EPM for Banking and Insurance: Why Finance Transformation Looks Different When Regulation Is Non-Negotiable

In most industries, a finance transformation project starts with a question about speed: how do we close faster, forecast more accurately, and spend less time on manual reconciliation?

In banking and insurance, that question comes second.

The first question is always: how do we ensure that the same data powering our management decisions also satisfies our regulators — without running two parallel finance functions to serve both audiences?

That distinction changes everything about how EPM is designed, implemented, and governed in financial services. The platform decisions, the data architecture, the governance model, the integration with risk functions — all of it looks materially different when regulatory reporting is not a downstream output of financial planning but an integrated requirement running through the centre of it.

Most EPM implementations ignore this. They import best practices from manufacturing or retail, apply them to a bank or insurer, and discover six months later that the model cannot simultaneously produce a management P&L, a Solvency II QRT, a Basel IV capital plan, and a stress test submission — let alone do all of them from the same underlying data, at the speed regulators require.

This post examines what EPM for banking and insurance actually requires — and why the finance functions getting it right are building something fundamentally different from a faster version of what they had before.


Key Takeaways
  • According to Empyrean's 2025 Bank Risk and Performance Survey, 35% of financial institutions reported budgeting and planning tools as their biggest FP&A challenge — making it the single most commonly cited pain point across the banking sector
  • 74% of banking institutions collaborate on shared assumptions between ALM and financial planning — but only 1 in 3 have the tools to fully integrate those processes, according to the same survey
  • KPMG's 2026 stress test preparation guidance states that banks should use the second half of 2026 to resolve outstanding BCBS 239 data quality issues and align stress test starting point data with COREP and FINREP standards — ahead of the 2027 EBA/ECB stress test cycle
  • IFRS 17, which replaced IFRS 4 for insurance contracts in January 2023, has introduced significant changes to liability valuation — requiring insurers to maintain parallel calculation environments that can reconcile Solvency II and IFRS 17 figures simultaneously
  • The organisations closing the regulatory-management reporting gap are not those with the most technology — they are those that resolved the data architecture problem before selecting a platform

Why Banking and Insurance Finance Is a Different Problem

Every finance function deals with two reporting requirements: management reporting (what does the business need to know to make decisions?) and regulatory reporting (what do supervisors need to see to assess risk and compliance?). In most industries, these two requirements are largely aligned — a clean management P&L is also the foundation for statutory reporting.

In banking and insurance, they are not aligned. They are structurally different frameworks built on different valuation bases, different aggregation hierarchies, different timing requirements, and different data definitions — all of which need to reconcile with each other and ultimately trace back to the same underlying source data.

A regional bank running its annual planning cycle needs to produce: a management budget by business line, a regulatory capital plan under Basel IV requirements, a stress test submission for supervisory review, a liquidity coverage ratio projection, and a net stable funding ratio forecast. These are not variations of the same output. They are different analytical frameworks that share data but apply it differently.

An insurance company closing its annual accounts needs to simultaneously produce IFRS 17 financial statements — based on probability-weighted estimates of future cash flows with explicit risk adjustment — and Solvency II regulatory returns based on market-consistent valuation of technical provisions. EIOPA's 2024 implementation study found that IFRS 17 insurance liabilities were on average 2.5% lower than corresponding Solvency II technical provisions, and 8.6% lower when the contractual service margin is included. Reconciling that difference at group level, across multiple legal entities, multiple lines of business, and multiple reporting currencies, is not a spreadsheet exercise.

The EPM question in financial services is not "how do we plan faster?" It is "how do we build a single data and model architecture that can serve all of these requirements simultaneously — without duplicating effort, without creating reconciliation risk, and without building a separate team for each reporting framework?"


The Three Gaps That Define Financial Services FP&A

According to Empyrean's 2025 Bank Risk and Performance Survey, 35% of financial institutions reported budgeting and planning tools as their biggest FP&A challenge — the single most commonly cited pain point across the banking sector. Three structural gaps explain why that figure has remained consistently high despite significant investment in finance technology.

