PRA IFRS 9 ECL Letter 2026: Data Governance Joins the Auditor Review

RegReportingDesk card: PRA, Prudential Regulation Authority, United Kingdom

On 30 September 2026 the Prudential Regulation Authority published a Dear CFO letter from David Bailey, its Executive Director for Prudential Policy, setting out thematic feedback on IFRS 9 expected credit loss (ECL) accounting. The PRA IFRS 9 ECL letter draws on the written reports that auditors of the major UK-headquartered banks and building societies sent the regulator in 2026. This year it adds something the earlier rounds did not cover: the PRA reviewed firms’ governance and controls over ECL data for the first time, alongside the model risk and climate risk themes it continued to monitor from its 2025 assessment.

The stakes sit in the letter’s next steps. For its 2027 review, the PRA has asked auditors for their views on firms’ progress against the areas of focus set out in the annex, and it encourages each firm to perform its own assessment and share it with its auditors. It has also asked auditors for views on how firms identify and monitor credit risk in private market exposures and reflect changes in ECL on a timely basis.

Much of what the annex describes lands directly on finance and reporting teams: critical data elements, reconciliations, lineage into financial reporting outputs, post-model adjustments and the monitoring packs behind them. The backdrop is a low provisioning level. The letter reports that aggregate ECL coverage across firms and asset classes is at its lowest since before Covid, says that this does not in itself indicate under-provisioning, and treats data governance and controls as part of what gives confidence that low cover reflects underlying asset quality.

Related reading: UK FINREP Reporting: PRA Rules, Templates and Filing Deadlines

Five dates around the 2027 written auditor report cycle

The working calendar comes from the Auditors Part of the PRA Rulebook and from SS1/23 and SS5/25, the two supervisory statements the annex footnotes as existing expectations; the letter sets no compliance deadline of its own.

  • 30 September 2025: the previous Dear CFO letter on IFRS 9 ECL, covering written auditor reports received in 2025.
  • 3 December 2025: PS25/25 published SS5/25 on climate-related risks, replacing SS3/19 in its entirety from that date. The PRA said supervisors would not ask for evidence of firms’ internal reviews and action plans until at least after the end of the six-month review period.
  • 23 April 2026: the April 2026 version of SS1/23, the model risk management statement, took effect following the Low Impact Amendments Finalisation paper LIAF01/26.
  • 30 September 2026: this letter, covering written auditor reports received in 2026.
  • 120 days from the 2026 accounting reference date: the window in which the auditor must deliver the next written report under rule 8.4(1) of the Auditors Part. For a 31 December 2026 year-end, my count of 120 days beginning with that date ends on 29 April 2027.

One procedural rule shapes the timing. Rule 8.5 requires the auditor to consult the PRA in advance of preparing the report. The governing supervisory statement, SS1/16, adds the operating timetable: the PRA discusses the scope of the report with auditors and will decide it by the end of the second quarter of each financial year; once the scope has been decided, no further questions may be added before the report is due. The 30 September 2026 letter says the PRA has asked auditors for their views on firms’ progress in the identified areas for its 2027 review, but does not state when those questions were agreed. Firms should therefore not assume that a self-assessment prepared after publication of the letter will precede the auditor’s consultation with the PRA.

Who receives the PRA IFRS 9 ECL letter, and who sits outside Chapter 8

The letter is addressed to chief financial officers of selected PRA-regulated deposit-takers and does not say how those recipients were chosen. Its evidence base is the written reports that auditors provide under Chapter 8 of the Auditors Part, together with related discussions with auditors and firms and thematic work by PRA staff. Chapter 8 applies to the auditor of a firm that meets three conditions, the balance sheet test being measured as at the last accounting reference date:

  • the firm is a UK bank or building society;
  • it is not itself the subsidiary undertaking of an undertaking that is not a UK undertaking; and
  • it has an individual balance sheet total above £50 billion, or it belongs to a group with a consolidated balance sheet total above £50 billion.

For those firms, rule 8.3 requires the auditor to provide a written report to the PRA every year on the firm’s audited annual report and accounts. The report also covers the ultimate parent’s accounts where there is one, unless the auditor does not also audit that parent, and the ring-fenced holding company’s accounts where the firm is a ring-fenced body. Rule 8.4 says the report must give information about key judgment areas, including matters of valuation, quality of earnings, key accounting judgments, and the quality of the systems and controls relevant to preparing the annual report and accounts. In my reading, ECL sits squarely in the last two.

