## 1espea2024006-print-pdf — EXECUTIVE SUMMARY (FSAP targeted review of LSIs)

## Source details

**Canonical URL:** [1espea2024006-print-pdf — EXECUTIVE SUMMARY (FSAP targeted review of LSIs)](https://www.imf.org/-/media/files/publications/cr/2024/english/1espea2024006-print-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2024/english/1espea2024006-print-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2024/english/1espea2024006-print-pdf.pdf.json)

---

### Scope and context
- Targeted review of banking regulation and supervision of Spain’s Less Significant Institutions (LSIs) as part of the 2024 Financial Sector Assessment Program (FSAP).
- Review covered:
  - (i) supervisory powers and independence of Banco de España (BdE);
  - (ii) supervisory approach and tools for LSIs;
  - (iii) oversight of LSIs’ governance and risk management;
  - (iv) regulation and supervision of LSIs’ key risks (credit risk and problem assets, related party transactions, funding and liquidity risks, interest rate risk in the banking book);
  - (v) oversight approach for LSIs’ climate-related financial risks.
- Findings and recommendations are based on the regulatory framework and supervisory practices as of end-October 2023.
- Context notes:
  - Progress since the 2017 FSAP and evolution of EU/EA frameworks, including BdE adoption of key elements of the SSM LSI supervisory methodology.
  - Risks remain from tighter global financial conditions, interest rate risk, and potential borrower repayment capacity deterioration.

### Main findings: supervisory powers, independence, and governance
- Significant progress has been made to enhance LSI regulation and supervision, but some 2017 FSAP recommendations remain unimplemented.
- BdE possesses a broad range of supervisory and corrective powers and there is no evidence of interference; however, additional safeguards are recommended to secure operational independence and reduce constraints on prudential mandate delivery.
- Specific independence-related issues and observations:
  - BdE needs more autonomy to issue prudential regulations in areas not harmonized at EU level (example area: related party transactions).
  - Explore options to give BdE flexibility to issue timely prudential requirements for emerging regulatory issues.
  - BdE decisions and sanctions can be appealed administratively before MINECO; BdE sanctions are final and enforceable only after the administrative appeal process ends, which could take "sometimes up to one year."
  - Presence of the Secretary General of the Treasury and International Financing (MINECO) on BdE’s Governing Council and the possibility of participation by the Minister of Economy, Trade and Enterprise or the Secretary of State for the Economy and Business Support (in a nonvoting capacity) are perceived as potential channels for political influence.
  - Recommendation to remove the possibility for banks to appeal BdE supervisory decisions and sanctions to MINECO and to limit the role of official political representatives on the Governing Council in supervisory decisions.

### Supervisory approach and tools
- Offsite and planning:
  - BdE’s supervisory priorities for the LSI sector for 2023 include: credit risk management, business model and sustainability, operational risk, governance, capital planning and climate risk expectations.
  - Supervisory activities determined through a supervisory framework document and an annual action plan approved by the BdE’s Executive Commission; summaries shared with the ECB.
  - New LSI classification methodology (ECB Supervisory Board, January 2021) introduces High-Impact (HI) and High-Risk (HR) LSIs; BdE maps to high priority (HP), medium priority (MP), low priority (LP).
  - SREP applied annually for all LSIs using SSM LSI SREP methodology; risk profile assessed on a score from one to four; P2R and P2G determined through SREP (P2G calibrated every other year; P2G started in 2021).
- Offsite monitoring:
  - Quarterly offsite monitoring uses four blocks of alerts: (i) BdE alert indicators; (ii) quarterly indicators used by the ECB; (iii) automatic SREP rating score values; (iv) recovery plan indicators.
  - The alert system provides multi-perspective monitoring but contains redundancies; recommendations include streamlining alerts, reducing overlap, and better integrating them into supervisory planning.
- Onsite inspections and resources:
  - BdE target maximum inspection cycle: two years for LSIs with a SREP score of four, four years for LSIs considered high supervisory priority, and five years for other LSIs.
  - Actual inspection frequency is lower than targets for some institutions due to resource constraints; examples: "few institutions have not been inspected for about six or seven years," "only one out of 18 HP LSI had been inspected 4.5 years ago."
  - Recommendations: increase frequency of targeted and thematic onsite activities (especially for medium- and high-priority/impact LSIs), rebalance inspection types, and ensure adequate forward-looking supervisory resources.
- Interaction and governance dialogue:
  - BdE holds periodic meetings with LSIs’ boards and senior management (first quarter meeting, supervisory dialogue on SREP, meetings on draft SREP decisions/capital decisions/recovery plans).
  - BdE has not periodically held separate meetings with banks’ independent directors or heads of internal control functions; recommendation to engage periodically with independent board members and heads of control functions, especially for HP LSIs.

### Regulation and oversight of key risks

- Market and sector structure (selected figures)
  - At end-2022, banks account for 67 percent of financial sector assets, at 203 percent of GDP.
  - Ten Spanish banking groups, considered SIs, account for over 90 percent of banking sector assets as of end March 2023.
  - Spanish LSIs and the Instituto de Crédito Oficial (ICO) represent 5.5 percent of the banking sector.
  - Table excerpt (Spain: Banks Operating in Spain):
    - Spanish SIs: Number of Groups 10; Percent of Assets 90.2 (2021) and 90.5 (2022)
    - Other SSM SIs via subsidiary/branch: Number of Groups 26 (2021) and 29 (2022); Percent of Assets 3.6 (both years)
    - Spanish LSIs: Number of Groups 57 (2021) and 56 (2022); Percent of Assets 5.7 (2021) and 5.5 (2022)
    - Branches of other SSM LSIs: Number of Groups 40 (2021) and 38 (2022); Percent of Assets 0.3 (both years)
    - Branches of non-EU banking groups: Number of Groups 4; Percent of Assets 0.2 (both years)
    - Total: 137 groups in both 2021 and 2022; Percent of Assets 100.0 (both years)
  - LSI business model distribution (proportions shown):
    - Retail Bank 66%
    - Diversified Lenders 8%
    - Central Savings / Cooperative Banks 6%
    - Custodian 6%
    - Investment Bank 5%
    - Asset Management 4%
    - Corporate/ Wholesale Lender 3%
    - Consumer Credit 2%
- Prudential indicators for LSIs (Table 3: Spain: LSIs’ Key Prudential Indicators)
  - Total Capital Adequacy: 20.54 / 21.03 / 21.37 (2021 / 2022 / Q2-2023)
  - Liquidity Coverage Ratio (LCR): 281.53 / 285.41 / 298.90 (2021 / 2022 / Q2-2023)
  - LTD: 67.65 / 67.26 / 68.47 (2021 / 2022 / Q2-2023)
  - Nonperforming Loans Ratio (NPL): 2.80 / 2.58 / 2.62 (2021 / 2022 / Q2-2023)
  - NPL Coverage: 45.08 / 47.16 / 47.26 (2021 / 2022 / Q2-2023)
  - ROA: 0.35 / 0.48 / 0.89 (2021 / 2022 / Q2-2023)
  - Observations: capital and liquidity levels comfortably above minimums; NPLs improved slightly; profitability increased. LSIs held about 33 percent of assets in government and other debt securities at end Q1-2023 (compared to about 17 percent for SIs).
- Corporate governance and risk management
  - Legal basis: LOSS, Royal Decree 84/2015, BdE circular 2/2016, and adopted EBA guidelines.
  - BdE reviews ICAAP/ILAAP annually; reports rated on a four-step scale; results inform P2R and P2G.
  - Thematic reviews (BdE 2020 cooperative review; ECB 2021 LSI governance review) identified weaknesses in board composition and independence of internal control functions; follow-ups in SREP 2021–2023.
  - Recommendation: continue and expand targeted/thematic onsite activities to strengthen risk culture and governance practices.
- Credit risk and problem assets
  - BdE circular 4/2017 (Annex 9) sets classification and provisioning rules; all LSIs use alternative solutions for ECL estimation.
  - LOSS (article 93.k) gives BdE power to impose sanctions for insufficient loan-loss provisions under accounting rules but does not explicitly empower BdE to require increases in provisions against specific exposures for prudential purposes.
  - Recommendation: LOSS should explicitly empower BdE to require an increase in provisions against specific assets or exposures for prudential purposes (in line with essential criterion 7 of core principle 18 of the 2012 BCPs).
  - Thematic ECB/SSM review (2020) on LSI credit underwriting found weaknesses in updating policies, pricing, proactive monitoring, and follow-up of refinanced operations; BdE issued recommendations.
- Related parties and concentration risk
  - Concentration risk reviewed within SREP and ICAAP; assessment of excessive concentration risk is limited to corporate exposures and does not explicitly include sovereign exposures.
  - Large exposures framework: CRR defines large exposure as exposure ≥ ten percent of eligible capital; large exposure limit is 25 percent of eligible capital.
  - Related-party framework deficiencies:
    - LOSS (Article 29.7) reporting requirement is narrow; BdE circular 4/2017 Rule 62(1) is an accounting/ disclosure rule and does not cover key prudential aspects (board members, senior management, conflicts of interest, arms’ length requirement).
    - No aggregate limits on related party exposures; no explicit deduction from capital nor collateralization requirement for related-party exposures.
    - Recommendation: align framework on related party transactions with 2012 BCPs—expand definition, require arms’ length terms and conflict-of-interest safeguards, and introduce a limit on aggregate related party exposures.
  - Specific recommendation: remove the BdE prior-authorization requirement for individual loans to board members and senior management and instead establish an overall robust prudential framework, including an aggregate limit.
- Liquidity and funding risk
  - LSIs subject to LCR (effective January 2018) and NSFR (effective June 2021); LSIs report LCR monthly and NSFR quarterly.
  - BdE performs FLESB liquidity stress testing; offsite review of liquidity ratios performed by BdE offsite team and Horizontal Functions Department.
  - Few onsite inspections focused on liquidity risk; inspections found material deficiencies (absence of contingency plans, outdated policies, miscalculation of regulatory ratios).
  - Recommendation: conduct periodic targeted/thematic onsite inspections focused on liquidity and funding risk management for LSIs.
- Interest Rate Risk in the Banking Book (IRRBB)
  - Framework: LOSS, Royal Decree 84/2015, EBA guidelines (including EBA/GL/2022/14).
  - BdE SREP IRRBB two-step methodology: Step 1 materiality assessment in phases (KRIs, EVE/NII assessment), Step 2 controls assessment (qualitative questionnaires); overall IRRBB score aggregates risk and control scores.
  - Inspections found deficiencies in IRRBB policies, NII projections, and implementation of limits.
  - Recommendation: increase targeted or thematic onsite inspections on IRRBB, especially for LSIs with higher exposure.
- Operational risk, IT and outsourcing
  - Regulatory basis: LOSS, Royal Decree 84/2015, EBA guidelines; COREP reports required on operational risk losses.
  - BdE requires immediate notification of significant cyber incidents; since 2023 LSI department performs offsite monitoring of IT risk with IT questionnaires and IT risk onsite division conducts IT inspections.
  - Two large service providers create outsourcing concentration; both supervised by BdE.
- Climate-related financial risks
  - BdE published supervisory expectations in October 2020 and started industry outreach and questionnaires (first in 2021, second in 2023).
  - BdE opted-in four Spanish LSIs for ECB-led thematic review and disclosure exercises; thematic review report released November 2022; disclosure exercise report April 2023.
  - BdE plans to gradually integrate climate risk assessment into SREP (including the business model score).
  - Recommendation: establish a medium-term framework to integrate climate-related financial risk oversight into routine supervisory activities and increase related resources.
- AML/CFT supervision
  - BdE cooperates with CPBCIM and Sepblac; joint risk matrix developed and in final stages of adoption.
  - BdE may carry out inspections and make recommendations but cannot issue requirements or sanctions for AML/CFT breaches; CPBCIM issues requirements and sanctions.
  - Process issues: CPBCIM joint inspection plan approval can be time-consuming and delay inspections (example: 2021 inspections started in April after the cooperation agreement).
  - Recommendations: implement the AML/CFT matrix, integrate it in supervisory planning, increase AML/CFT onsite coverage, streamline joint inspection planning, and consider granting BdE more enforcement powers related to AML/CFT weaknesses and breaches.
  - FATF follow-up: latest follow-up report December 2019; Spain upgraded on two immediate outcomes; Spain remains in regular follow-up.

### Key consolidated recommendations (selected, with priorities and timing as reported)
- BdE’s Supervisory Powers and Independence
  1) Grant the BdE legal powers to issue prudential regulations in areas not harmonized at EU level and explore options to allow the BdE the flexibility to timely issue prudential requirements for other areas that could emerge in the future — Priority: H; Timing: NT
  2) Remove the appeal powers of MINECO with respect to BdE supervisory decisions and sanctions, without prejudice to the possibility of instituting an internal administrative appeal process within the BdE — Priority: H; Timing: NT
  3) Limit the role of official political representatives in the BdE Governing Council with respect to deciding on supervisory issues and sanctions — Priority: H; Timing: NT
  4) Ensure that prudential considerations are not subordinated to other factors in deciding on mergers and acquisitions — Priority: M; Timing: I
- Supervisory Approach and Tools
  5) Review the offsite monitoring system to streamline alerts and reduce their overlap, better integrate it in supervisory planning processes, and tailor the depth/frequency of offsite activities (particularly SREP) to LSI impact and risk — Priority: H; Timing: I
  6) Increase the frequency of onsite activities and perform more targeted inspections (especially for medium and high priority LSIs) and more thematic onsite activities — Priority: H; Timing: I
  7) Engage periodically with banks’ independent board members and heads of control functions, especially for high priority LSIs — Priority: H; Timing: I
  8) Utilize the full panoply of enforcement tools, including sanctions, where appropriate — Priority: M; Timing: I
- Regulation and Oversight of Key Risks
  9) Continue monitoring and addressing LSIs’ governance and risk management weaknesses by performing more targeted / thematic onsite activities — Priority: H; Timing: I
  10) Strengthen BdE oversight and inspection activities on banks’ liquidity risk management policies and practices — Priority: H; Timing: I
  11) Align the framework on related party transactions with the BCPs in relation to definition of related parties, arms’ length and conflict of interest rules, and a limit on aggregate exposures to related parties — Priority: H; Timing: NT
  12) Remove the requirement for the BdE to authorize banks’ loans to their directors and senior management — Priority: M; Timing: NT
  13) Take into account excessive concentration risk for a broader range of exposure types, including sovereign risk concentration, when setting P2R — Priority: M; Timing: NT
  14) Ensure more focus on onsite inspection of IRRBB risk management policies and practices, through thematic or targeted onsite activities — Priority: H; Timing: I
  15) Continue monitoring and assessing climate risk through targeted and thematic work, ensure climate risk oversight becomes gradually integrated in routine supervisory processes, and increase related resources — Priority: M; Timing: NT
  16) Implement the AML/CFT matrix and integrate it in supervisory planning activities; Increase AML/CFT risk-based targeted inspection activities; and grant BdE powers to issue requirements and sanctions related to ML/TF risks — Priority: H; Timing: NT

*Source: EXECUTIVE SUMMARY and Technical Note, 1espea2024006-print-pdf (FSAP targeted review of LSIs).*

### EXECUTIVE SUMMARY __________________________________________________________________________ 6

### 1espea2024006-print-pdf - EXECUTIVE SUMMARY

### Scope and context
- Targeted review of banking regulation and supervision of Spain’s Less Significant Institutions (LSIs) as part of the 2024 Financial Sector Assessment Program (FSAP).
- Review covered: (i) supervisory powers and independence of Banco de España (BdE); (ii) supervisory approach and tools for LSIs; (iii) oversight of LSIs’ governance and risk management; (iv) regulation and supervision of LSIs’ key risks (credit risk and problem assets, related party transactions, funding and liquidity risks, interest rate risk in the banking book); and (v) oversight approach for LSIs’ climate-related financial risks.
- Findings and recommendations are based on the regulatory framework and supervisory practices as of October 2023.
- Context notes:
  - Progress since the 2017 FSAP and evolution of EU/EA frameworks, including BdE adoption of key elements of the SSM LSI supervisory methodology.
  - Risks remain from tighter global financial conditions, interest rate risk, and potential borrower repayment capacity deterioration.

### Main findings: supervisory powers, independence, and governance
- Significant progress has been made to enhance LSI regulation and supervision, but some 2017 FSAP recommendations remain unimplemented.
- BdE possesses a broad range of supervisory and corrective powers and there is no evidence of interference; however, key additional safeguards are recommended to secure operational independence and reduce constraints on prudential mandate delivery.
- Specific independence-related issues:
  - BdE needs more autonomy to issue prudential regulations in areas not harmonized at EU level (example area: related party transactions).
  - Explore options (including feasible legal changes) to give BdE flexibility to issue timely prudential requirements for emerging regulatory issues.
  - Remove the possibility for banks to appeal BdE supervisory decisions and sanctions to the Ministry of Economy, Trade and Enterprise (MINECO).
  - Limit the role of official political representatives on BdE’s Governing Council in deciding supervisory issues, decisions, and sanctions.

