Group internal control system

The responsibility for ensuring the adequacy and effectiveness of the Internal control system lies with the audit committee and the bank’s Board of Directors.

/media/fv5hjtic/shutterstock_2731726033_compressed.jpg?rxy=0.4614225437010247,0.6329186289429789&width=700&height=550&v=1dd023f2a1c35f0

The Internal control system (ICS), in accordance with act 243/2/07.07.2025, comprises a set of control mechanisms and procedures that continuously cover all of the bank’s activities and contribute to its effective and secure operation. The bank fosters a culture that encourages a positive approach to risk management and regulatory compliance across the group, supported by a robust and comprehensive internal control framework.
The ICS is adopted and implemented by the group’s subsidiaries in line with their size, internal organisation, scale and operational complexity.
In particular, the ICS ensures:

  • effective and efficient operations,
  • prudent conduct of business and consistent execution of business strategy through efficient use of available resources,
  • proper identification, measurement and mitigation of risks,
  • reliability of financial and non‑financial reporting, both internal and external,
  • sound administrative and accounting procedures, and
  • compliance with laws, regulations, supervisory requirements, as well as internal policies, procedures, rules and decisions of the bank.

To safeguard the ICS, the bank has assigned responsibilities to independent units (Risk management, Internal audit and Regulatory compliance) as well as to the Board committees. For the implementation of the ICS, the bank applies the “Three Lines Model”.

The first line of defence comprises business and operational units, which are responsible for managing risks within their day‑to‑day activities. They are also responsible for developing procedures and control points to effectively address risks, as well as for implementing corrective actions in cases where weaknesses in processes or controls are identified.

The second line of defence consists of functions established and staffed by Management to oversee risks, aiming to strengthen and/or monitor the procedures and controls developed by the first line of defence. These functions include the Risk Management and Regulatory Compliance Divisions.
The bank’s Risk Management Division adopts a structured approach to identifying and managing risks associated with its activities, contributing to business continuity and sustainable growth. The Division operates under a dedicated Regulation of Operation and established procedures. Its key objectives include identifying and assessing all types of risks that may affect the bank’s sound operation and sustainability, clearly defining roles and responsibilities in risk management, ensuring effective risk mitigation and prompt action where required, timely reporting and consultation with Management or Supervisory Authorities on critical issues, as well as continuous communication regarding emerging risks.
At the same time, the bank maintains a Regulatory Compliance Division, which monitors compliance not only with the letter but also with the spirit of laws, regulatory and supervisory rules and principles, codes of conduct and market best practices. Its objective is to minimise the risk of non‑compliance, financial loss or reputational damage arising from failure to adhere to applicable requirements. The Regulatory Compliance Division reports functionally to the Board of Directors through the Audit Committee, while administratively it reports to the Chief Executive Officer (CEO).

The Internal Audit Division, maintaining a high level of independence, provides objective assurance regarding the effectiveness of the Internal Control System, including how the first and second lines of defence fulfil their responsibilities.
The Internal Audit Division operates in accordance with the Code of Ethics and the International Professional Practices Framework (IPPF) of the Institute of Internal Auditors, Law 4706/2020, and the relevant decisions of the Hellenic Capital Market Commission, and is governed by its own Regulation of Operation.