Risk Management

Articles on Risk Management from ADVISORI

The EU AI Act for Banks: What 13 Years of BCBS 239 Are Really Worth in the Age of AI

The EU AI Act for Banks: What 13 Years of BCBS 239 Are Really Worth in the Age of AI

The EU AI Act finds banks on familiar ground: data quality, data lineage, model risk management, and human oversight are disciplines that BCBS 239 has required since 2013 and that the ECB has tightened in its RDARR Guide. The head start is real, but limited. Three requirements have no equivalent in the current framework: bias and fairness controls, the explainability of model decisions, and the fundamental rights impact assessment under Article 27. An assessment that identifies specific areas requiring action.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

September 04, 2026

10 min read
AI-Ready Data: Assessing Your Data – The Data Quality Dimensions That Determine AI Success

AI-Ready Data: Assessing Your Data – The Data Quality Dimensions That Determine AI Success

AI readiness is decided earlier than most organizations expect — at the level of the data itself. This article sets out the data quality dimensions that make data AI-ready, places data readiness for AI within the regulatory framework from the EU AI Act to BCBS 239, and explains why the four classic quality dimensions are not sufficient for AI models.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

September 03, 2026

10 min read
AI Governance for Banks: Connecting Data, Models, and Internal Structures

AI Governance for Banks: Connecting Data, Models, and Internal Structures

AI governance does not replace what banks already do well. It builds on it. This article shows how data governance, model governance, and internal governance combine into a framework that satisfies supervisors and enables AI at scale: from dataset suitability and continuous monitoring to accountability across the three lines of defense.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

July 30, 2026

5 min read
9th MaRisk Amendment 2026: What Changes for Banks Now

9th MaRisk Amendment 2026: What Changes for Banks Now

The 9th MaRisk Amendment is final: more proportionality, SNCI reliefs, new size categories. All changes, deadlines and an implementation roadmap to 2027.

David Curtis Behm's avatar

David Curtis Behm

July 24, 2026

7 min read
The EU Benchmarks Regulation Tightens Again: What ESMA's 2026 Internal Control Guidelines Mean for Benchmark Administrators

The EU Benchmarks Regulation Tightens Again: What ESMA's 2026 Internal Control Guidelines Mean for Benchmark Administrators

The EU Benchmarks Regulation has acquired another layer. On 5 May 2026, ESMA published new Guidelines on Internal Controls that apply from 1 October 2026 — the latest step in a regulatory story running straight back to the LIBOR scandal. Here's what benchmark administrators and credit rating agencies now have to demonstrate.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

July 17, 2026

10 min read
The EBA Climate Stress Test: The New 2027 Climate Risk Module and What Banks Should Do

The EBA Climate Stress Test: The New 2027 Climate Risk Module and What Banks Should Do

The draft 2027 EBA stress test introduces a dedicated climate risk module, layering transition and flood shocks onto the adverse macro-financial scenario. It leaves capital ratios untouched for now, but it produces exactly the kind of supervisory dataset that shapes future cycles, so the draft is best treated as a dry run.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

July 13, 2026

8 min read
PD Model Backtesting in the Spotlight: What the EBA's 2026 Paper Means for European Banks

PD Model Backtesting in the Spotlight: What the EBA's 2026 Paper Means for European Banks

For two decades, the performance of banks' PD models stayed inside confidential supervisory channels. The EBA's April 2026 Staff Paper changes that — applying systematic PD model backtesting across EU IRB banks, sharpening the binomial test for both asset and serial correlation, and putting a Tier 1 capital number on the result.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

June 25, 2026

10 min read
Credit Risk Modeling Trends 2026: Five Shifts Risk Managers Should Prepare For

Credit Risk Modeling Trends 2026: Five Shifts Risk Managers Should Prepare For

The credit risk function of 2026 looks materially different from the one most banks still operate. Here are the five shifts, from generative AI to ESG integration, that risk managers should plan for now.

Dr. Helge Thiele's avatar

Dr. Helge Thiele

May 19, 2026

5 min read
Less & Faster IRB Model Changes — What Actually Changed (and Why It Matters)

Less & Faster IRB Model Changes — What Actually Changed (and Why It Matters)

How the new IRB rules transform many previously time-consuming model changes into simple notifications—thereby drastically shortening approval times and significantly accelerating implementation

Dr. Helge Thiele's avatar

Dr. Helge Thiele

April 24, 2026

5 min read
ESG Dashboard: Structure, KPIs & Tools for CSRD Sustainability Reporting

ESG Dashboard: Structure, KPIs & Tools for CSRD Sustainability Reporting

An ESG dashboard makes sustainability performance visible and auditable. This guide covers essential environmental, social, and governance KPIs, CSRD/ESRS alignment, data collection strategies, and tool selection for organizations building audit-ready ESG reporting.

Boris Friedrich's avatar

Boris Friedrich

April 20, 2026

12 min read
DORA ICT Risk Management: Requirements and Implementation Guide for Financial Institutions

DORA ICT Risk Management: Requirements and Implementation Guide for Financial Institutions

DORA Articles 5–15 establish the ICT risk management framework that financial institutions must implement. This guide breaks down governance, framework structure, ICT systems management, detection, business continuity, and the learning loop — with a practical implementation roadmap.

Boris Friedrich's avatar

Boris Friedrich

April 16, 2026

16 min read
DPIA-Guide: Data Protection Impact Assessment Under GDPR - Step by Step

DPIA-Guide: Data Protection Impact Assessment Under GDPR - Step by Step

A Data Protection Impact Assessment (DPIA) is mandatory for high-risk data processing under GDPR. This step-by-step guide covers when a DPIA is required, the 6-step methodology, risk evaluation, mitigating measures, and documentation requirements for regulatory compliance.

Boris Friedrich's avatar

Boris Friedrich

April 07, 2026

12 min read

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance