WBS ICAAP Submission Portal 1 Overview Following consultation with credit institutions supervised by Wholesale Banks Supervision (WBS) the Central Bank of Ireland’s ICAAP Submission Portal for credit institutions (the Portal) has been updated to ensure that it remains fit for purpose. All credit institutions supervised by WBS are required to complete this document within timeframes set by their supervisor. It is the responsibility of each credit institution to design, implement and maintain the processes, methodologies and controls that underpin their ICAAPs. The Central Bank anticipates that in most organisations, the ‘building’ of the ICAAP will be conducted by persons with appropriate skills and experience in the organisation. Consistent with the Central Bank’s Corporate Governance Code and the relevant EBA standards, we expect the Boards of institutions supervised by WBS to (inter-alia) understand the parameters and key assumptions underpinning their institution’s ICAAP, to challenge their appropriateness, to suggest amendments to the framework and to instigate internal and external reviews on their behalf to ensure that the ICAAP is fit for purpose on an on-going basis. In so doing, the Board takes ownership and responsibility for the ICAAP. Institutions should note in this regard that the Portal is a communication tool that describes those processes, methodologies and controls. A completed Portal therefore does not constitute a functioning ICAAP. The ICAAP Submission Portal will form an integral part of all stages of the supervisory dialogue between your institution and the Central Bank of Ireland. Following its initial review your Examination Team will request further supporting documentation and data. Our interaction with you will assess the following in particular: The extent to which each institution’s Board and senior management have taken responsibility for the ICAAP. The extent to which the design of the ICAAP has been fully specified and documented. The extent to which the ICAAP is used to inform decision-making. 2 The extent to which the ICAAP is risk-based. The extent to which the ICAAP is reviewed. The comprehensiveness of the coverage of the ICAAP. The adequacy of measurement and assessment processes. The adequacy of your institution’s capital. 3 Contents Page 1. General and Miscellaneous 5 2. Business Profile 6 3. Governance and Integration 7 4. Risk Materiality and Appetite 11 5. Individual Risks 15 6. Stress Testing 32 7. Capital Strategy 35 8. Capital 37 9. Review Process 39 10. Future Plans 41 11. Sign-Off 42 4 1. General and Miscellaneous 1.1 Please name the licensed entity or entities to which this submission refers. 1.2 Please provide the date of the institution’s Board meeting during which this ICAAP submission was reviewed. Please enclose a copy of the relevant minute of the Board meeting. 1.3 Please provide the following details for the key contact in your institution on ICAAP related issues: Name Job Title Department Postal Address Phone Number Fax Number E-Mail 1.4 Please provide the following details for the key contacts in the regulatory authority of your parent institution (if applicable) and your subsidiaries (if applicable): Name Job Title Department Postal Address Phone Number Fax Number E-Mail 5 2. Business Profile 2.1 Please enclose a copy of your institution’s business strategy and business plan. Please state the date of the Board meeting during which it was approved and provide a copy of the minutes of the meeting. 2.2 Please provide data in the following table on all business lines of the entity: Business Line % of Overall Revenue % of in the Last Financial Revenue Overall in Year Year to Date 100% 100% the Please provide also the definition of revenue you have used to complete this question. 2.3 Please provide an assessment of your institution’s performance by business line in the last financial year and the year to date. 2.4 Please provide an assessment of your institution’s profitability in the last financial year and the year to date. 2.5 Please provide a breakdown of your institution’s funding at the most recent available date. 6 3. Governance and Integration 3.1 Board & Committees 3.1.1 Please enclose a copy of your institution’s organisation charts identifying the interface between the Board, Board sub-committees and all management committees. These charts should also provide the reporting lines of the Chief Risk Officer, the Compliance Officer, the Head of Internal Audit and key business unit/overseas branch heads. 3.1.2 Please provide the names and roles/job titles of all current members of the Board, the Board sub-committees and management committees. 3.1.3 Please provide the following information about the charters/terms of reference of your institution’s Board, Board sub-committees and management committees: Document Reference Title Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) 7 3.1.4 Please identify any changes which have been made to the composition and structure of the Board, Board sub-committees and management committees since the last submission of your institution’s ICAAP Portal. 3.1.5 Please outline how the effectiveness of the Board and its sub-committees is monitored. 3.1.6 If your institution is a subsidiary, please identify the reporting lines (if any) into the Group of (i) the Board and management sub-committees (ii) the individuals you have identified in question 3.1.2 and (iii) the Chief Risk Officer, the Compliance Officer and the Head of Internal Audit. 