Image text
The supervisory review and evaluation process (SREP) over a decade on: Consolidation, integration and simplification
The EBA’s revised SREP Guidelines bring ESG, emerging risks and operational resilience into the core of bank supervision, alongside new rules for third-country branches and other regulatory developments. The result is a more flexible framework that seeks to focus supervisory attention on the areas of greatest risk.
Abstract: The European Banking Authority’s (EBA’s) revised SREP Guidelines consolidate previously dispersed provisions into a single supervisory framework and incorporate developments in the EU banking regulatory landscape since the last major update. The review retains the core SREP architecture while reorganising the treatment of risks, institutions and supervisory measures to improve consistency and flexibility. Among the most significant changes are the integration of ESG factors, emerging risks and operational resilience, alongside new provisions covering third-country branches and subsidiaries, the output floor limiting reductions in capital requirements from banks′ internal models, the Digital Operational Resilience Act (DORA) and credit spread risk in the banking book. The Guidelines also introduce a more flexible escalation framework for supervisory measures and expand proportionality for Category 4 institutions—small and non-complex banks with lower-risk profiles—including the possibility of extending the minimum cycle for a full SREP assessment from three to five years for qualifying institutions. For banks, the revised framework does not change their underlying regulatory obligations but will affect how those obligations are assessed and translated into supervisory requirements. With the Guidelines due to apply from 1 January 2027, institutions should prepare in advance for greater supervisory scrutiny of next-generation risks and ensure that the relevant documentation, metrics and risk-management frameworks are in place.

Twelve years of supervision under the SREP framework: The need for an update
Twelve years on from the onset of the Banking Union, Europe’s banks are considerably more resilient than in the run-up to the Great Financial Crisis. A large part of that positive transformation is attributable to the supervisory review and evaluation process (SREP). Since its creation in 2014, the SREP has been articulating the bank supervisory effort in the European Union: under its umbrella, the competent authorities build a comprehensive vision of each institution’s risk profile, viability and sustainability and determine the capital, liquidity and governance measures derived from each evaluation. It is, therefore, an exercise in abstraction that translates all the information gathered through on-site inspections, remote reviews and ongoing dialogue between the supervisor and the institution into specific Pillar 2 Requirements (P2R) and Guidance (P2G).

Since its first version, the framework has demonstrated a noteworthy ability to adapt, undergoing two significant updates prior to the one addressed in this paper: in 2018, with the addition of the P2G dimension and the mapping of stress test outcomes into capital expectations, as per the EBA’s Pillar 2 Roadmap; and in 2021, to reflect the changes ushered in by the Capital Requirements Directive (CRD) V, including assessment of the risk of excessive leverage (P2R-LR and P2G-LR) and the requirement to cooperate with the AML/CFT supervisors. Lastly, on 26 July 2026, the EBA published its third major update of its Guidelines (revised) on common procedures and methodologies for the supervisory review and evaluation process (SREP) and supervisory stress testing (EBA/GL/2026/06).
This third review was not prompted by shortcomings in the existing framework but rather a dual effort to unlock continuous improvement. On the one hand, the risk perimeter that needs to be covered by the supervisor has ballooned: the Banking Package (CRD VI and CRR III), the Digital Operational Resilience Act (DORA) and the IRRBB/CSRBB package on interest rate risk and credit spread risk in the banking book have added risk dimensions that the original SREP, conceived of in a different context, did not contemplate. On the other hand, over a decade of application had yielded a wealth of valuable experience: the peer reviews carried out by the EBA itself and the lessons learnt from recent episodes of market stress pointed not to design flaws, but to room for improvement of a framework that, in substance, has shown itself to work.

It is important to underline, therefore, as the EBA does, that this review does not alter the SREP′s architecture: the framework continues to be articulated around an assessment of the institutions’ business model, internal governance, risks to capital and risks to liquidity and funding, with a common scoring system and integrated communication of results. What is changing is the manner in which these elements are documented, how they connect up and how flexibly they are applied (proportionality). Indeed, the review can be distilled into three complementary goals:

  • Consolidating into a single playbook provisions that were scattered across different sets of guidelines up until now.

  • Integrating next-generation risks across the board.

  • Simplifying the wording to unlock more selective and risk-focused supervision.

