What are the five stages of CySEC's SREP, and what happens at each?
The five stages of the SREP in order, what CySEC does at each, how the stages connect, and how today's EBA and ESMA framework and the measures in Law 165(I)/2021 compare.
By the ExamPass CY editorial teamLast reviewed 6 min read
Short answer
The exam material, following CySEC's 2012 guidelines, divides the SREP into five stages: planning, when CySEC plans its review and asks the CIF for its ICAAP report; review and assessment of the ICAAP, usually desk-based, possibly with an on-site check; review of additional information, such as recent inspections and visits; supervisory measures for risk mitigation, when CySEC sets the Pillar 2 capital requirement; and SREP validation, CySEC's internal check of its results. Dialogue with the firm runs through all five. Today's EBA and ESMA guidelines organise the SREP into ten components instead.
The five SREP stages at a glance
| Stage | What happens |
|---|---|
| 1. Planning | CySEC plans its review of each CIF internally and asks the firm for its ICAAP report |
| 2. Review and assessment of the ICAAP | Usually a desk-based review of the report, the process behind it and supporting documents, sometimes with an on-site check of how the ICAAP works in practice |
| 3. Review of additional information | Results of ongoing supervision and of recent inspections or visits relevant to the ICAAP; controls, governance and wider compliance |
| 4. Supervisory measures for risk mitigation | Pillar 2 capital requirement set; other measures to mitigate risk imposed |
| 5. SREP validation | CySEC's internal, independent check of the SREP's results and method |
| Throughout | CySEC and the firm stay in dialogue at every stage; it is not a stage of its own |
| Today's framework | Joint EBA and ESMA guidelines, applicable from 19 June 2023: ten components from categorisation to supervisory measures |
| Measures in law today | Early action where a breach is likely within 12 months; a plan to restore compliance, presented within one year, with a deadline set by CySEC; additional own funds, capital guidance and specific liquidity requirements; limits on variable pay and distributions |
Source: CySEC Circular C027 (2012); Joint EBA and ESMA Guidelines EBA/GL/2022/09, Title 2; Law 165(I)/2021, sections 31–35.
In the exam
The exam is written from the exam material, which predates the changes below. Expect its answer. If that answer is not among the options and the current rule is, choose the current rule.
Five stages or ten components
Exam material: CySEC's SREP runs in five stages: planning, review and assessment of the ICAAP submission, review of additional information, supervisory measures for risk mitigation, and SREP validation.
Current law (since 19 June 2023 (EBA/GL/2022/09)): The joint EBA and ESMA guidelines organise the review of Class 2 and Class 3 CIFs into ten components, from categorisation and key-indicator monitoring to supervisory measures, with review cycles set by the firm's category.
The components are not stages, so a question on the stages or their order follows the five-stage model.
What happens at each of the five stages?
The exam material describes the five-stage SREP from CySEC's 2012 guidelines, Circular C027. The first stage is planning: CySEC's internal planning of the review for each CIF, which includes asking the firm to submit its ICAAP report. The second is review and assessment of the ICAAP submission. CySEC typically reviews the report at its desk, together with the process the firm followed to prepare it and any supporting documents, and it may add an on-site assessment of how the ICAAP is applied in practice.
The third stage is the review of additional information. CySEC brings in the outcome of its ongoing supervision and of recent inspections or visits relevant to the ICAAP, and it may review the firm's controls and governance, the results of any SREP on-site review and its general compliance with the rules. The fourth stage is supervisory measures for risk mitigation: CySEC sets the Pillar 2 capital requirement and imposes any other measures needed to reduce risk. The fifth is SREP validation, CySEC's internal and independent check that its SREP work, method and results are sound and consistent. Dialogue between the firm and CySEC runs through every stage rather than forming a stage of its own.
Terms used in this note
- ICAAP report
- The document in which a CIF sets out its internal capital adequacy assessment, submitted to CySEC when requested.
- Desk-based review
- A review carried out at CySEC's offices from documents, as opposed to an on-site visit.
- Pillar 2 capital requirement
- Capital CySEC requires above the minimum to cover risks the minimum does not capture.