3.2 Design & Approval of the ICAAP 3.2.1 Please identify all functions that had a role in the design of the current ICAAP and include narrative that provides a comprehensive overview of that role. 3.2.2 Please describe how your institution’s Board satisfies itself that the scope, methodology and objectives of the current ICAAP are appropriate. In your answer, please provide evidence of the discussion and challenge of the ICAAP that took place at the relevant Board meetings. 3.2.3 Please describe the role of senior management in the design of the current ICAAP. Reference should be made in your response to (inter-alia), any training and familiarisation programmes provided to senior management. 8 3.3 Utilisation of ICAAP Results 3.3.1 Please describe how the Board and its sub-committees utilise the ICAAP results in decision making about risk. Please provide relevant examples. 3.4 Documentation 3.4.1 Please provide the following information about the document(s) approved by the Board specifying the scope, methodology and objectives of the current ICAAP: Document Reference Title Board Date of Last Date of Next Distribution Approval Review Review List Date 3.4.2 Please provide the following information about all other documentation that specifies the scope methodology and objectives of the current ICAAP: Document Reference Title Date of Date of Next Last Review Distribution List Review 9 3.4.3 Please provide the following information with respect to all reports generated by the ICAAP that are sighted by the Board. Under report description, describe the role of each report from the perspective of the Board: Report Report Produced Reference Description By Sighted By Frequency of Distribution Distribution List 10 4. Risk Materiality and Appetite 4.1 Risk Materiality 4.1.1 In the table below, please list all material risk types to which your institution is currently exposed in order of their priority with the most material being listed first: Risk 1 2 3 4 5 6 7 4.1.2 Please outline your institution’s definition of risk materiality from both a qualitative and a quantitative perspective. 4.1.3 Please describe how materiality was determined referencing key discussions and challenge at Board/Board sub-committee level since the date of the last submission of your institution’s ICAAP Portal. The role of senior management should be given particular attention in your response. 4.1.4 Please identify any changes to your definition of risk materiality since the last submission of your institution’s ICAAP Portal. 11 4.1.5 Please provide, in the table below, the following information pertaining to your institution’s documents that define risk materiality: Document Title Approval Approval Date of Date of Distribution Level Date Last Next List Review Review Reference (Board, Risk Committee etc.) 4.1.6 For each of your institution’s material risks, please provide the following information: Risk Type Definition Documented Time Policy/ Approved Date of Date of Distribu Policy/ Horizon Strategy By and Last Next tion List Strategy of Reference Date Review Review (Y/N) Strategy 4.1.7 For those risks which were deemed immaterial, please provide a reasoned analysis of how a determination of immateriality was reached. 12 4.2 Risk Appetite 4.2.1 Please provide your institution’s quantitative and qualitative definition of risk appetite. 4.2.2 Please detail your institution’s risk appetite for each of its material risks. 4.2.3 On a per risk basis, please describe how the risk appetite has changed since the last submission of your institution’s ICAAP Portal. 4.2.4 Please provide the following information about documents detailing your institution’s risk appetite: Document Reference Title Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) 4.2.5 Please describe how your institution’s Board satisfies itself that the business strategy is appropriate for the risk appetite. In your answer, please provide detail of the discussion and challenge of the matter at Board meetings that have taken place since the last submission of your institution’s ICAAP Portal. 13 4.3 Other 4.3.1 Please identify those Board members who possess specific risk management skills and experience and outline the skills and experience possessed. 4.3.2 Please provide an overview of risk/ICAAP training provided to Board members since the last submission of your institution’s ICAAP Portal. In addition please provide an overview of other supports available to independent non executive directors on risk matters. 14 5. Individual Risks 5.1 Credit Risk 5.1.1 Please identify the sources of your institution’s credit risk referring to (inter alia) portfolio risk and product type. Risk Measurement 5.1.2 Please set out clearly the processes and the methodologies currently employed to measure credit risk and the level at which it is measured (transaction, portfolio etc). 5.1.3 If processes and methodologies (ECAP models etc.) used in your institution for the measurement of credit risk are dependent upon or driven by parent/group processes and methodologies, please describe how these processes and methodologies were determined to be appropriate for your institution. 5.1.4 Please describe any substantive changes to the processes and methodologies used to measure credit risk since the last submission of your institution’s ICAAP Portal. 5.1.5 Please outline the major differences between the Pillar 1 and Pillar 2 processes and methodologies used to measure credit risk. Risk Monitoring 5.1.6 Please describe how credit risk is monitored at transaction and portfolio level referencing in particular: the key departments/units/sections involved reporting lines 15 the key reports generated including but not limited to watch lists, non performing loans, restructuring and provisioning levels all controls surrounding the monitoring process any other information you deem relevant 5.1.7 For each of the key reports identified in Question 5.1.6, please provide the following information: Report Title Circulation List Frequency of Circulation 5.1.8 Please identify the committee responsible for monitoring credit risk and enclose a copy of the terms of reference for this committee highlighting therein all references to the committee’s risk monitoring function. 5.1.9 Please describe any substantive changes to the process for monitoring credit risk since the last submission of your institution’s ICAAP Portal. Risk Management/Mitigation 5.1.10 Please describe how credit risk is managed/mitigated at transaction and portfolio level referencing in particular: The role of the Board and Board sub-committees in managing/mitigating credit risk The role of key individuals and departments in managing/mitigating credit risk 16 All relevant reports circulated to the Board, Board sub-committees and management committees Key limits (including concentration limits) The process for the reporting and resolution of limit breaches Staff training 5.1.11 For each of the key reports identified in Question 5.1.10, please provide the following: Title Circulation List Frequency of Circulation 5.1.12 Please identify the mitigants used by your institution in the management of credit risk (e.g. hedging products, securitisation, business insurance and other methods that reduce risk) and the extent and purpose of their use. 5.1.13 In those areas where risk mitigation is not determined to be necessary for this risk, please provide the rationale for this determination. 5.1.14 Please describe any substantive changes to credit risk management since the last submission of your institution’s ICAAP Portal, including but not limited to credit risk appetite and limits. 17 Procedures 5.1.15 Please provide the following data on all procedures documents underpinning the measurement, monitoring and management of credit risk: Document Title Reference Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) Board Oversight 5.1.16 Please outline how the Board satisfies itself that it has received the requisite data to carry out its oversight function in relation to credit risk. Capital 5.1.17 With reference to your response to Question 5.1.2, please provide a description of how the capital for credit risk was determined to be adequate (to include an analysis of correlation and diversification benefits and other determinants if applicable). 18 5.2 Market Risk 5.2.1 Please identify the sources of your institution’s market risk referring to (inter alia) proprietary trading, product type and customer driven exposure. Risk Measurement 5.2.2 Please set out clearly the processes and the methodologies currently employed to measure market risk and the level at which it is measured (transaction, portfolio etc). 5.2.3 If processes and methodologies (VaR models, pricing models etc.) used in your institution for the measurement of market risk are dependent upon or driven by parent/group processes and methodologies, please describe how these processes and methodologies were determined to be appropriate for your institution. 5.2.4 Please describe any substantive changes to the processes and methodologies used to measure market risk since the last submission of your institution’s ICAAP Portal. 5.2.5 Please outline the major differences between the Pillar 1 and Pillar 2 processes and methodologies used to measure market risk. Risk Monitoring 5.2.6 Please describe how market risk is monitored at transaction and portfolio level referencing in particular: the key departments/units/sections involved reporting lines the key reports generated including but not limited to independent price verification/pricing sources, mark-to-model valuation, real time pricing, real time limit utilisation, exception reports and limit breaches 19 the use of straight-through processing the accountancy treatment used in relation to instruments in the trading book the process for the reporting and resolution of limit breaches all controls surrounding the monitoring process any other information you deem relevant 5.2.7 For each of the key reports identified in Question 5.2.6, please provide the following information: Report Title Circulation List Frequency of Circulation 5.2.8 Please identify the committee responsible for monitoring market risk and enclose a copy of the terms of reference for this committee highlighting therein all references to the committee’s risk monitoring function. 5.2.9 Please describe any substantive changes to the process for monitoring market risk since the last submission of your institution’s ICAAP Portal. Risk Management/Mitigation 5.2.10 Please describe how market risk is managed/mitigated at transaction and portfolio level referencing in particular: The role of the Board and Board sub-committees in managing/mitigating market risk The role of key individuals/units in managing/mitigating market risk Structure and reporting lines of front, middle and back office functions 20 All relevant reports circulated to the Board, Board sub-committees and management committees Key limits Staff training 5.2.11 For each of the key reports identified in Question 5.2.10, please provide the following: Title Circulation List Frequency of Circulation 5.2.12 Please identify the mitigants used by your institution in the management of market risk (e.g. hedging activity and type of hedges employed, control and limit structure and other methods that reduce risk) and the extent and purpose of their use. 5.2.13 In those areas where risk mitigation is not determined to be necessary for this risk, please provide the rationale for this determination. 5.2.14 Please describe any substantive changes to market risk management since the last submission of your institution’s ICAAP Portal including but not limited to market risk appetite and limits. 21 Procedures 5.2.15 Please provide the following data on all procedures documents underpinning the measurement, monitoring and management of market risk: Document Title Reference Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) Board Oversight 5.2.16 Please demonstrate how the Board satisfies itself that it has received the requisite data to carry out its oversight function in relation to market risk. Capital 5.2.17 With reference to your response to Question 5.2.2, please provide a description of how the capital for market risk was determined to be adequate (to include an analysis of correlation and diversification benefits and other determinants if applicable). 22 5.3 Operational Risk 5.3.1 Please identify your institution’s sources and types (e.g. fraud risk) of operational risk. Risk Measurement 5.3.2 Please set out clearly the processes and the methodologies currently employed to measure operational risk and the level at which it is measured (transaction, portfolio etc). 5.3.3 If processes and methodologies (ECAP models etc.) used in your institution for the measurement of operational risk are dependent upon or driven by parent/group processes and methodologies, please describe how these processes and methodologies were determined to be appropriate for your institution. 5.3.4 Please describe any substantive changes to the processes and methodologies used to measure operational risk since the last submission of your institution’s ICAAP Portal. 5.3.5 Please outline the major differences between the Pillar 1 and Pillar 2 processes and methodologies used to measure operational risk. Risk Monitoring 5.3.6 Please describe how operational risk is monitored referencing in particular: the key departments/units/sections involved reporting lines the key reports generated including reports on operational risk incidents and the associated financial consequences including but not limited to impact on provisioning the role of the event loss database 23 all controls surrounding the monitoring process any other information you deem relevant 5.3.7 For each of the key reports identified in Question 5.3.6, please provide the following information: Report Title Circulation List Frequency of Circulation 5.3.8 Please identify the committee responsible for monitoring operational risk and enclose a copy of the terms of reference for this committee highlighting therein all references to the committee’s risk monitoring function. 5.3.9 Please describe any substantive changes to the process for monitoring operational risk since the last submission of your institution’s ICAAP Portal. Risk Management/Mitigation 5.3.10 Please describe how operational risk is managed/mitigated referencing in particular: The role of the Board and Board sub-committees in managing/mitigating operational risk The role of key individuals and departments in managing/mitigating operational risk All relevant reports circulated to the Board, Board sub-committees and management committees The parameters of the operational risk database Key limits around loss events and reporting thereof The process for the reporting and resolution of limit breaches 24 Staff training 5.3.11 For each of the key reports identified in Question 5.3.10, please provide the following: Title Circulation List Frequency of Circulation 5.3.12 Please identify the mitigants used by your institution in the management of operational risk (e.g. business insurance, disaster recovery site, BCP etc.) and the extent and purpose of their use. 5.3.13 In those areas where risk mitigation is not determined to be necessary for this risk, please provide the rationale for this determination. 5.3.14 Please describe any substantive changes to operational risk management since the most recent submission of your institution’s ICAAP Portal including but not limited to operational risk appetite and limits. 25 Procedures 5.3.15 Please provide the following data on all procedures documents underpinning the measurement, monitoring and management of operational risk: Document Title Reference Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) Board Oversight 5.3.16 Please demonstrate how the Board satisfies itself that it has received the requisite data to carry out its oversight function in relation to operational risk. Capital 5.3.17 With reference to your response to Question 5.3.2, please provide a description of how the capital for operational risk was determined to be adequate (to include an analysis of correlation and diversification benefits and other determinants if applicable). 