22.11.2014 Views

CP10 (Full Document) - European Banking Authority

CP10 (Full Document) - European Banking Authority

CP10 (Full Document) - European Banking Authority

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

credit risk that an institution wants to take on can be defined and<br />

controlled using a limit system, while it is difficult to set limits for<br />

operational risk (although it can be mitigated by insurance and/or<br />

internal controls).<br />

467. Article 105(1) and (2) of the CRD provides that permission to<br />

calculate operational risk capital requirement using the AMA can be<br />

given only if the competent authority is satisfied that the institution<br />

meets the qualifying criteria in Annex X, Part 3.<br />

468. In particular, with regard to internal governance matters, the<br />

following elements have to be taken into account:<br />

· Reporting: There must be a regular reporting on operational risk<br />

exposures and loss experience. The institution shall have<br />

procedures for taking appropriate corrective action. (Annex X,<br />

Part 3, Paragraph 4)<br />

· Operational risk management function: The institution must<br />

have an independent risk management function for operational<br />

risk. (Annex X, Part 3, Paragraph 3)<br />

· Internal Audit: The operational risk management processes and<br />

measurement systems shall be subject to regular reviews<br />

performed by internal and/or external auditors (Annex X, Part 3,<br />

Paragraph 6).<br />

Hierarchy of responsibility/level of decision<br />

469. Sound internal governance requires that the decision­making process<br />

be clearly stated within each institution, in terms of hierarchy and<br />

level of responsibility.<br />

· The management body (both supervisory and management<br />

function) (see paragraphs 347 to 349 for the definitions of these<br />

terms) should be responsible for approving all material aspects of<br />

the overall operational risk framework. This includes all activities<br />

aimed at identifying, assessing and/or measuring, monitoring,<br />

controlling, and mitigating operational risk.<br />

· The management body (management function) should ensure<br />

that all components of the operational risk framework, including<br />

controls and mitigation, are functioning as intended<br />

· The operational risk management function designs, develops,<br />

implements, and executes risk management and measurement<br />

processes and systems;<br />

· The Internal Audit should provide an assessment of the overall<br />

adequacy of the operational risk framework, as well as of the<br />

operational risk management function.<br />

Management body and Senior Management<br />

470. The management body (both supervisory and management function)<br />

should be responsible for approving all material aspects of the<br />

operational risk framework. This includes:<br />

Page 110 of 123

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!