Two groups fall outside that perimeter even when they apply IFRS 9 to large loan books. A UK bank owned by an overseas parent is excluded by the second condition whatever its size. A UK-headquartered bank or building society below £50 billion on both the individual and group measure is excluded by the third. Neither firm’s auditor produces a written report under Chapter 8, so neither firm contributes a Chapter 8 written auditor report to the evidence base behind this letter.

The annex is careful about how far its conclusions travel. The PRA says the areas of focus were developed with the size, nature and complexity of the written-reporting population in mind, and that it thinks the findings will generally be helpful to all firms applying IFRS 9 ECL. Helpful to all is a weaker statement than applying to all. The letter also states that, although it is not the PRA’s role to set, interpret or enforce accounting standards, the PRA has an interest in how they are implemented where that affects its statutory objectives. The areas of focus are described as aligned with, and building on, existing supervisory expectations in SS1/23 and SS5/25.

ECL data governance: what the first review found

The data feedback covers data capable of materially affecting ECL. The letter names customer and account data, collateral information, credit scores, macroeconomic forecasts, and arrears and forbearance data. Auditors’ reports were broadly positive and did not indicate a pervasive risk of material misstatement arising from ECL data. Firms generally had established governance and financial reporting controls. What varied was the maturity, documentation and consistency of application, across firms and across portfolios within the same firm.

Critical data elements that never pass through the model

Firms generally had processes for identifying critical data elements (CDEs) capable of materially affecting ECL. The better practice the PRA describes has three parts: sensitivity analysis that stresses individual model inputs against quantitative thresholds, qualitative criteria to catch items such as macroeconomic variables that a threshold test may miss, and periodic review and attestation of the CDE inventory after changes to models, systems or reporting processes.

The gap the letter identifies is narrower and more practical. There was less evidence that CDE frameworks consistently covered material data used outside core model execution, such as post-model adjustment (PMA) calculations or model monitoring. The letter describes this as consistent with SS1/23’s expectations on the integrity, quality and representativeness of data used in model and PMA processes; for PMAs, Principle 5.1(e)(iii) of SS1/23 expects the independent review to cover inputs, to ensure the integrity of the data used to calculate the PMA. An overlay computed in a spreadsheet from an arrears extract therefore draws on ECL data in the sense the letter means, even though no model ever consumes that extract. CDE inventories built by walking the model’s input layer will not find it.

Hand-offs between data providers and users

Firms generally assigned responsibility for data, systems and controls across the ECL process. The stronger frameworks assigned ownership at the level of individual CDEs, including monitoring, remediation and periodic attestation, used cross-functional governance committees for data standards and material data-quality issues, and documented formal hand-offs between data providers and users that set out quality requirements, intended use and fitness for purpose.

At some firms accountability stayed fragmented across systems, teams or locations. The letter associates unclear hand-offs with gaps in controls or with heavier reliance on downstream review and on specialist knowledge held by key personnel.

Reconciliations as the first line of detection

A common observation was reliance on manual reconciliations, trend analysis and other downstream reviews, in some cases with recurring manual remediation. The PRA accepts that these controls provide assurance over reported ECL and remain important. Its concern is the case where they are the principal way data-quality issues get found: they then give less direct assurance over data quality at source and can delay identification of root causes. The letter says this was most evident in legacy systems, non-core portfolios and manually intensive processes.

The PRA sees scope for firms to assess whether material data risks are addressed at the most effective points in the ECL data flow, and to consider stronger preventative and automated controls at source and at transfer and transformation points. It adds that this may support earlier remediation of upstream data used for more than one purpose. Auditors also identified unresolved general IT control weaknesses at some firms, including privileged access issues, which can increase the risk of unauthorised changes to critical data, systems or code.

Lineage and third-party hosting

Lineage maturity varied between firms and sometimes between portfolios. Better practice traced CDEs from source systems through significant transformations to model use and financial reporting outputs, refreshed lineage after changes to CDE definitions, source systems or models, mapped controls and owners to the significant points in the flow, and documented the governance of manual adjustments, including rationale, independent review, approval and post-implementation checks. Less developed practice relied on lineage maintained separately by individual system or control owners, with no consolidated end-to-end view, and gaps appeared for some legacy models and for data used in model monitoring or PMAs.

Several reports described frameworks for cloud infrastructure and third-party services used in ECL processes. The PRA encourages firms to keep under review the oversight of ECL data sourced from, processed by or hosted by third parties, including the scope and timeliness of external assurance over third-party controls and the adequacy of the complementary controls the firm itself operates.

What a clean ECL data review does not cover

Reporting teams should read one sentence of paragraph 8 closely: auditors’ reports did not assess firms’ wider risk data or regulatory reporting frameworks. A positive message on ECL data governance is therefore silent on the controls behind prudential returns, even where the returns draw on the same arrears, forbearance and collateral fields. The PRA’s remark about upstream data used for more than one purpose appears aimed at exactly that overlap, though the letter does not say so in terms. Where one arrears field feeds both the ECL engine and a regulatory return, a control placed at source serves both, while a correction applied only in the ECL reconciliation leaves the return exposed. The lineage disciplines involved are close to those discussed in our note on BCBS 239 risk data aggregation and reporting, although the letter itself does not refer to BCBS 239.

Post-model adjustments and model monitoring

The letter defines PMAs broadly: all model overlays, management overlays, model overrides or any other adjustments made to model output where risks and uncertainties are not adequately reflected in existing models. SS1/23 uses the same definition. The PRA remains focused on PMA completeness, so that provisions reflect actual expectations of credit losses, including risks the models or economic scenarios do not fully capture.

Firms generally separate PMAs for event-driven risks, such as geopolitical developments, from PMAs for persistent model limitations that need remediation. For the event-driven category, better practice included periodic horizon scanning, stand-back assessments of how responsive models are under different economic scenarios, defined triggers for considering a PMA, and separate review and approval routes for event-driven PMAs and PMAs that arise from model performance issues.

Monitoring at the level the model was built

Firms continued to introduce more granular and automated monitoring for newer models. The better practice monitors borrower cohorts and ECL components at the level used in model design; the letter’s examples are interest-only and near-maturity cohorts, and the separate probability of default (PD), exposure at default and loss given default (LGD) components. Less developed practice monitored only in aggregate, did not follow the model’s segmentation, or applied monitoring inconsistently across components. The letter also saw monitoring thresholds set too broadly to prompt timely investigation.

One finding deserves attention from anyone who prepares the ECL committee pack: back-testing that did not adequately distinguish model performance from economic forecasting error. IFRS 9 paragraph B5.5.52 requires an entity to regularly review its methodology and assumptions to reduce differences between estimates and actual credit loss experience. A gap between estimate and outcome can come from the model or from the forecast fed into it, and a back-test that cannot separate the two cannot tell management which of them to fix.

Economic input boundaries, which flag when current or forecast conditions move outside the ranges used in model development, were used inconsistently. Better practice documented the boundaries, calibrated them with sensitivity analysis, had them independently reviewed through validation, and investigated breaches.

Monitoring after the overlay

Pre-PMA monitoring remained the main way firms assessed underlying model performance. Post-PMA monitoring was less consistently formalised. For PMAs that address model limitations, the better practice linked pre- and post-PMA monitoring at the relevant cohort or component level to test whether the PMA was still calibrated appropriately. SS1/23 points the same way: Principle 5.1(d) expects the impact of PMAs to be made clear by presenting model results with and without them, and Principle 5.1(g) expects a process for considering whether material or recurring PMAs for the same limitation indicate flawed model design.

Strategic redevelopment continued to reduce reliance on PMAs for long-standing limitations, at a pace that varied across firms. The letter’s examples of better practice include replacing legacy models outright, segmenting borrowers more finely to capture affordability risk for those refinancing from historically low rates, and improving economic sensitivity using experience from high interest rate and inflation environments. On governance, it highlights independent checks that deployed models match the versions validated, consolidated assessments of validation effectiveness, and formal grading, escalation and tracking of validation findings. The PRA also thinks it important for model risk controls to keep pace with automation, covering monitoring tools and their code, the quality and lineage of monitoring data, and the completeness of model inventories and change records.

Where SS1/23 applies and where it does not

A firm cannot assume that every reference to SS1/23 in the letter binds it to SS1/23. Paragraph 1.2 of the supervisory statement limits its expectations to UK-incorporated banks, building societies and PRA-designated investment firms with internal model approval for regulatory capital, meaning IRB for credit risk, the internal model approach for market risk or the internal model method for counterparty credit risk. Firms without that permission are outside its expectations, although the PRA says they may find the principles useful. For firms inside the scope, paragraph 1.3 extends the statement to all models, explicitly including models used for financial reporting purposes, which brings IFRS 9 ECL models within the model risk framework. The April 2026 amendment made through LIAF01/26 clarified that the SS1/23 expectations are not conditions for internal model approval.

Climate risk in ECL: the refinancing-at-maturity question

No firm identified a material current-period impact of climate-related credit risk on ECL. The PRA nonetheless reports further progress, including more granular portfolio analysis, enhanced scenario analysis and stronger model and data governance. Its review looked at four capabilities: identifying the climate risk drivers most likely to affect ECL, using quantitative analysis to challenge ECL, adapting economic scenarios and weightings to include those drivers, and building the data and models to reflect them in loan-level ECL estimates.

The most specific climate point concerns refinancing. Firms generally concluded that current climate-related refinancing impacts were immaterial, citing short-dated exposures or limited evidence of impact on recent refinancing outcomes. The PRA observes that the evidence behind those conclusions was more limited than for other climate transmission channels.

The PRA sees scope for firms to consider more explicitly whether climate risks could affect a borrower’s ability to repay or refinance at loan maturity, for instance through higher borrowing, adaptation or insurance costs, or lower collateral values. A minority of firms had begun to build this into stress testing, credit assessment and monitoring. Better practice used forecast interest costs in climate models to assess how borrowing costs, debt levels and refinancing conditions affect creditworthiness, and brought climate-related refinancing risk into credit grading and monitoring, for example by assessing customers in high-emitting sectors whose transition plans were not aligned to the firm’s internal targets. Weaker practice relied mainly on broad sector assessments with little forward-looking borrower-level analysis.

Scorecards are the other pressure point. The letter reports that most firms used climate questionnaires and scorecards in corporate credit processes, but evidence that their outputs changed credit grades, watchlists, staging or ECL was limited. The better practice set escalation criteria for when a scorecard result should influence the ECL assessment.

On scenarios, direct incorporation of climate into the scenarios used to calculate ECL remained limited. Weaker practice relied mainly on longer-term scenarios, captured climate only through economy-wide indicators such as GDP, benchmarked against external climate scenarios without portfolio-level analysis, or considered climate only in the baseline scenario and left it out of the downside cases. Modelling examples in the letter include property-level PD modelling for flood, subsidence, storm and energy performance certificate (EPC) risks on the retail side, and transition risk models for specialised lending exposed to carbon pricing, such as shipping, project finance and power generation, on the corporate side. Corporate physical risk modelling was at an earlier stage.

For data teams, the most concrete detail is in paragraph 65: better practice used unique property identifiers to link internal data with EPC and flood-risk datasets, improving consistency and traceability. The letter also warns that as climate ECL work becomes more data-intensive, end-to-end governance and controls need to develop in parallel. That reads as carrying the CDE and lineage findings over to climate data and proxies.

The climate feedback presses on the evidence behind an immateriality conclusion. The letter’s stated benchmark is the PRA’s updated supervisory expectations in SS5/25, and the policy statement that introduced SS5/25 said, in its response to feedback on the draft, that the proposed policy was aligned to existing accounting standards and did not impose additional requirements.

Securitisation and recovery assumptions: observations outside the grey boxes

The annex uses two registers. Grey boxes mark areas of focus that the PRA will continue to monitor through written auditor reports. The securitisation and recovery material is presented as observations that firms are encouraged to consider where relevant to their exposures and risk management practices. A self-assessment that treats both alike will overstate the second.

On-balance-sheet securitisations

The review concentrated on firms with more material securitisation activity and on transactions where the securitised loans stayed on the firm’s balance sheet. In those cases firms generally continued to recognise ECL on the underlying loans and recognised credit protection benefits separately. Auditors did not identify significant current concerns about measuring those benefits, partly because expected defaults were low and protection was funded or collateralised. Governance at inception looked mature, but routine post-transaction monitoring of whether the protection benefit remains recoverable was less consistent. The letter says the risks relevant to recoverability under adverse conditions may include counterparty and wrong-way risk, legal enforceability, collateral access, claims processes and timing, valuation uncertainty and fraud risk.

