Home › Academy › Library › ECB Guide to internal models - February 2024…
Synthesis note · Guide

ECB Guide to internal models - February 2024 (credit risk, market risk, counterparty credit risk)

European Central Bank - Banking Supervision (SSM) · 2024 · Guide · 285 pages · Intermediate

The ECB guide on internal models provides guiding principles for the assessment of credit, market, and counterparty risks. It includes recommendations on internal governance, model validation, and data usage. This document is essential for financial institutions seeking to comply with regulatory requirements for risk management.

General Information

This document is the "ECB Guide to internal models" published by the European Central Bank (ECB) - Banking Supervision (SSM) in February 2024. It is a consolidated guide of 285 pages (only the first 92 pages are provided) covering internal models used for credit risk, market risk, and counterparty credit risk. The guide is based on the European regulatory framework, notably Regulation (EU) No 575/2013 (CRR) and associated delegated regulations, as well as feedback from financial institutions and experiences from the TRIM (Targeted Review of Internal Models) process. The scope includes general principles, governance, internal validation, internal audit, model usage, change management, third-party involvement, as well as chapters specific to different types of risks. The guide reflects the applicable law as of 2024 and incorporates recent regulatory developments, while specifying that some parts may be revised upon the final adoption of regulatory technical standards (RTS).

Executive Summary

The ECB guide on internal models aims to clarify the interpretation and application of European regulatory requirements related to the use of internal models for calculating capital requirements for credit risk, market risk, and counterparty credit risk (Pillars 1). It responds to the ECB’s regulatory obligation to grant permissions for the use of internal models subject to compliance with CRR conditions. This document is essential as it ensures transparency and consistency in the supervision of internal models within the euro area, thereby contributing to financial stability and the robustness of supervised banks. The main findings are as follows: (i) the need for solid and clearly defined governance, including precise responsibilities for management and decision-making bodies; (ii) the importance of comprehensive and up-to-date documentation of internal models, enabling independent understanding and validation; (iii) the establishment of a model risk management framework covering the entire model lifecycle; (iv) strict requirements regarding independence and resources for internal validation and audit functions; (v) precise rules for the phased deployment of IRB approaches, including quantitative thresholds (minimum 50% IRB coverage in EAD and RWEA) and qualitative criteria; (vi) procedures governing model changes, extensions, or reverts, with implementation deadlines generally under three months; (vii) consideration of climate and environmental risks in models when these risks are material. The conclusions emphasize that compliance with regulatory requirements must be ensured by robust, transparent, and regularly controlled processes, with an active role of management in model supervision. The main recommendations concern the adoption of clear governance policies, rigorous maintenance of a model register, implementation of independent and regular internal validation, as well as transparent communication with supervisory authorities. The guide also stresses the need for proactive management of IRB deployment plans and model changes to avoid operational and compliance risks.

Context and Objectives

This guide was developed to meet the ECB’s regulatory obligation to supervise and authorize the use of internal models by financial institutions in the euro area, pursuant to Articles 143, 283, and 363 of the CRR. It aims to provide a common and transparent framework for assessing the compliance of internal models with regulatory requirements, taking into account feedback from sector stakeholders and experiences from the TRIM process. The objectives are to ensure robustness, consistency, and comparability of internal models used for calculating capital requirements, while respecting recent regulatory developments. The guide is intended for ECB supervisory teams, financial institutions, and their internal auditors. It covers models related to credit risk, market risk, and counterparty credit risk, specifying general principles, governance, validation, audit requirements, as well as deployment and modification modalities. The document specifies that some parts may be updated following the final adoption of regulatory technical standards by the European Commission. The scope is limited to internal models approved for calculating capital requirements (Pillars 1) and does not cover internal models used for other purposes.

Summary of Key Points by Theme

- Governance and Responsibilities: The guide emphasizes the need for clear governance of internal models. The management body (governing body) and senior management must have defined roles, notably regarding approval of material aspects of models and regular monitoring. Dedicated committees must be mandated and chaired by a member of the management body. In-depth knowledge of models by these bodies is essential to ensure effective supervision (p. 9-27).

- Documentation and Model Register: Institutions must maintain complete and up-to-date documentation for each model, including methodology, assumptions, limitations, data, usage instructions, and validation results. A model register must list key information (owner, scope, approvals, restrictions, weaknesses, developments) and be subject to regular controls (p. 7-9).

