2025
Ris
Management
Report
Faroya Banki
Board of Directors
and Executive Board
Group objectives and Risk Management Report
To keep our shareholders and other stakeholders informed
of the group's risk and capital management policies,
including risk management methodologies and practices,
both short and long term.
- Introduction 3
-
Organisation 4
Introduction. 4
Risk policies and limits 5
Risk organization 5
Board of Directors 7
Executive Board 7
Staff departments 7
Business units 8
Reporting 8
-
Capital Management 10
Framework of the Group's capital management 10
Pillar I 10
Pillar II 10
Solvency requirement 11
The methodology 12
Group solvency requirement 12
Combined buffer requirement 13
Excess capital 14
Leverage ratio 15
-
Credit Risk 16
Definition 16
Policy 16
Credit process 16
Credit risk classification 17
Credit exposure 17
Credit exposure, quality, and concentration 18
Risk mitigation 20
Monitoring and portfolio management 22
Credit risk management 22
Impairment/Losses 23
The Supervisory Diamond 24
-
Market Risk 25
Organisation 25
Definition 25
Policy and responsibility 25
Control and management 26
Market risk 26
Interest rate risk 26
Exchange rate risk 27
Equity market risk 27
-
Liquidity Risk 28
Definition 28
Control and management 28
Operational liquidity risk 28
Liquidity stress testing 28
Twelve-month liquidity 28
Structural liquidity risk 28
Funding sources 29
Collateral provided by the Group 29
-
Operational Risk 30
Definition 30
Policy 30
Measurement and control 30
Long-term goals in operational
risk management 30
-
Insurance Risk 31
Capital requirements 31
Trygd non-life insurance 31
NordikLív-Life insurance… 34
-
Introduction
The purpose of Føroya Banki's Risk Management Report is to ensure transparency in the Føroya Banki Group and to make available information on how the Group manages the risks it encounters.
Føroya Banki's Risk Management Report is published annually on the Group's website: https://www.foroyabanki.com/rmr, simultaneously with the release of the Group's Annual Report 2025. The Risk Management Report is a separate unaudited document. There are no audit requirements for the Risk Management Report, but much of the information in the Risk Management Report will also be provided in the audited Annual Report 2025.
-
Organisation
-
Introduction
Understanding and ensuring transparency in risk taking are key elements of the Føroya Banki Group's business strategy. The Group's ambition is to set high standards for risk management. Our risk organization supports this ambition, and it has developed in-depth risk management expertise.
The Board of Directors sets out the overall risk policies for all types of material risk while the Chief Executive Officer (CEO) is responsible for the day-to-day management of the Group, including implementation of the risk policies and risk management.
The Executive Board consists of Group CEO, Turið F. Arge. At the chief operational level, the Group is divided into two main business units:
Corporate Banking operations In the Faroe Islands and Greenland, headed by Brian Smedemark
Personal Banking operations in the Faroe Islands and Greenland, headed by Silja á Borg Færø
Figure 1The business units are supported by the following units:
Credit Services, Finance, Accounting, Treasury, IT, Marketing, Markets and HR. The Group's risk officer and compliance officer are members of CEO's office.
The Board of Directors and the Group Executive Management Team have established various sub-committees, including an Audit Committee, a Risk Committee, a Credit Committee, a Remuneration Committee, and a Nomination Committee.
The Group allocates resources to manage and monitor risk and to ensure on-going compliance with approved risk limits. The Group has a reporting cycle to ensure that the relevant management bodies, including the Board of Directors, the Chief Executive Officer, and the Group Executive Management Team, are kept informed of relevant developments in risk measures.
The Group's risk policies as well as its limits and organizational framework for risk management are described in greater detail in the following sections.
-
Risk policies and limits
The Board of Directors sets out the overall risk policies and limits for all material risk types. The Board also determines the general principles for managing and monitoring risk, and it reviews the risk policies and limits annually. The Group uses risk appetite as a strategic concept to determine its risk-based limits. Risk appetite represents the maximum risk the Group is willing to assume in pursuit of its business targets. The risk appetite framework offers an overview of various risk dimensions and enables the Group to manage risk measurement across these dimensions in accordance with its overall risk policies.
The framework is based on an analysis of the current risk profiles of the Group and its major business units. It includes setting explicit targets, limits, and contingency plans in accordance with the risk policies. It also includes monitoring of risk levels.
Key risk elements are identified on an on-going basis in a dynamic process driven by new products, procedures, risk measurement applications as well as economic developments. The Group conducts risk management at the customer and industry levels as well as based on geographical location and collateral type. It takes a comprehensive approach to the core risk dimensions:
Credit risk
Market risk
Liquidity risk
Operational risk
Other risk dimensions are incorporated at the Group and business unit levels where appropriate. They include insurance and concentration risk, financial strength, and earnings robustness. Specific risk instructions for the main business units are prepared based on the overall risk policies and limits. These instructions are used to prepare business procedures and reconciliation and control procedures for the relevant units and for system development purposes.
-
Risk organization
Føroya Banki's "Rules of procedure" for the Board of Directors and the "Board of Directors' Instructions to the Executive Board" specifies the responsibilities of the Board of Directors and the Executive Board and the division of responsibilities between them. This two-tier management structure has been developed in accordance with Faroese and Danish legislation, and the "Rules of procedure" and "Board of Directors' Instructions to the Executive Board" are key documents in the Group's management structure, including the organization of risk management and authorizations.
The Board of Directors lays down overall policies, while the Executive Board oversees the Group's day-to-day management and reports to the Board of Directors. None of the Group's executive managers serve on the Board of Directors of the parent company. The risk and capital management functions are separate from the credit assessment and credit-granting functions, as shown in figure 2.
Figure 2The Group's management structure also reflects the statutory requirements governing listed Faroese companies in general and financial services institutions in particular. The Føroya Banki Group applies to comply or explain principle set out in the recommendations issued by the Committee of Corporate Governance. These recommendations apply to companies listed on NASDAQ Copenhagen.
The Audit Committee examines accounting, auditing, and security issues that the Board of Directors, the Audit Committee, the internal auditor, or the external auditors believe deserve attention. The Risk Committee reviews the internal control and risk management system.
The Audit Committee consists of Árni Tór Rasmussen, Chair of the Committee, Kristian Reinert Davidsen, member of the board and Marjun Hanusardóttir, member of the board.
The Risk Committee consists of Tom Ahrenst, Chair of the Committee, Birgir Durhuus, Chair of the board, Annfinn Vitalis Hansen, vice chair of the board.
The Boards Credit Committee consists of Tom Ahrenst, Chair of the Committee and the CEO, the COO, the head of the Credit department.
The Executive Board has assembled the Group Executive Management Team and established a Credit Committee
i.e. a risk-orientated sub-committee.
-
Board of Directors
The Board of Directors must ensure that the Group is appropriately organized. As part of this duty, it appoints the members of the Executive Board and the Group's Chief Internal Auditor.
The largest credit facilities are submitted to the Board of Directors for approval, and the Board defines overall limits for market risk and liquidity risk. Regular reporting enables the Board of Directors to monitor whether the overall risk policies and systems are being complied with and whether they meet the Group's needs. In addition, the Board of Directors reviews reports analysing the Group's portfolio, particularly information about industry concentrations, large exposures, and impaired exposures.
Internal Audit examines accounting, auditing, and security issues. These are issues that the Board of Directors or the external auditors believe deserve day-to-day attention. Internal Audit also reviews the internal control and risk management systems.
-
Executive Board
The Executive Board is responsible for the day-to-day management of the Group as stated in the "Rules of procedure" for the Board of Directors and the "Board of Directors' Instructions to the Executive Board".
