Tallinn, Estonia  ·  Libreville, Gabon contact@carmagnole.eu  ·  +372 5355 0223
Supervision

The file is ready, the control is not: what supervisors test in the second line

Published 4 June 2026  ·  9 minute read

Internal governance produced 17% of the qualitative measures issued in the ECB's 2025 SREP, and not one significant institution scored better than 2- on that element. The reason is not missing policies; it is that institutions assemble a presentable file where supervisors test an operating control.

An inspection of the second line is almost always prepared as a documentation exercise. Policies are refreshed, committee packs are indexed, the risk appetite statement is reprinted with the current year on the cover. All of that answers a question supervisors stopped asking a long time ago. The question actually put is narrower and considerably harder: does the control operate, across the whole population it claims to cover, leaving a trace that someone outside the institution can follow without having to accept anyone's word for it. The distance between the file and the control is where findings come from, and inspection teams have become efficient at locating it.

The aggregate numbers make the point. In the ECB's 2025 SREP cycle, covering 105 significant institutions, internal governance accounted for 17% of the qualitative measures issued, second only to credit risk at 40%. The average internal governance score improved to 2.77 from 2.83, which reads as progress until you notice that 36% of banks still sat at a flat 3 and that not one institution scored 2+ or better on this element. Governance is where scores move least, year after year. Policies are not the constraint.

The 2020 revision took the organisation chart away as a defence

When the Institute of Internal Auditors reissued its model in July 2020, it dropped "of defence" from the name and, more consequentially, stopped describing lines as places. The revised Three Lines Model describes roles: oversight by the governing body, first and second line roles that both sit under management, and independent assurance from internal audit. An institution can therefore no longer answer a supervisory challenge by pointing at a box on an organigram. Where a control is designed, calibrated and monitored by the same people who execute the underlying activity, the second line role is not being performed, whatever the reporting line asserts.

European rules had already moved in that direction. EBA/GL/2021/05 of 2 July 2021 sets out four cumulative conditions at paragraph 175 for an internal control function to be regarded as independent: its staff perform no operational tasks within the scope they monitor; it is organisationally separate from what it controls; its head is not subordinate to a person responsible for managing the monitored activities; and its remuneration is not linked to the performance of those activities. The last of these fails quietly and often. A compliance officer whose variable pay tracks the commercial results of the division under review has an independence problem that no charter repairs.

Reporting lines are tested for the same reason. Paragraph 172 requires the heads of risk management, compliance and internal audit to report and be directly accountable to the management body, with their performance reviewed there. Paragraph 174, echoing Article 76(5) of Directive 2013/36/EU, is blunter still: the head of the risk management function must not be removed without the prior approval of the management body in its supervisory function. For AML and CFT, EBA/GL/2022/05, applicable since 1 December 2022, requires one named member of the management body to carry ultimate responsibility for AML/CFT obligations and places the compliance officer in the second line with direct access to the board. Inspectors treat these as verifiable facts rather than intentions. Who signed the compliance officer's last appraisal, and did the supervisory function see it before it was signed?

Design and operation are two tests, and sampling decides the second

A designed control lives in a procedure: an owner, a stated frequency, a described check. An operating control leaves a record on each occurrence, carrying at minimum a date, a scope, a person, a result, and where the result was adverse, the decision taken and what followed from it. Supervisors test these separately. The second test is the one institutions lose.

Consider the periodic review of high risk relationships. Design is rarely the difficulty. Operation is settled by two questions. The first concerns population completeness: how many relationships fell within scope during the period, extracted from which system, reconciled against what. Where the count in the risk report diverges from the count in the operational system, the discussion has already ceased to be about financial crime and become one about data governance, and it has done so before a single file was opened. The second concerns sample results. An inspector will pull perhaps twenty five files, weighted deliberately toward the awkward ones, and read what was written where the ownership chain was opaque or the customer uncooperative. Clean files establish very little. The difficult file shows how the control behaves under pressure rather than in laboratory conditions.

Completeness is the underrated half of that pair. The ECB has said plainly that progress on risk data aggregation and risk reporting remains slow and insufficient, citing an absence of board level prioritisation, inadequate data architecture and IT infrastructure, and deficiencies in data quality controls, adding that remediation programmes often lack the necessary ambition. RDARR accounted for 20% of internal governance qualitative measures in 2025, level with the risk management framework and just behind the management body at 23%. Under the supervisory priorities for 2026 to 2028, the ECB has announced targeted on-site inspections of RDARR frameworks and of previously identified severe findings. An institution that cannot reconcile its own populations should expect its second line testing to be discounted wholesale.

Limits that bind nobody, and information that changes nothing

The risk appetite framework is where the second line most frequently becomes decorative. A statement is approved by the board, expressed in aggregate ratios, and then never cascaded into anything a business head can feel in a Tuesday morning decision. Supervisors have tested this head on. Between the fourth quarter of 2024 and the second quarter of 2025 the ECB benchmarked risk appetite frameworks across 28 banks, extending the exercise to roughly twenty further significant institutions from the third quarter of 2025. Most frameworks were assessed as mature. The gaps identified were precise: the governance process surrounding the framework, effective coverage of certain non-financial risks, alignment between risk identification and appetite, the granularity of metrics and limits, and the connection between the remuneration framework and the appetite. Granularity is the technical term for whether a limit reaches the person capable of breaching it.

A related failure is the indicator that is produced and then absorbed. A threshold is crossed, the breach appears in the pack, the minute records that the committee noted it, and nothing subsequently moves. That is worse than not measuring at all, because the institution has documented across consecutive months that it observed a deteriorating position and elected no response. Experienced inspectors read indicator series backwards for precisely this reason: identify the month the number turned, then look for what changed afterwards. If the only answer is a footnote, the second line has built a reporting activity and mistaken it for a control.

Escalation is tested through seniority and dates. Who was informed, at what level, how many working days after detection, and what authority did that person hold. An escalation path terminating in a committee with no power to halt the activity is not one.

Findings, deficiencies, and the plan that quietly slipped

Institutions habitually blur the difference between a finding and a deficiency; supervisors never do. A finding is an observation with evidence attached to it. A deficiency is a conclusion that a control fails to achieve its objective, and it carries a severity rating, a named owner and a deadline. Downgrading deficiencies into findings by softening the language is a familiar move with a familiar cost: when the same issue resurfaces in the following cycle, the earlier softening becomes evidence about the institution's governance rather than about the underlying subject.

Remediation tracking is where that cost compounds. A plan bearing a target quarter and a department name will slip. A plan naming an individual, with interim milestones, defined evidence of closure and validation by a function other than the one that performed the remediation, will usually hold. The ECB has moved to a defined remediation and escalation process precisely in order to monitor progress over time, and open items carried from prior cycles are read as a statement about management capability rather than about the topic they concern.

Two decades of Basel guidance point the same way. The 2005 paper on the compliance function insisted that each bank be prepared to demonstrate that its chosen approach is effective, and the 2015 corporate governance principles restated that expectation for the risk function. Both are demands for evidence rather than for architecture. Institutions read them as descriptions of structure; supervisors read them as descriptions of proof.

The eight weeks before an inspection, spent properly

Stop refreshing policies. Identify the six controls that carry the greatest weight in what the second line tells the board, and for each produce a single page setting out the population and how it was derived, the reconciliation to source systems, the sample tested and its results, the exceptions found, the escalations with names and dates, and the current remediation status with an owner. Do this before the inspection team arrives, and treat any control for which that page cannot be assembled within five working days as a deficiency you have just identified yourself. Then say so in the opening meeting, with dates against each item. An institution that hands over its own list of weak controls changes the character of the inspection: the team's work becomes verification rather than discovery, sampling narrows, and conclusions arrive faster. The institutions that emerge well from inspections are, with remarkable consistency, the ones that found the problem first.

Sources

European Central Bank, Aggregated results of the 2025 SREP, November 2025. European Central Bank, Supervisory priorities 2026-28, November 2025. European Central Bank, Annual Report on supervisory activities 2024, March 2025. European Banking Authority, Guidelines on internal governance under Directive 2013/36/EU (EBA/GL/2021/05), 2 July 2021. European Banking Authority, Guidelines on policies and procedures in relation to compliance management and the role and responsibilities of the AML/CFT Compliance Officer (EBA/GL/2022/05), 14 June 2022. Institute of Internal Auditors, The IIA's Three Lines Model: An Update of the Three Lines of Defense, July 2020. Basel Committee on Banking Supervision, Compliance and the compliance function in banks, April 2005. Basel Committee on Banking Supervision, Corporate governance principles for banks, July 2015.

Carmagnole OÜ  ·  4 June 2026
All publications