Business
Alisa Pankki Oyj : Capital and Risk Management 2025
Alisa Pankki Oyj : Capital and Risk Management

About this update from Alisa Pankki Oyj
Alisa Bank Plc Pillar III - Capital and risk management report 2025 Sisällysluettelo INTRODUCTION 4 Disclosure of Pillar III information 4 Risk appetite 4 Risk management in Alisa Bank 5 Risk position / Key ratios and figures 6 Credit risk 6 Own funds and Capital adequacy 6 Liquidity risk 8 Market and interest rate risk 9 Interest rate risk 9 Compliance and operational risk 9 Risk statement approved by the Board of Directors 10 RISK MANAGEMENT IN ALISA BANK 11 Objective of risk management 11 Three lines of defense 11 Organization and principles of risk management 12 Credit and Risk Management Committee 12 CEO 12 Compliance 13 Internal Audit 13 Business and support units 14 Own funds 15 Leverage ratio 15 Capital adequacy 16 Definition 19 Credit risk profile 19 Non-performing loans 19 Credit risk management principles 20 Credit risk management organization 20 Credit quality assessment and credit risk mitigation 21 Definition of default and accounting principles 21 Credit risk adjustments 22 LIQUIDITY RISK 23 Definition 23 Liquidity risk profile 23 Liquidity risk management 24 Liquidity risk monitoring and reporting 25 Stress testing 25 Market risk 26 Interest rate risk 26 Managing interest rate risk 27 OPERATIONAL RISK 28 Definition 28 Appendix: Summary Table of Pillar III requirements 29 INTRODUCTION Alisa Bank ("the bank") focuses on financing small and medium-sized enterprises and serving retail savings customers by offering selected banking and financial services through its own balance sheet Customer acquisition is based on both Alisa Bank's own and its partners digital channels During the financial year, the bank made a strategic decision to exit retail lending as part of focusing on its business and improving profitability. In connection with this decision, the bank sold a significant portion of the retail loan portfolio in December 2025. With respect to the remaining retail loan portfolio, the bank expects the sale to be completed during 2026 Risk management plays a key role in the Bank's operations, supporting business management and the management of risks arising from changes in the operating environment. The Bank's main risk categories are credit risk, operational and compliance risk, as well as market risk and liquidity risk. The bank maintains a comprehensive risk management framework that is aligned with its business strategy and risk appetite and approved by the Board of Directors. The framework ensures systematic identification, assessment, monitoring and control of all material risks through clearly defined governance structures, policies, limits and reporting processes. Risks are identified using both bottom-up and top-down approaches and are monitored against quantitative and qualitative risk appetite metrics. Independent control functions provide oversight and assurance on the effectiveness of risk management and internal controls. The framework covers all material risk types and supports transparent Pillar III disclosures in accordance with applicable regulatory requirements. Disclosure of Pillar III information This report presents information on the Bank's risks, risk management and capital adequacy in accordance with applicable regulatory requirements, including Part Eight of the EU Capital Requirements Regulation (CRR 575/2013) and related EBA guidance. The Bank fulfils its disclosure obligations by publishing Pillar III information alongside its annual report. As a small and non-complex institution, the Bank provides the qualitative and quantitative disclosures required for this category. Pillar III information is unaudited and is complemented by risk-related disclosures in the Board of Directors' report, the financial statements, and other documents, such as the Corporate Governance Statement and the Remuneration Report, available on the Alisa Bank's website. Risk appetite Alisa Bank defines its risk appetite through a set of qualitative and quantitative risk appetite statements that provide clear guidance on the level of risk the Bank is willing to accept when executing its strategic objectives. Risk appetite statements also involve the definition of risk capacity limits. It defines the maximum amount of risk that the Bank can undertake given its current capacity without breaching requirements set by regulators and supervisors. Risk appetite limits are set for all material risk types. Risk appetite limits are translated into each business-level targets and limits and furthermore into all product categories. Ongoing monitoring and reporting of risk exposures against the risk limits are carried out by the business units and the Risk Control Unit to ensure that risk-taking activities remain within the risk appetite. Risk management in Alisa Bank Alisa Bank's ("the Company") Board of Directors has the primary responsibility for risk management. The Board of Directors confirms the risk strategy, Risk Management Policy, risk limits and other guidelines according to which risk management and internal control are organized. Alisa Bank's risk management strategy is based on the Company's approved strategy and goals. Alisa Bank focuses on retail banking and offers selected banking services mainly to business customers. The Company does not have either excessive customer risk or concentration risk. The Company's Board of Directors sets the level of risk appetite by approving risk area-specific risk strategies and the necessary risk limits and monitoring limits. The implementation of the risk strategy is monitored regularly through the risk reports, produced independently from business operations. The Company keeps its capital adequacy at a safe level. The Company's capital adequacy and risk-bearing capacity will be strengthened through profitable business operations and, in addition, debt and equity instruments that increase own funds. The Board of Directors gets regularly information on the Company's various risks and their levels. The Board of Directors also approves the authority and framework for risk-taking by defining risk limits for credit and market risks. The day-to-day risk monitoring and control lies with the Heads of business units. CET1 ratio 31,1% Total capital ratio 34,6% Leverage ratio 6,7% Risk position / Key ratios and figures Credit risk Credit risk is the Company's primary risk. It is managed in accordance with the Credit Risk Policy approved by the Board of Directors by setting targets and risk limits for the loan portfolio's quality and concentrations. These limits are followed by the business units and the risk control team. During the financial year, the loan portfolio decreased compared to the previous year. Despite the reduction in the total loan volume, the Bank's relative credit risk position deteriorated due to an increase in the ratio of non-performing loans. However, the absolute amount of non-performing loans declined compared to the prior year. The loan portfolio decreased during the financial year compared to the previous year and amounted to EUR 58.9 million (EUR 149.5 million) before loan loss provisions at the end of the financial year. The reduction in the loan portfolio was mainly due to the sale of the personal customer's loan portfolio. The Company had one customer group exposure exceeding 10 per cent of own funds, as calculated in accordance with capital adequacy regulations. The exposure is largely mitigated by an eligible guarantee from an export credit agency. The ten largest customer group exposures accounted for 21.0 per cent of the total loan portfolio. Business lending was primarily concentrated in manufacturing, wholesale and retail trade, and real estate activities. Concentration risk is monitored at the level of customer groups and industry sectors. The amount of non-performing exposures decreased year-on-year to EUR 5.6 million (EUR 7.1 million). The NPL ratio was at 9.5 per cent (4.8 per cent) at the end of the reporting period. The increase in the ratio was mainly due to the contraction of the loan portfolio. The NPL ratio of the business loan portfolio was 7.1 per cent. Non-performing exposures consisted mainly of business lending, and their level was affected by an increase in SME-companies' bankruptcies. The development of non-performing business loans was influenced by a single significant customer exposure. The exposure is largely mitigated by an eligible guarantee from an export credit agency, and the unguaranteed portion has been fully recognised. In the NPLs calculation the customer exposure is recognized to full value without the guarantee. Own funds and Capital adequacy The objective of the Bank's capital adequacy management is to ensure a sufficient level of capital in relation to risks of its business and changes in the operating environment. Capital adequacy is assessed considering both regulatory capital requirements and the key business and balance sheet-related risks. The Board of Directors is responsible for the overall management of capital adequacy and determines the risk strategy and capital targets to ensure the Bank's risk-bearing capacity and continuity of operations. The total capital requirement for banks consists of a minimum capital requirement of 8.0 % in accordance with Pillar I and an additional fixed capital requirement of 2.5 % in accordance with Act on the Credit Institutions. The Finnish Financial Supervisory Authority (FIN-FSA) imposed a P2G guidance for Alisa Bank as of 1%. P2G means Pillar 2 guidance, and it must be covered by Common Equity Tier 1 capital. To strengthen the risk-bearing capacity of the banking sector, FIN-FSA imposed a systemic risk buffer requirement. The decision came into effect for all Finnish banks on 1.4.2024 and it shall be covered by the Consolidated Common Equity. FIN-FSA imposed a discretionary additional capital requirement (pillar 2) P2R, for Alisa Bank based on the supervisor's assessment (SREP) in April 2024. The additional capital requirement is 2.25% and it comes in such a way that at least three quarters of the additional capital requirement must be primary capital, of which at least three quarters must be core capital (CET1) in accordance with the EU capital adequacy regulation. The discretionary additional capital requirement is valid from December 31, 2024, onwards, until December 31, 2027. In the capital adequacy calculation Alisa Bank uses the Standardised Approach for the credit risk calculation and the basic indicator approach for operational risks. At the end of the financial year, the Group's capital adequacy exceeded clearly regulatory requirements. The total capital ratio was 34.6 per cent and the Common Equity Tier 1 (CET1) ratio was 31.1 per cent, providing the Bank with a substantial buffer against business risks and changes in the operating environment. The Group's capital structure consists of core capital and supplementary capital, and the level of own funds supports the Bank's strategic objectives and risk-bearing capacity. 34 671 -15 132 19 539 0 0 0 19 539 6 100 -3 914 2 186 CAPITAL AND RISK POSITION, EUR 1,000 31.12.2025 Common Tier Capital before adjustments Adjustments to Common Tier 1 Capital Common Tier 1 Capital in total (CET1) Additional Tier 1 Capital before adjustments Adjustments to Tier 1 Capital Additional Tier 1 Capital in total (AT1) Total Tier 1 capital (T1 = CET1 + AT1) Tier 2 Capital before adjustments Adjustments to Tier 2 Capital Tier 2 Capital in total (T2) Total Capital (T1 + T2) 21 725 45 892 758 16 087 62 738 31,1 31,1 34,6 Total risk weighted exposure amounts Credit and Counterparty risk Market risk Operational risk Risk weighted exposure in total Common Equity Tier 1 ratio (CET 1), % Tier 1 ratio (T1), % Total Capital Ratio (TC), % LEVERAGE RATIO, EUR 1,000 31.12.2025 Total Equity, Tier 1 capital 19 539 Total Exposure Amount 292 327 Leverage ratio (LR), % 6,7 LCR 1210 % NSFR 441 % Liquidity risk Liquidity risk can be defined as a mismatch between funding sources and the use of funds. The risk may materialise if the Company is unable to meet its payment obligations as they fall due. The Company's main liquidity risks arise from maturity mismatches between funding and lending. Liquidity adequacy is ensured by setting a cash reserve limit defined by the Company's Board of Directors. The Company prepares for the repayment of future liabilities by restricting lending, if necessary, in the coming years, thereby safeguarding its liquidity position. The Company's liquidity remained stable and at a good level throughout 2025. At the end of the financial year, the Company's Liquidity Coverage Ratio (LCR) was 1,210 per cent (minimum requirement 100 per cent). The liquidity buffer consisted entirely of high-quality liquid assets (Level 1 assets), namely deposits held with the Bank of Finland. The Net Stable Funding Ratio (NSFR), which measures the adequacy of stable funding, stood at 441 per cent at the end of the reporting period (minimum requirement 100 per cent). The Company has no outstanding bond issuances. The majority of its funding consists of retail deposits, i.e. deposits from private individuals and SMEs. Market and interest rate risk Market risk consists of interest rate risk in the banking book and foreign exchange risk. The banking book comprises on- and off-balance sheet items related to lending and funding, as well as the liquidity reserve. Foreign exchange risks are kept at a moderate level in order to avoid material financial losses or risk concentrations arising from exchange rate movements. As at 31 December 2025, the largest foreign currency positions were loan receivables of DKK 0.4 million and SEK 0.3 million. A 10 per cent depreciation of these currencies would result in an estimated financial loss of EUR 0.08 million. The correlation of these currencies with the euro is relatively high, which mitigates the risk. Of the net loan portfolio, 99 per cent was denominated in euros, and no material foreign exchange risks arise from other balance sheet items. Interest rate risk Interest rate risk arises from differences in the interest rate repricing and maturities of assets and liabilities in the Bank's banking book as market interest rates change. Changes in market interest rates affect both the fair value of on- and off-balance sheet items (net present value risk) and net interest income (earnings risk). At the end of the financial year, the Company's investment portfolio included debt securities amounting to EUR 14.9 million, the valuation of which is affected by changes in market interest rates. The debt securities are low risk in nature and have short maturities of up to 12 months. Compliance and operational risk Compliance Risk is defined in Alisa Bank as the risk of legal or regulatory sanctions, material financial loss, fines or loss to reputation Alisa Bank may suffer because of its failure to comply with laws, regulations, rules, agreements, related self-regulatory organization standards, and codes of conduct applicable to its licensed operations. The Board of Directors holds the ultimate responsibility for the management of compliance risk in the Alisa Bank. The Management at all levels of the Company is responsible for effective management of Compliance Risk in Alisa Bank. Operational risk refers to direct or indirect financial loss resulting from inadequate or failed internal processes, people, and systems, or external events. Operational risks also contain legal, compliance, and information security risks. Operational risks are thus related to management systems, operational processes, people, and various external factors or threats. Operational risks are managed by the business line. The most significant source of operational risks are the development of new products and services, risks related to IT security, fraud risk and compliance risk. The Company's board confirms the principles of operational risk management every year. In operational risk management, the Company's main goal is to manage reputational risk and ensure business continuity and regulatory compliance in the short and long term. Risk statement approved by the Board of Directors The Board of Directors of Alisa Bank approves the Risk Management Policy including the principles concerning risk management and risk monitoring. The Board sets the risk appetite. The Board gets regular reports on various risks risk limit overdrafts and their development. With this announcement, the Board of Directors confirms that the risk management arrangement and systems at Alisa Bank are adequate in relation to the Company's risk profile and strategy. RISK MANAGEMENT IN ALISA BANK Objective of risk management The Board of Directors of Alisa Bank have primary responsibility for the Company's risk management. The Company's Board of Directors has primary responsibility for the Group's risk management. The Company's Board of Directors has determined the level of risk that the Company is willing to take in order to achieve its strategic goals. The accepted level of risk is based on a risk appetite framework, on which the key principles and rules guiding risk-taking are also based. The objective is to ensure the adequacy of risk-bearing capacity in relation to all material risks. The Board of Directors confirms the risk management principles and responsibilities according to which risk management and internal control are organised. The Board confirms the principles and responsibilities of risk management, the Company's risk limits and other general instructions according to which risk management and internal controls are organized. The objectives of the risk management framework in Alisa Bank are: Making the management aware of the risks of having financial significance in the short or long term. Ensuring rationality of business and risk management processes; creating a decision-making basis, proportional to Company's risk-taking ability, for risk-taking and risk mitigation. Ensuring full commitment of the employees to continuous risk management work. Making risk management a part of normal daily management. Three lines of defense The strategies and processes to manage risk and to organize internal control in Alisa Bank are applied according to the three lines of defense. There are independent functions established in the Company to ensure the implementation of effective and comprehensive internal controls. Defense lines are: Business and support functions (first line of defense) Risk control function (second line of defense) Compliance function (second line of defense) Internal audit function (third line of defense) Organization and principles of risk management Board of Directors The Board approves the risk appetite framework that forms the basis for the principles concerning risk management and risk monitoring. The Board sets the risk appetite and the top-level limits. Within these limits the Credit and Risk Management Committee and/or the Heads of the Business Units give restrictive guidelines. The Board also approves internal capital and liquidity adequacy assessments and regularly assesses the stress testing framework and results. The results of the stress tests are taken into consideration when defining or reviewing the risk strategies and risk limits. Credit and Risk Management Committee The Credit and Risk Management Committee is a supervisory and consultative body working under the mandate of the Board. Credit and Risk Management Committee members are appointed by the Board. The committee's mandates and responsibilities are described in the working principles of the committee and include the following: Controlling the bank's credit, market, and liquidity risks. Controlling the banks' balance sheet usage and structure Preparation of decisions on risks and risk management to the Board (including risk limits) Expressing opinions on issues with significant impact on Company's risk profile Deciding on matters where the Board has delegated decision making authority to Credit and Risk Management Committee. Reporting to the CEO and the Board on the overall risk profile of the Company Reporting and presenting an overview of its activities to the Board including reporting to the Board on decisions made under the authority delegated by the Board. Control the adequacy of operational risk management. CEO The CEO is responsible for organising the Bank's risk management framework and ensuring that risk management and control arrangements are aligned with the Bank's risk appetite. Together with senior management and the Credit and Risk Management Committee, the CEO regularly assesses identified risks, maintains the risk limit framework and defines clear mandates for risk-taking. Stress testing is conducted on a regular basis and forms an integral part of the risk identification and assessment process, particularly for financial risks. The CEO is also responsible for implementing effective internal control and monitoring systems and for ensuring that risk management principles are understood and applied throughout the organisation. Heads of business units are accountable for managing risks arising from their respective operations. Group Risk Control Group Risk Control (GRC) is an independent control function responsible for monitoring and overseeing the Bank's risk-taking activities and the implementation of the Risk Management Framework. GRC supports business units in developing their risk management practices and provides both unit-level and aggregate risk reporting to senior management, the Credit and Risk Management Committee and the Board of Directors. GRC is responsible for identifying, assessing, monitoring and reporting all material financial and non-financial risks to which the Bank is, or may become, exposed, and for maintaining a holistic view of the Bank's risk profile. The function monitors risk positions against approved limits, escalates limit breaches, reports risk inconsistent with the risk appetite and acts as an early warning function. GRC also facilitates risk identification and materiality assessments, supports risk appetite and limit setting, proposes enhancements to the risk management framework and ensures compliance with applicable regulatory requirements. Compliance Compliance risk is defined as the risk of legal or regulatory sanctions, financial loss, fines or reputational damage arising from the Bank's failure to comply with applicable laws, regulations, rules, agreements and standards. The Board of Directors has ultimate responsibility for compliance risk management, while management at all levels is responsible for its effective implementation. The Compliance function supports the Board, executive management and business units by promoting adherence to regulatory requirements, internal policies and ethical standards, and by identifying, monitoring and reporting compliance risks. Compliance risk is managed in line with the Bank's risk appetite, and the Bank expects strict observance of both the letter and spirit of applicable laws and regulations across all operations and jurisdictions. Compliance function operates independently from business activities while maintaining a cooperative working relationship with management and business units to enable early identification and mitigation of compliance risks. Its responsibilities include assessing compliance risks related to existing and new products, services, business practices, customer relationships and distribution channels, as well as monitoring regulatory changes. Compliance reports directly to the Board of Directors and the Audit Committee in accordance with the Compliance Policy, providing regular and ad hoc reporting on identified risks, the effectiveness of controls, complaint handling and remedial actions. In cases of significant noncompliance risk, Compliance may escalate matters directly to senior management, the Board or the Audit Committee. The Compliance function works closely with other control functions and is subject to periodic review by Internal Audit. Internal Audit Independent Internal Audit is responsible for reviewing the application and effectiveness of risk management procedures and risk assessment methodologies. Internal audit conducts risk- based and general audits and reviews that the Internal governance arrangements, processes, and mechanisms are sound and effective, implemented and consistently applied. Internal audit is also in charge of the independent review of the first two lines of defense including ensuring that the segregation of duties is defined and established between risk management (first line) and risk control (second line). Business and support units Business and support units constitute the first line of defense and have primary responsibility for risk-taking within the Bank. The heads of business units and the Head of Loan Origination and Monitoring are responsible for identifying, managing and controlling risks within their respective areas, including the setting, monitoring and adequacy assessment of risk limits. Risk management within the units ensures that risks inherent to business activities are appropriately identified, monitored and mitigated, supported by up-to-date procedures and guidelines approved in line with the Board's Risk Management Policy. Unit heads oversee daily operations, ensure timely management of operational incidents and propose changes to risk limits based on continuous risk identification and stress testing. Team leaders are responsible for ensuring that employees are aware of and comply with applicable risk management guidelines. All employees share responsibility for risk management, and business and support units are accountable for reporting operational risk incidents to the GRC function. OWN FUNDS AND CAPITAL ADEQUACY Own funds Alisa Bank Group's capital adequacy figures are presented on 31.12.2025. The Bank's total capital requirement comprises a minimum Pillar I requirement of 8.0% and an additional capital conservation requirement of 2.5% under the Act on Credit Institutions. In addition, the Finnish Financial Supervisory Authority (FIN-FSA) has imposed a systemic risk buffer applicable to all Finnish banks, effective from 1 April 2024, to be met with consolidated Common Equity Tier 1 (CET1) capital. Furthermore, based on the Supervisory Review and Evaluation Process (SREP), FIN-FSA has imposed a discretionary Pillar 2 Requirement (P2R) of 2.25%. At least three quarters of the P2R must be met with Tier 1 capital, of which at least three quarters must be CET1 capital in accordance with EU capital adequacy regulation. The P2R is effective from 31 December 2024 until 31 December 2027. Alisa Bank Group's capital adequacy ratio was 34,6%, exceeding the bank's total capital requirement (13,75%). The common equity Tier 1 ratio was 31,1%, exceeding common equity tier 1 requirement of 9,27% and Tier 1 capital requirement of 11,19%. At the end of the review period, the group's capital structure was strong and consisted of core capital (CET 1) and Tier 2 capital (Tier 2). The group's own funds (TC) were EUR 21,7 million: Tier 1 capital (T1) EUR 19,5 million was entirely common equity Tier 1 ratio (CET1) and Tier 2 capital (T2) EUR 2,1 million consisted of debenture loan. Alisa Bank´s leverage ratio was 6,7% at the end of the review period. Leverage ratio Alisa Bank leverage ratio leverage ratio (Leverage Ratio) is presented in accordance with the Commission's delegated act and represents the Company's tier 1 capital relationship to total adjusted assets and off-balance sheet items. Leverage ratio has been calculated with figures for the end of the reporting period. After CRR II entered into force in 2021, a 3% binding minimum requirement for the leverage ratio was introduced. For the Leverage ratio, the Risk Appetite level set by the Board of 3,5% has been introduced, exceeding the minimum regulatory requirement by 0,5%. Alisa Bank's leverage ratio was 6.7 per cent at the end of the review period. The exposure amount decreased due to decrease in the loan stock. Alisa Bank monitors excessive leverage as part of the capital management process. The Company's leverage ratio is set at the internal minimum target level as part of the overall risk appetite strategy and risk budgeting. Capital adequacy The objective of the Bank's capital adequacy management is to ensure that capital remains sufficient to cover all material risks arising from its operations. To achieve this, the Bank identifies and assesses all relevant risks and evaluates its risk-bearing capacity in relation to its overall risk profile. The internal capital adequacy assessment process plays a central role in determining the Bank's total risk position. Capital management is based on the Pillar I capital requirements under the CRR as well as risks not fully captured under Pillar I, such as interest rate risk and business risk. Through its internal assessment, the Bank estimates the level of capital required to absorb unexpected losses arising from these risks. The Board of Directors has overall responsibility for capital adequacy management. The Board approves the principles governing the internal capital adequacy assessment process, sets the Bank's risk strategy and target capital levels, and defines risk limits to ensure adequate capitalization. The Board reviews capital adequacy, the capital plan and key solvency risks annually, taking into account changes in the operating environment. Information on the Bank's own funds is presented below in accordance with Article 437 of the CRR. Template EU KM1 - Key metrics template 31.12.2025 30.6.2025 31.12.2024 Available own funds (amounts) 1 Common Equity Tier 1 (CET1) capital 19 538 658 18 737 626 20 128 111 2 Tier 1 capital 19 538 658 18 737 626 20 128 111 3 Total capital Risk-weighted exposure amounts 21 724 631 21 538 612 23 534 083 Total risk exposure amount Capital ratios (as a percentage of risk-weighted exposure amount) Common Equity Tier 1 ratio (%) Tier 1 ratio (%) Total capital ratio (%) Additional own funds requirements to address risks other than the risk of excessive leverage (as a percentage of risk-weighted exposure amount) Additional own funds requirements to 112 217 613 133 372 62 737 606 31.1 % 31.1 % 34.6 % 2.25 % 1.27 % 1.69 % 10.25 % 2.50 % 0 % 0 % 1 % 3.50 % 13.75 % 445 16.7 % 15.1 % 16.7 % 15.1 % 19.2 % 17.6 % 2.25 % 2 % EU 7a address risks other than the risk of excessive leverage (%) EU 7b of which: to be made up of CET1 capital (percentage points) EU 7c of which: to be made up of Tier 1 capital (percentage points) EU 7d Total SREP own funds requirements (%) Combined buffer and overall capital requirement (as a percentage of risk-weighted exposure amount) Capital conservation buffer (%) Conservation buffer due to macro- 1.27 % 1 % 1.69 % 2 % 10.25 % 10 % 2.50 % 2.50 % 0 % 0 % EU 8a prudential or systemic risk identified at the level of a Member State (%) Institution specific countercyclical capital buffer (%) Global Systemically Important Institution 0 % 0 % 0 % buffer (%) Other Systemically Important Institution 0 % 0 % 0 % buffer (%) EU 9a Systemic risk buffer (%) 10 EU 10a 11 Combined buffer requirement (%) 0 % 0 % 1 % 1 % 3.50 % 3.50 % EU 11a Overall capital requirements (%) 13.75 % 13.75 % 12 CET1 available after meeting the total SREP own funds requirements (%) Leverage ratio 15 918 699 12 262 670 12 432 521 13 Total exposure measure 292 327 193 335 183 461 435 041 863 14 Leverage ratio (%) 6.68 % 5.59 % 4.63 % Additional own funds requirements to address the risk of excessive leverage (as a percentage of total exposure measure) EU 14a Additional own funds requirements to address the risk of excessive leverage (%) - - - EU 14b of which: to be made up of CET1 capital (percentage points) - - - EU 14c Total SREP leverage ratio requirements (%) 3 % 3 % 3 % Leverage ratio buffer and overall leverage ratio requirement (as a percentage of total exposure measure) EU 14d Leverage ratio buffer requirement (%) - - - EU 14e Overall leverage ratio requirement (%) Liquidity Coverage Ratio 3 % 3 % 3 % 15 EU 16a EU 16b 16 17 Total high-quality liquid assets (HQLA) (Weighted value -average) Cash outflows - Total weighted value, average Cash inflows - Total weighted value, average Total net cash outflows (adjusted value, average) Liquidity coverage ratio (%) (average) Net Stable Funding Ratio 216 981 557 271 110 586 314 525 701 49 838 953 54 549 484 52 285 844 18 185 399 19 609 532 16 710 527 31 653 554 34 939 952 35 575 317 685 % 776 % 884 % 18 Total available stable funding 264 635 970 293 774 186 380 685 930 19 60 048 650 103 307 230 119 483 Total required stable funding 948 20 NSFR ratio (%) 440.7 % 284.4 % 318.6 % CREDIT RISK Definition Credit risk is defined as the risk of loss resulting from the failure of Alisa Bank borrowers and other counterparties to fulfill their contractual obligations, and that collateral provided does not cover Alisa Bank claims. Credit risk is the Company's key risk and is managed in accordance with the credit risk policy approved by the Board of Directors by setting targets and risk limits for the loan portfolio's quality and concentration. These limits are followed by business units and Risk Control Unit. Credit risk consists mainly of the Company's outstanding loan portfolio. Credit risk and counterparty risk also arise from other receivables, and off-balance-sheet commitments, such as unused credit facilities and limits. Credit risk profile The Company's credit risk primarily arises from its lending activities to customers. The Bank's financing portfolio consists mainly of small and medium-sized enterprises (SMEs), with the majority of the financing granted comprising invoice financing, which is short-term in nature and bears a fixed interest rate. As part of its strategic focus, the Bank is in the process of exiting its remaining portfolio of consumer lending. Credit risk represents the most significant financial risk for the Bank. During the financial year, the loan portfolio decreased compared to the previous year. Despite the reduction in the total loan volume, the Bank's relative credit risk position deteriorated due to an increase in the ratio of non-performing loans. However, the absolute amount of non-performing loans declined compared to the prior year. Loan amount (t euros) 2025 % 2024 % Personal customers Finland 10 600 18 % 96 393 65% Personal customers from other EU countries 2 846 5 % 5 523 4% Public sector entities 547 1 % 680 0% Business customers Finland 44 611 76 % 46 871 31% Business customers EU countries 253 0 % 21 0% Total 58 856 100% 149 488 100% Non-performing loans At the end of the review period, the amount of non-performing loans was EUR 5.6 million (7.1). The NPL ratio, which describes non-performing receivables in relation to all loans and receivables, was 9.5 (4.8) percent at the end of the review period. Most of the financing granted is invoice financing, which is short-term and has fixed interest rates. The main driver of the amount of non-performing loans in the business credit portfolio, has been the increasing bankruptcies in Finland. Of the remaining personal finance loan stock, approximately 18 percent are non-performing loans. The share of loan receivables past due by more than 30 days but less than 90 days was 2.0 (3.5) per cent of the total loan portfolio, while the share of receivables past due by more than 90 days was 4.3 (3.0) per cent. Of the Bank's non-performing loans, 58 per cent related to business loans, 28 per cent to domestic retail loans and 14 per cent to foreign loans. The proportion of past-due loans among business customers decreased during the review period, particularly in invoice financing, where short maturities and case-by-case assessment support predictable credit risk management. The Bank monitors the development of credit risk based on past-due exposures and other early warning indicators (UTP criteria). Credit risk management principles Credit risk management is based on the Risk Management Policy and applied in accordance with the three lines of defence model and applicable laws and regulations. Group risk management policies provide the framework for credit risk limits, while the Board of Directors sets overall risk levels. Credit decision-making is delegated to the Loan Origination and Monitoring (GLOM) team, which assesses transaction-level credit risk and makes independent decisions within approved limits. Alisa Bank applies appropriate credit risk measurement methods for limit setting. Credit risk development is continuously monitored with the support of the Group Risk Control function, which performs independent analysis and reporting. Monitoring focuses on portfolio quality, non-performing loans and limit utilisation. Borrowers are subject to continuous assessment and periodic review based on segment and risk level, with enhanced monitoring applied to higher-risk exposures. Limit breaches are documented, analysed and reported, and credit granting criteria may be adjusted through the Credit and Risk Management Committee to ensure alignment with the approved risk appetite. Credit risk management organization Alisa Bank Board of Directors approves risk appetite framework and risk appetite statements. High level guidelines & policies for credit risk appetite and risk limits are based on risk appetite framework. The Credit and Risk Management Committee approves specific Credit Policies and sets and approves credit risk limits within the risk limits defined by the board. The CEO of the Alisa Bank approves of the credit pricing. Loan approval hierarchy is defined in the Credit Risk Policies. Group Risk Control (GRC) is a part of the second line of defense and is independent of the Business units. GRC monitors credit risk limits and performs independent risk analysis and reporting. An independent internal audit in the third line of defense performs audits on the first two lines of defense. Internal Audit reviews the application and effectiveness of risk management procedures and risk assessment methodologies. Credit quality assessment and credit risk mitigation Loans to business customers are based on lending products with guarantee. In business lending Alisa Bank aims to minimize credit losses. The Bank's business customers mainly consist of small and medium-sized enterprises, whose profitability may, however, continue to be affected by the weakened economic situation. The Company monitors the development of the credit risk of the loan portfolio through the number of payment delays, unlikeliness to pay (UTP-criteria) and via changes in credit risk classes. In case there is UTP-criteria met, this affects to expected credit loss provisions and the loan receivable is moved to ECL-stage 2 or 3. Collaterals and guarantees Credit risk in business lending is managed using collateral and guarantees. In invoice financing, invoice receivables serve as collateral for the financing provided, while business loans are primarily secured by various guarantees, such as personal guarantees and guarantees granted by the state or municipalities. The principles governing the assessment and management of acceptable collateral are defined in the Bank's business lending Credit Policy. Distribution by risk class The Company classifies all customers into risk classes 0 to 5, based on the information available on the counterparty. The classification is based on the bank's internal assessment, which utilizes external credit rating data. Monitoring is continuous and can lead to a transfer from one risk class to another. Risk class 0 includes primarily defaulted loans. The risk categories in use are defined as follows: Risk class 5: The low-risk category comprises business and personal customers Risk class 4: The moderate-risk category comprises business and personal customers Risk class 3: The increased risk category comprises business and personal customers Risk class 2: The second-highest risk category includes business and personal customers Risk class 1: The highest risk category include business and personal customers Risk class 0: Defaulted business and consumer customers, and customers of risk classes 1 or 2 with over 30/60-days payment delays. Definition of default and accounting principles In accordance with Alisa Bank's accounting principles, credit risk is assessed at each reporting date to determine whether a significant increase in credit risk has occurred. The assessment is primarily based on changes in the probability of default since initial recognition, the presence of payment delays exceeding 30 days, and the application of forbearance measures. A loan is considered in default when a payment is overdue by 90 days or more, or earlier if the borrower is subject to bankruptcy, debt restructuring, or is otherwise assessed as unlikely to meet its obligations. The definition of default is applied at customer level and includes unlikeliness-to-pay criteria (UTP-criteria). The Bank actively monitors changes in borrowers' repayment capacity. The definitions of default, impairment and past due status are aligned for accounting and regulatory purposes, subject to limited exceptions such as technical defaults. Credit risk adjustments Credit risk adjustments are executed either according to the IFRS 9 expected credit loss (ECL) model, or a manual decision made by the heads of business units in the Alisa Bank based on counterparty analysis. A three-stage model is used to determine credit losses. In the first stage, the likelihood that the debtor will experience payment issues within the following 12 months is estimated. Stage 1 includes items where credit risk is estimated not to have materially increased after initial recognition or the credit risk of the item is estimated to be low. If the debtor's credit risk has materially increased after initial recognition, expected credit loss is estimated for the entire duration of the contract (stage 2). Assets in stage 3 are assets with impaired value regarding which matters have already come to light that will have a negative impact on future cash flows, including the insolvency of the counterparty. Counterparty credit risk Counterparty credit risk is the risk that the counterparty to a transaction could default before the final settlement of the transaction. Alisa Bank has not engaged in any derivative or securities financing transactions. Below is presented Alisa Bank total risk exposure amounts according to the requirements laid down in Article 92 of the EU Capital Requirements Regulation 575/2013 and in Article 73 of Directive 2013/36/EU. Template EU OV1 - Overview of total risk exposure amounts Total risk exposure amounts (TREA) Total own funds requireme nts a b c 31.12.2025 31.12.2024 31.12.2025 1 Credit risk (excluding CCR) 45 892 391 105 182 269 3 671 391 2 Of which the standardised approach 45 892 391 105 182 269 3 671 391 20 Position, foreign exchange and commodities risks (Market risk) 758 475 803 358 60 678 21 Of which the standardised approach 758 475 803 358 60 678 23 Operational risk 16 086 740 27 386 817 1 286 939 EU 23a Of which basic indicator approach 16 086 740 27 386 817 1 286 939 29 Total 62 737 606 133 372 445 5 019 008 LIQUIDITY RISK Definition Liquidity risk refers to the risk that the Company is unable to meet its payment obligations as they fall due as a result of an imbalance between incoming and outgoing cash flows. The Company's most significant liquidity risks arise from differences in the volumes and maturities of funding and lending. The starting point for liquidity risk management is the Company's ability to obtain sufficient and cost-effective funding in both the short and long term, as well as adequate diversification of funding sources. The Bank has diversified its deposit channels to reduce concentration risk, and at the end of the financial year, savings deposits obtained through deposit comparison platforms accounted for 26 per cent of total deposits. More than 82 per cent of the deposit base was covered by deposit guarantee schemes. Liquidity risk profile The Company's liquidity remained stable throughout 2025. The Bank has no derivative exposures or collateral requirements. At the end of 2025, the liquidity coverage ratio (LCR) was 1,210 per cent and the net stable funding ratio (NSFR) was 441 per cent, both significantly exceeding the regulatory minimum of 100 per cent and the Company's internal risk limit of 140 per cent. Below are presented the breakdown of financial assets and liabilities according to maturity. LCR and NSFR Development, 1000€ 31.12.2025 Liquidity Coverage Ratio LCR-ratio (12 months average) % 685 Total high quality liquid asset (12 months average) 216 982 Cash outflows (12 months average) 49 839 Cash inflows (12 months average) 18 185 Total net cash outflows (12 months average) 31 654 Net Stable Funding ratio Total available stable funding 264 636 Total required stable funding 60 049 NSFR-ratio % 441 Liquidity risk management Alisa Bank's liquidity risk management starts with the Company's ability to acquire enough competitively priced funding for the short and long term. An important part of liquidity risk management is planning the liquidity position for both the short and long term. That is managed by setting a limit approved by the Company's Board of Directors for the Company's cash resources. The Company prepares for the repayment of future debts by limiting new lending in the coming years, if necessary, and thus ensures the liquidity position. The heads of units are responsible for the risk of liquidity created in their functions. They are responsible for the liquidity risk concerning their own respective business and product areas. Alisa Bank liquidity risk management is organized in a way that it ensures that the liquidity risk metrics used to govern, measure, and mitigate liquidity risk are always adequate and usable. The Credit and Risk Management Committee's responsibility is to ensure methodology meets Alisa Bank's specific requirements. Governance, measurement, and mitigation is organized in a way which guard against any conflict of interest between the parties. All relevant personnel are aware of the guidelines and principles regarding liquidity management and that all relevant business units understand the liquidity strategy and the implications that their actions may have on the Company's liquidity position. The CEO and Management team follow Alisa Bank's liquidity position and risks, capital markets developments and all other events that could affect Alisa Bank liquidity position. Liquidity management focuses especially on identifying how much liquidity is required to keep Alisa Bank's operations running and monitoring the funding base. One of Alisa Bank's liquidity management objectives is to have long-term funding in balance with the lending portfolio. Liquidity risk monitoring and reporting The target is that liquidity risk is monitored across the whole Company in a way which ensures that all relevant cash flow elements related to Alisa Bank liquidity are defined and monitored. Alisa Bank uses Early Warning indicators and limits to ensure an early response to any developments that might trigger stress on its liquidity position. The early warning indicator is a limit making sure adequate measures are taken in times of liquidity constraints. Alisa Bank manages liquidity efficiently and accurately by having clear roles and responsibilities between units and teams. Group Risk Control monitors and analyzes liquidity position and provides the CEO, Credit and Risk Management Committee and Management team adequate information regarding liquidity risk. GRC provides the Board with adequate information regarding liquidity risk. Funding and Finance teams monitor continuously liquidity risk limits. Alisa Bank has a liquidity buffer that acts as the primary counter-balancing vehicle vs. existing liabilities. The funding team is responsible for managing the buffer. The Credit and Risk Management Committee's responsibility is to monitor the size and composition of the buffer. The Credit and Risk Management Committee analyzes the composition of the liquidity buffer. The Board of Directors receives reports on liquidity risk position on a regular basis. Liquidity risk measurement and reporting topics cover the development of key liquidity ratios LCR and NSFR, development of financing costs, concentrations in funding base, substantial changes in the liquidity reserve, and possible diminishing alternative finance sources and stress tests. Stress testing Stress testing is done to ensure that Alisa Bank can remain a going concern and withstand any form of financial stress. The Credit and Risk Management Committee oversees the development of the scenarios. The stress tests form an integral part of the risk culture at Alisa Bank as the results are used to determine the size of the Liquidity Buffer required and furthermore the composition of the buffer. Stress test scenarios are kept updated. Credit and Risk Management Committee should provide new scenarios on shorter notice when current scenarios no longer reflect the defined business strategy and risk appetite. The Credit and Risk Management Committee is responsible for evaluating and approving the new scenarios and the methodology. The ability to stress test at will is kept during times of high liquidity even if the stress tests are performed less frequently. Stress tests include market-wide stress and idiosyncratic stress. Stress testing considers all substantial risks related. The Credit and Risk Management Committee is responsible for approving the detailed stress test principles. MARKET RISK Market risk Market risk consists of interest rate risk in the banking book and foreign exchange risk. The banking book comprises on- and off-balance sheet items related to lending and funding, as well as the liquidity reserve. Foreign exchange risks are kept at a moderate level to avoid material financial losses or risk concentrations arising from exchange rate movements. As of 31 December 2025, the largest foreign currency positions were loan receivables DKK 0.4 million and SEK 0.3 million. A 10 per cent depreciation of these currencies would result in an estimated financial loss of EUR 0.08 million. The correlation of these currencies with the euro is relatively high, which mitigates the risk. Of the net loan portfolio, 99 per cent was denominated in euros, and no material foreign exchange risks arise from other balance sheet items. The bank's Treasury is responsible for controlling the foreign exchange risk and mitigating the risk. There are risk limits for exchange rate risk as a part of risk appetite statements. Foreign exchange risk is reported by Group Risk Control as part of monthly risk reporting for Credit and Risk Management Committee and the Board. Interest rate risk Interest rate risk arises from differences in the interest rate repricing and maturities of assets and liabilities in the Bank's banking book as market interest rates change. Changes in market interest rates affect both the fair value of on- and off-balance sheet items (net present value risk) and net interest income (earnings risk). At the end of the financial year, the Company's investment portfolio included debt securities amounting to EUR 14.9 million, the valuation of which is affected by changes in market interest rates. The debt securities are low risk in nature and have short maturities of up to 12 months. The Company's objective is to balance the interest rate bases of assets and liabilities and to reduce unexpected volatility in net interest income. The pricing of lending and funding is a key factor in the management of net interest income and interest rate risk. Most of the financing granted consists of invoice financing, which is short-term in nature and bears a fixed interest rate. Interest rate risk is monitored and reported regularly to the Executive Management Team and the Board of Directors in accordance with limits set by the Board, and is measured by assessing the impact of interest rate shocks on own funds and net interest income. As at 31 December 2025, a two percentage point increase in interest rates would increase the economic value of own funds by 2.9 per cent and improve net interest income by approximately EUR 1.7 million on an annual basis (8.5 per cent of Common Equity Tier 1 capital), while a corresponding decrease in interest rates would reduce the economic value of own funds by 3.7 per cent and decrease net interest income by approximately EUR 1.7 million on an annual basis (-8.6 per cent of Common Equity Tier 1 capital). The table below presents the standard interest rate risk sensitivity scenarios defined by the European Banking Authority (EBA). Managing interest rate risk The Company measures interest rate risk in the banking book (IRRBB) through interest rate sensitivity analyses assessing the impact of interest rate changes on both the economic value of equity (EVE) and net interest income (NII). IRRBB is measured, monitored and managed using standardized scenarios and is assessed against Board-approved risk appetite limits. Calculations are based on a constant balance sheet assumption, implied forward rates and behavioral modelling for non-maturity deposits and reinvestments. IRRBB measurement relies on assumptions related to reinvestment behavior and interest rate fixing periods, using expected cash flows and their present values. Foreign exchange risk has no material impact on net interest income due to limited exposure. The Bank aims to balance the repricing profiles of assets and liabilities to reduce volatility in net interest income. Interest rate risk and limit utilization are reported regularly to the Credit and Risk Management Committee and the Board of Directors, including EVE and NII metrics, FX exposure, forward-looking risk levels, duration measures and any limit breaches. 570 -730 -455 458 601 -53 Interest rate sensitivity analysis, 1000€ 31.12.2025 All rates rise by 200 b.p. All rates decline by 200 b.p. Short team rates decline by 250 b.p. and long-term rates decline by 100 b.p. rm rates rise by 250 b.p. and long-term rates decline by 100 b.p. Short term rates rise by 250 b.p. Short term rates decline by 250 b.p. OPERATIONAL RISK Definition Operational risks refer to risks arising from inadequate or failed internal processes, systems or personnel, or from external events. Operational risks also include internal and external fraud risks. In addition, operational risks comprise legal risks as well as risks related to regulatory compliance and information security. Losses resulting from realised operational risks during the review period were immaterial in relation to the own funds allocated to cover operational risks. During the financial year, the Bank identified fraud risks particularly in relation to payment services and digital channels. The realised fraud cases and the resulting losses were not material in relation to the Bank's financial position or results. The Bank manages fraud risks through preventive control mechanisms, continuous monitoring and staff training. The management of fraud risks is continuously developed to respond to changes in the operating environment and the threat landscape. The Company's Board of Directors approves the principles for operational risk management annually. The primary objectives of operational risk management are to ensure business continuity, compliance with regulatory requirements in both the short and long term, and the management of reputational risk. Business continuity and disruption management form part of information and communication technology (ICT) risk management and are key elements of the Company's operational risk management framework. ICT risk management takes into account the EU financial sector regulation DORA (Digital Operational Resilience Act), which entered into force in 2025. Realised operational risk events are reported from business units to the risk control function. The monitoring, oversight and reporting of operational risks are carried out within the Company's risk control function. Realised operational risks are reported as part of the monthly risk report. The Company's management and Board of Directors receive at least annually a Company-wide risk and control self-assessment. Based on this report, the Board is able to form an overall view of the operational risks affecting the business and their potential impact on the Company. Appendix: Summary Table of Pillar III requirements Article of CRR and CRR2 Title Description Index / Reference Institutions shall disclose their risk management objectives and policies for each separate category of risk, including the risks referred to under this Title. These disclosures shall include: 435 Risk Management objectives and policies the strategies and processes to manage those risks; Pillar III report - Risk management in Alisa Bank The structure and organization of the relevant risk management function including information on its authority and statute, or other appropriate arrangements; Pillar III report - Risk management in Alisa Bank the scope and nature of risk reporting and measurement systems; Pillar III report the policies for hedging and mitigating risk, and the strategies and processes for monitoring the continuing effectiveness of hedges and mitigants; Pillar III report Declaration approved by the management body on the adequacy of risk management arrangements of the institution providing assurance that the risk management systems put in place are adequate regarding the institution's profile and strategy; Pillar III report - Introduction a concise risk statement approved by the management body succinctly describing the institution's overall risk profile associated with the business strategy. This statement shall include key ratios and figures providing external stakeholders with a comprehensive view of the institution's management of risk, including how the risk profile of the institution interacts with the risk tolerance set by the management body. Pillar III report - Introduction Institutions shall disclose the following information, including regular, at least annual updates, regarding governance arrangements: the number of directorships held by members of the management body; Alisa Bank website the recruitment policy for the selection of members of the management body and their actual knowledge, skills, and expertise; Corporate governance statement and Alisa Bank website the policy on diversity regarding selection of members of the management body, its objectives and any relevant targets set out in that policy, and the extent to which these objectives and targets have been achieved; Corporate governance statement and Alisa Bank website whether or not the institution has set up a separate risk committee and the number of times the risk committee has met; Corporate governance statement and Alisa Bank website the description of the information flow on risk to the management body. Pillar III report - Risk management in Alisa Bank Article 436 Scope of application Institutions shall disclose the following information regarding the scope of application of the requirements of this Regulation in accordance with Directive 2013/36/EU: the name of the institution to which the requirements of this Regulation apply Pillar III report an outline of the differences in the basis of consolidation for accounting and prudential purposes, with a brief description of the entities therein, explaining whether they are: (i) fully consolidated; (ii) proportionally consolidated; (iii) deducted from own funds; (iv) neither consolidated nor deducted Not applicable any current or foreseen material practical or legal impediment to the prompt transfer of own funds or repayment of liabilities among the parent undertaking and its subsidiaries; Not applicable the aggregate amount by which the actual own funds are less than required in all subsidiaries not included in the consolidation, and the name or names of such subsidiaries; Not applicable if applicable, the circumstance of making use of the provisions laid down in Articles 7 and 9. Not applicable Article 437 Own funds Institutions shall disclose the following information regarding their own funds: a full reconciliation of Common Equity Tier 1 items, Additional Tier 1 items, Tier 2 items and filters and deductions applied pursuant to Articles 32 to 35, 36, 56, 66 and 79 to own funds of the institution and the balance sheet in the audited financial statements of the institution Not Applicable; capital Adequacy The consolidation group is the same as legal concern.