My bookmarksSign up free

Commission Delegated Regulation (EU) 2022/439 CHAPTER 3 — ASSESSMENT METHODOLOGY FOR THE FUNCTION OF VALIDATION OF INTERNAL ESTIMATES AND OF THE INTERNAL GOVERNANCE AND OVERSIGHT OF AN INSTITUTION

Article 9–Article 17 · 9 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

SECTION 1 — General provisions

General

Article 9

1.   In order to assess whether an institution is compliant with the requirements on internal governance, including requirements on senior management and management body, internal reporting, credit risk control and internal audit, oversight and validation, competent authorities shall verify all of the following: (a) the robustness of the arrangements, mechanisms and processes of validation of rating systems of an institution and the appropriateness of the personnel responsible for the performance of the validation (‘validation function’) as referred to in points (c) and (f) of Article 144(1), point (d) of Article 174, Article 185 and Article 188 of Regulation (EU) No 575/2013, in respect of: (i) the independence of the validation function, in accordance with Article 10; (ii) the completeness and frequency of the application of the validation process, in accordance with Article 11; (iii) the adequacy of the methods and procedures of the validation function, in accordance with Article 12; (iv) the soundness of the reporting process and the process for addressing the validation conclusions, findings and recommendations in accordance with Article 13; (b) the internal governance and oversight of the institution, including the credit risk control unit and the internal audit of the institution, as referred to in Articles 189, 190 and 191 of Regulation (EU) No 575/2013 in respect of: (i) the role of senior management and the management body, in accordance with Article 14; (ii) the management reporting, in accordance with Article 15; (iii) the credit risk control unit, in accordance with Article 16; (iv) the internal audit, in accordance with Article 17. 2.   For the purposes of the verification under paragraph 1, competent authorities shall apply all of the following methods: (a) review the relevant internal policies and procedures of the institution; (b) review the relevant minutes of the institution’s internal bodies, including the management body, or committees; (c) review the relevant reports relating to the rating systems, as well as any conclusions and decisions taken on the basis of those reports; (d) review the relevant reports on the activities of the credit risk control, internal audit, oversight and validation functions prepared by the staff responsible for each of those functions or by any other control function of the institution, as well as the conclusions, findings and recommendations of those functions; (e) obtain written statements from or interview the relevant staff and senior management of the institution. 3.   For the assessment of the validation function, in addition to the methods referred to in paragraph 2, competent authorities shall apply all of the following methods: (a) review the roles and responsibilities of all staff involved in the validation function; (b) review the adequacy and appropriateness of the annual validation work plan; (c) review the validation manuals used by the validation function; (d) review the process of categorisation of the findings and the relevant recommendations in accordance with their materiality; (e) review the consistency of the conclusions, findings and recommendations of the validation function; (f) review the role of the validation function in the internal approval procedure of rating systems and all related changes; (g) review the action plan of each relevant recommendation, also in terms of its follow-up, as approved by the appropriate management level. 4.   For the assessment of the credit risk control unit, referred to in point (c) of Article 144(1) and Article 190 of Regulation (EU) No 575/2013, in addition to the requirements referred to in paragraph 2, competent authorities shall apply all of the following methods: (a) review the roles and responsibilities of all relevant staff and senior management of the credit risk control unit; (b) review the relevant reports submitted by the credit risk control unit and the senior management, to the management body or to the designated committee thereof. 5.   For the assessment of the internal audit or another comparable independent auditing unit as referred to in Article 191 of Regulation (EU) No 575/2013 in addition to the requirements referred to in paragraph 2, competent authorities shall apply all of the following methods: (a) review the relevant roles and responsibilities of all relevant staff involved in the internal audit; (b) review the adequacy and appropriateness of the annual internal audit work plan; (c) review the relevant auditing manuals and work programs and the findings and recommendations included in the relevant audit reports; (d) review the action plan of each relevant recommendation, also in terms of its follow-up, as approved at the appropriate management level. 6.   In addition to the methods listed in paragraph 2, competent authorities may review other relevant documents of the institution for the purposes of the verification under paragraph 1.

