Managing Climate Risks
with Existing Tools
In practice, proportionality is often confused with relief: less data, less analysis, less modelling. That misses the point. For climate risks in particular, proportionality does not begin with reduction — it begins with the question of which risk factors are genuinely decision-relevant for the institution. Smaller banks do not need less rigour; they need a different level of granularity. Technically, this means less unnecessary detail, greater traceability and a stronger link to management steering. The skill lies in selection — are the material exposures identified? Are the transmission chains plausible? Are uncertainties disclosed? Are the guardrails actionable? Proportionality is not the reduction of ambition — it is the reduction of unnecessary complexity.
"Simple" is often mistaken for "weak" in practice — but the real question is whether a model is transparent enough to actually trigger decisions. A good what-if analysis doesn't ask whether one specific scenario will occur, but what an institution would feel first if it did — for example if the CO₂ price spikes, a regional flood occurs, or both happen at once. What matters is not the scenario itself, but the transmission chain: borrower → collateral → capital → liquidity → management steering. A scenario that can be explained in one sentence can be discussed at board level — a model that almost no one in the house can explain stays stuck in the specialist department. A clear stress picture is worth more than precise pseudo-accuracy: this is exactly the logic the Executive Summary distills: Working Paper at tmaul.de/publications
In many projects the model question comes too early: teams first ask how precisely something can be quantified — when a different question should come first. What decision is the model meant to prepare? Capital buffers, liquidity reserves, concentration limits, lending conditions? Decision-makers do not need a model that explains everything — they need a robust answer to three questions: What happens? Where does it happen? When must action be taken? Climate risks are a particularly revealing test case here — not because they are especially ESG-specific, but because they affect capital, liquidity and concentrations simultaneously. Good risk models do not sell certainty. They create decision-making capability.
Climate risks have arrived in risk management — but they have often yet to reach actual management steering. The real challenge does not start with ESG reporting, data availability or sustainability metrics. The decisive question is: what happens to capital, liquidity and concentrations under climate stress? Climate risks do not materialise as an isolated ESG risk — they transmit through credit risk, collateral valuation, liquidity and ICAAP/RTF. The critical point is often not the individual loan default, but the combined stress on capital and liquidity simultaneously. The challenge is no longer one of awareness — it is one of robust management logic. Full analysis: Working Paper on tmaul.de/publications
ZAG-MaRisk &
Limit Management
The ZAG-MaRisk demands more than documentation and policies. Many payment service providers underestimate the supervisory expectation at its core: who decides on risk — and is that responsibility unambiguously defined? Limit management is a management process, not a reporting exercise. Effective governance requires clear roles across all three lines, a defined escalation path and supervisory-ready documentation without unnecessary bureaucracy. The principle of "no business without a limit" is not a formality — it makes risks visible before they become problems.
Governance in
Credit Decisions
CCD2 fundamentally shifts the regulatory lens: no longer just the credit contract, but the entire decision-making process is in scope — from data use and scoring logic to customer dialogue. This affects not only banks, but everyone who has integrated credit functions into their business model: BNPL providers, merchants, platforms, payment service providers. CCD2 does not turn non-banks into banks — but it requires proportionate governance. The defining question is organisational, not technical: who is accountable for the credit decision?
Part 2 clarifies who CCD2 actually affects and what a functioning control model requires. What matters is the role in the process, not the industry. The regulatory target state calls for clear ownership, versioned scoring logic, documented change processes and defined monitoring — no banking framework, but structure. Credit decisions become a board-level responsibility: requirements apply at every touchpoint, from advertising through pre-contractual disclosures to checkout and ongoing customer communication.
While much of the CCD2 debate focuses on governance, regulation first makes itself felt operationally: in the credit process itself. The checkout becomes a regulatory core process — with mandatory creditworthiness assessment even for small amounts, pre-contractual information obligations, withdrawal rights and transparent cost disclosure. Most significantly: algorithmic decisions must be explainable. Customers have the right to a traceable justification — the black box is no longer regulatorily viable.
ESG Risk Management
for SNCIs
BRUBEG embeds ESG risks in the KWG through new sections 26c and 26d — not as standalone risk categories, but as cross-cutting risk drivers affecting credit, market, liquidity and operational risks. For management boards, this means ESG risks are an integral part of business and risk strategy, not an isolated side topic. Inaction is not an option: supervisors will systematically assess ESG risks within SREP, and BaFin can mandate corrective measures where risk management is found inadequate.
With the legal framework in place, the question becomes practical: how to implement? Part 2 provides a phase-based roadmap for SNCIs: Phase 0 establishes clarity on responsibilities and ambition level, Phase 1 meets minimum requirements and produces the first ESG risk plan, Phase 2 deepens integration into ICAAP/ILAAP and steering processes, Phase 3 prepares for the end of the transitional arrangement in 2030. The key is not complexity but embeddedness: the ESG risk plan must be anchored in regular management and steering processes.
Proportionality is not a regulatory discount — it is an obligation to justify. The choice of simplified approaches must be deliberate, risk-oriented and owned by management: not automatic, not delegated. What supervisors actually assess is not model complexity but consistency and accountability — was the ambition level consciously set, is the materiality analysis documented, does the methodology feed into real management decisions? The difference between weak and strong argumentation lies not in the outcome, but in the reasoning.
The ESG risk plan is not a compliance checkbox — it reveals whether governance is more than a concept. Building it with form-filling logic produces compliance without management effect. Building it with steering logic embeds it in board decisions, ICAAP and strategy — and creates the foundation for genuine management effectiveness. The defining question is not whether the plan is formally complete, but whether it actually informs capital planning, limit-setting and portfolio decisions.