My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1085 CHAPTER 2 — ASSESSMENT OF QUALITATIVE REQUIREMENTS

Article 5–Article 21 · 17 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Overview of the assessment of qualitative requirements

Article 5

When assessing an institution’s compliance with the qualitative requirements set out in Article 325bi of Regulation (EU) No 575/2013, competent authorities shall: (a) verify whether the institution has a clear organisational structure for the governance and management of the market risk model, including well defined, transparent and appropriate lines of responsibility; (b) verify whether the decision-making process of the institution regarding all aspects of market risk internal models is clearly established in the institution’s internal documentation; (c) verify, in accordance with Article 6: (i) the adequacy of the composition of the senior management and the management body; (ii) the role of the senior management and the management body; (d) verify, in accordance with Article 7, whether the set-up of the trading desks for which the institution is in the process of being granted the approval, or has already obtained the approval, is adequate; (e) assess, in accordance with Article 8, the internal governance and oversight of the institution in relation to the risk control unit; (f) assess, in accordance with Article 9, whether the internal policy is adequate for the introduction of new products; (g) verify, in accordance with Article 10, whether the internal model is reviewed independently; (h) assess: (i) in accordance with Article 11, the adequacy of the internal validation process and of its outcome; (ii) in accordance with Article 12, the scope of the validation and its completeness; (i) assess, in accordance with Article 13, the adequacy of the internal regular reporting; (j) assess: (i) in accordance with Article 14, the adequacy of position limits; (ii) in accordance with Article 15, the adequacy of the process to update those limits; (iii) in accordance with Article 16, the adequacy of the process followed where those limits are breached; (k) assess: (i) in accordance with Article 17, the adequacy ofthe stress testing programme; (ii) in accordance with Article 18, the adequacy of reverse stress-testing scenarios and ad-hoc stress-testing scenarios; (l) assess, in accordance with Article 19, the adequacy of the IT systems; (m) verify, in accordance with Article 20, whether the internal risk-measurement model, including any pricing model, has a proven track record of being reasonably accurate in measuring risks, and does not differ significantly from the models that the institution uses for its internal risk management. For the purposes of point (a), competent authorities shall take into account the nature and size of the institution, and the scale and complexity of its activities.

Assessment of the adequacy of the composition and role of the management body and senior management

Article 6

1.   When assessing the adequacy of the composition and the role of the senior management and the management body as referred to in Article 325bi(1), point (c), of Regulation (EU) No 575/2013, competent authorities shall: (a) verify whether the institution, in its documentation of the risk management system, describes: (i) the composition, the roles and responsibilities of the management body and senior management; (ii) the roles and responsibilities of each member of the management body and senior management; (b) verify whether the senior management is constituted of members that represent the highest hierarchical levels below the management body, and has defined responsibility for the proper functioning of the internal model for market risk; (c) verify whether the composition of any internal committee structure established by the management body to support its decision-making is adequate, as required by paragraph 2; (d) verify whether the role of the senior management is adequate, as required by paragraph 3; (e) verify whether the role of the management body, and of the committees constituting the internal committee structure referred to in point (c), are adequate, as required by paragraph 4. Where an institution’s management body delegates any of its tasks to an internal committee, competent authorities shall, in the context of those delegated tasks, make the assessments required by this Regulation at the level of the internal committee designated by the management body. 2.   For the purposes of paragraph 1, first subparagraph, point (c), competent authorities shall verify whether: (a) for each committee of the internal committee structure, the management body has clearly set out its mandate, hierarchy, reporting lines, permanent members, frequency of meetings, and levels of responsibility; (b) the internal committee structure has a committee that assesses any new product, proposes those products to the senior management for approval, and monitors those products and whether the risk control unit, and any other function of the institution that is affected by the introduction of a new product, are represented in such committee; (c) the governance underpinning the internal committee structure allows for the effective and timely control of all internal position limits referred to in Article 325bi(1), point (b), of Regulation (EU) No 575/2013; (d) the governance underpinning the internal committee structure ensures active involvement of the management body in the risk-control process as required by Article 325bi(1), point (c), of Regulation (EU) No 575/2013; (e) as part of the internal documentation, the institution has documented all aspects referred to in point (a). 3.   For the purposes of paragraph 1, first subparagraph, point (d), competent authorities shall verify whether: (a) the senior management of the institution takes appropriate corrective actions where weaknesses of the internal risk-measurement model or the internal default risk model are identified by any of the following: (i) the risk control unit; (ii) the qualified parties tasked with the validation of the internal model (‘validation function’); (iii) the internal audit function; (iv) any other control function of the institution; (b) the senior management of the institution is informed of, and follows up on, the recommendations made by the internal audit, the risk control unit, the validation function, in relation to the internal risk-measurement model or the internal default risk model; (c) the senior management of the institution is able to ensure the overall quality of the institution’s governance of the valuation of positions included in the internal risk-measurement model or the internal default risk model. 4.   For the purposes of paragraph 1, first subparagraph, point (e), competent authorities shall verify whether the management body: (a) on the basis of a proposal from the risk control unit, approves all relevant policies and procedures related to the implementation of the internal model, including the appropriate organisational structure, to ensure that the internal model is implemented with integrity; (b) on the basis of a proposal from the risk control unit and after due consideration of the conclusions and recommendations resulting from the validation process, approves the methodologies for assessing market risk applied in the internal model; (c) on the basis of an assessment from the risk control unit and after due consideration of the conclusions and recommendations resulting from the validation process, approves any new products; (d) on the basis of a proposal from the risk control unit, approves and updates the internal position limits; (e) on the basis of a proposal from the risk control unit laying down and assessing the acceptable level of risk, approves the acceptable level of risk, the internal capital allocation and the budget by trading desk; (f) adopts the approval procedure for breaches of internal position limits; (g) approves or requires corrective actions in relation to breaches of the internal position limits escalated by the risk control unit in accordance with Article 16(1), point (b); (h) on the basis of a proposal from the risk control unit: (i) approves the stress testing programme; (ii) discusses the results of the stress tests; (iii) assesses potential action, and where necessary, takes corrective actions.

