COREP Reporting Explained: A Practical Guide to Prudential Reporting

Updated September 2026

What Is COREP and Why It Matters

COREP stands for Common Reporting. It’s the standardized format through which EU banks and other regulated entities submit their prudential information, covering capital adequacy, risk exposure, asset quality, and liquidity data, to supervisory authorities.

COREP is relevant to prudential reporting, regulatory finance and risk-reporting functions at institutions within the CRR supervisory-reporting perimeter. COREP is a core regulatory obligation. Regulators need consistent, timely data on capital adequacy and risk from thousands of institutions to monitor systemic risk, stress-test the financial system, and enforce prudential standards. Late, incorrect or missing regulatory reporting can result in supervisory follow-up and, depending on the applicable legal basis and circumstances, enforcement measures. Supervisors treat data quality as a core pillar of their oversight.

Related reading: IFRS 18 and FINREP Reporting: Interim Templates

Regulation and Legal Authority

COREP sits within the Capital Requirements Regulation (CRR) and Capital Requirements Directive framework. The core legal obligation comes from CRR Article 430, which requires institutions to report information to their competent authority on a regular basis. The European Commission adopts the supervisory-reporting ITS on the basis of draft technical standards developed by the EBA. The EBA separately publishes the reporting framework technical package, including the DPM, taxonomy and validation material.

Within the Single Supervisory Mechanism, supervisory competence depends on the institution’s status: significant institutions are directly supervised by the ECB, while less significant institutions are supervised by national competent authorities under ECB oversight. In Luxembourg, the CSSF is the national competent authority and operates the local first-level reporting arrangements. The CSSF publishes Luxembourg supervisory-reporting guidance and specifies local transmission arrangements, including eDesk/API. The statutory EBA-ITS reporting reference and remittance dates are laid down in Implementing Regulation (EU) 2024/3117 rather than being independently set by the CSSF.

The framework has evolved significantly. The original CRR (Regulation (EU) No 575/2013) has been amended by CRR2 (Regulation (EU) 2019/876, largely applicable from June 2021) and most recently by CRR3 (Regulation (EU) 2024/1623, applicable from 1 January 2025). CRR3 introduced the output floor, revised credit-risk rules and the new operational-risk framework from 2025. The CRR3 FRTB own-funds requirements for market risk are an exception: their application has been deferred until 1 January 2027, and the pre-FRTB market-risk framework continues to apply until then.

The EBA updates reporting templates periodically to reflect legislative changes. For the COREP modules covered here, EBA Reporting Framework 4.2 is the applicable framework. The EBA describes 4.2 as expected to apply from Q4 2025 on a module-specific basis and gives June 2026 as the first reference date for the additional COREP operational-risk requirements. The EBA consulted in 2026 on proposed amendments covering ESG, liquidity and leverage-ratio reporting. Those proposals are not current requirements and should be treated as future changes only once the relevant ITS and reporting framework become applicable.

Reporting Standards and Format

From the March 2026 reference date, the EBA reporting framework transitioned to xBRL-CSV. First-level collection arrangements remain subject to the competent authority’s specifications; in Luxembourg, the CSSF handbook specifies EBA framework version 4.2 in xBRL-CSV format and collects COREP/FINREP through eDesk/API. Your finance or compliance team typically doesn’t write these files by hand. You use reporting software that takes your underlying data and translates it into a valid submission that your NCA’s system can ingest. The software also validates your submission against the EBA’s technical specifications before you send it.

The validation rules are strict. A field might be required if certain conditions are met (e.g., if you’re a large institution reporting on IRB models, you must populate template C 08.01). Validation outcomes depend on the applicable validation rule and the competent authority’s collection process. Blocking errors must be corrected before an accepted filing can be completed, while institutions should follow the NCA’s published handling of other validation findings.

If your institution has not yet tested the xBRL-CSV submission pipeline, do so before your next live filing. The format transition introduces its own category of potential errors.

Who Has to Report?

Scope of Reporting Entities

Credit institutions are within the CRR supervisory-reporting framework, but the reports required at individual, consolidated or sub-consolidated level depend on the CRR application rules and any applicable waivers or exemptions. This includes traditional banks, as well as certain investment firms that remain subject to CRR requirements. Note that since the introduction of the Investment Firms Regulation (IFR, Regulation (EU) 2019/2033) and the Investment Firms Directive (IFD), most investment firms are no longer subject to CRR/COREP. They report under the IFR framework instead. Most MiFID investment firms are subject to IFR/IFD, but the CRR perimeter is not limited to firms above EUR 15 billion. Investment firms carrying out the relevant dealing-on-own-account or underwriting/firm-commitment activities can be subject to CRR under Article 1(2) or (5) IFR, including under the EUR 15 billion tests or competent-authority designation; firms meeting the EUR 30 billion CRD threshold are generally required to apply for authorisation as credit institutions, subject to the competent-authority waiver provided for in Article 8a(3a) CRD. Many institutions within the CRR reporting perimeter also have obligations under other EU regimes, but the scope of each regime must be assessed separately; the operational-resilience regime, for example, sets out DORA ICT incident reporting requirements separately from COREP.

The framework distinguishes between consolidated, individual, and sub-consolidated level reporting:

  • Individual level: Institutions apply the relevant CRR requirements on an individual basis where the individual-application rules apply, subject to the exemptions and waivers provided for in the CRR.
  • Consolidated level: Parent institutions and other entities required by the CRR to comply on the basis of their consolidated situation report at consolidated level in accordance with Articles 11 and 18 CRR.
  • Sub-consolidated level: Within a group, some entities also report on a sub-consolidated basis depending on regulatory requirements.

Your institution’s reporting scope depends on your legal structure, where you’re licensed, and whether you’re a standalone entity or part of a group. Reporting level is determined by the individual, consolidated and sub-consolidated application rules in the CRR. Individual reporting applies subject to the relevant exemptions and waivers, while consolidated reporting applies to the relevant parent or designated consolidating entity; group membership alone does not mean that every entity reports at both levels.

Proportionality and Thresholds

CRR Article 4(1)(145) defines an SNCI through a cumulative set of conditions, including average total assets of no more than EUR 5 billion over the preceding four-year period, with Member States able to lower that threshold. Proportionality affects specified reporting requirements and methodologies, but individual simplifications apply only where the CRR and ITS conditions are met; for example, simplified NSFR requires prior competent-authority permission.

Some templates are conditional. If you don’t have IRB models approved by your supervisor, you don’t report the IRB credit risk templates (C 08.01, C 08.02). If you’re not significant on a consolidated basis, your group may not report certain detailed breakdowns. Conditional reporting requires you to understand your own institution’s risk model approval and reporting scope.

Branches of third-country banks operating in the EU typically have reporting obligations determined by national law and the treatment of the branch under the local supervisory framework.

What Gets Reported: Key Templates and Data

Own Funds and Capital Requirements

Templates C 01.00 (Own Funds) and C 02.00 (Capital Requirements) are fundamental. C 01.00 breaks down your regulatory capital into Common Equity Tier 1 (CET1), Additional Tier 1 (AT1), and Tier 2, with detailed lines showing what’s included, what’s deducted, and what’s transitional. Where applicable transitional provisions remain relevant, C 05.01 reports transitional provisions, while C 05.02 reports grandfathered instruments not constituting State aid.

C 02.00 shows your capital requirements for credit risk, market risk, and operational risk by approach. Under CRR3, the operational-risk own-funds requirement is based on the Business Indicator Component (BIC) under Articles 312 and 313 CRR, subject to specific transitional provisions. In particular, Article 314(4) allows certain EU parent institutions previously permitted to use the alternative standardised approach for retail and commercial banking to continue that treatment for those business lines until 31 December 2027 or until the relevant permission under Article 314(3) is granted, whichever is earlier. For market-risk own-funds requirements, institutions continue to apply the pre-FRTB framework until 1 January 2027; the CRR3 FRTB capital requirements have been deferred until that date. Smaller banks using standardized approaches have simpler submissions.

Capital Ratios and Solvency

Template C 03.00 (Capital Ratios) shows your CET1 ratio, Tier 1 ratio, and Total Capital ratio as of the reporting date. These ratios determine whether you’re above regulatory minimums. The CRR Article 92 minimum CET1 ratio is 4.5%. Separately, the CRD combined buffer requirement comprises the 2.5% capital conservation buffer plus the applicable institution-specific countercyclical, G-SII/O-SII and systemic risk buffers. Pillar 2 requirements under the CRD are separate from the combined buffer requirement.

Template C 04.00 is the Memorandum Items template. Total risk exposure amount is reported in C 02.00; the total-assets datapoint specified in Article 15(2) of Implementing Regulation (EU) 2024/3117 is reported in C 40.00.

Credit Risk and Asset Quality Templates

Templates C 07.00 (standardised approach) and C 08.01/C 08.02 (IRB approach) report credit-risk exposures by the applicable exposure classes and reporting dimensions. Geographical breakdowns are reported separately in C 09.01 and C 09.02 where the Article 5(2) threshold in Implementing Regulation (EU) 2024/3117 is met. You’re showing where your credit risk is concentrated, essential for supervisors assessing systemic risk.

IRB templates are complex and require detailed inputs on probability of default (PD), loss given default (LGD), exposure at default (EAD), and model parameters. The underlying model assumptions must be consistently fed into your reporting system. A small error in how you classify an exposure or apply a rating may trigger validation findings depending on the applicable rule set.

C 09.01 and C 09.02 provide geographical breakdowns of exposures by residence of the obligor for SA and IRB exposures respectively. C 09.04 is a separate country breakdown used for the institution-specific countercyclical capital buffer; there is no C 09.03 in the current sequence. This is particularly important for institutions with significant exposures to specific regions. Your supervisor uses this data to stress-test your capital position under country-specific scenarios.

Large Exposures and Concentration Risk

Templates C 26.00 to C 29.00 cover large-exposure reporting. Under CRR Article 392, an exposure to a client or group of connected clients is a large exposure where its value is equal to or exceeds 10% of Tier 1 capital. Article 395 generally prohibits an exposure exceeding 25% of Tier 1 capital after the prescribed credit-risk-mitigation treatment, subject to the CRR’s specific rules and exemptions.

Large exposures must be validated carefully. A single client relationship might span multiple legal entities or jurisdictions, and grouping errors can arise. Some institutions maintain a separate large exposures register that feeds into their submission; others map from their credit risk system directly. Large-exposure reporting is subject to close supervisory scrutiny.

Leverage Ratio

The current leverage-ratio reporting set in Section 6 of Annex I includes C 40.00, C 43.00, C 44.00, C 47.00 and the applicable C 48 leverage-volatility reporting; it is not a contiguous C 43.00-to-C 47.00 template range. The leverage ratio denominator (total exposure measure) is calculated under Articles 429 to 429g CRR from the prescribed exposure values for assets, derivatives, securities-financing transactions, off-balance-sheet items and regular-way purchases or sales awaiting settlement, subject to the exclusions in Article 429a and the other adjustments specified in those provisions.

The leverage ratio has been a binding Pillar 1 minimum requirement since 28 June 2021, when CRR2 took effect. The minimum is 3% for most institutions, with a higher buffer for globally systemically important institutions (G-SIIs).

The leverage-ratio templates require detailed exposure-component reporting. Missing or mis-classified items, including incorrect treatment of collateral or securities-financing transactions, can produce an incorrect total exposure measure and may trigger validation findings.

Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR)

The current LCR template set comprises C 72.00, C 73.00, C 74.00, C 75.01, C 76.00 and C 77.00. These templates report your institution’s ability to meet a liquidity stress scenario over 30 days. You’re showing high-quality liquid assets against net cash outflows. These templates break out inflows and outflows by type of counterparty, maturity, and product.

CRR Article 412 establishes the liquidity-coverage requirement and Delegated Regulation (EU) 2015/61 specifies it in detail. The normal minimum LCR is 100%. CRR Article 412(3) expressly provides that institutions may use their liquid assets to meet their obligations under stressed circumstances as specified under Article 414; where the ratio falls or is expected to fall below 100%, the Article 414 CRR notification and liquidity-restoration requirements apply.

NSFR reporting is conditional by methodology: SNCIs using the simplified NSFR methodology with prior competent-authority permission report C 82 and C 83; other institutions report C 80 and C 81; all institutions in scope report C 84. The NSFR became a binding Pillar 1 requirement under CRR2 (from June 2021). You’re showing available stable funding relative to required stable funding. Like the LCR, NSFR must be at or above 100%.

Both liquidity template sets are data-intensive and depend on accurate classification by counterparty, product and maturity. LCR treatment also depends on the applicable liquid-asset haircuts and inflow/outflow rates, while NSFR treatment depends on the applicable available-stable-funding and required-stable-funding factors. A misclassification can affect the reported ratios, with the effect depending on the size and regulatory treatment of the item.

Other Templates

Operational risk (C 16.xx): Under CRR3, the operational-risk own-funds requirement is the Business Indicator Component (BIC). In CRR Article 314, ILDC means the interest, leases and dividend component of the Business Indicator, not an Internal Loss Data Component. Separate operational-loss information is reported in C 16.03. Under Reporting Framework 4.2, institutions continue to report C 16.01 using the updated technical tables from the March 2026 reference date, while C 16.02, C 16.03 and C 16.04 first become mandatory from the June 2026 reference date subject to the applicable ITS scope conditions; C 16.04 is specifically a quarterly template for EU parent institutions reporting subsidiaries subject to Article 314(3) CRR.

ESG reporting: The EBA consulted in 2026 on proposed ESG supervisory-reporting templates covering, among other items, transition and physical risk. Those proposals are not yet applicable supervisory-reporting requirements.

Remuneration reporting is a separate reporting area under the CRD/EBA framework with requirement-specific scope. High-earner data collection under Article 75(3) CRD is not limited to larger institutions; the EBA’s current Guidelines state that national competent authorities collect the relevant high-earner information for all credit institutions.

When and How Often: Reporting Frequency and Deadlines

Frequency by Template

COREP frequencies depend on the reporting requirement. Own-funds reporting includes quarterly and semi-annual information; large-exposure and leverage-ratio reporting are quarterly; NSFR is quarterly; and LCR reporting is monthly. Other requirements may be semi-annual or annual where the ITS specifies that frequency.

The exact frequency depends on the specific reporting requirement and any applicable proportionality conditions. Some requirements are quarterly, while reduced frequencies or other proportionality measures apply only where the CRR and Implementing Regulation (EU) 2024/3117 provide for them.

Submission Deadlines

Under Article 3 of Implementing Regulation (EU) 2024/3117, quarterly remittance dates are 12 May, 11 August, 11 November and 11 February; semi-annual remittance dates are 11 August and 11 February; annual reporting is due 11 February; and monthly reporting is due on the 15th calendar day after the reference date. Where a remittance date is a public holiday in the Member State of the competent authority, or a Saturday or Sunday, Article 3(2) moves the remittance date to the following working day. Article 3 does not provide a generic extended remittance deadline for SNCIs.

Your NCA may set specific portal submission windows. In Luxembourg under CSSF rules, always confirm the exact deadline with the CSSF’s published reporting calendar. Miss the deadline and your institution is non-compliant. Submitting 3-5 days before the deadline leaves time for resubmission if validation fails.

Multi-Stage Submission Process

Your submission isn’t instantaneous. You prepare data weeks in advance, validate it internally, send it to your NCA’s portal, and the NCA system validates again. The NCA applies its own collection and validation process. A submission may be rejected or returned with validation findings depending on the applicable rule and the NCA’s handling; institutions must correct and resubmit where required. This back-and-forth can extend over days.

The CSSF provides an eDesk PREPROD environment for testing supported reporting procedures. Institutions should use the published testing facilities and CSSF contact channels rather than assume that an informal supervisory pre-review is available.

