## 1grcea2026005

## Source details

**Canonical URL:** [1grcea2026005](https://www.imf.org/-/media/files/publications/cr/2026/english/1grcea2026005.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2026/english/1grcea2026005.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2026/english/1grcea2026005.pdf.json)

---

### EXECUTIVE SUMMARY — overall assessment and supervisory approach
- Supervision of LSIs is effective in Greece.
- The Bank of Greece (BoG) supervisory approach is thorough, systematic and intrusive, with the Supervisory Review and Evaluation Process (SREP) as the core framework, adapted to Greece’s local risks and environment.
- The SREP process is transparent internally and to LSIs, with risks clearly identified and reflected in supervisory actions and Pillar 2 capital add-ons.
- BoG benefits from robust independence and the ability to attract and retain staff with the desired skills and experience.
- Collaboration and coordination with other parties are effective, both internally (such as AML supervisors) and externally (with other supervisors and authorities).

### Areas needing improvement in supervisory framework and process
- Enforcement and sanctioning regime: processes could be tighter and the framework better calibrated; penalties might better reflect the offence and provide the right level of deterrence.
- No explicit BoG risk tolerance framework for LSI supervision: absence of internal or external articulation of tolerance could lead to lack of clarity about how far supervisory actions should aim to reduce or eliminate risk.
- Need for medium-term resource planning and continued vigilance on emerging risks (notably ICT and cyber) to ensure adequate resourcing.

### Key resourcing and strategic recommendations (high level)
- FSAP encourages BoG to maintain and build on its supervisory approach and to review resourcing needs in an agile manner.
- Establish processes to identify resourcing needs and deliver needed resources in a timely manner.
- Specific recommendation:
  - Recommendation 1: Review the merit of a distinct supervisory budget, along with an agile approach to changing staff needs, to provide additional safeguards to the independence and financial robustness of BoG supervisory function. Authority: BoG. Timing: ST.

---

### Credit risk and Non-Performing Loans (NPLs)
- Credit risk remains the most important risk for Greek LSIs; BoG should continue close monitoring of NPLs and credit risk management.
- Despite decline in NPL ratios, some legacy NPLs remain outstanding and new NPLs have been increasing (new NPLs rose in H1 2025).
- Implementation of the ECB’s Guideline for the application of the prudential backstop to LSIs leads to a more conservative approach to provisioning coverage for NPLs.
- Judicial delays in realizing security: creditors in Greece often encounter significant delays in the judicial process, with realization of security often taking a very long time — authorities need to address these delays.
- Supervisory actions: BoG’s off-site and on-site analysis and supervisory actions around credit risk and problem assets are generally effective.
- NPL statistics and dynamics:
  - Stock of NPLs declined by 84 percent from €107 bn in Q1 2016 to €6bn at end-Q2 2025.
  - NPL ratio reduced from 46 percent to around 3 percent today; EU average = 2.1 percent.
  - Three LSIs remain with NPLs ranging between 25 and 45 percent (three LSIs had high legacy NPLs with coverage ratios between 40 percent and 60 percent as of end-2024).
  - Small uptick in the NPL stock in LSIs in the first half of 2025.
- Recommendations related to credit risk and NPLs:
  - Recommendation 6: Accelerate the legal amortization of DTCs to a timing aligned with the voluntary scheme currently in place for their prudential amortization in SI banks. Authority: BoG, MoEF. Timing: MT.
  - Recommendation 7: Greece should expedite legislative change to address delays in the judicial process for realizing security and addressing longstanding NPLs. Authority: Government. Timing: ST.
  - Recommendation 8: BoG should maintain a strong focus on credit risk and NPLs. Authority: BoG. Timing: I.

---

### Capitalization, Deferred Tax Credits (DTCs), and HAPS
- Weighted average CET1 Capital ratio (banking sector) at end-2024 = 15.9 percent; total capital ratio = 19.7 percent.
- DTCs remain substantial in banks (especially the SIs). The total amount is equivalent to roughly 50 percent of SIs’ CET1 Capital.
- As of end-2024:
  - DTCs stood at the equivalent of 50.1 percent of SIs’ CET1 Capital.
  - For LSIs, the ratio is 2.4 percent.
  - Only three LSIs had DTCs, with the highest at 30 percent of CET1 Capital.
- SIs have started accelerating prudential amortization of DTCs with intention to eliminate them completely by 2031-33 (as opposed to 2041 under the current legal amortization calendar); this is voluntary and dependent on profitability/dividend capacity.
- Hellenic Asset Protection Schemes (HAPS):
  - 19 SPVs set up since 2019 (HAPS I, HAPS II for SIs; HAPS III for LSIs).
  - As of Q2 2025, total outstanding guaranteed amount = €16.2 billion.
  - NPL reduction outcome: NPLs fell from €81 billion (ratio 40.6 percent in Q2 2019) to €6 billion (ratio 3.0 percent in Q4 2024).
  - Final maturities of senior notes in the 19 deals vary between 24 years and 56 years as of Q2 2025.
  - Two major contributory factors to slower-than-expected resolution: (i) slow judicial process and (ii) underestimate of recovery costs.
- Recommendation:
  - Recommendation 6 (repeated): Accelerate the legal amortization of DTCs to align timing with the voluntary SI bank scheme. Authority: BoG, MoEF. Timing: MT.

---

### Profitability, liquidity, funding, and macroprudential measures
- Profitability and income structure:
  - Low cost to income ratios and high net interest margins supported profitability and capital rebuilding.
  - Profitability indicators (Greece | Banking Union*):
    - Net interest margin: 2023 = 2.7% ; 2024 = 2.6% ; Dec 2024 = 1.6%
    - Operating costs / total assets: 2023 = 1.2% ; 2024 = 1.2% ; Dec 2024 = 1.3%
    - Cost to income ratio: 2023 = 35.4% ; 2024 = 36.2 % ; Dec 2024 = 54.9%
    - Cost of credit risk: 2023 = 1.1% ; 2024 = 0.7% ; Dec 2024 = 0.5%
    - Return on Assets: 2023 = 1.2% ; 2024 = 1.3% ; Dec 2024 = 0.7%
    - Return on Equity: 2023 = 12.0% ; 2024 = 12.2% ; Dec 2024 = 9.5%
  - High net interest margins driven by strong deposit franchises and low cost of deposit funding (weighted average interest rate on loans = 4.6 percent; on deposits = 0.3 percent).
- Liquidity and funding metrics:
  - All Greek banks have liquidity coverage ratios (LCRs) of more than 200 percent; weighted average LCR at end-2024 = 218 percent.
  - Net stable funding ratios (NSFRs) are well in excess of the regulatory minimum; weighted system average NSFR at end-2024 = 139 percent.
  - Loan to deposit ratio at end-2024 = 73 percent.
  - LCRs and NSFRs are underpinned by strong deposit growth and HQLA buffers.
- Macroprudential policy actions:
  - Borrower Based Measures (BBMs) effective January 2025:
    - LTV limits set at 80 percent.
    - DSTI (DTI) limits set at 40 percent.
    - Higher limits for first-time buyers.
  - Countercyclical capital buffer (CCyB):
    - Intermediate level of 0.25 percent as of October 1st 2025.
    - Positive neutral CCyB set at 0.5 percent, effective from October 1st 2026.
  - Macroprudential analysis is carried out by the Macroprudential Policy Division of the Financial Stability Directorate; deployment decided at the Executive Committee.

