CySEC Advanced · Chapter 9 · Topic 5 of 13

What processes must a CIF have for credit, market, liquidity, operational and leverage risk?

The baseline duty for IFR firms, then the CRD rules the exam tests for credit and counterparty, residual, concentration, securitisation, market, interest rate, operational, liquidity and leverage risk.

By the ExamPass CY editorial teamLast reviewed 8 min read

Short answer

The exam material sets out the CRD rules for each risk: credit granted on sound criteria without sole or mechanical reliance on external ratings; written policies for residual and concentration risk; action against a liquidity shortage when short positions fall due before long ones; internal capital for basis risk; systems for interest rate risk outside the trading book; business continuity plans; funding assumptions reviewed and liquidity recovery plans tested at least annually; and the leverage ratio as a warning sign. Since 5 November 2021 Class 2 CIFs have followed a shorter list in Law 165(I)/2021.

Risk processes at a glance

Class 2 baselineStrategies, policies, processes and systems for material risks to clients, to the market and to the firm, and for liquidity risk over suitable periods including intraday
Credit and counterparty riskSound, well-defined granting criteria; internal methods not relying solely or mechanically on external ratings; other relevant information weighed even where requirements rest on a rating
Credit monitoringOngoing, including problem credits, value adjustments and provisions; adequately diversified portfolios
Residual riskCredit risk mitigation proving less effective than expected; covered in written policies and procedures
Concentration riskCounterparties, connected groups, sectors, regions, activities, commodities and large indirect exposures such as one collateral issuer; covered in written policies
Market riskShorts due before longs: act against a liquidity shortage; index shares netted against futures, or opposite futures that differ: internal capital for basis risk; reduced underwriting positions: capital to the next working day
Operational riskPolicies covering model risk and rare, severe events; contingency and business continuity plans
Liquidity (CRD firms)Pledged and unencumbered assets kept apart; scenarios and funding assumptions reviewed at least annually; liquidity recovery plans tested at least annually and approved by senior management
Excessive leverageIndicators: the leverage ratio (Tier 1 over the total exposure measure, as a percentage; minimum 3% for CRR firms) and mismatches between assets and liabilities

Source: Law 165(I)/2021, section 23; Law 97(I)/2021, sections 40–48; Directive 2013/36/EU, Articles 79–87; Regulation (EU) 2019/2033, Article 43; Regulation (EU) No 575/2013, Articles 92(1)(d) and 429.

In the exam

The exam is written from the exam material, which predates the changes below. Expect its answer. If that answer is not among the options and the current rule is, choose the current rule.

  • Detailed rules per risk type

    Exam material: Every CIF follows detailed process rules for credit, residual, concentration, securitisation, market, interest rate, operational, liquidity and leverage risk, such as testing liquidity recovery plans at least annually.

    Current law (since 26 June 2021 (Regulation (EU) 2019/2033, Article 43); 5 November 2021 (Law 165(I)/2021, section 23)): These CRD rules bind only banks and Class 1-minus CIFs (Law 97(I)/2021 sections 40 to 48). Class 2 CIFs follow the shorter duty in Law 165(I)/2021 section 23, and IFR firms hold liquid assets of at least one third of their fixed overheads requirement.

Which rules apply to a CIF's risk processes today?

The exam material lists detailed rules for each type of risk, taken from the CRD through CySEC Directive DI144-2014-14. For Class 1-minus CIFs they now sit in Law 97(I)/2021 (sections 40 to 48), and for banks in the banking law. Since 5 November 2021 Class 2 CIFs have followed a shorter duty in Law 165(I)/2021 section 23: robust strategies, policies, processes and systems to identify, measure, manage and monitor material risks to clients, to the market and to the firm itself, including risks that could deplete own funds, and liquidity risk over suitable periods, including intraday. Class 3 CIFs cover the client, firm and liquidity limbs. General rules on risk management for all CIFs sit in the MiFID II framework; see What organisation, risk management and internal audit must an investment firm have?.

Terms used in this note

Residual risk
The credit risk left when collateral, guarantees or other mitigation work less well than expected.
Basis risk
The risk that two positions meant to offset each other, such as index futures and the index shares, do not move together.
Unencumbered asset
An asset not pledged or otherwise tied up, so it can be sold or used as collateral when needed.
Leverage ratio
Tier 1 capital divided by total exposures without risk weighting, as a percentage.

What does the exam material require for credit, concentration and market risk?

Credit must be granted on sound, well-defined criteria, with a clear process for approving credit and for changing, renewing or refinancing it. Internal methods must assess credit risk for single obligors, securities and securitisation positions and for the portfolio as a whole, and must not rely solely or mechanically on external ratings. Where an own funds requirement rests on a rating, or on an exposure being unrated, the firm still weighs other relevant information when it allocates internal capital. Portfolios are monitored continuously, which means identifying and handling problem credits and setting aside enough value adjustments and provisions, and they are diversified in line with the firm's target market.

Residual risk, the risk that credit risk mitigation works less well than expected, and concentration risk must both be addressed in written policies and procedures. Concentrations can arise from counterparties, including central counterparties, from connected groups, and from exposures in one sector, region, activity or commodity, as well as from large indirect exposures, for example where much of the collateral comes from one issuer. Securitisation risk, for a firm acting as investor, originator or sponsor, must be assessed so that the economic substance of each deal is reflected.

For market risk, the firm needs policies for all material sources and effects. Where short positions fall due before long ones, it must guard against a liquidity shortage. A firm that nets index shares against index futures must hold internal capital for basis risk, the risk that the future and the shares do not move together. The same applies to opposite positions in index futures that differ in maturity or composition. A firm that reduces its underwriting position must hold capital for the risk between the initial commitment and the next working day. Separately, systems must identify, evaluate and manage interest rate risk from non-trading activities.

What does it require for operational, liquidity and leverage risk?

Operational risk policies must cover model risk and rare but severe events, and must say what counts as operational risk. They include contingency and business continuity plans, which keep the firm running and limit its losses in a severe disruption. Since 21 February 2025, Law 97(I)/2021 has required those plans to include ICT continuity, response and recovery plans, in line with the EU's Digital Operational Resilience Act.

Liquidity risk needs robust strategies and systems over suitable periods, including intraday, with liquidity buffers and limits tailored to business lines, currencies and entities. The firm separates pledged assets from unencumbered assets available at all times, especially in an emergency, and considers where assets are held and any limits on moving them. It runs alternative scenarios and reviews its funding assumptions at least annually. Its liquidity recovery plans are tested at least annually, and the results go to senior management, who must approve them. These are CRD rules; IFR firms must hold liquid assets of at least one third of their fixed overheads requirement.

For excessive leverage, the firm needs policies to identify, manage and monitor it, allowing for falls in own funds from expected or realised losses. Indicators include the leverage ratio and any mismatch between assets and liabilities. The leverage ratio is Tier 1 capital divided by the total exposure measure, as a percentage; since 28 June 2021 the CRR has set a 3% minimum. It does not apply to IFR firms.

How to think about it

Match each risk to its tell-tale trigger. Credit risk calls for judgement beyond ratings. Residual risk is protection that underperforms, and concentration is too much in one name, sector, place or collateral issuer. Shorts due before longs point to liquidity, and mismatched hedges to basis risk. Rare, severe events belong to operational risk, and asset–liability mismatches to leverage. The annual rhythm applies to liquidity: funding assumptions reviewed and recovery plans tested at least once a year.

Common mistakes

  1. Confusing residual risk with concentration risk. Residual risk is mitigation that underperforms; concentration risk is too much exposure in one name, sector, region or collateral issuer.

  2. Treating a business continuity plan as an IT back-up. It must keep the whole firm operating and limit losses in severe disruption.

  3. Expecting risk weights in the leverage ratio. It deliberately ignores risk weights: Tier 1 capital over the total exposure measure.

  4. Applying CRD liquidity and leverage rules to every CIF. IFR firms hold liquid assets of at least one third of their fixed overheads requirement and have no leverage ratio.

Practise this topic

Test what you just read

The Chapter 9 pack has 198 exam-style questions, 14 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 48 free Chapter 9 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error