SECTION 2 — Methodology for assessing the validation function

Independence of the validation function

Article 10

1.   When assessing the independence of the validation function for the purposes of Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that the unit responsible for the validation function or, where there is no separate unit dedicated only to the validation function, the staff performing the validation function fulfils all of the following: (a) the validation function is independent from the personnel and management function responsible for originating or renewing exposures and for the model design or development; (b) the staff performing the validation function is different from the staff responsible for the design and development of the rating system, and from the staff responsible for the credit risk control function; (c) it reports directly to senior management. 2.   For the purposes of paragraph 1, where the unit responsible for the validation function is organisationally separate from the credit risk control unit and each unit reports to different members of the senior management, competent authorities shall verify, both of the following: (a) that the validation function has adequate resources, including experienced and qualified personnel to perform its tasks; (b) that the remuneration of the staff and senior managers responsible for the validation function is not linked to the performance of the tasks relating to either credit risk control or to originating or renewing exposures. 3.   For the purposes of paragraph 1, where the unit responsible for the validation function is organisationally separate from the credit risk control unit, and both units report to the same member of the senior management, competent authorities shall verify all of the following: (a) that the validation function has adequate resources, including experienced and qualified personnel to perform its tasks; (b) that the remuneration of the staff and senior managers responsible for the validation function is not linked to the performance of the tasks relating to either credit risk control or to originating or renewing exposures; (c) that there is a decision-making process in place to ensure that the conclusions, findings and recommendations of the validation function are properly taken into account by the senior management of the institution; (d) that no undue influence is exercised on the conclusions, findings and recommendations of the validation function; (e) that all necessary corrective measures to address the conclusions, findings and recommendations of the validation function are decided and implemented in a timely manner; (f) that internal audit regularly assesses the fulfilment of the conditions referred to in points (a) to (e). 4.   For the purposes of paragraph 1, where there is no separate unit responsible for the validation function, competent authorities shall verify all of the following: (a) that the validation function has adequate resources, including experienced and qualified personnel to perform its tasks; (b) that the remuneration of the staff and senior managers responsible for the validation function is not linked to the performance of the tasks relating to either credit risk control or to originating or renewing exposures; (c) that there is a decision-making process in place to ensure that the conclusions, findings and recommendations of the validation function are properly taken into account by the senior management of the institution; (d) that no undue influence is exercised on the conclusions, findings and recommendations of the validation function; (e) that all necessary corrective measures to address the conclusions, findings and recommendations of the validation function are decided and implemented in a timely manner; (f) that internal audit regularly assesses the fulfilment of the conditions referred to in points (a) to (e); (g) that there is effective separation between the staff performing the validation function and the staff performing the other tasks; (h) that the institution is not a global or other systemically important institution in the meaning of Article 131 of Directive 2013/36/EU. 5.   When assessing the independence of the validation function, competent authorities shall also assess whether the choice of the institution with regard to the organisation of the validation function as referred to in paragraphs 2, 3 and 4 is adequate, taking into account the nature, size and scale of the institution and the complexity of the risks inherent in its business model.

Completeness and frequency of the validation process

Article 11

1.   When assessing the completeness of the validation function for the purposes of the requirements laid down in Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that: (a) the institution has defined and documented a complete validation process for all rating systems; (b) the institution performs the validation process referred to in point (a) with an adequate frequency. 2.   When assessing the completeness of the validation process as referred to in paragraph 1(a), competent authorities shall verify that the validation function: (a) critically reviews all the aspects of the specification of the internal ratings and risk parameters, including the procedures for data collection and data cleansing, the choices of the methodology and model structure, and the process for the selection of the variables; (b) verifies the adequacy of the implementation of internal ratings and risk parameters in IT systems and that grade and pool definitions are consistently applied across departments and geographic areas of the institution; (c) verifies the performance of the rating systems taking into account at least risk differentiation and quantification and the stability of the internal ratings and risk parameters and the model specifications; (d) verifies all changes relating to internal ratings and risk parameters and their materiality in accordance with the Delegated Regulation (EU) No 529/2014 and that it consistently follows up on its own conclusions, findings and recommendations. 3.   When assessing whether the frequency of the validation process referred to in paragraph 1(b) is adequate, competent authorities shall verify that the validation process is performed regularly for all rating systems of the institution following an annual work plan and that: (a) for all rating systems the processes required by Article 185(b) and Article 188(c) of Regulation (EU) No 575/2013 (‘back-testing’) are performed at least once annually; (b) for the rating systems covering material types of exposures, the verification of the performance of the rating systems as referred to in paragraph 2(c), takes place at least once annually. 4.   Where an institution applies for permission to use the internal ratings and risk parameters of a rating system or for any material changes to internal ratings and risk parameters of a rating system, competent authorities shall verify that the institution performs the validation referred to in paragraph 2(a), (b) and (c) before the rating system is used for the calculation of own funds requirements and for internal risk management purposes.

