The mission of risk management in the Bank Millennium Group is to ensure that all types of risks, financial and non-financial, are managed, monitored and controlled as required for the risk profile (risk tolerance), nature and scale of the Group’s operations. Important principle of risk management is the optimization of the risk and profitability trade-off – the Group pays special attention to ensure that its business decisions balance risk and profit adequately.
The goals of the risk management mission are achieved through implementation of the following actions:
Development of risk management strategies, credit policy, processes and procedures defining the principles for acceptance of the allowable level of particular types of risk,
Increasingly wider implementation of the IT tools for risks identification, control and measurement,
Increasing awareness of employees as regards their responsibility for proper risk management at every level of the Group’s organizational structure.
Risk management is centralized for the Group and takes into account the need to obtain the assumed profitability and to maintain proper risk-capital relationship, in the context of having proper level of capital to cover the risk.
Within risk management system, a broad range of methods is used, both qualitative and quantitative, including advanced mathematical and statistical tools supported by adequate IT systems.
When defining the business and profitability targets, the Group takes into account the specified risk framework (risk tolerance) in order to ensure that business structure and growth will respect the risk profile that is targeted and that will be reflected in several indicators such as:
Loan growth in specific products / segments
Structure of the loan portfolio
Asset quality indicators
Cost of risk
Capital requirements / Economic capital
Amount and structure of liquidity needed.
The risk management and control model at the Group’s level is based on the following main principles:
ensuring the full-scope quantification and parameterization of various types of risks in the perspective of optimizing balance sheet and off-balance sheet items to the assumed level of profitability of business activity. The main areas of analysis encompass credit risk, market risk, liquidity risk and operational risk;
all types of risks are monitored and controlled in reference to the profitability of operations and the level of capital necessary to ensure the safety of operations from the point of view of capital adequacy. The results of risk measuring are regularly reported as part of the management information system;
the segregation of duties between risk origination, risk management and risk control.
The Risk management process of the Group is presented in the below diagram:
The split of competence in the field of risk management is as follows:
The Supervisory Board is responsible for overseeing the compliance of the Group’s risk-taking policy with the Group’s strategy and its financial plan. Within the Supervisory Board acts the Committee for Risk Matters, which supports it in realization of those tasks, among others, issuing opinion on the Group’s Risk Strategy, including the Group’s Risk Tolerance;
The Management Board is responsible for the effectiveness of the risk management system, internal capital estimation process, for reviewing the internal capital calculation and maintenance process and the internal control systems;
The Credit Committee, the Capital, Assets and Liabilities Committee, and the Liabilities at Risk Committee are responsible for current management of different areas of banking risk, within the framework determined by the Management Board;
The Risk Committee and the Processes and Operational Risk Committee are responsible for defining the policy and for monitoring and control of different areas of banking risk, within the framework determined by the Management Board;
The Validation Committee is responsible for confirmation of risk models validation results and follow-up in the implementation of the measures defined by the Models Validation Office;
The Risk Department is responsible for risk management, including identifying, measuring, analyzing, monitoring and reporting on risk within the Bank. The Risk Department also prepares risk management policies and procedures as well as provides information and proposes courses of action necessary for the Capital, Assets and Liabilities Committee, Risk Committee and the Management Board to make decisions with respect to risk management;
The Rating Department is mainly responsible for risk rating assignment for Corporate clients (based on the evaluation of clients’ creditworthiness) as well as for rating monitoring and potential revision during the period of its validity. Rating assignment process is independent from credit decision process;
The Corporate Credit Underwriting Department and the Retail Credit Underwriting Department have responsibility, within the Corporate Customer segment and Retail Customer segment, respectively, for the credit decision process, including analyzing customers’ financial situation, preparing credit proposals for the decision-making levels and making credit decisions within specified limits;
The Retail Liabilities Collection Department has responsibility for monitoring repayment of overdue debts by retail customers and their collection;
The Corporate Recovery Department develops specific strategies with respect to each debtor from recovery portfolio, which aims to maximize timely collection of the outstanding debt and minimize the risk incurred by the Group. This approach is constantly revised to reflect updated information, and the best practices and experiences regarding collection of overdue debts;
The Treasury Control and Analyses Office has responsibility for monitoring the use of part of the Group’s limits, including counterparty and stop-loss limits, the Group’s FX position, results of active trading and control of operations of the treasury segment;
The Models Validation Office has responsibility for qualitative and quantitative models analysis and validation, independent from the function of models development; development of the models validation and monitoring tools; activities connected with issuing opinions on the adequacy of the models for the segment, for which they were developed; preparing reports for the Validation Committee needs;
Fraud Risk Management Team has responsibility for implementation and monitoring the Bank policy execution in the scope of fraud risk management in cooperation with others Bank units.Team constitutes a competence center for anti-fraud process;
The Compliance Department has the responsibility to ensure compliance with legal regulations, related regulatory standards, market principles and standards as well as internal organization regulations and codes of conduct.
The Group has prepared a comprehensive guideline document for the risk management policy/strategy: “Risk Strategy for 2019-2021” (2018-2020 version was in force previously). The document takes a 3-year perspective and is reviewed and updated annually. It is approved by the Bank’s Management Board and Supervisory Board. The risk strategy is inextricably linked to other strategic documents, such as: Budget, Liquidity Plan, and Capital Plan.
The Risk Strategy bases on the two concepts defined by the Group:
Risk profile – current risk level expressed in amount or type of risk the Group is currently exposed. The Group also has a forward looking view how their risk profile may change under both expected and stress economic scenarios in accordance withrisk tolerance,
Risk tolerance – the maximum amount or type of risk the Group is prepared to accept to achieve its financial and strategic objective.
Goal of Risk Strategy is to define a risk profile and to maintain a risk profile for all risk types within the limits set in the risk tolerance.
Risk tolerance measures consider both the current and forecasted target risk profile. They have been defined in the key areas, listed below:
Liquidity and funding
Franchise and reputation.
The Group has a clear risk strategy, covering retail credit, corporate credit, markets activity and liquidity, operational and capital management. For each risk type and overall the Group clearly defines the risk tolerance.
The Risk Tolerance of the Group is mainly defined through the principles and targets defined in Risk Strategy and complemented in more detail by the principles and qualitative guidelines defined in the following documents:
a. Capital Management and Planning Framework
b. Credit Principles and Guidelines
c. Rules on Concentration Risk Management
d. Principles and Rules of Liquidity Risk Management
e. Principles and Guidelines on Market Risk Management on Financial Markets
f. Principles and Guidelines for Market Risk Management in Banking Book
g. Investment Policy
h. Principles and Guidelines for Management of Operational Risk
i. Stress tests policy.
Within risk tolerance, the Group has defined tolerance zones (build up based on the “traffic lights” principle). As for all tolerance zones have been set:
Escalation process of taken decisions/actions (bodies/organizational entities responsible for decisions and actions)
Catalogue of decisions/actions on risk controls and mitigation
Risk tolerance monitoring procedures.
The Group pays particular attention to continuous improvement of the risk management process. One measurable effect of this is a success of the received authorization to the further use of the IRB approach in the process of calculating capital requirements.