ICAAP and ILAAP
ICAAP and ILAAP for banks in Germany: normative and economic perspectives, a worked example, SREP and the ECB's July 2026 clarifications.
A curated map connects guideline identifiers, business topics and German supervisory practice. It starts with the implementation list in MaRisk of 30 June 2026.
This selection addresses credit institutions within the scope of MaRisk. Banks, investment firms and insurers need different regulatory inventories. Establish the legal entity, authorisation, supervisor and consolidation level before assigning a document. The map covers the eight guidelines expressly identified in MaRisk AT 1 paragraph 2. It is not a complete catalogue of EBA publications.
MaRisk identifies these guidelines as implemented insofar as they concern institutions’ risk management. The suggested owners and work products below are editorial suggestions. Institutions assign responsibilities within their own organisation.
| Guideline | Topic | Suggested owner | Work product |
|---|---|---|---|
| EBA/GL/2018/04 | Stress testing | Risk control | Scenarios, assumptions and actions |
| EBA/GL/2018/06 | Non-performing and forborne exposures | Credit risk | Portfolio management and treatment rules |
| EBA/GL/2019/02 | Outsourcing | Outsourcing management | Service, risk, contract and monitoring |
| EBA/GL/2020/06 | Loan origination and monitoring | Credit operations and risk | Credit decisions and ongoing monitoring |
| EBA/GL/2021/05 | Internal governance | Management and control functions | Responsibilities, segregation and oversight |
| EBA/GL/2022/14 | Interest rate and credit spread risk in the banking book | Treasury and risk control | Assessment, limits and reporting |
| EBA/GL/2025/01 | ESG risk management | Risk control and strategy | Risk drivers, data and management |
| EBA/GL/2025/04 | Environmental scenario analysis | Risk control | Scenario assumptions and resilience analysis |
EBA guidelines are issued under Article 16 of the EBA Regulation. Competent authorities and financial institutions must make every effort to comply with them. An RTS or ITS adopted as an EU regulation is a different type of instrument. For the guidelines listed here, MaRisk explains when an expressly referenced guideline section also needs to be considered. Copying the entire guideline into a second, parallel control system does not reflect that implementation route accurately.
Include DORA when assessing the rules for ICT risk and ICT third parties. An old assignment to an EBA guideline cannot settle applicability on its own. SREP guidelines concern supervisory assessment. They are not an additional daily business process to be copied wholesale into an internal register. These relationships should therefore be recorded as interfaces.
A useful record includes the document identifier, precise provision, version, publication date, application date, relevant entity, German implementation route and accountable owner. Add affected policies, controls, evidence and the reasoned implementation decision. Publication and application dates belong in separate fields. A future application date does not establish when preparation should start.
A practical sequence is to record the official publication, compare the previous version, decide applicability, map internal documents and approve changes with deadlines. The responsible function then checks that implementation has reached day-to-day operations. Preserve previous assessments in the version history. The maintenance template brings the review, decision and next review date together.
Relevance depends on the addressee, activities, supervisor and application date. The MaRisk implementation list is a useful starting point for its scope, but it is not a complete institution-specific legal inventory.
No. Record both dates and any transitional rules separately. Explicitly record when an earlier guideline is replaced.
ICAAP and ILAAP for banks in Germany: normative and economic perspectives, a worked example, SREP and the ECB's July 2026 clarifications.
Classify outsourcing and ICT services under MaRisk AT 9 and DORA Articles 28–30. Contracts, registers, risk assessments and practical exit testing.
The SREP connects business model, governance, capital risks and liquidity risks. Banks need a consistent account of their data, assumptions, decisions and outstanding actions.
Bring a concrete task. Together, we will define what the application needs to do.
Discuss your project