Search for Q&As

Enquirers can use various factors to search for a Q&A:

  • These include searching by the Q&A ID; legal reference, date submitted, technical standard / guideline, or by keyword if known.
  • Searches can be extended to more than one legal act, topic, technical standard or guidelines by making multiple selections (i.e. pressing 'Ctrl' on your keyboard, and selecting the relevant ones from the drop-down lists by left mouse-click).


Q&As refer to the provisions in force on the day of their publication. The EBA does not systematically review published Q&As following the amendment of legislative acts. Users of the Q&A tool should therefore check the date of publication of the Q&A and whether the provisions referred to in the answer remain the same.

Please note that the Q&As related to the supervisory benchmarking exercises have been moved to the dedicated handbook page. You can submit Q&As on this topic here.

List of Q&A's

The implementation of commercial agent exclusion for e-commerce platforms

Should the settlement of the debt by an e-commerce platform be considered a sufficient reason to exclude the e-commerce platform from the scope of PSD2 or an indispensable requirement for a commercial agent mandate?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

On the requirements for 'inherence' in strong customer authentication (SCA)

Do the elements required for ‘inherence’ in strong customer authentication (SCA) provide the complete authentication or can they form a part of an authentication decision with some non-biometric elements and still satisfy the inherence condition, for example, as one element of a user profile of several elements. For example, if the biometric, say keystroke dynamics, provides 50% of the decision and other characteristics (e.g. device data, location data) provide the other 50%, does this satisfy the requirement for inherence assuming the condition for 'very low probability of unauthorised access' is also satisfied and that another SCA condition, 'knowledge' or 'possession' is also satisfied? if so, is there a threshold, say 50%, below which it ceases to qualify as 'inherence'?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication

Customer data transfer to Member States for the purpose of supervision

Does the phrase “data related to their customers” under Article 6 of the Delegated Regulation refer to personal customer data (as defined by EU Regulation 2016/679) or general data for management purposes (e.g. descriptive statistics on the number of customers, customer risk distribution, etc.)?

  • Legal act: Directive (EU) 2015/849 (AMLD)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2019/758 – RTS on implementation of group wide AML/CFT policies in third countries

Disclosure of information within the group related to suspicious activity reports (SARs) to the competent authorities

Does the requirment under Article 5 of the Delegated Regulation refer to the sharing of information on the underlying data of the Suspicious Activity report (SAR) (e.g. transactions, customer data) without disclosing whether the SAR was filed and sent to the local authorities of the third country?

  • Legal act: Directive (EU) 2015/849 (AMLD)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2019/758 – RTS on implementation of group wide AML/CFT policies in third countries

Retroactivity concerning customer consent for data sharing and processing

Is there the expectation that such consent clauses, under Article 4 of the Delegated Regulation, be incorporated into contracts on a go-forward basis from the date the Regulation entered into force (i.e. with new customers and existing customer contract renewals) or is there the expectation that all existing customer contracts will be remediated to meet this requirement? What approach should be used with former customers?

  • Legal act: Directive (EU) 2015/849 (AMLD)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2019/758 – RTS on implementation of group wide AML/CFT policies in third countries

Prudential filter on unrealised gains and losses on governmental exposures and interaction with the IFRS 9 transitional arrangements

What amount of unrealised gains/losses under the “a” of Article 468 needs to be considered to be filtered by factor f for a sovereign exposure measured at FVOCI?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

"Unexpected outflow" in the context of applying large exposure exemptions granted in Article 390(6)(c) CRR

Are the exposures created between service providers, which are caused by clients signing up to new products outside of business hours, an “unexpected outflow” in the context of applying the exemptions granted in Article 390(6)(c) of the Regulation (EU) No 575/2013 as amended by Regulation (EU) 2019/876 (CRR2)?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Interpreting the definitions of "client activity" and "unexpected" in modern financial services market in the context of CRR

Are “top ups” a “client activity” as defined in Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (herein ‘CRR')? How “unexpected” should they be interpreted in the modern payments environment?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Validation Rule on C 09.02 Template - V4787

Is validation rule v4787 correct?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) No 680/2014 - ITS on supervisory reporting of institutions (repealed)

PD-/PD+ for RWA-/RWA+

Are PD-/PD+ calculated separately for each of the (sub)portfolios listed in Annex 4, or are the PD-/PD+ values obtained for a client/exposure to be used consistently and unchanged for all (sub)portfolios?

  • Legal act: Directive 2013/36/EU (CRD)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2016/2070 - ITS on Supervisory Reporting (for benchmarking the internal approaches) (as amended)

Applicability of the Guidelines of the Committee of European Banking Supervisors on Article 106(2)(c) and (d) of Directive 2006/48/EC (CRD)

Are the implementation guidelines on Article 106(2)(c) and (d) of Directive 2006/48/EC (CRD) of the Committee of European Banking Supervisors applicable for interpreting Regulation (EU) No 575/2013 as amended by Regulation (EU) 2019/876?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

SME supporting factor for exposures collateralised by residential property

How should the SME supporting factor be calculated for exposures to SME where the total amount owed to the institution is collateralised by residential property?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

How to use bank guarantees instead of PII

Is it acceptable to use third party (other than credit institutions) commitments that are covered by a guarantee from a credit institution as a comparable guarantee instead of professional indemnity insurance (PII)?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: EBA/GL/2017/08 - Guidelines on the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance

RWA formula for defaulted exposures where institutions use own estimates of LGDs

At which level should the flooring in the RWA formula for defaulted exposures (Articles 153(1)(ii) and 154(1)(i) of CRR2) be applied?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Alternative strong customer authentication for citizens without mobile

Why does the PSD2 allow banks to deny the access to the electronic financial services to customers without a mobile but with a PC?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication

Other retail deposits subject to higher outflow rates: treatment of joint accounts

According to Article 25(2) (a) of Delegated Act 2015/61 “Retail deposits with total deposits balance, including all the client’s deposit accounts at that credit institution or group, exceeding € 500.000” are subject to higher outflows. How should this threshold be tested in case of joint accounts?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Delegated Regulation (EU) 2015/61 - DR with regard to liquidity coverage requirement

Risk weight for new asset class of non-preferred senior debt

What risk weight should be applied to non-preferred senior (NPS) debt, under the standardised approach for credit risk?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Definition of a financial institution as regards the application of the Delegated Regulation

Is an institution, that is a subsidiary of a holding company which, in turn, owns several financial subsidiaries, not considered as a group for the purposes of the Delegated Regulation, since their parent company does not fall within the definition of a financial entity set out in Article 3 of Directive (EU) 2015/849 (AMLD)?

  • Legal act: Directive (EU) 2015/849 (AMLD)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2019/758 – RTS on implementation of group wide AML/CFT policies in third countries

Reporting of International Organizations not treated as sovereign in template C43

Should exposures to International Organizations not treated as sovereign be included in Row 160 of template C43?

  • Legal act: Regulation (EU) No 575/2013 (CRR)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) No 680/2014 - ITS on supervisory reporting of institutions (repealed)