Minimum requirements for internal ratings-based approaches

Note

For institutions with a fiscal year ending October 31 or December 31, respectively.

1. Introduction

OSFI’s Capital Adequacy Requirements (CAR) Guideline permits institutions to calculate regulatory capital for credit risk using an internal ratings-based (IRB) approach.Footnote 1 To be eligible for the IRB approach, institutions need to demonstrate to OSFI that they meet certain minimum requirements both at initial approval and on an ongoing basis.

Institutions should refer to Chapter 5 of the CAR Guideline for the minimum requirements applicable to the IRB approach. The application of these requirements may require interpretation, and institutions need to obtain OSFI approval for their implementation.

This note sets out the principles that institutions should apply when interpreting and meeting the minimum requirements. As these requirements apply across multiple asset classes, the discussion of a particular requirement may refer to more than one asset class.

Please refer to OSFI’s Corporate Governance Guideline for OSFI’s expectations of institution Boards of Directors in regards to the management of capital and liquidity.

2. Overview

The following sections elaborate on the key elements of the minimum requirements for the IRB approach and outline the principles that institutions should apply in meeting those requirements. OSFI will consider adherence to these principles when providing initial approval to use the IRB approach and when assessing institutions’ ongoing use of the approach.

The remainder of this note covers the following six topics of the IRB minimum requirements:

  • Risk quantification
  • Data maintenance
  • Oversight
  • Use of ratings and estimates of default and loss
  • Validating risk rating systems
  • Collateral management

3. Risk quantification

Chapter 5 of the CAR Guideline provides standards for the quantification of key IRB estimates: probability of default (PD), loss given default (LGD), and exposure at default (EAD).Footnote 2

This section of the note elaborates on the CAR Guideline and synthesizes principles for quantification of IRB estimates. The principles apply to all applications of the IRB method that require PD, LGD, and EAD.

Risk quantification is the process of assigning values to the three key risk parameters for IRB assessments of credit risk capital in IRB institutions: PD, LGD, and EAD. Discipline and judgement are required for successful application of the many methods available for risk quantification. Institutions will plan their quantification carefully, with attention to ratings philosophy, governance, and data integrity, along with more technical issues of statistical inference, to ensure that the continuing commitment of resources is effective. Prompt and complete documentation is needed to give credence to the outputs of the rating system and to obtain regulatory approval.

The following sets out principles that OSFI expects institutions to apply to risk quantification, with some discussion and general examples. They are given with the understanding that the application of these principles will be tempered with good judgment. This understanding does not negate the principles, but may restrain their application to avoid undue costs or perverse results. Institutions may encounter situations where the suggested procedures have negligible impact or do not make estimates more robust. In these cases, the institutions may consider other procedures.

Documentation is essential for process review, validation, other aspects of good governance, and future risk quantification, but only to levels of detail that could plausibly be useful. Lists of what "might" be done are not exhaustive and are not meant to discourage institutions from proposing better approaches to risk quantification.

Principles

The methods that institutions use to estimate risk parameters will depend on their portfolio, information systems, expertise, and history. However, all institutions need to establish an effective risk quantification framework that observes the principles outlined in this section.

3.1. Scope of risk quantification

Institutions should demonstrate that each parameter has been reasonably estimated. To do this, they should specify and document all aspects of risk quantification, including sample data, segmentation, estimation, application, and the role and scope of expert judgment.

Documentation for the risk quantification process should describe how all material and relevant aspects of risk quantification are implemented for each parameter. As part of an institution’s risk quantification process, institutions should consider new analytical techniques and evolving industry practices and adopt them if they improve the accuracy of estimates. All material changes to risk quantification should be immediately documented.

3.2. Data from different sources

Institutions will use data from different sources, including sources beyond their control. In risk quantification, institutions should understand the data they use and adjust them for their intended use.

To estimate the IRB parameters, an institution should use data from a population that represents the population to which the parameters will be applied. Not only should the obligors be similar, but characteristics and outcomes should also be defined consistently. If strict consistency is impossible, the institution should make suitable adjustments that, as much as possible, are based on empirical study.

Data from representative populations should be collected and adjusted for the purpose of estimation, which is to provide inputs to the capital formula that comply with the definitions and standards of the CAR Guideline. Institutions should review the data they use, study how they were collected, and compare their characteristics to regulatory standards. The institution should look to the CAR Guideline and other specific guidance for many of these standards, but a few deserve special attention here: definition of default, economic loss, rating philosophy, and the combination of data from different sources.

a) Definition of default

Many public studies of credit loss are based on a definition of default that varies from the definition used in the CAR Guideline. Institutions’ own data developed for pricing and risk management may be based on a different definition. There may be good reasons for institutions to use various definitions in their internal systems. However, institutions are required to compare the estimates for IRB capital to estimates used elsewhere in the institution.

Institutions are also required to use external data that is relevant to IRB estimation and to benchmark their results to external data. Institutions should therefore find ways to adjust estimates to a common definition of default. In order for statistics based on the IRB definition to be compared to other measures of default that are more or less inclusive, institutions’ information systems should flag different default events or horizons.

b) Economic loss

LGD is based on economic loss. Economic loss may be calculated using the exposure at the time of default, including principal, unpaid interest, and fees, and the present value of subsequent recoveries and related expenses discounted at a suitable rate. The institution should model and discount recoveries at a rate reflecting the uncertainty of recovery to arrive at economic, rather than accounting loss. Alternatively, the market value, net of expenses, at or near the time of default is a suitable value for recovery.

Institutions should trace or allocate recoveries and costs of recovery to specific defaulted facilities. Then, institutions should be able to trace or allocate recoveries to homogeneous pools with respect to LGD and to the correct time of default. The allocation of recovery costs may require judgment, but the process should be carefully designed to ensure that all true recovery costs are reasonably allocated. Institutions should test the effect of workout period assumptions on LGD parameters.

c) Rating philosophy

Macroeconomic factors cause credit losses to vary systemically over time. Therefore, institutions should model credit losses so that data collected over a term of years may be fairly compared to data from another term.

Institutions should pay attention to how exposures are classified under rating systems. Some rating systems focus on predicting next year's probability of default; as economic conditions change, ratings assigned to exposures may change dynamically in response. Other rating systems are designed to capture stress conditions and to group risks according to characteristics that are common through economic cycles. Migrations across ratings are infrequent and idiosyncratic; however, the default rate of each rating group changes with the economy. Often, institutions use hybrid rating systems. Institutions should understand the rating methodology behind data they use for parameter estimation and decide whether an adjustment is appropriate to improve quantification and to meet the requirements of the CAR Guideline.

d) Combination of data

Sample data for risk quantification may come from various sources. For example, institutions often combine internal data with external data. When developing IRB standards, institutions should follow their internal standards for the combination of data from different sources to develop IRB estimates. The internal standards should address:

  • consistency in definitions and rating philosophy;
  • weighting data for statistical credibility;
  • similarity of the underlying populations to the targeted portfolio; and
  • the need to extend the data used through economic cycles.

External data will pose special challenges for the application of this principle. However, the need to understand and make suitable adjustments is as important for external data as it is for internal.

3.3. Sufficiency of data

Institutions should document their methods used to address the sufficiency of data in either the sample data or the existing portfolio. Here, professional judgment may play a decisive role, but institutions should ensure that the application of judgement does not result in parameters that provide an optimistic view of the future.

As much as possible, estimates should be based on relevant data, especially data from an institution’s own experience. However, for some portfolios there may be inadequate data. For these portfolios, estimates may be based on careful judgement; however, such judgment should not be biased toward low estimates of risk and reducing required capital. Instead, conservatism should be used to address the uncertainty. The institution should document the reasoning and any empirical support for the estimate, as well as the mechanics of the estimation.

Although this principle allows institutions to use the IRB method when institutions cannot provide at robust estimates from internal or external data, approval to use the IRB method will depend on an institution’s continued efforts to obtain accurate and relevant data.Footnote 3

3.4. Segmentation

Institutions should identify risk drivers to help classify exposures into homogeneous groups. Institutions should justify their segmentation schemes, evaluating the advantages and disadvantages of using fewer or more risk drivers.

Institutions should identify risk driversFootnote 4 for each risk parameter. In selecting which risk drivers to use, an institution should consider its own practices in the origination, acquisition and management of exposure, the practices of peer institutions (where available), and studies from industry associations and academics.

Institutions should use the most discriminating risk drivers to segmentFootnote 5 portfolios into homogenous groupsFootnote 6, i.e., groups that are similar with respect to PD, LGD, or factors used to arrive at EADFootnote 7. An institution should use a risk driver to segment risks if this improves estimates. Granular segments provide more valid estimates as the composition of a loan portfolio changes. However, finer segmentation also results in small groups of obligors.

The observed default rates and loss severity for the small groups will be more volatile, adding uncertainty to risk estimates and validation. In designing their segmentation of risk, institutions should justify their choice of risk drivers and the structure of risk grades to which estimates of PD, LGD, or EAD are assigned.

3.5. Long-run estimation

Institutions should develop their estimates of PD, LGD, and EAD from data collected over a sufficient term to meet the standards of the CAR Guideline. Institutions should study their own experience over time with special attention to the response of their ratings assignment and risk estimates to macroeconomic conditions and changes in risk management.

Institutions should develop IRB parameters using long-term data and should model the behaviour of IRB parameters that result from their methodology through time. The CAR Guideline specifies that institutions should have at least five to seven years of data to use the IRB method, but an average of five to seven years of data may not meet the requirements for a long-term average, and may not meet the requirements to include stress years. For EAD and LGD, institutions should not only incorporate data from stress years, but should also consider the correlation of LGD and EAD to default rates.

3.6. Uncertainty in risk quantification

Parameter estimates are intended to be predictive of future outcomes. Institutions should identify sources of uncertainty in risk quantification and document how they have addressed the uncertainty and the rationale for doing so.

Institutions should estimate values of PD, LGD, and EAD as precisely and accurately as possible. However, such estimates are subject to uncertainty and, therefore, potential errors. In order to avoid over-optimism, an institution may need to adjust its estimates by adding a margin of conservatism. The extent of such adjustments should be related to factors such as the relevance and the quality of the sample data, the precision of the statistical estimates, and the amount and nature of judgment used throughout the process. For example, institutions could produce loss distribution curves and confidence intervals of estimates with different confidence levels.

Institutions should develop policy for the application of conservatism. For each estimate, they should also identify the sources of uncertainty, the range of uncertainty from each source, and the level of conservatism used. This tracking is necessary to assess the overall level of conservatism used, to verify that the level is adequate, and to modify conservatism suitably as new data becomes available.

To build a rational approach to conservatism, institutions should classify sources of error. Many classifications are possible, but there should be a sound connection between the classification and how the institution handles potential for error. Some types of uncertainty may be better handled at different levels of risk quantification than others. The application of conservatism at every step to cover a large portion of outcomes could lead to excessive conservatism overall. Therefore, the institution should focus on adequate margins for capital, rather than for each estimate.

In its classification of sources of error, an institution might address:

  • sampling error resulting from a low number of obligors in the development dataset or a low number of obligors in the portfolio to which it is applied;
  • uncertainty about a long-term average, because the institution cannot adequately sample the entire distribution of macroeconomic effects;
  • uncertainty whether the dataset from which the institution develops an estimate truly represents the population to which the estimate is applied;
  • uncertainty that may arise from suspicion that data has been selected or adjusted in ways inconsistent with the standards or intentions of the CAR Guideline (e.g., arbitrary truncation of values to suit accounting conventions); and
  • uncertainties in the timing and amount of cash flows for LGD estimates, as well as the length of the workout term.

For each source of error, the institution should consider whether the overall degree of conservatism used by the institution is appropriate.

3.7. Response

Risk quantification should be a dynamic process that responds to internal and external events.

Institutions should have a consistent process to ensure that new data are incorporated into the PD, LGD, and EAD estimates as they become available. The need to use fresh internal data is obvious as new business replaces old and long-term customers change. However, institutions should also set up processes to identify and incorporate relevant external data. They should consider changes in the competitive environment that might affect the risk characteristics of their own customers.

Changes in the external environment, the institutions’ own practices and its mix of customers will affect the usefulness of some factors in predicting risk. Reviews of the external and internal environment should be regular and comprehensive. Estimates should be reviewed and updated when required and at least once a year. However, the institution should respond more rapidly to special events.

With respect to each homogeneous pool/grade of risks for IRB estimation, institutions should maintain logs of significant changes to institution practice and the external environment (as applicable) that could be expected to affect the behaviour of the pool or grade.

3.8. Conclusion

Most of the principles for IRB risk quantification elaborated here imply the good practices that institutions should apply in their capital management and projections of loss. Some, such as the attention to macroeconomic factors and the incorporation of conservatism, are requirements of the CAR Guideline that may not be in place for other purposes. All principles should be followed carefully to develop the risk parameters that drive capital under the IRB approach. In particular, institutions should recognize the uncertainties of their data and assumptions; any bias in their calculations should result in higher regulatory capital.

4. Data maintenance

This section of the note elaborates on the data management requirements for institutions adopting the IRB approach as outlined in Chapter 5 of the CAR Guideline. All relevant and material quantitative and qualitative data used to assess and manage credit risk should be adequately maintained. Institutions will need to maintain comprehensive historical data across legal entities and geography. This data will include, but not be limited to, borrower information, credit transaction details, portfolio risk characteristics, ratings, rating migration, default, and collateral.

Data management and timely execution of underlying information technology initiatives are major challenges that institutions need to address in order to successfully implement the IRB methodology under the CAR Guideline. The CAR Guideline outlines the scope and certain characteristics of data maintenance; however, there is limited description of expectations on the data maintenance (or generic “data management”) process itself.

The term “data maintenance” incorporates the key components of the data management process, including data collection, data processing, data access/retrieval and data storage/retention.

The following provides general guidance on data maintenance and principles for institutions to apply when establishing an enterprise-wide IRB framework. These principles are not intended to be prescriptive or limiting in any manner.

Principles

4.1. Senior management and oversight

Institutions seeking IRB approval should adopt an approach to managing their information technology initiatives and data management processes that is appropriate to the nature, scope, and complexity of their data maintenance requirements.

Institutions should have appropriate processes and procedures in place supported by effective Senior Management oversight to ensure successful completion of their programs related to IRB data maintenance for IRB approval and ongoing compliance with the IRB approach.

In particular, institutions’ Senior Management should assess the scope, plans and risks associated with timely execution of data maintenance projects, and take effective measures to mitigate these risks. The accountabilities of Senior Management will include, but are not limited to:

  • Reviewing and approving organizational structure and functions to facilitate development of appropriate data architecture to support implementation of the CAR Guideline;
  • Establishing an enterprise-wide data management framework defining, where appropriate, the institution’s policies, governance, technology, standards and processes to support the data collection, data maintenance, data controls and distribution of processed data, i.e., information;
  • Ensuring data maintenance processes provide security, integrity and auditability of the data from its inception through to its archival and/or logical destruction;
  • Instituting internal audit programs, as appropriate, to provide for periodic independent audits of data maintenance processes and functions; and
  • Ensuring the appropriate policies, procedures and accountabilities are in place to monitor the enterprise-wide observance of the data management framework, including ongoing updates to procedures and documentation, as necessary.

4.2. Data Collection

In the context of the CAR Guideline, the data collection component (also referred to as data acquisition or data capture) would typically involve determining the requisite data elements in various internal or external source systems, and their validation and extraction to appropriate operational data stores or data repositories.

Institutions’ data collection processes should:

  • Establish clear and comprehensive documentation for data definition, collection and aggregation, including data mapping to source/aggregation routines, data schematics where necessary, and other identifiers, if any;
  • Establish standards for data accuracy, completeness, timeliness and reliability;
  • Ensure that data elements collected encompass the necessary scope, depth and reliability to substantiate rating definitions, rating assignment, rating refinement, risk parameters, overrides, back-testing and other processes, capital ratio computations, and relevant management and regulatory reporting;
  • Identify and document data gaps and, where applicable, document the manual or automated workarounds used to close data gaps and meet data requirements;
  • Establish standards, policies and procedures around the cleansing of data through reconciliation identifiers, field validation, reformatting, decomposing or use of consistent standards, as appropriate; and
  • Establish procedures for identifying and reporting on data errors and data linkage breaks to source, downstream and/or external systems.

4.3. Data Processing

The data processing component covers a wide range of data management tasks, including the conversion through multiple systems (or manual processes), transmissions, source and network authentication, validation, reconciliation, and so on.

Institutions’ data processing should:

  • Limit reliance on workarounds and manual data manipulation in order to mitigate the operational risk related to human error and dilution of data integrity;
  • Establish standards and data processing infrastructure for life-cycleFootnote 8 tracking of credit data including, but not limited to, relevant history covering borrowers, obligors, credit facilities, transactions, repayments, rollovers, restructuring, and sale and error trails, as appropriate;
  • Ensure appropriate levels of front-end validation/data cleansing for each process and reconciliation to related processes as applicable, e.g., accounting and general ledger, line of business management information system;
  • Establish adequate controls to ensure processing by authorized staff acting within designated roles and established authorities;
  • Institute appropriate change control procedures for changes to the processing environment, including, where applicable, change initiation, authorization, program modifications, testing, parallel processing, sign-offs, release, library controls; and
  • Provide appropriate levels of disaster back-up, process resumption and recovery capabilities to mitigate loss of data and/or data integrity.

4.4. Data access and retrieval

From OSFI’s supervisory perspective, a key component of data maintenance is the continued availability of institutions’ data and information for the purpose of IRB approval and ongoing monitoring of IRB compliance, such as back-testing, replication, historical, or other trend analyses.

Institutions should ensure that:

  • Data repositories and underlying extract, query and retrieval routines are designed and built to support the institutions’ own data requirements as well as ongoing needs for supervisory assessments of various data as appropriate, including credit portfolios, history, borrower/industry profiles, exposures, process quality, asset class analyses;
  • Access controls and data/information distribution are based on user roles/responsibilities and industry best practices in the context of effective segregation of duties, “need to know”, as validated by institutions’ internal compliance and audit functions; and
  • Access to data/information is not restricted in any arrangements where data maintenance is outsourced to external service provider(s). Notwithstanding these arrangements, institutions should be able to provide data/information at no additional cost.

4.5. Data storage/retention

The data storage/retention component of data maintenance addresses the dual expectations of electronic data retention and archiving to meet the minimum historical retention criteria established under the CAR Guideline, as well as the requirements of institutions and OSFI to ensure ongoing IRB compliance and credit risk management data/information calls.

The CAR Guideline requires institutions to use all relevant data in the development of IRB internal estimates. In order to support internal estimates and ensure that all relevant risks are considered, data may be needed for a long period of time.

For corporate, sovereign and bank exposures, a minimum of five years of underlying history for PD estimates and a minimum of seven years underlying history for LGD and EAD estimates should be maintained. For retail exposures, a minimum of five years of underlying history for PD, LGD, and EAD estimates is required.

In addition, institutions should:

  • Establish documented policies and procedures addressing storage, retention and archival, including, where applicable, the procedures for logical/physical deletion of data and destruction of data storage media and peripherals;
  • Maintain back-ups of relevant data files/stores and data bases in a manner that can facilitate ready availability of the data/information to meet information calls on IRB-compliance and ongoing supervisory assessments; and
  • Ensure that availability of electronic versions for all relevant and material data/information is in a machine-readable format and can be made accessible.

5. Oversight expectations

Institutions planning to use the IRB approach will need to demonstrate to OSFI that their corporate governanceFootnote 9, internal controls, and use of risk ratings are sufficiently advanced and sophisticated to be commensurate with the nature, scope, complexity and risk profile of the institution. In addition, the minimum requirements outlined in Chapter 5 of the CAR Guideline require institutions to ensure that their overall credit risk management practices are consistent with the evolving sound practice guidelines issued by OSFI.

The practices outlined in this section of the note are consistent with OSFI’s assessment of the effectiveness of an institution’s corporate governance and risk management and control practices as described in OSFI’s Supervisory Framework and Corporate Governance Guideline. OSFI will use its reliance-based supervisory approach for assessing the appropriateness and effectiveness of risk management and control practices at IRB institutions, and for assessing their ongoing adherence to minimum requirements.

Principles

Governance activities include setting business strategy and objectives, determining risk appetite, setting capital management strategy, establishing culture and values, developing internal policies, and monitoring performance. These activities need to be included in an effective corporate governance framework that observes principles of strong Senior Management oversight, effective credit risk management and models oversight, appropriate controls to ensure adherence to all applicable IRB minimum requirements, and effective reviews by Internal Audit or an equally independent function.

5.1. Senior management oversight

An institution’s Senior Management should ensure that rigor and discipline are incorporated into the institution’s risk management policies, operational controls, and reporting processes with respect to credit risk. Senior Management should approve all material aspects of the institution’s risk rating and estimation processes.

The use of an IRB institution’s internal loss estimates for regulatory capital purposes will mean that it will be critically important for Senior Management and Credit Risk Management to be proactive, thorough, and timely in carrying out their respective responsibilities relative to IRB minimum requirements.

Senior Management needs to ensure that Credit Risk Management is well positioned to carry out oversight of OSFI’s IRB framework, both at initial approval and post-approval. Credit Risk Management is expected to incorporate the IRB minimum requirements in mandates and accountabilities, risk management processes, and model review activities, where appropriate. Senior Management, Internal Audit, and other control functions should assess the effectiveness of the institution’s internal controls, including those related to rating systems, and whether the institution’s operations to satisfy IRB minimum requirements and results are reliably reported. Senior Management will need to ensure that Credit Risk Management and Internal Audit have adequate resources and skills to carry out the relevant work.

In order to qualify for and maintain IRB status, an institution should ensure that:

  • Senior Management has gained the appropriate level of understanding of the CAR Guideline and, in particular, IRB concepts, the institution’s risk rating system, and associated management reports. Mechanisms to gain the appropriate level of understanding of IRB concepts include awareness sessions and meetings/ discussions between Senior Management, Risk Management, and Internal Audit. These mechanisms allow Senior Management to review the scope of the work to be carried out by Credit Risk Management and Internal Audit for IRB purposes.
  • Senior Management is aware of the impact of OSFI’s framework on the institution’s existing processes of quantification, assessment, monitoring and control/mitigation of credit risk.
  • Senior Management fully understands the critically important role that the use of rating systems plays in meeting the IRB minimum requirements, including the requirement that they receive, on an ongoing basis, periodic reports on whether internal rating systems are operating properly.
  • Mechanisms for application and approval of policy changes or exceptions should be in place.
  • The institution’s risk management policies include accountabilities for the development, implementation and ongoing maintenance of and adherence to practices to meet IRB requirements.
  • Senior Management receives appropriate representations in order to fulfil their responsibilities relating to IRB approval.

In addition, Senior Management should ensure that:

  • the various components of the IRB framework fit together seamlessly and are being appropriately operationalized;
  • incentives to make the system rigorous extend across line, Risk Management and other oversight/control groups; and
  • rating systems provide accurate and consistent internal loss estimates across a range of economic conditions.

Senior Management should take an active role, articulating its expectations for the technical and operational aspects of the rating system and the controls governing this process. Consequently, Senior Management should possess or develop a sound understanding of the design and operation of the rating system, and understand how the institution’s credit policies, underwriting standards, lending practices, and collection and recovery practices affect internal loss estimates.

In addition to overseeing the control processes, Senior Management should regularly interact with risk managers and those responsible for validating the performance of the rating system to discuss the performance of the rating process, areas needing improvement, and the status of efforts to improve previously identified deficiencies.

Senior Management should satisfy itself that the institution meets the use test, such that internal ratings are engrained into the risk management culture and practices of the institution. Internal ratings and estimates of default and loss should be an integral part of credit approval, risk management, internal capital allocation and corporate governance functions of institutions using the IRB approach.

A well-designed rating system plays an important role in institution decision-making and monitoring processes for a number of important activities, including containing the risk profile within the Risk Appetite FrameworkFootnote 10, reserving, portfolio management, performance management, economic capital modelling and management, and regulatory capital management. The use of internal ratings and estimates purely for purposes of regulatory capital reporting, and not for decision-making and monitoring, is not acceptable to OSFI both at initial approval and on an ongoing basis.

For a more fulsome discussion of the ‘use’ test, please refer to section 6 (use of ratings and estimates of default and loss) of this note.

a) Reporting

Management reporting to Senior Management should be timely and comprehensive.

The depth and frequency of information provided to Senior Management should be commensurate with their oversight responsibilities, the significance and type of information being reported, and the condition of the institution. Information provided should be sufficiently detailed to assess the continuing appropriateness of the institution’s rating approach, the adequacy of the controls around the rating system, and the status of adherence to minimum IRB requirements.

As outlined in the IRB minimum requirements in the CAR Guideline, an institution’s credit risk control units, or some other function that is equally independent from origination, are expected to report regularly (at least annually) to Senior Management on the effectiveness of the institution’s rating system.

Risk Management’s reports to Senior Management should include key information and analyses derived from an institution’s rating system for both retail and non-retail exposures, as outlined in the IRB minimum requirements. Such reporting should be at the appropriate level of summary detail for Senior Management. The following fundamental information should be included in the reports:

  • risk profile by grade;
  • risk rating migration across grades, with emphasis on unexpected results;
  • parameter estimates by rating system grade;
  • comparison of realized PD, LGD, and EAD against expectations;
  • potential changes in regulatory and economic capital; and
  • capital stress testing results.

Reports should also incorporate results of ongoing activities related to testing the effectiveness of ratings systems, such as:

  • the results of validation;
  • the comparison of rating system performance against benchmarks; and
  • the exceptions to corporate policies.

Results of Internal Audit reviews related to rating systems and processes should be provided to Senior Management in a timely manner. Material findings should be escalated promptly, as appropriate.

5.2. Credit risk control

Institutions should have a system of robust credit risk control mechanisms that governs the implementation, use, and maintenance of risk rating systems and credit risk management practices.

Institutions should have independent credit risk control units, for non-retail and retail exposures, that are responsible for the design or selection, implementation and performance of their internal rating systems. The unit(s) should be functionally independent from the personnel and management functions responsible for originating exposures.

Standards for credit risk management should be established and be appropriate for each credit risk portfolio. These standards should also be aligned on an enterprise-wide basis, providing consistency and the overall objective of soundness of risk management and measurement.

a) Coverage of ratings

All credit risk exposures should be rated within the institution’s rating systems.

Chapter 5 of the CAR Guideline states that for corporate, sovereign and bank exposures, each borrower, including each separate legal entity and all recognized guarantors, should be assigned a borrower rating and that each exposure should be associated with a facility rating, as part of the loan approval process.

As part of the IRB approval process, and on an ongoing basis, institutions will be required to satisfy OSFI that:

  • Processes have been operationalized to capture and track the rating information throughout the credit origination, approval, and management processes. This tracking should be evident in credit applications, collateral management systems, rating models, and the institution’s management information systems.
  • Rating systems are able to aggregate connected borrowers for non-retail exposures. The institution’s definition of what constitutes a connected exposure should be clearly detailed in policies, providing clear examples of what constitutes a connection, or not.
  • Implementation and practices in use at the institution are in line with the institution’s rating system policies and practices that adhere to IRB minimum requirements.
b) Integrity of rating assignment process

Institutions should be able to demonstrate the integrity of rating assignments with clear accountabilities assigned to ensure independence. The rating assignments and periodic rating reviews should be completed or approved by a party that does not directly stand to benefit from the extension of credit.

Institutions can achieve objective risk ratings through use of an independent rating approval process, i.e., one in which the parties responsible for approving ratings and transactions are separate from the transaction originators. Institutions with a less independent rating process should compensate by strengthening other control and oversight mechanisms. A significant factor in the evaluation of the integrity of the rating assignments will be an assessment of the degree of independence and the strength of the compensating controls.

Responsibility for recommending and approving ratings varies by institution and, quite often, by portfolio. At some institutions, ratings are assigned and approved by relationship managers and/or deal teams. Most institutions have independent credit officers assign and/or approve ratings. Institutions that delegate rating responsibility to relationship managers or deal teams need to ensure that rigorous controls exist to prevent bias from affecting the rating assignment process. Roles and responsibilities of rating assignors should be clearly documented, in line with the objectives in the institution’s rating assignment practices.

Institution policies should articulate who bears ultimate responsibility for rating accuracy and rating system performance. Individuals involved in rating assignment, parameter estimation, and rating system oversight should be held accountable for complying with rating system policies and ensuring that aspects of the rating system within their control are unbiased and as appropriate as possible. For accountability to be effective, it should be both observable and reinforced. These individuals should have the tools and resources necessary to carry out their responsibilities.

With regard to the integrity of rating processes, documented policies and procedures should address the following questions:

  • Who (i.e., oversight functions, line roles, such as the relationship manager or portfolio manager, etc.) will propose or recommend both borrower and facility ratings, initially and for the purposes of periodic reviews?
  • Who has authority to confirm or approve risk ratings (typically an independent function such as Risk Management)?
  • Who is responsible for the verification of rating inputs?
  • Who has the authority to approve exceptions and under what circumstances?
  • Who has the authority to update rating changes in the system and how and when will these be effected?
  • What are the processes to ensure that initial rating assignments and any subsequent rating changes are captured in the institution’s data collection systems?
  • What are the controls to verify that processes are being followed?
  • What are the processes to ensure the findings and recommendations resulting from Internal Audit’s periodic reviews of the rating process are promptly addressed?
c) Transparency

Third parties should be able to observe and understand rating systems’ goals, characteristics, and components.

Transparency refers to the ability of third parties, such as auditors or bank supervisors, to observe and understand a rating system’s goals and the distinguishing characteristics of individual rating grades. The rating definitions should be clear and detailed enough to allow third parties to understand the assignment of ratings, to replicate rating assignments, and to evaluate the appropriateness of the grade/pool assignment.

IRB institutions should have transparency in both the overall rating system and the individual ratings. Absent this principle, the roles, responsibilities and accountabilities of individuals and groups in the business units or oversight functions would be vague, and a comprehensive validation of the rating system’s performance would be difficult.

Transparency requires documentation that captures the following key areas:

  • the design, time horizon, purpose, and performance standards of the rating system;
  • the rating assignment process, including procedures for adjustments and overrides;
  • the rating definitions and criteria, scorecard criteria, and model specifications;
  • the parameter estimates (internal estimates) and the process for their estimation;
  • the definition of the data elements to be warehoused to support controls, oversight, validation, and parameter estimation; and
  • the specific responsibilities of, and performance standards for, individuals and units involved with the rating system and its oversight.