### Supervisory approach and tools
- BdE’s supervisory priorities focus on relevant LSI risks using thorough offsite analyses (including a framework based on four blocks of alerts) and a horizontal monitoring system.
- Opportunities to enhance effectiveness:
  - Streamline the alert-based offsite monitoring system to reduce overlap between indicators and better integrate it with supervisory planning, while avoiding loss of important supervisory information.
  - Increase targeted onsite activities for medium- and high-risk/-impact LSIs and conduct thematic onsite inspections/reviews for selected topics.
  - Implement more proportionate application of some strenuous offsite processes, notably the Supervisory Review and Evaluation Process (SREP) which is applied annually for all LSIs.
  - Ensure adequate forward-looking supervisory resources to apply enhancements and enforce requirements timely.
- Governance oversight:
  - BdE’s thematic reviews on cooperative governance and participation in ECB thematic review have advanced governance improvements.
  - Continue with targeted/thematic onsite inspections to address remaining governance and risk management weaknesses.
  - Engage periodically with banks’ independent board members and heads of control functions, especially for high priority LSIs.

### Regulation and oversight of key risks
- Credit risk and problem assets:
  - Extensive regulatory requirements and supervisory activities have been instrumental in addressing credit risk—this remains a key LSI priority.
  - Prudential framework for related party transactions needs alignment with the Basel Core Principles (BCPs) to allow a more conservative approach, including revising definition of related parties, arms’ length and conflict of interest rules, and setting limits on aggregate exposures to related parties.
  - Recommendation to remove BdE’s power requirement to authorize banks’ loans to their directors and senior management.
- Liquidity and funding risk:
  - BdE monitors capital and liquidity levels; recent inspections revealed weaknesses in LSIs’ liquidity risk management.
  - Strengthen supervisory scrutiny and inspection activities on liquidity risk management policies and practices.
- Interest Rate Risk in the Banking Book (IRRBB):
  - Monitoring exposures to IRRBB is part of offsite and horizontal analyses, but inspections found weaknesses in IRRBB management—recommend more focus via thematic or targeted onsite activities.
- Concentration risk:
  - Consider excessive concentration risk for a broader range of exposure types, including sovereign risk concentration, when setting Pillar 2 Requirements (P2R).
- Operational risk:
  - Continue addressing operational risk gaps through supervisory activities (noted in broader report sections).
- Climate-related financial risks:
  - BdE’s proactive outreach, expectations, and reviews have increased LSI awareness.
  - Continue embedding climate-related financial risks into supervisory activities and processes; increase related resources.
- AML/CFT supervision:
  - Joint BdE–Sepblac work is an opportunity to enhance risk-based oversight of ML/TF risks.
  - Develop and implement a joint risk matrix, integrate it in planning, increase onsite coverage of AML/CFT in the banking sector.
  - Consider granting BdE more powers to issue requirements and sanctions related to AML/CFT weaknesses and breaches.

### Key recommendations (from Table 1)
- BdE’s Supervisory Powers and Independence
  1) Grant the BdE legal powers to issue prudential regulations in areas not harmonized at EU level and explore options to allow the BdE the flexibility to timely issue prudential requirements for other areas that could emerge in the future — Priority: H; Timing: NT
  2) Remove the appeal powers of MINECO with respect to BdE supervisory decisions and sanctions, without prejudice to the possibility of instituting an internal administrative appeal process within the BdE — Priority: H; Timing: NT
  3) Limit the role of official political representatives in the BdE Governing Council with respect to deciding on supervisory issues and sanctions — Priority: H; Timing: NT
  4) Ensure that prudential considerations are not subordinated to other factors in deciding on mergers and acquisitions — Priority: M; Timing: I
- Supervisory Approach and Tools
  5) Review the offsite monitoring system to streamline alerts and reduce their overlap, better integrate it in supervisory planning processes, and tailor the depth/ frequency of offsite activities (particularly SREP) to LSI impact and risk — Priority: H; Timing: I
  6) Increase the frequency of onsite activities and perform more targeted inspections (especially for medium and high priority LSIs) and more thematic onsite activities — Priority: H; Timing: I
  7) Engage periodically with banks’ independent board members and heads of control functions, especially for high priority LSIs — Priority: H; Timing: I
  8) Utilize the full panoply of enforcement tools, including sanctions, where appropriate — Priority: M; Timing: I
- Regulation and Oversight of Key Risks
  9) Continue monitoring and addressing LSIs’ governance and risk management weaknesses by performing more targeted / thematic onsite activities — Priority: H; Timing: I
  10) Strengthen BdE oversight and inspection activities on banks’ liquidity risk management policies and practices — Priority: H; Timing: I
  11) Align the framework on related party transactions with the BCPs in relation to definition of related parties, arms’ length and conflict of interest rules, and a limit on aggregate exposures to related parties — Priority: H; Timing: NT
  12) Remove the requirement for the BdE to authorize banks’ loans to their directors and senior management — Priority: M; Timing: NT
  13) Take into account excessive concentration risk for a broader range of exposure types, including sovereign risk concentration, when setting P2R — Priority: M; Timing: NT
  14) Ensure more focus on onsite inspection of IRRBB risk management policies and practices, through thematic or targeted onsite activities — Priority: H; Timing: I
  15) Continue monitoring and assessing climate risk through targeted and thematic work, ensure climate risk oversight becomes gradually integrated in routine supervisory processes, and increase related resources — Priority: M; Timing: NT
  16) Implement the AML/CFT matrix and integrate it in supervisory planning activities; Increase AML/CFT risk-based targeted inspection activities; and grant BdE powers to issue requirements and sanctions related to ML/TF risks — Priority: H; Timing: NT

*Source: EXECUTIVE SUMMARY, 1espea2024006-print-pdf (FSAP targeted review of LSIs).*

### 3. In this context, the FSAP undertook a targeted review of the regulation and

### 3. In this context, the FSAP undertook a targeted review of the regulation and supervision of LSIs in Spain

### Scope and basis of the review
- Review covered:
  - (i) the supervisory powers and independence of the BdE;
  - (ii) the supervisory approach and tools for LSIs;
  - (iii) the oversight of LSIs’ governance and risk management;
  - (iv) the regulation and supervision of LSIs’ key risks, including credit risk and problem assets, related party transactions, funding and liquidity risk, and interest rate risk in the banking book (IRRBB);
  - (v) the oversight approach with respect to LSIs’ climate-related financial risks.
- The review is based on the regulatory framework and supervisory practices that were in place by end-October 2023.
- Findings guided by the 2012 Basel Core Principles for Effective Banking Supervision (BCPs) and build on the most recent assessment of the EA framework, including the 2018 EA FSAP assessment and RCAP reports by the BCBS about the EU.

### Cooperation and inputs
- BdE provided:
  - a self-assessment of compliance with the 2012 BCPs (building on the most recent EA BCP self-assessment);
  - responses to a complementary questionnaire;
  - examples of actual supervisory practices and assessments.
- ECB provided responses to a dedicated questionnaire.
- IMF team engaged with BdE, MINECO, ECB/SSM, professional organizations, and banks.

### Market structure — high-level facts and composition
- At end-2022, banks account for 67 percent of financial sector assets, at 203 percent of GDP.
- Majority of banking sector assets are directly supervised by the ECB.
- Ten Spanish banking groups, considered SIs, account for over 90 percent of banking sector assets as of end March 2023.
- Spanish LSIs and the Instituto de Crédito Oficial (ICO) represent 5.5 percent of the banking sector.
- Remaining 4 percent belong to subsidiaries and branches of foreign credit institutions.
- Table excerpt: Spain: Banks Operating in Spain
  - 2021 / 2022
  - Spanish SIs: Number of Groups 10; Percent of Assets 90.2 (2021) and 90.5 (2022)
  - Other SSM SIs via subsidiary/branch: Number of Groups 26 (2021) and 29 (2022); Percent of Assets 3.6 (both years)
  - Spanish LSIs: Number of Groups 57 (2021) and 56 (2022); Percent of Assets 5.7 (2021) and 5.5 (2022)
  - Branches of other SSM LSIs: Number of Groups 40 (2021) and 38 (2022); Percent of Assets 0.3 (both years)
  - Branches of non-EU banking groups: Number of Groups 4; Percent of Assets 0.2 (both years)
  - Total: 137 groups in both 2021 and 2022; Percent of Assets 100.0 (both years)
- Note: ICO is state-owned, attached to MINECO; does not accept retail deposits and is fully guaranteed by the state; ICO was not included in the scope of this technical note.

### LSI sector structure and business models
- There are 66 individual LSIs organized under 56 credit institutions or groups subject to a capital decision.
- Distribution: 35 credit cooperatives, 19 banks, and 2 savings banks.
- LSI cooperative sector: 42 individual institutions organized under two cooperative groups and 4 separate institutions.
- Two cooperative groups operate under two different forms of integrated models (see regulatory distinctions below).
- LSIs predominantly perform retail activities but include entities with other business models serving specific market niches.
- Figure (distribution of LSI sector by business model) proportions shown as:
  - Retail Bank 66%
  - Diversified Lenders 8%
  - Central Savings / Cooperative Banks 6%
  - Custodian 6%
  - Investment Bank 5%
  - Asset Management 4%
  - Corporate/ Wholesale Lender 3%
  - Consumer Credit 2%

### Institutional Protection Schemes (IPS) — regulatory particularities (Box 1)
- Historical context:
  - Before the GFC there were about 83 independent credit cooperatives.
  - Between 2009 and 2014 consolidation reduced the number to 63, 25 of which formed part of two IPS.
  - Following regulatory IPS launch in 2017-8, most independents joined a new regular IPS under article 113.7 CRR.
  - Current sector composition:
    - 18 cooperatives part of a reinforced IPS considered as a SI;
    - 30 LSI cooperatives part of a regular IPS;
    - 8 LSI cooperatives part of a reinforced IPS (article 10 CRR and additional provision 5 of LOSS);
    - 4 independent LSI cooperatives.
- Main regulatory particularities:
  - Regular IPS (article 113.7 CRR):
    - Financial support arrangements: Financial support agreement with immediately available funds through an ex-ante established Fund.
    - Internal oversight/governance: Internal uniform system to monitor and classify risks of all members; institutions permanently affiliated to a central body that monitors solvency and liquidity and issues instructions; central entity determines business policies and strategies.
    - Application of regulatory requirements: Requirements apply at level of each IPS member; Zero percent risk weight for credit exposures or non-deduction of holdings in own funds to other IPS members; Publication of an annual aggregate/consolidated report; Requirements applied at consolidated level of the overall IPS.
    - Deposit guarantee: IPS members’ Deposit Guarantee Scheme contributions are reduced by their contribution in ex-ante fund. Contributions are made at the consolidated level of the IPS.
    - MREL: If relevant, MREL is set at level of each IPS member. MREL are reduced by contributions to the ex-ante fund.
  - Reinforced IPS (article 10 CRR and additional provision 5 LOSS):
    - Commitments of central body and affiliated institutions are joint, and the commitments of affiliated institutions are entirely guaranteed by the central body.
    - Institutions are permanently affiliated to a central body that monitors their solvency and liquidity and issues instructions to their management.
    - Requirements are applied at the consolidated level of the IPS. MREL requirements are to be met at the consolidated level of the IPS.

### LSI prudential indicators (Table 3: Spain: LSIs’ Key Prudential Indicators)
- 2021 / 2022 / Q2-2023
  - Total Capital Adequacy: 20.54 / 21.03 / 21.37
  - Liquidity Coverage Ratio (LCR): 281.53 / 285.41 / 298.90
  - LTD: 67.65 / 67.26 / 68.47
  - Nonperforming Loans Ratio (NPL): 2.80 / 2.58 / 2.62
  - NPL Coverage: 45.08 / 47.16 / 47.26
  - ROA: 0.35 / 0.48 / 0.89
- Observations:
  - Prudential indicators of the LSI sector have strengthened in recent years.
  - On average, LSIs’ capital and liquidity levels have been comfortably above minimum requirements.
  - NPL levels have shown a slight improvement and profitability has increased.
  - LSIs have a lower loan to deposit (LTD) ratio compared to SIs, reflecting increased exposures of LSIs to government and other debt securities which accounted for about 33 percent of LSIs’ assets at the end of Q1-2023, almost double the same ratio for SIs (of around 17 percent).

### Institutional setting — supervisory responsibilities and arrangements
- Single Supervisory Mechanism (SSM):
  - ECB and NCAs of Banking Union countries form the SSM.
  - ECB, working closely with NCAs, is directly responsible for supervision of SIs.
  - LSIs are under direct supervision of NCAs while ECB exercises oversight for the functioning of the system.
  - ECB has direct responsibility over approvals (for proposals drafted by the NCA) for licensing, withdrawal of licenses, and qualifying holdings in LSIs.
  - Authorization and supervision of non-EEA bank branches and supervision of AML/CFT are responsibilities of NCAs.
  - Although ECB can take enforcement action or take over direct supervision of an LSI, in practice it has relied on NCAs and only in exceptional circumstances assisted in onsite inspections or taken over supervision (e.g., assisting in stressed situations and when NCAs were resource constrained).
- BdE responsibilities:
  - BdE is the NCA responsible for prudential supervision of Spanish LSIs and of branches of banks from third countries operating in Spain (established in law 10/2014 transposing CRD; LOSS).
  - LOSS applies to LSIs and SIs without prejudice to EU regulation.
  - BdE legal framework includes law 13/1994 (updated in 2015) on the autonomy of the BdE (LABE) and supporting regulations.
  - BdE is direct prudential supervisor of other financial institutions including specialized lending institutions, mutual guarantee societies, re-guarantee companies, appraisal companies, payments institutions, electronic money institutions, account information service providers, currency exchange bureaus, banking foundations (limited scope), ICO, and Sareb.
  - BdE supervises these institutions to ensure proper functioning considering their impact on financial stability.
  - BdE has oversight competencies in banking conduct, transparency, and consumer protection; AML/CFT oversight in cooperation with Sepblac; supervision and authorization of covered bond programs; supervision of certain provisions for securitizations; oversight of payment systems and instruments.
- BdE as accounting regulator:
  - BdE issued Circular 4/2017 (banking accounting circular) compatible with IFRS.
  - IFRS directly apply to consolidated financial statements of banking groups with listed securities and to consolidated financial statements of other banking groups that opt to apply IFRS voluntarily.
  - Circular 4/2017 directly applicable to: (i) consolidated financial statements of banks without traded securities that do not opt for IFRS; and (ii) individual financial statements of all banks.

### Cooperation, resolution, macroprudential, and AML/CFT frameworks
- Bilateral MoUs:
  - BdE signed MoUs with DGSFP in 2004 and with CNMV in 2009 (both are in process of being updated since they recently expired).
- Resolution framework:
  - Law 11/2015 transposes BRRD into Spanish law.
  - Executive resolution authority: FROB (Spanish Executive Resolution Authority).
  - BdE assigned preventive resolution function, acting independently from BdE supervisory function.
  - FROB and BdE resolution function signed a MoU in 2017; an addendum signed in November 2021 extends validity until November 2025.
  - BdE has internal regulations to formalize cooperation and information exchange between resolution and supervision functions (Internal Circular 1/2020, of February 18).
- Macroprudential Authority:
  - AMCESFI established in 2019 (Autoridad Macroprudencial Consejo de Estabilidad Financiera).
  - AMCESFI brings together representatives from MINECO, BdE, CNMV, and DGSFP.
  - Royal Decree 102/2019 sets organisation and functioning; tasks include identification, monitoring and regular analysis of systemic risk factors; can issue warnings and recommendations; can publish opinions on proposed macroprudential policy measures by sectoral authorities.
  - AMCESFI structured around a Council and a Financial Stablity Technical Committee (CTEF). Council meets at least twice per year; CTEF meets at least quarterly.
  - Key responsibilities assigned to MINECO (Chair and Secretary of the Council, Vice-chair of the CTEF) and BdE (Vice-chair of the Council, Chair and Secretary of the CTEF).
- AML/CFT institutional arrangements:
  - Commission for the Prevention of Money Laundering and Monetary Offences (CPBCIM) promotes and coordinates implementation of measures to prevent ML and resolves disciplinary proceedings for AML breaches.
  - CPBCIM chaired by the Secretary of State for Economy and Business Support; executive service is Sepblac (Spain’s FIU).
  - Law 10/2010 (April 28) is main legislation for Prevention of Money Laundering and Financing of Terrorism; Royal Decree 304/2014 develops Act 10/2010, including customer due diligence rules.
  - CPBCIM comprises over 20 key AML/CFT agencies (policy makers, FIU, law enforcement, BdE, other supervisors, customs, tax, intelligence, data protection, judiciary, etc.).
  - CPBCIM acts in plenary and through a Standing Committee (formal requests to obliged persons) and a Financial Intelligence Committee (coordinates ML/TF risk analysis).
  - CPBCIM Secretariat resides in the Secretariat General of the Treasury and International Financing.
  - CPBCIM required to meet at least twice a year.

### BdE internal structure and decision-making for supervision
- Directorate General for Banking Supervision organized into six departments:
  - Significant Institutions Departments I and II;
  - LSI and other non-SSM Institutions Department;
  - Inspection, Internal Model and AML Department;
  - Horizontal Functions Department;
  - SSM Coordination and Supervisory Strategy Department.
- LSI supervision mainly performed by LSI and other non-SSM Institutions Department comprising 62 staff for LSI supervision, with assistance from other departments.
- Supervisory decision-making:
  - Executive Commission and Governing Council (both headed by BdE Governor) hold supervisory decision-making authority.
  - Executive Commission competent to decide on authorization proceedings, issue recommendations and requirements to banks, and initiate sanction proceedings. It is chaired by the Governor and includes the Deputy Governor and two elected Governing Council members.
  - Imposition of sanctions is within competencies of the Governing Council.
  - Governing Council composition: Governor, Deputy Governor, six elected members, Secretary General of the Treasury and International Financing (MINECO), and Vice-Chair of CNMV. BdE’s Directors-General and Secretary General attend meetings in a nonvoting capacity.
  - Minister of Economy, Trade and Enterprise or Secretary of State for the Economy and Business Support may attend Governing Council meetings as participating but non-voting members when considered necessary and may submit motions; these prerogatives have not been used at least in the recent past.

*Source: 1espea2024006-print-pdf — Technical Note (FSAP country report material) — content as provided.*

### 20. While the BdE has broad supervisory powers within the limitations of the EU and EA

### 1espea2024006-print-pdf - 20. While the BdE has broad supervisory powers within the limitations of the EU and EA

### Legal empowerment and limitations
- The government, as head of the executive power, is empowered to issue regulatory rules under article 97 of the Spanish Constitution.
- Normally a law empowers the Government or a Minister to rule on a matter (by Royal Decree or Minister Order), and that legal act may expressly empower the BdE to further develop the regulation by means of a Circular.
- Direct granting of regulatory powers by law to the BdE—and not through a legal act of the Government or a Minister—is described as "rather exceptional" due to consultative bodies (such as the State Council) imposing restrictions under the Spanish constitutional and legal framework.
- Given national transposition and application of the EU prudential regulatory framework, the limitation on the BdE’s powers to set prudential requirements is mostly relevant for areas not harmonized at the EU level (examples: requirements for related party transactions).

### Areas outside BdE remit and cross-authority processes
- MINECO is responsible for authorizing mergers, carveouts and the transfer of assets and liabilities, in whole or in part, involving a bank, and for approving any other agreement with similar legal effect.
- MINECO requests a report from the BdE (and other authorities, including the “comunidades autónomas” or CC.AA.) when considering such operations; CC.AA. have certain corporate governance powers for credit cooperatives and residual savings banks (e.g., determining number of assembly meetings; starting proceedings for breaches).
- The process for considering divergent views among authorities is not clear; the report recommends ensuring prudential considerations by the BdE are not subordinated to other considerations.

### BdE’s Supervisory Independence
- LABE establishes main rules for BdE operational autonomy: BdE is an institution under public law with its own legal personality and full public and private legal capacity and shall pursue activities with autonomy from the Spanish general administration.
- BdE is not subject to general provisions on organization and functioning of the Spanish general administration but is subject to public procurement rules (Law 9/2017) insofar as they do not affect its autonomy.
- While BdE can issue supervisory measures and sanctions against banks, BdE decisions can be appealed administratively before MINECO; BdE sanctions are final and enforceable only after the administrative appeal process ends, which could take "sometimes up to one year."
- LABE (article 2) designates the "Sala de lo Contencioso-Administrativo of the Audiencia Nacional" as sole jurisdiction for appeals against BdE acts not subject to administrative appeal and against MINECO decisions on appeals filed against BdE acts; judgments of the Audiencia Nacional may be appealed (recurso de casación) before the Supreme Court.
- Note on enforceability of sanctions: Sanctions imposed are directly enforceable even if a judicial appeal has been filed against them, provided that no administrative appeal has been filed within a month against the Decision or that the MINECO has decided to reject the appeal.
- Political representation risks:
  - Presence of the Secretary General of the Treasury and International Financing on the BdE’s Governing Council could be perceived as potential government interference given the Council decides on supervisory matters including sanctions, supervisory budgets and nomination of senior supervisory staff.
  - Possibility of participation of the Minister of Economy, Trade and Enterprise or the Secretary of State for the Economy and Business Support in a nonvoting capacity could be seen as another potential interference; authorities indicated such participation has not occurred in practice in the recent past.
  - The report suggests alternative cooperation structures to promote information exchange without undermining BdE operational independence.

### Recommendations (strengthening BdE powers and independence)
- Grant the BdE the legal powers to issue prudential regulations and requirements for areas not harmonized at the EU level (example cited: related parties) and explore potential solutions to ensure timely BdE power to issue prudential requirements for future regulatory issues.
- Remove the appeal powers of MINECO with respect to BdE supervisory decisions and sanctions, without prejudice to the possibility of instituting an internal administrative appeal process within the BdE.
- Ensure prudential considerations are not subordinated to other factors in decisions on mergers and acquisitions.
- Limit the role of official political representatives in the BdE Governing Council with respect to deciding on supervisory issues, sanctions, budget, and nomination of senior supervisory staff.

### Supervisory approach and tools — priorities and planning
- BdE supervisory priorities for the LSI sector for 2023 include: credit risk management, business model and sustainability, operational risk, governance, capital planning and climate risk expectations. Priorities for 2022 and 2021 were mostly similar to those set for 2023.
- Supervisory activities for LSIs are determined based on an annual action plan:
  - BdE prepares a supervisory framework document outlining main risks and supervisory strategy for each LSI or LSI group.
  - An annual action plan determines offsite analysis and inspection tasks for each LSI during the year.
  - Both documents are approved by the BdE’s Executive Commission; summaries are shared with the ECB.

### LSI classification and SREP
- New LSI classification methodology approved by the ECB Supervisory Board in January 2021 introduces categories of High-Impact (HI) LSIs and High-Risk (HR) LSIs using separate impact and risk criteria; first application effective as of January 2022.
- BdE tailors classification into high priority (HP), medium priority (MP), and low priority (LP); HI and HR LSIs are included in BdE’s HP list, plus other LSIs selected by indicators (size, profitability, credit risk).
- Supervisory Review and Evaluation Process (SREP):
  - SREP is a key BdE offsite tool based on the SSM LSI SREP methodology.
  - Risk profile assessed on a score from one to four.
  - SREP determines required Pillar 2 capital surcharge (P2R) and recommended additional capital surplus (P2G).
  - BdE performs SREP annually for all LSIs or LSI groups; P2G component is calibrated every other year (P2G started being applied in 2021).
  - Recommendation: consider further proportionality in offsite processes, particularly the annual application of SREP to all LSIs.

### Offsite monitoring, alerts, and thematic analysis
- Quarterly offsite monitoring uses four blocks of alerts:
  - a system of alert indicators developed by the BdE to detect weaknesses;
  - quarterly indicators of financial deterioration used by the ECB as part of their notification system;
  - quarterly values of the automatic SREP rating score;
  - values of indicators and thresholds in each LSI’s recovery plan.
- Quantitative alerts (including regulatory ratios) are grouped into areas that accumulate penalty scores to determine risk; qualitative alerts carry no penalty score but inform residual risk assessment.
- The alert system provides comprehensive multi-perspective monitoring but may contain redundancies (some alerts refer to the same risk/indicator), potentially distorting comparative risk profiles across institutions.
- Recommendations for offsite system:
  - Streamline alert system to remove redundancies while preserving important supervisory information.
  - Better integrate the offsite alert system into supervisory planning and use it as an input to plan supervisory activities, including onsite inspections, especially as BdE plans more proportionality in annual SREP.
- Thematic reviews and horizontal analysis:
  - BdE has conducted thematic reviews on governance and business model; ongoing reviews include IT questionnaire, outsourcing, and climate risk questionnaire.
  - Reviews covered C&E risk assessment, business model analysis, IT, outsourcing, cyber incident notification, IT risk, and governance in credit cooperative LSIs.
  - Reviews informed SREP score adjustments and recommendations; some leveraged ECB-led reviews.

### Interaction with LSIs and governance dialogue
- BdE holds periodic meetings with LSIs’ boards and senior management:
  - First quarter meeting dedicated to discussing closing financial statements for the previous year.
  - "Supervisory dialogue" meeting to discuss results of the annual SREP.
  - Additional meetings for draft SREP decisions, capital decision letters, and recovery plan assessments.
- BdE has not periodically held separate meetings with banks’ independent directors or heads of internal control functions in recent years.