- SREP validation
- CySEC's internal quality check of its own SREP results before they are final.
How do the stages connect?
Read the stages as a chain in which each one uses the output of the one before. Planning produces the request, so the ICAAP report exists before any review starts. The ICAAP review produces CySEC's first view of the firm's own assessment. Additional information then tests that view against what supervision and inspections have shown. Only with the combined evidence does CySEC decide on capital and other measures, and validation checks that decision before it is final. To place any event, ask what must already have happened for it to take place, and what it produces for the next step. The principles that guide the SREP, such as a risk-based approach and the identification of risks and deficiencies, apply across the stages rather than forming stages themselves; see What is the SREP, how intense is it, and what does it decide?.
How does today's SREP framework differ?
CySEC still publishes Circular C027, but since 19 June 2023 joint EBA and ESMA guidelines, which CySEC lists on its website, have set common procedures for reviewing Class 2 firms under the IFD, and Class 3 firms where CySEC decides a review is needed. Instead of five stages, the guidelines describe ten components: categorisation of the firm; monitoring of key indicators; business model analysis; internal governance and firm-wide controls; risks to capital; risks to liquidity; adequacy of own funds; adequacy of liquidity resources; an overall SREP assessment and score; and supervisory measures, including early intervention where needed. The firm's category drives how often each element is reassessed. For the few CIFs still under the CRR (Class 1-minus), the review follows section 55 of Law 97(I)/2021 and the EBA's SREP guidelines for institutions (EBA/GL/2022/03), which apply from 1 January 2023. Revised EBA guidelines (EBA/GL/2026/06), published on 26 June 2026, will replace them from 1 January 2027.
Since 5 November 2021, Law 165(I)/2021 has set out the measures. CySEC may act early where a firm is likely to breach its requirements within the next 12 months. It may require the firm to present, within one year, a plan to restore compliance, and set a deadline for carrying it out. It may also require additional own funds and specific liquidity requirements, and it may give capital guidance. Its other powers include limiting variable pay as a share of net revenues and restricting distributions. The five-stage model remains the exam's framework, so learn it as the order in which CySEC's 2012 process runs.
How to think about it
Remember the order as plan, read, verify, decide, check. CySEC plans and asks for the report, reads the ICAAP, verifies it against other evidence, decides on capital and measures, and checks its own work. Talking to the firm is not a separate step: it happens all the way through. If a question describes an event, work out which of these five verbs it belongs to.
Common mistakes
Confusing the firm's tasks with CySEC's stages. The stages describe CySEC's work; the firm's part is to supply the ICAAP report and engage in the dialogue.
Reading desk-based as no visits. The ICAAP review is usually desk-based but may include an on-site assessment, and later stages draw on inspections.
Treating validation as the firm's sign-off. Validation is CySEC's internal quality check of its own SREP results.
Learning the five stages as current law. They come from CySEC's 2012 guidelines; the current framework uses the EBA and ESMA components and the measures in Law 165(I)/2021.
Legal references
- CySEC Circular C027: Guidelines GD-IF-03 for the Supervisory Review and Evaluation Process (issued 12 July 2012) (opens in a new tab)
Structure of the SREP (five stages) · frequency and intensity
- Joint EBA and ESMA Guidelines on the SREP under Directive (EU) 2019/2034 (EBA/GL/2022/09), as published by CySEC (opens in a new tab)
Title 2 (overview of the common SREP framework, categorisation and minimum engagement) · paragraph 12 (application from 19 June 2023)
- The Prudential Supervision of Investment Firms Law of 2021 (Law 165(I)/2021), Greek text on CyLaw (opens in a new tab)
Section 31 (supervisory measures) · Section 32 (supervisory powers) · Section 33 (additional own funds) · Section 34 (guidance) · Section 35 (specific liquidity requirements)
- Directive (EU) 2019/2034 on the prudential supervision of investment firms (IFD), consolidated version of 24 December 2024 (opens in a new tab)
Articles 36–42 (supervisory review and evaluation, measures and powers)
Practise this topic
Test what you just read
The Chapter 9 pack has 198 exam-style questions, 15 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 48 free Chapter 9 flashcards →