After the 2008 financial crash, a consensus emerged among regulators that to understand the risks to financial systems, data was needed in greater quality and quantity. The demands on supervisors have grown rapidly and have been extended to new risk categories.  

Supervisors need a structured way to identify and assess risks so that they can allocate scarce supervisory resources. This has led to a move from a compliance-based approach to risk-based supervision

According to the Financial Services Commission of Barbados, this is a “comprehensive, formally structured system that assesses risks within the financial system, giving priority to the resolution of those risks.” 

In simple terms, it refers to a process that identifies critical risks that individual banks face as well as systemic risks in the financial system.  

The risk-based supervision process consists of two main components: identifying and understanding risks and mitigating those risks. A risk-based approach involves tailoring the supervisory response to fit the assessed risks. This approach allows supervisors to allocate finite resources to effectively mitigate the risks they have identified.  

Implemented properly, a risk-based approach is more responsive, less burdensome, and delegates more decisions to the people best-placed to make them. 

What are the types of risks involved in risk-based supervision?  

There are two types of risk; inherent risk which all financial institutions are exposed to, and quality of risk management, which may see two organisations exposed to the same level of risk respond in different ways. 

Below are examples of inherent risk

  • Operational risk: The everyday risks involved in operating and managing a business. 
  • Market risk: This relates to possible changes in stocks and share prices. 
  • Credit risk: The risk of not being paid by entities owing money to the institution. 
  • Related-Party risk: Transactions between related parties such as shareholders and supervised institutions face the risk that the interests of the institution will be subjugated to those of the shareholders. 
  • Liquidity risk: The risk that the institution will require liquid funds but not be able to access such when required to meet an obligation that is due and payable. 
  • Underwriting risk: This type of risk is specifically applicable to insurance companies. 

What does the risk-based supervision process look like?  

According to Deloitte, one of the ‘Big Four’ accountancy firms, risk-based supervision involves increased engagement between supervisors and the senior management of the bank to ensure good corporate governance, transparency and accuracy of information used for decision making. 

The risk-based supervision process involves the continuous collection of financial and non-financial data from banks so that the regulator can independently perform analysis of raw data through off-site surveillance. 

Risk-based supervision includes targeted reviews by the supervisor to evaluate the impact of systemic risks on the bank. It is designed to enable the supervisor to form an objective view on the probability of failure and impact of failure based on the existing control framework of the bank.  

Effective risk-based supervision involves increased reliance on the bank’s audit and compliance functions, and the use of capital add-ons based on the probability of failure to encourage banks to strengthen their control environment. 

What are the challenges to introducing risk-based supervision? 

There are wide-ranging challenges when it comes to introducing risk-based supervision, including data quality, scalability of regulatory reporting processes, the efficacy of risk management systems and cost of compliance. 

Supervisors need a good understanding of risks, a strong legal basis - including both mandate and powers - as well as political and organisational support. Adequate capacity and resources are also necessary to succeed in implementing a robust risk-based supervisory approach.  

The transition from a rule-based to a risk-based approach can take time. It requires a change in the supervisory culture, and investment in capacity building and training of staff, in addition to the development and implementation of a comprehensive supervisory toolkit.  

How can organisations transition to risk-based supervision? 

According to the Paris-based intergovernmental organisation Financial Action Task Force, the transition to risk-based supervision is a challenging task. In a March 2021 report, the organisation which comprises 39 member countries, recommended the following steps for a successful transition: 

  • Develop a legal framework and define the scope of the regime, listing what activities or types of entities will be regulated. Think about powers needed for the specific sector based on the risks it presents.  
  • Establish a preliminary understanding of the sector, including identifying an estimate of the entities in scope, the size of their operations, and so on. 
  • Establish supervisory authority and staff. 
  • Programme of staff training: Who should deliver it? Who should you involve? What training is available? 
  • Develop inspection procedures around obligations in legislation, international best practices. 
  • Think about the frequency and focus of inspections. 
  • Learn about your cohorts – identify inherent risks by understanding the specific threats and vulnerabilities in each sector.  
  • Think about the balance between off-site reviews and onsite inspections. Sometimes it is difficult to establish residual risks in certain cohorts without an on-site visit. 
  • Identify residual risks after applying AML/CFT measures. 
  • Undertake outreach with the sector before commencing inspections, for example, send out information booklets and templates. 
  • Think about undertaking capacity-building inspections for both the entity and the supervisor. 

If the scale of these changes seems daunting, you can choose to partner with a SupTech provider to help automate parts of the transition, lowering your overheads and headcount.   

How can automation support risk-based supervision? 

The scale and complexity of financial data reporting requirements are increasing at a pace. Automating the process removes errors, reduces manual effort and speeds up the regulatory reporting process.  

Regulators making this transition do not need to do so alone. We are trusted by regulators in more than 30 jurisdictions and can bring the expertise and experience we have gained to support your transition to risk-based supervision. Our expert team is happy to answer any questions you might have around risk-based supervision.

Contact us to find out how we can help you

Contenus similaires

  • From Vision to Execution: Operationalizing EBA Reporting Simplification

    Contenu

    From Vision to Execution: Operationalizing EBA Reporting Simplification

    The EBA's supervisory reporting simplification is a major shift towards integrated data architecture. In the final part of our EBA reporting simplification series, our experts analyze key takeaways from the recent EBA workshop on how the plan will be operationalized.

    Lire
  • EBA simplification is the first step toward integrated supervision

    Contenu

    EBA simplification is the first step toward integrated supervision

    In this Q&A, Regnology experts analyze the EBA's plan to untangle the "Regulatory Web" of fragmented reporting. They explain it is the first phase of a two-step global trend toward Integrated Supervision, moving from eliminating silos within regulatory domains to the future vision of enabling data sharing between them.

    Lire
  • EU Supervisory Reporting: Why the EBA’s simplification agenda is really a data architecture story

    Contenu

    EU Supervisory Reporting: Why the EBA’s simplification agenda is really a data architecture story

    The EBA’s simplification package is not a reduction exercise; it is a structural shift. Our new discussion paper analyzes the move from fragmented reports to an integrated data architecture.

    Lire

Contactez-nous