Home › Academy › Library › Final Report on revised SREP and supervisory…
Synthesis note · Guide

Final Report on revised SREP and supervisory stress testing Guidelines

European Banking Authority (EBA) · 2026 · Guide · 290 pages · Intermediate

The final report presents revised guidelines for the supervisory review and evaluation process (SREP) to harmonize stress testing across the EU. These guidelines integrate recent regulatory changes and supervisory experiences accumulated over the past decade while aiming to simplify the existing framework. They also seek to strengthen supervisory convergence across the EU and ensure that the SREP remains fit for…

General Information

The document is the final report of the revised guidelines on common procedures and methodologies for the Supervisory Review and Evaluation Process (SREP) and prudential stress testing, published by the European Banking Authority (EBA) in June 2026. It is a 290-page guide intended for competent banking supervisory authorities in the European Union. The scope covers credit institutions and investment firms supervised under Directive 2013/36/EU, including financial, operational, governance, ESG risks, as well as third-country branches, for the application period starting 1 January 2027.

Executive Summary

The main subject concerns the update of the SREP guidelines, the core of the prudential supervision process for financial institutions in the EU, integrating recent regulatory developments and nearly ten years of practical experience. This revision aims to harmonize supervisory practices, strengthen European convergence, and integrate new aspects such as ESG factors, operational resilience, third-country branches, and the interaction between Pillar 1 and Pillar 2 capital requirements, notably the output floor. The SREP framework retains its fundamental structure, organized around institution categorization, business model analysis, governance assessment, capital risks, liquidity and funding risks, and the overall evaluation with communication and supervisory measures. The integration of ESG and operational resilience risks is transversal, avoiding the creation of separate modules. A flexible escalation framework for supervisory measures is introduced to enhance effectiveness and speed of intervention. The revised guidelines replace those of 2022 and will apply from 1 January 2027, with a translation and compliance notification period for competent authorities. They aim to ensure more targeted, proportionate, and effective supervision, while considering institution specificities and emerging risks, notably climate and geopolitical risks. Finally, they strengthen the link between SREP, stress tests, early intervention measures, resolution, and anti-money laundering and counter-terrorism financing.

Context and Objectives

The document was developed in response to significant evolution of the European regulatory framework since the last version of the SREP guidelines in 2022, notably with the 'banking package' (Directive (EU) 2024/1619 and Regulation (EU) 2024/1623), the Digital Operational Resilience Act (DORA) and the IRRBB/CSRBB package. It also responds to lessons learned from nearly ten years of SREP application, peer reviews and recent financial crises, which highlighted needs for improvement and simplification. The objective is to integrate these developments and experiences into a single, clear, harmonized and proportionate framework, while maintaining the fundamental objectives of the SREP: to comprehensively and coherently assess the risk profile, viability and sustainability of institutions, and to impose appropriate supervisory measures. The scope covers credit institutions and investment firms supervised under CRD/CRR, including third-country branches. The limits concern the exclusion of stress tests conducted directly by the EBA in cooperation with competent authorities.

Summary of Key Points by Theme

- General SREP framework: The SREP is a continuous process integrating all supervisory activities (on-site, off-site, stress tests, ICAAP/ILAAP, etc.) to assess the viability and risk profile of institutions. It includes categorization of institutions into four categories based on size, systemic importance, nature and complexity, to apply the proportionality principle in frequency and intensity of assessments (pp. 9-10, 30-32).

- Categorization and proportionality: Categories 1 to 4 correspond respectively to large institutions, medium to large institutions, small to medium, and small non-complex institutions. Categorization can be adjusted at group or individual entity level according to risk profile. An extension of assessment frequency (up to 5 years) is possible for certain low-risk stable category 4 institutions (pp. 9-11, 31-32).

- Business Model Analysis (BMA): The analysis covers current viability and medium-long term sustainability of the business model, including vulnerabilities related to ML/TF, ICT, ESG, operational resilience and geopolitical risks. Use of previous assessments is encouraged if the risk profile is stable (p. 14).

- Internal governance and controls: The assessment covers organizational structure, risk culture, remuneration management, internal control functions, risk management, ICT systems, ML/TF risk management, recovery plan governance, and capacity to promptly address deficiencies. Integration of the DORA framework and third-party risk management is a major new element (pp. 16-17).