Adequacy of the methods and procedures of the validation function

Article 12

When assessing the adequacy of the validation methods and procedures for the purposes of the requirements laid down in Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that those methods and procedures allow for a consistent and meaningful assessment of the performance of the internal rating and risk estimation systems, and shall verify that: (a) the validation methods and procedures are appropriate for assessing the accuracy and consistency of the rating system; (b) the validation methods and procedures are appropriate to the nature, degree of complexity and range of application of the institution’s rating systems and data availability; (c) the validation methods and procedures clearly specify the validation objectives, standards and limitations, contain a description of all validation tests, data sets, and data cleansing processes, set out data sources and reference time periods, and set the fixed targets and tolerances for defined metrics, for the initial and regular validation respectively; (d) the validation methods used, and in particular the tests performed, the reference data set used for the validation and the respective data cleansing, are applied consistently over time; (e) the validation methods include back-testing, and benchmarking as set out in Article 185(c) and Article 188(d) of Regulation (EU) No 575/2013; (f) the validation methods take account of the way business cycles and the related systematic variability in default experience are considered in the internal ratings and risk parameters, especially regarding PD estimation.

Soundness of the reporting process and the process for addressing the validation conclusions, findings and recommendations

Article 13

When assessing the soundness of the reporting process and the process to address the validation conclusions, findings and recommendations, for the purposes of the requirements laid down Article 144(1)(f), Article 174(d), Article 185 and Article 188 of Regulation (EU) No 575/2013, competent authorities shall verify that: (a) the validation reports identify and describe the validation methods used, the tests performed, the reference data set used and the respective data cleansing processes and include the results of those tests, the conclusions of the validation, the findings and the respective recommendations; (b) the conclusions, findings and recommendations of the validation reports are directly communicated to senior management and to the management body of the institution or to the committee designated by it; (c) the conclusions, findings and recommendations of the validation reports are reflected in changes and improvements in the design of internal ratings and risk estimates, including in the situations described in the first sentence of Article 185(e) and Article 188(e) of Regulation (EU) No 575/2013; (d) the decision-making process of the institution takes place at the appropriate management level.

SECTION 3 — Methodology for assessing internal governance and oversight

The role of senior management and management body

Article 14

When assessing the institution’s corporate governance as referred to in Article 189 of Regulation (EU) No 575/2013, competent authorities shall verify that: (a) the decision-making process of the institution, its hierarchy, reporting lines- and levels of responsibility are clearly laid down in the internal documentation of the institution and consistently reflected in the minutes of its internal bodies; (b) both the management body or the committee designated by it and the senior management approve at least the following material aspects of the rating systems: (i) all relevant policies relating to the design and implementation of rating systems and the application of the IRB Approach, including the policies relating to all material aspects of the rating assignment and risk parameter estimation and validation processes; (ii) all relevant risk management policies, including those relating to IT infrastructure and contingency planning; (iii) the risk parameters of all rating systems used in internal risk management processes and in the calculation of own funds requirements; (c) the management body or the committee designated by it sets an appropriate organisational structure for the sound implementation of the rating systems by way of a formal decision; (d) the management body or the committee designated by it approves by way of a formal decision the specification of the acceptable level of risk, taking into account the internal rating system scheme of the institution; (e) the senior management has a good understanding of all rating systems of the institution, of their design and operation, of the requirements for the IRB Approach and of the institution’s approach to meeting those requirements; (f) the senior management notifies the management body or the committee designated by it of material changes to or exceptions from established policies that materially impact the operations of the institution’s rating systems; (g) the senior management is in a position to ensure on an ongoing basis the good functioning of the rating systems; (h) the senior management takes relevant measures where weaknesses of the rating systems are identified by the credit risk control, the validation, the internal audit or any other control function.

Management reporting

Article 15

When assessing the adequacy of the management reporting as referred to in Article 189 of Regulation (EU) No 575/2013, competent authorities shall verify that: (a) the management reporting includes information about all of the following: (i) the risk profile of the obligors or exposures, by grade; (ii) the migration across grades; (iii) an estimation of the relevant risk parameters per grade; (iv) a comparison of realised default rates, and, where own estimates are used, of realised LGDs and realised conversion factors against expectations; (v) stress test assumptions and results; (vi) the performance of the rating process, areas needing improvement and the status of efforts to improve previously identified deficiencies of the rating systems; (vii) validation reports; (b) the form and the frequency of management reporting are adequate having regard to the significance and the type of the information and to the level the recipient occupies in the hierarchy, taking into account the institution’s organisational structure; (c) the management reporting facilitates the senior management’s monitoring of the credit risk in the overall portfolio of exposures covered by the IRB Approach; (d) the management reporting is proportionate to the nature, size, and degree of complexity of the institution’s business and organisational structure.

Credit risk control unit

Article 16

1.   When assessing the internal governance and oversight of the institution in relation to the credit risk control unit referred to in Article 190 of Regulation (EU) No 575/2013, competent authorities shall verify that: (a) the credit risk control unit or units are separate and independent of the personnel and management functions responsible for originating or renewing exposures; (b) the credit risk control unit or units are functional and adequate for their tasks. 2.   For the purposes of the verification under paragraph 1(a), competent authorities shall verify that: (a) the credit risk control unit or units are distinct organisational structures within the institution; (b) the head of the credit risk control unit or the heads of such units are part of the senior management; (c) the credit risk management function is organised taking into account the principles set out in Article 76(5) of Directive 2013/36/EU; (d) the staff and the senior management responsible for the credit risk control unit or units are not responsible for originating or renewing exposures; (e) senior managers of the credit risk control unit or units and of units responsible for originating or renewing exposures report to different members of the management body of the institution or of the committee designated by it; (f) the remuneration of the staff and senior management responsible for the credit risk control unit or units is not linked to the performance of the tasks relating to originating or renewing exposures. 3.   For the purposes of the verification under paragraph 1(b), competent authorities shall verify that: (a) the credit risk control unit or units are proportionate to the nature, size and degree of complexity of the business and organisational structure of the institution, and in particular to the complexity of the rating systems and their implementation; (b) the credit risk control unit or units have adequate resources, and experienced and qualified personnel to undertake all relevant activities; (c) the credit risk control unit or units are responsible for the design or selection, implementation and oversight and the performance of the rating systems, as required by the second sentence of Article 190(1) of Regulation (EU) No 575/2013, and that the areas of responsibility of that unit or those units include those listed in Article 190(2) of that Regulation; (d) the credit risk control unit or units regularly inform the senior management of the performance of the rating systems, of areas needing improvement, and of the status of efforts to improve previously identified deficiencies.

Internal audit

Article 17

1.   When assessing the internal governance and oversight of the institution in relation to the internal audit or another comparable independent auditing unit, as referred to in Article 191 of Regulation (EU) No 575/2013, competent authorities shall verify that: (a) the internal audit or the other comparable independent auditing unit reviews the following, at least annually: (i) all rating systems of the institution; (ii) the operations of the credit risk control function; (iii) the operations of the credit approval process; (iv) the operations of the internal validation function; (b) the review under point (a) facilitates the specification in the annual work plan of areas that require a detailed review of compliance with all requirements applicable to the IRB Approach laid down in Articles 142 to 191 of Regulation (EU) No 575/2013; (c) the internal audit or the other comparable independent auditing unit are functional and adequate for their tasks. 2.   For the purposes of the verification under paragraph 1(c), competent authorities shall verify that: (a) the internal audit or the other comparable independent auditing unit provides sufficient information to the senior management and the management body of the institution on the compliance of the rating systems with all applicable requirements for the IRB Approach; (b) the internal audit or the other comparable independent auditing unit is proportionate to the nature, size and degree of complexity of the institution’s business and organisational structure, and in particular to the complexity of the rating systems and their implementation; (c) the internal audit or the other comparable independent auditing unit has adequate resources, and experienced and qualified personnel to undertake all relevant activities; (d) the internal audit or the other comparable independent auditing unit is not involved in any aspect of the operation of the rating systems which it reviews in accordance with paragraph 1(a); (e) the internal audit or the other comparable independent auditing unit is independent from the personnel and management responsible for originating or renewing exposures and reports directly to senior management; (f) the remuneration of the staff and senior management responsible for the internal audit function is not linked to the performance of the tasks relating to originating or renewing exposures.

Back to Commission Delegated Regulation (EU) 2022/439 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next