Article 368 › 2
The review referred to in point (h) of paragraph 1 shall include both the activities of the business trading units and of the independent risk-control unit. At least once a year, the institution shall conduct a review of its overall risk-management process. The review shall consider the following: (a) the adequacy of the documentation of the risk-management system and process and the organisation of the risk-control unit; (b) the integration of risk measures into daily risk management and the integrity of the management information system; (c) the process the institution employs for approving risk-pricing models and valuation systems that are used by front and back-office personnel; (d) the scope of risks captured by the risk-measurement model and the validation of any significant changes in the risk-measurement process; (e) the accuracy and completeness of position data, the accuracy and appropriateness of volatility and correlation assumptions, and the accuracy of valuation and risk sensitivity calculations; (f) the verification process the institution employs to evaluate the consistency, timeliness and reliability of data sources used to run internal models, including the independence of such data sources; (g) the verification process the institution uses to evaluate back-testing that is conducted to assess the models' accuracy.
← 1 · All articles · 3 →
Source: EUR-Lex CELLAR · retrieved 2026-09-04