Documentation · Prudential

Pillar 2 — ICARA.

Assessing the harms your firm can cause, and the capital and liquidity you hold against them.

Manual Prudential Reporting Engine → Pillar 2 · Version 2.0 · 7 screenshots
NoteThis guide assumes you know how to sign in, navigate the Solutions menu, complete Settings and work with sessions. Those are covered in the Getting Started guide and are not repeated here.

What this module does

Pillar 1 answers a standardised question: what does the regulation say this firm must hold? Pillar 2 answers a harder one: what could actually go wrong here, and is the firm holding enough against it?

The ICARA — Internal Capital and Risk Assessment — is the firm's own view. REGREP models four risk categories against your own parameters, compares the result with the Pillar 1 requirement, and shows where the internal assessment exceeds the standardised one. That difference is the additional capital for harms the K-Factors do not capture.

RiskWhat the module models
Market riskValue at Risk across the banking book and trading book, at a confidence level you set.
Counterparty riskExpected loss and Credit VaR by currency and counterparty, using your own correlation and loss-given-default assumptions.
Operational riskScenario-based Operational VaR built from a risk register — likelihood, typical impact and extreme but plausible impact.
LiquidityAn internal assessment of the liquidity requirement, compared with the Pillar 1 basic requirement.

Before you start

ImportantCreate the Pillar 1 session for the same reporting date first. Pillar 2 can run standalone, but linking a Pillar 1 session carries the own funds, K-Factor and exposure data across automatically — without it you are entering everything by hand and the Pillar 1 comparison is unavailable.

Solutions → Regulatory Reporting → Prudential Reporting Engine → Pillar 2 — ICARA.

The Pillar 2 session list
Figure 1 — The Pillar 2 session list.
  1. 1Create a session with the + button. Pillar 2 has no Archived Sessions tab — a deleted session is gone.

Creating a session

The Add Session dialog
Figure 2 — The Add Session dialog.
  1. 1Session Selection — choose the Pillar 1 session that supplies the baseline data. This is the field that matters most.
FieldWhat to enter
Session NameA descriptive title, for example "Q1 2026 ICARA — Solo".
Reporting DateThe effective date of the assessment. Match it to the Pillar 1 session.
Session SelectionThe Pillar 1 session to draw baseline figures from. Leave blank only for a standalone assessment.
Audited SessionWhether the underlying financial figures are audited.
Reporting ScopeSolo or Consolidated.
NoteA standalone session — one created without a linked Pillar 1 session — requires you to upload counterparty and market risk exposure data manually on the Data page, and the Pillar 1 versus Pillar 2 comparisons on Session Home and K-Factors will have nothing to compare against. Use it only when there is a reason not to link.

The session workspace

Session Home for a session linked to a Pillar 1 session
Figure 3 — Session Home for a session linked to a Pillar 1 session.
  1. 1Session parameters and the navigation to each risk module.
  2. 2Own funds available, against the threshold requirement before and after Individual Capital Guidance.
  3. 3The K-Factor comparison matrix — Pillar 2 requirement, Pillar 1 requirement, and the additional capital for harms not captured.

The bar chart at the top left compares the three Pillar 1 requirements. The pie chart below shows which risk category drives the Pillar 2 requirement — in a typical investment firm, market risk and operational risk dominate.

NoteThe bar chart labels permanent minimum capital as PMR, while Pillar 1 and Settings call the same figure PMC. They are the same number.

EXPORT SESSION RESULTS in the top-right downloads a complete summary of the assessment.

The pages in a session

PagePurpose
Session HomeThe overall position and the Pillar 1 comparison.
Session SettingsThe statistical parameters every calculation on this session uses.
DataCounterparty risk and market risk exposures, inherited or uploaded.
VolatilityCustom historical volatility data, or the defaults from Session Settings.
C'party RiskExposure distributions, expected loss and Credit VaR.
Operational RiskThe scenario register and Operational VaR.
Market RiskBanking book and trading book Value at Risk.
Internal Liquidity AssessmentThe internal liquidity requirement against available liquidity.
K-FactorsThe consolidated matrix mapping every assessment back to a K-Factor.

Session Settings

ImportantSet these before running any calculation. Every figure the module produces depends on them, and changing a parameter later means re-running every risk calculation in the session.
Session Settings
Figure 4 — Session Settings.
  1. 1SAVE applies the parameters to the session. Nothing recalculates until you re-run each risk module.
SettingWhat it controls
Individual Capital GuidanceA supervisory overlay added to the threshold requirement. Enter the amount your competent authority has set; leave at zero if none applies.
Default volatility (SMA / EWMA)The baseline volatility used when no custom volatility file has been uploaded.
Volatility ApproachWhich method drives the market risk calculation — simple moving average, or exponentially weighted.
Market Risk — TenorThe holding period in days for the VaR calculation.
Market Risk — Confidence LevelThe statistical confidence level, typically 99.5%.
Counterparty Risk — CorrelationThe assumed correlation between counterparty defaults.
Counterparty Risk — Loss Given DefaultThe proportion of an exposure assumed lost on default.
Operational Risk — CorrelationThe assumed correlation between operational loss scenarios. A lower value produces a smaller correlated sum.
Liquidity Risk — Confidence LevelThe confidence level for the internal liquidity model.
NoteThese are your firm's assumptions and you must be able to justify them to a supervisor. Record the rationale for each in your ICARA document — the platform stores the values, not the reasoning behind them.

Data and volatility

The Data page holds the exposures the risk models work from, split between Counterparty Risk (CPR) and Market Risk (MR) tabs.

  • Where a Pillar 1 session is linked, both are populated automatically from it. This is the normal case and nothing needs uploading.

  • Where it is not, use the Upload CPR and Upload MR fields and select IMPORT.

  • The CPR Data tab shows top exposures for the trial balance, on and off balance sheet, and trading counterparties. The MR Data tab shows banking and trading book exposures with their calculated SMA and EWMA volatility.

ImportantAfter reviewing or uploading data on either tab, select CALCULATE OWN FUNDS REQUIREMENT in the top-right. Until you do, the risk pages show the previous run — or nothing at all.

The Volatility page lets you upload your own historical price or asset volatility data, which then replaces the defaults for the asset classes it covers. Where no file is uploaded, the defaults from Session Settings apply throughout.

Operational risk

Operational risk is the part of the ICARA that is genuinely yours. The platform supplies a starting register; the judgement about what could go wrong in your firm, how likely it is and how bad it could be, is not something software can supply.

Operational Risk → Input
Figure 5 — Operational Risk → Input.
  1. 1The action menu — add a custom risk, import the default risk bank, calculate, or export to Excel.
  2. 2Input and Output tabs. Output holds the charts and the OpVaR summary.
  3. 3K-Factor mapping — assigns each scenario to the K-Factor whose harm it represents, or to K-Other.

Building the register

  1. Open the action menu (…) and select DEFAULT RISK BANK to import the standard scenario templates.

  2. Add anything specific to your firm with ADD CUSTOM RISK+ ADD NEW. Each scenario needs a name, a likelihood, a typical impact and an extreme but plausible impact.

  3. Review every imported scenario. A default scenario with default numbers is not an assessment.

  4. Map each scenario to a K-Factor, or to K-Other where no K-Factor captures the harm.

  5. Select CALCULATE OPERATIONAL RISK.

ColumnWhat it means
LikelihoodThe probability of the scenario occurring within the assessment period, as a percentage.
Typical ImpactThe loss in a normal occurrence of this scenario.
Extreme but plausible ImpactThe loss in a severe but credible occurrence. This drives the tail of the distribution and therefore OpVaR.
Expected LossCalculated — likelihood applied to impact.
OpVaRCalculated — the Operational Value at Risk contribution of this scenario.
K-FactorsThe K-Factor this harm maps to. Scenarios mapped to K-Other produce capital additional to the whole K-Factor framework.
NoteThe Output tab shows the number of scenarios assessed, impact against likelihood, the simple versus correlated sum of operational risks, and the OpVaR summary. The gap between the simple and correlated sums is driven by the operational risk correlation in Session Settings — worth understanding before you defend the number.

Market and counterparty risk

Market Risk → Input
Figure 6 — Market Risk → Input.
  1. 1CALCULATE MARKET RISK runs or refreshes the model; EXPORT EXCEL downloads inputs and outputs.
  2. 2Input shows exposures and the VaR at your chosen confidence level; Output holds the analytics.

The Input tab summarises exposure size and VaR for the banking book and the trading book, then breaks the exposures down by currency, asset type and foreign exchange position. The Output tab visualises the same data: VaR by asset class, by currency, by commodity, and a heat map of the twenty largest VaR exposures.

Counterparty risk

The C'party Risk page works the same way. The Input tab groups exposures by currency, showing counterparty counts, converted exposure, expected loss and Credit VaR; the eye icon on any row drills into the individual counterparties behind it. The Output tab summarises average probability of default, expected loss and CVaR, with bar charts by currency.

Select CALCULATE COUNTERPARTY RISK to run the model. Results export to Excel or PDF.

Internal liquidity adequacy

The Internal Liquidity Adequacy Assessment page
Figure 7 — The Internal Liquidity Adequacy Assessment page.
  1. 1HISTORICAL LIQUIDITY opens the log of liquidity positions by date; CALCULATE AVAILABLE LIQUIDITY recalculates eligible liquid assets.
  2. 2The Pillar 1 basic requirement against the Pillar 2 internal assessment.

The Pillar 1 basic liquidity requirement is one third of the Fixed Overhead Requirement. The Pillar 2 figure is your own assessment, and will normally be higher — it is meant to reflect what the firm would actually need in stress, not a formula.

Use HISTORICAL LIQUIDITY → + ADD NEW to record liquidity positions by date and amount, building the history a supervisor will expect to see.

K-Factors summary

The K-Factors page is where the assessment resolves. It maps every operational risk scenario, market risk input and counterparty exposure onto the individual K-Factor categories, and sets the Pillar 2 own funds requirement beside the Pillar 1 KFR.

The bottom row — the additional capital requirement for harms not captured by the K-Factors — is the output of the whole exercise, and the number your ICARA document has to justify.

A complete ICARA cycle

  1. Complete the Pillar 1 session for the same reporting date.

  2. Create the Pillar 2 session and link that Pillar 1 session.

  3. Set every parameter on Session Settings and save.

  4. Review the Data page, then select CALCULATE OWN FUNDS REQUIREMENT.

  5. Upload custom volatility data if you use it.

  6. Build the operational risk register: import the default bank, add your own scenarios, review every number, map to K-Factors, calculate.

  7. Calculate market risk and counterparty risk.

  8. Record liquidity positions and calculate available liquidity.

  9. Review the K-Factors summary and the additional capital requirement.

  10. Export the session results and file them with your ICARA document.

Troubleshooting

SymptomLikely cause and fix
Session Home shows no Pillar 1 comparisonNo Pillar 1 session was linked at creation. The link cannot be added afterwards — create a new session.
A risk page shows no resultsThe calculation has not been run. Use the CALCULATE button on that page.
Results do not reflect a parameter you changedSession Settings changes do not recalculate automatically. Save, then re-run each risk module.
Operational VaR looks implausibly largeCheck the extreme but plausible impacts — a misplaced digit here moves OpVaR more than anything else. Then check the operational risk correlation.
Market risk VaR is zeroNo exposures were inherited or uploaded. Check the Data page and that the linked Pillar 1 session has an imported trading book.
The threshold requirement is unchanged after entering ICGSave Session Settings, then reopen Session Home. Pre-ICG and post-ICG figures are equal when ICG is zero.

Document control

VersionDateChange
2.0January 2026Rewritten to start at the module. Navigation and Settings move to the Getting Started guide. Documents the consequences of a standalone session, the calculate-then-review dependency on each risk page, the K-Other mapping, and the derivation of the Pillar 1 basic liquidity requirement. Notes that the Session Home chart labels permanent minimum capital as PMR where the rest of the platform uses PMC. Adds a full ICARA cycle and troubleshooting. Screenshots refreshed using fictional firm data.
1.0Original Pillar 2 manual.

REGREP is an independent software provider. This manual describes how to operate the platform and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Other guides

The rest of the documentation set.

All documentation
Manual

DAC2

Preparing, validating and submitting financial account information under the EU automatic exchange framework.

Read the guide