Foroya BankiOMXCOP: FOBANK

Risk Management Report 2025

· Issued by Foroya Banki

2025

Ris

Management

Report



Faroya Banki

Board of Directors

and Executive Board

Group objectives and Risk Management Report

To keep our shareholders and other stakeholders informed

of the group's risk and capital management policies,

including risk management methodologies and practices,

both short and long term.

Contents
  1. Introduction 3
  2. Organisation 4
    1. Introduction. 4

    2. Risk policies and limits 5

    3. Risk organization 5

      1. Board of Directors 7

      2. Executive Board 7

      3. Staff departments 7

      4. Business units 8

    4. Reporting 8

  3. Capital Management 10
    1. Framework of the Group's capital management 10

    2. Pillar I 10

    3. Pillar II 10

      1. Solvency requirement 11

      2. The methodology 12

      3. Group solvency requirement 12

    4. Combined buffer requirement 13

    5. Excess capital 14

    6. Leverage ratio 15

  4. Credit Risk 16
    1. Definition 16

    2. Policy 16

    3. Credit process 16

    4. Credit risk classification 17

    5. Credit exposure 17

      1. Credit exposure, quality, and concentration 18

    6. Risk mitigation 20

    7. Monitoring and portfolio management 22

      1. Credit risk management 22

    8. Impairment/Losses 23

    9. The Supervisory Diamond 24

  5. Market Risk 25
    1. Organisation 25

    2. Definition 25

    3. Policy and responsibility 25

    4. Control and management 26

    5. Market risk 26

    6. Interest rate risk 26

    7. Exchange rate risk 27

    8. Equity market risk 27

  6. Liquidity Risk 28
    1. Definition 28

    2. Control and management 28

      1. Operational liquidity risk 28

      2. Liquidity stress testing 28

      3. Twelve-month liquidity 28

      4. Structural liquidity risk 28

      5. Funding sources 29

    3. Collateral provided by the Group 29

  7. Operational Risk 30
    1. Definition 30

    2. Policy 30

    3. Measurement and control 30

    4. Long-term goals in operational

      risk management 30

  8. Insurance Risk 31
    1. Capital requirements 31

    2. Trygd non-life insurance 31

    3. NordikLív-Life insurance… 34

  1. Introduction

    The purpose of Føroya Banki's Risk Management Report is to ensure transparency in the Føroya Banki Group and to make available information on how the Group manages the risks it encounters.

    Føroya Banki's Risk Management Report is published annually on the Group's website: https://www.foroyabanki.com/rmr, simultaneously with the release of the Group's Annual Report 2025. The Risk Management Report is a separate unaudited document. There are no audit requirements for the Risk Management Report, but much of the information in the Risk Management Report will also be provided in the audited Annual Report 2025.

  2. Organisation
    1. Introduction

      Understanding and ensuring transparency in risk taking are key elements of the Føroya Banki Group's business strategy. The Group's ambition is to set high standards for risk management. Our risk organization supports this ambition, and it has developed in-depth risk management expertise.

      The Board of Directors sets out the overall risk policies for all types of material risk while the Chief Executive Officer (CEO) is responsible for the day-to-day management of the Group, including implementation of the risk policies and risk management.

      The Executive Board consists of Group CEO, Turið F. Arge. At the chief operational level, the Group is divided into two main business units:

      • Corporate Banking operations In the Faroe Islands and Greenland, headed by Brian Smedemark

      • Personal Banking operations in the Faroe Islands and Greenland, headed by Silja á Borg Færø

        Figure 1

        The business units are supported by the following units:

      • Credit Services, Finance, Accounting, Treasury, IT, Marketing, Markets and HR. The Group's risk officer and compliance officer are members of CEO's office.

      The Board of Directors and the Group Executive Management Team have established various sub-committees, including an Audit Committee, a Risk Committee, a Credit Committee, a Remuneration Committee, and a Nomination Committee.

      The Group allocates resources to manage and monitor risk and to ensure on-going compliance with approved risk limits. The Group has a reporting cycle to ensure that the relevant management bodies, including the Board of Directors, the Chief Executive Officer, and the Group Executive Management Team, are kept informed of relevant developments in risk measures.

