Introduction
In an increasingly interconnected financial system, risk-based supervision (RBS) has become the dominant supervisory paradigm across banking, insurance, and capital markets. The principle of proportionality ensures that regulatory intensity is aligned with the risk profile, size, and systemic importance of financial institutions. This approach allows supervisors to allocate scarce resources efficiently, strengthen financial stability, and reduce unnecessary compliance burdens on smaller, non-systemic firms. Global standard setters—the Basel Committee on Banking Supervision (BCBS), the International Association of Insurance Supervisors (IAIS), and the International Organization of Securities Commissions (IOSCO)—all emphasize proportionality as a cornerstone of effective supervision. Yet the implementation of proportionality differs significantly across jurisdictions, reflecting variations in financial market structures, supervisory philosophies, and institutional maturity.
The Core of Proportional Supervision
At the heart of proportionality lies risk identification. Supervisors map systemic vulnerabilities, conduct stress tests, and apply entity-level scoring to assess exposure. Based on this assessment, supervisory intensity is calibrated. Larger, more complex, and interconnected institutions attract more frequent and intrusive scrutiny, while smaller or less risky entities benefit from lighter oversight. Flexibility in supervisory tools allows regulators to apply different mixes of on-site inspections, thematic reviews, and desk-based surveillance. Increasingly, this is supported by SupTech—supervisory technology that enables real-time data monitoring and early-warning risk detection.
Comparative Regulatory Practices
The following table compares how major regulators implement proportionality in their supervisory models, with emphasis on the methodologies, their application, and distinctive features.
| Jurisdiction / Regulator | Supervisory Model Name | Supervisory Approach | Use of Proportionality | Key Features |
| UK – PRA / FCA | Firm Categorization Framework | Structured RBS under PRA Rulebook and FCA Handbook | High | Entities grouped into tiers based on systemic importance with proportional capital, liquidity, and governance requirements |
| US – Federal Reserve, OCC, FDIC | Enhanced Prudential Standards (EPS) / CCAR | Dodd-Frank Act; CCAR stress testing | Medium-High | GSIBs face enhanced standards, while community banks follow simplified regimes |
| EU – ECB / ESAs | SREP (Supervisory Review & Evaluation Process) | Single Supervisory Mechanism under CRD/CRR | Strong | SREP scores drive supervisory depth, frequency, and capital add-ons |
| Ireland – CBI | PRISM (Probability Risk & Impact SysteM) | Explicit, impact-based RBS model | Very High | Entities classified from Low to High Impact with proportional supervisory plans |
| Australia – APRA | PAIRS / SOARS | Prudential standards with risk-based oversight | Moderate | Early-warning indicators and resilience-focused supervision |
| Singapore – MAS | Risk Assessment Framework for FIs | Forward-looking, preventive supervision | High | Strong emphasis on early intervention and proactive measures |
| Hong Kong – HKMA | Risk-Based Supervisory Framework | Basel-aligned RBS manual | Moderate | Oversight scaled according to systemic footprint |
| India – RBI / SEBI | SPARC (Supervisory Programme for Assessment of Risk & Capital) | Risk-based inspection framework | Growing emphasis | Supervisory resources aligned with risk scoring, though still evolving |
| Bahrain – CBB | CMORTALE (CBB Risk-Based Supervision Framework) | Basel-aligned RBS across banks, insurers, and markets | High | CMORTALE evaluates capital adequacy, management quality, operational risk, risk management, transparency, asset quality, liquidity, and earnings. Outcomes drive regulatory actions and strengthen governance (CBB Annual Report 2023) |
The CMORTALE Methodology in Bahrain
Bahrain’s Central Bank (CBB) provides a compelling case study of how proportionality can be embedded within a structured risk-based framework. The CBB applies the CMORTALE methodology across its supervisory activities, covering banks, insurers, and capital market licensees. CMORTALE examines capital adequacy, management quality, operational risk, risk management frameworks, transparency and disclosure, asset quality, liquidity, and earnings. The inspection outcomes are not merely descriptive but lead to regulatory actions that may include enhanced monitoring, remediation requirements, or sanctions. This ensures that licensees strengthen governance and risk management practices while the broader objectives of financial stability, consumer protection, and public confidence are maintained. (Published in the Annual Report , CBB)
Supervisory Tools in Practice
While the models differ, the supervisory toolkit also reflects proportionality. The table below summarizes common tools and their application across major jurisdictions.
| Jurisdiction / Regulator | Stress Testing | Thematic Reviews | Reporting Requirements | Other Tools |
| UK – PRA / FCA | Annual for systemic firms; simplified for smaller entities | Used extensively to review sectors such as liquidity or conduct | Tiered reporting proportional to firm size and complexity | Skilled person reviews; firm categorization |
| US – Federal Reserve, OCC, FDIC | CCAR for GSIBs; DFAST for mid-sized banks; exemptions for small banks | Sector-specific reviews in credit and cyber risk | Regulatory reporting scaled to size and risk | Enhanced prudential standards; resolution planning |
| EU – ECB / ESAs | EU-wide stress tests coordinated by EBA | Frequent thematic reviews across risk areas | Proportional data reporting; simplified for non-complex institutions | SREP-driven capital guidance |
| Ireland – CBI | Impact-driven, high frequency for “High Impact” firms | Used to assess systemic vulnerabilities | PRISM reporting tailored by impact classification | Supervisory engagement intensity aligned to impact |
| Australia – APRA | Applied selectively, often sectoral | Common in areas such as climate risk and governance | Prudential returns scaled by risk rating | Supervisory action escalated via SOARS framework |
| Singapore – MAS | Institution-specific stress testing | Regular sectoral reviews, especially cyber and AML | Risk-based reporting; lighter for low-risk firms | Forward-looking preventive interventions |
| Hong Kong – HKMA | Stress testing of systemic banks annually | Thematic reviews for priority risks | Simplified templates for small firms | Basel-aligned onsite inspections |
| India – RBI / SEBI | SPARC-based, varying intensity | Increasingly used in priority sectors | Reporting aligned to risk categories | Onsite/offsite blended supervision |
| Bahrain – CBB | Applied within CMORTALE framework, Supervisory Stress Test ( Banks), Review ICAAP submissions | Used to test resilience of banks and other licensees | Proportional reporting through CBB Rulebook | CMORTALE-based scoring leading to remedial actions |
Trends
Across global regulators, proportionality is now a defining feature of risk-based supervision. Systemically important institutions undergo frequent, deep inspections and regular stress testing, while smaller firms face lighter oversight. Supervisory technology is playing a growing role, with regulators deploying data analytics, AI-driven anomaly detection, and automated reporting portals to apply proportionality at scale.
Although global frameworks such as Basel and IAIS provide a common baseline, regulators adapt proportionality to local contexts. Ireland’s PRISM model applies explicit classifications, the EU’s SREP integrates risk scoring into capital add-ons, and Bahrain’s CMORTALE demonstrates a structured, multidimensional framework in the Gulf region.
Proportionality is not a dilution of regulation but a refinement of oversight intensity. It strengthens resilience, prevents crises, and promotes efficiency while easing compliance for low-risk firms. The future of supervision lies in increasingly data-driven proportionality, where technology allows regulators to monitor risk continuously and act dynamically in line with evolving threats.



Leave a Reply