The Executive Board sets forth specific risk instructions and supervises the Group's risk management practices. It reports to the Board of Directors on the Group's risk exposures and approves material business transactions, including credit applications up to a defined limit.
The Group has also organized various sub-committees/functions for specific risk management areas such as asset and liability management and the management of risk parameters and models affecting the Group's capital and risk-weighted assets. The sub-committees consist mostly of members of the management team.
The sub-committees are:
Committee
Function
Credit Committee
Overview of credit risk. Review of applications. Implementing Creditpolicies approved of the Board of Directors.
Market Committee
Overview of the Groups market risk. Analysing, planning and
recommendation.
Risk, Solvency and Liquidity Committee
Overview of the Groups main risks. Analysing, planning and
recommendation.
Rating Committee
Overview of the Groups statistic ratingmodel and AML model
IT Committee
Overview of the Groups IT-risks. Analysing, planning and
recommendation.
-
Staff departments
The Group's overall risk issues including credit, market, liquidity, and operational risks are monitored by the Group's Risk Officer, in co-operation with managers of business units and subsidiaries, reporting directly to the Executive Board.
The Finance department oversees the Group's financial reporting, budgeting, liquidity, and capital structure. It also has overall responsibility for the Group's compliance with the Capital Requirements Directive and related legislation and for the internal capital adequacy assessment process.
The Group has established a functional separation between units that enter into business transactions with customers or otherwise expose the Group to risk on the one hand and units in charge of overall risk management on the other.
The Group's Risk Management is carried out by the Group's Risk Officer which is a part of the CEO's Office with reporting rights and obligations to the Executive Board and reporting rights to the Board of Directors in risk-related matters. Risk Management has overall responsibility for monitoring the Group's risk portfolio and reporting on overall risk measures. In addition, Risk Management is responsible for the implementation of risk models and risk analysis and for providing support to the Risk Committee.
The Credit Department has the overall responsibility for the credit process in all of the Group's business units. This includes responsibility for developing credit classification and valuation models and for seeing that they are used by the local units in their day-to-day credit processing. The Credit Department is in charge of determining the utilization of portfolio limits for industries and countries and of the quarterly process of calculating the impairment of exposures. It also keeps track of the credit quality of the Group's loan portfolio by monitoring trends in unauthorized overdrafts and overdue payments, new approvals to weak customers and other factors. In addition, the Credit Department reports to the Group management and to business units on developments in the Group's credit risk. Finally, the department is in charge of providing management information about credits, of monitoring credit approvals in the business units, and of determining the Group's requirements relating to its credit systems and processes.
The CEO's office is in charge of analysing and monitoring strategic business risk and corporate governance.
-
Business units
Core risk dimensions such as market risk and liquidity risk are managed centrally. For credit risk, however, lending authority for specific customer segments and products has been delegated to the individual business units. The business units carry out the fundamental tasks required for optimal risk management. This includes updating the necessary registrations about customers that are used in risk management tools and models, as well as maintaining and following up on customer relationships.
Each business unit is responsible for preparing carefully drafted documentation before business transactions are undertaken and for properly recording the transactions. Each business unit is also required to update information on customer relations and other issues as may be necessary.
The business units must ensure that all risk exposures comply with specific risk instructions as well as the Group's other guidelines. Loan and credit approvals to retail customers and small business customers are given according to the lending authorities delegated to the individual branches.
Customer advisers are responsible for the basic credit assessment of customers. Their lending authority depends on customer classification, and they can approve credits up to certain amounts. Advisers must forward applications for credit facilities beyond their lending authority to the branch management, which may decide to submit applications to the Credit Department.
-
Board of Directors
-
Reporting
The Group has a reporting cycle to ensure that the relevant management bodies, including the Board of Directors, the Executive Board, and the Group Executive Management Team, are kept informed of, among other things, developments in risk measures, the credit portfolio, non-performing loans, market risk, strategic and operational risk.
The Board of Directors receives the principal risk reports (see Table 1-3) and the principal solvency requirement in the form of the Group's annual solvency handbook (ICAAP). As part of the quarterly evaluation of the Group's solvency requirement, the Board of Directors receives up-to-date information on any material changes in the Group's risk profile. On a monthly basis the Board of Directors receives a report on the Group's market and liquidity risk.
Table 1-3 Preferred risks: Monitoring, analysing, and reportingTable 1
Risk appetite
Strategic determination of risk-based limits, representing the maximum risk that the Group is
willing to assume in pursuit of business tagets an in accordance with its overall risk polisies.
Risk policy
Review of the Group's overall risk policy to determine whether revisions are required.
Models and parameters
Update on the use of risk models and risk parameters.
Quality of credit portfolio
Analysis of impairment charges and losses by business unit and portfolio break-downs by
category, size, business unit etc.
Table 2
Føroya Banki Group methodology Evaluation of the preferred risk and level of capital according to the FSA's 8+ approach.
Key figures for the credit portfolio An overview of credit-quality indicators, classifications and trends in lending volumes.
Market risk
Large exposures
Analysis of the Group's current equity, fixed income and currency positions and report on the
utilisation of Board approved limits since the preceding report.
An overview of exposures equal to or exceeding 10% of the Group total capital and the sum of these exposures including the precentage of the Group's total capital is represents.
Table 3
Liquity risk
Analysing and stress tests of the Group's current liquity
Market risk
Analysis of the Group's current equity, fixed income and currency positions and report on the
utilisation of Board approved limits since the preceding report.
-
Introduction
-
Capital Management
Føroya Banki is well capitalized with a high solvency ratio and excess cover relative to the statutory requirements. The Board of Directors is focused on maintaining the capital base necessary to fulfil its strategic goals and sustain the Bank's continued business development. Constant monitoring and valuation of the Group solvency ratio forms an integral part of the Group's capital management.
-
Framework of the Group's capital management
The basis of the Føroya Banki Group's capital management is the CRD IV requirements and the Internal Capital Adequacy Assessment Process (ICAAP), which consists of three pillars.
Pillar I contains a set of rules for a mathematical calculation of the Total capital and the risk weighted assets (RWA).
Pillar II describes the supervisory review and evaluation process and contains the framework for the internal capital adequacy assessment process.
Pillar III deals with market discipline and sets forth disclosure requirements for risk and capital management.
-
Pillar I
In accordance with the CRD IV requirements stipulated in the regulation (EU) No 575/2013 of the European parliament and of the Council of 26 June 2013, total RWA is calculated as the sum of RWA for credit, market, and operational risk. Total capital is calculated as the sum of common equity tier 1 (CET1) and additional tier 1 and tier 2 instruments.
Table 4 sets out the Bank's Solvency statement as of 31 December 2025, including the basis for calculating risk-weighted items, CET 1 capital, Core capital and Total capital.
- Pillar II
-
Framework of the Group's capital management
While Pillar I contains uniform rules for capturing a financial institution's risk and calculating the capital requirements in accordance with the CRD IV requirements, it does not necessarily capture all risk affecting individual institutions. Pillar II contains a framework for an Own Risk Solvency Assessment process based on the situation and characteristics of the individual institution. The underlying aim of the Pillar II process is to enhance the link between an institution's risk profile, its risk management systems and its capital. Institutions are expected to develop sound risk management processes that properly identify, measure, aggregate and monitor their risk.
Pillar II is underpinned by four principles:
Assessment of capital adequacy in relation to the institution's risk profile and capital strategy
Review and evaluation of the assessment and its ability to monitor and ensure compliance with its own requirement.
The expectation that the institution will operate above the Minimum Capital Requirement (MCR) and the ability of the Danish FSA to require a financial institution to maintain a capital buffer relative to the MCR.
FSA intervention at an early stage to prevent capital from falling below the minimum level required to support the risk profile or to require rapid remedial action if capital is not maintained or restored.