- Capital risks: The assessment covers credit, market, operational, IRRBB and CSRBB risks, with particular attention to relevant subcategories. The approach now includes measurement of risks related to transfer pricing mechanisms in third-country groups. Integration of ESG risks into capital risks is transversal (pp. 19-21).

- SREP capital assessment: Additional capital requirements (P2R and P2R-LR) are determined to cover risks not or insufficiently covered by Pillar 1 requirements, with attention to capital quality (CET1 for P2G, Tier 1 for P2G-LR). The interaction with the output floor is clarified and operationalized (pp. 22-24).

- Liquidity and funding risks: Merger of liquidity and funding risk assessments into a single adequacy note, integrating evaluation of liquidity resources and associated controls. Specific measures may be imposed in case of deficiencies (pp. 25-26).

- Communication and supervisory measures: Introduction of a flexible escalation framework for supervisory measures, ranging from enhanced dialogue to sanctions, depending on severity and institution’s capacity to remedy deficiencies. Communication of SREP results is streamlined to enhance transparency and effectiveness (pp. 15-16, 32-33).

- Integration of ESG risks: ESG risks are integrated into all SREP elements, with initial priority on environmental risks, notably climate, and progression towards social and governance risks. Use of stress tests to assess resilience to environmental risks is encouraged (pp. 17-18).

- Operational resilience: Integrated transversally into the SREP, covering continuity of critical functions, operational, ICT, third-party risk management and business continuity, aligned with DORA and BCBS principles (p. 18).

- SREP for third-country branches: A specific framework is introduced to assess governance, business model, capitalization and liquidity of third-country branches, with frequency and intensity proportionate to their classification (pp. 18-19).

- Links with other processes: The SREP incorporates results from other supervisory activities (inspections, internal models, recovery plans, AML/CFT, etc.) and feeds these processes. The ORC from the recovery plan is an informative element for capital and liquidity assessment (pp. 19-20).

- AML/CFT: Risks related to money laundering and terrorist financing are considered in the SREP, aligned with the AML D6 package and enhanced cooperation between prudential and AML/CFT authorities (p. 20).

- Early intervention and resolution measures: The SREP serves as a basis to trigger early intervention measures and failure procedures, aligned with the BRRD directive and existing EBA guidelines (pp. 20-21).

Main Findings and Lessons Learned

- Findings: The SREP framework is maintained in its fundamental structure but enriched to integrate regulatory developments (CRD VI, CRR III, DORA) and emerging risks (ESG, operational resilience). Integration of ICT guidelines into the SREP simplifies and harmonizes digital risk assessment. The escalation framework for supervisory measures is formalized to improve responsiveness and effectiveness. The SREP for third-country branches is now formalized in a dedicated title.

- Assumptions: The gradual approach for ESG risk integration assumes progressive improvement of data and methodologies. The operational resilience assessment relies on existing frameworks without creating new obligations.

- Interpretations: The consolidation of guidelines aims to strengthen European convergence and proportionality, adapting frequency and intensity of assessments to risk profile. The transversal integration of ESG and operational risks reflects their systemic nature and the need for a holistic approach.

- Uncertainties: The precise impact of new requirements on national supervisory practices will depend on local implementation. Institutions’ capacity to adapt to new ESG and operational requirements remains to be observed. The complexity of the interaction between Pillar 1, Pillar 2 and the output floor requires ongoing vigilance.

Conclusions and Recommendations

The EBA recommends competent authorities to adopt the revised guidelines as of 1 January 2027, after official translation and compliance notification. These guidelines replace those of 2022 and now integrate ICT risk assessment within the SREP framework. They aim to strengthen convergence and effectiveness of prudential supervision in Europe, focusing on a proportionate, targeted and integrated risk approach, notably ESG and operational risks. The EBA encourages authorities to apply these guidelines flexibly, considering the risk profile of institutions, and to fully use the escalation framework for supervisory measures to ensure rapid and appropriate intervention. Transparent communication of SREP results to institutions is also emphasized as a lever for continuous improvement. Finally, integration of SREP assessments with other supervisory processes, including AML/CFT, recovery plans, and resolution measures, is essential for coherent and effective supervision.

Key takeaways

References

Year
2026
Type
Guide
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2026-06/fd5fbfa1-2efb-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.