EBA Revised Definition of Default Guidelines: What Changes for Financial Institutions
FINANCIAL SERVICESTargeted amendments following CRR3 preserve the core prudential framework while introducing important clarifications and operational changes.
18 Sep 2026 6 min read

In July 2026, the European Central Bank (ECB) published a clarification on the Internal Capital Adequacy Assessment Process (ICAAP), the Internal Liquidity Adequacy Assessment Process (ILAAP) and the related submission packages. The clarification does not introduce a new regulatory framework or additional requirements. Rather, it complements the existing ECB ICAAP Guide and provides further clarity on how institutions are expected to implement, govern and evidence these processes, particularly where supervisory reviews have identified inconsistencies in practice.
The underlying message is clear: ICAAP and ILAAP should function as embedded management frameworks, rather than as exercises primarily designed for supervisory reporting. Capital and liquidity assessments should feed into governance, strategic planning, risk management and day-to-day management decisions, with ICAAP remaining an important input to the Supervisory Review and Evaluation Process (SREP).
The ECB has not amended the seven ICAAP principles. Instead, clarification places greater emphasis on their effective implementation and on the evidence institutions can provide that they operate in practice.
The principles continue to cover:
The broader ICAAP architecture should connect strategy, capital planning, risk identification, risk appetite and limits, risk quantification, stress testing and reporting. This integration should also be reflected across the three lines of defense, ensuring that ICAAP is connected to the institution’s wider risk management framework rather than operating as a standalone process.
A central theme of the clarification is the relationship between the Normative Perspective and the Economic Perspective. The two should operate as a continuous, bidirectional feedback loop: economic risk assessments should inform capital planning, while normative outcomes should help identify risks that may affect regulatory capital.
Where the two perspectives lead to different conclusions, the rationale for management decisions and any resulting adjustments should be transparent, justified and documented.
The Economic Perspective should also have a tangible role in management decisions, including:
This reinforces the distinction between regulatory capital requirements and management buffers. Management buffers are an internal management concept, determined by the institution’s own risk appetite and capital planning. They should therefore be understood as an internal safeguard for management purposes, rather than as a regulatory minimum or a measure of available capital.
The clarification also reinforces expectations around the quality, appropriateness and governance of risk quantification. Methodologies should reflect the institution’s business model, risk profile, size, complexity and risk appetite. Importantly, risks should not simply be excluded because they are difficult to quantify or supported by limited data; where quantification is challenging, institutions are expected to apply appropriately conservative approaches.
Data quality therefore becomes an important component of the overall framework, covering attributes such as:
Independent validation remains an essential safeguard. Where institutions rely on vendor models, they should demonstrate sufficient understanding of those models and ensure that they are appropriately tailored to their own risk profile.
The same principle applies to outsourcing: while operational activities may be transferred to a third party, responsibility for the underlying risk remains with the institution. A forward-looking assessment of the risks associated with an outsourcing arrangement should therefore take place before implementation.
Stress testing should provide a forward-looking view of how severe but plausible scenarios could affect an institution’s capital and liquidity position. The ECB also emphasises the interaction between ICAAP and ILAAP stress testing, including the combined effects of capital and liquidity pressures, funding constraints and potential asset liquidation.
Reverse stress testing adds another dimension by examining scenarios that could threaten the viability of the institution’s business model. The resulting insights should feed into capital, liquidity and funding plans, which are expected to remain dynamic and responsive to emerging vulnerabilities.
This places a clear responsibility on the management body: it should not only approve the relevant frameworks, but also understand the vulnerabilities and management actions identified through them.
The clarification also reinforces the ECB’s move towards more continuous supervisory visibility. Following the approach introduced in the 2025 SREP cycle, institutions submit their ICAAP and ILAAP documentation through a two-leg approach:
The CAS and LAS are indicative of around 15 pages, while continuous submissions are intended to capture substantive changes rather than editorial amendments. The objective is to give Joint Supervisory Teams more timely visibility of material developments and support more proactive supervision.
The significance of the ECB’s clarification therefore lies less in what institutions are required to do differently on paper and more in how convincingly they can demonstrate that existing expectations are embedded in practice.
Institutions should consider whether they can evidence, in particular:
Ultimately, the supervisory question is not simply whether an institution has an ICAAP or ILAAP framework in place. It is whether those frameworks actively support the understanding of risk, the planning of capital and liquidity, and the decisions through which the institution is managed.
Subscribe here to receive our newsletters
Targeted amendments following CRR3 preserve the core prudential framework while introducing important clarifications and operational changes.
The EBA’s proposed methodology combines a lighter reporting framework with a more risk-sensitive approach and the first structured integration of climate risk
The adoption of the Crypto-Asset Reporting Framework (CARF) and the updated Common Reporting Standard (CRS 2.0) through the EU Directive DAC8 marks a significant evolution in the international tax reporting landscape.