Under Principle 1 the bank must have a process for assessing overall capital adequacy against its risk profile and a strategy for keeping capital at the right level (SRP20.1). It must show that internal capital targets are well founded, consistent with its risk profile and operating environment, mindful of the business cycle, and supported by rigorous forward-looking stress testing (SRP20.5). The process must have five features: board and senior management oversight, sound capital assessment, comprehensive assessment of risks, monitoring and reporting, and internal control review (SRP20.6). The board sets risk tolerance and the strategic plan states capital needs and sources (SRP20.8, SRP20.9). The assessment must cover credit, operational, market, banking book interest rate, liquidity and other risks such as reputational and strategic risk (SRP20.11 to SRP20.27). Senior management or the board must receive regular reports on the risk profile and capital needs, and the process must be independently reviewed, including data accuracy, scenario validity and stress testing (SRP20.28 to SRP20.30). The ICAAP should run on a consolidated basis and, where supervisors require, per legal entity, incorporate stress testing, analyse how capital instruments behave in stress, and address short- and long-term needs; differences from the supervisory Pillar 2 assessment trigger a dialogue (SRP30.2). Risks not captured in Pillar 1, such as concentration, securitisation and valuation risk, must be built in (SRP30.6).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.