Pillar 2 capital requirements are set by supervisors on a bank-by-bank basis, on top of the minimum capital floors established under Pillar 1. Regulators assess each institution’s individual risk profile through a structured review process, then assign additional capital add-ons to cover risks that Pillar 1 either does not fully capture or does not capture at all. The exact amount varies by institution, jurisdiction, and the quality of the bank’s own internal risk assessment. Below, we unpack the most common questions about how Pillar 2 works in practice.
How do regulators actually calculate Pillar 2 capital requirements?
Regulators do not use a single fixed formula to calculate Pillar 2 capital requirements. Instead, supervisors conduct a structured review of each bank’s risk profile and assign a Pillar 2 add-on based on their judgment of where Pillar 1 capital falls short. This review is known as the Supervisory Review and Evaluation Process, or SREP, in the EU and UK context.
During a SREP, supervisors assess several dimensions of the bank’s position. They look at the adequacy of internal capital models, the quality of risk management processes, and the results of the bank’s own internal capital assessment. They also factor in the bank’s business model, profitability outlook, and sensitivity to macroeconomic stress. The outcome is a Pillar 2 Requirement that is specific to that institution and reviewed at least annually.
In practical terms, supervisors often benchmark their assessments against peer institutions and use quantitative models to estimate capital shortfalls in specific risk categories. But the final number is a supervisory decision, not a mechanical output. This is precisely why the quality of a bank’s internal risk data and stress testing framework has a direct influence on the Pillar 2 outcome it receives.
What risks does Pillar 2 cover that Pillar 1 does not?
Pillar 2 covers risks that fall outside the scope of Pillar 1’s standardized capital calculations, or where Pillar 1 underestimates the actual exposure for a specific institution. The most important categories include Interest Rate Risk in the Banking Book (IRRBB), concentration risk, liquidity risk beyond LCR and NSFR floors, pension obligation risk, and strategic or reputational risks.
Pillar 1 sets capital requirements for credit risk, operational risk, and certain market risk positions using standardized or internal model approaches. These are designed as industry-wide floors. But every bank has a unique balance sheet, and risks that are immaterial at the sector level can be highly material for a specific institution.
IRRBB is a particularly relevant example. Under the Basel framework and its regional implementations, including the IRRBB framework embedded in Basel.NXT and APS 117 in Australia, supervisors expect banks to hold capital against the sensitivity of their banking book to interest rate movements. This is assessed under Pillar 2 because Pillar 1 does not prescribe a standardized capital charge for it. The same logic applies to concentration risk, where a bank heavily exposed to a single sector or counterparty faces risks that the standardized credit risk approach does not fully reflect.
What’s the difference between Pillar 2 Requirement and Pillar 2 Guidance?
The Pillar 2 Requirement (P2R) is a binding, legally enforceable capital add-on set by the supervisor. The Pillar 2 Guidance (P2G) is a non-binding supervisory expectation about the additional capital buffer a bank should hold above P2R to absorb stress. Breaching P2R triggers automatic supervisory restrictions; breaching P2G does not, but it prompts supervisory dialogue.
This distinction matters in practice. P2R is included in the calculation of the Maximum Distributable Amount (MDA), which determines whether a bank can pay dividends, bonuses, or coupon payments on Additional Tier 1 instruments. P2G sits above this threshold and acts more like a forward-looking cushion, particularly relevant under stressed economic conditions.
The EU and UK both use this two-tier structure, though with some differences in how P2G is communicated and applied. In the UK, the Prudential Regulation Authority has been explicit about the distinction since its post-Brexit framework diverged from the European Banking Authority’s approach. In both jurisdictions, P2G is informed heavily by stress test results, which is one reason that the quality and credibility of a bank’s stress testing directly affects its capital planning flexibility.
How does the ICAAP feed into Pillar 2 decisions?
The Internal Capital Adequacy Assessment Process (ICAAP) is the primary input a bank provides to its supervisor for Pillar 2 decisions. Through the ICAAP, a bank documents its own view of all material risks, quantifies the capital it believes it needs to cover those risks, and demonstrates that its governance and risk management processes are adequate. Supervisors use this document as a starting point for their own SREP assessment.
A well-constructed ICAAP does more than satisfy a compliance checkbox. It gives supervisors confidence that management understands the bank’s risk profile and has a credible plan to maintain capital adequacy under stress. Where the ICAAP is thin, poorly evidenced, or relies on outdated models, supervisors will apply more conservative assumptions in their own assessment, which typically results in a higher Pillar 2 add-on.
Basel
Pre-configured Basel models, out-of-the-box regulatory scenarios, and liquidity metrics.
Ready in weeks, not months.
The ICAAP also covers forward-looking capital planning under multiple macroeconomic scenarios. This includes dynamic balance sheet modeling, stress test frameworks, and interdependency analysis across risk types. Banks that can demonstrate robust scenario modeling, including the impact of rate shocks on banking book earnings and credit losses under adverse conditions, tend to have more productive conversations with their supervisors about Pillar 2 outcomes.
The ILAAP, the liquidity equivalent of the ICAAP, feeds into Pillar 2 liquidity expectations in the same way. Together, the ICAAP and ILAAP form the core of the supervisory dialogue under Pillar 2.
Do Pillar 2 requirements differ between the EU, UK, and US?
Yes, Pillar 2 requirements differ meaningfully between the EU, UK, and US, both in structure and in how supervisors apply them. All three jurisdictions implement the Basel framework, but each has adapted Pillar 2 to fit its own regulatory architecture and supervisory culture.
EU and UK
In the EU, the European Central Bank and national competent authorities conduct SREP assessments under the Capital Requirements Directive and Regulation framework. P2R and P2G are both used, and the EBA publishes guidelines that create a degree of consistency across member states. The EU’s Basel.NXT implementation, including IRRBB compliance requirements, has been phased in through the CRR3 package.
The UK, following its departure from the EU, has developed its own implementation through PRA rules and the near-final Basel 3.1 standards. The PRA has retained the P2R and P2G structure but has introduced some divergence in how specific risk categories, including IRRBB, are treated and communicated to banks.
United States
The US does not use the same SREP terminology. Instead, the Federal Reserve, OCC, and FDIC apply supervisory capital expectations through stress testing frameworks such as DFAST and CCAR for larger institutions, alongside internal capital planning requirements. The US has been slower to implement the full Basel.NXT package, and its Pillar 2 equivalent is more embedded in the supervisory examination process than in a formal annual SREP cycle.
Can Pillar 2 requirements change after they are set?
Yes, Pillar 2 requirements can and do change. Supervisors review Pillar 2 add-ons at least annually as part of the SREP cycle, and they can revise requirements up or down based on changes in a bank’s risk profile, the quality of its risk management, macroeconomic conditions, or updated supervisory methodology. A bank that improves its internal models, stress testing capabilities, or capital planning processes can see its Pillar 2 add-on reduced over time.
Conversely, deterioration in asset quality, increased concentration exposures, or weaknesses identified in an ICAAP submission can prompt supervisors to increase the requirement between scheduled reviews. In periods of systemic stress, regulators have also used Pillar 2 tools to temporarily adjust requirements across the sector, as seen during the early stages of the COVID-19 pandemic when some authorities reduced P2G to give banks more operational flexibility.
For banks operating across multiple jurisdictions, managing Pillar 2 variability across different regulatory regimes adds another layer of complexity. Keeping your risk calculations current, your stress testing credible, and your ICAAP documentation aligned with the latest supervisory expectations is the most reliable way to maintain predictability in your Pillar 2 outcome.
At ElysianNxt, our Basel.NXT solution covers the full ICAAP and ILAAP framework, including dynamic balance sheet modeling, macroeconomic scenario selection, and stress testing across all risk types, all within a single real-time platform. If you want to see how that works in practice, explore our ICAAP and ILAAP solution.
Related Articles
- What is APS 210 and how should ADIs approach liquidity compliance?
- What is a regulatory reporting connector and how does it work?
- How to reduce regulatory reporting costs?
- How do climate risks factor into credit stress testing?
- What is economic capital and how is it calculated?
This content was generated with the help of AI and it may contain mistakes