Chapter 087: United Kingdom Reporting
Section 18: Regional Regulatory Reporting Tracks · Chapter 087 of 100
UK reporting combines prudential returns, financial information, Bank of England statistics and applicable FCA conduct collections. A group must determine its PRA entity scope, current UK definitions and submission channel rather than import an EU taxonomy unchanged. Large-exposure reporting below provides one practical example of that discipline.
1. Chapter opening
Maintain a UK obligation register by legal entity, return, rule basis, accounting basis, reference date, frequency, deadline and channel. PRA and FCA collections may use RegData; Bank of England statistical collections have their own instructions and channels. FINREP/COREP-derived terminology remains useful, but UK rule amendments and implementation dates can diverge from the EU. The final PRA PS1/26, published 20 January 2026, sets 1 January 2027 for the Basel 3.1 rules and reporting requirements; the internal model approach for market risk takes effect on 1 January 2028. As at 3 October 2026, these are future-effective UK changes, distinct from current requirements and EU CRR3. PRA PS1/26. Bank of England regulatory reporting.
2. Learning objectives
- Define large exposure and connected clients (control + economic dependency tests).
- Aggregate exposures across products (loans, derivatives, SFTs, OBS, trading).
- Apply limits (25% headline, tighter inter-G-SII) with exemption handling.
- Complete large-exposure reporting (top-20, detail templates) with lineage.
- Operate breach protocol (notify, remediate, report).
3. Business context
Concentration decisions must remain within applicable statutory and internal limits. Internal exceptions can alter a bank's tighter appetite only through authorised governance; they cannot override a legal cap. Measure pricing, credit risk and headroom before commitment. There is no evidenced universal two-to-three-times-exposure cost of a breach.
| Test | Catches |
|---|---|
| Control (majority/voting/dominant influence) | Subsidiaries, SPVs, management links |
| Economic dependency (50%+ revenue/funding, guarantees, same source) | Supply chains, common funding, cross-defaults |
4. Finance and accounting view
4.1 Aggregation worked (fictional, Tier 1 = 8bn, limit 2bn)
Fictional example, millions: Tier 1 =8,000 and assumed applicable limit =2,000. Product exposures are loans 900, converted commitment 300, derivatives 400, issued guarantees 500 and trading positions 200: total 2,300. Suppose eligible cash collateral reduces the relevant derivative exposure by 200 and eligible third-party protection substitutes 300 of client exposure to a separate guarantor; client exposure is 1,800 (22.5%). Preserve the substituted 300 as exposure to the guarantor and assess its connections and limits; it has not vanished. A connected client adds 400, producing 2,200 or 27.5%, a breach under these assumed rules. Escalate and notify under the actual requirement. Derivative and securities-financing exposure calculation methods follow current rules; the retired current exposure method is not a generic option.
4.2 Reporting and exemptions
Determine the applicable large-exposure reporting templates, counterparty populations and consolidation level from current UK instructions. Aggregate banking and trading exposures where required, with prescribed conversions, netting and mitigation. Assess exemptions exposure by exposure: sovereign treatment is not simply an investment-grade-rating test, CCP treatment depends on exposure type and rules, and intragroup treatment depends on applicable permission/conditions. A guarantor substitution transfers exposure to the guarantor rather than deleting it.
4.3 Deep dive: dependency discovery analytics and pre-deal checking architecture
Dependency discovery (finding economic connections before they default together): data analytics mining shared addresses/directors/phone numbers (entity-resolution engines with match scoring), payment-flow analysis (revenue dependency inferred from transaction concentrations), guarantee/collateral webs (shared security = shared fate), and market intelligence (sector maps, supply-chain databases, news monitoring for distress contagion). Relationship-manager questionnaires (dependency declarations at onboarding + annual refresh with liability for omission) complement analytics — human knowledge catches what data misses, data catches what humans hide. Unidentified-connection rate (found in review vs total) is the KPI; persistent misses trigger enhanced due-diligence regimes for originating teams. The entity-resolution technology has improved significantly — graph databases that map relationships between entities (common directors, shared addresses, ownership links, transaction flows) can identify connections that traditional tabular analysis misses. A shared director or address is an investigation signal, not automatic proof of control. Revenue, funding and guarantee dependence require the prescribed contagion analysis, including the ability to replace the source.
