Home › Academy › Library › ECB guide to internal July 2025 This…
Synthesis note · Guide

ECB guide to internal July 2025 This publication has become

European Central Bank - Banking Supervision (SSM) · 2025 · Guide · 370 pages · Intermediate

This ECB guide on internal models provides guidelines for risk management within financial institutions. It covers topics such as data governance, internal validation, and the use of machine learning techniques. The publication is regularly updated to reflect regulatory changes and user feedback.

General Information

The document is the "ECB guide to internal models" published by the European Central Bank - Banking Supervision (SSM) in July 2025. It is a consolidated guide of 370 pages (only the first 119 pages are provided) intended to clarify the application of European rules relating to internal models used by financial institutions for the calculation of capital requirements in credit, market risk and counterparty credit risk. The guide covers general principles, governance, validation, documentation, risk management related to internal models, as well as specific chapters on credit, market and counterparty credit risks. It incorporates regulatory developments from the CRR, CRR2 and CRR3 regulations, as well as feedback from institutions and public consultations. The period covered includes the latest regulatory developments up to July 2025, with particular attention to the impacts of machine learning techniques in internal models (p. 1-33).

Executive Summary

This ECB guide aims to ensure a common understanding and consistent application of European regulatory requirements relating to internal models used for the calculation of capital requirements in credit, market risk and counterparty credit risk. It is essential because these models directly influence risk measurement and the financial soundness of supervised institutions, impacting the stability of the European banking system (p. 6).

The main findings are:

- The need for robust and coherent governance at the consolidated and individual entity level, with clear principles and guidelines on the model lifecycle, including development, validation, implementation and review (p. 8-9).

- The importance of complete and up-to-date documentation, allowing understanding, replication and independent validation of models, with a detailed model register (p. 9-10).

- Strict data governance practices, including security, quality and consistency, particularly for data derived from human judgments (p. 10-11).

- The establishment of a risk management framework related to models, including a written policy, a register, qualitative and quantitative assessment methodologies, communication procedures, as well as competency and training requirements (p. 11-12).

- Clear definition of roles and responsibilities of the general management and senior management in model governance (p. 12).

- The requirement for independent internal validation, initial and annual, with organizational arrangements proportionate to size and complexity, ensuring absence of conflicts of interest (p. 13-14).

- The key role of internal audit, independent and adequately resourced, to ensure regular and effective model reviews, with rigorous follow-up of action plans (p. 14-15).

- Integration of climate and environmental risks in the assessment of model risk materiality (p. 15).

- Detailed principles on the use of machine learning (ML) techniques in internal models, highlighting their increased complexity, specific needs in governance, validation, audit, data management, IT infrastructure, and the necessity to explain and document models to ensure transparency and auditability (p. 15-26).

- Precise expectations on managing model changes, notably for dynamic ML models, with monitoring of evolutions, prevention of drifts and rigorous classification of modifications (p. 17-18).

- The importance of a rigorous override policy, particularly for ML models, with detailed documentation and use of explainability techniques (p. 26-27).

- Implementation deadlines for material model changes generally less than three months after authorization, except justified exceptions (p. 27).

- Strict principles governing outsourcing of tasks related to internal models, including formal contracts ensuring access to information, continuity, quality, independent validation, and maintenance of internal skills (p. 28-33).

The conclusions emphasize the need for rigorous and harmonized application of these principles to ensure the reliability, robustness and compliance of internal models, notably in a context of rapid technological evolution with increasing integration of machine learning. The guide recommends institutions strengthen their governance, validation, audit, documentation and data management frameworks, while ensuring appropriate training of stakeholders and careful monitoring of model changes. Finally, it highlights the importance of attentive supervision by the ECB, notably through internal investigations on models and their modifications (p. 6-33).

Context and Objectives

The guide was developed to meet the requirements of Articles 143, 283 and 325 of the CRR regulation, amended by CRR2 and CRR3, which require the ECB to authorize the use of internal models for the calculation of capital requirements in credit, market risk and counterparty credit risk. Its objective is to provide transparency and consistency in the interpretation and application of these rules by the ECB when assessing institutions (p. 6).

The guide also aims to harmonize practices of the ECB’s internal supervisory teams, taking into account the specificities of supervised institutions. It does not replace applicable European or national legislation, nor the regulatory technical standards (RTS, ITS) adopted or under adoption by the EBA and the European Commission. It incorporates the latest regulatory developments, notably the postponement to January 1, 2026 of the application of FRTB standards for market risk, as well as EBA guidelines on the boundary between the banking book and trading book (p. 6-7).

The guide responds to the increasing complexity of internal models, notably with the growing integration of machine learning techniques, and to challenges related to governance, validation, documentation, risk management, regulatory compliance, data management and model supervision. It sets a clear framework for institutions to ensure robustness, transparency and compliance of internal models, while specifying expectations regarding outsourcing and third-party involvement (p. 6-33).

The document’s limitations relate to its nature as an interpretative guide based on the regulation in force at the publication date, with updates planned according to future regulatory developments. Only the first 119 pages are available for this summary.

Summary of Key Points by Theme

Governance and organization:

- Importance of coherent governance at consolidated and entity levels, with clear principles and guidelines on the internal model lifecycle (development, calibration, validation, approval, implementation, use, review) (p. 8-9).

- Clearly defined roles and responsibilities for the management body (executive board) and senior management, with precise documentation of committees dedicated to model governance (p. 12).

Documentation:

- Complete and up-to-date documentation required to allow understanding, replication and independent validation of models, including methodology, assumptions, data, usage instructions and validation results (p. 9-10).

- Internal model register with information on owner, scope, materiality, approval date, restrictions, key weaknesses, changes and versioning (p. 9-10).

Data management:

- Rigorous data governance compliant with standards such as DORA and BCBS 239, including security, quality, data lifecycle management and consistency of human labelling (p. 10-11).

Risk management related to models:

- Formalized framework with written policy, register, qualitative and quantitative assessment methodologies, communication procedures, role definitions, competency requirements and adapted training (p. 11-12).

- Classification of models according to complexity, identifying highly complex models (notably those using ML) and dynamic (self-adaptive) models (p. 12).

Internal validation:

- Mandatory initial and annual validation, with strong organizational independence between development and validation (three organizational options depending on size and complexity) (p. 13-14).

- Validation equipped with adequate resources, qualified personnel, and robust procedures to challenge models (p. 14).

Internal audit:

- Independent audit, separate from operational units, reporting directly to the management body, with adapted resources and competencies (p. 14-15).

- Rigorous follow-up of findings, action plans, and regular reporting to committees and competent authorities (p. 15).

Climate and environmental risks:

- Mandatory integration of climate and environmental risks in the assessment of internal model risk materiality (p. 15).

Use of machine learning (ML) techniques:

- Pragmatic definition of ML as complex, non-linear techniques with many parameters and low explainability (p. 15-16).

- Enhanced governance for ML models, including specific skills for all actors (developers, validators, audit, users, management) (p. 16-18).

- Clear policy on change management, distinguishing material changes, maintenance and autonomous adaptations, with monitoring of drifts (p. 17-18).

- Specific internal validation, including hyperparameter challenge, robustness evaluation, out-of-sample and out-of-time tests, and use of explainability tools (p. 18-20).

- Internal audit adapted to ML specificities, with increased frequency and intensity for complex or dynamic models (p. 19-20).

- Enhanced data governance for ML-specific data, including exploratory analysis and bias control (p. 20-21).

- Adapted IT infrastructure, ensuring traceability, versioning and auditability of ML models (p. 21-22).

- Strict outsourcing framework for ML-related tasks, maintaining internal skills and rigorous control of providers (p. 22-33).

Mathematical methodology:

- Rigorous justification of ML component structure and parameters, with attention to over- and under-fitting, and storage of elements necessary for replication (p. 22-23).

- Motivation of model complexity, avoiding unnecessary complexity relative to performance gains and organizational objectives (p. 23-24).

- Use of explainability tools to ensure plausibility, intuition and transparency of estimates, with documentation of technique limitations (p. 23-25).

Use of ML models:

- Clear definition of uses, functionalities and limits in internal policies (p. 25).

- Increased monitoring of specific risks related to ML model use, notably biases and changes for uses other than capital calculation (p. 25-26).

- Rigorous override policy, with complete documentation, use of explainability tools before override, and thorough training of concerned staff (p. 26-27).

Change management and implementation:

- Implementation of material changes within a reasonable timeframe, generally less than three months after authorization, with justified exceptions (p. 27).

Outsourcing:

- Strict framework for outsourcing contracts, ensuring full access to information, continuity, communication with authorities, and maintenance of internal skills (p. 28-33).

- Possibility to delegate validation and audit under conditions of independence and strict control, including "cool-off" periods to avoid conflicts of interest (p. 29-31).

- Independent monitoring of providers and quality control of external data used (p. 31-33).

Main Results and Lessons Learned

Established facts:

- The ECB published a detailed consolidated guide in July 2025, integrating regulatory developments CRR, CRR2, CRR3, and feedback from institutions (p. 1-7).

- The guide specifies expectations regarding governance, documentation, validation, audit, data management, risk management and outsourcing of internal models (p. 8-33).

- The growing use of machine learning techniques in internal models imposes specific increased requirements in governance, validation, audit, explainability, IT infrastructure and data management (p. 15-27).

Hypotheses:

- Integration of climate and environmental risks in internal models is necessary and applicable (p. 15).

- Dynamic ML models require specific monitoring and classification due to their autonomous adaptation capacity (p. 12, 17).

Interpretations:

- The increased complexity of ML models justifies strengthened requirements regarding independence of validation and audit functions, as well as higher frequency of controls (p. 13-20).

- Explainability of ML models is a key issue to ensure plausibility and transparency of estimates, conditioning user and supervisor trust (p. 23-25).

- Management of human overrides must be particularly rigorous for ML models, to avoid biases and ensure decision quality (p. 26-27).

Uncertainties:

- Future evolution of regulatory technical standards (RTS, ITS) and EBA policies may lead to guide updates (p. 6).

- The potential impact of AI regulation (AI Act) on internal models remains to be clarified (p. 7).

- Practical implementation of recommendations, notably for complex ML models, will depend on institutions’ capacities and resources (p. 15-27).

Conclusions and Author’s Recommendations

The ECB concludes that to ensure regulatory compliance and robustness of internal models, institutions must:

- Establish clear and coherent governance at all levels, with well-defined roles and responsibilities for management and committees (p. 12).

- Exhaustively document models, with an up-to-date register and rigorous document management policies (p. 9-10).

- Adopt strict data governance practices, ensuring quality, security and consistency, notably for data derived from human judgments (p. 10-11).

- Deploy a risk management framework related to models, including qualitative and quantitative assessment, communication, definition of competencies and training (p. 11-12).

- Ensure independence and competence of validation and internal audit functions, with resources adapted to model complexity (p. 13-15).

- Integrate climate and environmental risks in model evaluation (p. 15).

- Apply specific requirements for ML models, notably in governance, validation, audit, explainability, change management, IT infrastructure and outsourcing (p. 15-33).

- Respect rapid implementation deadlines (generally less than three months) for material model changes (p. 27).

- Strictly control outsourcing of model-related tasks, maintaining internal skills and rigorous oversight of providers (p. 28-33).

The guide also recommends active supervision by the ECB, including internal investigations on models and their modifications, to guarantee compliance and soundness of internal models within the European banking system (p. 6-33).

Key takeaways

References

Year
2025
Type
Guide
Level
Intermediate
Licence
Attribution required, educational use
Original document
https://www.bankingsupervision.europa.eu/framework/supervisory-policy…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.