      The Group's risk policies as well as its limits and organizational framework for risk management are described in greater detail in the following sections.

    2. Risk policies and limits

      The Board of Directors sets out the overall risk policies and limits for all material risk types. The Board also determines the general principles for managing and monitoring risk, and it reviews the risk policies and limits annually. The Group uses risk appetite as a strategic concept to determine its risk-based limits. Risk appetite represents the maximum risk the Group is willing to assume in pursuit of its business targets. The risk appetite framework offers an overview of various risk dimensions and enables the Group to manage risk measurement across these dimensions in accordance with its overall risk policies.

      The framework is based on an analysis of the current risk profiles of the Group and its major business units. It includes setting explicit targets, limits, and contingency plans in accordance with the risk policies. It also includes monitoring of risk levels.

      Key risk elements are identified on an on-going basis in a dynamic process driven by new products, procedures, risk measurement applications as well as economic developments. The Group conducts risk management at the customer and industry levels as well as based on geographical location and collateral type. It takes a comprehensive approach to the core risk dimensions:

      • Credit risk

      • Market risk

      • Liquidity risk

      • Operational risk

      Other risk dimensions are incorporated at the Group and business unit levels where appropriate. They include insurance and concentration risk, financial strength, and earnings robustness. Specific risk instructions for the main business units are prepared based on the overall risk policies and limits. These instructions are used to prepare business procedures and reconciliation and control procedures for the relevant units and for system development purposes.

    3. Risk organization

      Føroya Banki's "Rules of procedure" for the Board of Directors and the "Board of Directors' Instructions to the Executive Board" specifies the responsibilities of the Board of Directors and the Executive Board and the division of responsibilities between them. This two-tier management structure has been developed in accordance with Faroese and Danish legislation, and the "Rules of procedure" and "Board of Directors' Instructions to the Executive Board" are key documents in the Group's management structure, including the organization of risk management and authorizations.

      The Board of Directors lays down overall policies, while the Executive Board oversees the Group's day-to-day management and reports to the Board of Directors. None of the Group's executive managers serve on the Board of Directors of the parent company. The risk and capital management functions are separate from the credit assessment and credit-granting functions, as shown in figure 2.

      Figure 2

      The Group's management structure also reflects the statutory requirements governing listed Faroese companies in general and financial services institutions in particular. The Føroya Banki Group applies to comply or explain principle set out in the recommendations issued by the Committee of Corporate Governance. These recommendations apply to companies listed on NASDAQ Copenhagen.

      The Audit Committee examines accounting, auditing, and security issues that the Board of Directors, the Audit Committee, the internal auditor, or the external auditors believe deserve attention. The Risk Committee reviews the internal control and risk management system.

      The Audit Committee consists of Árni Tór Rasmussen, Chair of the Committee, Kristian Reinert Davidsen, member of the board and Marjun Hanusardóttir, member of the board.

      The Risk Committee consists of Tom Ahrenst, Chair of the Committee, Birgir Durhuus, Chair of the board, Annfinn Vitalis Hansen, vice chair of the board.

      The Boards Credit Committee consists of Tom Ahrenst, Chair of the Committee and the CEO, the COO, the head of the Credit department.

      The Executive Board has assembled the Group Executive Management Team and established a Credit Committee

      i.e. a risk-orientated sub-committee.

      1. Board of Directors

        The Board of Directors must ensure that the Group is appropriately organized. As part of this duty, it appoints the members of the Executive Board and the Group's Chief Internal Auditor.

        The largest credit facilities are submitted to the Board of Directors for approval, and the Board defines overall limits for market risk and liquidity risk. Regular reporting enables the Board of Directors to monitor whether the overall risk policies and systems are being complied with and whether they meet the Group's needs. In addition, the Board of Directors reviews reports analysing the Group's portfolio, particularly information about industry concentrations, large exposures, and impaired exposures.

        Internal Audit examines accounting, auditing, and security issues. These are issues that the Board of Directors or the external auditors believe deserve day-to-day attention. Internal Audit also reviews the internal control and risk management systems.

      2. Executive Board

        The Executive Board is responsible for the day-to-day management of the Group as stated in the "Rules of procedure" for the Board of Directors and the "Board of Directors' Instructions to the Executive Board".

        The Executive Board sets forth specific risk instructions and supervises the Group's risk management practices. It reports to the Board of Directors on the Group's risk exposures and approves material business transactions, including credit applications up to a defined limit.

        The Group has also organized various sub-committees/functions for specific risk management areas such as asset and liability management and the management of risk parameters and models affecting the Group's capital and risk-weighted assets. The sub-committees consist mostly of members of the management team.

        The sub-committees are:

        Committee

        Function

        Credit Committee

        Overview of credit risk. Review of applications. Implementing Creditpolicies approved of the Board of Directors.

        Market Committee

        Overview of the Groups market risk. Analysing, planning and

        recommendation.

        Risk, Solvency and Liquidity Committee

        Overview of the Groups main risks. Analysing, planning and

        recommendation.

        Rating Committee

        Overview of the Groups statistic ratingmodel and AML model

        IT Committee

        Overview of the Groups IT-risks. Analysing, planning and

        recommendation.

      3. Staff departments

        The Group's overall risk issues including credit, market, liquidity, and operational risks are monitored by the Group's Risk Officer, in co-operation with managers of business units and subsidiaries, reporting directly to the Executive Board.

        The Finance department oversees the Group's financial reporting, budgeting, liquidity, and capital structure. It also has overall responsibility for the Group's compliance with the Capital Requirements Directive and related legislation and for the internal capital adequacy assessment process.

        The Group has established a functional separation between units that enter into business transactions with customers or otherwise expose the Group to risk on the one hand and units in charge of overall risk management on the other.

        The Group's Risk Management is carried out by the Group's Risk Officer which is a part of the CEO's Office with reporting rights and obligations to the Executive Board and reporting rights to the Board of Directors in risk-related matters. Risk Management has overall responsibility for monitoring the Group's risk portfolio and reporting on overall risk measures. In addition, Risk Management is responsible for the implementation of risk models and risk analysis and for providing support to the Risk Committee.

        The Credit Department has the overall responsibility for the credit process in all of the Group's business units. This includes responsibility for developing credit classification and valuation models and for seeing that they are used by the local units in their day-to-day credit processing. The Credit Department is in charge of determining the utilization of portfolio limits for industries and countries and of the quarterly process of calculating the impairment of exposures. It also keeps track of the credit quality of the Group's loan portfolio by monitoring trends in unauthorized overdrafts and overdue payments, new approvals to weak customers and other factors. In addition, the Credit Department reports to the Group management and to business units on developments in the Group's credit risk. Finally, the department is in charge of providing management information about credits, of monitoring credit approvals in the business units, and of determining the Group's requirements relating to its credit systems and processes.

        The CEO's office is in charge of analysing and monitoring strategic business risk and corporate governance.

      4. Business units

        Core risk dimensions such as market risk and liquidity risk are managed centrally. For credit risk, however, lending authority for specific customer segments and products has been delegated to the individual business units. The business units carry out the fundamental tasks required for optimal risk management. This includes updating the necessary registrations about customers that are used in risk management tools and models, as well as maintaining and following up on customer relationships.

        Each business unit is responsible for preparing carefully drafted documentation before business transactions are undertaken and for properly recording the transactions. Each business unit is also required to update information on customer relations and other issues as may be necessary.

        The business units must ensure that all risk exposures comply with specific risk instructions as well as the Group's other guidelines. Loan and credit approvals to retail customers and small business customers are given according to the lending authorities delegated to the individual branches.

        Customer advisers are responsible for the basic credit assessment of customers. Their lending authority depends on customer classification, and they can approve credits up to certain amounts. Advisers must forward applications for credit facilities beyond their lending authority to the branch management, which may decide to submit applications to the Credit Department.

    4. Reporting

      The Group has a reporting cycle to ensure that the relevant management bodies, including the Board of Directors, the Executive Board, and the Group Executive Management Team, are kept informed of, among other things, developments in risk measures, the credit portfolio, non-performing loans, market risk, strategic and operational risk.

      The Board of Directors receives the principal risk reports (see Table 1-3) and the principal solvency requirement in the form of the Group's annual solvency handbook (ICAAP). As part of the quarterly evaluation of the Group's solvency requirement, the Board of Directors receives up-to-date information on any material changes in the Group's risk profile. On a monthly basis the Board of Directors receives a report on the Group's market and liquidity risk.

      Table 1-3 Preferred risks: Monitoring, analysing, and reporting

      Table 1

      Risk appetite

      Strategic determination of risk-based limits, representing the maximum risk that the Group is

      willing to assume in pursuit of business tagets an in accordance with its overall risk polisies.

      Risk policy

      Review of the Group's overall risk policy to determine whether revisions are required.

      Models and parameters

      Update on the use of risk models and risk parameters.

      Quality of credit portfolio

      Analysis of impairment charges and losses by business unit and portfolio break-downs by

      category, size, business unit etc.

      Table 2

      Føroya Banki Group methodology Evaluation of the preferred risk and level of capital according to the FSA's 8+ approach.

      Key figures for the credit portfolio An overview of credit-quality indicators, classifications and trends in lending volumes.

      Market risk

      Large exposures

      Analysis of the Group's current equity, fixed income and currency positions and report on the

      utilisation of Board approved limits since the preceding report.

      An overview of exposures equal to or exceeding 10% of the Group total capital and the sum of these exposures including the precentage of the Group's total capital is represents.

      Table 3

      Liquity risk

      Analysing and stress tests of the Group's current liquity

      Market risk

      Analysis of the Group's current equity, fixed income and currency positions and report on the

      utilisation of Board approved limits since the preceding report.

  3. Capital Management

    Føroya Banki is well capitalized with a high solvency ratio and excess cover relative to the statutory requirements. The Board of Directors is focused on maintaining the capital base necessary to fulfil its strategic goals and sustain the Bank's continued business development. Constant monitoring and valuation of the Group solvency ratio forms an integral part of the Group's capital management.

    1. Framework of the Group's capital management

      The basis of the Føroya Banki Group's capital management is the CRD IV requirements and the Internal Capital Adequacy Assessment Process (ICAAP), which consists of three pillars.

      • Pillar I contains a set of rules for a mathematical calculation of the Total capital and the risk weighted assets (RWA).

      • Pillar II describes the supervisory review and evaluation process and contains the framework for the internal capital adequacy assessment process.

      • Pillar III deals with market discipline and sets forth disclosure requirements for risk and capital management.

    2. Pillar I

      In accordance with the CRD IV requirements stipulated in the regulation (EU) No 575/2013 of the European parliament and of the Council of 26 June 2013, total RWA is calculated as the sum of RWA for credit, market, and operational risk. Total capital is calculated as the sum of common equity tier 1 (CET1) and additional tier 1 and tier 2 instruments.

      Table 4 sets out the Bank's Solvency statement as of 31 December 2025, including the basis for calculating risk-weighted items, CET 1 capital, Core capital and Total capital.

    3. Pillar II

While Pillar I contains uniform rules for capturing a financial institution's risk and calculating the capital requirements in accordance with the CRD IV requirements, it does not necessarily capture all risk affecting individual institutions. Pillar II contains a framework for an Own Risk Solvency Assessment process based on the situation and characteristics of the individual institution. The underlying aim of the Pillar II process is to enhance the link between an institution's risk profile, its risk management systems and its capital. Institutions are expected to develop sound risk management processes that properly identify, measure, aggregate and monitor their risk.

Pillar II is underpinned by four principles:

  • Assessment of capital adequacy in relation to the institution's risk profile and capital strategy

  • Review and evaluation of the assessment and its ability to monitor and ensure compliance with its own requirement.

  • The expectation that the institution will operate above the Minimum Capital Requirement (MCR) and the ability of the Danish FSA to require a financial institution to maintain a capital buffer relative to the MCR.

  • FSA intervention at an early stage to prevent capital from falling below the minimum level required to support the risk profile or to require rapid remedial action if capital is not maintained or restored.

Earlier from Foroya Banki

All Foroya Banki news releases