The presentation finding matters for anyone who maps accounting lines into returns or management information. Across firms, credit protection benefits were reflected in reimbursement assets, issued liabilities, net interest income or credit impairment charges, and the review did not produce a clear and consistent picture of the gross and net financial statement effects. The PRA says it is important for internal reporting to give a clear view of the underlying credit risk, the credit protection benefit and the resulting net financial effect. Read across firms, that means a credit impairment charge can include the protection benefit at one firm and exclude it at another, depending on where the benefit is booked. For the capital side of these structures, see our summary of the BCBS report on synthetic risk transfers and capital relief.

The letter adds two related points. Where the underlying assets are derecognised, a case it places outside this assessment, the PRA says judgements on derecognition and controls over aggregate retained risk remain a supervisory focus, to be discussed with firms and auditors as appropriate. Where transactions involve unconsolidated entities, the letter says SS1/25 on step-in risk may also be relevant; that supervisory statement’s coverage also includes guidelines for completing the step-in risk reporting templates SI0, SI1 and SI2.

Recovery strategies and LGD

The letter says it remains important for firms to keep challenging whether the recovery assumptions behind LGD models are realistic. It saw targeted reviews of vulnerable sectors triggered by forward-looking developments such as expected market deterioration, policy changes and emerging funding pressures, but the reports said little about the indicators used to trigger those reviews. LGD models became more granular, though data availability still constrained some portfolios. For monitoring, the letter sees scope for firms to challenge whether LGD models remain responsive to a broader range of recovery strategies and adverse outcomes, which may include lower debt sale prices, longer recovery periods, higher forced sale discounts and more complex legal cases.

Private market exposures: the question for 2027

Private markets is the one topic the letter adds for the 2027 review outside the annex areas of focus. The PRA has asked auditors, for the 2027 review, for their views on firms’ processes for identifying and monitoring credit risks in private market exposures and for reflecting changes in ECL in a timely way. Its stated reason is the difficulty of identifying and aggregating these exposures and of obtaining timely and reliable data on complex, leveraged, interconnected and correlated risks.

The letter is explicit that this is forward-looking work to support wider cross-firm supervisory analysis, with no finding from the current review behind it. It also gives no definition of private market exposures. A firm preparing for the 2027 questions therefore has to decide which exposures its answer will cover and show how it aggregates them across the systems in which they are booked. That is an aggregation and data-sourcing exercise before it is a provisioning one. For a related EU supervisory view on private credit, see our note on the ESAs’ autumn 2026 risk update on private credit.

Turning the annex into a self-assessment

The letter encourages, without requiring, a firm-run assessment shared with the auditor. The annex already supplies the structure. The table below lists the grey-box areas of focus by paragraph, paraphrased, so each can carry an owner and evidence.

Annex paragraph Area of focus (paraphrased)
12 Range of methods to identify and refresh CDEs, with quantitative and qualitative thresholds; CDE frameworks extended to data used in model monitoring and PMAs
15 Clear, granular end-to-end accountability for CDEs, including controls at significant hand-offs
20 Balance of preventative and detective controls across the ECL data flow; remediation of general IT control weaknesses, including privileged access
23 Complete and usable end-to-end lineage for material ECL data, including manual interventions
29 Processes to respond to new and evolving risks, and completeness of PMAs
35 Monitoring aligned with model segmentation and components; links from monitoring outcomes to mitigating actions, including post-PMA monitoring
37 Delivery of strategic model redevelopment plans to reduce reliance on material PMAs
42 Consistent application of monitoring and validation enhancements; governance of automated monitoring and completeness of model inventories
45, 47 Wider sub-portfolio and sub-sector coverage of climate risk drivers; stress test outputs informing whether climate risks are reflected in ECL
51 End-of-term refinancing risk under combined climate and macroeconomic downside conditions
57, 60 Granular sector and portfolio quantitative assessments to refine PD and LGD; climate scorecards with escalation criteria into staging and ECL
63, 68 Broader downside climate scenarios, including short- and medium-term disorderly pathways; capabilities to translate scenarios into the climate risk variables relevant to the risk profile of the loans being assessed; climate model and data limitations, second-line review and proxy controls

Ownership is the first decision, because the rows cross three functions. A workable split, in my view, puts the CDE, hand-off and lineage rows with finance and data owners, the monitoring and PMA rows with model owners and validators, and the climate rows with credit risk. For firms within SS1/23’s scope, paragraph 1.7 already expects the model risk self-assessment to be updated at least annually and shared with the board. The model rows can sit in that document, but the data rows cover source systems, hand-offs and reconciliations that reach well beyond the model lifecycle and need their own named owners.