- Model Risk Management: A model risk management framework must be established, integrating a written policy, a model register, qualitative and quantitative risk assessment methodologies, communication procedures, and clear responsibility definitions. This framework must cover the entire model lifecycle (p. 9).

- Internal Validation: The validation function must be independent from model development, with adequate resources and qualified skills. Three organizational options are envisaged depending on the institution’s size and complexity, with the most robust recommended for large entities. Validation must be performed initially and at least annually, covering detailed quantitative and qualitative analyses (p. 10-35).

- Internal Audit: Internal audit must regularly review models, be independent from operational units, have sufficient resources, and report directly to the management body. Follow-up on audit recommendations must be rigorous, with regular reports to relevant committees (p. 11-13).

- Deployment and Use of IRB Models: The guide sets a minimum threshold of 50% IRB coverage in terms of exposure at default (EAD) and risk-weighted exposure amounts (RWEA) at the consolidated level. Deployment must be documented in a plan approved by management, with a maximum horizon of five years. Plan modifications require approval from the competent authority under specific conditions. Compliance monitoring with deployment rules and permanent partial use (PPU) is required (p. 15-20).

- Reversion to Less Sophisticated Approaches: Institutions may request to revert to the standardized approach (SA) or foundation IRB approach (F-IRB) under strict conditions, including operational necessity, data availability, and no intention to reduce capital requirements. Detailed documentation and objective criteria must support these requests (p. 19-21).

- Integration of Climate and Environmental Risks: Climate and environmental risks must be assessed in the model lifecycle and integrated into internal models when these risks are material (p. 13).

- Understanding and Reporting: The management body must have a general understanding of models, while senior management must have an in-depth understanding. Reporting must be adapted to the hierarchical level, with frequency and detail proportional to model materiality. Reports must include performance, limitations, validation results, and corrective measures (p. 24-26).

- Credit Risk Control Unit (CRCU): This unit must be independent from commercial functions, clearly mandated, and responsible for the performance and maintenance of rating systems. It provides data to validation and implements corrective actions (p. 26-27).

Main Findings and Lessons Learned

- Findings: The ECB has defined a clear and detailed framework for supervising internal models, based on the CRR and European standards under adoption. Institutions must comply with precise requirements regarding governance, documentation, validation, audit, and model deployment. The minimum consolidated IRB coverage threshold is set at 50% in EAD and RWEA. Validation must be independent, regular, and rigorous, with quantitative and qualitative analyses covering performance, stability, data representativeness, overrides, and code quality. Internal audit must be independent and adequately resourced. Reporting must be adapted to recipients and enable effective model monitoring. Climate risks must be integrated if material.

- Assumptions: The guide assumes that institutions have the necessary resources and capabilities to apply these requirements. It also presumes that internal models are primarily used for calculating capital requirements (Pillars 1).

- Interpretations: The ECB considers that governance robustness and validation quality are essential to limit risks related to internal models. It recommends practices regarded as "best practice" but acknowledges that other methods may ensure compliance if equivalent. The ECB stresses the importance of transparent communication and adapted reporting for effective supervision.

- Uncertainties: Some parts of the guide may evolve following the final adoption of regulatory technical standards by the European Commission. The impact of future regulatory developments on institutions’ practices remains to be clarified. Moreover, the effective implementation of recommendations may vary depending on institutions’ size, complexity, and structure.

Conclusions and Recommendations

The guide concludes that institutions must establish robust and coherent frameworks for managing, validating, auditing, and documenting their internal models to ensure compliance with regulatory requirements and reliability of capital calculations. Responsibilities of the management body and senior management must be clearly defined and actively exercised, notably regarding policy approval, performance monitoring, and change management. IRB deployment plans must be approved, monitored, and modified under strict control, with implementation deadlines generally under three months. Internal validation must be independent, regular, and cover a comprehensive set of quantitative and qualitative analyses, with clear reporting to governance bodies. Internal audit must be independent, adequately resourced, and ensure rigorous follow-up of recommendations. Integration of climate risks into models is required when these risks are material. Finally, the guide recommends transparent communication with supervisory authorities and exhaustive documentation of models and associated processes. These measures are priorities to guarantee the soundness of internal models and the safety of the financial system. The guide foresees future updates depending on the evolution of regulatory technical standards.

Key takeaways

References

Year
2024
Type
Guide
Level
Intermediate
Licence
Attribution required, educational use
Original document
https://www.bankingsupervision.europa.eu/framework/supervisory-policy…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.