Assessment of whether trading desks comply with Article 104b of Regulation (EU) No 575/2013

Article 7

When assessing whether trading desks comply with Article 104b of Regulation (EU) No 575/2013, competent authorities shall: (a) review the business strategy referred to in Article 104b of that Regulation as documented in the internal policies of the institution under Article 325bi(1), point (e), of that Regulation, and verify whether: (i) internal policies clearly describe the economic rationale of the business strategy, including its primary activities, trading, and hedging strategies; (ii) internal policies describe the features of the financial instruments and commodities traded by the trading desk, and contains a regularly updated and comprehensive list of those financial instruments and commodities; (iii) the institution highlights in its internal policies the instruments that are most frequently traded and that contribute the most to the acceptable level of risk for the trading desk; (iv) internal policies describe risk factor’s types inherent in the financial instruments and commodities referred to in point (ii); (v) internal policies clearly describe how the instruments and commodities referred to in point (ii) are hedged, what are the expected slippages and mismatches of hedges, and what is the expected holding period for the positions in the trading desk; (vi) the business strategies of the trading desks are distinctive, as required by Article 104b(2), point (a), of Regulation (EU) No 575/2013, by: (1) identifying the main characteristics of the trading desks in terms of business strategy, including primary activities, trading and hedging strategies; (2) verifying that the main characteristics referred to in point (1) meaningfully differ from one trading desk to another; (b) verify whether transactions between trading desks are consistent with the business strategies of those trading desks and that those transactions are not performed to: (i) reduce the own funds requirements for market risk; (ii) meet the profit and loss attribution requirements; (iii) meet the back-testing requirements; (c) review the organisational structure referred to in Article 104b(2), point (b), of Regulation (EU) No 575/2013 and the annual business plan referred to in Article 104b(2), point (e), of that Regulation, as documented in the internal policies of the institution under Article 325bi(1), point (e), of that Regulation; (d) verify whether for each trading desk, the institution has identified one or two head dealers, and that where two head dealers have been appointed, they either have roles, responsibilities, and authorities that are clearly separated, or one has ultimate oversight over the other; (e) review the reports referred to in Article 104b(2), points (d) and (f), of Regulation (EU) No 575/2013, and verify whether all aspects referred to in those points are complied with; (f) verify whether the institution duly documents and justifies cases where a dealer is assigned to more than one trading desk as referred to in Article 104b(3) of Regulation (EU) No 575/2013, and, for that purpose: (i) review the responsibility of that dealer in the context of the trading desks to which he or she has been assigned; (ii) verify whether the tasks performed by the dealer in one trading desk as per the business strategy of that desk do not contradict, nor create any conflict with, the tasks that the dealer performs for the other trading desks; (g) verify whether the rationale for the inclusion of the trading desks in the scope of the alternative internal model approach meets all of the following conditions: (i) the rationale is documented in the internal policies as required by Article 325bi(1), point (e), of Regulation (EU) No 575/2013; (ii) the rationale ensures consistency in the approach used for calculating the own funds requirements for market risk among trading desks managing similar positions; (iii) the rationale is coherent with the business strategy of the trading desks as referred to in Article 104b(2), point (a), of Regulation (EU) No 575/2013; (h) verify whether the business strategy entails that at least 10 % of the own funds requirements for market risk are calculated in accordance with the internal model approach. For the purposes of point (a)(i), competent authorities shall verify whether the business strategy specifies how much of the trading activities are customer driven, and whether the business strategy entails trade origination and structuring, or execution of services, or both. For the purposes of point (b), competent authorities may, where appropriate, require the institution to provide a sample of transactions between trading desks, including between trading desks for which the institution computes the own funds requirements with the internal model approach and trading desks for which the institution uses the standardised approach.