Evidence is the second decision. The better-practice descriptions in each section of the annex give the clearest benchmark of what the PRA considers mature: sensitivity-based CDE identification, CDE-level ownership with attestation, automated controls at transformation points, consolidated lineage, cohort-level monitoring, linked pre- and post-PMA monitoring, and documented escalation from climate scorecards. Rows where the honest answer is a downstream reconciliation used as the principal check, or an aggregate-only monitoring report, are the rows where the letter found less direct assurance at source or less developed practice.

Frequently Asked Questions

Our UK bank is above £50 billion but owned by a US group. Does the letter apply to us?

Chapter 8 excludes a firm that is the subsidiary undertaking of an undertaking that is not a UK undertaking, so your auditor would not be producing a written report under that Chapter and your firm would sit outside the Chapter 8 written-reporting population. The PRA’s view that the findings will generally be helpful to all firms applying IFRS 9 ECL still applies.

Does the letter change any FINREP, COREP or other regulatory return, or its submission dates?

The letter is thematic feedback on accounting practice, drawing on auditor reports among other inputs, and it amends no template, data item or remittance date. It also states that those reports did not assess regulatory reporting frameworks. Changes to PRA regulatory returns such as FINREP and COREP are made through the PRA Rulebook and the related supervisory statements.

Our year-end is not 31 December. How does the timing work?

The 120-day window in rule 8.4(1) runs from the firm’s own accounting reference date, so the written report deadline moves with the year-end. By analogy with this letter, which covers reports received in 2026, the 2027 review will draw on reports received in 2027; for a non-December year-end those may relate to a different financial year from a December filer’s.

We concluded that climate risk has no material effect on current-period ECL. Is that conclusion itself a problem?

The letter reports that no firm identified a material current-period impact, so the conclusion is common. Its concern is the support behind it, particularly for refinancing risk at maturity, where it found the evidence more limited than for other transmission channels. The annex contrasts forward-looking, borrower-level analysis for exposed sectors with weaker practice that relied mainly on broad sector assessments.

Is sharing our self-assessment with the auditor mandatory?

The letter encourages it, and no rule requires a firm to share one unprompted. Rule 8.6 of the Auditors Part does, however, require a firm to cooperate with its auditors in preparing the written report. The PRA has asked auditors for their views on progress against the areas of focus, so the auditor is asked for a view whether or not the firm shares one. The letter does not say how an auditor will use a shared assessment, so sharing is best treated as the firm putting its own view on record alongside the auditor’s.

Does the low ECL coverage chart mean the PRA thinks provisions are too low?

The letter says the lowest coverage since before Covid is consistent with improving asset-quality indicators and does not in itself indicate under-provisioning. The chart behind that statement plots aggregate ECL provisions as a share of lending for major UK deposit-takers from 2019 Q4 to 2026 Q2. The annex adds that its thematic work complements broader supervisory work to consider firms’ provision levels.

Do the private market questions affect our 2026 year-end ECL?

The letter places them in the 2027 review as a request for auditors’ views on processes, and describes them as forward-looking work with no finding from the current review. They introduce no new accounting requirement. IFRS 9 impairment requirements continue to apply to financial instruments that are within the standard’s ECL scope. The PRA letter does not define ‘private market exposures’, so it should not be assumed that every exposure captured by a firm’s working private-markets definition is itself subject to ECL.

Key Takeaways

  • Check the three Chapter 8 tests against the 2026 accounting reference date before assuming the auditor will be asked about the annex: UK bank or building society, no non-UK parent, and above £50 billion individually or at group level.
  • Prepare the firm’s self-assessment promptly and share it with the auditor as the letter encourages; do not assume it can be dated ahead of the rule 8.5 consultation, because SS1/16 provides for the scope of the written report to be discussed and decided earlier in the audit cycle.
  • Assess material data used in PMA calculations and model monitoring for inclusion in the CDE framework, with appropriate ownership and periodic review and attestation after changes to models, systems or reporting processes.
  • Ensure back-testing adequately distinguishes model performance from economic forecasting error.
  • Ensure internal reporting provides a clear view of underlying credit risk, credit protection benefits and the resulting net financial effect for on-balance-sheet securitisations.
  • Write down a working definition of private market exposures and the systems it is aggregated from before auditors form their views for the 2027 review.
  • Keep the grey-box areas of focus and the securitisation and recovery observations in separate parts of the self-assessment.

Sources and References

  • PRA, Letter from David Bailey, Thematic feedback on accounting for IFRS 9 expected credit losses (ECL), 30 September 2026: bankofengland.co.uk
  • PRA, Letter from David Bailey, Thematic feedback on accounting for IFRS 9 expected credit losses (ECL), 30 September 2025: bankofengland.co.uk
  • PRA Regulatory Digest, September 2025 (listing the 30 September 2025 letter): bankofengland.co.uk
  • PRA Rulebook, Auditors Part, Chapter 8 (Written Reports by Auditors to the PRA), rules 8.1 to 8.6: prarulebook.co.uk
  • PRA, SS1/16 Written reports by external auditors to the PRA (scope and timetable of questions): prarulebook.co.uk
  • PRA, SS1/23 Model risk management principles for banks (April 2026 version, effective 23 April 2026): publication page and PDF
  • PRA, LIAF01/26 Low Impact Amendments Finalisation, April 2026: bankofengland.co.uk
  • PRA, PS25/25 Enhancing banks’ and insurers’ approaches to managing climate-related risks, Update to SS3/19, 3 December 2025: bankofengland.co.uk
  • PRA, SS5/25 Enhancing banks’ and insurers’ approaches to managing climate-related risks, December 2025: bankofengland.co.uk
  • PRA, SS1/25 Step-in risk, 22 April 2025: bankofengland.co.uk
  • IFRS Foundation, IFRS 9 Financial Instruments (including application guidance paragraph B5.5.52): ifrs.org

Before the 2026 year-end ECL sign-off

For its 2027 review, the PRA has asked auditors of the largest UK-headquartered deposit-takers for their views on how firms identify and control the data that moves ECL, how they monitor models and overlays, how they evidence climate conclusions, and how they identify and monitor credit risks in private market exposures. The practical deliverable is a dated self-assessment against the paragraph 12 to 68 areas of focus, with named owners in finance, modelling and credit risk, in the auditor’s hands before the year-end ECL judgements are signed off and well inside the 120-day window that, for a 31 December year-end, closes on 29 April 2027.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • EBA 2026 O-SII List: Which EU Banks Carry an O-SII Buffer

    Updated July 2026In this guideWhat the EBA published on 2 June 2026The EBA does not designate your bankHow much capital the O-SII buffer demandsWhere the O-SII buffer sits in the capital stackWhat changes in your COREP and Pillar 3 reportingFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesReading the 2026 O-SII List Without Getting BurnedAn O-SII buffer…

  • BoE Delays November 2026 RTGS Standards Release: CHAPS Roadmap Reset

    The Bank of England will not run its November 2026 RTGS standards release. On 27 August 2026 the Bank confirmed it is deferring that release in its entirety, including the messaging standards for CHAPS payments, after Swift announced its decision to delay the November 2026 Swift Standards Release. For any CHAPS direct participant that had…

  • Non-Maturity Deposit Stability: What BCBS Working Paper 47 Signals

    Updated September 2026In this guideWhat the Committee actually published on 20 February 2026The 2023 question behind the reviewWhere deposit behaviour is priced into the LCRThe NSFR encodes the same split at a one-year horizonWhy a literature review lands on your models, not your ratiosPillar 2 and the supervisory review of deposit assumptionsWhat to check in…

  • Swedish Countercyclical Capital Buffer: Riksbank Holds at 2%

    On 10 September 2026 the Riksbank decided to leave the Swedish countercyclical capital buffer at 2 per cent, the level it treats as neutral; the decision was published on 11 September. For a reporting team the headline is that the Swedish rate is unchanged at 2 per cent, so this decision itself does not introduce…

  • EBA Third-Country Branch Reporting – What the New Harmonised Standards Mean for Your Branch

    Updated July 2026In this guideWhy This Framework ExistsWho Must ReportWhat Gets Reported: Annex I – Branch-Level TemplatesWhat Gets Reported: Annex II – Head Undertaking TemplatesReporting Frequencies and Remittance DatesRelationship to COREP and FINREPLuxembourg RelevanceTimeline and Transitional ProvisionsImplementation ChallengesCRR3 InteractionPractical Steps for ImplementationFrequently Asked QuestionsKey TakeawaysRelated ArticlesSources and ReferencesReport Library › Prudential ReportingIf you run regulatory…