Intelligent CRD Risk Management for excellent risk governance

CRD Risk Management

The CRD Directive establishes comprehensive risk management requirements for financial institutions that go well beyond traditional risk control.

  • 01Optimized ICAAP processes with automated capital planning
  • 02Intelligent stress testing frameworks for predictive risk analysis
  • 03Risk governance and appetite management based on machine learning
  • 04Automated SREP preparation with technology-supported documentation
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

CRD Risk Management: Governance Framework, Capital Adequacy and Integrated Bank Steering

Articles 74–96 of the Capital Requirements Directive (CRD) require credit institutions to maintain a comprehensive risk management framework with clear governance structures, documented risk strategy and adequate risk bearing capacity. ADVISORI supports banks in implementing these requirements — from risk inventory through ICAAP to embedding the three lines of defence model.

We advise banks and financial services firms on establishing and enhancing their supervisory risk management framework. Our service spectrum ranges from risk inventory and ICAAP design through three lines of defence implementation to preparation for supervisory examinations.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Risk Management Governance under CRD and MaRisk

Establishing and enhancing the risk management organisation under CRD Art. 74–76 and MaRisk AT 4.1 — from board responsibility through the CRO function to the risk controlling unit.

  • Organisational structure: responsibilities, reporting lines and escalation paths in risk management
  • CRO function: requirements for independence, qualifications and access to the management body
  • Risk controlling function: set-up, staffing and MaRisk-compliant functional separation
  • Risk committee: establishment, composition and reporting obligations under KWG § 25d
02

ICAAP and Risk Bearing Capacity

Designing and enhancing the Internal Capital Adequacy Assessment Process — normative and economic perspective per BaFin/Bundesbank guidance and EBA SREP guidelines.

  • Normative perspective: capital planning over the planning horizon with regulatory ratios
  • Economic perspective: risk coverage potential, risk measurement and internal capital allocation
  • Risk inventory: identification, assessment and documentation of all material risk types
  • Capital planning process: linking business strategy, risk strategy and capital requirements
03

Risk Appetite Framework and Risk Strategy

Developing and operationalising a risk appetite framework (RAF) as the link between business strategy and operational risk management — including limit systems and escalation mechanisms.

  • Risk appetite statement: qualitative and quantitative definition of risk tolerance at institution level
  • Limit system: deriving risk limits per risk type and business line from the risk appetite
  • Monitoring and escalation: early warning indicators, thresholds and defined escalation paths
  • Risk strategy: alignment with business strategy and annual review process
04

Three Lines of Defence and Internal Control

Implementing the three lines of defence model as the governance foundation — with clear delineation between operational risk management, independent oversight and internal audit.

  • First line of defence: risk ownership in business lines and operational controls
  • Second line of defence: independent risk controlling and compliance function
  • Third line of defence: internal audit with risk-based audit plan
  • Documentation: functional separations, reporting lines and evidence for supervisory examinations
05

Integrated Bank Management and Risk Integration

Connecting individual risk management processes into an integrated bank management framework — from risk inventory through capital allocation to risk-based performance management.

  • Risk aggregation: consolidating all risk types considering correlations and diversification effects
  • Capital allocation: risk-adjusted distribution of economic capital across business lines
  • Risk-based steering: RORAC/RAROC metrics for strategic decision-making
  • Risk reporting: building MaRisk-compliant risk reporting to management body and supervisory board
06

CRD VI / MaRisk 2026: Regulatory Adjustments

Supporting the implementation of current regulatory changes — CRD VI transposition (BRUBEG), MaRisk revision 2026, ESG risk integration and new institution classification.

  • CRD VI gap analysis: identifying action items from BRUBEG and new KWG requirements
  • ESG risk integration: embedding climate and sustainability risks in the risk inventory and ICAAP
  • Transition planning: preparing the supervisory transition plan per CRD VI / EBA guidelines
  • Proportionality assessment: evaluating requirements under new institution classification (MaRisk revision)

5 phases

Our Advisory Approach to CRD Risk Management

We follow a structured approach that links regulatory requirements (CRD, MaRisk, EBA guidelines) with the individual risk profile and business strategy of your institution. Every engagement begins with a gap analysis and culminates in an actionable implementation roadmap.

  1. Gap analysis

    benchmarking your existing risk management framework against CRD Art. 74–96, MaRisk AT 4.1 and relevant EBA guidelines

  2. Risk inventory and materiality assessment of all risk types as the foundation for risk strategy and ICAAP

  3. Design and documentation of the risk bearing capacity concept (normative and economic perspective)

  4. Step 4

    Implementation of the three lines of defence model with clear role assignments (CRO, risk controlling, internal audit)

  5. Support during supervisory examinations and SREP preparation with focus on governance evidence

Your contact

Melanie Düring

Head of Risk Management

The intelligent implementation of CRD Risk Management requirements is the key to supervisory excellence and strategic risk superiority in EU banking. Our solutions enable institutions not only to achieve regulatory compliance, but also to develop operational excellence in risk control and capital optimization. By combining deep risk management expertise with advanced technologies, we create lasting competitive advantages while protecting sensitive risk data.

Why ADVISORI for CRD Risk Management

  • 01Over 50 completed projects in integrated bank management and supervisory risk management since 2010
  • 02Experience with BaFin, Bundesbank and ECB examinations — proven governance evidence and SREP documentation
  • 03Interdisciplinary team of risk managers, regulatory specialists and process consultants
  • 04End-to-end support from gap analysis through implementation to supervisory sign-off

CRD VI & MaRisk 2026: New Requirements

The CRD VI transposition (BRUBEG) and the planned MaRisk revision 2026 raise governance standards for risk management — particularly in ESG risk integration, institution classification and transition planning. Early gap analysis secures compliance.

