Dukhan Bank Q.p.s.c.QSE: DUBK

Pillar III Disclosures – June 2025

· Issued by Dukhan Bank Q.p.s.c.


Basel III - Pillar 3 Disclosures 30-June -2025

Contents

Introduction 2

DIS20: Overview of risk management, key prudential metrics and RWA 2

KM1: Key Metrics (at consolidated group level) 2

OVA: Bank Risk Management Approach 3

OV1: Overview of Risk Weighted Assets 9

CC1: Composition of Regulatory Capital 11 CC2: Reconciliation of regulatory capital to balance sheet 14 DIS30: Links between financial statements and regulatory exposures 15 DIS31: Asset encumbrance 15 ENC: Asset encumbrance 15 DIS40: Credit risk 16 CRA: General Qualitative information about Credit Risk 16 CR1: Credit Quality of Asset 18 CR2: Changes in Stock of Defaulted Financing and Sukuks 19 CRC: Qualitative disclosure related to credit risk mitigation techniques 19 CR3: Credit risk mitigation techniques - overview 20 CRD: Qualitative disclosure on banks' use of external credit ratings under the standardized approach for credit risk 21 CR4: Standardized approach - credit risk exposure and CRM effects 21 CR5: Standardized approach - exposures by asset classes and risk weights 22 DIS42: Counterparty credit risk 23 CCR1: Quantitative disclosure related to CCR 23 CCR3: Quantitative disclosure related to CCR 23 DIS50: Market risk 24 MRA: General qualitative disclosure requirements related to market risk 24 MR3: Market risk under the simplified standardized approach 26 DIS80: Leverage Ratio 27 LR1 - Summary comparison of accounting assets vs leverage ratio exposure measure 27 LR2 - Leverage Ratio Common disclosure template 28 DIS85: Liquidity 29 LIQA - Liquidity risk management 29 LIQ1: Liquidity Coverage Ratio (LCR) 32 LIQ2: Net Stable Funding Ratio (NSFR) 33

‌Introduction

The Qatar Central Bank (QCB) supervises Dukhan Bank (the Bank) and its subsidiaries (together referred to as the "Group") on a consolidated basis, and therefore receives information on the capital adequacy of, and sets capital requirements for, the Group as a whole. The capital requirements are computed at a Group level using the Basel III framework as laid out in QCB circular 3/2014 dated 06/01/ 2014. The Basel framework is structured around three 'pillars', with the Pillar 1 minimum capital requirements and Pillar 2 supervisory review process complemented by Pillar 3 market discipline. These disclosures are in line with the requirements of Pillar 3 under Basel Framework and is required by QCB bide circular 6/2022 dates 08/01/2022.

Pillar 3 Disclosure June 2025

Pillar 3 disclosures complement the minimum capital requirements and the supervisory review process. Its aim is to encourage market discipline by developing disclosure requirements which allow market participants to assess specified information on the scope of application of Basel III, capital, particular risk exposures and risk assessment processes, and hence the capital adequacy of the Group. Disclosures consist of both qualitative and quantitative information and are provided at the consolidated level. The disclosures presented as part of this document is in line with disclosure template provided by Basel Committee of Banking Supervision in DIS 10 dates 11/11/2021 and QCB circular 6/2022 dated 08/01/2022. The figures mentioned in the disclosures are in QAR Mn.

The QCB issued Basel III capital regulations in 2014 introducing minimum capital requirements at three levels, namely Common Equity Tier 1 (CET1), Additional Tier 1 (AT1) and Total Capital. Additional capital buffers (Capital Conservation Buffer - 2.5%) introduced are over and above the minimum CET1 requirement of 6%. In November 2022 QCB published revised capital guidelines mainly focused on updates on Pillar 1 capital requirements introduced Basel III - Reforms with January 2024 as timeline for adaption.

‌DIS20: Overview of risk management, key prudential metrics and RWA

‌KM1: Key Metrics (at consolidated group level)

Jun-25

Dec-24

Jun-24

Available capital (amounts)

1

Common Equity Tier 1 (CET1)

12,268

11,784

11,659

1a

Fully loaded ECL accounting model

-

-

0

2

Tier 1

14,089

13,605

13,479

2a

Fully loaded ECL accounting model Tier 1

-

-

0

3

Total capital

14,913

14,375

14,191

3a

Fully loaded ECL accounting model total capital

-

-

Risk-weighted assets (amounts)

4

Total risk-weighted assets (RWA)

81,501

82,942

79,806

Risk-based capital ratios as a percentage of RWA

Jun-25

Dec-24

Jun-24

5

Common Equity Tier 1 ratio (%)

15.05%

14.21%

14.61%

5a

Fully loaded ECL accounting model CET1 (%)

6

Tier 1 ratio (%)

17.29%

16.40%

16.89%

6a

Fully loaded ECL accounting model Tier 1 ratio (%)

7

Total capital ratio (%)

18.30%

17.33%

17.78%

7a

Fully loaded ECL accounting model total capital ratio (%)

Additional CET1 buffer requirements as a percentage of RWA

8

Capital conservation buffer requirement (2.5% from 2019) (%)

2.50%

2.50%

2.50%

9

Countercyclical buffer requirement (%)

0.00%

0.00%

0.00%

10

Bank D-SIB additional requirements (%)

0.50%

0.50%

0.50%

11

Total of bank CET1 specific buffer requirements (%)

3.00%

3.00%

3.00%

(row 8 + row 9+ row 10)

12

CET1 available after meeting the bank's minimum

6.05%

5.21%

5.61%

capital requirements (%)

Leverage Ratio

13

Total leverage ratio measure

133,637

132,399

127,314

14

Leverage ratio (%) (row 2/row 13)

10.54%

10.28%

10.59%

14a

Fully loaded ECL accounting model leverage ratio (%)

10.54%

10.28%

10.59%

Liquidity Coverage Ratio

15

Total HQLA

22,388

19,694

16,847

16

Total net cash outflow

17,578

11,770

12,817

17

LCR ratio (%)

127.36%

167.3%

131.4%

Net Stable Funding Ratio

18

Total available stable funding

78,335

78,284

74,533

19

Total required stable funding

73,522

73,156

71,481

20

NSFR ratio (%)

106.5%

107.0%

104.3%

‌OVA: Bank Risk Management Approach

Dukhan Bank faces various financial and non-financial risks in its business and operations, including capital, credit, liquidity, market (trading and banking

book), compliance, legal,IT and cyber security and operational risks. In order to manage these risks, the Bank has developed procedures (Risk Policies and Procedures) to ensure that appropriate risk governance is exercised at all levels of the Bank, including the Board of Directors, Executive Committees, the Senior Management team as well as all the departments in the Bank.

The Banks Risk Policies and Procedures document the framework for the identification and measurement of a wider array of risk types as set out above, prescribe appropriate risk limitations, monitor, and record the events of such risks on an ongoing basis and prescribe appropriate remedial action. The Bank has

established a risk management framework for the entire group, which is reviewed on an annual basis. At the same time, Bank maintains its compliance with Basel III, QCB and other regulatory guidelines.

Risk Management Framework

Risk is inherent in the business of Banking; however, it is managed though established mechanisms that identify, assess, measure, monitor and control those risk. The prudence in the risk management framework of Dukhan Bank is largely due to pre-determined roles and responsibilities assigned to Board of Directors, Risk management committees, Executive committees, Senior Management along with individual employees in the Bank.

Risk management is critical to the Bank's continuing profitability and sustainability and each individual in the Bank is responsible for risk exposure related to their roles in accordance with "three lines of defense" principle. The Bank promotes a robust risk culture across the organization though a top-down risk governance structure (as shown below)



The overall responsibility of risk management (executed via pertinent committees/ Senior Management/ Risk Management Division- RMD) rests with the Board of Directors (BOD). Therefore, it is the duty of the BOD to recognize the risks to which the Bank is exposed and to ensure the Implementation of a risk management framework and maintaining adequate and capable infrastructure to support the framework.

The Board Audit Compliance and Risk Committee (BACRC) is designated by the BOD to fulfill its oversight responsibilities which includes

  • Ensuring the existence of sound internal controls within the Bank.

  • Examining and following up on issues raised by internal auditors, external auditors and QCB.

  • Reviewing progress made by Bank in the identification of risks.

  • Ensuring implementation of action plans to monitor and manage all risks across the Bank

  • Reviewing matters of compliance to ensure the Bank meets regulatory and legal requirements.

  • Reviewing and approving of risk measurement methodologies and assumptions.

  • Reviewing various Risk reports on a periodic basis and identifying appropriate action.

    The day-to-day risk management and implementation of the risk management framework is achieved through Risk management Division (RMD) under the guidance of the Chief Risk Officer (CRO). The RMD as the second line of defense is responsible administration, maintenance and support the overall risk management framework. The key responsibilities of RMD are

  • Monitoring and reporting the risk positions to respective executive risk management committees and BACRC

  • Proposing risk limits and quantification of risks in terms of capital and provision requirements.

  • Ensuring proper implementation of Board approved risk framework

  • Ensuring timely implementation of regulatory guidelines related to risk management department

  • Co-ordinate with both first line and third line of defense (Internal Auditor) strengthen the existing risk management framework

  • Provide awareness and training to business and operations divisions (first line of defense) related to risk management

  • Ensuring adoption of robust risk culture across all departments of the Bank

  • Carry out Bank wide periodical risk assessment, measurement, stress testing and regulatory reporting.

    The Internal Audit department has the objective of providing assurance and consulting function designed to support the Bank to accomplish its goals by bringing a systematic auditing approach to evaluate the effectiveness of risk management, control, and governance processes. The Internal Audit, as a third line of defense, is organizationally independent from all other functions in the Bank, and accountable to provide independent assurance to the BOD through the Board Audit Compliance and Risk Committee (BACRC).

    The Bank has also established executive level committees for ensuring wholistic risk management across the organization.

    Asset & Liability Management Committee (ALCO) is responsible for

  • Develop and review the ALM strategy of the Bank.

  • Propose liquidity, profit rate, foreign exchange, investment strategies, objectives, policies and limits and submit them to the Board Audit, Compliance and Risk Committee (BACRC)

  • Propose to the management committee and implement policies to allocate available capital and other funding to the operations, together with the related cost of such funding.

  • Review and approve Contingency Liquidity Plan (CLP) for the bank.

  • Propose emergency funding policies to the Board of Directors

  • Communicate the approved strategies and policies to all concerned in the Bank.

  • Identify funding requirements for each business group and means to address funding gaps.

  • Ensure compliance with the ALM guidelines, set by the Risk committee.

  • Ensure that procedures and controls are put in place for implementing the policies.

  • Define Funds transfer pricing guidelines.

  • Suggest the hurdle rates for the business unit level.

  • Review the scenarios to be considered for the recovery plan and identify the set of recovery options that can be executed in the event of crisis, where the survival of the Bank is at risk.

    The Operational Risk Management Committee is responsible for

  • Committee is responsible for managing and overseeing all aspects of operational risk including the business continuity in the Bank.

  • Committee ensures that all operational risk policies are effectively implemented and the system / platform to monitor and report inherent operational risks is robustly protecting the interests of the Bank.

  • Approve and oversee the implementation of ORMF to explicitly manage operational risk as a

    distinct risk to the Bank's safety and soundness.

  • To facilitate the identification and pro-active management of the top operational risks in the Organization.

  • Review and approve policies and procedures relating to operational risk to ensure compliance with applicable laws and regulations.

  • To analyze frauds and other significant operational losses or exceptions, including areas of regulatory non-compliance and breaches, and to recommend corrective measures (lessons learned) to prevent recurrences across all areas in the Bank.

  • To raise awareness of new trends and developments in operational risk management techniques and alignment with best practices.

  • To promote a sound risk culture in the Bank that proactively manages risk.

  • Develop and implement BCM (Business Continuity Management) strategy, policies, processes, and procedures required to ensure critical business activities are continued in case of emergencies and major unforeseen disasters.

  • Develop, review, and oversee implementation of Information Security policies and procedures, review emerging threats to the organization and endorse necessary plans /budgets to address it.

  • To review and discuss significant Operational Risk Reports on key Operational Risks and action plans.

    The responsibilities of the credit risk committee are

  • Evaluate the investment proposals in line with the risk appetite and strategy of the Bank.

  • Recommend investment proposals to BACRC for review (if required) and ensure adequate mitigation actions are put in place.

  • Ensure compliance to risk parameters and prudential limits approved by the Board.

  • Monitor implementation of Credit Risk Management policy approved by the Board.

  • Review the provisions for key investments.

  • Review all past due cases.

  • Promote a Risk Culture in the Group that proactively manages risk.

  • Monitor adherence to Credit Policy

  • Monitor trends in the credit quality of the bank's loan portfolio

  • Approve/ recommend new requests/ renewals as per delegated authority.

  • Approve product programs

  • Approving excess over limits

  • Approving extensions - beyond 90 days

  • Approve amendments in terms and conditions

  • Approve Deferral of documentation

  • Approve/Recommend restructuring arrangements

  • Approve Provisions

  • Approve write-offs in line with QCB Guidelines

    Risk Measurement Systems

    As a key part of Pillar I risks, Dukhan Bank manages its credit risk as per established credit risk policies, internal credit ratings, regular obligor credit reviews and active monitoring at a credit portfolio level. Diversification of credit risk is managed with concentration limits at the individual, industry, geography, and product level. Other credit risk mitigation occurs through the use of collateral, guarantees, credit structures and appropriate credit documentation. The Bank manages its market risk exposures in line with market risk policies. Key traded risk mitigation occurs through a detailed framework of policies and management of capital resources. These tools and techniques provide the Risk Committee and the Board of Directors with the ability to control risk appetite, capital allocations and the active monitoring of strategic targets.

    The user uses a leading asset-liability management and liquidity management solution to help optimize the management of the balance sheet and ensure that risk monitoring and controls are of the highest standards. Operational risk management has been enhanced with further implementation of data security systems, continuous training and awareness, improved business continuity infrastructure and disaster recovery sites. The same risk governance impetus is scheduled to continue in line with the continued implementation of the Banks business strategy.

    The strategic risk management approach of the Bank leads to group-wide portfolio management, enterprise risk standards, asset/liability risk management, liquidity and market risk management, risk systems, , Internal Capital Adequacy Assessment Process (ICAAP) and regulatory relationships. Enterprise risk management standards are established in order to direct the overall internal control and governance activities, including risk model validations, and the establishment of relevant group policies in relation to principal risks and overall group risk classification's, detailed limit framework and regular monitoring. Other material risks including compliance, regulatory and legal risk, and reputational risk are managed through comprehensive policies & procedures and well-established processes for assessment, monitoring and mitigation of these risks.

    Stress Testing

    Following the principles set out in the Basel III Accord and regulatory guidelines provided by QCB, Dukhan Bank has in place an advanced framework for stress testing, which is wholly integrated with the Banks strategy, business decisions and financial forecast development. The key components of the stress testing framework emphasize the use of scenarios which captures the current economic and geopolitical challenges, integration with the Bank's risk governance, prudence of the methodologies being applied at each level of testing, and stresses relatable to the products of the Bank.

    Various levels of stress testing and scenario analysis is performed to inform a holistic assessment of risk, probe loss potential, augment risk identification and monitoring. These include: (i) Top-down stress testing which informs strategic decisions, for example capital adequacy, and aids articulation and challenge of enterprise-level risk appetite and Strategic Risk Objectives; and (ii) Bottom-up stress testing which informs tactical risk specific actions, by way of portfolio monitoring, risk profitability measurement and reviewing appetite thresholds for enhanced internal controls. The suite of scenarios covers various historical, forward-looking, sensitivity stresses and what-if scenarios. Stress testing and scenario analysis can be performed at various levels of granularity.

    The Bank considers stress testing and scenario analysis as one of the most important tools for risk management. Stress testing exercise provide useful insight into the specific vulnerabilities and risk characteristics of the Bank's portfolio. In addition, stress testing is a core aspect of the risk appetite calibration process linking bottom-up business plans and top-down Board risk appetite and capacity.

    Various emerging risks in the short-term could pose a threat to strategic goals. Consolidated stress tests and scenario analysis probe the loss potential of plausible downturn scenarios. The impact on the credit outlook and market risk factors are calibrated and the potential volatility in the Bank earnings and capital adequacy quantified. In addition, scenarios and stress testing is also used to assess the capital and liquidity adequacy of the Bank (including subsidiaries and branches) as required by local regulators, and for internal risk management purposes. Scenario analysis is essential in strategic and financial planning purposes.