COREP in Practice: Workflows, Tools, and Team Structure

Data Sources and System Landscape

COREP data comes from multiple systems. Capital and own funds typically feed from your general ledger and financial accounting system. Credit risk exposure and IRB data come from your credit risk or loan origination system. Liquidity data comes from your asset-liability management (ALM) or treasury system. Market risk data comes from your trading or valuation system.

No single system holds all the data. Your institution needs data governance: clear mappings from system outputs to template inputs, reconciliations across systems, and sign-offs. Accountability for each mapping and reconciliation needs to be clearly assigned.

Technology and Reporting Software

Specialized regulatory reporting software (from vendors such as Axiom/AxiomSL, Wolters Kluwer OneSumX, Regnology, or others) ingests data from your underlying systems, applies transformations, validates against EBA specifications, and outputs the required submission format.

The software is only as good as the data you feed it. If source data contain a classification error, that error can flow into the reported data and may trigger a validation finding depending on the applicable rule set; technical validation should not be treated as proof that the underlying data are correct.

Typical Team Structure

A medium-sized bank might have:

  • Head of Regulatory Reporting: Overall accountability, relationship with the supervisor, sign-off on submissions.
  • Senior Analyst / Template Owner: Owns one or more templates (e.g., the liquidity analyst owns C 72-C 77, the credit risk analyst owns C 07-C 09).
  • Data Engineer / ETL Developer: Builds and maintains the data pipelines and transformations.
  • Validator / QA Analyst: Runs pre-submission validation, checks for reasonableness, flags anomalies.

Smaller institutions might consolidate these roles. In a startup bank with 50 people, the head of compliance might personally handle COREP. Larger institutions have entire departments. The key is clear ownership: someone must be accountable for each template.

Typical Quarterly Workflow

Weeks 1-2 post-quarter-end: Underlying systems close and produce P&L, balance sheet, and risk reports. The reporting team begins reconciling these to previous submissions and prior-month expectations. Are capital ratios where they should be? Does credit risk exposure match what was expected?

Weeks 2-3: Data extraction begins. Credit risk, finance, treasury, and risk teams produce reports for each template. These go through internal review. Outliers are investigated.

Weeks 3-4: Configuration of the reporting software. The team loads the data, runs initial validation, and addresses any findings before resubmission. Common reasons for validation failures include missing required fields, inconsistent data types, failed cross-checks, or business logic errors.

Week 4+: Remediation. The team identifies the source of each validation error, fixes the underlying data in the source system or via corrections, and reloads. This cycle repeats until validation passes.

Final days: Final quality assurance. Management review. Submission to the NCA.

The time from quarter-end to submission deadline is compressed. If you start late or encounter major data issues, you’ll be under pressure.

Common Errors and Pitfalls

Data Reconciliation Failures

One of the most common issues is data not reconciling between systems. For example, your credit risk system shows EUR 10 million in exposure to a counterparty, but your financial accounting system shows only EUR 9.5 million. The difference might be due to collateral treatment, accrued interest, or a classification difference. Until it’s reconciled, your templates won’t be reliable.

Reconciliation must be systematic and documented. Your supervisor will find discrepancies in a supervisory review and ask why your reported figures don’t match your accounting records.

IRB Model Parameters

If you’re using IRB for credit risk, your reported capital requirements depend on probability of default (PD), loss given default (LGD), and exposure at default (EAD) estimates.

Common errors:

  • PD not updated: Your model was calibrated years ago, but actual default rates have changed. Using stale PD estimates means your capital requirement is too low or too high.
  • Counterparty classification inconsistency: A borrower is classified as small business in your risk system but as large corporate in your accounting system.
  • Exposure rollup error: You have exposures to a client at multiple business units, and only some are captured in the C 08.02 submission.

Liquidity Template Errors

LCR and NSFR templates are complex. Common errors include:

  • Wrong maturity assumption: A deposit with a stated maturity of 6 months classified as on-demand because the depositor can withdraw early in practice.
  • Haircut applied incorrectly: High-quality liquid assets have regulatory haircuts (e.g., 0% for cash and central bank reserves, 15% for Level 2A assets). If you apply the wrong haircut, your liquid asset position is wrong.
  • Off-balance-sheet items omitted: Committed credit and liquidity facilities, derivative cash flows and other contingent funding obligations must be treated in accordance with the applicable LCR outflow rules. For other products and services under Article 23 of Delegated Regulation (EU) 2015/61, institutions assess the likelihood and potential volume of outflows and competent authorities determine outflows for material items.

Audit Trails and Documentation

Your supervisor can ask at any moment: “Why is this number 50 basis points lower than last quarter?” You need to be able to answer in seconds. That requires audit trails, meaning a record of which system the number came from, when it was extracted, whether it was adjusted, and why.

Without systematic documentation, data lives in spreadsheets, adjustments are made informally, and six months later nobody can reconstruct the trail. Institutions that do this well have a centralized repository that logs every figure, its source, and any adjustments. It’s dry work, but it matters.

Recent Changes and Future Outlook

CRR3 Impact on Templates

CRR3 (Regulation (EU) 2024/1623), applicable from 1 January 2025, has introduced significant changes:

  • Operational risk overhaul: CRR3 replaced the former operational-risk framework with a Business Indicator Component-based own-funds requirement, subject to the Article 314(4) transitional ASA exception. Reporting Framework 4.2 updates C 16.01 and adds C 16.02-C 16.04; the latter three first become mandatory from the June 2026 reference date subject to their scope conditions.
  • Output floor: A floor on the benefit institutions can derive from using internal models, phasing in from 50% in 2025 to 72.5% by 2030.
  • Revised credit risk standardized approach: More granular risk weight buckets and revised treatment of certain exposure classes.
  • FRTB for market risk: CRR3 contains the new market-risk framework, but its own-funds requirements are deferred until 1 January 2027. The EBA has stated that the corresponding CRR3 FRTB reporting requirements have not yet become part of the applicable reporting framework and are being integrated for the deferred implementation.
  • Proportionality: SNCIs benefit from simplified requirements in several areas.
  • Leverage ratio refinements: Adjusted treatment for certain derivative and central clearing arrangements.

ESG Reporting Expansion

The EBA consulted in 2026 on proposed ESG supervisory-reporting templates, including transition-risk, physical-risk and broader environmental-risk information. As of September 2026, those proposals are not yet applicable supervisory-reporting requirements.

Supervisory Focus Areas

Topics receiving supervisory attention across EU banking jurisdictions include:

  • Interest rate risk: More detailed reporting of repricing gaps and duration mismatches.
  • Climate and nature risk: Concentration in carbon-intensive sectors, transition risk, and nature-related financial risk.
  • Credit quality deterioration: Given the macroeconomic environment, supervisors are paying close attention to asset quality trends.

Coming Soon: Template-by-Template Deep Dives

Detailed, template-level guides for each reporting framework covered on this site will address field-by-field walkthroughs, field mappings, and validation rule analysis for individual COREP modules.

Frequently Asked Questions

What is COREP reporting?

COREP (Common Reporting) is the standardized submission of prudential data, covering capital, risk, liquidity, and asset quality information, by EU credit institutions to their supervisory authorities. It enables regulators to monitor systemic risk and ensure institutions maintain adequate capital.

Who must file COREP reports?

Credit institutions and investment firms within the CRR reporting perimeter are subject to the applicable CRR supervisory-reporting requirements, with reporting level and modules determined by the CRR’s individual, consolidated and sub-consolidated application rules and relevant waivers or exemptions. Most MiFID investment firms are instead subject to the IFR/IFD framework. The CRR perimeter includes the relevant IFR tests and the CRD Article 8a credit-institution authorisation regime, including its competent-authority waiver. SNCIs may benefit from specified proportionality measures where the relevant conditions are met.

How often do institutions report?

Reporting frequency is requirement-specific. Requirements subject to quarterly reporting use reference dates of 31 March, 30 June, 30 September and 31 December; other requirements may be monthly, semi-annual or annual as specified in Implementing Regulation (EU) 2024/3117. SNCIs benefit from reduced frequency only where the applicable CRR and ITS conditions provide for it.

