ECB Fines Belgium's Belfius Bank €6.94 Million for IRB Model Implementation Delays
 european central bank building sign in frankfurt germany, Tobias Arhelger / Shutterstock.com.

The European Central Bank has imposed a €6,940,000 administrative penalty on Belfius Banque SA, the Belgian state-owned lender, after determining that the bank failed to deploy updated internal-rating-based credit risk models within the timeframe required under ECB supervisory requirements. The decision, dated 6 June 2025 and announced publicly on 18 July 2025, classified the severity of the breach as severe, placing it in the highest category of supervisory concern applied to such model governance failures.

The breach period ran from 27 January 2024 to 17 March 2025, a span of more than thirteen months during which Belfius did not have the revised internal models in production as required by its regulatory obligations. Internal-rating-based models sit at the heart of a bank's approach to calculating risk-weighted assets, and delays in their deployment can materially affect the accuracy of capital ratio reporting and the granularity of credit risk measurement across large and complex loan portfolios.

THE NATURE OF THE IRB MODEL BREACH

The IRB approach allows banks to use their own credit risk models, subject to regulatory approval and validation, to determine the capital they must hold against different categories of lending exposure. When a bank receives approval for updated models, it is bound to implement them on the schedule agreed with the supervisor. Belfius failed to meet that obligation across a period spanning more than a year, and the ECB's supervisory assessment found that the resulting gap in model deployment constituted a severe regulatory breach rather than a minor or technical procedural lapse with limited prudential consequence.

To manage the consequences of the delay, Belfius applied regulatory capital corrections throughout 2024 to adjust for the gap created by the postponed model deployment. Those corrections were intended to ensure that the bank's reported capital position remained prudent despite the absence of the updated models, but they did not eliminate the underlying supervisory concern about the institution's failure to execute on its approved implementation plan and the governance and operational processes that allowed such an extended delay to occur.

The ECB did not disclose the specific technical or operational cause of the failure to meet the implementation deadline. IT programme delays and integration challenges across risk systems, data infrastructure and reporting pipelines are common causes of such breaches at large financial institutions. The bank did not publicly dispute the finding, and the completion of the model deployment in March 2025 brought the breach period to a formal close ahead of the ECB's public announcement.

PENALTY SIZE AND SUPERVISORY SIGNAL

The €6.94 million fine is calibrated to reflect the duration of the breach period, the ECB's severe severity classification and any factors taken into account under the Single Supervisory Mechanism framework for imposing administrative sanctions on significant institutions. The ECB has authority to penalise significant institutions for breaches of directly applicable European Union law, and the quantum of each penalty considers the nature, gravity and duration of the infringement as well as the degree of responsibility attributable to the institution.

Belfius is classified as a significant institution under the SSM and is therefore subject to direct ECB supervision. The announcement adds to a growing body of ECB enforcement decisions that demonstrate the supervisor's willingness to impose material financial sanctions for model governance failures, a signal that implementation timelines are treated as binding regulatory commitments. For the broader supervised community of European banks, the case reinforces the importance of robust programme management and escalation processes when complex model deployments encounter technical difficulties.