Pre-deal checking architecture (no limit-busting ticket books): real-time group-aggregation check at credit approval (all products, connected group, post-CRM, vs limit with headroom display), hard stops above limits (system blocks, internal-appetite exception workflow; statutory limits remain binding unless the applicable law or supervisor permits specific treatment), soft warnings in amber zone (enhanced monitoring auto-triggered), and pipeline aggregation (approved-but-undrawn pipeline counts against headroom — limits consumed at approval, not disbursement). Post-deal monitoring (daily batch aggregation with intraday triggers for trading desks) catches market-driven breaches (derivative MTM spikes) within hours. Breach analytics (frequency, duration, root cause) feed limit-calibration reviews — limits breached routinely are miscalibrated, not merely disobeyed. The pre-deal checking system must be the single point of aggregation for all products — a bank where lending, derivatives, guarantees, and trading each have separate limit systems with manual aggregation at the end is a bank that will discover limit breaches after they occur, not before. The pipeline aggregation is particularly important: an approved-but-undrawn commitment consumes the applicable regulatory converted exposure and any stricter internal allocation, rather than invariably its full nominal even though no cash has been advanced — limits must be tested at commitment, not disbursement.
5. Product and customer impact
Limit headroom rations large-ticket business — relationship teams need live group-aggregation views before pitching; connected-client discovery (dependency questionnaires at onboarding, refreshed periodically) prevents surprise aggregation; exemption-eligible structures (collateral, guarantees) are pitched as limit-efficient solutions. The practical impact on relationship management is significant: a relationship team pitching a 500m facility must first check the existing group exposure, model the incremental exposure including CCFs and CRM, then test against the limit with headroom — a process that takes minutes with a properly configured system and hours without one. Relationship teams that understand the limit framework can structure deals to maximise headroom: qualifying guarantees from non-connected third parties reduce net exposure, collateral arrangements that meet CRM eligibility criteria (cash, qualifying sovereign debt, bank guarantees) reduce post-CRM exposure, and structures must still satisfy connected-client aggregation; separate legal entities do not by themselves avoid grouping. The limit framework therefore creates a commercial incentive for sophisticated structuring — banks with strong limit management can offer larger facilities (within limits) by using CRM-efficient structures, while banks with weak limit management must either decline facilities or accept sub-optimal structures.
6. Regulatory and supervisory view
For the concentration example, apply the current PRA Large Exposures rules, connected-client definitions, exemptions and immediate notification duty. General 25% and large-exposure 10% Tier 1 benchmarks have specific exceptions and counterparty treatments; no risk committee can authorise a statutory breach. Use the regulator's actual remediation deadline, not an invented five-business-day standard. US single-counterparty credit limits and Indian concentration rules are separate regimes and cannot be described as the same control-only test or automatically identical limit.
7. Systems and data view
LE engine: group-linkage master (control + dependency flags), exposure aggregation across product systems (post-CCF/netting/CRM per rules), limit monitoring with pre-deal checking, template generator, breach workflow (notify, plan, track). Controls: linkage-change governance, limit-table versioning, pre-deal hard/soft stops, breach timers. The group-linkage master must be maintained with current dependency data — stale connections (where dependency has ceased) create false positives that waste investigation resource, while missed connections (where dependency has arisen) create false negatives that allow breaches to accumulate undetected. The linkage review cadence should be at least annual for all large exposures, with triggered reviews when market intelligence suggests changing dependency patterns.
8. End to end process
- Identify and link connected clients. 2. Aggregate all-product exposures with CRM. 3. Test against limits pre-deal and daily. 4. Report top exposures with lineage. 5. Breach: notify, freeze, remediate on deadline. 6. Review linkages and limits periodically.
