2021-12-21 | NBB_2021_32

Added · Updated

EBA Guidelines on criteria for assessing exceptional cases where institutions exceed large exposure limits and on the timeframe and measures for return to compliance

The EBA establishes criteria for competent authorities to assess exceptional cases where institutions exceed large exposure limits under Article 395(1) of Regulation (EU) No 575/2013 and defines the timeframe and measures for return to compliance. Competent authorities must evaluate breaches based on frequency, predictability, and circumstances beyond the institution's control, generally allowing a maximum return-to-compliance period of three months, extendable to one year only in exceptional justified cases. Institutions exceeding limits must immediately report specific details and, if granted more than three months, submit a detailed compliance plan outlining remedial actions, capital increases, and governance improvements to ensure prompt restoration of compliance.

National Bank of Belgium logo

Belgium

National Bank of Belgium

Click to view thumbnail

1 EBA/GL/2021/09 15 September 2021 Guidelines defining the criteria for the assessment of exceptional cases in which institutions exceed the large exposure limits set out in Article 395(1) of Regulation (EU) No 575/2013 and of the timeframe and measures for return to compliance referred to in Article 396(3) of Regulation (EU) No 575/2013

2

  1. Compliance and reporting obligations Status of these Guidelines
  2. This document contains guidelines issued pursuant to Article 16 of Regulation (EU) No 1093/2010. 1 Pursuant to Article 16(3) of Regulation (EU) No 1093/2010, competent authorities and financial institutions must make every effort to comply with the guidelines.
  3. Guidelines represent the EBA’s view of appropriate supervisory practices within the European System of Financial Supervision and of how Union law should be applied in a specific area. Competent authorities as defined in Article 4(2) of Regulation (EU) No 1093/2010 to whom the guidelines apply should comply by embedding them into their supervisory practices (for example, by adapting their legal frameworks or their supervisory processes), even where guidelines are primarily directed at institutions. Reporting obligations
  4. Pursuant to Article 16(3) of Regulation (EU) No 1093/2010, competent authorities shall notify the EBA by (03.01.2022) whether they comply or intend to comply with these guidelines or, if not, the reasons for non-compliance. Competent authorities that do not respond by the deadline will be considered not to have complied with the guidelines. Notifications shall be submitted by sending the form on the EBA website to compliance@eba.europa.eu, quoting “EBA/GL/2021/09”. Notifications must be submitted by persons authorised to report on behalf of their competent authorities whether they comply with the guidelines. Any change in the status of compliance must also be reported to the EBA.
  5. Notifications will be published on the EBA website pursuant to Article 16(3) of Regulation (EU) No 1093/2010. 1 Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC (OJ L 331, 15.12.2010, p. 12).

3 2. Subject-matter, scope and definitions Subject-matter 5. In accordance with Article 396(3) of Regulation (EU) No 575/2013, these guidelines specify the criteria that competent authorities should apply when assessing the exceptional cases referred to in Article 396(1) of Regulation (EU) No 575/2013 in which a competent authority allows an institution to exceed the limits set out in Article 395(1) of Regulation (EU) No 575/2013. Furthermore, these guidelines set out the criteria that competent authorities should apply when determining an appropriate timeframe within which an institution must return to compliance with the large exposure limits set out in Article 395(1) of Regulation (EU) No 575/2013 and when establishing the measures that must be taken to ensure the prompt return to compliance with those limits. 6. In addition, these guidelines specify what additional information should be provided to the competent authority when reporting a breach of a large exposure limit in accordance with Article 396(1) of Regulation (EU) No 575/2013. Scope 7. These guidelines apply to the assessment of the exceptional cases referred to in Article 396(1) of Regulation (EU) No 575/2013 by competent authorities. They also apply to the manner in which competent authorities can determine an appropriate timeframe for the institution to return to compliance with those limits and to establish the measures that must be taken to ensure the prompt return to compliance with the limits by the institution, including the submission of a plan for prompt return to compliance. 8. These guidelines do not apply to the cases referred to in Article 395(5) of Regulation (EU) No 575/2013, provided that the institution meets the conditions set out in that provision. Addressees 9. These guidelines are addressed to competent authorities as defined in Article 4(2)(i) of Regulation (EU) No 1093/2010 and to financial institutions as defined in Article 4(1) of Regulation (EU) No 1093/2010. Definitions 10. Unless otherwise specified, terms used and defined in Regulation (EU) No 575/2013 and Directive 2013/36/EU have the same meaning in these guidelines.

4 3. Implementation Date of application 11. These guidelines apply from 1 January 2022.