---

### Supervisory framework, SREP, organizational arrangements, and resources
- SSM (ECB + NCAs) is the overarching framework. ECB directly supervises SIs and oversees LSI supervision conducted by NCAs; ECB approves licenses, withdrawals and qualifying holdings in LSIs.
- BoG follows the EU Single Rulebook and SSM regulation; active participant in SSM, ECB and EBA working groups.
- BoG is designated macroprudential authority for Greece (Law 4261/2014) and BoG independence is enshrined in law (Article 5A of its Statute).
- SREP specifics:
  - SREP is core tool to assess LSI risks, determine capital requirements and set supervisory program; methodology based on SSM LSI methodology.
  - Institutions scored on a scale of one (lowest risk) to four (highest risk) with plus (+) and minus (-) gradings within the two middle categories, delivering ten gradings.
  - Inputs: prudential data, ICAAP, ILAAP, a BoG stress test, questionnaire on internal controls, on-site inspection results, meetings and public sources.
  - Elements scored: (i) business model; (ii) internal governance and risk management; (iii) risks to capital (credit, market risk, IRRBB, operational risk); (iv) liquidity. First three determine P2R.
  - SREP outcomes: P2R (Pillar 2 surcharge) and P2G (recommended additional capital surplus); actionable supervisory plans and P2R add-ons are granular by risk area.
  - Frequency by risk: high impact LSIs = annual SREP; higher risk = every two years; small lower-risk non-complex and TCBs = every three years; automated summary assessment annually for all LSIs.
  - Horizontal reviews by Methodology and Risk Analysis teams promote consistency.
- Organizational and budgetary features:
  - BoG is publicly listed; Government holding = 30 percent; Statute limits Government to 35 percent and other shareholders to 2 percent.
  - Dividends are a fixed amount per share = €13.3mn a year.
  - Net profits amounted to €82.9mn in 2024.
  - BoG Executive Committee Act 238/2/10.1.2025 on supervisory fees (effective as of January 2026) sets methodology for annual supervisory costs & fees per bank and establishes a fixed fee for license assessment = €20,000.
  - Budget ceiling approved by the General Council; Governor provides top-down allocation direction.
- Resourcing risks and ICT supervision:
  - Budget setting framework and lack of a distinct supervisory budget create medium-term resource risk, especially given evolving needs (e.g., DORA demands for skilled ICT personnel).
  - ICT Supervision divided into two Divisions: “ICT Risk Assessment” (off-site) and “ICT Risk Inspections” (on-site); staff grew from about 10 to 17 over the last five years.
  - DORA introduces significant demands on banks and supervisors, presenting an ongoing resource allocation challenge.
- Key supervisory recommendation on resources:
  - Recommendation 13: Undertake a full strategic review of resource requirements for ICT and in other areas of Supervision under the most pressure, and increase / reallocate resources as appropriate. Authority: BoG. Timing: ST.

---

### Governance, related parties, concentration, change of control, and HCAP
- Governance and board oversight:
  - Requirements around governance and risk management are comprehensive and supervisory oversight is strong, but governance remains an area for continued focus given inherent challenges in small LSIs.
  - BoG Executive Committee Act 243/2/07.07.2025 adopts EBA guidelines and introduced requirement for a minimum number (two or 25 percent depending on size) of independent non-executive directors.
  - Recommendation 3: Heighten supervision of governance, including through on-site inspections, particularly for larger and riskier LSIs, including a focus on more high-quality independent directors. Authority: BoG. Timing: ST.
- Concentration and related party exposures:
  - BoG assesses single party, geographic and sectoral concentration risks in LSIs and uses P2R add-ons when concentration risks are significant.
  - Proportion of large exposures relative to total credit rose from about 21 percent in 2021 to about 47 percent in Q2 2025.
  - Identified gap: absence of a specific requirement for Boards to sign off on all concentration risks.
  - Recommendation 9: Introduce a requirement for Boards to sign-off on all concentration risks. Authority: BoG. Timing: MT.
  - Related party framework gaps:
    - EU definition of related parties does not align with Basel/BCP; Greek national framework lacks some core elements and does not include all affiliates.
    - No limit on total exposures to related parties in Greek law; BCPs set such a limit at 25 percent of CET1 Capital.
    - Recommendation 10: Align the definition of related parties with that of the BCPs by including all affiliated companies and their directors and family. Authority: BoG. Timing: ST.
    - Recommendation 11: Introduce a limit on total exposures to related parties of 25 percent of CET1 Capital. Authority: BoG. Timing: ST.
- Change of control and HCAP:
  - Acquisitions of qualifying holdings covered by EU framework as of 11 January 2026 and subject to prior BoG approval; BoG can deprive a shareholder of voting rights as mitigant.
  - Recent merger approved creating the fifth largest bank; BoG assessed business plans, securitization, capital injections, SRT, and governance suitability.
  - HCAP (fully owned by MoEF) retains veto power over strategic decisions in the fifth largest bank (HCAP stake = 36.2 percent); legacy power may permit undue government interference.
  - Recommendation 5: Remove the special powers granted to HCAP in relation to its participation in the fifth largest bank. Authority: Government. Timing: ST.
- Enforcement and sanctions:
  - BoG has powers to impose a wide range of administrative penalties; new legislation expected January 2026 will introduce periodic penalty payments (PPPs).
  - Concern: relatively low level of financial penalties imposed historically.
  - Recommendation 14: Review and codify clearly the escalation process for sanctions and review the sanctions matrix so that all sanctions actions are timely, consistent and effective as deterrents. Authority: BoG. Timing: ST.

---

### IRRBB, market risk, and operational risk findings
- IRRBB:
  - BoG includes IRRBB in SREP and imposes P2R add-ons; assesses IRRBB from both earnings (NII) and economic value (EVE) perspectives.
  - Some LSIs carry relatively high IRRBB: "in the range of 30-40 percent of CET1 Capital at risk from a parallel 200bp upward shift."
  - Current mitigants: low deposit betas and low deposit rates maintained; market dynamics could change quickly.
  - Recommendation 12: LSI supervisors should discuss with banks the magnitude of the risk, ensure strong risk control frameworks commensurate with the risk profile, and continue to apply appropriate P2R add-ons. Authority: BoG. Timing: I.
- Market risk:
  - Greek LSIs have limited exposure to market risk; market RWAs in cases with trading portfolios are "less than 1 percent and roughly 2.7 percent of total RWAs".
- Operational risk and ICT:
  - BoG’s operational risk framework is comprehensive; DORA and evolving ICT risks impose significant supervisory resource needs.
  - On-site inspections highlighted ICT as a major risk and generated numerous recommendations.
  - Recommendation 13 (repeated): Undertake a full strategic review of resource requirements for ICT and other pressured supervisory areas, and increase/reallocate resources as appropriate. Authority: BoG. Timing: ST.