Assessment of the internal governance and oversight of the institution in relation to the risk control unit

Article 8

1.   When assessing the internal governance and oversight of the institution in relation to the risk control unit referred to in Article 325bi(1), point (b), of Regulation (EU) No 575/2013, competent authorities shall verify whether that risk control unit: (a) is completely separate and independent from the personnel and the management functions responsible for the trading business areas; (b) is duly represented in the institution’s decision-making bodies and is involved in the decision-making process where any of the following issues are on the agenda: (i) the approval of new methodologies for assessing market risk and of any changes to existing methodologies; (ii) the approval of the establishment of a trading desk; (iii) the approval or update of reports and inventories within the remit of the risk control unit; (iv) the setting of the acceptable level of risk; (v) the setting and regular update of the internal limit structure; (vi) the approval of limit breaches; (vii) the approval of new products or new business lines; (viii) the approval of pricing models used for risk purposes; (ix) the approval of stress testing programmes; (x) the approval of IT infrastructure systems related to risk management tools; (c) is adequate, is proportionate to the size of the institution and the risks of the business, and has the resources necessary to perform its tasks effectively; (d) has sufficiently experienced, qualified and trained staff to undertake all relevant activities for the effective risk management of the internal model and for monitoring and challenging the actions of other units, in particular of the trading business units; (e) is responsible for the outcome of the calculations based on the internal-risk measurement model and the internal default risk model. 2.   For the purposes of paragraph 1, point (a), competent authorities shall verify whether: (a) the risk control unit is composed of one or more separate organisational structures in the institution’s organisational chart; (b) the heads of the risk control unit or units are senior managers of the institution; (c) the staff and the senior management responsible for the risk control unit are not responsible for any trading business activities; (d) senior managers of the risk control unit and those responsible for business areas have different reporting lines to the management body of the institution; (e) the variable remuneration of the staff and senior management responsible for the risk control unit is not linked to the performance of the tasks related to trading business areas under their supervision in a way that hinders or impedes their independence. 3.   For the purposes of paragraph 1, point (b), competent authorities shall take into account: (a) the documented view of the risk control unit when either the management body or the relevant committee of the internal committee structure discuss any of the issues referred to in paragraph 1, point (b); (b) the minutes of the institution’s management body or relevant committee of the internal committee structure, and the action points reflected therein; (c) the reports of the risk control unit about internal position limits, and any decisions regarding limit breaches; (d) information provided by the staff and senior management of the institution, where appropriate. For the purposes of point (b), competent authorities shall assess the degree of involvement of the risk control unit when the institution’s management body or relevant committee of the internal committee structure discuss any of the issues referred to in paragraph 1, point (b). Competent authorities shall identify cases where the view of the risk control unit and the final decision taken by either the management body or the relevant committee of the internal committee structure diverge.

Assessment of the new product policy

Article 9

When assessing whether the internal policies referred to in Article 325bi(1), point (e), of Regulation (EU) No 575/2013 are adequate for the introduction of any new product, including new financial instruments, activities, markets, booking locations or business lines, competent authorities shall verify whether: (a) the risk control unit has documented a new product policy and the management body has approved that policy, including a definition of ‘new product’; (b) the internal committee structure has a committee (‘new product committee’) that assesses, controls and monitors all issues arising from the introduction of new products, including, where relevant: (i) assessing regulatory compliance; (ii) reviewing any pricing models used for risk purposes; (iii) specifying the market parameters to be used for calibration purposes, the way the calibration is to be done, and the frequency of update of the calibration; (iv) introducing any new methodologies for assessing market risk; (v) assessing the impacts on the acceptable level of risk, capital adequacy, and profitability; (vi) ensuring the availability of front, back and middle office resources and internal tools and expertise that allow for the understanding and monitoring of any associated new risks; (vii) specifying and proposing to the management body the restrictions in terms of maturities, underlying, counterparties, and internal limits for such new product; (viii) assessing the adequacy of the accounting schemes and ensuring that the internal reporting appropriately reflects the underlying risks; (c) the management body, based on an assessment by the new product committee, authorises the trading of new products; (d) where the management body delegates the authorisation task to the new product committee: (i) the volume allowed for the new product is restrictive enough to prevent any material losses stemming from such new products, including, where appropriate, shorter trial periods for products referred to in Article 2, point (c); (ii) the authorisation is delegated separately for each type of new product and always for a limited period of time, with a maximum of 6 months; (iii) the authorisation, if renewed, is only renewed once by the management body; (iv) after a one-year period, all relevant issues referred to in point (b) are addressed, or no additional trading in that new product is allowed; (e) without the specific approval from the new product committee, the business areas are not authorised to trade new products before the issues referred to in point (b) are addressed; (f) in the specific cases where traders are allowed to trade new products that do not comply with point (b), the new-product committee approves the transactions on an individual basis and within the limits referred to in point (d)(i); (g) the new product committee meets frequently enough to evaluate and approve any new product transaction and to monitor all the issues referred to in point (b) that those transactions may pose; (h) transactions are monitored individually until all issues referred to in point (b) have been fully addressed and, based on an assessment by the new product committee, the management body confirms that the transactions are fully incorporated into all relevant IT systems and controlled via the regular risk-management system; (i) all new products, regardless of their degree of incorporation into the IT systems, are computed both in the internal risk-measurement model and in the daily changes to the portfolio’s value used for back-testing and profit and loss attribution test purposes.

