Macro-Risk Assessment
The annual Macro-Dimension compliance risk assessment (High Level - HL) is carried out for all regulatory areas (Level 2). All key regulatory areas are evaluated through the quantitative and qualitative assessment of predefined risk indicators. Inherent risk at the High Level is assessed on the basis of a set of main standard indicators with a weighting factor according to their effect on the overall risk assessment. Through the Macro Risk Assessment, entity-level controls (at Bank/Group level) are evaluated either individually or collectively, according to their ability to mitigate risk. Based on this assessment, the residual risk is determined.
Micro Risk Assessment
The applied Compliance Risk Methodology provides a more detailed and analytical assessment at the level of risk scenarios for:
- A number of areas that are considered Very High/High Risk (based on the residual risk from the macro-assessment)
- All new regulations, especially for the first year of implementation
- Risks related to money laundering/terrorist financing.
The inherent compliance risk is calculated based on the assessment of specific parameters such as the impact and likelihood of occurrence of a regulatory breach scenario (at the Level 3 - Obligation categories). As compliance risk mitigation measures, process controls and general IT controls are evaluated based on Compliance Risk Testing in terms of control design and operating effectiveness. The residual compliance risk is generated automatically, using a matrix embedded in the tool.
To assess compliance risk and the Bank's controls to mitigate it, the Group Compliance Risk Governance & Monitoring Division conducts Compliance Risk Testing and ongoing Monitoring using key risk and performance indicators (KRIs & KPIs).
Compliance Risk Testing is a dynamic risk-based compliance assessment process, carried out periodically across selected business products and services. It examines the design/operational effectiveness of compliance controls and compliance with the institutional framework and applicable policies and procedures.
Compliance Risk Testing is carried out by independent, specialized teams. It is designed in the context of an Annual Plan, proposed by Division 516 and approved by the competent Board Committees. It takes place at specified intervals and retroactively covers a given period (e.g. 12 months).
The results, findings and corrective actions are validated by the Group's Chief Compliance Officer and communicated to the Compliance, Ethics & Culture Committee of the Board of Directors, while they are monitored by Division 516 through the Connected Risk Compliance Module.
Ongoing Monitoring is facilitated, among others, through two dashboards:
Compliance Risk Dashboard & Quality Assurance Dashboard
The Compliance Risk Dashboard features specialized Key Risk Indicators (KRIs) to facilitate the process of effectively monitoring compliance risks. It provides insights into compliance trends and helps identify compliance weaknesses before they become a real threat. Thus, compliance is transformed from a set of regulations into a goal with a well-defined evolutionary path.
The frequency of monitoring and reporting is usually determined during the KRIs (Key Risk Indicators) selection phase and can be quarterly, semi-annual or annual. The frequency is determined based on best practices and the nature of each indicator. The indicators are subject to annual review by the Group Chief Compliance & Corporate Governance Officer and the Head of Group Compliance, Risk Governance & Monitoring, and may be amended when necessary.
The Quality Assurance Dashboard is a tool for monitoring the quality level of regulatory compliance, based on the regular review of specific KPIs (Key Performance Indicators) for each of the Division’s Units.
The thresholds of each indicator are set to serve as early warning signals for more effective quality assurance management and are established:
- in line with best practices
- following regulatory limits
- based on historical data
The frequency of monitoring and reporting is usually determined during the KPI selection phase and can be quarterly, semi-annual or annual. The frequency is determined based on best practices and the nature of each indicator. Limits and frequency are subject to annual review.
In addition, the Group Compliance Risk Governance & Monitoring Division, recognizing the need for timely and effective management of Compliance Risk, is developing innovative tools and Intelligent Automated Solutions that will enable real-time monitoring of Compliance Risk, both at the customer level and at the Bank-wide level.
External Quality Assurance - ISO Certifications
The Group Compliance and Corporate Governance Division, with the initiative and actions of the Group Compliance Risk Governance & Monitoring Division, was successfully awarded the following ISO certifications:
- ISO 37000 Governance of Organizations (based on EBA 2017 Internal Governance Guidelines)
- ISO 37301 Compliance Management Systems
- ISO 9001 Quality Management Systems
- ISO 37001 Anti-Bribery Management Systems