Navigation and service of the Landwirtschaftlichen Rentenbank

jump directly to:

Non-financial risks

Definition

Non-financial risks comprise operational risks and strategic risks.

Operational risks arise from inadequate or failed systems and processes, from human misconduct or from external events. They also include legal risks, compliance risks, outsourcing risks, IT risks, information security risks, personnel risks, model risks, project risks and event-related or environmental risks.

Strategic risks comprise the risk sub-types business/strategic risks, reputational risks and pension risks.

Business/strategic risk describes the risk that Rentenbank’s business-strategic objectives are not achieved as a result of its business policy positioning or adverse framework conditions, and that this has a negative effect on its net assets and earnings position.

Reputational risk is the risk of losses arising from a deterioration in the way Rentenbank is perceived by relevant internal and external stakeholders, resulting in adverse economic effects or a loss of confidence in Rentenbank.
Pension risk refers to the risk of pension provisions being measured inadequately.

Risk assessment and management

From an economic perspective, non-financial risks are quantified using a simulation model (value at risk). The data basis consists of the risk estimates from self-assessments carried out by process owners, the risk analyses of other organisational units and the historical loss events arising from operational risks. The risk model allows a detailed analysis of individual risks and risk drivers as well as the simulation of scenarios.

All loss events and near misses at Rentenbank are recorded decentrally in a loss event database by operational risk officers. Risk Controlling analyses and aggregates the loss events and further develops the methodology of the instrumentarium.
In the self-assessments, material operational risk scenarios in individual business processes are analysed and assessed on a risk-oriented basis. Risk-reducing measures are also determined in this context.

The Risk Controlling Department centrally aggregates and analyses all non-financial risks. It is responsible for the use of relevant instruments and the development of methods for the identification, assessment, management and communication of risks. Non-financial risks are managed by the respective organisational units.

The Cyber Security & Non-Financial Risk Department monitors information security risks, third-party service provider risks and risks relating to business continuity management. To this end, processes and methods for the identification, assessment, management and monitoring of risks have been established.

The Legal & Committees Department manages and monitors legal risk. It informs the Management Board, both on an ad hoc basis and regularly in the form of half-yearly reports, about pending or threatened legal disputes. Rentenbank reduces legal risks arising from the conclusion of transactions by using largely standardised contracts. For this purpose, the Legal Department is involved at an early stage in decision-making, and material projects must be coordinated with the Legal & Committees division. Legal disputes are recorded in the loss event database without delay. A designated risk indicator is monitored for the early identification of risk.

Regulatory risk, as a component of compliance risk, is managed by the Compliance function and the ART through the active monitoring of regulatory projects and other legislative initiatives affecting Rentenbank, as well as through the identification of potential consequences for Rentenbank.

On the basis of a materiality and risk analysis, compliance-related risks are identified and it is analysed whether general and institution-specific requirements for an effective organisation are being met. The same applies to risks arising from money laundering, terrorist financing and criminal offences that could endanger Rentenbank’s assets. Organisational measures are derived from the risks identified in order to optimise risk prevention.

In particular, compliance with due diligence obligations and the identification of counterparties (know-your-customer principle) are important elements of anti-money laundering prevention. The necessary procedures and processes for this purpose have been established, and any suspicious cases are reported without delay by the Anti-Money Laundering Officer to the Financial Intelligence Unit (FIU). In 2025, there were no suspicious cases relating to money laundering or terrorist financing, nor were any other criminal offences identified.

The risks associated with outsourcing and other external sourcing of IT services are captured under operational risks. Rentenbank has established the function of a Central Outsourcing Officer, who is supported by the Central Outsourcing Management Department. Outsourcing monitoring is carried out on a decentralised basis. Central outsourcing management also includes the management and monitoring of the outsourcing portfolio. On the basis of a standardized risk analysis, a distinction is made between material and non-material outsourcing arrangements. Special requirements apply to material outsourcing arrangements, in particular with regard to contracts, management and monitoring, and reporting. Third-party service provider risks are integrated into operational risk management and presented transparently.

To protect data, systems, networks and the site, Rentenbank has implemented an Information Security Management System (ISMS). The Cyber Security & Non-Financial Risk Department monitors compliance with the requirements set out in the ISMS regarding the confidentiality, availability and integrity of information. Employees receive regular information security training and are made aware of risks through various channels. Information security risks are integrated into operational risk management and presented transparently. This also includes risks arising from threats related to cyber risks. To this end, penetration tests are carried out regularly by external service providers.

For emergency or crisis situations, Rentenbank’s Business Continuity Management Department has established preventive and reactive measures for time-critical business processes. Emergency manuals, business continuity plans and recovery plans govern the handling of operational disruptions. Rentenbank reviews and monitors the effectiveness of these plans on the basis of test and exercise plans. Rentenbank reviews and monitors the effectiveness of these plans on the basis of test and exercise plans.

The Code of Conduct and professional external corporate communications contribute to mitigating reputational risks.

For the measurement of pension provisions, parameters such as interest rates, inflation and life expectancy are used on the basis of an external actuarial report. The related interest rate risks are taken into account within interest rate risk in the banking book (IRRBB).

Non-financial risks are limited within economic risk-bearing capacity, separately for operational risks and strategic risks.

The loss events identified during the reporting year, the findings from the self-assessments, the risk analyses of the organisational units and the monitoring of early warning indicators do not indicate any risks that could endanger Rentenbank’s continued existence.