What is the reporting deadline?

The standard EBA remittance date is approximately 42 calendar days after quarter-end (12 May, 11 August, 11 November, 11 February). Your NCA may set specific portal deadlines. In Luxembourg, always confirm with the CSSF’s published reporting calendar.

What happens if my report fails validation?

The outcome of an NCA validation finding depends on the applicable validation rule and the NCA’s collection process. Where the submission is rejected or correction is required, the institution must address the relevant data or filing issue and resubmit in accordance with the NCA’s process.

What format are COREP reports submitted in?

From the March 2026 reference date, the EBA reporting framework uses xBRL-CSV; institutions must follow the first-level collection specification of their competent authority. In Luxembourg, the CSSF applies EBA framework version 4.2 in xBRL-CSV. Your reporting software should handle the format conversion, but test your submission pipeline before your first live filing in the new format.

What is the relationship between COREP and FINREP?

COREP focuses on prudential data (capital, risk, liquidity). FINREP focuses on financial reporting (balance sheet, income statement, asset quality). Both form part of EU supervisory reporting, but their applicable frequencies depend on the individual reporting requirement; neither framework should be described as exclusively quarterly. Some data elements appear in both but with different definitions or granularity.

  • CRR3 FRTB Market Risk Reporting: Explains the Fundamental Review of the Trading Book reporting requirements introduced under CRR3, including the new standardized and internal model approaches for market risk capital.
  • EBA Operational Risk Management RTS Under CRR3: Covers the EBA’s draft RTS on the operational risk management framework under Article 323 CRR, which are under consultation until 31 December 2026 and are not yet binding. COREP operational-risk reporting is governed separately by the supervisory-reporting ITS and is based on the CRR Business Indicator Component framework, subject to the applicable Article 314 transitional and reporting-scope rules.
  • IFRS 18 and FINREP Reporting: Interim Templates: Examines how the IFRS 18 standard affects FINREP reporting, the companion financial reporting framework that sits alongside COREP in the EU supervisory data architecture.
  • DORA ICT Incident Reporting: Sets out ICT-incident reporting obligations for financial entities within DORA’s scope. DORA and CRR/COREP scope must be assessed separately.

Key Takeaways

  • CRR supervisory reporting applies to institutions within the CRR reporting perimeter, subject to the rules on individual, consolidated and sub-consolidated application and the applicable waivers and exemptions. Non-compliance carries enforcement risk and supervisory scrutiny. Treat data quality as a strategic priority.
  • COREP involves multiple templates across capital, credit risk, liquidity, and operational data. You’re coordinating data from multiple systems, often on tight quarterly deadlines.
  • Deadlines are firm: approximately 42 calendar days from quarter-end to submission is standard for quarterly templates. Planning, data governance, and early validation are essential.
  • CRR3 introduces significant changes from 2025. The operational-risk framework, output floor and revised credit-risk rules already affect current calculations and reporting. The CRR3 FRTB own-funds requirements are deferred until 1 January 2027 and should not be presented as currently applicable. Ensure your systems reflect the current framework version (4.2).
  • The EBA reporting framework transitioned to xBRL-CSV from the March 2026 reference date. Institutions should test against the collection specification imposed by their competent authority; in Luxembourg, CSSF applies EBA framework version 4.2 in xBRL-CSV.
  • Data quality is critical. Errors in classification, calculation, or reconciliation may trigger validation findings. The outcome depends on the applicable validation-rule set and the competent authority’s collection process, so technical validation should not be treated as a substitute for data-quality controls. Invest in data governance, system integration, and quality assurance.
  • Scope matters. Understand whether you report at individual, consolidated, or both levels, and which templates are conditional for your institution.
  • Supervisory engagement helps. Most NCAs offer guidance or published testing facilities. A call to the CSSF (or your NCA) to clarify a template interpretation can save weeks of rework.
  • Keep documentation and audit trails. You need to be able to explain every number, its source, and any adjustments.

Sources and References

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts