Law / European Union

EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06), automated models and model governance

EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06)

Guidance, not a law: the European Banking Authority's reading of Capital Requirements Directive, Robust Governance Arrangements of Institutions (Article 74(1)). It binds nobody by itself; the law it reads does.

Guidance on an AI sector rules rule, addressed to public and private bodies.

Private right of action
No
Instrument type
guidance published by a regulator
Obligation class
Governance
Audit expectation
continuous
Who audits it
Self

As of .

What the regulator expects

  • These guidelines are addressed to competent authorities and financial institutions (paragraph 13) and apply from (paragraph 18). They apply to institutions, as defined in point 3 of Article 4(1) of Regulation (EU) No 575/2013, and Section 5, on loan origination, also applies to the creditors that paragraph 6 names under Directive 2014/17/EU and Directive 2008/48/EC. Section 4, which holds the paragraphs on automated models and model governance, and Section 8 apply in relation to all credit risk being taken by institutions, excluding debt securities, derivatives and securities financing transactions (paragraphs 6 and 8).
  • Institutions should specify, in their credit risk policies and procedures, the conditions for the application of automated decision-making in the credit-granting process, including the products, segments and limits for which automated decision-making is allowed (paragraph 38(g)).
  • Institutions should specify the use of any automated models in the creditworthiness assessment and credit decision-making processes in a way that is appropriate to the size, nature and complexity of the credit facility and the types of borrowers, and set out appropriate governance arrangements for the design and use of such models and the management of the associated model risk (paragraph 41).
  • When using technology-enabled innovation for credit-granting purposes, institutions should capture the inherent risks in their risk management and control frameworks, commensurate with the business model, credit risk exposure, complexity of the methods and extent of use, and ensure that the management body sufficiently understands its use, limitations and impact on credit-granting procedures (paragraph 53(a) and (b)).
  • Institutions should understand the underlying models used, including their capabilities, assumptions and limitations, and ensure their traceability, auditability, and robustness and resilience, and ensure that the models are fit for purpose, giving consideration to developing an interpretable model if explanations are required during the models' use (paragraph 53(c) and (d)).
  • Institutions should understand the quality of data and inputs to the model, detect and prevent bias in the credit decision-making process, and ensure safeguards for the confidentiality, integrity and availability of information and systems (paragraph 53(e)).
  • Institutions should ensure that the performance of the model, including the validity and quality of its outputs, is continuously monitored and that appropriate remediation measures are taken in a timely manner in the case of detected issues (paragraph 53(f)).
  • When using automated models for creditworthiness assessment and credit decision-making, institutions should understand the models used, and their methodology, input data, assumptions, limitations and outputs (paragraph 54).
  • Institutions should have in place internal policies and procedures detecting and preventing bias and ensuring the quality of the input data, and measures to ensure the traceability, auditability, and robustness and resilience of the inputs and outputs (paragraph 54(a) and (b)).
  • Institutions should have in place internal policies and procedures ensuring that the quality of the model output is regularly assessed, using measures appropriate to the model's use, including backtesting the performance of the model (paragraph 54(c)).
  • Institutions should have in place control mechanisms, model overrides and escalation procedures within the regular credit decision-making framework, including qualitative approaches, qualitative risk assessment tools (including expert judgment and critical analysis) and quantitative limits (paragraph 54(d)).
  • Institutions should have adequate model documentation that covers the methodology, assumptions and data inputs and the approach to detecting and preventing bias and ensuring the quality of input data, and the use of model outputs in the decision-making process and the monitoring of these automated decisions on the overall quality of the portfolio or products in which these models are used (paragraph 55).
  • The credit decision-making framework should clearly articulate the decision-making powers and limitations of each decision-maker and of any automated models for credit decision-making purposes, in line with the criteria for such models set out in Section 4.3.4 (paragraph 65).

Who enforces it

Enforcement body

The competent authorities of the Member States, which should comply with the guidelines by incorporating them into their practices as appropriate, and which notify the European Banking Authority whether they comply or intend to comply; the guidelines carry no enforcement action of their own.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

The European Banking Authority issued the guidelines pursuant to Article 16 of Regulation (EU) No 1093/2010, and its final report says that, in accordance with Article 16(3), competent authorities and financial institutions must make every effort to comply with the guidelines.

Paragraph 2 says that the guidelines set the European Banking Authority's view of appropriate supervisory practices within the European System of Financial Supervision or of how Union law should be applied in a particular area. Paragraph 5 says that the guidelines specify the internal governance arrangements, processes and mechanisms laid down in Article 74(1) of Directive 2013/36/EU.

Paragraph 5 also says that the guidelines specify the requirements on credit and counterparty risk laid down in Article 79 of that Directive. Paragraph 5 also says that the guidelines specify the requirements in relation to the creditworthiness assessment of the consumer laid down in Chapter 6 of Directive 2014/17/EU and Article 8 of Directive 2008/48/EC. Paragraph 6 says that the guidelines apply to institutions, as defined in point 3 of Article 4(1) of Regulation (EU) No 575/2013.

Paragraph 6 also says that Section 5 applies to creditors, as defined in Article 4(2) of Directive 2014/17/EU where the loan falls under that Directive and as defined in point (b) of Article 3 of Directive 2008/48/EC where the loan falls under that Directive, in each case with the exception the paragraph states. Paragraph 8 says that Sections 4 and 8 apply in relation to all credit risk being taken by institutions, excluding debt securities, derivatives and securities financing transactions.

Paragraph 13 says that the guidelines are addressed to competent authorities, as defined in points (i), (iii), (vi) and (vii) of Article 4(2) of Regulation (EU) No 1093/2010, and financial institutions, as defined in Article 4(1) of Regulation No 1093/2010. Paragraph 18 says that the guidelines apply from .

Paragraph 19 says that Sections 5 and 6 apply to loans and advances originated after , and that Section 5 also applies to existing loans and advances whose terms and conditions have been changed after , where the changes follow a specific credit decision approval and their implementation requires a new loan agreement with the borrower or an addendum to the existing agreement.

Paragraph 22 says that, for Section 8, institutions that lack the information and data needed to monitor existing borrowers or credit facilities granted before the application date should collect the missing information and data until through regular credit review of borrowers. Paragraph 23 repeals the Guidelines on creditworthiness assessment (EBA/GL/2015/11) with effect from the date of application of these guidelines. The European Banking Authority's page for the guidelines gives the status in force and the application date 30/06/2021.

Paragraph 38(g) says that the credit risk policies and procedures should specify the conditions for the application of automated decision-making in the credit-granting process, including identifying products, segments and limits for which automated decision-making is allowed.

Paragraph 41 says that institutions should specify the use of any automated models in the creditworthiness assessment and credit decision-making processes in a way that is appropriate to the size, nature and complexity of the credit facility and the types of borrowers.

Paragraph 41 also says that institutions should set out appropriate governance arrangements for the design and use of such models and the management of the associated model risk, taking into account the criteria set out in Section 4.3.4.

Paragraph 53 says that, when using technology-enabled innovation for credit-granting purposes, institutions should understand the underlying models used, including their capabilities, assumptions and limitations, and ensure their traceability, auditability, and robustness and resilience.

Paragraph 53 also says that institutions should understand the quality of data and inputs to the model and detect and prevent bias in the credit decision-making process, ensuring appropriate safeguards to provide confidentiality, integrity and availability of information and systems.

Paragraph 53 also says that institutions should ensure the performance of the model, including the validity and quality of its outputs, is continuously monitored and appropriate remediation measures are taken in a timely manner in the case of detected issues. Paragraph 54 says that, when using automated models for creditworthiness assessment and credit decision-making, institutions should understand the models used, and their methodology, input data, assumptions, limitations and outputs.

Paragraph 54 also says that institutions should have in place internal policies and procedures detecting and preventing bias and ensuring the quality of the input data. Paragraph 54 also says that institutions should have in place internal policies and procedures ensuring that the quality of the model output is regularly assessed, including backtesting the performance of the model.

Paragraph 54 also says that institutions should have in place control mechanisms, model overrides and escalation procedures within the regular credit decision-making framework.

Paragraph 55 says that institutions should have adequate model documentation that covers the methodology, assumptions and data inputs, and an approach to detecting and preventing bias and ensuring the quality of input data, and the use of model outputs in the decision-making process and the monitoring of these automated decisions on the overall quality of the portfolio or products in which the models are used.

Paragraph 65 says that the credit decision-making framework should clearly articulate the decision-making powers and limitations of each decision-maker and of any automated models for credit decision-making purposes, in line with the criteria for such models set out in Section 4.3.4.

Back to the example  ·  Lint your app