The ECB guide to internal models provides guidelines for the Targeted Review of Internal Models (TRIM). It includes general principles and risk-type-specific recommendations, as well as guidance on data governance and model risk management. This document is regularly updated to incorporate industry feedback and regulatory changes.
- Title: ECB guide to internal models
- Author/organization: European Central Bank - Banking Supervision (SSM)
- Date: June 2026
- Type: consolidated guide, 374 pages (only the first 120 pages provided)
- Scope: regulatory and practical framework for supervision of internal models for calculating capital requirements in credit, market and counterparty risk, according to CRR, CRR2, CRR3
- Target population: credit institutions and investment firms supervised by the ECB
- Sector: European banking sector
- Period: regular updates, latest version June 26, 2026
- Specificity: removal of content related to the estimation of the conversion factor (CCF) in this version
- Traceability: precise page citations in parentheses
The ECB guide to internal models (ECB Guide to Internal Models) published in June 2026 aims to clarify the ECB's understanding and application of European regulatory requirements (CRR, CRR2, CRR3) related to the use of internal models for calculating capital requirements in credit, market and counterparty risk (Pillar 1). This document is a transparency tool for supervised institutions and an internal guide for supervisory teams to ensure a consistent and harmonized approach.
The guide updates the ECB's principles and expectations in light of regulatory developments, notably the postponement to January 1, 2026, of the application of FRTB standards (CRR3) for market risk, leading to the temporary coexistence of separate chapters for CRR2 and CRR3 market risk models. It also incorporates feedback from sector stakeholders collected during public consultations.
Key points emphasized by the guide include:
- The need for robust and consistent governance at consolidated and local levels, with clear principles and controls over the internal model lifecycle.
- The importance of complete, updated and accessible model documentation, including a detailed model register with information on owners, uses, limits and versions.
- Strict requirements regarding data governance, model risk management framework, independence and competencies of internal validation and audit functions.
- Integration of climate and environmental risks into internal models when these risks are material.
- A detailed chapter on the use of machine learning (ML) techniques in internal models, with specific expectations on complexity, explainability, governance, validation, audit, change management, IT infrastructure and third-party use.
- Precise recommendations on managing material changes or extensions to models, with an implementation timeframe generally expected within three months after notification.
- Principles governing outsourcing of tasks related to internal models, emphasizing retention of responsibilities by the institution, contractual transparency, information access, and maintenance of internal skills.
The guide does not replace applicable regulation but clarifies the ECB's interpretation and application. It stresses that so-called "best practices" are recommended but not exclusive means to ensure prudent compliance.
In conclusion, the guide recommends institutions strengthen governance, documentation, risk management and monitoring of internal models, especially for complex models and those incorporating ML techniques, to ensure reliability of capital calculations and regulatory compliance.
- The guide responds to the regulatory obligation arising from Articles 143, 283 and 325 of the CRR and its amendments CRR2 and CRR3, which require the ECB to authorize the use of internal models under strict conditions.
- It aims to provide a clear and homogeneous interpretation of regulatory requirements for supervisory teams and supervised institutions.
- The guide is an evolving document, integrating feedback from public consultations and regulatory developments, notably the deferred implementation of FRTB standards.
- It does not replace applicable European and national regulations, nor the technical standards adopted by the European Commission.
- The scope covers internal models for credit, market and counterparty risk, as well as transversal aspects such as governance, validation, audit, data management, model risk management, climate risks and use of ML techniques.
- Limitations: only the first 120 pages are provided; content on the estimation of the conversion factor (CCF) has been removed as it is under revision by the EBA.
- Stakes: ensure robustness, consistency and compliance of internal models to guarantee the prudential soundness of institutions and protection of the financial system.
Governance and organization:
- Importance of consistent governance at consolidated and local entity levels, with binding principles and guidelines or audited and aligned local principles (p. 8-9).
- Clear identification of management and senior management responsibilities, with dedicated committees for internal model governance, mandated and documented (p. 11-12).
Model documentation:
- Complete documentation covering methodology, assumptions, data, user instructions, validation and performance (p. 9-10).
- Model register with detailed information (owner, scope, materiality, restrictions, versions, weaknesses) including third-party models (p. 10).
- Annual controls and clear policies for document management and archiving (p. 10).
Data governance:
- Robust data governance practices in accordance with the ECB guide on risk aggregation and reporting and DORA and BCBS 239 standards (p. 10-11).
- Processes to ensure consistency of data derived from human judgment (p. 11).
Model risk management:
- Formalized framework including written policy, model register, identification and mitigation of uncertainties and deficiencies, qualitative and quantitative evaluation methods, model lifecycle, communication and reporting, definition of roles and responsibilities, and appropriate training (p. 11-12).
- Regular assessment of model complexity, identification of highly complex or dynamic models (p. 12).
Internal validation:
- Mandatory initial and annual validation, with independence ensured by organizational separation (three options depending on size and complexity) (p. 12-14).
- Enhanced validation for complex and ML models (p. 19-20).
Internal audit:
- Regular independent review, with clear function separation, direct reporting to management, adequate resources and skills, follow-up of recommendations and reporting to authorities (p. 14-15).
Climate and environmental risks:
- Integration of climate risks into internal models when materially relevant (p. 15).
Use of machine learning (ML) techniques:
- Pragmatic definition of ML as complex, nonlinear techniques with many parameters and high data demand (p. 16-17).
- Specific governance covering skills, change management, validation, audit, IT infrastructure, and outsourcing (p. 17-22).
- Increased requirements for explainability, justification of complexity, documentation, monitoring of drifts and automatic updates (p. 23-26).
- Controlled use in decision-making processes, with vigilance on additional risks (bias, adjustments), and monitoring of override overloads (p. 26-27).
Change and extension management:
- Rapid implementation (generally within 3 months after notification), with justification for exceptional delays (p. 27-28).
Outsourcing and third parties:
- Strict contractual framework guaranteeing information access, support to authorities, maintenance of internal skills and operational continuity (p. 28-32).
- Final responsibility retained by the institution, even in case of delegation (p. 30).
- Independent monitoring of third-party performance (p. 32).
Regulatory references and alignment:
- The guide relies on CRR, CRR2, CRR3, CRD, RTS, ITS, EBA Guidelines, BCBS 239, DORA, and other relevant standards (p. 7-8).
- The guide is an evolving document considering regulatory developments and sector feedback.
- Established facts:
- The guide formalizes the ECB's expectations on governance, documentation, validation, audit, data management, risk management, climate risks and use of ML in internal models (p. 6-27).
- The complexity and materiality of models, notably those incorporating ML, determine the level of governance, validation and audit requirements (p. 12, 16-27).
- Independence of validation and audit functions is essential and must be adapted to the size and complexity of the institution (p. 12-15).
- Outsourcing is permitted under strict conditions, with retention of responsibilities and maintenance of internal skills (p. 28-32).
- Assumptions:
- Increased use of ML in internal models is a trend requiring specific adaptations of governance and controls (p. 16-27).
- Temporary coexistence of CRR2 and CRR3 models for market risk requires a dual approach in supervision (p. 6).
- Interpretations:
- The ECB considers "best practices" as recommended but not exclusive means to ensure prudent compliance (p. 6).
- Use of explainability techniques is crucial to guarantee understanding, plausibility and robustness of ML models (p. 23-26).
- Uncertainties:
- The guide will be updated according to finalization of RTS and ITS by the EBA and European Commission (p. 6).
- The future impact of the AI Act on internal models remains to be clarified (p. 6).
- Content related to the conversion factor (CCF) is under revision by the EBA and has been removed (p. 2).
- The guide recommends institutions implement robust and consistent governance of internal models at all levels, with clear principles and controls over the model lifecycle.
- It highlights the need for complete, accessible and up-to-date documentation, as well as a detailed register of internal models.
- Institutions must ensure solid data governance, compliant with international and regulatory standards.
- Model risk management must be formalized within a framework covering identification, assessment, mitigation, communication and training.
- Independence and competencies of internal validation and audit functions must be adapted to the size and complexity of models, with enhanced requirements for ML models.
- Climate risks must be integrated into internal models when relevant.
- Use of ML techniques in internal models must be governed by specific principles regarding complexity, explainability, validation, audit, change management, IT infrastructure and outsourcing.
- Material changes or extensions to models must be implemented rapidly, generally within three months, except for justified exceptions.
- Outsourcing of tasks related to internal models must comply with strict requirements on transparency, information access, maintenance of internal skills and operational continuity.
- The guide will be updated according to regulatory developments and stakeholder feedback.
- Priority is given to regulatory compliance, model robustness and risk control, notably in a context of increasing technological innovation.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.