Banking Law And Model Risk Regulation Spain .

Banking Law and Model Risk Regulation in Spain

1. Introduction

Model risk regulation in Spain concerns the legal and supervisory controls applied when banks use mathematical, statistical, econometric or machine-learning models to measure and manage financial risks.

Examples include models used for:

credit-risk scoring;

probability of default (PD);

loss given default (LGD);

exposure at default (EAD);

counterparty credit risk;

market risk;

stress testing;

impairment;

capital requirements;

liquidity forecasting; and

regulatory risk-weight calculations.

Spain does not have a single statute called a “Model Risk Regulation Act.” Instead, model risk is regulated through the EU Capital Requirements Regulation (CRR), CRR3, Capital Requirements Directive, ECB/SSM supervision, EBA standards and guidelines, and Spanish supervisory law.

For Spanish banks, the European framework is particularly important because since 2014 significant Spanish credit institutions have been directly supervised within the Single Supervisory Mechanism (SSM) by the ECB, with the Banco de España participating in supervision. The Banco de España's supervisory model expressly includes investigation and, where appropriate, authorization of internal models used to calculate capital requirements for credit, counterparty, market and operational risks.

 

2. Meaning of Model Risk

Model risk can arise when a bank relies on a model that produces an inaccurate or inappropriate result.

For example, a credit-risk model may underestimate the probability that borrowers will default.

If the bank uses that model to calculate regulatory capital, the consequences can extend beyond an individual lending decision.

An inaccurate model could produce:

underestimated risk → lower risk-weighted assets → lower required capital → insufficient loss-absorbing capacity.

For this reason, model risk is also a prudential banking risk.

The EBA has a specific mandate to develop technical standards and supervisory guidance concerning internal models used for IRB credit risk, counterparty credit risk and market risk.

 

3. Institutional Structure in Spain

Model-risk supervision in Spain involves several institutions.

European Central Bank

The ECB directly supervises significant Spanish banks under the SSM and is responsible for major decisions concerning internal-model permissions and prudential supervision.

Banco de España

The Banco de España participates in the SSM and supervises less significant institutions under the applicable framework. It also performs inspections, ongoing supervision and model-related supervisory work.

European Banking Authority

The EBA develops technical standards, guidelines and supervisory convergence tools.

European Commission

The Commission adopts delegated and implementing regulations under the CRR framework.

Spanish legislation

Spanish banking legislation provides the domestic institutional and enforcement framework within which the EU prudential rules operate.

This produces a layered system rather than a purely national Spanish model-risk regime.

 

4. Capital Requirements Regulation

The central legal instrument is Regulation (EU) No 575/2013 — the Capital Requirements Regulation (CRR), as amended, including by CRR3, Regulation (EU) 2024/1623.

The CRR establishes the conditions under which banks may use internal models for regulatory capital purposes.

The ECB's current internal-model guide explains that Articles 143, 283 and 325 CRR concern permissions for internal models covering credit risk, counterparty credit risk and market risk.

This is important because banks do not have an unrestricted right to choose any mathematical model they prefer.

Where a model is used to calculate regulatory capital, the bank must satisfy prescribed regulatory requirements.

 

5. Internal Ratings-Based Approach

The Internal Ratings-Based (IRB) approach allows qualifying banks to use internal estimates for credit-risk parameters rather than relying entirely on standardized regulatory risk weights.

Important parameters include:

probability of default;

loss given default;

exposure at default; and

maturity.

These parameters affect the calculation of risk-weighted exposure amounts.

The advantage is greater sensitivity to the actual risk profile of exposures.

The corresponding danger is model risk.

If a bank systematically underestimates risk, its capital requirement can also be understated.

The EBA's model-validation work therefore focuses on harmonizing internal-model governance across different types of prudential models.

 

6. Regulatory Permission

A bank cannot simply announce that it will use an internal model for regulatory capital and immediately rely on it.

The CRR requires regulatory permission where the relevant internal-model approaches are used.

The ECB's 2025 guide confirms that the ECB grants permission for internal models where the CRR requirements are satisfied and subsequently conducts model investigations and ongoing monitoring.

This creates a lifecycle:

development → validation → application → supervisory approval → ongoing monitoring → remediation or possible restriction.

 

7. Model Governance

A bank should have a formal model-governance framework.

It should identify:

who owns the model;

who develops it;

who validates it;

who approves it;

who monitors it;

who can modify it;

how deficiencies are escalated; and

when the model must be replaced or recalibrated.

The central principle is independence.

The person who develops a model should not be the only person deciding whether that model works properly.

This principle is particularly important where models influence regulatory capital.

 

8. Independent Validation

Model validation is a central component of model-risk management.

Validation should test whether:

the model performs as intended;

assumptions remain appropriate;

data are reliable;

estimates remain stable;

predictions are sufficiently accurate;

limitations are understood;

results remain reasonable during stress; and

the model is being used within its approved scope.

The ECB states that internal validation plays a key role in assessing the reliability and accuracy of significant institutions' internal models. It also requires significant institutions using IRB models to submit standardized validation information concerning PD, LGD and credit-conversion-factor models.

 

9. Back-Testing

Models should be compared with actual outcomes.

For example, if a model predicts that a portfolio has a particular probability of default, actual default experience should subsequently be examined.

This allows the bank to determine whether the model systematically:

overpredicts risk;

underpredicts risk; or

performs reasonably well.

Market-risk models have additional requirements concerning back-testing and profit-and-loss attribution under the Basel/CRR framework.

Back-testing is therefore a practical mechanism for identifying model deterioration.

 

10. Stress Testing

Historical accuracy is not enough.

A model can perform well under normal conditions but fail during a crisis.

Banks therefore need stress testing.

Examples include scenarios involving:

severe recession;

unemployment increases;

property-price declines;

interest-rate shocks;

market volatility;

sovereign stress;

liquidity disruption; or

simultaneous deterioration across several risk factors.

The Basel internal-model framework requires rigorous stress-testing programmes for banks using internal models for market risk.

Spanish supervisors also use stress testing as part of the broader supervisory framework.

 

11. Data Governance

A sophisticated model cannot compensate for poor data.

Model-risk management therefore includes:

data accuracy;

completeness;

consistency;

lineage;

representativeness;

storage;

access controls; and

documentation.

The ECB's 2025 internal-model guide expressly adds supervisory expectations concerning data governance and the use of machine-learning techniques in internal models.

This is increasingly important for Spanish banks using large datasets or automated modelling techniques.

 

12. Machine Learning and AI Models

Modern banking models may incorporate:

machine learning;

neural networks;

gradient boosting;

automated feature selection;

alternative data; and

other advanced statistical techniques.

The fact that a model uses AI does not exempt it from prudential requirements.

The ECB's July 2025 internal-model guide specifically clarified supervisory expectations concerning machine-learning techniques.

The regulatory concern is not simply whether the technology is “AI.”

The important questions are:

Can the model be validated?

Is the data reliable?

Are the assumptions understood?

Can the bank demonstrate compliance with the CRR?

Can the supervisor understand enough of the model to assess its prudential reliability?

 

13. Explainability

Complex models can create explainability problems.

A traditional regression model may allow a bank to explain why a particular variable affects a prediction.

A complex machine-learning model may make that explanation considerably more difficult.

For prudential purposes, however, a bank must still be able to demonstrate that the model satisfies regulatory requirements.

Explainability therefore becomes part of model governance.

This does not necessarily mean every model must be mathematically simple.

It means that the institution must maintain sufficient documentation, validation and controls to demonstrate appropriate use.

 

14. Model Documentation

Model documentation should normally describe:

purpose;

scope;

methodology;

assumptions;

variables;

data sources;

estimation period;

calibration;

limitations;

validation;

performance;

overrides;

governance;

change history; and

approval status.

The Basel framework similarly emphasizes comprehensive documentation of internal models, including methodology, portfolio application, responsibilities and approval/review processes.

Documentation is especially important during a supervisory inspection.

 

15. Model Change Management

Models evolve.

Changes may be necessary because:

new data become available;

portfolios change;

economic conditions change;

regulatory requirements change;

model weaknesses are identified; or

new methodologies become available.

However, a bank cannot make unrestricted changes to a regulatory model.

Material changes can require supervisory approval or notification depending on the relevant CRR provisions and applicable regulatory framework.

The bank must therefore maintain a controlled model-change process.

 

16. Model Inventory

A large bank may have hundreds or thousands of models.

A proper model-risk framework therefore requires a central model inventory.

The inventory should identify:

model name;

business owner;

purpose;

risk type;

regulatory status;

materiality;

validation date;

approval date;

next review;

known limitations; and

dependencies.

This allows senior management and supervisors to understand the institution's model ecosystem.

 

17. The Three-Lines Structure

Model-risk governance is commonly organized through three lines of control.

First line

Business and risk teams develop and use models.

Second line

Independent model-risk management challenges and oversees models.

Third line

Internal audit independently evaluates the framework.

The purpose is to prevent model developers from becoming the sole judges of their own models.

 

18. Model Risk and SREP

Model risk is also relevant to the Supervisory Review and Evaluation Process (SREP).

SREP examines matters such as:

business model;

governance;

risks to capital;

capital adequacy;

liquidity;

internal controls; and

risk-management systems.

The EBA's SREP framework specifically covers internal governance and institution-wide control arrangements, risks to capital and adequacy of capital, and liquidity and funding risks.

Consequently, model deficiencies can become broader prudential concerns.

 

19. Pillar 1 and Pillar 2

A useful distinction is between:

Pillar 1

Standardized regulatory requirements under the CRR, including approved internal-model approaches where permitted.

Pillar 2

Supervisory assessment of risks not sufficiently captured by Pillar 1.

This distinction is important because a bank may comply with a formal accounting or capital calculation rule and still face additional prudential requirements if the supervisor identifies a risk inadequately captured by the bank's systems.

The CJEU's recent Deutsche Bank and Others v ECB judgment confirmed the importance of the ECB's second-pillar powers to identify specific prudential risks and impose appropriately reasoned corrective measures following individual supervisory assessment.

 

20. Climate and Environmental Model Risk

Model risk increasingly includes climate-related risks.

Traditional historical data may not adequately represent future climate-related losses.

For example:

historical flood losses may underestimate future losses;

property valuations may fail to reflect transition risks;

carbon-intensive borrowers may face changing regulatory costs;

physical climate events may affect collateral values.

The ECB's revised internal-model guide has specifically clarified expectations regarding the inclusion of material climate-related risks in models.

Spanish banks therefore need to consider whether their historical datasets and modelling assumptions remain appropriate in a changing risk environment.

 

21. Model Risk and Accounting Models

Not every banking model is a regulatory-capital model.

Banks also use models for:

IFRS 9 expected-credit-loss calculations;

provisioning;

valuation;

liquidity;

stress testing;

pricing;

fraud detection; and

business decisions.

The legal treatment can differ depending on the purpose.

A model used solely for internal management is not necessarily subject to exactly the same approval regime as an IRB model used to determine regulatory capital.

Nevertheless, serious model deficiencies can still become prudential concerns if they affect the bank's risk management or financial position.

 

22. Consumer Protection and Credit Models

Credit-scoring models can also raise consumer-law and data-governance issues.

For example, a bank may use an automated model to determine whether a customer qualifies for credit.

The bank must consider applicable requirements concerning:

data protection;

accuracy of personal information;

fairness;

explainability where legally required;

non-discrimination;

governance; and

human oversight where applicable.

Therefore, model risk is not limited to capital calculations.

It can also affect individual customers.

 

23. Model Outsourcing

Banks may obtain models or modelling components from external vendors.

That does not eliminate the bank's regulatory responsibility.

The bank must still understand:

what the model does;

what data it uses;

how it is validated;

how it changes;

what limitations exist; and

whether the vendor can provide adequate documentation.

A bank cannot reasonably defend a regulatory model failure merely by saying that the model was supplied by a third party.

 

Important Case Law

There are relatively few Spanish judgments specifically titled “model risk regulation.” This is because internal-model regulation is principally an EU prudential-supervision matter and many disputes concern ECB supervisory powers rather than the mathematical model itself.

The following cases are therefore important because they establish the legal principles governing internal models, prudential discretion, individual risk assessment, capital requirements and ECB supervision.

1. Crédit Mutuel Arkéa v ECB — Joined Cases C-152/18 P and C-153/18 P (2019)

This is a foundational SSM case.

The CJEU considered the ECB's supervisory role and the relationship between the ECB and national authorities.

The Court confirmed the importance of the ECB's role in ensuring consistent prudential supervision within the Banking Union.

Model-risk relevance

Internal models cannot be assessed entirely through national approaches.

For significant Spanish institutions, model permissions and prudential decisions operate within the common SSM framework.

The judgment therefore supports the principle of centralized and harmonized prudential supervision.

 

2. Société Générale v ECB — T-143/18 (2020)

The General Court considered the ECB's power to impose prudential measures under the SSM framework.

The case formed part of a series of judgments concerning ECB second-pillar powers and the treatment of risks affecting regulatory capital.

Model-risk relevance

The case illustrates that compliance with the mechanical requirements of the CRR does not necessarily prevent the ECB from examining whether the bank's overall risk-management arrangements adequately capture prudential risks.

This principle is highly relevant to model risk.

A bank may have a technically approved model but still face supervisory scrutiny if the model or related arrangements inadequately capture a material risk.

 

3. Crédit Agricole and Others v ECB — T-144/18 (2020)

The General Court examined the ECB's prudential powers in relation to capital treatment.

The judgment formed part of the coordinated litigation concerning the ECB's ability to impose additional prudential measures.

Model-risk relevance

The case supports the broader principle that the ECB can assess whether a bank's risk-management arrangements adequately address prudential risks.

Model approval is therefore not the end of the supervisory process.

Ongoing supervisory assessment remains possible.

 

4. Confédération Nationale du Crédit Mutuel and Others v ECB — T-145/18 (2020)

This case was another part of the 2020 litigation concerning the scope of the ECB's prudential powers.

Model-risk relevance

The case demonstrates the distinction between:

formal compliance with a first-pillar rule

and

the supervisor's broader assessment of whether the institution's risks are adequately controlled.

That distinction is fundamental to modern model-risk management.

 

5. BPCE and Others v ECB — T-146/18 (2020)

The General Court again examined the ECB's supervisory powers under the SSM framework.

Model-risk relevance

For model governance, the case reinforces the importance of the second pillar.

A regulatory model should not be treated as an isolated mathematical calculation.

The supervisor can consider the bank's broader arrangements, strategies, processes and mechanisms for managing risks.

 

6. Arkéa Direct Bank and Others v ECB — T-149/18 (2020)

This judgment formed part of the same line of cases concerning ECB prudential intervention.

Model-risk relevance

The case is useful for understanding the supervisory relationship between standardized CRR rules and additional prudential measures.

It supports the concept that prudential supervision is not exhausted by checking whether a bank has mechanically complied with a formula.

 

7. BNP Paribas v ECB — T-150/18 and T-345/18 (2020)

The General Court's BNP Paribas judgment also addressed the ECB's ability to use second-pillar supervisory powers.

These cases are particularly useful when analyzing the legal boundary between:

first-pillar capital rules;

accounting treatment;

prudential risk assessment; and

additional supervisory requirements.

The 2026 CJEU judgment in Deutsche Bank and Others v ECB expressly referred to this 2020 series of judgments when discussing the ECB's second-pillar powers.

 

8. ECB v Crédit Lyonnais — C-389/21 P (2023)

This is a particularly important case concerning individual assessment and supervisory discretion.

The case involved ECB treatment of certain exposures and the supervisory assessment of risk.

The CJEU emphasized that where an institution enjoys discretion, the decision-maker must observe procedural guarantees, including carefully and impartially examining all relevant aspects of the individual situation.

Model-risk relevance

This principle is directly useful for model-risk regulation.

A supervisory authority should not simply apply a model or methodology mechanically.

It should consider relevant institution-specific circumstances.

Likewise, banks should maintain sufficient data and documentation to demonstrate why a model is appropriate for their particular portfolio.

 

9. Crédit Mutuel Arkéa v ECB — C-152/18 P and C-153/18 P

The Crédit Mutuel Arkéa judgment is also important because the Court confirmed the institutional structure of the SSM and the ECB's role in prudential supervision.

The Court emphasized the objective of ensuring the consistent application of prudential requirements within the Banking Union.

Model-risk relevance

Model-risk governance must therefore be understood as part of EU-level prudential convergence, not merely as a matter of Spanish banking practice.

 

10. Deutsche Bank AG and Others v ECB — C-556/24 P (2026)

This is a particularly current authority.

On 29 January 2026, the CJEU dismissed an appeal concerning ECB prudential measures involving irrevocable payment commitments and CET1 capital.

The Court held that the ECB has second-pillar powers to impose individual prudential measures where a supervisory assessment identifies a risk that is not sufficiently addressed by first-pillar requirements.

The Court emphasized several principles highly relevant to model-risk regulation:

the ECB can identify risks not adequately covered by first-pillar rules;

prudential measures may be institution-specific;

the ECB must perform an individual examination;

supervisory decisions must be properly reasoned;

evidence must be reliable and consistent; and

the supervisory assessment must concern a real situation rather than a purely hypothetical risk.

This is one of the strongest recent authorities for understanding the legal architecture surrounding prudential model risk.

 

24. Legal Principles From the Case Law

The cases collectively establish several important principles.

Principle 1 — Model compliance is not the same as risk compliance.

A bank can satisfy a formula while still presenting a prudential risk requiring supervisory attention.

Principle 2 — Supervisory assessment must be individualized.

The ECB cannot simply assume that every institution presents identical circumstances.

Principle 3 — Supervisory discretion has legal limits.

Where authorities have discretion, they must consider relevant facts carefully and impartially.

Principle 4 — Decisions must be reasoned.

A bank must be able to understand the basis for a supervisory requirement.

Principle 5 — Evidence matters.

Supervisory conclusions should be supported by reliable and relevant information.

Principle 6 — Model approval is not permanent immunity.

Internal models remain subject to ongoing supervisory monitoring.

 

25. Ongoing Model Monitoring

A critical feature of Spanish/EU model regulation is that approval is not the end of the process.

The ECB conducts ongoing model monitoring.

The ECB explains that significant institutions with approved IRB models must provide annual validation information, including statistical measures concerning PD, LGD and credit-conversion-factor models.

This means the regulatory lifecycle is:

approval → implementation → monitoring → validation → benchmarking → remediation.

 

26. Model Performance Deterioration

A model can become inaccurate even if it was originally valid.

Reasons include:

economic changes;

changes in borrower behavior;

portfolio composition changes;

new products;

regulatory changes;

data deterioration; and

structural economic breaks.

Therefore, model governance must be continuous.

Banco de España's earlier supervisory material expressly recognized that credit-risk models and portfolios are dynamic and that initial supervisory validation must be complemented by continuing model monitoring.

 

27. Regulatory Consequences of Model Failure

If a model no longer satisfies regulatory requirements, possible consequences can include:

remediation;

restrictions on model use;

additional capital requirements;

supervisory findings;

model redevelopment;

increased conservatism;

withdrawal of permission;

return to a standardized approach; or

other prudential measures.

The precise consequence depends on the nature and severity of the deficiency.

 

28. CRR3 and the New Model Environment

CRR3 has materially changed the internal-model landscape.

The 2025 ECB guide reflects CRR3 changes concerning:

credit-risk models;

market-risk models;

internal-model permissions;

output-floor requirements;

data governance; and

machine-learning techniques.

One important policy direction is reducing excessive variability in risk-weighted assets generated by different internal models.

The EBA's work on the IRB framework similarly seeks greater consistency and reduced unwarranted variation in risk estimates.

 

29. Model Risk and the Output Floor

The output floor is particularly significant.

It limits the extent to which a bank's internally modeled risk-weighted assets can fall below a specified proportion of the standardized approach calculation.

This reduces the possibility that internal models produce extremely low capital requirements compared with standardized calculations.

Consequently:

internal model → regulatory risk estimate

is increasingly supplemented by:

standardized calculation → output-floor constraint.

This creates an additional safeguard against excessive model optimism.

 

30. Model Risk Management Framework for a Spanish Bank

A comprehensive framework should contain:

Governance

Board-level responsibility and clearly allocated model ownership.

Inventory

A complete list of models and their regulatory materiality.

Development standards

Documented methodology and data requirements.

Independent validation

Separate challenge and validation functions.

Performance monitoring

Regular back-testing and benchmarking.

Stress testing

Testing under severe but plausible scenarios.

Data governance

Reliable data, lineage and quality controls.

Change management

Formal procedures for model modifications.

Documentation

Complete technical and regulatory records.

Regulatory communication

Timely interaction with the ECB/Banco de España where required.

Remediation

Documented correction of identified deficiencies.

 

Conclusion

Model risk regulation in Spain is fundamentally an EU prudential-supervision subject implemented through the CRR/CRR3 and the Single Supervisory Mechanism, with the ECB and Banco de España playing central supervisory roles. Spanish banks using regulatory internal models cannot treat them as ordinary proprietary mathematical tools. The models become part of the bank's prudential infrastructure and are subject to regulatory permission, validation, monitoring and supervisory review.

The current framework is becoming more demanding. The ECB's 2025 Guide to Internal Models expressly addresses governance, data quality and machine-learning techniques and reflects CRR3 developments affecting credit, market and counterparty-risk models.

The most relevant jurisprudence includes:

Crédit Mutuel Arkéa v ECB — Joined Cases C-152/18 P and C-153/18 P

Société Générale v ECB — T-143/18

Crédit Agricole and Others v ECB — T-144/18

Confédération Nationale du Crédit Mutuel and Others v ECB — T-145/18

BPCE and Others v ECB — T-146/18

Arkéa Direct Bank and Others v ECB — T-149/18

BNP Paribas v ECB — T-150/18 and T-345/18

ECB v Crédit Lyonnais — C-389/21 P

Deutsche Bank and Others v ECB — C-556/24 P (2026)

The recent Deutsche Bank judgment is particularly significant because the CJEU confirmed that the ECB can use second-pillar powers to address institution-specific prudential risks not sufficiently covered by first-pillar rules, provided the supervisory assessment is properly grounded, individualized and capable of judicial review.

The central legal principle is therefore:

A bank's model must not merely be mathematically sophisticated; it must be appropriately governed, documented, validated, monitored and capable of producing prudentially reliable results. Regulatory approval is not the end of model risk management—ongoing validation and supervisory scrutiny remain essential.

LEAVE A COMMENT