---

### Banking sector structure and key statistics (selected)
- The four largest banks (the SIs) account for about 94 percent of banking assets.
- Banks hold approximately €300 billion in assets on a solo basis, comprising 85 percent of the financial sector.
- The banking sector amounts to approximately 128 percent of GDP as of December 2024.
- The credit-to-GDP ratio has fallen from a high of 136 percent in 2012 to under 100 percent today.
- There is only one active Third Country Branch (TCB) which is small and accounts for about 0.6 percent of banking assets.
- LSIs: eight in total; two target niche markets (one shipping, one digital banking) and six (four cooperative banks) offer traditional deposit-taking and lending services.
- Some small LSIs still have a significant portion of their balance sheet in NPLs (in the region of 30 percent).
- New mortgages increased by 20 percent in 2024.
- Credit to the private sector reached 9.4 percent (y/y) in Q4 2024.
- Stock of NPLs: €107 bn in Q1 2016 → €6bn at end-Q2 2025 (an 84 percent decline).

---

### Consolidated list of numbered recommendations (with authority and timing where specified)
- Recommendation 1: Review the merit of a distinct supervisory budget, along with an agile approach to changing staff needs, to provide additional safeguards to the independence and financial robustness of BoG’s supervisory function. Authority: BoG. Timing: ST.
- Recommendation 2: BoG to consider introducing a risk tolerance framework in its supervisory approach to LSIs. Authority: BoG. Timing: (implied near-term consideration).
- Recommendation 3: Heighten supervision of governance, including through on-site inspections, particularly for larger and riskier LSIs, including a focus on more high-quality independent directors. Authority: BoG. Timing: ST.
- Recommendation 4: Monitor EU changes to change-of-control powers and review BoG processes to include automatic suspension of voting rights if change in control approval was based on false information or notification failures. Authority: BoG. Timing: MT/ongoing monitoring.
- Recommendation 5: Remove the special powers granted to HCAP in relation to its participation in the fifth largest bank. Authority: Government. Timing: ST.
- Recommendation 6: Accelerate the legal amortization of DTCs to a timing aligned with the voluntary scheme currently in place for their prudential amortization in SI banks. Authority: BoG, MoEF. Timing: MT.
- Recommendation 7: Greece should expedite legislative change to address delays in the judicial process for realizing security and addressing longstanding NPLs. Authority: Government. Timing: ST.
- Recommendation 8: BoG should maintain a strong focus on credit risk and NPLs. Authority: BoG. Timing: I.
- Recommendation 9: Introduce a requirement for Boards to sign-off on all concentration risks. Authority: BoG. Timing: MT.
- Recommendation 10: Align the definition of related parties with that of the BCPs by including all affiliated companies and their directors and family. Authority: BoG. Timing: ST.
- Recommendation 11: Introduce a limit on total exposures to related parties of 25 percent of CET1 Capital. Authority: BoG. Timing: ST.
- Recommendation 12: LSI supervisors should discuss with banks the magnitude of IRRBB, ensure strong risk control frameworks commensurate with the risk profile, and continue to apply appropriate P2R add-ons. Authority: BoG. Timing: I.
- Recommendation 13: Undertake a full strategic review of resource requirements for ICT and other supervisory areas under the most pressure, and increase/reallocate resources as appropriate. Authority: BoG. Timing: ST.
- Recommendation 14: Review and codify clearly the escalation process for sanctions and review the sanctions matrix so that all sanctions actions are timely, consistent and effective as deterrents. Authority: BoG. Timing: ST.

*Source: EXECUTIVE SUMMARY and selected chapters, 1grcea2026005*

### EXECUTIVE SUMMARY __________________________________________________________________________ 5

### EXECUTIVE SUMMARY

### Supervision of Less Significant Institutions (LSIs): overall assessment
- Supervision of LSIs is effective in Greece.
- The Bank of Greece (BoG) supervisory approach is thorough, systematic and intrusive, with the Supervisory Review and Evaluation Process (SREP) as the core framework, adapted to Greece’s local risks and environment.
- The SREP process is transparent internally and to LSIs, with risks clearly identified and reflected in supervisory actions and Pillar 2 capital add-ons.
- BoG benefits from robust independence and the ability to attract and retain staff with the desired skills and experience.
- Collaboration and coordination with other parties are effective, both internally (such as AML supervisors) and externally (with other supervisors and authorities).

### Areas needing improvement in supervisory framework and process
- Enforcement and sanctioning regime: processes could be tighter and the framework better calibrated; penalties might better reflect the offence and provide the right level of deterrence.
- No explicit BoG risk tolerance framework for LSI supervision: absence of internal or external articulation of tolerance could lead to lack of clarity about how far supervisory actions should aim to reduce or eliminate risk.
- Need for medium-term resource planning and continued vigilance on emerging risks (notably ICT and cyber) to ensure adequate resourcing.

### Resourcing and strategic recommendations
- FSAP encourages BoG to maintain and build on its supervisory approach and to review resourcing needs in an agile manner.
- Recommendation to establish processes to identify resourcing needs and deliver needed resources in a timely manner.
- Specific recommendation (Table 1, #1): Review the merit of a distinct supervisory budget, along with an agile approach to changing staff needs, to provide additional safeguards to the independence and financial robustness of BoG supervisory function. Authority: BoG. Timing: ST.

### Credit risk and NPLs
- Credit risk remains the most important risk for Greek LSIs; BoG should continue close monitoring of NPLs and credit risk management.
- Despite decline in NPL ratios, some legacy NPLs remain outstanding and new NPLs have been increasing.
- Implementation of the ECB’s Guideline for the application of the prudential backstop to LSIs leads to a more conservative approach to provisioning coverage for NPLs.
- Judicial delays in realizing security: creditors in Greece often encounter significant delays in the judicial process, with realization of security often taking a very long time — authorities need to address these delays.
- Specific supervisory actions: BoG’s off-site and on-site analysis and supervisory actions around credit risk and problem assets are generally effective.
- Recommendation highlights from Table 1:
  - #6: Accelerate the legal amortization of DTCs to a timing aligned with the voluntary scheme currently in place for their prudential amortization in SI banks, given the legal amortization would be applicable to all banks, including LSIs. Authority: BoG, MoEF. Timing: MT.
  - #7: Greece should expedite legislative change to address delays in the judicial process for realizing security and addressing longstanding NPLs. Authority: Government. Timing: ST.
  - #8: BoG should maintain a strong focus on credit risk and NPLs. Authority: BoG. Timing: I.

### Other material risks
- Interest rate risk in the banking book (IRRBB) and operational risk warrant ongoing and increased attention; both are significant for LSIs and may not be getting required attention from banks’ Boards.
- Supervisors should push banks to fully recognize and manage IRRBB and operational risk; market dynamics and Pillar 2 capital add-ons are mitigants but not sufficient alone.
- Recommendation (Table 1, #12): LSI supervisors should discuss with banks the magnitude of the risk, and ensure that they have a strong risk control framework commensurate with the risk profile, as well as continuing to apply appropriate P2R add-ons. Authority: BoG. Timing: I.
- Recommendation (Table 1, #13): Undertake a full strategic review of resource requirements for ICT and other supervisory areas under the most pressure, and increase/reallocate resources as appropriate. Authority: BoG. Timing: ST.

### Governance and board oversight
- Requirements around governance and risk management are comprehensive and supervisory oversight is strong, but governance remains an area for continued focus given inherent challenges in small LSIs.
- Supervisory actions have elevated the importance of sound governance, but governance challenges for small LSIs will likely persist.
- Recommendation highlights:
  - #3: Heighten supervision of governance, including through on-site inspections, particularly for larger and riskier LSIs, including a focus on more high-quality independent directors. Authority: BoG. Timing: ST.
  - #9: Introduce a requirement for Boards to sign off on all concentration risks. Authority: BoG. Timing: MT.

### Short-term regulatory and legacy priorities
- With a growing Greek economy and a more stable banking system, authorities should introduce regulations in areas where there is no applicable EU framework and address legacy issues.
- Specific short-term attention areas:
  - Related party definition and limits:
    - The EU-aligned CRD definition of related parties does not comply with Basel standards; recommendation to align with Basel by including all affiliated companies and their directors and family.
    - Recommendation (#10): Align the definition of related parties with that of the BCPs by including all affiliated companies and their directors and family. Authority: BoG. Timing: ST.
    - Recommendation (#11): Introduce a limit on total exposures to related parties of 25 percent of CET1 Capital. Authority: BoG. Timing: ST.
  - Deferred Tax Credits (DTCs):
    - DTCs are government guaranteed deferred tax assets and a legacy of Greece’s 2010s crisis; perceived as lower quality capital and exacerbating the Sovereign / bank nexus.
    - Recommendation (#6 repeated): Accelerate legal amortization of DTCs to align timing with voluntary SI bank scheme. Authority: BoG, MoEF. Timing: MT.
  - Hellenic Corporation of Assets and Participations (HCAP) special powers:
    - HCAP, fully owned by MoEF, retains veto power over strategic decisions — legacy feature that may permit undue government interference.
    - Recommendation (#5): Remove the special powers granted to HCAP in relation to its participation in the fifth largest bank. Authority: Government. Timing: ST.
  - Enforcement and sanctions:
    - Recommendation (#14): Review and codify clearly the escalation process for sanctions and review the sanctions matrix so that all sanctions actions are timely, consistent and effective as deterrents. Authority: BoG. Timing: ST.

### Banking sector structure and key statistics
- The four largest banks (the SIs) account for about 94 percent of banking assets.
- Banks hold approximately €300 billion in assets on a solo basis, comprising 85 percent of the financial sector.
- The banking sector amounts to approximately 128 percent of GDP as of December 2024.
- The credit-to-GDP ratio has fallen from a high of 136 percent in 2012 to under 100 percent today.
- There is only one active Third Country Branch (TCB) which is small and accounts for about 0.6 percent of banking assets.
- LSIs: eight in total; two target niche markets (one shipping, one digital banking) and six (four cooperative banks) offer traditional deposit-taking and lending services.
- Some small LSIs still have a significant portion of their balance sheet in NPLs (in the region of 30 percent).
- New NPLs rose in H1 2025.

### Scope and approach of the FSAP note
- No FSAP for Greece since 2006; this review is from a fresh first-principles perspective within the EU context.
- The review considered the EU regulatory environment, the EA FSAP completed in July 2025, and areas where no applicable EU framework exists.
- Core Basel Core Principles (CP) used to structure discussions include CP1, CP2, CP3, CP7, CP8, CP9, CP10, CP11, CP13, CP14, CP15, CP16, CP17, CP18, CP19, CP20, CP23, CP24, CP25, CP26.

*Source: EXECUTIVE SUMMARY, 1grcea2026005*

### 9. The Greek banking sector displays low cost to income ratios and high net

### 1grcea2026005 - 9. The Greek banking sector displays low cost to income ratios and high net

### Profitability and income structure
- Combination of low cost to income ratios and high net interest margins has yielded good base profits and underlies the return to financial health, good overall profitability and the ability to rebuild capital over the last five years.
- High net interest margins are driven significantly by strong deposit franchises and low cost of deposit funding, which has remained low even through the rising rate environment of recent years.
- Table of profitability indicators (Greece | Banking Union*):
  - Net interest margin: 2023 = 2.7% ; 2024 = 2.6% ; Dec 2024 = 1.6%
  - Operating costs / total assets: 2023 = 1.2% ; 2024 = 1.2% ; Dec 2024 = 1.3%
  - Cost to income ratio: 2023 = 35.4% ; 2024 = 36.2 % ; Dec 2024 = 54.9%
  - Cost of credit risk: 2023 = 1.1% ; 2024 = 0.7% ; Dec 2024 = 0.5%
  - Return on Assets: 2023 = 1.2% ; 2024 = 1.3% ; Dec 2024 = 0.7%
  - Return on Equity: 2023 = 12.0% ; 2024 = 12.2% ; Dec 2024 = 9.5%
- Source of profitability data: Bank of Greece Financial Stability Report May 2025.
- Note: Banking groups in the Banking Union are directly supervised by the ECB.

### LSIs (List and key metrics as of December 31, 2024)
- Cooperative Bank of Chania — Assets (consol.) = 726 (€ mil) ; Total Capital Ratio (consol) = 15,85% ; NPL Ratio (consol) = 43,8%
- Credia Bank — Assets (consol.) = 7,540 (€ mil) ; Total Capital Ratio (consol) = 14,82% ; NPL Ratio (consol) = 3,3%
- Cooperative Bank of Thessaly — Assets (consol.) = 397 (€ mil) ; Total Capital Ratio (consol) = 17,46% ; NPL Ratio (consol) = 31,9%
- Optima Bank — Assets (consol.) = 5,541 (€ mil) ; Total Capital Ratio (consol) = 14,40% ; NPL Ratio (consol) = 0,5%
- Cooperative Bank of Epirus — Assets (consol.) = 354 (€ mil) ; Total Capital Ratio (consol) = 17,02% ; NPL Ratio (consol) = 26,8%
- Viva Bank (Werealize) — Assets (consol.) = 734 (€ mil) ; Total Capital Ratio (consol) = 9,31% ; NPL Ratio (consol) = 0,3%
- Cooperative Bank of Karditsa — Assets (consol.) = 275 (€ mil) ; Total Capital Ratio (consol) = 22,78% ; NPL Ratio (consol) = 6,9%
- Aegean Baltic Bank — Assets (consol.) = 1,151 (€ mil) ; Total Capital Ratio (consol) = 27,28% ; NPL Ratio (consol) = 0,6%

### Capitalization and Deferred Tax Credits (DTCs)
- Weighted average CET1 Capital ratio (banking sector) at end-2024 = 15.9 percent; total capital ratio = 19.7 percent.
- DTCs remain substantial in banks (especially the SIs). The total amount is equivalent to roughly 50 percent of SIs’ CET1 Capital.
- SIs have started amortizing DTCs faster; intention is to eliminate them completely by 2031-33 (as opposed to 2041 under the current legal amortization calendar).
- Banks paid dividends in 2024 for the first time since the crisis.
- Prudential capital positions were significantly improved by 2015 regulations that provided an effective government guarantee to (what were then) Deferred Tax Assets (DTAs).

### Liquidity and funding
- All Greek banks have liquidity coverage ratios (LCRs) of more than 200 percent; weighted average LCR at end-2024 = 218 percent.
- Net stable funding ratios (NSFRs) are well in excess of the regulatory minimum; weighted system average NSFR at end-2024 = 139 percent.
- Loan to deposit ratio at end-2024 = 73 percent.
- Drivers: deposits have risen strongly in the last five years and loan growth being minimal; banks have built up HQLA buffers.

### Risks, credit and real estate developments
- Systemic risk remains contained with low private sector leverage, an improving sovereign balance sheet and strong banking sector liquidity.
- Credit developments:
  - Credit to the private sector reached 9.4 percent (y/y) in Q4 2024.
  - New mortgages increased by 20 percent in 2024 (albeit from a very low base).
  - Net growth in consumer and household credit remained low due to repayments.
- Residential real estate prices have increased significantly this decade; much financing came from sources other than borrowed money, including investments by nonresidents.
- NPL evolution:
  - Stock of NPLs declined by 84 percent from €107 bn in Q1 2016 to €6bn at end-Q2 2025.
  - NPL ratio reduced from 46 percent to around 3 percent today; EU average = 2.1 percent.
  - Reduction driven by securitizations under the Hercules Asset Protection Scheme (HAPS), supported by €21.5 bn of government guarantees (none triggered to date).
  - Three LSIs remain with legacy NPLs and high NPL ratios in the region of 20 to 40 percent.
  - Small uptick in the NPL stock in LSIs in the first half of 2025.
- Concentration:
  - Proportion of large exposures relative to total credit rose from about 21 percent in 2021 to about 47 percent in Q2 2025.
  - HHI index = 1283 (very close to the EU average).

### Macroprudential policy actions
- BoG implemented Borrower Based Measures (BBMs) effective January 2025:
  - LTV limits set at 80 percent.
  - DSTI (DTI) limits set at 40 percent.
  - Higher limits for first-time buyers to mitigate distributional impacts.
- Countercyclical capital buffer (CCyB):
  - BoG adopted a positive neutral CCyB set at 0.5 percent, effective from October 1st 2026.
  - Intermediate level of 0.25 percent as of October 1st 2025.
- Macroprudential analysis carried out by the Macroprudential Policy Division of the Financial Stability Directorate; deployment decided at the Executive Committee.

### Supervisory framework, governance, and resources
- SSM (ECB + NCAs) is the overarching legislative and institutional framework for banking supervision in the EA. ECB directly supervises SIs and oversees LSI supervision conducted by NCAs; ECB approves licenses, withdrawals and qualifying holdings in LSIs.
- BoG follows the EU Single Rulebook and SSM regulation; active participant in SSM, ECB and EBA working groups.
- BoG is designated macroprudential authority for Greece (Law 4261/2014).
- BoG independence is enshrined in law (Article 5A of its Statute) and evident in practice.
- BoG’s supervisory powers derive from Article 55A of the BoG Statute and Law 4261/2014.
- Organizational and budgetary features:
  - BoG is publicly listed; Government holding = 30 percent; Statute limits Government to 35 percent and other shareholders to 2 percent.
  - Dividends are a fixed amount per share = €13.3mn a year.
  - Net profits amounted to €82.9mn in 2024.
  - BoG Executive Committee Act 238/2/10.1.2025 on supervisory fees (effective as of January 2026) sets a transparent methodology for annual supervisory costs & fees per bank and establishes a fixed fee for assessing a banking license application = €20,000.
  - Budget ceiling approved by the General Council; Governor provides top-down direction for allocation.
- Resourcing risks:
  - Budget setting framework and lack of a distinct supervisory budget create medium-term resource risk, especially given evolving needs (e.g., DORA demands for skilled ICT personnel).
  - The framework allows deviation from the original budget (reprioritization and a buffer) which provides some flexibility.
- BoG published its first Annual report on Prudential Supervision and Resolution Activities in June 2025 covering supervisory and resolution activities in 2024.

### Supervisory organization and cooperation
- Article 55A accords supervisory powers to the Executive Committee (Governor and Deputy Governors), which delegates authority to the Credit and Insurance Committee (CIC).
- ICT Supervision is divided into two Divisions: “ICT Risk Assessment” (off-site) and “ICT Risk Inspections” (on-site), both within the Supervised Institutions Inspections Directorate.
- Domestic supervisory cooperation functions well; MoU with HCMC updated; AML / CFT supervisory findings are communicated systematically and ad hoc to LSI prudential supervisors and incorporated into SREPs.

### Key recommendation
- Recommendation 1: Review the merit of a distinct supervisory budget, along with an agile approach to changing staff needs, to provide additional safeguards to the independence and financial robustness of BoG’s supervisory function.

*Source: IMF country chapter as provided in the supplied content.*

### 36. The Turkish Banking Supervisor is the only relevant overseas supervisor for LSIs and

### 36. The Turkish Banking Supervisor is the only relevant overseas supervisor for LSIs and

### Supervisory Process
- The Turkish Banking Supervisor is the home supervisor for one TCB; BoG have an MoU with the Banking Regulation and Supervision Agency of Turkey. BoG provided support to an on-site inspection of the Greek operations by the home supervisor.
- No LSIs currently have an overseas presence.
- Of the two TCBs, one is dormant as a result of sanctions.

- SREP is the key tool used by the BoG offsite supervisors to assess LSI risks, determine their capital requirements and set the supervisory program. The SREP tool is based on the SSM LSI methodology.
- Risk profiling:
  - Institutions are scored on a scale of one (lowest risk) to four (highest risk).
  - A recent innovation introduces gradings within the two middle categories: a plus (+) or minus (-), delivering a system with ten gradings.
- SREP outcomes:
  - Concludes with a determination of the Pillar 2 Capital surcharge (P2R) and the recommended additional capital surplus (P2G) for each LSI.
  - See Appendix I for a diagram outlining the workings of the SREP (referenced in source).
- Frequency:
  - High impact LSIs: annual SREP (determined according to a set of criteria set by the ECB).
  - Higher risk entities: every two years.
  - Small lower-risk non-complex institutions and third country branches (TCBs): every three years.
  - Backstop: automated summary assessment annually for all LSIs.
- Inputs to SREP:
  - Prudential data, ICAAP, ILAAP (both required ahead of the SREP), a stress test conducted by the BoG, and a questionnaire about internal controls and processes completed by the LSI.
  - Other information: results of on-site inspections, meetings with the bank and public sources.
- Elements scored by SREP:
  - (i) business model;
  - (ii) internal governance and risk management;
  - (iii) risks to capital (credit, market risk, IRRBB, operational risk);
  - (iv) liquidity.
  - The first three elements determine the P2R. The liquidity risk profile does not feed through to the P2R but is used to determine supervisory actions around liquidity and funding.
- Scoring and governance:
  - Scores are first calculated automatically from the data and a (constrained) supervisory judgement is overlaid.
  - Risk levels and risk controls across the four areas are combined to produce the overall risk grade of one to four.
  - Detailed memos to the CIC analyze information, the risk rating and the action plan. The CIC adopts the SREP decisions.
- Horizontal analysis and consistency:
  - BoG’s Methodology team and the Risk Analysis team conduct horizontal reviews of SREP outputs, including key metrics (profitability, capital, asset quality etc.), facilitating benchmarking, comparisons between LSIs and consistency of risk scores and supervisory programs.
- Supervisory action plans and P2R add-ons:
  - Actionable outcomes from SREP are supervisory action plans and P2R add-ons, with add-ons determined for each risk area.
  - P2R add-ons are built up in a granular way with specific add-ons for each risk area.
  - SREP outcomes are shared with banks transparently; supervisory action plans and compliance with individual items are carefully monitored.
  - LSIs met confirmed risk analysis and action plans are clear and supported by evidence.
- On-site inspections:
  - Planned on a risk basis or as part of horizontal reviews. Annual planning process where supervision teams submit “bids” and discuss priorities with Inspection Directorate management.
  - On-site inspection reports reviewed and found to be thorough with conclusions and action plans well-evidenced.
  - Third parties are not used but could be commissioned in periods of heavy demand.
- ICT supervision:
  - Two separate Divisions under the Supervised Institutions Inspections Directorate cover ICT risks for both on-site and off-site supervision.
  - A single division performing IT risk assessments and on-site inspections was originally established in 1998 until 2018 when the Division was split.
  - Rationale: ICT skills are specialized; creating a pool of horizontal ICT Risk resources allocable to resource-intensive projects.
  - Outputs of the teams are of a similar standard to core supervision areas but there are challenges in sourcing skills and high demands on the team.
  - See recommendations 1 and 13 which recommend allocating more resources to areas of growing importance such as this.
- Risk tolerance:
  - BoG would benefit from a careful review of its risk tolerance as the Greek economy and financial system emerge to a more normal state.
  - Current absence of articulated internal or external tolerance could lead to:
    - (i) an effective zero tolerance with accompanying moral hazard; or
    - (ii) a premature tolerance of losses with risks to confidence and of contagion.
  - Lack of a framework could lead to internal confusion on how far supervisory actions should aim to reduce or eliminate risk.
  - Recommendation 2: BoG to consider introducing a risk tolerance framework in its supervisory approach to LSIs.

### Supervision of Risk Management and Governance
- Legal and regulatory framework:
  - Greek governance requirements updated in July 2025, following EU regulations.
  - Banking Law 4261/2014 sets core governance requirements, transposing relevant CRD provisions from EU law.
  - Recent update: BoG Executive Committee Act 243/2/07.07.2025 enhances internal governance arrangements, introducing requirements related to board role and composition, organizational framework and structure, risk culture and business conduct, internal control framework and business continuity management, supervisory reporting and transparency.
  - New Act introduced requirement for a minimum number (two or 25 percent depending on the size of the bank) of independent non-executive directors.
- Risk management framework:
  - BoG Executive Committee Act 243/2/07.07.2025 adopts the EBA guidelines on internal governance (EBA/GL/2021/05).
  - Requires credit institutions to have appropriate risk management strategies approved by the Board of Directors.
  - Board responsibilities include overall risk strategy, the institution’s risk appetite and its risk management framework, ensuring management body devotes sufficient time to risk and risk management issues, risk culture, adequate internal governance and internal control framework.
  - Risk management and internal audit functions required to be independent.
- Supervisory focus and practices:
  - Governance and risk management remain a continued focus given inherent governance challenges facing LSIs.
  - As part of SREP, offsite supervisors review detailed questionnaires, quality of ICAAP and ILAAP, Board minutes, internal audit reports and information from on-sites and meetings with Boards and management.
  - BoG has sanctioned and fined LSIs for governance failings, elevating importance of sound governance.
  - Supervisory actions recommended: comprehensive proactive approach, more forceful and targeted measures such as improving the number and quality of independent directors, enhancing board accountability, fostering a strong risk culture.
  - Supervisors uncovered governance weaknesses through regular monitoring, on-site inspections and specific disclosures.
  - Theme: need for greater challenge by independent directors.
  - Recommendation 3: Heighten supervision of governance, including through on-site inspections, and particularly for larger and riskier LSIs, including a focus on more high-quality independent directors.

### Change of Control and Significant Acquisitions
- Regulatory framework:
  - Acquisitions of a qualifying holding in non-bank financial companies by credit institutions covered by the EU legislative framework as of 11 January 2026 and are meanwhile subject to prior approval of the BoG.
  - Law 4261/2014 art. 15(2)(d) & BoG Governor’s Act 2604/2008, accompanied by clarifications from BoG Banking and Credit Committee Decision 281/10/17.03.2009 provide powers and criteria.
  - Article 24 of Law 4261/2014 sets out five criteria to consider in any application by a potential acquirer of a qualifying holding.
- Limitations and mitigants:
  - EU law does not give authorities power to automatically unwind a transfer of ownership of a bank where it takes place without necessary notification or was based on false information.
  - Under EU Law (Art 22(1) and 23(2) of CRD) the ECB can issue a negative decision and undertake actions such as freezing votes of shareholders based on national implementation of Art 26(2) of CRD.
  - In Greece BoG can deprive the shareholder of voting rights—considered a good mitigant.
  - Recommendation 4: monitor whether EU intends to introduce these changes and BoG should review their processes and include an automatic suspension of voting rights if a change in control approval was based on false information or they had not been properly notified.
- Mergers and approvals:
  - Significant acquisitions or disposals of assets, including mergers of credit institutions, require BoG approval under Law 2515/1997; full information and business plans are required.
  - Mergers/divisions of credit institutions require prior approval of BoG and the MoD. BoG approves from a prudential point of view; MoD approves based on corporate transformations. Both decisions necessary for validity; if BoG objects, MoD cannot approve.
- Recent merger example:
  - BoG approved merger of two LSIs creating the fifth largest bank in Greece.
  - Process included securitization of the majority of the merging banks’ historic NPL book.
  - BoG considered:
    - The business plans of the merged entity.
    - The impact of the securitization and capital injections on the merged bank’s overall capital position and NPL prospects.
    - That the securitization met the BoG’s requirements for Significant Risk Transfer.
    - The suitability of the Board and governance arrangements of the merged entity.
  - BoG and MoD roles were carried out separately; independence of BoG’s prudential decision-making was not compromised.
- HCAP involvement:
  - Hellenic Corporation of Assets and Participations (HCAP), fully owned by the MoEF, keeps a veto power over any strategic decision of participated banks.
  - Example: the fifth largest bank—HCAP retains a 36.2 percent stake and can veto strategic decisions, including any transaction that would result in dilution of its participation (e.g. a new merger).
  - HCAP can only nominate non-executive board members but retains veto power.
  - This is legacy from HFSF and may result in undue interference from the government in market operations and transactions.
  - HCAP does not seem to have a timeline or approved criteria setting conditions for completing divestment in the two remaining banks in which it holds an equity stake.
  - Recommendation 5: Remove the special powers granted to HCAP in relation to its participation in the fifth largest bank.

### Supervision of Core Financial Risks
- Capital
  - Capital calculations are consistent with EU rules; a defining feature of the Greek environment is the scale of Deferred Tax Credits (DTCs).
  - Greece on paper has the same deficiencies as described in the EA FSAP assessment given adoption of EU rules.
  - Most significant gaps not relevant to Greece as banks do not use internal models for credit risk calculation.
  - Capital treatment of bancassurance conglomerates under the ‘Danish compromise’ may become relevant given recent acquisition of an insurer by an SI bank.
  - Some Greek LSIs hold DTCs (Deferred Tax Assets with a government guarantee—see explainer in Appendix 2), with the highest at 30 percent of CET1 Capital.
  - DTCs are a legacy of the crisis and are seen as lowering quality of banks’ balance sheets and impacting the Sovereign / bank nexus.
  - SI banks recently decided to accelerate prudential amortization in proportion to their annual payout of dividends to reduce DTCs faster than the 20-to-30 years originally envisaged.
  - Recommendation 6: Accelerate the legal amortization of DTCs to a timing aligned with the voluntary scheme currently in place for their prudential amortization in SI banks, given that the legal amortization would be applicable to all banks, including LSIs.
- Pillar 2
  - BoG’s Pillar 2 capital add-ons are well-supported and mitigate financial risks identified.
  - P2R is the Pillar 2 surcharge; P2G is guidance (recommended additional capital surplus).
  - BoG runs a systematic and thorough process to arrive at add-ons.
- Credit Risk
  - EU framework contains a thorough approach to credit risk; BoG has implemented the full suite.
  - CRR covers minimum requirements to measure credit risk for capital purposes, including definitions of forbearance, non-performing and defaulted loans (¶58).
  - CRR describes credit granting and monitoring process and contains capital requirements with respect to credit risk, including usage of internal models, need for stress testing (Chapter 3), and use of credit risk mitigation techniques (Chapter 4). The CRD is transposed into Greek national law.
  - Credit risk is the most important financial risk facing LSIs; BoG emphasized it in both offsite and on-site supervision.
  - In period 2022-25, four of BoG’s six LSI inspections focused on credit risk (the other two examined ICT risk).
  - On-site inspection reports evidenced comprehensive review of all relevant aspects of credit risk management with appropriate findings and action points.
  - BoG focuses on collateral valuation, rules around frequency of revaluation and requirement to rotate appraisers are checked at on-site inspections.
- NPLs
  - Greece has been challenged by persistence of high levels of NPLs, largely a legacy of the crisis; although largely securitized to loan servicers, some LSIs retain significant amounts on balance sheets.
  - Judicial process can be very slow—a contributing factor to long tail of legacy NPLs.
  - This issue is covered in the Article IV and in the FSAP Technical Note on Insolvency Creditor Rights and Credit Servicers.
  - Three LSIs have NPLs ranging between 25 and 45 percent.
  - Recommendation 7: Greece should expedite legislative change to address delays in the judicial process for realizing on security and addressing longstanding NPLs.
- Prudential backstop (NPL provisioning)
  - EU Regulation 2019/630 of April 17, 2019 introduced minimum loss coverage for NPLs with a sliding scale depending on time the exposure has not been performing.
  - For legacy (pre-2016) Greek exposures, 100 percent coverage will be required by 2029.
  - The three LSIs with high legacy NPLs had coverage ratios between 40 percent and 60 percent as of end-2024 so the prudential backstop would be expected to have an impact as it is progressively implemented.
  - Recommendation 8: BoG should maintain a strong focus on credit risk and NPLs.

*Source: 1grcea2026005 - 36. The Turkish Banking Supervisor is the only relevant overseas supervisor for LSIs and (IMF PDF chapter).*

### 59. BoG assesses single party, geographic and sectoral concentration risks in LSIs and

### 59. BoG assesses single party, geographic and sectoral concentration risks in LSIs and

### Concentration risks: findings and recommendations
- BoG assesses single party, geographic and sectoral concentration risks in LSIs and these form important inputs to the SREP. P2R add-ons are used when concentration risks are significant.
- The increase in single concentration risk over recent years points to continued vigilance in calibrating the P2R add-on.
- Greece has transposed the ECB regulations, so the EA FSAP findings are relevant.
- Identified gap: absence of a specific requirement for Boards to sign off on all concentration risks in EU / BoG rules. This creates a potential lack of supervisory leverage but is mitigated in practice by off-site questionnaires and on-site inspections that ensure Boards are fully appraised and engaged.
- Recommendation 9: Introduce a requirement for Boards to sign-off on all concentration risks.

### Related party exposures: findings and recommendations
- The EU regulatory framework lacks a requirement to monitor and control separately and in aggregate related party exposures, as requested by the BCPs; the Greek national framework lacks some core elements.
- The EA BCP assessment found EU definitions of a related party are not aligned with the Basel standard; no limits or thresholds triggering supervisory notification or approval are prescribed in EU law.
- Greek law includes a broader definition of related parties but still falls short of the Basel definition: the Greek definition does not include all affiliates of the bank.
- There is no limit on total exposures to related parties in Greek law; the BCPs set such a limit at 25 percent of CET1 Capital. Greek law applies limits only on exposures to each related party.
- EA FSAP noted absence of horizontal or thematic reviews of related party transactions.
- In practice, for Greek LSIs: supervisory attention to related party transactions occurs through SREP and on-site credit inspections; one case led to firm action; there is formal regular reporting of related party exposures.
- Recommendations:
  - Recommendation 10: align the definition of related parties with that of the BCPs by including all affiliated companies and their directors and family.
  - Recommendation 11: introduce a limit on total exposures to related parties of 25 percent of CET1 Capital.

### IRRBB: findings and recommendation
- BoG includes IRRBB in its SREP and imposes a full range of P2R add-ons; the scale of IRRBB risk in some LSIs warrants ongoing supervisory attention.
- BoG has adopted the EBA guidelines and assesses IRRBB from both earnings (Net Interest Income) and an economic value (EVE) perspective.
- Some LSIs carry relatively high IRRBB, "in the range of 30-40 percent of CET1 Capital at risk from a parallel 200bp upward shift."
- Current mitigating factors: Greek banks have experienced low deposit betas and maintained consistently low rates on deposits even during rising interest rates; net interest margins are high; weighted average interest rate on loans is 4.6 percent and on deposits 0.3 percent.
- Risk outlook: IRRBB risk is not as serious or immediate as raw numbers imply, but market dynamics could change quickly (e.g., aggressive new entrants offering better deposit rates).
- Recommendation 12: LSI supervisors should discuss with banks the magnitude of the risk, and ensure that they have a strong risk control framework commensurate with the risk profile, as well as continuing to apply appropriate P2R add-ons.

### Market risk: findings
- Greek LSIs have limited exposure to market risk; BoG’s supervisory attention is appropriately low.
- Only two LSIs report limited trading portfolios; market RWAs in those cases are small ("less than 1 percent and roughly 2.7 percent of total RWAs").
- Supervisors assess market risk as part of SREP and have concluded no specific supervisory action is warranted to date.
- Reporting and quarterly analysis (including six KRIs) would alert supervisors to any change in market risk exposures.

### Operational risk and ICT: findings and recommendation
- BoG’s regulatory and supervisory framework for operational risk is generally comprehensive and effective, but the supervisory task is significant in scope and resource requirements.
- EU framework for operational risk is rooted in the CRD/CRR and Digital Operational Resilience Act (DORA); BoG has incorporated these into local regulations and references the SSM Manual to supervise operational risk.
- In 2018 BoG established a separate department focused on ICT risk; staff grew from about 10 to 17 over the last five years.
- Offsite analysis uses ICAAPs, self-assessment questionnaires, and on-site inspection inputs, feeding into the SREP framework; SREPs are subjected to horizontal analysis for consistency.
- DORA introduces significant demands on banks and supervisors, presenting an ongoing resource allocation challenge with risk of ICT department resource strain.
- Small size and simple business models of most LSIs limit exposure to some operational risks but make attracting ICT expertise difficult; BoG has encouraged ICT expertise on Boards with some success.
- On-site inspections have highlighted ICT as a major risk factor for LSIs and generated numerous recommendations.
- Recommendation 13: Undertake a full strategic review of resource requirements for ICT and in other areas of Supervision under the most pressure, and increase / reallocate resources as appropriate.

