|
Particularly as regards:
If IT strategies relating to data and system architecture are comprehensive and sufficiently embedded in strategic decision-making processes, this will support the enhancement of such governance arrangements.
Integrated operational processes for risk, adequate reporting, and the mitigation of risks stemming from pervasive manual processes (which in many cases are neither traced nor independently reviewed and approved) also represent good practices in this regard.
The general conclusions set out in this report are, of course, without prejudice to the ECB’s assessment of the risk governance of individual credit institutions, which is conducted in the context of its ongoing supervisory work and takes account of the specificities of each entity in terms of the application of the relevant legal framework.