7 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about CRD Risk Management

What does the risk management framework under CRD Art. 74–96 encompass?

Articles 74–96 of the Capital Requirements Directive (CRD) require credit institutions to maintain a comprehensive risk management framework. The core components are:

• Governance structure: The management body bears overall responsibility for risk management and must establish an independent risk controlling function (Art. 76 CRD). Large institutions also need a risk committee.
• Risk strategy: Institutions must maintain a documented risk strategy covering all material risk types, aligned with the business strategy.
• ICAAP: The Internal Capital Adequacy Assessment Process ensures the institution holds sufficient capital to cover all material risks at all times.
• Risk appetite framework: Quantitative and qualitative determination of risk tolerance at institution level.
• Three lines of defence: Clear separation between operational risk management, independent oversight and internal audit.

In Germany, MaRisk (AT 4.1) specifies these requirements and adds obligations around risk inventory, risk bearing capacity and risk reporting.

How do the normative and economic perspectives of risk bearing capacity differ?

Since the Bundesbank/BaFin guidance of 2018, all German credit institutions must assess their risk bearing capacity from two perspectives:

• Normative perspective: Ensuring all regulatory capital requirements (CET1, Tier 1, total capital, capital buffers) are met over a multi-year planning horizon — including under adverse scenarios. The basis is CRR own funds requirements and Pillar 2 add-ons.
• Economic perspective: Assessing whether internal risk coverage potential is sufficient to cover all material risks. Internal risk measurement methods may go beyond the regulatory standard approaches.

Both perspectives are brought together in the ICAAP and must be consistent with the risk strategy and capital planning process. BaFin reviews risk bearing capacity regularly as part of the SREP.

What role does the CRO play in the risk management framework?

The Chief Risk Officer (CRO) plays a key role in supervisory risk management. CRD and MaRisk set the following requirements:

• Independence: The CRO must operate independently from revenue-generating business lines and must not simultaneously be responsible for risk-generating activities.
• Access to management: Direct reporting line to the management body and, where applicable, to the risk committee of the supervisory board.
• Qualifications: Sufficient expertise in risk management and banking supervisory law.
• Scope of responsibility: Oversight of the risk controlling function, risk inventory, risk bearing capacity calculation and risk reporting.
• Removal protection: The CRO can only be removed with consent of the supervisory body.

Under MaRisk (AT 4.4.1), in significant institutions the risk controlling function must be led by a member of the management board who is not simultaneously responsible for market or trading areas.

How does the three lines of defence model work in banking practice?

The three lines of defence model is the central governance concept for risk management in credit institutions. It structures responsibilities across three levels:

• 1st line of defence — Business lines: Front-office units bear direct responsibility for identifying and managing operational risks. They implement controls and adhere to risk limits.
• 2nd line of defence — Risk controlling and compliance: Independent oversight functions that develop risk methodologies, calculate risk bearing capacity, monitor limit adherence and ensure regulatory compliance.
• 3rd line of defence — Internal audit: Process-independent review of the entire risk management system based on a risk-oriented audit plan.

The functional and organisational separation of the three lines is critical. MaRisk (AT 4.4) requires that risk controlling and compliance functions are set up independently from market areas up to the management board level.

What changes with CRD VI and the MaRisk revision 2026 for risk management?

The CRD VI transposition through BRUBEG and the planned MaRisk revision 2026 bring significant changes:

• ESG risk integration: Institutions must systematically integrate climate and sustainability risks into the risk inventory and ICAAP. The materiality threshold is set at 5% of economic risk coverage potential.
• Institution classification: The MaRisk revision introduces three size categories — very small institutions (up to EUR 1bn balance sheet), small institutions/SNCIs (up to EUR 5bn) and other LSIs — with graduated requirements.
• Transition planning: Preparation of a supervisory transition plan as a risk management instrument per CRD VI and EBA guidelines.
• Governance tightening: Extended requirements for key function holders under KWG §§ 25c, 25d.
• Proportionality relief: Simplified stress tests and extended validation cycles for small institutions.

ADVISORI supports institutions with gap analysis, action planning and implementation of these new requirements.

How is integrated bank management linked to risk management?

Integrated bank management connects risk management with profit-oriented bank steering into one coherent management approach:

• Risk aggregation: All material risk types are consolidated into an overall risk profile, considering correlations and diversification effects.
• Capital allocation: Economic capital is distributed across business lines on a risk-adjusted basis — the foundation for risk-adjusted performance measurement (RORAC/RAROC).
• Strategic steering: Risk strategy and business strategy are aligned consistently and reviewed annually.
• Limit system: Institution-level limits are cascaded into individual limits per risk type and business line.
• Risk reporting: The risk reporting system keeps management body and supervisory board regularly informed about risk profile, risk bearing capacity and limit utilisation (MaRisk BT 3).

MaRisk requires these processes to be documented in an integrated bank management concept with the risk bearing capacity process as the central element.

What requirements does MaRisk set for the risk inventory?

The risk inventory is the starting point of the entire risk management process and is governed by MaRisk AT 2.2:

• Scope: All risks of the institution must be identified and assessed for materiality at least annually — and on an ad-hoc basis when triggered by events.
• Risk types: Credit risk, market risk, liquidity risk, operational risk, interest rate risk in the banking book and further institution-specific risks.
• Assessment criteria: Materiality is judged using quantitative (e.g. share of total risk) and qualitative criteria.
• ESG risks: From 2026, climate and sustainability risks must be explicitly included in the risk inventory.
• Documentation: Risk inventory results must be documented transparently and presented to the management body.
• Strategy linkage: The risk strategy and ICAAP parameterisation are derived from the risk inventory.

The risk inventory forms the basis for the ICAAP, risk appetite framework and the entire limit system.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance