ICAAP and ILAAP
ICAAP and ILAAP for banks in Germany: normative and economic perspectives, a worked example, SREP and the ECB's July 2026 clarifications.
The SREP connects business model, governance, capital risks and liquidity risks. Banks need a consistent account of their data, assumptions, decisions and outstanding actions.
The ECB conducts the SREP for significant institutions with national authorities. BaFin and the Bundesbank work together under the national framework for less significant German institutions. Ongoing supervision, reporting, inspections and institution-specific evidence inform the process. Depth, frequency and priorities depend on the institution. A single annual questionnaire does not represent the entire SREP.
The four elements answer different questions. Their results need to fit together: a growth strategy, for example, affects capital needs, funding and management requirements.
| SREP element | Supervisory question | Useful internal material |
|---|---|---|
| Business model | Is the business model viable? | Strategy, earnings plan, concentrations |
| Governance and risk management | Do management and controls work? | Responsibilities, reports, findings |
| Risks to capital | What affects capital and risk coverage? | ICAAP, risk inventory, capital plan |
| Risks to liquidity | Are liquidity and funding resilient? | ILAAP, cash flows, contingency planning |
The published ECB methodology describes information gathering, a standardised initial assessment and detailed supervisory judgement. Quantitative indicators are considered with control effectiveness and the bank’s specific circumstances. Scores summarise this assessment. They are not a credit rating calculated by the bank and do not by themselves determine an automatic capital add-on.
For each response, establish the reference date, definition, source, business approval and any difference from earlier submissions. An internal workflow can connect questions, accountable departments and response deadlines. Resolve inconsistencies between the risk report, capital plan and board decision before submitting a response. Dialogue explains the findings; the formal decision can contain quantitative and qualitative measures.
Record capital requirements, supervisory expectations and organisational measures separately. Each action needs an owner, deadline and appropriate closure criterion. The ECB reform describes a tiered follow-up based on the severity of findings. Less active follow-up therefore does not mean that internal evidence is no longer needed.
P2R is a binding additional capital requirement. P2G is an additional supervisory capital expectation. Action tracking therefore distinguishes legal effect, capital planning and feedback to the supervisor.
The ECB uses its revised P2R methodology in the 2026 SREP cycle; resulting requirements apply from 1 January 2027. Distinguish the assessment year from the effective date of the decision. ICAAP soundness remains relevant to SREP assessments even though the revised P2R methodology no longer relies on ICAAP data as its calculation basis. The bank’s supervisory communication and applicable methodology govern its actual position.
ICAAP is the bank’s internal assessment of capital adequacy. SREP is supervisory review. Internal material informs supervision, while responsibilities and decisions remain distinct.
No. Multi-year planning for individual modules must be distinguished from ongoing monitoring and the overall assessment.
A score alone does not establish a capital requirement. Supervisors apply their methodology and institution-specific assessment.
ICAAP and ILAAP for banks in Germany: normative and economic perspectives, a worked example, SREP and the ECB's July 2026 clarifications.
Understand P2R and P2G, CET1 composition and MDA. A worked capital example and 2026 methodology changes for ECB banks and German LSIs.
A curated map connects guideline identifiers, business topics and German supervisory practice. It starts with the implementation list in MaRisk of 30 June 2026.
Bring a concrete task. Together, we will define what the application needs to do.
Discuss your project