### Supervision of liquidity risk: findings
- BoG has fully implemented LCR and NSFR in line with EU regulations.
- The LSI SREP methodology (incorporated via Banking Supervision Directorate circular No. 40) covers:
  - (i) short-term liquidity risk (capacity to meet short-term obligations),
  - (ii) funding sustainability risk (longer-term funding profile sustainability),
  - (iii) liquidity and funding risk management.
- Third country branches (TCBs) are subject to same liquidity requirements as locally incorporated banks.
- LSIs submit ILAAPs annually; these are reviewed thoroughly and feed into SREP risk and control analyses.
- LSIs’ liquidity metrics have been relatively robust: deposits have grown strongly over the last five years while lending grew more slowly; banks have maintained healthy HQLAs.
- Resulting metrics: LCRs over 200 percent across the sector and NSFRs well above the regulatory minimum.
- Given current position, liquidity is not a major priority; BoG will continue monitoring and can focus more on liquidity if circumstances change or as a thematic review.

### Sanctions and enforcement: findings and recommendation
- BoG has powers to impose a wide range of administrative penalties, including financial; this range is set to expand if CRD VI is transposed into national legislation as expected in January 2026.
- New legislation will introduce power to impose periodic penalty payments (PPPs) in addition to administrative penalties and other administrative measures for breaches of relevant laws at national (BoG decisions) and EU level. PPPs act as ongoing deterrents and incentives to quickly remediate issues.
- Over the last five years BoG has imposed sanctions for both AML/CFT and prudential breaches, including removal of individual Board members and fines on individual LSIs.
- Internal process: decisions taken at the CIC with legal sign-off; draft notice communicated to interested party and objections independently assessed; administrative appeals permitted but none lodged.
- Concern: relatively low level of financial penalties imposed.
- Recommendation 14: review and codify clearly the escalation process and review the sanctions matrix so that all sanctions actions are timely, consistent and effective as deterrents.

### Appendix I — Overview of the SSM Supervisory Review Process (summary)
- SREP methodology relies on quantitative and qualitative assessments, overlaid with supervisors’ expert judgement, to derive tailored SREP decisions.
- Methodology built on four elements, tailored per institution:
  - Business model assessment.
  - Internal governance and risk management assessment.
  - Capital assessment — includes risk-by-risk assessment of credit risk, market risk, operational risk and IRRBB, and ICAAP outcomes (governance, capital planning, scenario design and stress testing, independent reviews, documentation, data and infrastructure, risk capture/aggregation).
  - Liquidity assessment — includes risk-by-risk assessment of short-term liquidity, long-term funding sustainability and ILAAP reliability (governance, funding strategy, scenario design, stress testing, contingency funding plan, controls, independent reviews, documentation, data and infrastructure, risk capture/aggregation).
- Sector and economic developments are considered via quarterly risk analysis packs, financial stability reviews, quarterly bulletins, internal policy sessions, SSM priorities, and SSM horizontal assessments.
- Frequency of engagement with each LSI is based on risk profile, business model changes, and the nature, scale, and complexity of the institution.

### Appendix II — Deferred Tax Credits (DTCs): key findings and statistics
- DTC origins: Greek debt crisis; DTAs created from serious losses were converted into DTCs by government law 4172/2013 for DTAs created before 23 November 2016.
- Eligibility categories for conversion into DTCs:
  - Losses from Greek sovereign debt restructuring, amortized over 30 years.
  - Losses due to write-offs and disposal of loans below par, amortized over 20 years.
  - Accumulated provisions and other loan losses due to credit risk, amortized when realized.
- Conversion mechanism: DTCs convert into shares via government injection if a bank makes a loss in any year; conversion percentage equals the year’s losses as a percentage of year-end capital plus year’s losses (illustrative formula provided in source).
- DTCs are a prudential concept: they do not need to be deducted from Common Equity for prudential purposes, so they remain as assets on the balance sheet for prudential purposes; they do not technically “count as CET1 capital” but are not deducted.
- As of end-2024:
  - DTCs stood at the equivalent of 50.1 percent of SIs’ CET1 Capital.
  - For LSIs, the ratio is 2.4 percent.
  - Only three LSIs had DTCs, with the highest at 30 percent of CET1 Capital.
- Market perception: DTCs are perceived as lowering quality of capital due to Sovereign / bank nexus, risk of dilution upon conversion, and reputational legacy effects; authorities and banks are motivated to eliminate them.
- SI initiative: accelerated non-linear prudential amortization of DTCs in proportion to dividend payout to accelerate prudential derecognition by eight years (by 2031-33 instead of 2041); voluntary initiative agreed with SSM.
- Caveat: this is a temporary solution dependent on banks remaining profitable and paying dividends; accounting and tax treatment unchanged.

### Appendix III — Hellenic Asset Protection Schemes (HAPS): key findings and statistics
- HAPS are state-sponsored securitization schemes; 19 SPVs set up since 2019:
  - HAPS I (2019-20) and HAPS II (2022-23) for the four SIs.
  - HAPS III (2024-25) for LSIs.
- Purpose: remove NPLs from banks’ balance sheets to clean balance sheets and allow focus on servicing the economy.
- NPL reduction outcome: NPLs fell from €81 billion (ratio 40.6 percent in Q2 2019) to €6 billion (ratio 3.0 percent in Q4 2024).
- Structure:
  - Each SPV issued senior, mezzanine and junior notes; senior bonds have minimum rating BB+.
  - Transferring bank purchases entirety of senior notes and expected to hold to maturity; transferring bank must retain 5 percent of mezzanine and junior bonds per Securitization Regulation 2017/2402 risk retention.
  - Remaining mezzanine and junior bonds mainly purchased by third party investors, mainly overseas.
- Senior notes:
  - Benefit from a government guarantee enabling a zero percent risk weight for transferring bank holding them.
  - Guarantee triggered only if SPV fails to pay interest when due or principal at final maturity.
  - Under HAPS law, there is no contractual repayment schedule for senior debt except final maturity, which equals final maturity of the longest-dated underlying loan (usually a mortgage).
  - Of the 19 deals, the final maturity varies between 24 years and 56 years as of Q2 2025.
- Performance and risks:
  - As of Q2 2025, total outstanding guaranteed amount was €16.2 billion.
  - This represents a decrease of €4.2 billion (or 21 percent) over the lifetime of the structures, which is less than the projected 36 percent at inception.
  - Two major contributory factors to slower-than-expected resolution: (i) slow judicial process and (ii) underestimate of recovery costs.
  - Although NPLs are off banks’ balance sheets, they remain in the economy, managed by credit servicers, and can pose a risk to economic growth and to the sovereign.

*International Monetary Fund — Greece (selected sections).*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2026/english/1grcea2026005.pdf_