26 Outsourcing 5.3.18 Please complete the following table with regard to your institution’s key risk, business and control activities that are outsourced to a third party or intra-group: Outsourced Provider Governed by Date of Last Date of Next Activity Service Level Review of SLA Review of Agreement (Y/N) SLA 27 5.4 Other Material Risks The following questions should be answered on an individual risk basis for all material risks to which your institution is exposed excluding credit, market and operational risk. This Section should also be completed for concentration risk to the extent that this risk has not been covered in other parts of Section 5. Please copy and complete this section for each of those risks. 5.4.1 Please identify the sources of your institution’s _______ risk. Risk Measurement 5.4.2 Please set out clearly the processes and the methodologies currently employed to measure _____ risk and the level at which it is measured (transaction, portfolio etc). 5.4.3 If processes and methodologies (ECAP models etc.) used in your institution for the measurement of ______ risk are dependent upon or driven by parent/group processes and methodologies, please describe how these processes and methodologies were determined to be appropriate for your institution. 5.4.4 Please describe any substantive changes to the processes and methodologies used to measure _____ risk since the last submission of your institution’s ICAAP Portal. Risk Monitoring 5.4.5 Please describe how _____ risk is monitored at transaction and portfolio level referencing in particular: the key departments/units/sections involved reporting lines the key reports generated 28 all controls surrounding the monitoring process any other information you deem relevant 5.4.6 For each of the key reports identified in Question 5.4.5, please provide the following information: Report Title Circulation List Frequency of Circulation 5.4.7 Please identify the committee responsible for monitoring _____ risk and enclose a copy of the terms of reference for this committee highlighting therein all references to the committee’s risk monitoring function. 5.4.8 Please describe any substantive changes to the process for monitoring _____ risk since the last submission of your institution’s ICAAP Portal. Risk Management/Mitigation 5.4.9 Please describe how _____ risk is managed/mitigated at transaction and portfolio level referencing in particular: The role of the Board and Board sub-committees in managing/mitigating ______ risk The role of key individuals/units in managing/mitigating ______ risk All relevant reports circulated to the Board, Board sub-committees and management committees Key limits The process for the reporting and resolution of limit breaches 29 Staff training 5.4.10 For each of the key reports identified in Question 5.4.9, please provide the following information: Title Circulation List Frequency of Circulation 5.4.11 Please identify the mitigants used by your institution in the management of _____ risk (e.g. hedging products, securitisation, business insurance and other methods that reduce risk) and the extent and purpose of their use. 5.4.12 In those areas where risk mitigation is not determined to be necessary for this risk, please provide the rationale for this determination. 5.4.13 Please describe any substantive changes to the process for managing/mitigating _____ risk since the most recent submission of your institution’s ICAAP Portal. 30 Procedures 5.4.14 Please provide the following data on all procedures documents underpinning the measurement, monitoring and management of _____ risk: Document Title Reference Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) Board Oversight 5.4.15 Please demonstrate how the Board satisfies itself that it has received the requisite data to carry out its oversight function in relation to _______ risk. Capital 5.4.16 With reference to your response to Question 5.4.2, please provide a description of how the capital for _____ risk was determined to be adequate (to include an analysis of correlation and diversification benefits and other determinants if applicable). 31 6. Stress Testing 6.1 Design & Approval of the Stress Testing Framework 6.1.1 Please identify all functions that had a role in the design of the current stress scenarios and include narrative that provides a comprehensive overview of that role. 6.1.2 Please describe how your institution’s Board and/or its sub-committees satisfies itself that the stress testing scenarios and methodologies used are appropriate. In your answer, please provide detail of the discussion and challenge of the scenarios and methodologies that took place at the relevant Board and/or Board sub-committee meetings since the last submission of your institution’s ICAAP Portal. 6.1.3 Please provide the following information about the document(s) approved by the Board specifying the scope, methodology and objectives of the stress testing framework: Document Reference Title Board Date of Last Date of Next Distribution Approval Review Review List Date 32 6.2 Scenarios 6.2.1 Please provide the following information about all stress tests your institution conducts on a scheduled basis: Stress Risk(s) Test Portfolio(s) Frequency Reference Stressed Stressed of Testing Frequency Parties Date Date of for with to the of Last Next Document Which Review Review Review Containing Scenario Scenario is Reviewed 6.2.2 Please describe how the stress testing framework assesses the impact of stress testing upon the following: Regulatory capital Balance sheet P&L Liquidity 33 6.3 Decision Making 6.3.1 Please provide the following information about the documents containing the results of the stress tests that are sighted by the Board and/or its sub-committees: Document Title Circulated to: Reference Frequency of Circulation 6.3.2 Please describe how the results of the stress tests are used in decision making about capital. Please provide examples. 