This threefold aim —consolidation, integration and simplification— is in sync with the regulatory thrust currently shaping the European banking system. The political and institutional streamlining drive, tangible in the agenda pursued by the ECB’s High-Level Task Force on Simplification, has yielded one of its clearest exponents in this review: less red tape without compromising an iota of the prudential stringency built up over the last decade.
Consolidation: A single supervisory playbook for the SREP
The first of the three objectives translates into the centralisation, within a single text, of provisions that were formerly addressed in separate sets of guidelines. The most tangible example of this line of initiative is the repeal of the specific Guidelines on ICT Risk Assessment under the SREP, whose contents are now part of the core SREP framework, specifically within operational risk. The revised Guidelines clarify that ICT risks are part of the operational risk category and that DORA strengthens its prudential treatment.

They also introduce a new section devoted specifically to the assessment of branches in third countries, thereby fulfilling the mandate introduced by the CRD VI to harmonise the supervision of these institutions given their increasing presence in the EU. The revised Guidelines also merge the assessments of liquidity and funding risks, which were previously evaluated in a more segmented manner, into a single analytical block.

The centralisation exercise is rounded out with a thorough editorial review: the text referring to provisions already addressed in other legislative documents or evaluations deemed obsolete has been removed; those references have been included in a separate document and will remain accessible for transparency purposes. The desired result is a more manageable text which lessens the burden of regulatory interpretation on the competent authorities themselves and, by extension, fosters more predictable supervisor engagement from the institutions’ standpoint.

Integration: Next-generation risks, institutional boundaries and technical adjustments
The second pillar of the review, and arguably the one with the greatest significance in conceptual terms, entails the cross-cutting integration into the SREP of a set of elements that, until now, had not been addressed in a systematic or unified manner: three new risk dimensions (next-generation risks: ESG factors, emerging risks and operational resilience); differentiated treatment of third-country banking groups; and a series of technical adjustments with prudential implications in areas such as the output floor, the integration of DORA and the inclusion of credit spread risk (CSRBB).

ESG factors. Environmental, social and governance risks are no longer addressed as a standalone category, having been embedded into all elements of the SREP, underpinned by the premise that these risks materialise through traditional financial risk categories. The business model analysis (BMA) will evaluate the impact of physical and transition climate risks on the institutions’ viability in the short, medium and, notably long term, with time horizons of at least ten years. As part of the governance assessment, the SREP will assess whether the management body has the knowledge needed to manage these risks and integrate the transition plans. In the assessment of risks to capital, ESG factors will now be treated as drivers of the traditional credit or operational risks.

Emerging risks. Unlike the ESG factors, the Guidelines create a more open-ended category for new or evolving risks presenting significant uncertainty and without proven assessment methodologies for which the EBA has deliberately opted for a high-level treatment that provides the competent authorities with room for flexibility. Two specific examples are referenced: geopolitical risks whose source, management strategy and impact on profitability must be evaluated as part of the BMA, as well as featuring among the low-probability and high-impact risks in the internal capital adequacy assessment process (ICAAP); and crypto-asset activities, which are assessed as part of the BMA when an institution provides related services. It is noteworthy that the EBA stuck with this high-level approach despite the requests received during the consultation phase: several participants called for more specific guidance around the risks derived from artificial intelligence but the banking authority opted instead to rely on the expert judgement of the supervisor in a field in the midst of transformation.

Operational resilience
The revised Guidelines formally adopt the concept of operational resilience, understood as an institution′s ability to continue to provide its critical or important functions through disruption. The approach to operational resilience is holistic and integrated; it is not treated as a standalone module. The aim is to build upon areas already covered and assessed, including ICT risk management, third-party risk management and business continuity management, without introducing a new framework or duplicating existing reporting obligations. On the governance front, the management body is expected to play an active role supervising the effectiveness of this approach.

Third-country branches and subsidiaries. The revised Guidelines differentiate between banking groups from outside the EU depending on whether they operate through a branch or a subsidiary. For branches, the Guidelines address the CRD VI mandate to harmonise their supervision, scaling the intensity of the assessment as a function of their size and risk profile. Unlike other institutions, third-country branches cannot be subject to ‘failing or likely to fail’ scores. For subsidiaries, a new approach has been introduced to ensure their capital adequacy when they are reallocated market losses from other group entities under transfer pricing arrangements.

Output floor. The Guidelines clarify how the supervisors should proceed when an institution becomes bound for the first time by the output floor, the lower limit designed to stop a bank’s internal model calculations from reducing capital requirements too far. A temporary cap then comes into play so that the Pillar 2 requirement does not automatically increase simply due to the change in the risk-weighted asset calculation. The cap is subsequently removed, after the supervisor reviews the requirement, so as to eliminate any potential double-counting effects.