Independent review of the internal risk-measurement model

Article 10

1.   When assessing the independent review of the internal risk-measurement models in accordance with Article 325bi(1), point (h), of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the reviewer is independent; (b) the resources assigned to the review are appropriate; (c) the process established within the institution to address the recommendations made by the reviewer is adequate; (d) the reviewer reviews the internal risk-measurement models on at least an annual basis, and includes the conclusions of that review in a report submitted to the senior management and the management body; (e) the report referred to in point (d) provides sufficient information to the senior management and the management body of the institution on all elements referred to in Article 325bi(2) and Article 325bp(7) of Regulation (EU) No 575/2013, and identifies the areas in the annual work plan that require a more detailed compliance analysis of those elements; (f) the review is adequate, proportionate to the size and the complexity of the portfolios concerned, and effective in identifying shortcomings. 2.   For the purposes of paragraph 1, competent authorities shall verify whether: (a) the review is proportionate to the nature, size, and complexity of the institution’s business and organisational structure, and in particular to the complexity of the internal models and their implementation; (b) the reviewer has resources that are adequate to undertake all relevant activities, and sufficiently experienced and qualified staff; (c) the reviewer is not, nor has been involved in any aspect of the design and implementation of the internal model subject to review; (d) the reviewer is independent from the staff and management function responsible for the business and risk control units; (e) the variable remuneration of the staff and management responsible for the review is not linked to the performance of the tasks related to the institution’s trading business areas in a way that hinders or impedes their independence. 3.   Competent authorities shall examine the latest and other relevant reports produced by the reviewer and verify that the remediation of the issues identified in those reports is relevant, material, and credible.

Assessment of the validation of any internal risk measurement models, and of the outcome of such validation

Article 11

1.   When assessing whether any internal risk-measurement models are adequately validated, as referred to in Article 325bj of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the validation process is conducted by staff that is not nor has been involved in any way in the development of the internal model subject to validation; (b) the validation process is conducted with sufficient resources, including experienced and qualified staff; (c) the variable remuneration of the staff and senior managers responsible for the validation process is not dependent on the performance of the tasks related to the institution’s risk control or business areas in a way that hinders or impedes their independence; (d) all necessary corrective measures resulting from the validation process are reflected in the validation report referred to in paragraph 2, and implemented in a timely manner; (e) a decision-making process is in place to ensure that the senior management of the institution takes into account the findings and recommendations resulting from the validation process; (f) the reviewer referred to in Article 10(1), point (a), regularly assesses the compliance with the conditions referred to in Article 10(1), points (e) and (f). 2.   When assessing the outcome of the validation process, competent authorities shall: (a) verify whether the recommendations, findings, and conclusions of the validation process are included in a validation report that identifies and describes: (i) the validation methodology; (ii) the tests performed; (iii) the reference dataset used; (iv) the respective data cleansing processes; (b) verify whether the conclusions, findings and recommendations of the validation report are directly communicated to, and considered by, the management body of the institution before that management body approves a model to be applied for the calculation of own funds requirements and before any subsequent changes in the methodologies are applied; (c) verify whether any remedial measure proposed by the validation functions is documented in the validation report and is accompanied by a timeline that is adequate for fixing the identified deficiencies; (d) verify whether an escalation process is included in the internal policies of the institution for those remedial measures that are overdue, and whether, based on evidence from the past, that process is followed; (e) assess the overall quality of the outcome of the validation process by comparing the deficiencies identified in the assessment of the internal model in accordance with this Regulation with the deficiencies identified by the validation unit in the validation process.

Assessment of the adequacy of the scope and completeness of the internal validation

Article 12

1.   When assessing whether the scope of the internal validation referred to in Article 325bj of Regulation (EU) No 575/2013 is adequate, competent authorities shall verify whether the internal validation: (a) critically reviews all aspects of the methodologies and pricing functions used for capital purposes, including those applied to new products, thereby taking account of strengths and weaknesses compared to any alternative methodologies; (b) verifies: (i) the choice of market data; (ii) the mapping of risk factors to the relevant liquidity horizon; (iii) the mapping of a real price observation to a risk factor or to a bucket for which it is considered representative; (iv) the proxying approaches used; (c) verifies whether the distributional and any other relevant stochastic assumptions and parameters of the underlying stochastic processes, including volatility and correlation, are well justified, including with regard to: (i) the tails of the distributions relevant for the calculation of the expected shortfall risk measures referred to in Article 325bb of Regulation (EU) No 575/2013; (ii) the stress scenario risk measure referred to in Article 325bk of Regulation (EU) No 575/2013; (d) assesses the soundness of any empirical correlations used both within and across the broad categories of risk factors to calculate the unconstrained expected shortfall measure referred to in Article 325bh(2) of Regulation (EU) No 575/2013; (e) assesses the correlation assumptions made in the calculation of the own funds requirements for default risk, including: (i) the choice of the relevant copula, where modelled explicitly; (ii) the choice and weights of the systematic risk factors referred to in Article 325bp of Regulation (EU) No 575/2013; (iii) the ability of the model to explain default clusters; (f) assesses the assumptions made to obtain estimates of default probabilities and losses given default to compute own funds requirements for default risk; (g) assesses the assumptions made in relation to the modelling of hedges in the computation of own funds requirement for default risk as referred to in Article 325bo of Regulation (EU) No 575/2013; (h) analyses the results of the stress testing programme, including the results relating to default risk, and extracts relevant conclusions, if any, around methodological flaws or weaknesses stemming from particular market scenarios; (i) applies and analyses the results obtained for the hypothetical portfolios referred to in Article 325bj(3), point (c), of Regulation (EU) No 575/2013 to ensure that the internal model can account for structural features, including, where relevant, the following: (i) basis risks between different yield curves; (ii) less than perfectly correlated movements between similar but not identical positions; (iii) name-related basis risk and basis stemming from similar but not identical credit or equity positions; (iv) concentration risk; (j) verifies the robustness of the implementation of the internal risk measurement model in IT systems, and ensures that all business and support units apply methodologies consistently and for all relevant geographic areas; (k) verifies the appropriateness and materiality of the proxies by assessing: (i) the percentage of proxied time series used; (ii) the percentage marginal contribution of proxied time series; (iii) the impact that proxy usage may have in the recognition of diversification effects. 2.   When assessing the completeness of the internal validation process, competent authorities shall verify whether: (a) for the internal validation conducted when the model is initially developed, the institution has performed and documented a complete validation process for all methodologies applied in the internal model; (b) for the periodic internal validation, the institution has conducted a complete validation, or has done the validation on areas to be validated following the changes referred to in paragraph 3 on: (i) any new methodologies required by the introduction of new products; (ii) areas related to any issues identified in the conclusions of previous validations and internal audit reviews. 3.   For the purposes of paragraph 2, point (b), competent authorities shall: (a) verify whether the internal policies of the institution ensure that the internal periodic validation is performed at least annually, and each time significant structural changes in the market or changes to the composition of the portfolio occur that may lead to the internal model no longer being adequate, including the following: (i) a number of overshootings that deviate significantly from the number anticipated by the model calibration; (ii) large market losses relative to the level predicted by risk metrics; (iii) a significant change in the institution’s business that may challenge the modelling assumptions; (iv) unusual and significant misalignments between the theoretical and hypothetical changes to the portfolios’ values; (b) verify whether the internal periodic validation is based on a work plan, approved by the management body, and that that work plan sets out: (i) the scope of the internal validation; (ii) the tasks performed by the validation unit; (iii) the priorities of the internal validation; (c) assess how the work plan referred to in point (b) ensures that a comprehensive and risk-oriented internal validation process is performed, and that relevant aspects are not omitted from the scope of the internal validation.

Assessment of the adequacy of reporting

Article 13

When assessing the adequacy of the reports referred to in Article 104b(2), points (d) and (f), and Article 325bi(1), point (b), of Regulation (EU) No 575/2013, competent authorities shall verify: (a) whether the institution maintains an inventory of those reports, specifying their content, frequency and addressees; (b) whether the inventory referred to in point (a) has been approved at the appropriate management level and is updated in consultation with the risk control unit.

Assessment of adequacy of trading limits

Article 14

When assessing the adequacy of trading limits referred to in Article 103(2), point (b)(ii), Article 104b(2), points (c) and (f), and Article 325bi(1), point (b), of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the institution has a clear breakdown of trading limits that is consistent with the acceptable level of risk set by the institution and the budget of each trading desk; (b) the choice of the trading limits reflects the trading strategy of the trading desk and the nature of the underlying risks; (c) the trading limits include the following: (i) a value-at-risk limit for the maximum level of portfolio aggregation at which the internal model is applied; (ii) a value-at-risk limit for each trading desk for which the institution calculates its own funds requirement for market risk with the internal risk-measurement model; (d) the institution has a further breakdown in the value-at-risk limits, proportional to the institution’s trading strategies; (e) all internal limits, including those referred to in point (c), are properly documented and formally approved; (f) as part of the limit approval and update process, the risk control unit assesses and documents the consistency and compatibility between the value-at-risk limits approved by the management body and the rest of the internal limits not based on value-at-risk, including sensitivities or loss trigger; (g) the institution properly documents and formally approves an inventory of authorised instruments and underlying risk positions that traders can enter. For the purposes of point (c)(i), the value-at-risk limit shall be the sum of individual value-at-risk limits when the permission to use the internal model approach, as referred to in Article 325(1), point (b), of Regulation (EU) No 575/2013, has not been granted.