6.3.3 Please describe how the results of the stress tests are used in other forms of decision making. Please provide examples. 6.3.4 Does your institution conduct reverse stress testing? If yes, please provide details. If no, please provide an overview of your institution’s future plans to conduct reverse stress testing. 34 7. Capital Strategy 7.1 Please provide your capital forecasts for the next three years and the detailed assumptions underlying these forecasts including but not limited to risks identified and potential new risks. 7.2 Please provide detail about the documents outlining the capital forecasts below: Document Reference Title Approval Approval Date of Date of Distribution Level Date Last Next List Review Review (Board, Risk Committee etc.) 7.3 Please set out any capital actions (i.e. increases/decreases in capital required) over the time horizon of the forecasts you have detailed in Question 7.1. 7.4 Please outline the significant changes to the capital strategy/capital plan since the last submission of your institution’s ICAAP Portal. 7.5 Please describe the role of all local and group functions and committees responsible for developing the capital/capital maintenance plan. 35 7.6 Please provide the minutes of all Board/Board sub-committee meetings at which the capital plan was discussed and/or approved since the date of the last submission of your institution’s ICAAP Portal. 7.7 Please describe the role of your parent/group in the approval process referencing in particular your parent’s/group’s support of the capital strategy. 36 8. Capital 8.1 Please state the date at which the information in this section is provided. 8.2 Please state your institution’s total own funds as at the date above. 8.3 Please provide a detailed breakdown of the constituents of your institution’s capital, including reference to all tiers and the constituents within these tiers. 8.4 Please complete the following table as per the date stated in Question 8.1 above above for all material risks to which your institution is currently exposed:1 Risk Type 8.5 Regulatory Capital Internal Capital Please complete the following table for all material risks to which your institution was exposed as at the date of the last submission of your institution’s ICAAP Portal: Risk Type 1 Regulatory Capital Internal Capital In the Regulatory Capital column, institutions should stipulate the regulatory capital for each risk as determined by regulatory capital methodologies (IRB etc.). In the Internal Capital column, institutions should stipulate the capital for each risk determined by internal methodologies (e.g. ECAP models). For some institutions, the regulatory and internal methodologies may be one and the same. 37 8.6 Does your institution hold capital that may need to be grandfathered under CRD II or CRD IV/Basel 3? If yes, please provide details. 38 9. Review Process 9.1 Since the last submission of your institution’s ICAAP Portal, please describe any and all internal and external reviews of the ICAAP that your institution has undertaken with reference in particular to their scope, objectives, methodologies and the role of all parties to the review. In preparing your response, please give due consideration in particular to ICAAP Principle 5 in the European Banking Authority’s paper entitled ‘Guidelines on the Application of the Supervisory Review Process Under Pillar 2’ (25 January 2006). 9.2 Please describe how your institution determines and maintains the independence of the reviewers. 9.3 Please complete the following table with respect to the documents presented to the Board and Board sub-committees detailing the findings of all reviews since the last submission of your institution’s ICAAP Portal: Document Ref Title Prepared By Completion Distribution List Date 9.4 Please describe the actions (if any) taken to follow up on the findings of the reviews identified in Question 9.1. Please report on the state of any outstanding items. 39 9.5 Please provide information in the table below pertaining to reviews of your institution’s operations against all the standards and guidelines of the CEBS/European Banking Authority that were conducted in the previous three years: CEBS/EBA Date of Conducted Report Sighted Circulated Guideline By Reference By To Review Please identify the Guidelines your institution determined were not relevant to its operations and provide the rationale for this determination 9.6 Please provide the following data on all internal audit reports pertaining to ICAAP produced since the last submission of your institution’s ICAAP Portal. In addition, please enclose an explanation of your audit ratings: Report Reference Title Date of Audit Number of Open Audit Rating Audit Items 40 10. Future Plans 10.1 Please describe any enhancements your institution plans to make to its ICAAP policies, processes and procedures over the next two years and the timelines for achieving the stated changes. 41 11. Sign Off I have reviewed this document in detail and I can confirm that to the best of my knowledge and belief, the data provided in it is complete and accurate. ____________________ Chief Executive Officer I have reviewed this document in detail and I can confirm that to the best of my knowledge and belief, the data describing the role of the Board and its sub-committees in the development, oversight and approval of the ICAAP is complete and accurate. ___________________ Chairman on behalf of the Board 42