When an institution uses a model to assign risk ratings or develop risk estimates, the model itself may not be transparent without a great deal of effort to document how the model functions. Consequently, in preparation for IRB qualification, and on an ongoing basis, institutions will be required to satisfy OSFI that:

  • Policies clearly define what constitutes a “model.”
  • The institution has a mechanism to maintain an up-to-date inventory of models.
  • The accountabilities of groups responsible for the use, development, validation, and vettingFootnote 11 of models, which may include line or other business units, Credit Risk Management or Internal Audit are clearly outlined.
  • There is a clear distinction between those individuals responsible for model development and those responsible for model validation and vetting. In general, OSFI believes that model development should be in a separate and distinct group from model validation and vetting. However, OSFI recognises that, in some limited circumstances, the same group may perform these activities. Where this occurs, the onus will be on Risk Management to demonstrate how this arrangement provides an effective challenge to model development.
  • Internal Audit has opined on the effectiveness of the model vetting and validation process, including the comprehensiveness of the work and the expertise of those responsible for model vetting and validation.

For a more fulsome discussion of the validation of rating systems, please refer to section 7 (validating risk rating systems) of this note.

5.3. Internal audit

OSFI expects Internal Audit, or an equally independent function, to review the effectiveness of the institution’s internal controls that are intended to ensure adherence to all applicable IRB minimum requirements, including the design elements of internal controls.

Chapter 5 of the CAR Guideline states that Internal Audit, or an equally independent function, should review, at least annually, an institution’s rating system and its operations. Areas of review include adherence to all applicable IRB minimum requirements. Internal Audit should document its findings.

Internal Audit should confirm that an institution’s system of controls over rating systems and their internal estimates are effective. As part of its review of control mechanisms, Internal Audit will evaluate the depth, scope, and quality of credit risk control’s work and will conduct sufficient testing to ensure that their conclusions are well founded. The level of testing will depend on whether Internal Audit is the primary or secondary independent reviewer of that work and the extent of independence of the other reviewer.

Internal Audit is expected to play a critical role in reporting to Senior Management with respect to the effectiveness of an institution’s internal controls designed to ensure adherence to all IRB minimum requirements. This report will contribute to Senior Management’s ability to fulfil their responsibilities with respect to IRB requirements. Results of Internal Audit reviews related to rating systems and processes should be provided to Senior Management in a timely manner. Material findings should be escalated promptly, as appropriate.

In preparation for IRB approval, Internal Audit activities should include, but not be limited to:

  • a review of processes with respect to the initial mapping exercise of the IRB minimum requirements to the audit programs;
  • a review of the detailed two- or three-year audit plan that would indicate the activities that would be reviewed annually and the activities that would be covered on some pre-determined cycle in order to assess the adherence to IRB minimum requirements;
  • a review of the audit scope and assessment of the design and effectiveness of the internal controls intended to ensure adherence to all IRB minimum requirements;
  • a review of reports related to the credit risk control units charged with the responsibility for the design, selection, implementation and validation of the institution’s rating systems. Internal Audit work should include a review of the effectiveness of the internal controls to ensure independence of credit risk control units;
  • an assessment of the adequacy of resources and skills required to perform the new Basel framework audit work; and
  • details of any Internal Audit work that would be outsourced to another, equally independent, function or external audit.

OSFI anticipates that Internal Audit will begin reviewing the design elements and effectiveness of internal controls to meet all applicable IRB minimum requirements as and when these are implemented at the institution. Many of these systems (e.g., loan classification systems) may be in place long before the institution seeks approval for the use of IRB, and Internal Audit should begin incorporating the review of these, as part of their regular audits, at an early date.

6. Use of ratings and estimates of default and loss

This section of the note outlines and explains principles that institutions should apply to satisfy the “use test” requirements in Chapter 5 of the CAR Guideline. Under the IRB methodology, institutions may calculate minimum regulatory capital using their own estimates of loss from their own internal ratings. However, the use test prohibits institutions from using default and loss estimates that are developed for the sole purpose of calculating regulatory capital. Institutions may only use rating systems and loss estimates from these systems if they are used in other operations of the institution.

In their normal operations, institutions develop internal ratings to measure and manage risk. The assumption behind the IRB method is that if ratings and estimates derived from these ratings play an important role in their operation, institutions are likely to ensure that the ratings and estimates derived from these ratings are accurate. Therefore, estimates from these ratings systems can be used to calculate a regulatory capital requirement that better reflects portfolio risks than do estimates calculated on external ratings. Another reason for the development of the IRB approach was to encourage institutions to improve their measurement and management of risk.

The following sets out principles that IRB institutions should apply to the use of ratings and estimates with some discussion and examples. They are given with the understanding that they will be tempered with good judgment. This understanding does not negate the principles, but may restrain their application to avoid undue costs or perverse results. When institutions encounter situations for which the examples given are not appropriate, they should consider other ways to satisfy the principles.

Principles

In discussion of the use test, “operations” should be interpreted as the operations listed in the use test requirements of the CAR Guideline; namely, the credit approval, risk management, internal capital allocations, and corporate governance functions of institutions.Footnote 12

6.1. Pervasive Use

To make the use of the IRB approach credible, internal ratings and estimates of default and loss should be entrenched in institution operations and reporting, including reports to senior management.

Most institutions rate risks to protect themselves from unprofitable credit exposures. However, some are satisfied with excluding the worst applicants for credit exposures and accepting the best, without attempting to estimate absolute levels of loss. IRB institutions should not only rank risks, they should also produce measures of risk that can be reliably translated into the measures defined in the CAR Guideline, especially the parameters PD, EAD, LGD, and maturity.

Institutions may use internal ratings and loss estimates that are not used to calculate IRB regulatory capital. However, the rating systems that are used to generate the inputs to IRB capital calculations should have a use with a material impact on institution operations. OSFI recognises that this may be more challenging for certain exposure classes (e.g., retail exposures); however, the underlying principle here is that the simple existence of models and parameter estimates used solely for regulatory capital purposes is not, in and of itself, sufficient for IRB approval purposes.

6.2. Broad Interpretation

Institutions should interpret internal ratings and default and loss estimates broadly.

An internal credit rating or estimate of credit losses should be considered for the use test even if it does not match all the requirements of the CAR Guideline for internal ratings and default and loss estimates. For example, an issuer of credit cards can claim that the scoring models it develops to predict the probability of going “bad” is using default estimates even if a “bad” account is not “defaulted” according to definitions contained within the CAR Guideline. Further, default and loss estimates may be implicit in models that predict profitability.Footnote 13

A narrow interpretation of “internal ratings” and “estimates” would require institutions to make radical and expensive changes to the functions listed in the CAR Guideline. Ratings and estimates developed specifically for other purposes may do their intended jobs better than ratings and estimates developed to IRB specifications. Risk management measures specified entirely by IRB requirements would likely become outdated, as the CAR Guideline changes infrequently. Accordingly, a narrow interpretation would be inconsistent with two key advantages of the IRB approach: encouraging institutions to develop their ability to manage risk and increasing sensitivity of capital to risk as institutions improve their risk measurement systems.

6.3. Identification

Institutions should identify all uses of risk rating systems, especially implicit or explicit measures of PD, LGD, EAD, and maturity, that are likely to have a material impact on institution operations.

Institutions cannot ensure consistency between estimates of PD, LGD, and EAD used throughout the institution with IRB risk inputs unless they know what they are. Without the maintenance of an inventory, there is little possibility that the institution can guard against the cherry picking of estimates.

This principle applies only to operations that are likely to have a material impact. It does not touch calculations for which the impact of credit losses is likely to be small, or that support recommendations that are not yet adopted. Institutions should be careful to distinguish between direct estimates of default and those parameters ‘backed out’ of models.

Institutions should maintain an inventory of models and estimates. Appendix 5 illustrates information that institutions should retain for retail models. Different information would be useful for non-retail exposures.

6.4. Consistency

Institutions should use estimates for IRB capital calculations that are consistent with the estimates that institutions use for other purposes. In deriving estimates for IRB capital, institutions should recognise risk factors in other operations of risk management, unless these factors have no material relevance.

As set out in the CAR Guideline, institutions need not use the same estimates in all their operations, but estimates should be consistent: one estimate should be plausible given the other. For example, an estimate of PD over one year used for IRB should generally be higher than the PD over six months, and by a factor consistent with the institution’s view of the incidence of defaults for aging exposures.

If the institution recognises a factor as relevant to the estimation or management of credit losses in its operations, it should presume that these factors are relevant to the calculation of IRB parameters, unless it is clear that they are not. For example, if the institution’s calculation of economic capital recognises that LGD varies by different classes of collateral, these classes should play a role in the calculation of IRB capital.

If two estimates used in operations are inconsistent with each other, it may be impossible to arrive at IRB estimates consistent with both. While the institution should aim to develop consistent estimates across its operations, the institution may satisfy the consistency principle by comparing its IRB estimates to the estimates that are most relevant, taking into account:

  • the similarity of the business providing data underlying the estimates to the business for which capital is calculated;
  • any margin of conservatism applied to either estimate; and
  • the institution’s interest in the accuracy of each estimate.

6.5. Reconciliation of estimates

Institutions should reconcile estimates used for IRB capital calculations with other estimates in their inventories.

Reconciliation demonstrates consistency. However, the term “reconciliation” is not to be confused with standards of reconciliation applicable to other financial reporting. Rather, it refers to a reasonable comparison of estimates. For example, an estimate of PD used for IRB regulatory capital purposes should rarely match a PD estimate for the same exposure that is used for pricing (if the defaults in question are defined differently), if only one of the estimates is conditional on current economic conditions, or the estimates are for defaults over different intervals.

Reconciliation is a requirement to demonstrate that differences in estimates are reasonable. It also includes, when estimates match, a demonstration that the use of matching estimates is appropriate, because the same thing is estimated. Appendix 4 further discusses reconciliation.

A reconciliation of estimates may also recognise intended conservatism.

6.6. Conservatism

If there are material discrepancies between the estimates used for IRB and the estimates for another use, the IRB capital requirements should typically be higher than capital requirements when using other estimates.

Institutions should be no less cautious in the calculation of regulatory capital than they are in their operations.