Assessment of the adequacy of the process to update trading limits

Article 15

1.   When assessing the adequacy of the process of updating the institution’s trading limits referred to in Article 103(2), points (b)(ii), Article 104b(2), points (c) and (f), and Article 325bi(1), point (b), of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the update process is coordinated and duly documented by the risk control unit; (b) the proposal for updating the trading limits reflects any changes in: (i) the acceptable level of risk set by the institution; (ii) the expected activity or in the budget objectives of the trading desks; (c) the proposal for updating the trading limits takes into account, over the period where the trading limit applicable at the time of the update has been used: (i) the average level of use of the trading limits applicable at the time of the update; (ii) the number and magnitude of trading limit breaches. 2.   Competent authorities shall verify whether the process to update trading limits is conducted at least every year, and more frequently where there are changes in the organisation or new business lines or products are introduced.

Assessment of the adequacy of the process relating to trading limit breaches

Article 16

1.   When assessing the adequacy of the process for the approval of trading limit breaches referred to in Article 104b(2), point (f), of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the institution has a clear and documented procedure for the approval by the management body of breaching trading limits; (b) the management body has specified materiality conditions according to which any breach of the trading limits are to be reported to the management body itself, irrespective of the level where the trading limits have been approved; (c) the risk control unit documents any breaches of the trading limits and reports such breaches to the responsible committee, sub-committee or individual manager; (d) the committee, sub-committee or individual manager referred to in point (c) either takes action when a trading limit is breached, or reports such breach to the management body, in accordance with point (b); (e) the documentation referred to in point (c) comprises the magnitude and main causes of the breach of the trading limit, including: (i) any increase in the trading positions; (ii) any methodological changes introduced in the internal risk-measurement model; (iii) any developments in market conditions. 2.   Competent authorities shall verify, in particular where a trading desk has frequently exceeded trading limits, whether the frequency and magnitude of breaches of trading limits, and the measures taken by the risk control unit and management body in response to such breaches, are appropriate. The competent authority shall conduct such verification.

Assessment of the adequacy of the stress testing programme

Article 17

1.   When assessing the adequacy of the programme of stress testing referred to in Article 325bi(1), point (g), and Article 325bp(7), point (b), of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the institution reviews scenarios applied as part of the stress testing programme at least annually; (b) the risk control unit runs the stress test scenarios determined in the stress testing programme frequently and at least every month, and at a higher frequency where the institution has significant trading activities; (c) the scenarios to be applied as part of the stress testing programme comprise, apart from historically observed or hypothetical scenarios, scenarios resulting from reverse stress testing and ad-hoc scenarios designed to address the relevant specific risk drivers; (d) the scenarios referred to in point (c) are reviewed at least on an annual basis. 2.   Competent authorities shall verify whether the scenarios referred to in paragraph 1, point (c), are used to assess the reasonableness of the elements constituting the own funds requirements for market risk, including the additional own funds requirement for default risk, when those own funds requirements are compared with potential losses stemming from severe, but plausible market scenarios. 3.   For the purposes of paragraph 2, competent authorities shall verify whether the institution, when it is assessing the reasonableness of the default risk model assumptions, in particular regarding the capture of credit risk concentrations, uses all of the following: (a) losses arising from events, including credit events; (b) hypothetical rating downgrades; (c) market events on specific issuers’ types; (d) changes to copulas’ types and parameters, where modelled explicitly.

Assessment of the adequacy of the reverse and ad-hoc stress testing scenarios

Article 18

1.   When assessing the adequacy of the reverse stress testing scenarios referred to in Article 325bi(1), point (g), of Regulation (EU) No 575/2013, competent authorities shall verify whether: (a) the risk control unit applies the reverse stress test as a tool to identify possible combinations of severe events and risk concentrations within the institution, including severe events and risk concentrations that derive from environmental risks; (b) the analysis performed with the reverse stress test complements the regular stress testing; (c) when identifying the scenario or scenarios resulting from reverse stress testing, the risk control unit assesses: (i) the business lines where traditional risk management models indicate an exceptionally good trade-off between risk and return; (ii) new products and new markets which have not experienced severe strains; (iii) exposures where there are no liquid two-way markets; (iv) foreign exchange exposures either pegged or subject to a cap or floor to other currencies; (v) positions in deep out-of-the-money options, in particular digital options; (vi) events not considered in the stress period used to calibrate the expected shortfall risk measures referred to in Article 325bb of Regulation (EU) No 575/2013; (vii) environmental risks in the form of both physical and transition risks. 2.   When assessing the adequacy of ad hoc stress testing scenarios as part of the stress testing programmes referred to in Article 325bi(1), point (g), of Regulation (EU) No 575/2013, competent authorities shall verify whether the risk control unit, when designing the ad hoc stress testing scenarios concerned, takes into account the composition, at the last reporting date, of the portfolio of positions included in the scope of the internal model. Competent authorities shall in particular verify: (a) whether the risk control unit uses the results obtained from sensitivity analysis towards single risk factors, considered individually and jointly, to identify scenarios that include the stress of a combined set of plausible risk factors; (b) whether the risk control unit explicitly has considered the following elements when establishing the ad hoc stress testing scenarios: (i) the illiquidity of markets in stressed market conditions, gapping of prices, concentration risk, and one-way markets; (ii) an event resulting in a rise in correlation across instruments or risk factors, or a sharp foreign exchange shift scenario, stemming from any currencies which are subject to a peg, cap, or floor at the time of the review, which are breaking those relationships, where such an event occurs at the same time as an event as referred to in point (i); (iii) event risks for equities and jump-to-default risk for credit positions, by considering either of the following: (1) four instantaneous defaults with zero recovery of the long debt positions in the current portfolio with the largest exposure and the two largest equity long positions in the current portfolio; (2) the event risk stemming from a sharp rise in equity prices for the two largest short positions; (iv) the non-linearity of products, by applying full revaluation of all positions to reflect non-linearity effects accurately, and by applying large enough shocks to trigger the exercise of some deep out-of-the-money options, in particular digital options; (v) event risks stemming from environmental risk drivers; (vi) other risks that may not be captured appropriately in the internal models, including risks derived from the use of proxies and the potential misalignment between a proxy and the underlying risk. For the purposes of point (b)(i), the risk control unit may consider larger shocks to reflect the impossibility of unwinding positions in a timely manner, in particular for cash instruments, that is caused by the fact that positions are concentrated, or that are due to a sharp increase in market illiquidity. For the purposes of point (b)(iv), the risk control unit may, in particular: (a) assess the potential risk incurred when hedging positions valued using a proxy; (b) apply the stressed scenario movements to the proxy while keeping illiquid positions constant.

Assessment of the internal risk-measurement model in relation to the robustness of the IT systems

Article 19

1.   When assessing whether the internal risk-measurement model is calculated and implemented with integrity as required by Article 325bi(1) of Regulation (EU) No 575/2013, competent authorities shall verify whether the institution’s IT systems related to market risk management and the IT systems supporting the internal model are robust enough to cope with execution errors. In particular, competent authorities shall: (a) assess the robustness of the IT systems during the last 250 business days; (b) verify whether: (i) appropriate remediation capabilities are in place in case of system breakdown; (ii) the institution is able to re-calculate any affected risk metrics; (iii) back-testing overshootings produced by technical problems are exceptional. 2.   Competent authorities shall verify whether an institution examines all internal model positions and instruments in the internal risk-measurement model and reconciles those positions and instruments with the end-of-day value systems by confirming, at least on a weekly basis, that the positions and instruments in one system correspond to those in the other systems. Competent authorities shall verify that the institution fully documents and monitors any positions and instruments not fully reconciled.

Assessment of reasonable accuracy of the internal risk-measurement model, including pricing model

