Learning Objectives:
-
Understand how cyber risk is integrated into the Supervisory Review and Evaluation Process (SREP).
-
Apply the SREP methodology to assess ICT risk.
-
Recognise the key risk categories in the SREP ICT risk assessment.
-
Understand the relationship between ICT risk and other risk categories.
6.1 The Supervisory Review and Evaluation Process (SREP)
The Supervisory Review and Evaluation Process (SREP) is the framework used by supervisors to assess the risk profile and viability of financial institutions. The ECB’s SREP methodology assesses ICT risk as a key component of operational risk. The Bank of Spain’s approach to ICT and cyber risk supervision is aligned with the SSM-level SREP methodology .
6.2 The SREP ICT Risk Assessment
The ECB’s SREP methodology identifies four ICT risk level modules :
ICT Security Risk: The extent to which the institution is exposed to ICT security risk. This includes risks related to unauthorised access, data breaches, and cyberattacks.
ICT Availability and Continuity Risk: The extent to which the institution is exposed to ICT availability and continuity risk. This includes risks related to system outages, service disruptions, and disaster recovery.
ICT Change Risk: The extent to which the institution is exposed to ICT change risk. This includes risks related to system changes, upgrades, and implementation of new technologies.
ICT Data Integrity Risk: The extent to which the institution is exposed to ICT data integrity risk. This includes risks related to data corruption, unauthorised modification, and data loss.
6.3 Weighting ICT and Cyber Risk
The weight assigned to ICT and cyber risk within the overall operational risk assessment is determined by several factors :
-
The complexity of the IT architecture
-
Major projects
-
Dependency on fully digitalised services
-
Track record of incidents
It is expected that in the near future the ICT and cyber risk weight will be raised to around 50 percent in SI supervision at the SSM level, which would be more in line with current developments in the financial sector. BdE aims at maintaining the alignment between SI and LSI supervisory methodology and thus will apply the same weight in LSI supervision .
6.4 Supervisory Actions
Based on the SREP assessment, supervisors may take a range of actions, including:
-
Recommendations: Issuing recommendations for improvement.
-
Requirements: Imposing requirements for corrective action.
-
Pillar 2 Requirements: Setting additional capital or liquidity requirements.
-
Enforcement Actions: Taking enforcement actions for non-compliance..