Source: OJ L, 2025/415, 24.3.2025

Current language: EN

Article 8 Internal governance arrangements under the stress testing exercises


Summary What does Article 8 of the RTS on stress test programmes say?

This article establishes the governance and organisational requirements surrounding the stress testing programme for issuers of asset-referenced tokens or e-money tokens.

Building directly on the stress testing framework introduced in Articles 5 to 7, it places ultimate ownership of the programme with the management body, which is responsible for both adopting and implementing it.

Beyond accountability, the article sets out how the stress testing programme must be embedded into the issuer's broader operations — integrated into the risk management framework, aligned with internal policies, supported by effective communication across the organisation, and used as a genuine input into strategic and business planning decisions.

Important points:

  • Ensure your stress testing programme is adopted and implemented by the management body, which bears full responsibility for it.
  • The programme must be integrated into the issuer's risk management framework and used to inform risk appetite, own funds, liquidity planning, and strategic decisions.
  • All elements of the stress testing programme must be appropriately documented and regularly updated within internal policies and procedures.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The stress testing programme of the issuer of asset-referenced tokens or e-money tokens shall be adopted by its management body, which shall be responsible for its implementation in accordance with this Regulation and with Regulation (EU) 2023/1114.

    1. The stress testing programme shall include an assessment as to whether the members of the management body collectively have sufficient knowledge, skills and experience to perform all the following:

      1. fully understand the impact of stress events on the overall risk profile of the issuer;

      2. ensure that clear responsibilities and sufficient resources such as skilled human resources and information technology systems, have been assigned and allocated for the execution of the stress tests;

      3. actively engage in discussions with staff involved in stress testing and with persons to whom tasks related to stress testing are outsourced;

      4. challenge key modelling assumptions, the scenario selection and the assumptions underlying the stress tests in general;

      5. decide on the necessary management actions and discuss them with the competent authorities.

    1. The stress testing programme shall be designed in a way which allows stress tests to be executed in accordance with the relevant internal policies and procedures of the issuer.

    1. Issuers of asset-referenced tokens or e-money tokens shall ensure that all elements of the stress testing programme, including its assessment, are appropriately documented and regularly updated, where relevant, in the internal policies and procedures.

    1. Issuers of asset-referenced tokens or e-money tokens shall ensure that the stress testing programme design foresees an effective communication across business lines and management levels, with a view to raising awareness, improving risk culture and instigating discussions on existing and potential risks as well as on possible management actions.

    1. The stress testing programme shall be designed as an integral part of an issuer’s risk management framework. Stress tests shall be designed to support different business decisions and processes as well as strategic planning. The strategic decisions shall take into account the shortcomings, limitations and vulnerabilities identified during stress testing.

    1. The outputs of stress tests shall be used as inputs to the process of establishing an issuer’s risk appetite and limits and shall act as a planning tool to determine the effectiveness of new and existing business strategies and assess the possible impact on own funds and liquidity.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod