under paragraph 1(b), competent authorities shall verify that:

(a) the credit risk control unit or units are proportionate to the nature, size and degree of complexity of the business and organisational structure of the institution, and in particular to the complexity of the rating systems and their implementation;

(b) the credit risk control unit or units have adequate resources, and experienced and qualified personnel to undertake all relevant activities;

(c) the credit risk control unit or units are responsible for the design or selection, implementation and oversight and the performance of the rating systems, as required by the second sentence of Article 190(1) of Regulation (EU) No 575/2013, and that the areas of responsibility of that unit or those units include those listed in Article 190(2) of that Regulation;

(d) the credit risk control unit or units regularly inform the senior management of the performance of the rating systems, of areas needing improvement, and of the status of efforts to improve previously identified deficiencies.

Article 17
Internal audit
1.

When assessing the internal governance and oversight of the institution in relation to the internal audit or another comparable independent auditing unit, as referred to in Article 191 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(b) the review under point (a) facilitates the specification in the annual work plan of areas that require a detailed review of compliance with all requirements applicable to the IRB Approach laid down in Articles 142 to 191 of Regulation (EU) No 575/2013;

(c) the internal audit or the other comparable independent auditing unit are functional and adequate for their tasks.

2.

For the purposes of the verification under paragraph 1(c), competent authorities shall verify that:

(a) the internal audit or the other comparable independent auditing unit provides sufficient information to the senior management and the management body of the institution on the compliance of the rating systems with all applicable requirements for the IRB Approach;

(b) the internal audit or the other comparable independent auditing unit is proportionate to the nature, size and degree of complexity of the institution’s business and organisational structure, and in particular to the complexity of the rating systems and their implementation;

(c) the internal audit or the other comparable independent auditing unit has adequate resources, and experienced and qualified personnel to undertake all relevant activities;

(d) the internal audit or the other comparable independent auditing unit is not involved in any aspect of the operation of the rating systems which it reviews in accordance with paragraph 1(a);

(e) the internal audit or the other comparable independent auditing unit is independent from the personnel and management responsible for originating or renewing exposures and reports directly to senior management;

(f) the remuneration of the staff and senior management responsible for the internal audit function is not linked to the performance of the tasks relating to originating or renewing exposures.

CHAPTER 4

ASSESSMENT METHODOLOGY FOR USE TEST AND EXPERIENCE TEST

Article 18
General
1.

In order to assess whether an institution is compliant with the requirements on the use of rating systems for the purposes of Article 144(1)(b), Article 145, Article 171(1)(c), Article 172(1)(a), Article 172(1)(c), Article 172(2) and 175(3) of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) internal ratings and default and loss estimates of the rating systems used in the calculation of own funds play an essential role in the risk management, credit approval and decision-making process in accordance with Article 19;

(b) internal ratings and default and loss estimates of the rating systems used in the calculation of own funds play an essential role in the process of the internal capital allocation in accordance with Article 20;

(c) internal ratings and default and loss estimates of the rating systems used in the calculation of own funds play an essential role in the corporate governance functions in accordance with Article 21;

(d) data and estimates used by the institution for the calculation of own funds and those used for internal purposes are consistent, and where discrepancies exist, that these are fully documented and reasonable;

(e) rating systems are broadly in line with the requirements set out in Article 169 to 191 of Regulation (EU) No 575/2013 and have been applied by the institution at least three years prior to the use of the IRB Approach, as set out in Article 145 of Regulation (EU) No 575/2013, in accordance with Article 22.

2.

For the purpose of the assessment under paragraph 1 competent authorities shall apply all of the following methods:

(a) review the institution's relevant internal policies and procedures;

(b) review the relevant minutes the institution's internal bodies, including the management body, or committees involved in the credit risk management governance;

(c) review the allocation of powers to take credit decisions, the credit management manuals and the commercial channels schemes;

(e) review the institution’s credit restructuring policies;

(f) review the documented regular reporting on credit risk;

(g) review the documentation on calculation of internal capital of the institution and the allocation of the internal capital to types of risk, subsidiaries and portfolios;

(h) review the relevant findings of the internal audit or of other control functions of the institution;

(i) review the progress reports on the efforts made by the institution to correct shortcomings and mitigate risks detected during relevant audits;

(j) obtain written statements from or interview the relevant staff and senior management of the institution.

3.

For the purpose of the assessment under paragraph 1, competent authorities may also apply any of the following additional methods:

(a) review the documentation of early warning systems;

(b) review the credit risk adjustments methodology and the documented analysis of its coherence with the calculation of own funds requirements;

(c) review the documented analysis of the risk-adjusted profitability of the institution;

(d) review the pricing policies of the institution;

(e) review the procedures for the collection and recovery of debts;

(f) review the planning manuals and reports on budgeting of the cost of risk;

(g) review the remuneration policy and the minutes of the remuneration committee;

(h) review other relevant documents of the institution.

Article 19
Use test in risk management, decision-making and credit approval process
1.

When assessing whether internal ratings and default and loss estimates of the rating systems used in the calculation of the own funds requirements play an essential role in the institution’s risk management and decision-making process and in its credit approval as required by Article 144(1)(b) of Regulation (EU) No 575/2013, with regard to assignment to grades or pools in accordance with Article 171(1), point (c), and (2), of that Regulation, with regard to assignment of exposures in accordance with Article 172(1), points (a), (b) and (c), of that Regulation and with regard to documentation of rating systems in accordance with Article 175(3) of that Regulation, the competent authorities shall verify that:

(a) the number of non-rated exposures and outdated ratings is immaterial;

2.

Where institutions use internal ratings and default and loss estimates in any of the following areas, competent authorities shall assess how that use contributes to those ratings and estimates playing an essential role in the institution’s risk management and decision-making processes and in its credit approval as referred to in paragraph 1:

(a) the pricing of each credit facility or obligor;

(b) the early warning systems used for the credit risk management;

(c) the determination and implementation of the collection and recovery policies and processes;

(d) the calculation of credit risk adjustments where this is in line with the applicable accounting framework;

(e) the allocation or delegation of competence for the credit approval process by the management board to internal committees, to the senior management and to the staff.

Article 20
Use test in the internal capital allocation
1.

When assessing whether internal ratings and default and loss estimates of the rating systems used in the calculation of own funds requirements play an essential role in the institution’s internal capital allocation as referred to in Article 144(1)(b) of Regulation (EU) No 575/2013, competent authorities shall assess whether these ratings and estimates play an important role in:

(a) the assessment of the amount of internal capital that the institution considers adequate to cover the nature and level of the risk to which it is or might be exposed as referred to in Article 73 of Directive 2013/36/EU;

(b) the allocation of the internal capital among types of risk, subsidiaries and portfolios.

2.

Where institutions take into consideration internal ratings and default and loss estimates for the purpose of calculating the cost of risk to the institution for budgetary purposes, competent authorities shall assess how taking those elements into consideration contributes to those ratings and estimates playing an essential role in the institution’s internal capital allocation.

Article 21
Use test in corporate governance functions
1.

When assessing whether internal ratings and default and loss estimates of the rating systems used in the calculation of own funds requirements play an essential role in the institution’s corporate governance functions as referred to in Article 144(1)(b) of Regulation (EU) No 575/2013, competent authorities shall assess whether these ratings and estimates play an important role in:

(a) the management reporting;

(b) the monitoring of the credit risk at the portfolio level.

2.

Where institutions take into consideration internal ratings and default and loss estimates in any of the following areas, competent authorities shall assess how taking those elements into consideration contributes to those ratings and estimates playing an essential role in the institution’s corporate governance functions referred to in paragraph 1:

(a) the internal audit planning;

(b) the design of the remuneration policies.

Article 22
Experience test
1.

When assessing whether rating systems broadly in line with the requirements set out in Article 169 to 191 of Regulation (EU) No 575/2013 have been applied by the institution at least three years prior to the use of the IRB Approach for the purpose of the calculation of the own funds requirements, as referred to in Article 145 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) those rating systems have been used in the institution’s risk management and decision-making processes and credit approval processes referred to in Article 19(1)(b);

(b) adequate documentation of the effective operation of the rating systems for those three years is available, in particular with regard to the respective monitoring, validation and audit reports.

2.

For the purposes of assessing a request for permission to extend the IRB Approach in accordance with the sequential implementation plan, paragraph 1 shall also apply where the extension concerns exposures that are significantly different to the scope of the existing coverage, such that the existing experience cannot be reasonably assumed to be sufficient to meet the requirements of Article 145(1) and (2) of Regulation (EU) No 575/2013 in respect of the additional exposures, as laid down in Article 145(3) of Regulation (EU) No 575/2013.

CHAPTER 5

ASSESSMENT METHODOLOGY FOR ASSIGNMENT OF EXPOSURES TO GRADES OR POOLS

Article 23
General
1.

In order to assess the institution’s compliance with the requirements regarding the assignment of obligors or exposures to grades or pools laid down in Articles 169, 171, 172 and 173 of Regulation (EU) No 575/2013, competent authorities shall verify both of the following:

(a) the adequacy of the definitions, processes and criteria used by the institution for assigning or reviewing the assignment of exposures to grades or pools, including the treatment of overrides, in accordance with Article 24;

(b) the integrity of the assignment process as referred to in Article 173 of Regulation (EU) No 575/2013, including the independence of the assignment process, as well as the reviews of the assignment, in accordance with Article 25.

2.

For the purposes of the verification under paragraph 1, competent authorities shall apply all of the following methods:

(a) review the institution’s relevant internal policies and procedures;

(b) review the roles and responsibilities of units responsible for origination and renewal of exposures and units responsible for the assignment of exposures to grades or pools;

(c) review the relevant minutes of the institution’s internal bodies, including the management body, or committees;

(d) review the institution’s internal reports regarding the performance of the assignment process;

(e) review the relevant findings of the internal audit or of other control functions of the institution;

(f) review the progress reports on the efforts made by the institution to correct shortcomings in the assignment or the review process and to mitigate risks detected during audits;

(g) obtain written statements from or interview the relevant staff and senior management of the institution;

(h) review the criteria used by the personnel responsible for human judgement in the assignment of exposures to grades or pools.

3.

For the purposes of the verification under paragraph 1, competent authorities may also apply any of the following additional methods:

(a) review the functional documentation of the relevant IT systems;

(b) conduct sample testing and review documents relating to the characteristics of an obligor and to the origination and maintenance of the exposures;

(c) perform their own tests on the data of the institution or require the institution to perform specific tests;

(d) review other relevant documents of the institution.

Article 24
Assignment definitions, processes and criteria
1.

When assessing the adequacy of definitions, processes and criteria used by the institution to assign or review the assignment of exposures to grades or pools in accordance with Articles 169, 171, 172 and 173 of Regulation (EU) No 575/2013, competent authorities shall verify that:

(a) there are adequate procedures and mechanisms in place that ensure a consistent assignment of obligors or facilities to an appropriate rating system;

(b) there are adequate procedures and mechanisms in place to ensure that each exposure held by the institution is assigned to a grade or pool in accordance with the rating system;

(c) for exposures to corporates, institutions, central governments and central banks, and for equity exposures where the institution uses the PD/LGD approach set out in Article 155(3) of Regulation (EU) No 575/2013, there are adequate procedures and mechanisms in place to ensure that all exposures to the same obligor are assigned to the same obligor grade, including exposures along different lines of business, departments, geographical locations, legal entities within the group and IT systems, and to ensure the correct application of the exemption from the requirement to have an obligor rating scale which reflects exclusively quantification of the risk of obligor default for specialised lending exposures, laid down in Article 170(2) of Regulation (EU) No 575/2013, and of the exemption from the obligation to assign separate exposures to the same obligor to the same obligor grade, laid down in Article 172(1)(e) of that Regulation;

(d) the definitions and criteria used for the assignment are sufficiently detailed to ensure a common understanding and consistent assignment to grades or pools by all the personnel responsible in all business lines, departments, geographical locations, legal entities within the group, regardless of which IT system is used;

(e) there are adequate procedures and mechanisms in place to obtain all relevant information about the obligors and the facilities;

(f) all relevant, currently available and most up-to-date information is taken into account;

Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.

This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence. EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.