    In accordance with IFRS 9 and FAS 30 guidelines for determining applicable credit impairment losses, the methodology incorporates forward-looking indicators in both the assessment of whether the credit risk of an instrument has increased significantly since its initial recognition and the measurement of expected credit loss (ECL). The Bank formulates a 'base case' view of the future direction of relevant economic variables as well as a representative range of other possible forecast scenarios. This process involves developing additional economic scenarios and considering the relative probabilities of each outcome. External information includes economic data and forecasts published by Qatar governmental bodies and global monetary authorities.

    The Group follows a rigorous and forward-looking stress testing procedure (in line with pillar 2 requirements of Basel 3 Accord as well as taking into consideration QCB guidelines) that identifies possible events or changes in market conditions (or risk factors) that could adversely impact the Group. This requires foreseeing situations under hypothetical scenarios considering the question 'what -if' and development of stress tests in such scenarios. This enables the Group to be well equipped to cope with the crisis situations when they arise. Risk function has the responsibility of conducting periodic stress testing of the credit portfolio.

    The stress-testing program of the Group involves the following steps:

  • Capturing reliable data (accuracy and timeliness)

  • Identification of risk factors that have an impact on the portfolio value. The different categories of risk factors used by the Group are:

    1. Obligor rating

    2. Environment (industry, economic, political, real estate prices, etc.)

    3. Model (assumptions, holding period, etc.)

    4. Analytics (correlation, transition matrices, etc.)

  • Construction of stress tests on the basis of single factor or multi-factor scenarios

  • Deciding magnitude of factor shock

  • Running stress tests

  • Reporting results of stress tests

  • Assessing the impact of abovementioned results on capital adequacy of the Group

  • Reassessing the relevance of stress tests on yearly basis.

Risk Mitigation

The Bank has set up a framework for credit risk mitigation as a step towards reducing credit risk in an exposure, at facility level, by a safety net of tangible and realizable securities including approved third-party guarantees/ insurance. Examples of the types of Credit Risk Mitigation (CRM) include netting agreements, collateral, and security, guarantees and other non-contractual support. The Bank ensures that all documentation is binding on all parties and is legally enforceable in all relevant jurisdictions. The Bank also ensures that all the documents are reviewed by appropriate authority and have appropriate legal opinions to verify and ensure its enforceability. Dukhan Bank has historically implemented a conservative credit policy. The Bank believes that its conservative approach to lending ensures that there is an adequate

spread of the risk through a diverse product range and customer base (by geography, industry, and obligor type). The Bank also ascertains that its conservative credit policy promotes the application of effective credit risk limits in its business, while providing adequate returns on the risk that is on par with the management's expectations. The Bank's effective monitoring of its risk, together with a conservative internal risk rating system and a timely recovery strategy, further augments Dukhan Bank's approach to risk mitigation.

The Bank has deployed a robust operational risk framework, which mandates RCSA, a process of identification of risk and associated controls for risk mitigation. Any deficiency in the controls is immediately addressed along with close monitoring of the specific risk. The three lines of defense framework adopted by the Bank also supports risk mitigation through the bottom's up approach.

‌OV1: Overview of Risk Weighted Assets

a

b

c

RWA

Minimum capital requirements

Jun-25

Dec-24

Jun-25

Dec-24

1

Credit risk (excluding

counterparty credit risk)

72,704.38

74,426.90

9,451.57

9,675.50

2

Of which: standardized

approach (SA)

72,704.38

74,426.90

9,451.57

9,675.50

3

Of which: foundation

internal ratings-based (F-IRB) approach

-

-

-

-

4

Of which: supervisory

slotting approach

-

-

-

-

5

Of which: advanced internal ratings-based

(A-IRB) approach

-

-

-

-

6

Counterparty credit risk

(CCR)

346.15

106.43

45.00

13.84

7

Of which: standardized

approach for counterparty credit risk

346.15

106.43

45.00

13.84

8

Of which: IMM

0.00

-

-

-

9

Of which: other CCR

0.00

-

-

0.00

10

Credit valuation

adjustment (CVA)

346.15

106.43

45.00

13.84

11

Equity positions under the simple risk weight approach and the internal model method during the five-year

linear phase-in period

0

-

-

-

Earlier from Dukhan Bank Q.p.s.c

All Dukhan Bank Q.p.s.c news releases