Status and independence of the Chief Risk Officer
1. The Chief Risk Officer shall serve as the corporate second line of defence for the financial risk assessment of the Union’s financial operations. The Chief Risk Officer shall enjoy autonomy in carrying out the tasks and responsibilities set out in this Decision.
2. The post of the Chief Risk Officer shall constitute a specific function which shall be occupied by a senior manager with adequate professional experience in financial risk management and shall be supported by a dedicated team having relevant expertise. The Chief Risk Officer shall report directly to the Member of the College responsible for the Budget with respect to the responsibilities set out in this Decision.
3. The Chief Risk Officer shall exercise its role independently of functions and tasks related to the design, planning, implementation, management, execution of, and accounting for the Union’s financial operations. The function of the Chief Risk Officer shall not be compatible with the functions of an authorising officer by delegation for the Union’s financial operations and of the Accounting Officer.
4. The Chief Risk Officer shall be considered equivalent to the service responsible within the meaning of Article 55 of the Rules of Procedure of the Commission in respect of the High Level Risk and Compliance Policy and the thematic risk and compliance policies. The Directorates General responsible for the Union’s financial operations shall be services with a legitimate interest who shall be consulted in interservice consultations on the High Level Risk and Compliance Policy and on those thematic risk and compliance policies which concern them.
5. The Chief Risk Officer shall be considered equivalent to the service with legitimate interest within the meaning of Article 58 of the Rules of Procedure of the Commission and shall be consulted in interservice consultations in particular on legislative proposals for programmes or instruments authorising budgetary guarantees and loans, as well as on acts implementing programmes or instruments authorising budgetary guarantees and loans and on acts concerning any Union financial operation. This shall include interservice consultations on draft guarantee agreements and loan agreements as well as decisions approving the main elements of guarantee agreements. When being consulted, the Chief Risk Officer shall exclusively assess aspects of the financial risk management and compliance with the High Level Risk and Compliance Policy and the thematic risk and compliance policies.
General tasks of the Chief Risk Officer
The Chief Risk Officer shall oversee the financial risks stemming from the Union’s financial operations and shall be responsible for the following general tasks:
(a)
lead the development of the risk framework governing the financial risk management and compliance for the Union’s financial operations, in particular drawing up a High Level Risk and Compliance Policy, supplemented by thematic risk and compliance policies;
(b)
set up and lead interservice working groups on the development of the High Level Risk and Compliance Policy and the thematic risk and compliance policies with participation of the Directorates General responsible for the Union’s financial operations and other Directorates General concerned;
(c)
oversee the implementation of the risk framework, including systems and processes needed to give effect to the High Level Risk and Compliance Policy and thematic policies by Directorates-General responsible for the Union’s financial operations concerned;
(d)
assess the financial risks arising from borrowing operations, liquidity management operations and programmes or instruments authorising budgetary guarantees and loans before proposals for these programmes or instruments are adopted by the Commission;
(e)
independently assess, consolidate, and report on the risks arising from the Union’s financial operations, taking into account the data and input from the Directorates General responsible for the Union’s financial operations, and on compliance with the risk management framework and specified limits, including any relevant provisions set out in the basic acts establishing the individual programmes and the Financial Regulation;
(f)
identify potential breaches of and non-compliance with the High Level Risk and Compliance Policy, thematic risk and compliance policies or other risk related guidelines, legal acts and policies and provide advice on mitigation measures where necessary, and/or review management and mitigating measures implemented or proposed by the Directorates-General responsible for the Union’s financial operations;
(g)
promote best practices, risk culture, consistent and harmonised risk approaches across Commission services in the management of the risks arising from the Union’s financial operations.
Specific tasks in respect of EU borrowing, debt management, liquidity management and asset management operations
In addition to the general tasks, the Chief Risk Officer shall have the following tasks in respect of EU borrowing, debt management, liquidity management and asset management operations:
(a)
define within the relevant thematic risk policy, where feasible, the risk appetite, and risk tolerance applicable for the different types of financial operations;
(b)
issue an opinion on the draft funding plan and its subsequent amendments;
(c)
issue an opinion on the liquidity management strategy for liquidity management operations prior to their adoption or amendment;
(d)
be consulted on the asset management guidelines, the strategic asset allocation, and the applicable benchmarks for asset management operations, before their adoption by the Directorate-General responsible for these operations;
(e)
define eligibility criteria for authorised counterparties and potential issuers that may be considered for investment opportunities;
(f)
define appropriate risk limits to ensure that the credit risk, market risk and liquidity risk undertaken through the asset management and liquidity management operations remain compliant with the risk objectives, risk capacity, risk appetite and risk tolerance set in the relevant investment guidelines, the High Level Risk and Compliance Policy and the thematic policies. The risk limits may be set up at counterparty level or instrument level, or set up at the level of the aggregated exposures;
(g)
assess, consolidate and report on risk exposures, executed by the Directorate-General for the Budget or, when relevant, outsourced to a third party.
Specific tasks related to assessment of financial risks of programmes or instruments authorising budgetary guarantees and loans
The Chief Risk Officer shall in respect of programmes or instruments authorising budgetary guarantees and loans:
(a)
conduct regular and independent portfolio risk assessments based on the approved risk methodologies and based on data provided by Directorates-General responsible for the Union’s financial operations;
(b)
provide relevant input on financial risks and contingent liabilities to reports adopted by the Commission on these issues, such as the risk assessment for reporting under Article 41(5) and Article 256 of the Financial Regulation based on information from the Directorates General responsible for the Union’s financial operations.
The High Level Risk and Compliance Policy
1. In furtherance of the general task referred to in Article 5(1)(a), the Chief Risk Officer shall prepare a High Level Risk and Compliance Policy.
2. The High Level Risk and Compliance Policy shall:
(a)
set the strategic risk objectives guiding the management of the different categories of financial risk arising from the implementation of the Union’s financial operations;
(b)
describe the risk governance framework which outlines the main roles and responsibilities related to the risk management and compliance framework of the Union’s financial operations;
(c)
present the Commission’s high level risk appetite statement;
(d)
identify the principal risks to the financial interests of the Union arising from the implementation of the Union’s financial operations and provide a high-level risk management and compliance framework for the assessment, measurement, mitigation and monitoring of those risks.
Thematic risk and compliance policies
1. The thematic risk and compliance policies shall set out the systems, rules, risk methodologies, procedures and processes for the risk management, reporting and compliance related to the main categories of financial risks arising from the Union’s financial operations and shall describe the roles and responsibilities of the different services involved in the management of the identified risks. Those policies shall take into account the specificities of different categories of the Union’s financial operations.
2. The thematic risk and compliance policies shall be in line with the High Level Risk and Compliance Policy.
Specific elements of thematic risk and compliance policies establishing risk framework for the Union’s budgetary guarantees and loans
1. The relevant thematic risk and compliance policy in respect to budgetary guarantees and loans shall:
(a)
establish the risk methodologies, including risk parameters and tools to evaluate potential losses resulting from budgetary guarantees and loans, which shall, inter alia, constitute guidance for the setting of the provisioning rate;
(b)
define the risk methodologies as appropriate to ensure Commission-wide consistency and convergence relevant in the process of the designing, negotiating, implementing and monitoring of budgetary guarantees and loans;
(c)
define the methodology to measure the level of financial risks to be provisioned as adequate safety buffer referred to in Article 214(2), second subparagraph of the Financial Regulation.
2. The risk methodologies and tools established in the thematic risk and compliance policies shall be used by both the first and second lines of defence when assessing envisaged programmes or instruments authorising budgetary guarantees and loans.
Implementation of the High Level Risk and Compliance Policy and thematic risk and compliance policies
1. The Chief Risk Officer shall oversee the implementation of the High Level Risk and Compliance Policy and the thematic risk and compliance policies by the Directorates-General responsible for the Union’s financial operations.
2. The Directorates-Generals responsible for the Union’s financial operations shall monitor the risks related to the respective Union’s financial operations and ensure compliance with the High Level Risk and Compliance Policy and thematic risk and compliance policies. To this effect, the Directorates-Generals responsible for the Union’s financial operations shall in particular:
(a)
take all necessary measures to implement controls and reporting systems needed to comply with the systems, methodologies and processes resulting from those policies;
(b)
ensure in the implementation of the Union’s financial operations that financial risks remain within the risk appetite and risk limits defined, where relevant, for the programme or instruments establishing the budgetary guarantee and loans;
(c)
provide regular reports to the Chief Risk Officer on compliance with the High Level Risk and Compliance policy and thematic risk and compliance policies;
(d)
document thoroughly the implementation of the Union’s financial operations which they oversee, report on situations where the risk of the portfolio of operations deviates or may deviate from the set risk levels;
(e)
respond in a timely manner to requests for additional information from the Chief Risk Officer, including relevant information available on operations guaranteed by the Union budget and conducted by implementing partners and counterparts, where this is required to enable the Chief Risk Officer to establish an independent assessment of the risks;
(f)
when working with third parties, notably implementing partners and counterparts, obtain the necessary information, available in particular in line with the respective guarantee agreements, about financial risks related to the Union’s financial operations.
3. The Directorates-General responsible for the Union’s financial operations shall establish the rules and procedures to ensure effective compliance with the High Level Risk and Compliance Policy and the relevant thematic risk and compliance policies for the Union’s financial operations for which they are responsible. The Chief Risk Officer may be consulted on these rules and procedures with a view to review their compliance with the High Level Risk and Compliance Policy and the thematic risk and compliance policies.
Advice to mitigate financial risks
1. The Chief Risk Officer may advise the Directorates-General responsible for the Union’s financial operations on the implementation of the High Level Risk and Compliance Policy or thematic risk and compliance policies or on the management of specific risks. Such advice may include appropriate remedial measures.
2. The Directorates-General responsible for the Union’s financial operations shall, without undue delay, address the advice or, as applicable, other non-compliance or breach of limits as referred to in the Article 5(f) and provide to the Chief Risk Officer explanations on the measures taken.
3. The Chief Risk Officer may, as appropriate, inform the Member of the College responsible for the Budget and the Member(s) of the College responsible for the Union’s financial operations concerned about the advice referred to in paragraph (1) and, where relevant, about the deliberations of the Risk and Compliance Committee. Such information may also include assessment of the rules and procedures referred to in Article 11(3).
4. The Chief Risk Officer shall regularly inform the Risk and Compliance Committee on the advice provided and on the follow up by the Directorates-General responsible for the Union’s financial operations.
Reports and information on financial risks
1. The Chief Risk Officer shall submit regular reports to the Member of the College responsible for the Budget, the Members of the College responsible for the Union’s financial operations, to the Risk and Compliance Committee, to the Director-General of the Directorate-General for the Budget, to the Accounting Officer and to the Directors-General responsible for the Union’s financial operations, respectively for their areas of competence, on financial risks arising from the Union’s financial operations in accordance with this Decision.
2. The Chief Risk Officer shall promptly inform the Member of the College responsible for the Budget in the event of material developments which call for urgent consideration. In addition, the Directorates-General concerned shall be timely and duly informed.
3. The Chief Risk Officer shall regularly inform the Risk and Compliance Committee, the Director-General of the Directorate-General for the Budget, the Accounting Officer and the Directorates-General responsible for the Union’s financial operations, on risks and non-compliance with rules and procedures or breaches of limits in respect of the Union’s financial operations, respectively for their areas of competence.
4. The Chief Risk Officer shall submit a report on the implementation and functioning of the High Level Risk and Compliance Policy to the College once per year, which may be accompanied by a proposal to review the policy.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.