5 4. Exceptional cases of breaches of large exposure limits and the timeframe and measures for return to compliance of those limits 12. Based on the information provided when reporting a breach of the limits set out in Article 395(1) of Regulation (EU) No 575/2013, and based on the information referred to in Chapter 4.2 of these guidelines and other information available to the competent authority, the competent authority shall carry out an assessment using the criteria described in Chapter 4.1 of these guidelines. 13. After the competent authority has assessed the appropriate timeframe in accordance with Chapter 4.3 of these guidelines, it shall notify the institution of the timeframe allowed to end the breach of the limit set out in Article 395(1) of Regulation (EU) No 575/2013. 4.1 Criteria for the assessment of the exceptional cases referred to in Article 396(1) of Regulation (EU) No 575/2013 14. Breaches of the limits set out in Article 395(1) of Regulation (EU) No 575/2013 shall always be considered as exceptional cases. 15. When assessing situations where an institution has exceeded the limits set out in Article 395(1) of Regulation (EU) No 575/2013, competent authorities shall in any case take into account the following aspects: a. the number of breaches and their frequency; b. the predictability of the breach; c. any circumstances beyond the control of the institution that led to the inability to prevent the breach. Number of breaches and their frequency 16. The competent authority shall assess whether the breach of the limits set out in Article 395(1) of Regulation (EU) No 575/2013 by the institution is a rare event. The assessment shall take into account any previous breaches by the institution that had the same cause, were caused by the same event, or concerned the same client or group of connected clients.

6 17. If an institution has reported a previous breach in the preceding twelve months that concerned the same client or group of connected clients as the current breach, the competent authority may decide that the event cannot be qualified as rare. If an institution has reported a previous breach in the preceding twelve months that had the same origin as the current breach, the competent authority may decide that the event cannot be qualified as rare. 18. If an institution has already reported two breaches of the large exposure limits in the preceding twelve months that concerned a different client or group of connected clients, had different causes, or were caused by different events, the competent authority may decide that a subsequent breach (or breaches) unrelated to those cannot be qualified as rare. Predictability of the breach 19. The competent authority shall assess whether the breach would have been foreseeable if the institution had applied sound and effective risk management in accordance with its obligations under Article 393 of Regulation (EU) No 575/2013 and the EBA Guidelines on internal governance.2 20. Furthermore, the competent authority shall examine whether the institution could have anticipated the breach using the available information. 21. In the case of identical or similar breaches by other institutions that can be attributed to the same cause, the competent authority may conclude that the breach was caused by an unforeseeable event. Circumstances beyond the control of the institution that made it impossible to prevent the breach 22. The competent authority shall assess whether the breach was caused by circumstances beyond the control of the institution. This may be assumed at least in the following cases: a. an unexpected and significant decrease in the institution’s own funds, including due to the consequences of major operational risks, such as external fraud, natural disasters, or pandemics, which are not related to the failure of the institution’s internal control mechanisms; b. cases where an exposure for which (full or partial) exemption was granted no longer qualifies for such an exemption due to a decision taken by a third party that could not be foreseen or prevented by the institution; c. cases where a court ruling or administrative decision leads to a changed interpretation of the applicable regulatory framework for large exposures and the institution has not had sufficient time to comply in order to prevent a breach of the limits set out in Article 395(1) of Regulation (EU) No 575/2013; d. the merger of counterparties/clients or purchases between counterparties/clients, but only in cases where the institution could not have been aware of such a merger or purchase or could not have expected it, so that it could not have prevented the breach. 23. Breaches caused by incorrect application or wrong interpretation of the regulatory framework for large exposures generally cannot be qualified as circumstances beyond the control of the institution. 24. If the competent authority concludes that the breach does not meet the criteria mentioned above, it shall in principle allow a maximum timeframe of three months for the return to compliance with the large exposure limits. 4.2 Information to be provided to the competent authority in case of a breach of the large exposure limits 25. When reporting an exposure value above the large exposure limits set out in Article 395(1) of Regulation (EU) No 575/2013 in accordance with Article 396(1) of that Regulation and to facilitate the assessment by the competent authority, the institution shall immediately provide at least the following information: a. the amount of the exceedance and the size of the breach in relation to its Tier 1 capital; b. the name of the client concerned, and, if applicable, the name of the group of connected clients concerned; c. the date of the breach; d. a description of any available collateral (even if it does not qualify for credit risk mitigation); e. a detailed explanation of the reasons for the breach; f. the remedial measures already taken or planned; and g. the time expected to be needed for a return to compliance with the large exposure limits. 26. The competent authority shall request further information and clarification if it considers that the information provided is not sufficiently detailed for a comprehensive assessment of the specific circumstances of the breach.