### Onsite inspection — frequency, types, and resource constraints
- Onsite inspections:
  - BdE target maximum inspection cycle: two years for LSIs with a SREP score of four, four years for LSIs considered high supervisory priority, and five years for other LSIs.
  - Actual inspection frequency for some institutions is lower than targets; BdE attributes this to lack of available resources. Example: "few institutions have not been inspected for about six or seven years," and "only one out of 18 HP LSI had been inspected 4.5 years ago."
  - Inspections are typically general inspections focusing on selected topics; outcomes: letter of findings followed by letter of requirements or recommendations approved by the BdE’s Executive Commission.
- Types of inspections: general, partial, and thematic; most performed are general with focus on selected issues.
- Recommendations to improve onsite approach:
  - Rebalance mix of inspection types and increase risk-based aspects.
  - Prioritize targeted inspections for MP and HP LSIs, particularly those of high impact or high risk, to allow more frequent and relevant inspections.
  - Conduct periodic thematic onsite activities across LSIs (e.g., governance and risk management).
  - Ensure BdE has adequate resources, on a forward-looking basis, to implement supervisory enhancements including onsite activities.

*Source: 1espea2024006-print-pdf - 20. While the BdE has broad supervisory powers within the limitations of the EU and EA*

### 38. The ECB performs a risk-based oversight of LSIs mostly relying on information and

### 1espea2024006-print-pdf - 38. The ECB performs a risk-based oversight of LSIs mostly relying on information and

### ECB oversight of LSIs
- The ECB performs a risk-based oversight of LSIs mostly relying on information and views exchanged with the NCAs.
- Information and inputs to the ECB include:
  - Views on individual supervisory cases through notifications of financial deterioration cases.
  - For HR/HI LSIs, notifications of NCAs’ material supervisory procedures and draft decisions.
- The ECB also:
  - Performs thematic reviews, mostly offsite, to identify different practices and promote high supervisory standards.
  - Conducts oversight via interactions between the country desk and the NCA, senior management visits, and bilateral technical calls or visits.

### B. Corrective Action Powers and Processes
- Legal basis and scope
  - LOSS (Article 68) allows the BdE to require credit institutions or consolidated groups to immediately adopt necessary measures when they do not meet requirements on solvency, liquidity, organizational structure, or internal risk control.
  - LOSS permits action when BdE has well-founded grounds to believe the institution will not comply with requirements over the next 12 months.
  - BdE can apply measures if an institution’s own funds or liquidity do not guarantee sound risk management and cover.

- Range of corrective powers (Article 68 of LOSS)
  - Holding capital or liquidity in excess over minimum requirements.
  - Reinforcing processes, mechanisms and strategies.
  - Requiring a plan to restore compliance or application of a specific provisioning policy.
  - Limiting the business, operations, and network of institutions or imposing a reduction in risks of particular activities or products.
  - Limiting variable remuneration or dividend distributions.
  - Increasing disclosures.
  - Additional LOSS measures relevant to particular risk areas.
  - Power to intervene and replace the management body of an institution while giving a reasoned account to MINECO and the FROB.

- Triggers and indicators for corrective action
  - Breaching P2G recommendations or some recovery indicators can be a basis for corrective measures.
  - For early intervention cases, BdE uses two blocks of triggers:
    - SREP score: institutions with an overall SREP score 4, or overall score of 3 with one of the subcomponents scored 4 (mainly governance, business model, capital adequacy and liquidity).
    - Indicators of financial deterioration as determined by reporting to the ECB.

- Sanctions framework (LOSS)
  - LOSS provides powers to apply administrative penalties to credit institutions, their directors and executives, and natural and legal persons with a qualifying holding.
  - Infringements classified into three categories: very serious, serious, and minor; LOSS defines situations for each category and indicates penalties.
  - Criteria for categorization include nature and scale of the infringement, degree of responsibility, gravity and duration, and systemic consequences.
  - Frequency of applying sanctions in prudential matters has been rather low in recent years.
  - Recommendation: Where appropriate, the BdE should not hesitate to use the full range of enforcement tools, including sanctions.

- Decision-making and appeals
  - BdE Executive Commission can formulate recommendations and requirements, agree to initiate sanctioning procedures and intervention measures, replace directors and take other precautionary measures.
  - Final decision on imposing a sanction is taken by the BdE’s Governing Council.
  - BdE decisions, measures, and sanctions can be appealed before MINECO and then before judicial courts.
  - In practice, MINECO has not overturned any of the BdE’s decisions or sanctions in the recent past.

### C. Recommendations (Enhancing risk-based supervision of LSIs)
- Review the offsite monitoring and alert system to:
  - Streamline the various blocks of used alerts.
  - Ensure overlap between indicators does not distort offsite analysis or supervisory attention, while not missing important supervisory information.
- Better integrate the offsite alert system into supervisory prioritization and planning processes, including onsite inspection planning.
- Apply more proportionality to tailor the depth and frequency of offsite activities (particularly the SREP process) to the various priorities of LSIs to improve efficiency.
- Increase onsite inspection activities to better align with the frequency set in internal guidelines and practices.
  - Reinforce the risk-based nature of onsite inspections by performing more targeted inspections, especially for medium and large sized LSIs, and thematic onsite activities.
- Engage periodically with banks’ independent board members and heads of control functions, especially for HP LSIs.
- Utilize the full panoply of enforcement tools, including sanctions, where appropriate.

### Regulation and oversight of key risks

#### A. Corporate Governance and Risk Management
- Framework and proportionality
  - Corporate governance and risk management requirements are based on LOSS, Royal Decree 84/2015 and BdE circular 2/2016, transposing Directive 2013/36/EU (CRD).
  - Requirements cover board functions and composition, board committees, fit and proper criteria, and the risk management function.
  - Banks with individual assets less than EUR 10 billion may have joint audit and risk committees and joint nomination and remuneration committees.
  - Credit cooperatives governed by law 27/1999; saving banks by law 26/2013.
  - BdE has adopted some EBA guidelines related to governance.

- ICAAP/ILAAP and SREP integration
  - BdE reviews ICAAPs and ILAAPs annually, guided by BdE’s ICAAP and ILAAP guidelines.
  - Reports are rated on a four-step scale from non-compliance to good.
  - Results inform assignment of P2R and P2G for LSIs and are discussed in SREP supervisory dialogue.

- Offsite and onsite assessment
  - Governance and risk management assessed via yearly meetings with LSIs’ boards/management and document reviews.
  - Onsite inspections provide additional assessment inputs and feed into SREP scoring.
  - SREP can result in requirements and recommendations via capital decision letters or post-inspection letters.

- Thematic reviews and follow-ups
  - BdE offsite thematic review of corporate governance of all credit cooperatives in 2020.
  - ECB thematic review in 2021 on LSI governance arrangements included several Spanish LSIs.
  - BdE review revealed weaknesses in board composition/functioning and independence of internal control functions.
  - Findings followed up in SREP 2021 and 2022; remaining findings followed for 2023 SREP measures.
  - Measures focus on ensuring adequate number of independent directors on cooperative boards and independence of second and third lines of defense.

- Recommendation
  - Continue and expand targeted or thematic onsite activities to strengthen risk culture and assess governance practices.

#### B. Capital
- Legal and regulatory basis
  - Capital requirements follow the EU Capital Requirement Regulation (CRR).
  - Buffers and Pillar 2 add-ons transposed into national law via LOSS, Royal Decree 84/2015 and BdE circular 2/2016.
  - Buffers include: capital conservation buffer, counter-cyclical buffer (CCyB), buffers for global and other systemically important institutions, and systemic risk buffer.
  - CCyB is set at zero percent (end-2023).

- Deviations from Basel III
  - 2014 BCBS RCAP assessed the EU capital framework as materially non-compliant with Basel minimum capital standards.
  - Main divergences include permanent partial use of exemptions in IRB approach; concessionary risk weights for small and medium enterprise exposures; splitting of residential mortgage loans into lending qualifying for 35 percent risk weight and lending not qualifying; CVA exemptions.
  - Many deviations may not be material for Spanish LSIs given business models and IRB usage (IRB applied by only one LSI in Spain so far).

- P2R and P2G assessment
  - SREP methodology considers factors including business model, IRRBB risk, governance, and concentration.
  - P2R surcharges based on ECB methodology for each SREP category.
  - BdE conducts annual stress test using the forward-looking exercise on Spanish banks (FLESB) tool to assess solvency under different macroeconomic scenarios.
  - P2G is assessed every other year based on BdE stress test results.

#### C. Credit Risk and Problem Assets
- Requirements and guidance
  - Credit risk management rules stem from general rules, Royal Decree 84/2015, and Annex 9 of BdE circular 4/2017.
  - BdE indicates compliance with EBA guidelines on loan origination and monitoring and on management of non-performing and forborne exposures.

- Treatment of problem assets (BdE circular 4/2017, Annex 9)
  - Distinguishes performing exposures, performing exposures under special monitoring, nonperforming exposures and total write-offs.
  - Specifies quantification and coverage of individual and collective credit-risk loss estimates.
  - Requires policies to reclassify and provision transactions as soon as abnormal situations or deterioration become apparent.
  - High NPL banks required to establish an annual NPL reduction strategy, followed up by BdE offsite monitoring.

- Expected credit losses (ECL)
  - BdE circular 4/2017 provides alternative solutions for entities without internal ECL models and establishes minimum provisioning requirements at each loan classification stage.
  - All LSIs use those alternative solutions for ECL estimation.
  - LOSS (article 93.k) gives BdE power to impose sanctions for insufficient loan-loss provisions under accounting rules.
  - In practice, BdE has required LSIs to increase provisions during onsite inspections or credit risk reviews per Circular 4-2017 provisions.
  - Prudential limitation: LOSS provides mandate to require application of a specific provisioning policy but does not explicitly empower BdE to require an increase in provisions against specific exposures for prudential purposes.
  - Recommendation: LOSS should explicitly empower the BdE to require an increase in provisions against specific assets or exposures for prudential purposes (in line with essential criterion 7 of core principle 18 of the 2012 BCPs).

- Onsite inspection focus
  - BdE inspectors review loan origination policies/processes, credit risk-related documents, sample loan files for accounting treatment soundness, and audit/internal control reports.

- Thematic reviews
  - 2020 ECB/SSM thematic review on LSI credit underwriting standards included several Spanish LSIs with high investment growth.
  - Identified weaknesses: updating risk management policies/manuals, pricing of operations, proactive credit monitoring, and identification/follow-up of refinanced operations.
  - BdE issued recommendations and requirements to address gaps.

#### D. Related Parties and Concentration Risk
- Concentration risk
  - BdE reviews concentration risk mainly within SREP.
  - Requirements for concentration risk management are in Royal Decree 84/2015 and CBE circular 2/2016; require written policies and procedures.
  - Geographical and sectoral concentration considered in credit risk and business model assessments.
  - Concentration risk considered in ICAAP and in determining P2R.
  - Assessment of excessive concentration risk is limited to corporate exposures and does not explicitly include concentration to sovereign exposures.

- Large exposures framework
  - Based on CRR: exposure to client/group considered large where value equals or exceeds ten percent of eligible capital.
  - Large exposure limit to a client/group is 25 percent of eligible capital.
  - CRR defines economic or control relationships for connected counterparties.
  - BdE supervisors review compliance as part of regular offsite monitoring.
  - BCBS RCAP: EU framework largely compliant with Basel large exposure standards; material finding relates to trading book exposures where EU allows limit to be exceeded up to 600 percent of a bank’s Tier 1 capital—less relevant for Spanish LSIs due to negligible trading book exposure.

- Related party transactions framework deficiencies
  - LOSS (Article 29.7) requires reporting of loans to board members and their related parties to the BdE; if interpreted as a definition, it is extremely narrow compared to 2012 BCPs.
  - Rule 62(1) of BdE circular 4/2017 provides a more detailed related-party definition but is an accounting circular aimed at disclosure; it does not include board members, senior management, and their interests.
  - Laws/regulations do not explicitly include key prudential aspects from 2012 BCPs, including:
    - Requirement that related party transactions not be undertaken on more favorable terms than corresponding exposures to non-related counterparties.
    - Prior board approval for transactions/write-offs exceeding specified amounts or posing special risks.
    - Exclusion of conflicted board members from approval processes.
  - BdE has adopted some EBA guidelines on conflicts of interest and arms’ length transactions, but these are not binding requirements, which may hinder enforcement.
  - No aggregate limits on related party exposures, nor a requirement to deduct such exposures from capital or collateralize them when assessing capital adequacy.

*Source: IMF staff report content provided in the supplied PDF excerpt.*

### 62. The BdE is assigned with the responsibility to authorize banks’ requests to grant

### The BdE is assigned with the responsibility to authorize banks’ requests to grant facilities to their board members and managers

### Authorization of related‑party loans to board members and managers
- LOSS (Article 26.5) does not allow banks to grant loans to their board members and senior managers above a limit determined by the regulation unless they have obtained a prior authorization by the BdE.
- Article 35 of Royal Decree 84/2015 sets the regime applicable for authorization of these loans and exceptions whereby credit institutions must apply to the BdE for authorization to grant loans and guarantees to members of boards of directors and managing directors and similar officers.
- Exception: such authorization is not needed for loans covered by collective labor agreements, granted in mass levels under contracts with standardized conditions provided that the loan does not exceed EUR 200 thousand.
- Perception and risk:
  - The authorization process gives the perception that the BdE is approving such loans and is responsible for their risks, which may pose reputational risk for the BdE.
  - While the aggregate amount of these loans may be small relative to banking sector assets, the authorization process does not fit with the BdE’s prudential and financial stability mandate.
- Recommendation:
  - Remove the BdE prior‑authorization requirement for individual related‑party loans to board members and managers and instead establish an overall robust prudential framework for related parties (including a limit on aggregate related party exposures) to limit transaction risks and reduce reputational risks for the BdE.

### Liquidity and funding risk (LSIs)
- Regulatory coverage and implementation:
  - LSIs in Spain are subject to the Liquidity Coverage Ratio (LCR) and the Net Stable Funding Ratio (NSFR) as applied in the EU legislation.
  - The LCR requirement came into force starting January 2018 and the regulation incorporating NSFR entered into force in June 2021.
  - LSIs report their LCR on a monthly basis and their NSFR on a quarterly basis.
- External assessments:
  - The 2017 BCBS RCAP assessment of LCR regulations in the EU concluded the framework is overall largely compliant with the Basel LCR standard; it identified one material deviation and four potentially material deviations.
  - The 2022 BCBS RCAP assessment of EU NSFR regulations assessed those regulations as largely compliant with the Basel NSFR standard; the main driver relates to the treatment of required stable funding which included nine not material findings.
- National framework and supervisory practice:
  - LOSS, Royal Decree 84/2015, and BdE circular 2/2016 detail liquidity risk management, require liquidity risk mitigation tools and contingency plans that must be tested at least once a year.
  - EU regulations add monitoring metrics including the maturity ladder, concentration of funding by counterparty, and concentration of funding by product type.
  - The BdE offsite supervisory team reviews LSIs’ liquidity ratios and aspects of liquidity and funding risk management as part of SREP; the Horizontal Functions Department performs additional sensitivity and scenario analysis.
  - The BdE conducts liquidity stress test exercises under its FLESB framework projecting LCR levels under baseline and adverse scenarios.
- Findings and gaps:
  - Few onsite inspections have focused on liquidity risk management; instances found material deficiencies including lack of a liquidity contingency plan, failure to update internal policies, and miscalculation of regulatory liquidity ratios.
  - The BdE has not planned or performed specific targeted or thematic onsite inspections focused on liquidity and funding risk management of LSIs.
- Recommendation:
  - Conduct periodic targeted or thematic onsite inspections focused on liquidity and funding risk management of LSIs to identify and remediate weaknesses more systematically.

### Interest Rate Risk in the Banking Book (IRRBB)
- Legal and guidance framework:
  - Main requirements are in LOSS, Royal Decree 84/2015 and the EBA guidelines adopted by the BdE (including EBA/GL/2022/14).
  - LOSS requires the BdE to implement prudential measures when, under supervisory shock scenarios, the institution net worth declines by more than 15 percent of Tier 1 capital or when net interest income declines significantly due to a sudden and unexpected change in interest rates.
- Supervisory methodology:
  - BdE supervisors assess IRRBB within the annual SREP via a two‑step process:
    - Step 1 — determination of IRRBB risk level in phases:
      - Phase 1: materiality assessment based on key risk indicators (KRIs).
      - Phase 2: if material, assess economic value perspective and earnings perspective using KRIs.
      - Phase 3: complement Phase 2 with additional aspects of EVE and earnings, leveraging a wider set of indicators.
    - Step 2 — assessment of controls (qualitative questionnaires).
    - Overall IRRBB risk score is the aggregation of risk level score and risk control score per the methodology matrix.
  - The BdE Horizontal Functions Department performs horizontal analysis of IRRBB exposures for SIs and LSIs, including annual monitoring of EVE and NII for LSIs.
- Findings and gaps:
  - A few inspections included IRRBB and found deficiencies: lack of policies for identification/measurement/management/monitoring/control, inappropriate implementation of regulatory requirements for NII projections, and lack of implementation of IRRBB limits in terms of NII.
- Recommendation:
  - Increase targeted onsite inspections or thematic onsite activities to obtain a comprehensive view of IRRBB risk management across LSIs, particularly those with higher exposure.

### Operational risk (including IT and outsourcing)
- Regulatory framework:
  - Operational risk requirements derive from LOSS, Royal Decree 84/2015, and adopted EBA guidelines on SREP and internal governance.
  - Royal Decree 84/2015 sets general conditions for outsourcing arrangements and specific conditions for outsourcing or delegation of essential functions.
  - COREP requirements include regular reports on operational risk losses by business lines and event type.
  - BdE requires immediate notification of any significant cyber incidents.
- Supervisory structure and activities:
  - Supervision performed by offsite, onsite, and horizontal teams; operational risk is mainly reviewed within SREP.
  - Since 2023, the LSI department performs offsite monitoring of IT risk where material, using IT questionnaires challenged by BdE IT experts.
  - IT risk onsite division conducts IT risk onsite inspections for LSIs; findings feed into SREP offsite assessments.
  - The BdE established committees and coordination structures to promote consistency in IT risk assessment.
- Outsourcing concentration:
  - Reviewing LSIs’ outsourcing arrangements is a significant part of BdE IT teams’ work.
  - Two large service providers supply material or important services to many LSIs, creating significant concentration in IT risks; both providers are supervised by the BdE (one as a financial institution under BdE remit and the other as part of a financial group supervised by the BdE).
  - The BdE has supervised these providers including through onsite inspections focusing on IT risk.

### Climate‑related financial risks
- BdE actions and governance:
  - In October 2020 the BdE published supervisory expectations relating to risks posed by “climate change and environmental degradation”.
  - The BdE announced it would start analyzing institutions’ implementation progress 18 months after issuing those expectations.
  - The BdE established a high‑level Coordination Group and a horizontal working group; it has a small team to coordinate actions on climate‑related risks for LSIs and an internal supervision network for knowledge sharing.
- Outreach and assessment exercises:
  - Since 2019 the BdE organizes an annual outreach with the industry on climate‑related financial risks.
  - In 2021 the BdE launched a first questionnaire to assess LSIs’ plans for alignment with supervisory expectations; LSIs were at very early stages then.
  - A second questionnaire was launched in 2023; the BdE is performing a deep analysis of submissions and including the assessment in the 2023 SREP and supervisory dialogue.
  - The BdE opted-in four Spanish LSIs to participate in ECB‑led thematic review and disclosure exercises; thematic review report publicly released November 2022 and disclosure exercise report in April 2023.
- Recommendation and implementation planning:
  - The BdE plans to gradually include assessment of LSIs’ management of climate‑related financial risks in SREP (including incorporation in the business model score component).
  - Recommendation: establish a medium‑term framework to integrate climate‑related financial risk oversight into routine supervisory offsite and onsite activities and SREP.
  - Note: this integration may have short to medium term implications for BdE resources until expertise is transferred across supervisory teams.

### AML/CFT supervision
- Cooperation and mandates:
  - CPBCIM and the BdE have been actively collaborating on AML/CFT oversight; latest agreement signed in March 2021.
  - The BdE cooperates with the CPBCIM and Sepblac in supervision of AML/CFT obligations, and authorities have agreements to draft joint inspection plans and exchange supervisory information.
  - The BdE may carry out inspections and supervisory actions to ensure compliance with certain AML/CFT obligations (e.g., due diligence, internal control and reporting) focusing on review of policies and procedures; the BdE may make recommendations, but requirements and sanctions can only be decided by the CPBCIM.
- Methodology and tools:
  - A common risk matrix has been developed jointly between Sepblac and the BdE and is in final stages of adoption.
  - Key components of the risk matrix:
    - (i) inherent risk assessed via four factors—customer profiles, geographies, products, distribution channels;
    - (ii) assessment of AML/CFT controls using automated indicators, governance evaluation based on inspection findings and external expert reports, meetings with supervised entities, and information from other authorities;
    - (iii) final risk profile combining inherent risks and controls.
  - Residual risk rating categories: low, medium-low, medium-high, and high.
  - The BdE developed a supervisory manual in 2022 outlining principles and processes for inspections.

*Source: https://www.imf.org/-/media/files/publications/cr/2024/english/1espea2024006-print-pdf.pdf*

### 80. While the BdE has performed a number of general and thematic inspections during

### 1espea2024006-print-pdf - 80. While the BdE has performed a number of general and thematic inspections during

### Inspection coverage and planning
- During the period 2020-22, BdE’s inspection activities (for both SIs and LSIs) included:
  - general inspections at eight institutions,
  - two targeted inspections on internal control,
  - a thematic inspection on currency exchange activities covering 15 institutions.
- Finding: A more frequent inspection coverage seems warranted to ensure broader and timelier coverage of supervised entities.
- Recommendation: Increase inspection activities, at least partially by conducting more risk-based inspection activities using the new common risk matrix as the basis for planning supervisory activities.
- Process issue: The process for approving the joint inspection plan at the CPBCIM level appears time-consuming and can delay the start of inspection activities. Example: inspections during 2021 did not start until April following the signing of the new cooperation agreement with the CPBCIM.

### Enforcement powers for AML/CFT
- Finding: The BdE does not have the powers to issue requirements and sanctions to prevent and address weaknesses in banks’ AML/CFT frameworks or breaches to AML/CFT laws and regulations.
  - BdE AML inspections revealed several findings regarding deficiencies in banks’ AML/CFT frameworks.
  - Based on law 10/2014 and the agreement signed between the BdE and the CPBCIM, the BdE has no enforcement powers in relation to AML/CFT obligations which can only be decided by the CPBCIM.
  - The BdE can issue recommendations for improvement to banks, but it is up to the CPBCIM to issue requirements and sanctions to address deficiencies.
  - The CPBCIM meets two to three times a year.
- Implication: This enforcement process constrains the BdE’s ability to timely address deficiencies in its role as the AML/CFT supervisor for banks.
- Recommendation: Consideration could be made to grant the BdE more enforcement powers in relation to AML/CFT deficiencies and breaches. Having such powers would also align the BdE further with the core principle 29 of the 2012 BCPs which requires, among others, that the supervisor has adequate powers to take action against a bank that does not comply with its obligations relevant to laws and regulation regarding criminal activities.

### FATF follow-up assessment
- The latest FATF follow-up report on Spain was published in December 2019 and was the fifth follow-up report following the mutual evaluation report adopted in October 2014.
- Findings:
  - Spain has made progress to improve the effectiveness of its AML/CFT system and achieved upgrades on two immediate outcomes:
    - intensifying supervision of lawyers, real estate agents and Trust and company service providers (TCSPs),
    - enhancing cooperation between Sepblac and the Inter-ministerial Body on Material of Defense and Dual-use (JIMDDU) to raise awareness and issue guidance, particularly in the financial sector, of the specific risks of proliferation-related target financial sanctions evasion.
  - Spain maintained a moderate rating on the outcome related to preventive measures and financial sanctions.
  - The priority action related to this outcome is to apply targeted financial sanctions when appropriate and without delay.
- Status: Spain will remain in regular follow-up and will continue to report back to the FATF on progress to strengthen its implementation of AML/CFT measures.

### Consolidated recommendations (paragraph 83 and related)
- Continue work to monitor and address LSIs’ governance and risk management weaknesses by performing more targeted onsite inspections/ thematic onsite activities.
- Strengthen BdE oversight and inspection activities on banks’ liquidity risk management policies and practices.
- Explicitly empower the BdE to require an increase in provisions against specific assets or exposures for prudential purposes.
- Align the framework on related party transactions with the 2012 BCPs by:
  - expanding the prudential definition of related party transactions,
  - applying rules on the need to ensure that related party transactions are conducted on arms’ length basis and subject to strict rules on avoidance of conflict of interest,
  - introduce an overall limit on exposures to related parties that is at least as strict as the large exposure limit.
- Remove the requirement for the BdE to authorize banks’ loans to their directors and senior management.
- Take into account excessive concentration risk for a broader range of exposure types, including sovereign risk concentration, when setting P2R.
- Ensure more focus on onsite inspection of IRRBB risk management policies and practices, through thematic or targeted onsite activities.
- Continue monitoring and assessing climate risk through targeted and thematic work, ensure climate risk oversight becomes gradually integrated in routine supervisory processes, and increase resources dedicated to work on climate-related risks.
- Continue with the implementation of the risk matrix for AML/CFT and integrate it in supervisory planning activities for AML/CFT, including for onsite; streamline the process to finalize and start executing the annual joint AML/CFT inspection plan and increase AML/CFT inspection activities, by performing more risk-based and targeted inspections; and grant the BdE more powers to issue requirements and sanctions related to ML/TF risks.

*Source: 1espea2024006-print-pdf (pages 80–83), https://www.imf.org/-/media/files/publications/cr/2024/english/1espea2024006-print-pdf.pdf*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2024/english/1espea2024006-print-pdf.pdf_