9. Controls and risks
| Risk | Control | Evidence |
|---|---|---|
| Unidentified connections | Dependency questionnaires, data analytics | Linkage reviews |
| Silent limit creep | Pre-deal checking, daily monitoring | Check logs, breach reports |
| Exemption abuse | Eligibility evidence per exposure | Exemption files |
| Late breach notice | Breach timers with escalation | Notice records |
10. Practical examples
A — Dependency discovered late: supplier-derivative + lending + guarantees aggregate over limit only after dependency flagged in review — reduction via partial sale at a discount. Lesson: dependency discovery at onboarding, refreshed annually. B — Trading spike: underwriting position breaches intraday; settlement-day exclusion evidenced narrowly; limit restored on distribution — documented, reported, closed.
10.3 Worked example: dependency review (fictional, millions)
Supplier S has exposure 120 (loans 70+derivatives 30+guarantees 20) and derives 65% of revenue from Client C, whose exposure is 1,800. The revenue link triggers investigation of replaceability and contagion; shared premises or directors are signals, not automatic proof of control. Assume the applicable analysis establishes economic dependency and requires grouping. Total exposure 1,920 divided by Tier 1 capital 8,000 is 24%, below the assumed 25% limit 2,000, leaving 80 headroom.
Monitor the group and future commitments. If C deteriorates, review S’s exposure, collateral eligibility and contractual remediation rights. The bank cannot simply accelerate amortisation without a valid right, and collateral does not guarantee zero loss. Preserve exposure amounts before and after mitigation and reassess the connections with evidence.
11. Diagrams
Figure 1. UK reporting preparation.
Figure 2. UK reporting purposes.
Figure 3. UK rule-change control.
12. Tables
Table 1 — Worked aggregation (fictional m, Tier 1 8,000)
| Leg | Gross | CRM | Net |
|---|---|---|---|
| Loans | 900 | — | 900 |
| Revolver EAD | 300 | — | 300 |
| Derivatives | 400 | −200 collateral | 200 |
| Guarantees | 500 | −300 qualifying | 200 |
| Trading | 200 | — | 200 |
| Client total | 2,300 | −500 | 1,800 (22.5%) |
Table 2 — Limit map (headline, verify)
| Rule | Level |
|---|---|
| Large-exposure definition | ≥10% Tier 1 |
| General limit | 25% Tier 1 |
| G-SII inter limit | 15% (headline) |
| Breach notice | Immediately under the applicable duty; do not invent a grace period |
13. Illustrative banking case study
The group nobody grouped (fictional). Several desks lend to legally distinct entities that share a material funding dependency. Internal desk limits pass while the connected-group exposure breaches the bank's applicable limit. The repair improves group linkage, cross-product calculation and pre-deal headroom checks, including guarantor substitution and exposures that change with market prices.
14. BA, developer, tester and operations guidance
- BA: Specify linkage rules (control + dependency), aggregation logic, exemption criteria and breach workflows.
- Developer: Master group linkages; aggregate cross-product live; enforce pre-deal checks; timer breaches.
- Tester: Dependency-discovery scenarios; limit-boundary aggregations; exemption allow/block; breach notification paths.
- Operations: Refresh linkages periodically; monitor headroom daily for top names.
15. Common mistakes
- Desk-level limits without group aggregation.
- Missing economic-dependency connections.
- Exemptions claimed without eligibility evidence.
- Breach notification delayed (follow the immediate applicable duty).
- Trading-book exclusions applied broadly without evidence.
16. Key takeaways
- Aggregate everything (all products, connected group) vs 25% of Tier 1.
- Both connection tests (control + economic) need data and refresh.
- Pre-deal checking prevents breaches; breach protocol (notify, freeze, remediate) contains them.
- Exemptions need per-exposure evidence.
- Maintain exposure calculations, connected-client evidence, exemption eligibility and immediate notification capability under the applicable UK rules.
17. References and verification notes
- Bank of England regulatory reporting: PRA/FCA cooperation and collection arrangements.
- PRA Rulebook: current Large Exposures and Regulatory Reporting provisions. Thresholds and examples above require the specific rule and scope; they are not a universal UK return specification.
- Figures are fictional training illustrations.