The comparison required by this principle should be done after the reconciliation process has converted estimates for operations to a form suitable to IRB, such as adjustments to account for variations in default and loss definitions.

Institutions should only apply this principle to estimates that have a material impact on their operations and where conservatism has a material cost.

6.7. Integrity

Where possible, institutions should develop default and loss estimates affecting a line of business from a common database, using a common model.

The development of many different databases and models creates many problems. These problems may include:

  • the need to identify and validate many estimates and uses;
  • the burden of reconciliation, which grows with the number of estimates;
  • increased operational risk, especially the possibility that exposures or losses are omitted;
  • the balkanization of data, reducing the precision of estimates; and
  • the possibility of bias in an institution’s choice of data or model for specific purposes.

These problems may be alleviated through the creation of an integrated database and a common model to serve different purposes. Further, an integrated database offers evident advantages for the discovery and validation of new explanatory variables.

There are often plausible reasons to retain distinct models for different purposes. For example, institutions issuing retail business often have different data available for origination than for ongoing account management and the development of provisions. A complex model may also take too much time to run for adjudication, but may be feasible for the estimation of a parameter used in IRB.

Whatever the reason for the use of different models, institutions should consider whether the models tell the same story. For example, the adjudication model might say that PD (or some proxy) depends on a set of given variables. The model used to calculate IRB PD might say that PD depends on another set of given variables. Both models should give the same answer for an average portfolio PD.

7. Validating risk rating systems

The term “rating system” comprises all of the methods, processes, controls, data collection and IT systems that support the assessment of credit risk, the assignment of risk ratings, and the quantification of default and loss estimates.

This section of the note elaborates on section 5.8.7 of Chapter 5 of the CAR Guideline. The principles apply to all rating systems under the IRB method.

Institutions use various rating methodologies and credit risk modelling approaches to differentiate credit quality, and to quantify default likelihood and loss severity. However, a rating system that has not been validated is not suitable for IRB standards. Under the CAR Guideline, ratings will drive minimum capital requirements for credit risk for institutions that are qualified to use the IRB method. Institutions will need to demonstrate the validity of rating systems as one of the minimum standards they must meet in order to obtain OSFI’s approval to use the IRB method.

The following sets out the principles that OSFI expects institutions to apply to validation, including discussion and general examples. They are provided with the understanding that the application of these principles will be tempered with good judgment. This does not negate the principles but may limit their application to avoid undue costs or perverse results.

Institutions may encounter situations in which the suggested procedures have negligible impact or do not help validation. In such cases, the institutions may consider other procedures. Documentation is essential for process review, validation, other aspects of good governance, and future risk quantification, but only to levels of detail that could plausibly be useful. Lists of what "might" be done are not exhaustive and are not meant to discourage institutions from proposing better approaches to validation.

Principles

Institutions will use different methods to validate their rating systems according to their history and current portfolio. To do this, all institutions need to establish an effective validation framework that observes principles of purpose, responsibility, independence, documentation, continuity, scope, response, and perspective. OSFI’s supervisory processes to approve and monitor the ongoing use of the IRB method for the calculation of regulatory capital under the CAR Guideline will include a review of adherence to the principles outlined below.

7.1. Purpose

Validation confirms that rating systems:

  • Identify factors to help discriminate risk;
  • Appropriately quantify measures of risk;
  • Produce measures of risk that have a response to macroeconomic conditions consistent with an institution’s intentions, and that meet the standards of the CAR Guideline for the calculation of IRB capital.

Institutions should have robust systemsFootnote 14 to validate the consistency and accuracy of rating systems, including rating assignment processes and the quantification of all relevant risk parameters. Validation should confirm that assigned risk ratings and risk measuresFootnote 15 react to changes in the credit environment in a manner consistent with a ratings philosophy formally adopted by the institution.Footnote 16 Consequently, an institution’s expectation of the performance of its rating systems should be consistent with its ratings philosophy.

7.2. Responsibility

Institutions validate the performance of their rating systems.

Institutions should designate specific groups to be responsible for the design and performance of the validation process, including the outputs. As rating systems are integral to the management of credit risk, economic capital and other vital matters, the CAR Guideline specifically requires that an institution’s Senior Management understand the operation of the rating system and have a detailed comprehension of its associated management reports. This understanding should include the validation process.

Under the CAR Guideline, Senior Management is also required to ensure that the rating system continues to operate properly. This would include verification that validations are timely and effective, and that the rating system is suitably adjusted to the findings of validation studies. See Appendix 6 on the use of scoring models for which institutions have incomplete information.

7.3. Integrity

The validation process should be independent of the design, operation and consequences of the rating system.

The goal of the validation process is to deliver an effective challenge to the design and operation of the rating system. IRB institutions should therefore demonstrate that the validation process for ratings systems is independent from the personnel and management functions responsible for originating exposures. Those who validate should have the knowledge, resources, accountability and independence to effectively challenge risk rating design, operation and risk quantification.

Overall responsibility for independent review of an institution’s validation processes lies with Internal Audit. While internal auditors may be able to review processes and controls related to validation, they may lack the technical expertise to review highly quantitative elements of validation. In such cases, the review of validation processes and outcomes should be conducted by other groups within the institution’s organization that are independent of those groups responsible for designing, operating and validating institution rating systems.

7.4. Documentation

Institutions should document their validation of rating systems to ensure that parties reviewing the material can understand the objectives of the rating systems, the scope and methodology of validation, and the conclusions drawn from validation activities.

In order to approve the use of parameters drawn from a rating system to drive regulatory capital under the IRB method, OSFI and the institution need clear and comprehensive documentation in order to understand the design of the rating system and the validation of the system. Part of the documentation will be a record of major changes to the risk rating system, as illustrated in Appendix 7 of this note.

7.5. Timing

Institutions should establish regular processes to validate their rating systems, but validation should also respond to special events or circumstances.

As noted in section 7.3, a process is required to show that rating systems and the risk parameters they generate remain valid, and policy should establish a schedule for formal reviews of validation, which should be performed at least once a year. More frequent reviews may be required depending on emerging results, availability of data, changes to validation procedures, and plausible impact on the institution. Institution policy should establish a minimum frequency for the comparison of experience to expectations.

A material change in products, or their distribution, should prompt special analysis to ensure that performance remains adequate. A major change in the rating system itself should also prompt special analysis to ensure that performance remains adequate.

7.6. Scope

Institutions should consider all data and issues that may be material and relevant to the validation of their rating systems.

Institutions may be unable to provide conclusive proof that their rating systems are valid by applying statistical tests, owing to data scarcity and the shortcomings of the tests themselves. Nonetheless, institutions should use whatever statistical tools can assess the likelihood of emerging results, supposing various hypotheses, to inform assessments of the performance of systems and the accuracy of estimates. They should also examine related data from internal and external sources to establish a context for assumptions, calculations and results.

Generally, institutions will arrive at a decision to revise their rating systems after reviewing them from many angles and seeing too many results that are unlikely under the assumed model. Institutions may also decide to revise their rating systems after concluding that this would improve their ability to discriminate risk. No combination of tests will prove conclusively that a rating system is valid, but institutions may construct a mosaic of evidence that provides reasonable confidence to the institution’s Senior Management and regulators.

Institutions should examine a variety of issues, including:

  • the relevance, completeness, consistency and adequacy of inputs;
  • the assumptions embedded in the rating systems;
  • the ability of the rating system to predict future outcomes for the business to which it is applied over a range of conditions;
  • the consistency between the theoretical models and implemented applications; and
  • the appropriate and intended use of the rating system.

To address these issues, institutions will generally need to perform many procedures. A discussion of some possible validation procedures is included in Appendix 8. Institutions should consider the application of these procedures to their own portfolios. In some cases, institutions will need to use other techniques. More elaboration on retail validation is included in Appendix 9.

7.7. Response

Institutions should adjust their ratings systems to take account of reasonable conclusions drawn from validation activities. In particular, they should identify and respond to deviations of experience from expectations that call into question the validity of their rating systems.

Institutions should develop and follow a formal policy to compare realized rates with estimated PDs (LGDs, EADs, or other measures) for each obligor grade. They should demonstrate that the realized default rates are within the expected range for the relevant grade, taking into consideration current conditions and the sensitivity to current conditions consistent with the embedded rating philosophy. Comparisons should also be performed for aggregations of grades.

Institutions should prepare, in advance, criteria to identify outcomes that may be inconsistent with the rating model or the estimates used in risk management. Appropriate adjustments should be made when these results occur. Institutions should compare experience against expectations according to an established schedule. Outputs from a validation, including recommendations from the validation function of the institution, should play an important role in the use and development of the rating system.

7.8. Perspective

Institutions should validate the overall performance, as well as the details, of their rating systems.

As noted in section 7.6, validation assessments are required for all material and relevant rating system elements. However, estimates of details are never exact, and cumulative errors across a number of components may seriously flaw aggregate results. Consequently, institutions should validate at different levels of granularity, as well as validating the overall performance of each rating system, to confirm that aggregate results are reasonable.

7.9. Conclusion

The validation of a rating system requires a continuing commitment of resources. The use of these resources will be most effective if the process is carefully planned, with due attention to ratings philosophy, governance and data integrity along with more technical issues of statistical inference. Once the validation is completed and documented, the outputs of the rating system will obtain credibility and applicability and acceptance in the institution’s risk management systems.

8. Collateral management principles

This section of the note outlines principles around Collateral Management Systems (CMS) for the purposes of approving internal risk rating systems (rating systems) for the IRB methodology and minimum regulatory capital calculation under the CAR Guideline.

This section is used to set out OSFI expectations relative to the minimum standards for IRB with respect to collateral management. It articulates principles for collateral management on the understanding that risk-based assessments will underpin each institution’s approach to collateral management. The document was written primarily with wholesale exposures in mind; changes in emphasis or content may be needed for other exposure classes and their associated risk mitigants.

Sound management and effective control of the techniques and collateral used for credit risk mitigation is a fundamental component of effective risk management. Institutions will use various systems and processes to manage collateral and will need to demonstrate that they have established effective collateral management policies, procedures and methodologies for the purposes of IRB approval and ongoing use of the IRB approach. In particular, institutions will need to demonstrate that the policies and procedures are appropriate for the level of capital relief they receive from the risk mitigation techniques employed.