Integration of DORA. ICT risk assessment has been moved to operational risk, clarifying that it forms part of the latter and that DORA strengthens its prudential treatment. The authorities must evaluate compliance with DORA for the ICT services received from ICT third-party providers and with the internal governance guidelines for the non-ICT services received from third-party providers. The revised Guidelines also strengthen data aggregation and risk reporting capabilities through resilient ICT systems, in line with the Basel Committee principles.

Scope expansion to include CSRBB. The scope of the interest rate risk in the banking book (IRRBB) evaluation has been expanded to explicitly cover credit spread risk in the banking book (CSRBB). The result is reflected in a combined IRRBB/CSRBB score. The EBA acknowledges, however, that the methodology applicable to CSRBB is less mature, which is why the corresponding guidelines are more proportionate and should be applied more flexibly.

Simplification: Flexible escalation of supervisory measures and increased proportionality
The third aim of the review —simplification— translates into two developments with a direct impact on the intensity and predictability of the supervisory effort.

Firstly, the updated Guidelines introduce a high-level escalation framework designed to guide the authorities when selecting the most appropriate supervisory measures for addressing any deficiencies identified. It is a flexible framework and is not strictly sequential. It is focused on the root causes of the deficiencies, which should be reflected in the scores assigned, and contemplates four increasingly stringent levels of intervention: enhanced supervisory dialogue, like holding a meeting with the management body or requiring a self-assessment; non-binding corrective measures, such as supervisory expectations and recommendations; binding corrective actions, for example, setting qualitative measures or setting/increasing the Pillar 2 or liquidity requirements; and, ultimately, enforcement, including administrative penalties, remedial measures or fines.

Secondly, the updated Guidelines substantially expand the proportionality criteria applicable to Category 4 small and non-complex institutions (SNCI). They retain the legacy four categories of institutions, defined by the size, systemic importance, scale, nature, and complexity of their activities. Those categories remain the benchmark for adjusting the frequency and scale of supervisory engagement and serve as a benchmark for assessing supervisory convergence ex-post. The revised Guidelines provide for an extension of the minimum frequency for the assessment of all SREP elements from three to five years for Category 4 institutions, provided they maintain a stable low-risk profile, sound financial metrics and healthy margins, and quarterly monitoring does not raise material concerns. Competent authorities retain discretion to increase the frequency of engagement whenever warranted. This proportionality rationale is enhanced by the possibility of undertaking lighter reviews of SREP elements or risk areas that are deemed immaterial and a multi-year SREP approach where in-depth assessments of selected risks or risk factors are planned over several cycles.

Scope and implications: What is going to change (and what will stay the same) for the banks?
Insofar as they are addressed to the competent authorities, the Guidelines impact the financial institutions indirectly; they do not speak to their substantive obligations, which continue to be set under the CRD, CRR and their implementing regulations, but rather to the manner in which those obligations are supervised, evaluated and translated into individual capital and liquidity requirements.

The main changes stem from the goal of articulating a more streamlined framework which brings all of the guidance related to the SREP into a single playbook, integrating ICT risk and third-country branches and merging the liquidity and funding risk assessments. This same rationalisation thrust is evident in the decision to extend the evaluation cycle from three to five years for small and non-complex institutions.

The simplification effort does not, however, imply any relaxation of risk coverage. The more established risks, such as the ESG factors, are being embedded into the supervisory process in a cross-cutting manner, accompanied by a sharper focus on emerging and evolving risks. The approach is more risk-focused, tailoring the scope, depth and intensity of the supervisory effort to each institution’s risk profile.

In parallel, the revised Guidelines render the supervisory process more efficient by means of the flexible escalation framework, a clearer link between the findings of each evaluation and the measures taken and clearer communication of the results of the process to the institutions themselves.

This reassessment of the SREP Guidelines comes at a time when the European supervisory agenda is simultaneously pursuing two objectives which can often appear to be contradictory: reducing regulatory complexity while maintaining, without giving an inch, the resilience built up by the European banking system over the past decade. The result, in the case of the SREP, is a more streamlined and better structured text which remains true to the forward-looking rigour that has characterised the process from the outset.

On the other hand, the more intense focus on the treatment of next-generation risks, as part of the business and governance model analysis, foreshadows more stringent supervisory engagement in these areas. The banks would be well advised to prepare the related documentation, metrics and risk management frameworks sufficiently ahead of their implementation in January 2027. As is often the case with well-designed regulatory simplification, reduced complexity does not imply laxer standards, but rather a sharper focus on what really matters.
Aitana Bryant, Andrea Blana and Jaime Morillo. Afi