A bank using IRB approaches must hold enough capital to meet Pillar 1 plus any shortfall revealed by its IRB credit risk stress test under CRE36.50 to CRE36.53 (SRP32.1), and must apply the reference definition of default in its PD, LGD and EAD estimates (SRP32.2). It must keep written credit risk mitigation policies to control residual risks such as failure to realise collateral, guarantor delay or untested documentation, review them regularly and justify the capital relief it takes (SRP32.3 to SRP32.5). Credit concentrations to single names, related groups, sectors, regions, common activities or protection providers must be covered by documented policies, limits tied to capital or total assets, periodic stress tests and the Pillar 2 capital assessment (SRP32.6 to SRP32.13). Counterparty credit risk needs sound policies, active board involvement, daily exposure reports reviewed by senior staff, daily and intraday credit line monitoring, routine stress testing and an independent review ideally at least once a year covering 14 listed areas (SRP32.14 to SRP32.23); internal model users must manage specific wrong-way risk (SRP32.24). Securitisation risks, including implicit support, pipeline and warehouse exposures, triggers and liquidity facilities, must be in MIS, analysed beyond external ratings, stress tested and capitalised in the ICAAP with contingency plans for market closure (SRP32.28 to SRP32.39). Expected credit loss accounting is not set out in SRP32; it appears in the Framework only through cross-references and in the KM1 and CR1 disclosure templates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.