Article 20

1.   When assessing whether the internal risk-measurement model, including any pricing model, has a proven track record of being reasonably accurate in measuring risks, and does not differ significantly from the models that the institution uses for its internal risk-measurement models as referred to in Article 325bi(1), point (f), of Regulation (EU) No 575/2013, competent authorities shall: (a) verify whether the institution has inventories, whereby those inventories comprise: (i) the pricing functions or methods used in the internal-risk measurement model and the pricing functions or methods used to calculate the end-of-day value of the portfolio; (ii) for each of the pricing functions or methods referred to in point (i), a concise description, the main features, assumptions, key parameters of those pricing functions or methods, how those features, assumptions and parameters were calibrated, and how those pricing functions or methods are implemented; (iii) a description of the scope of financial instruments and commodities included in the internal-risk measurement model covered by each pricing function or method; (iv) a description of the scope of financial instruments and commodities covered by each pricing function or method in the calculation of the end-of-day-value of the portfolio; (v) one or more metrics to measure the materiality of positions priced with the corresponding pricing function or method in the internal risk-measurement model; (vi) one or more metrics to measure the materiality of positions priced with the corresponding pricing function and method in the calculation of the end-of-day-value of the portfolio; (vii) a comprehensive mapping between the pricing functions and methods used in the internal risk-measurement model and the pricing functions and methods used in the calculation of the end-of-day-value of the portfolio; (b) verify whether the inventories referred to in point (a) are updated at least annually, and whether the internal policies of the institution provide for a specific update whenever that would be necessary due to substantial changes in the information provided in the inventories; (c) verify whether all the differences between the pricing functions used to compute the end-of-day value and the pricing functions used in the internal risk-measurement model are validated as part of the internal validation referred to in Article 325bj of Regulation (EU) No 575/2013; (d) assess, on the basis of the profit and loss attribution results and the back-testing results, whether there are pricing functions that may present deficiencies; (e) analyse the conclusions in the most recent reports by the institution’s internal validation referred to in Article 325bj of Regulation (EU) No 575/2013 regarding the accuracy of the internal risk-measurement model; (f) analyse the conclusions laid down in the most recent reports about the institution’s internal review of the accuracy of the internal risk-measurement model, as referred to in Article 325bi(1), point (h), of Regulation (EU) No 575/2013; (g) verify whether the institution has documented the differences between the internal risk-measurement model and the models that the institution uses for its internal risk management for the same scope of positions, and whether the institution is able to explain those differences; (h) analyse the results of the tests performed by the institution as part of its internal validation to verify whether the assumptions made in the internal risk-measurement model are appropriate and do not underestimate or overestimate the risk, as referred to in Article 325bj(3), point (a), of Regulation (EU) No 575/2013, in particular for the trading desks with the highest differences between the own funds requirements calculated in accordance with the alternative standardised approach referred to in Part Three, Title IV, Chapter 1a of Regulation (EU) No 575/2013, and the own funds requirements calculated in accordance with the internal risk-measurement model. For the purposes of point (d), competent authorities may, where appropriate, require the institution to calculate, on a set of instruments and commodities for which the competent authority wants to test the accuracy of the pricing functions, the risk-theoretical changes referred to in Chapter 2, Section 2, of Commission Delegated Regulation (EU) 2022/2059  ( 10 ) and the hypothetical changes referred to in Chapter 1, Section 2, of that Delegated Regulation, and require the institution to justify differences in outcome between the two measures. 2.   Where positions corresponding to product classes assigned to a trading desk are booked back-to-back with those of another entity of the group that is outside the scope of the highest level of consolidation within the Union, and the competent authority needs more evidence to verify that the internal risk-measurement model is reasonably accurate, the competent authority may require institutions to provide: (a) the actual, hypothetical, and risk theoretical changes over 60 business days in the trading desk portfolio’s value, without any hedges with the entity of the group being considered; (b) the value-at-risk numbers at trading desk level as referred to in Article 325bf of Regulation (EU) No 575/2013 over 60 business days, without any hedges with the entity of the group being considered; (c) an assessment of the profit and loss attribution results and back-testing results in light of the changes in the portfolio’s values referred to in point (a) and the value-at-risk numbers referred to in point (b). 3.   Where the market risk of positions corresponding to some product classes is transferred to another entity of the group that is outside the scope of the highest level of consolidation within the Union, and the effects of such transfer de facto resemble the effects of positions booked back-to-back, competent authorities may apply paragraph 2.

Assessment of the internal risk-measurement model in relation to additional back-testing programmes

Article 21

1.   When assessing whether the institution’s internal model is implemented with integrity as required by Article 325bi(1) of Regulation (EU) No 575/2013 in relation to the back-testing referred to in Article 325bj(3), point (b), of that Regulation, competent authorities shall verify whether, as part of such back-testing programmes, the institution: (a) runs the back-testing programme referred to in paragraph 2 or another internal back-testing programme that enables the institution to identify the contribution of modellable and non-modellable risk factors to the back-testing results; (b) applies direct expected shortfall back-testing approaches to its portfolios. For the purposes of point (b), competent authorities shall verify how the institution motivates the choice of the applied direct expected shortfall back-testing methodology, and analyse whether that methodology is conceptually sound. The institution may use the back-testing programmes referred to in the first subparagraph as an element to detect and monitor potential deficiencies in the calculation of the excepted shortfall measures. Where a competent authority decides on the permission to use the internal model approach to compute the own funds requirement for market risk in accordance with Article 325az, those back-testing programmes shall not supersede the outcomes of the regulatory back-testing referred to in Article 325bf of Regulation (EU) No 575/2013 and the profit and loss attribution requirements referred to in Article 325bg of that Regulation. 2.   For the purposes of paragraph 1, first subparagraph, point (a), the institution may run a back-testing programme that applies the following principles: (a) an overshooting is identified as a one-day change in HPL MRF or in (b) APL MRF that exceeds the value-at-risk number referred to in Article 325bf(6), point (a), of Regulation (EU) No 575/2013; (c) HPL MRF and APL MRF are calculated as follows: Where: — HPL are the hypothetical changes in the portfolio’s value; — APL are the actual changes in the portfolio’s value; — RTPL are the risk-theoretical changes in the institution’s portfolio’s value; — RTPL MRF are the risk-theoretical changes in the institution’s portfolio’s value considering only changes to modellable risk factors; (d) the institution identifies potential weaknesses in its risk-measurement model by counting the overshootings, as identified in accordance with point (a), that occurred over the last 250 business days, and by comparing the amount of the identified overshootings against the thresholds referred to in Article 325bf(3), points (a) and (b), of Regulation (EU) No 575/2013.

Back to Commission Delegated Regulation (EU) 2024/1085 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next