Principles

Institutions use different techniques to mitigate credit risk. However, all institutions need to establish collateral management systems and operational procedures and processes throughout the organization that observe principles of purpose, documentation, consistency, legal certainty and timeliness, risk identification, valuation, inspection, verification, operations, and reporting. The principles governing the collateral management policies and practices should be interpreted and applied consistently throughout the organization, but the implementation processes can vary within and among institutions.

The term “CMS” refers to all the systems, methods, processes, controls, data collection and IT systems that are used in the taking, management, valuation, maintenance, and realization of collateral held for credit risk mitigation purposes.

8.1. Purpose

In order for collateral to be recognised for regulatory capital purposes, institutions must meet all of the requirements with respect to IRB minimum standards and other qualifying criteria outlined in the CAR Guideline and demonstrate adherence to the under-noted CMS principles. At a minimum, individual institutions will adopt practices appropriate to their circumstances, risk profiles and their risk assessment, and business strategies.

8.2. Risk Management policies and documentation

Comprehensive collateral management principles, procedures, and processes should be incorporated or provided for institutions’ documented risk management policies.

Institutions should establish and maintain fully documented policies, procedures, and practices surrounding the scope, purpose, and use of the CMS, such that they can be readily understood by, and be available to, users and parties reviewing the material.Footnote 17

Appropriate documentation will help ensure that users understand the objectives of the system and how well these objectives are met, thereby reducing the possibility that the system will be used inconsistently.

8.3. Consistency of collateral definitions

Institutions will need to ensure consistency of definitions used throughout the organization for all collateral types to ensure that data systems capture consistent recovery rates for validation of internal loss estimates.

Definitions need to provide sufficient clarity to promote consistent treatment of collateral, thereby avoiding interpretive differences across different business units. To the extent that differences remain, they should be identified and supported for purposes of their acceptability in the risk quantification process.

8.4. Legal certainty and timeliness

Institutions’ collateral management systems should ensure that all necessary steps have been taken to fulfill legal requirements to secure an institution’s interest in the collateral, so that it has and maintains an enforceable security interest.

All documentation used in collateralizing a transaction should be binding on all parties and legally enforceable in all relevant jurisdictions. Institutions should have conducted sufficient legal review to verify this conclusion, should have a well-founded legal basis for this conclusion, and should re-conduct such a review, as necessary, to ensure continuing legal enforceability. For example, such a review may include the institution’s current practices, including reviews of standardized forms. An institution’s documentation and policies should also ensure that it has the legal right to take control, liquidate, or otherwise deal with the collateral in a timely fashion.

8.5. Comprehensive assessment of risks

Institutions will need to have policies and procedures to manage relevant and material risks that may arise from the use of collateral to mitigate credit risk.

Institutions should have clear definitions of the types of risks that arise in respect of collateral management and the associated processes and procedures used to manage these risks.

8.6. Valuations, inspections, and verifications

Institutions’ policies should explicitly define how and when to value, re-value, inspect, and verify collateral.

Collateral valuation estimates should be conservative to allow for the imprecision inherent in most collateral value estimates, particularly where there is no readily available market value.

Different asset types, collateral types, and borrowers’ risk profiles may require different processes and procedures for valuation, frequency of evaluation (and re-evaluation), and inspection and verification. Institutions’ policies should explicitly document and define the requirements for each process and the rationale for the approach adopted. Mark-to-market policies and procedures for financial collateral must be explicit and incorporate suitable control mechanisms.

Certain collateral types may require periodic verification and/or physical examination. Consequently, institutions should establish policies and procedures around these activities and track the application of these requirements to ensure consistency of application and control.

Institutions should document appropriate early warning indicators for various collateral types, where they find such indicators appropriate and provide the action requirements to be followed as a result of material changes to collateral value. Institutions should document their processes around the design and review of what they consider appropriate early warning indicators for various collateral types. In addition, institutions should document the associated action requirements that should be followed as a result of material changes to these early warning signals.

8.7. Operational Requirements

Institutions should examine all relevant and material data to ensure a complete collateral data set for the purposes of assessing the risk-mitigation benefits of collateral and developing internal loss estimates.

The examination of relevant and material data should include a review of a variety of data such as the collateral type, the loan-to-value parameters, the historical collateral values by obligor, the valuation and revaluation criteria, the collection costs tied to loans, the physical location of collateral (where applicable), and the associated recovery rates.

8.8. Internal reporting and analysis

Institutions will need to ensure that the internal reporting and analysis capability of the CMS supports key risk identification and mitigation and can therefore be used to inform risk management.

In addition to analysis of loss and recovery experience, the system must include internal reporting and analysis capabilities in order to provide ongoing support to the risk management process (see section i of Appendix 10).

8.9. Disclosure

Institutions will need to comply with all the disclosure requirements under OSFI’s Pillar 3 Disclosure Expectations as they relate to credit risk mitigation, including general credit risk exposures, disclosures specific to portfolios subject to IRB approaches, and credit risk mitigation-specific disclosures.

The Pillar 3 Disclosure Expectations set out the disclosure requirements for IRB institutions in respect of the credit risk mitigation techniques they employ. Institutions should therefore ensure their CMS support such disclosure requirements.

Appendix 1: Data maintenance (section 4) - data life cycle

Management oversight. Text version below.
Management oversight - Text version

This figure presents data management requirements under Management Oversight across four areas arranged from left to right: Data Collection, Data Processing, Data Retrieval, and Data Storage. Four downward arrows extend from the Management Oversight banner to each area, indicating that management oversight applies to all four functions.

Data Collection includes establishing thorough documentation, including data definitions/identifiers; capturing accurate, complete, and timely data from reliable sources; ensuring collected data encompasses the scope, depth and reliability needed to substantiate all processes and purposes; identifying and documenting data gaps; documenting manual/automated workarounds used to close data gaps; pre-cleanse data activities such as reconciliation identifiers, field validation, reformatting and decomposing; and ongoing reviews to identify and report data errors and data linkage breaks to source.

Data Processing includes limiting reliance on manual workarounds/manipulation; establishing standards and data process infrastructure for life-cycle tracking, including relevant history; ensuring appropriate levels of front-end validation at each process and reconciliation stage; establishing adequate controls to ensure authorization; establishing change control procedures; and providing appropriate levels of disaster back-up, process resumption and recovery capabilities.

Data Retrieval includes maintaining data repositories that support the institution's own data requirements and ongoing supervisory needs and ensuring access controls and distribution are based on user roles and industry best practices.

Data Storage includes meeting minimum historical data retention/archival criteria as per CAR, maintaining back-ups, and ensuring electronic versions of data are in machine-readable formats.

A solid horizontal arrow flows from Data Collection toward Data Storage, representing the movement of data across the lifecycle. The area along this flow is labeled Data In Transit and includes the requirements that OSFI's access to data is not restricted in any way and that the institution is to provide data at no cost to OSFI. A horizontal dotted line extends from the Data Storage back to Data Collection. It depicts a return flow from later stages of the data lifecycle back to the data collection function.

Within Data Storage, a downward arrow connects Data At Rest to Archived Data, and a second downward arrow connects Archived Data to Data Deletion, illustrating the progression of stored data through archival and eventual deletion. Overall, the figure depicts the lifecycle of data from collection, processing, retrieval, and storage through archiving and deletion, under ongoing management oversight.

Appendix 2: Use of ratings and estimates of default and loss (section 6) – examples of the application of the use test principles

Consistency and Reconciliation

1. Defaults defined over different terms

If an institution has reason to believe that the risk of default is reasonably constant through the tenor of a loan, it may reconcile PDt, to PDs, defined over terms t and s, respectively, through the formula (1−PDt)^(1/t)=(1−PDs)^(1/s). However, many loans exhibit strong seasoning effects. In this case, reconciliation would need to take into account the variation of default risk through time.

2. Differing default events

If one definition of default covers a different list of events than the definition of default used for IRB estimates, the institution should study the relative incidence of these events to justify the relationship between resulting estimates of PD, LGD, and EAD.

3. Differing definition of loss

Institutions should verify that estimates of loss are consistent, and verify differences. In particular, institutions should reconcile the economic losses used for IRB estimates to accounting estimates and data.

4. Components of loss

If non-IRB estimates are analysed into PD, LGD and EAD, the product should be reconciled to the product of PD, LGD, and EAD used for IRB after each component has been suitably adjusted (e.g., for differing definitions or terms) and reconciled individually. For some purposes, institutions may report and estimate losses without an analysis into PD, LGD and EAD as required for the calculation of IRB capital. Estimates of total loss to the total losses implied by PD*EAD*LGD from IRB estimates should be reconciled after other appropriate adjustments.

The institution should ensure a sensible relationship between current default estimates, long-term estimates, and the current default experience of other lenders in the same sector.

Appendix 3: Use of ratings and estimates of default and loss (section 6) – the relevance of acquisition and behaviour scores for retail and SME enterprise exposures

In their retail operations, institutions develop scores or other indicators that are useful in predicting events that are highly correlated with default as defined in the CAR Guideline. For example, scores may predict the probability of going "bad" over a horizon of 18 months. The scores are often used in decisions to extend more credit, to reduce limits, or to pursue full payment of outstanding loans. At acquisition, these scores are generally based on data from credit data agencies. Later, scores are enriched with data from the institution's own files, especially records of customers’ behaviour. As such, these scores are referred to as “behaviour scores.”

Section 6.3 of this note directs institutions to identify various measures of risk used in the management of the institution, and section 6.5 calls for their reconciliation. As drivers of ratings and measures of the likelihood of default (although not necessarily default as defined in the CAR Guideline), behaviour and acquisition scores should be identified and reviewed for consistency with IRB estimates. However, the depth of this review should be commensurate with the relevance of the score to the IRB estimates.

Institutions may be able to demonstrate that once behaviour scores are available, acquisition scores are irrelevant to the management of accounts and the prediction of risk: knowing acquisition scores in addition to behaviour scores does not help predict defaults.Footnote 18 This is strong evidence that acquisition scores do not affect the credibility of IRB estimates once behaviour scores replace them in the management of accounts and other functions sensitive to credit risk, such as the establishment of provisions and the measurement of economic capital.

With this evidence, there is no need to reconcile acquisition scores to IRB estimates for any business managed by behaviour scores, or to consider whether IRB segmentation is as predictive as acquisition scores. It is sufficient to compare IRB estimates to odds derived from behaviour scores and verify that the major drivers of behaviour scores are recognized in IRB segmentation.

Any institution that is originating transactions will have some business for which there are only acquisition scores. If this is material, the institution should compare the credit quality as predicted by acquisition scores to IRB estimates of PD.

Appendix 4: Use of ratings and estimates of default and loss (section 6) – reconciliation of estimates

As outlined in section 6.5 of this note, institutions should reconcile different estimates of default to their IRB inputs. Because both IRB and other estimates are subject to uncertainty, this reconciliation cannot be precise. When two estimates are bound by tight confidence intervals, apply to the same population, and differ only in one well-defined aspect (such as days’ delinquency to default), a close reconciliation should be possible. In other circumstances it may be possible only to demonstrate that the difference between the estimates is in the right direction.

The first step in this reconciliation is to determine what estimates are relevant and the degree of precision in these estimates. Generally, an estimate is relevant to an IRB estimate if it is applied to the same exposures.

The next step in this reconciliation is to identify how the development of the estimates differed in ways that might affect measures of risk. Some measures to consider are:

  • definition of default,
  • horizon for a probability measure,
  • population from which data are taken,
  • population to which data are applied,
  • segmentation of the estimates,
  • time of data collection,
  • response to environmental factors,
  • adjustments to arrive at a long-term average,
  • conservatism.

Institutions will think of other relevant factors. After identifying the differences in the development of the estimates, institutions should calculate the most likely effect of each difference, as well as a possible range. Finally, institutions should consider whether the aggregated differences could bring one estimate within the confidence interval surrounding the other.

An abridged example of reconciliation of a behaviour score bad rates to IRB PDs
 DifferenceBasis for probable effectEffect, Range
Definition of default
  • Behaviour score delinquency – 60 day
  • IRB - 90 day delinquency
Repeated comparisons in different years show that the 60-day definition results in X% higher defaults.X%, +/− E1%
Population
  • Development population for score - all cards.
  • IRB score applied to Gold Cards
For a given score, Gold cards have traditionally had a W% lower bad rate than average for all cards.W%, +/− E2%
Horizon
  • For behaviour scores, 18 months
  • For IRB, 1 year
Company studies show that if the retail PD over one year is between .005 and .02, the probability of default over 18 months is Z% higher.Z %, +/− E3%
Time of data collection
  • Behaviour scores most recently calibrated to data collected calendar year 2003.
  • IRB PD developed from time series of default rates 1997-2003, before adjustment for conservatism and long-term PD
Behaviour scores may be designed to be insensitive to economic cycle. Studies show that these behaviour scores give similar bad rates in good times as in recession. Changes in environment affect the distribution of scores. To overcome this difficulty, reconciliation will be of PDs aggregated across score bands used to segment IRB default rates.No effect expected within grades.
Adjustments to arrive at long-term average
  • None for behavior score
  • IRB is developed by adjusting average of a time series of observed default rates
Reconciliation will be done to IRB estimates before application of conservatism and adjustment to arrive at long-term average.Not applicable
Conservatism
  • No margin of conservatism in behaviour score. See above.
Reconciliation will be between estimates before margins of conservatism.Not applicable

The institution should determine how to aggregate the individual effects and arrive at a reasonable range of possibilities. It would then compare the behaviour score, adjusted for the aggregate effects of the differences, to the IRB PD, calculated before adjustment, to arrive at a long-term average and the addition of margins for conservatism. The institution would then decide whether the estimates are consistent. At best, given the many differences between the estimates, the institution might be able to decide that the aggregate probability of going bad predicted by the behaviour, could plausibly fall between 1.10 and 1.90 times the aggregate IRB for the same population, before adjustment to arrive at a long-term average and addition of margins of conservatism.

Appendix 5: Use of ratings and estimates of default and loss (section 6) - retail model inventory

Section 6.4 of this note outlines that institutions should maintain clear and comprehensive documentation regarding the objectives, scope and design of the rating systems. For retail exposures of retail risk rating systems where there could be multiple risk rating models, the following sample inventory listing could be used to summarize the rating system design and relevance of the models.

Name of ModelSpecific Product / PortfolioPurpose or TypeExposure ClassImplementation DateLast Validation DateNumber of AccountsExposure AmountDefinition of Event (Good/Bad)DescriptionReference Document
Residential MortgagesResidential Mortgage ApplicationAcquisitionResidential MortgageDec-00Mar-0410,0001.5 Billion90+ daysIncorporates credit bureau data to approve/decline/refer applications.Detailed documentation, methodology, development and validation of the model.
Card ProductsProduct 1Account ManagementQRREDec-01Feb-04100,000300 million60+ daysVendor developed model based on internal data.Detailed documentation, methodology, development and validation of the model.
Product 2IRB PD EstimationQRREFeb-04Jun-0495,000285 million180+ daysInternally developed model based on 5 years of internal data.Detailed documentation, methodology, development and validation of the model.
Personal LoansThinOriginationOther RetailOct-03Dec-0380,000240 million60+ daysOrigination model, based on credit bureau data and application characteristics.Detailed documentation, methodology, development and validation of the model.
Thick/CleanOriginationOther RetailSep-03Nov-03115,000345 million60+ daysOrigination model, based on credit bureau data and application characteristics.Detailed documentation, methodology, development and validation of the model.

Appendix 6: Validating risk rating systems (section 7) - use of scoring models for which institutions have incomplete information

Institutions are required to segment risks into homogeneous pools for the calculation of PD. For this segmentation, some institutions would like to use credit scoresFootnote 19 developed by external vendors to distinguish high risks from low risks. The developer may use data from other institutions. To protect the confidence of contributing institutions and their customers, developers may not share the full development dataset. Users of the scores may look at summary statistics or extracts from the development file, but the cost of doing this is material. Whether or not the institution can see full details of the dataset, the developer may consider the logic underlying a score as valuable intellectual property, and will not share the details with institutions.

Section 5.8.3 (vi) of chapter 5 of the CAR Guideline require documentation of design, rating criteria, and inputs to a system. Compliance with these requirements may be difficult when data collection is in the hands of a third party and details of the model generating scores are considered proprietary information. However, institutions may not ignore these requirements. Paragraph 234 of chapter 5 of the CAR Guideline states that the fact that a model uses proprietary technology from a third-party vendor does not exempt an institution from standards for rating systems or documentation.

The use of a credit score for retail segmentation is similar to the use of expert judgement in corporate underwriting, mapping to external rating systems, and using external benchmarks. These are expressly permitted or required by CAR, even though it is unlikely that institutions will be able to document all the processes behind an expert's judgment, the decisions of an external rating system, or the development of an external benchmark. Similarly, institutions may use credit scores to segment retail risks into homogeneous pools to develop IRB parameters, even without seeing all the development data, and without knowing the precise details of the scoring formula.

A model may use an input if it works reliably under all anticipated conditions. Although comforting, knowing the details of how an input was produced is neither sufficient nor absolutely necessary. For example, an input to structural models of credit risk is stock price, determined by thousands of individual investor decisions that may never be known, much less understood.

The use of credit scores to segment retail risks into homogeneous pools for the estimation of IRB PD depends on the empirical observation that the scores and PD are highly correlated. Scores are developed to predict the risk of default. Given the similarity of the definitions, one would not expect them to be independent. However, institutions should confirm the high degree of correlation.

Institutions are unlikely to want to use credits scores in the management of their retail accounts without having confidence in the integrity of the scores’ development and their continuing accuracy in predicting the odds of an account going bad. It is in the interest of developers to provide assurance to institutions.

In summary, institutions may use credit scores to segment risks for IRB estimation without having complete information about the underlying data or model. However, the institution should obtain information and perform analysis to ensure that the scores are relevant to the risks and are properly used. Normally this would include:

  1. From the developer
    • An exposition of the general methodology for developing scores, e.g., a specific type of neural network, logistic, or probit.
    • An understanding of the data available for modelling.
    • A statement of the purpose of the model, its intended output, and the conditions under which it is expected to work.
    • Historical performance of scoring models that the developer has built using this methodology.
    • A statistical profile of the development population.
    • An explanation of the developer's process to monitor and change the model when necessary.
    • Contractual undertakings to report the performance of the model and the statistical characteristics of the population against which its performance is measured.
    • Contractual undertakings to report any changes to the model.
  2. To assure the validity of the behaviour score as a relevant basis for segmentation, the institution should
    • review industry and academic literature to understand the strengths and weaknesses of the methodology used to develop the score
    • review the statistical profile of the development population
    • regularly recalibrate the score to the institution’s own customers, and confirm that the score accurately predicts the odds of going "bad" (or whatever event the score is designed to predict)
    • periodically calculate the correlation of the score to the probability of default as defined in the CAR Guideline
    • track the relation of the score to the definition of PD through time
    • test the power of the score to discriminate the risk of default

Appendix 7: Validating risk rating systems (section 7) - history of major changes

An institution must document a history of major changes in the risk rating process, and such documentation must support identification of changes made to the risk rating process subsequent to the last supervisory review. (paragraph 231 of chapter 5 of the CAR Guideline).

Further, under the principles included in section 3 and under section 7.5 of this note, institutions should track events and conditions that are likely to affect risk characteristics of their portfolios.

Institutions are expected to use this history as a tool to perform the following:

  • identify the need to change rating systems for adjusting estimates;
  • decide whether data remain relevant for estimating future outcomes for various exposures;
  • adjust parameters as the characteristics of the exposures to which they are applied change; and
  • interpret comparisons of observed outcomes against predictions.

Institutions should use sound judgment in deciding which changes, events, and conditions should be tracked. However, the following data could be useful for tracking purposes:

  • Date of change
  • Portfolio affected
  • Size of portfolio affected
  • Expected effect on PD, LGD, EAD
  • Type of change or event
  • Institution induced
    • Distribution method
  • Adjudication
    • New rating criteria
    • New cut off score
    • New behaviour score
  • Management of accounts
    • Reporting
    • Covenant policy
    • Collateral requirements
  • Environmental
    • New competing products or method of distribution
    • Changes in employment, housing prices, and so on.

Appendix 8: Validation of risk rating systems (section 7) – procedures generally required in a validation

This Appendix includes a list of potential validation procedures. Institutions should consider the application (and relevance) of this list to their own portfolios and may need to add or amend procedures according to their internal validation requirements. This list is provisional and may not be adequate for all institutions. It is the institution’s responsibility to validate, and this may require other procedures.

  1. Replication

    Verification that the rating assignment and risk quantification processes can be replicated following documented procedures and policies.

  2. A review of the logic and conceptual soundness of the rating system

    This should include a review of the implied ‘rating philosophy.’

  3. An audit of the information technology providing inputs to the system

    See section 4 of this note.

  4. Accuracy testing

    The validation should assess the discriminative power of the rating system and the reasonableness of the estimates of PDs and LGDs using prevailing tests. Institutions should also assess whether their ratings philosophies have been successfully and consistently implemented. For this, an analysis of regularly updated rating transition matrices may be of assistance.

  5. Sensitivity testing

    A validation should analyse the sensitivity of model outputs to model assumptions and to model inputs.

  6. Scenario testing

    A validation should identify possible events or future changes in economic conditions and assess the effect of these scenarios on rating assignment and risk quantification.

  7. Back testing

    A validation should regularly compare model outputs against subsequent real-world events and the rating system’s actual, realised performance.

  8. An inventory and analysis of the use of the rating system

    See section 6 of this note.

  9. A review of comparable external data

    The relevance of external data used and its consistency with internal data should be investigated and fully documented. Often, this will require a comparison of the definitions of default and loss. Institutions should attempt to reconcile internal and relevant external estimates of risk parameters covering comparable risks.

    In some circumstances, a formal benchmarking to external public rating systems will help confirm internal ratings and PDs. If internal data is limited, institutions should consider using estimates that incorporate some external results.

  10. Special attention to overrides and other exceptions

    Institutions should develop and implement a policy regarding how overrides and other exceptional business are fed back into the ongoing validation framework. All exceptions to the standard model or processing should be identified, documented and reported to those responsible for the design and performance of validations.

Appendix 9: Validation of risk rating systems (section 7) - external data and retail validation

The CAR Guideline calls on institutions’ validation procedures to incorporate all relevant, material and available data, information and methods. These principles of validation call on institutions to use data from internal and external sources. Appendix 8 of this note calls on institutions to review external data.

Institutions recognize the need to refer to external data in the quantification and validation of ratings and estimates for corporate portfolios, because, on their own, corporate portfolios generally have too few exposures and losses for credible estimates of PD, LGD, and EAD. The need to look at external data is not as obvious for the validation of retail portfolios, which usually generate ample data.

Although the sampling error in their internal data will be small, retail institutions may need to look outside their institution (for example, consider macroeconomic data) in their validation of IRB estimates. A review of events and results outside the institution may be useful for:

  1. Establishing the position of the dataset used to estimate parameters in the economic cycle

    The retail market and the management of retail accounts evolve rapidly. It is therefore difficult for an institution to distinguish the fluctuation of loss events that arise from changing market conditions or account management from the effects of the economic cycle. A review of the experience of other providers of retail credit may inform the institution’s assessment of the relative impact of management and economic factors and the calibration of estimates to achieve a long-term average.

    Although the external data may not be directly comparable to the product in question, the changes from year to year may inform the institution about macroeconomic events that do not depend on product. Securitisations may provide information about credit card experience. Performance metrics from the Bank of Canada, Statistics Canada, and the Canadian Bankers Association also provide useful information about retail credit performance. Although this data will include the exposures of other institutions with different marketing strategies, the observed fluctuations in aggregate results will likely reflect very general drivers.

  2. Interpreting discrepancies between an institution’s long-term averages and results observed in particular years

    Observed losses that come close to expected losses calculated from IRB estimates do not confirm the accuracy of the IRB estimates as long-term averages if all other credit institutions report lighter losses than usual. The results from peers may suggest that the current conditions are favourable, and that long-term losses should be well above current results. Similarly, losses that exceed what is predicted by IRB estimates do not show that the IRB estimates are inadequate if all credit institutions report unusually heavy losses.

  3. Anticipating the effects of changes in the marketplace

    Changes in the marketplace will affect the amount and quality of business acquired by individual institutions. Institutions may see signs of these changes from a review of internal evidence, but they will have better knowledge of these changes from a survey of industry practices, tabulations of market share, and other external data. Changes in the marketplace may suggest adjustments to estimates based on aging data.

Appendix 10: Collateral management (section 8) - policies and procedures for collateral management systems

There are numerous policies and procedures that institutions will likely be required to undertake to ensure their CMS are appropriate. Institutions should perform activities that are appropriate for their credit risk portfolios and support the credit risk mitigation techniques employed.

1. Risk management policies

Collateral management principles should be incorporated into institutions’ risk management policies.

Risk management policies should be comprehensive and clear as they relate to collateral management. Collateral management principles should be established for an institution, including any principles that are specific to business units. Policies and procedures should be reflected in the collateral management processes and systems that have been (or will be) implemented. The impact of compliance and non-compliance with these principles should be well understood by those responsible for implementing, maintaining and monitoring the system.

2. Collateral definitions and data collection

An institution’s policies should be consistent across the institution for collateral definitions and data collection. Institutions’ policies should give clear direction as to what constitutes relevant and material risks as they relate to collateral for credit risk mitigation. CMS should be sufficiently robust to assess relevant and material risks on an ongoing basis.

While it is recognized that business units within an institution will have different types of collateral classes that are prevalent and used for credit risk mitigation purposes, the definitions of these collateral classes need to be consistent across the enterprise. Definitions need to provide sufficient clarity to avoid interpretive differences that might arise from different practices and treatments across different business units within an institution.

Policies and procedures should address what constitutes material changes to collateral risks and what, if any, additional procedures are to be followed and actions taken as a result of these changes.

Data collection has to be sufficient for estimating PD or LGD and calculating capital under the CAR Guideline. Institutions’ policies should clearly define how collateral values would be captured and used for purposes of collateral management, and exceptions to an established treatment should be tracked to provide evidence of the validity and impact of such exceptions.

3. Documentation of CMS

Financial institutions should establish and maintain fully documented policies and procedures surrounding the scope, purpose and use of CMS, such that they can be readily understood by and be available to users across the institution.

Maintenance and updates to documented policies and procedures should be ongoing. Controls should be put in place to ensure that updates and changes to policies and procedures are documented in a timely fashion.

4. Valuation and re-valuation of collateral

Institutions should have established procedures and practices that explicitly define how to value each collateral type and establish clear practices for the frequency of re-valuations, and should explicitly define how and when to inspect each collateral type.

Institutions should have documented guidelines for conservatively estimating, on an ongoing basis and as appropriate, the market value of the collateral, taking into account factors that could affect that value (e.g., the liquidity of the market and obsolescence or deterioration) of the collateral. Policies and procedures for monitoring and/or revaluation should include triggers for increased frequency of monitoring.

Institutions should have systems in place for requesting and ensuring prompt receipt of additional collateral for transactions whose terms require maintenance of collateral values at specified thresholds.

Requirements for inspection for the same collateral type may differ across business lines. Policies should delineate these differences, which should be reasonable and based on sound principles.

5. Permissible prior charges on collateral

Institutions’ collateral policies should clearly articulate and define permissible prior charges or liens on the specific collateral. There should be processes in place to ensure that only such permissible prior charges or liens exist for security taken.

6. Legal certainty of collateral

Institutions should have CMS that ensure all steps necessary have been taken to fulfil legal requirements to secure the organization’s interest in the collateral.

Institutions should have operational procedures and risk management processes in place that ensure relevant and material documentation used in collateralizing a transaction is binding on all parties and legally enforceable in all relevant jurisdictions. Institutions should have conducted sufficient legal reviews to verify this conclusion, should have well-founded legal bases for the conclusion, and should re-conduct such reviews as necessary to ensure continuing enforceability.

The legal mechanism under which the collateral is pledged or transferred must ensure that institutions have the right to liquidate or take legal possession (in accordance with the terms of the documentation and the requirements of the jurisdiction) of the collateral in a timely manner in the event of the default, insolvency, or bankruptcy (or other defined credit event) of the obligor and, where applicable, the custodian holding the collateral. The ability to act in a timely manner is particularly important for collateral that is subject to rapid price/valuation changes such as debt securities.

Institutions’ policies and procedures should define responsibility for obtaining, monitoring and maintaining enforceable security interests.

Institutions should have clear and robust procedures for the timely liquidation of collateral to ensure observation of any legal conditions required for declaring the default of the borrower and prompt liquidation of the collateral in the event of default.

CMS should be sufficiently robust to track collateral liquidation dates, proceeds from disposition of collateral, where appropriate, and costs incurred and paid.

7. Interdependence between borrower and collateral

Institutions’ collateral valuation practices should take into account the interdependence (or not) of borrower and collateral.

Risk management policies at each institution will define what constitutes interdependencies between borrower and collateral. In particular, institutions should address, in a conservative manner, cases where the credit quality of the counterparty and the value of the collateral have a material positive correlation.

In reflecting collateral loss estimates, institutions will need to consider the extent of any interdependence between the risk of the borrower and that of the collateral or collateral provider. An institution’s assessment would have to conservatively address any significant degree of dependence, as well as any currency mismatch between the underlying obligation and the collateral. The associated internal estimates (e.g., LGDs) would have to be grounded in historical recovery rates on the collateral and should not be based solely upon the collateral’s estimated market value. Use of third party data, where relevant and material, could be used to supplement internal data.

8. Capital benefits of credit risk mitigants

Institutions should be able to demonstrate that the capital benefit claims are appropriate considering the robustness of credit risk mitigation policies.

Institutions should test their collateral management policies and procedures to ensure that systems are robust and reliable and appropriate for capital benefits of credit risk mitigants.

9. Internal reporting and analysis

Internal reporting and analysis will likely need to consider many areas. Some illustrative examples of those areas include:

  • concentration risk by collateral type
  • residual risks
  • trends
  • loan to value assessments
  • collateral values at obligor, portfolio and enterprise level
  • effectiveness of legal documentation
  • tracking of policy exceptions
  • volatility of collateral values
  • industry and geographic analysis
  • regulatory capital reporting

Institutions should develop measures appropriate to their respective CMS in respect of internal reporting and analysis. These measures need not include all of the above examples in every instance.