7 4.3 Criteria for determining an appropriate timeframe for the return to compliance of the limits set out in Article 395(1) of Regulation (EU) No 575/2013 27. After the competent authority has assessed the breach reported by the institution in accordance with Chapter 4.2 of these guidelines, it shall determine an appropriate timeframe for the return to compliance with the limits set out in Article 395(1) of Regulation (EU) No 575/2013. 28. A competent authority shall allow the institution a timeframe of up to three months to end a breach if it concludes that it is a repeated breach or if the size of the breach may have significant consequences for the financial situation of the institution. 29. If a competent authority decides to allow a timeframe of more than three months to end a breach and return to compliance with the limits set out in Article 395(1) of Regulation (EU) No 575/2013, the appropriate timeframe determined by the competent authority shall be suitable for a rapid restoration of the limits. 30. The timeframe for return to compliance shall generally not exceed one year. If justified by the specific circumstances of the breach and the measures of the compliance plan referred to in Chapter 4.4, the competent authority may exceptionally allow a timeframe of more than one year to end the breach. Such cases, however, should not be the norm. 31. In its assessment to determine the appropriate timeframe for return to compliance, the competent authority shall take into account at least the following elements: a. previous breaches by the institution; b. the timeliness with which the institution notifies the breach; c. the reason(s) for the breach; d. the systemic nature, complexity, and size of the breach; e. the possible consequences for the overall financial situation of the institution; f. the general distribution of risks in the institution’s banking portfolio across different counterparties; g. the type of client or group of connected clients and their creditworthiness; h. the measures already taken to end the breach. Previous breaches by the institution 32. The competent authority shall take into account any previous breaches by the institution and the scope of the measures taken in the relevant cases for return to compliance. In the case of repeated breaches, the competent authority shall in particular assess whether the new breach has the same cause as in previous cases. The timeliness with which the institution notifies the breach or the remedial measures for return to compliance 33. If an institution unduly delays the notification of a breach, the competent authority may consider allowing the institution a shorter timeframe for return to compliance. The reason(s) for or the repeated nature, complexity, and size of the breach 34. The competent authority shall assess the reasons for the breach as well as the current and future materiality of the possible consequences for the institution. 35. When the causes of the breach are complex, the competent authority may need additional information and shall request it. The overall financial situation of the institution 36. The competent authority shall investigate whether the compliance with the institution’s statutory capital requirements (Tier 1 common equity ratio, Tier 1 capital ratio, total capital ratio) is well above the minimum level. The general distribution of risks in the institution’s banking portfolio across different counterparties 37. The competent authority shall assess the adequacy of the institution’s risk management and its diversification approach. The type of client and its creditworthiness 38. The competent authority shall take into account the type of counterparty and its creditworthiness. It shall assess whether the statutory capital ratios might fall below the minimum due to possible default by the relevant client or group of connected clients, if available, and the resulting loss. The measures already taken to end the breach 39. The competent authority shall take into account the measures the institution has already taken, in particular given that some of those measures may ultimately facilitate a rapid return to compliance. 4.4 Measures to be taken for the prompt return to compliance by the institution of the limits set out in Article 395(1) of Regulation (EU) No 575/2013 40. If a competent authority has allowed an institution a timeframe of more than three months for return to compliance with the limits set out in Article 395(1) of Regulation (EU) No 575/2013, the institution shall submit a compliance plan for prompt return to compliance. 41. The compliance plan shall include at least the following points: a. arrangements to reduce the relevant exposure(s);

8 b. measures to increase the institution’s own funds where necessary; c. arrangements to improve internal risk management and control processes; d. necessary changes to the institution’s compliance policy; e. suitable procedures to ensure the prompt implementation of the measures; and f. a detailed schedule for the implementation of the measures, including the intended date of return to compliance. 42. The measures proposed by institutions shall include a description of any expected risks or obstacles to the effective and prompt implementation of the compliance plan. 43. The competent authority shall assess whether the measures are suitable, adequate, and feasible to ensure a prompt return to stable and constant compliance, and whether the detailed schedule is suitable and feasible. 44. If the competent authority has significant concerns about the measures, it shall notify the institution thereof immediately. 45. The institution shall immediately inform the competent authority if certain measures cannot be implemented as planned. The competent authority shall closely monitor the implementation of the measures to guarantee effective and prompt return to compliance. It shall in particular verify whether the various milestones are fully achieved. If the institution fails to achieve one or more milestones, the competent authority shall request the institution to address this failure appropriately. 46. The frequency and intensity of the competent authority’s supervision shall be appropriate and proportionate to the cause and size of the breach, its possible consequences for the institution, and the specifics of the compliance plan and measures taken for less than three months. Furthermore, it shall take into account the development of the relevant exposure(s) based on information regularly provided by the institution. The competent authority shall request additional information where necessary. 47. The competent authority shall decide and notify the institution whether it should conduct an internal or external audit of the internal control and risk management processes, the results of which shall be provided to both the institution’s management body and the competent authority. 48. The competent authority shall have a documented standard procedure with clear instructions for the steps required to verify whether institutions have notified the timely return to compliance. 49. Institutions shall ensure in accordance with the EBA Guidelines on internal governance that their management body supervises the implementation of the measures taken for the correct and timely return to compliance with the limits set out in Article 395(1) of Regulation (EU) No 575/2013.

9

10