35%
of financial institutions cite budgeting and planning tools as their biggest FP&A challenge (Empyrean 2025)
2 in 3
banks reconcile ALM and FP&A outputs manually at period end — introducing timing delays and reconciliation risk
Gap 1: ALM and FP&A plan from different assumptions
Asset and Liability Management and financial planning are the two most consequential planning functions in a bank — and in most organisations they are disconnected. 74% of banking institutions collaborate on shared assumptions between ALM and planning, but only 1 in 3 have the tools to fully integrate those processes. That means 2 in 3 banks are reconciling ALM outputs and FP&A outputs manually at period end — introducing timing delays, reconciliation risk, and the persistent possibility that the capital plan and the business plan are built on incompatible assumptions about interest rates, credit risk, and balance sheet growth.

The consequence is not just inefficiency. It is that the CFO and the CRO are looking at different versions of the institution's forward position — and discovering the discrepancy when a board question requires a combined view neither team can instantly provide.
Gap 2: Regulatory reporting and management reporting are produced by separate processes
Most banks and insurers maintain two parallel finance architectures: one that produces management accounts and planning outputs, and one that produces regulatory submissions. Data flows from source systems into both, is transformed differently in each, and then has to be manually reconciled before the CFO can sign off on either.

This architecture made sense when regulatory reporting was a periodic, largely backward-looking exercise. Under Basel IV, IFRS 17, and Solvency II, it no longer does. Regulatory submissions now require forward-looking projections, stress-tested scenarios, and granular data disaggregation that needs to be consistent with management reporting — not reconciled to it after the fact.
Gap 3: Stress testing is treated as a project, not a process
KPMG's 2026 stress test preparation guidance states that banks should use the second half of 2026 to prepare for intense activity in the early months of 2027, focusing on resolving outstanding BCBS 239 data quality issues, aligning stress test starting point data with COREP and FINREP standards, and bringing relevant functions together to make early decisions about data and reporting architecture.

That guidance reflects a persistent reality: most banks treat stress testing as a project that mobilises resources annually, rather than as a continuous planning capability embedded in the EPM environment. The result is that stress test submissions are time-consuming, resource-intensive, and disconnected from the management planning cycle — meaning the insights generated by the stress test are rarely used to improve the business plan, because by the time the submission is complete, the planning cycle has already moved on.

"We Already Have Risk Systems — Why Do We Need EPM?" — The Objection Worth Addressing

This is the most consistent pushback in financial services EPM engagements — and it reflects a real structural reality. Banks and insurers typically have sophisticated risk management systems: RAROC models, credit risk platforms, ALM systems, actuarial models for insurance liabilities. The question is legitimate: why add an EPM layer on top of what already exists?

The answer is not that EPM replaces risk systems. It is that risk systems and EPM serve different purposes — and the gap between them is where most financial services finance functions are losing time, accuracy, and strategic coherence.

Risk systems are designed to measure and monitor risk positions — credit exposure, market risk, liquidity risk, capital adequacy. They are typically granular, backward-looking in orientation, and built for regulatory precision rather than management usability.

EPM platforms are designed to connect strategy, planning, and performance across the organisation — translating risk outputs into financial plans, connecting regulatory requirements to business decisions, and giving finance, risk, and business leadership a shared view of where the organisation is heading and what it needs to do to get there.

The organisations that have closed the regulatory-management reporting gap are those that have built a data and model architecture where risk system outputs flow automatically into the EPM environment — so that the capital plan reflects the credit risk position, the stress test scenarios feed into the management budget, and the regulatory submission and the board presentation are produced from the same underlying data, not reconciled after the fact.

That integration is not a technology question. It is an architecture question. And it is the design decision that determines whether an EPM investment in financial services generates the returns it was meant to produce.


What Good EPM Looks Like in Banking and Insurance

A mid-tier regional bank is preparing its annual capital plan under Basel IV requirements. The process involves the credit risk team producing loan loss projections, the treasury team running NII sensitivity analysis across rate scenarios, the business lines submitting volume and margin forecasts, and the FP&A team consolidating all of it into a capital adequacy projection and a management P&L.

Disconnected Environment
Process runs across four separate systems
Multiple manual handoffs between teams
Takes six to eight weeks of intensive effort
Final submission cannot be easily interrogated
Component assumptions documented in different formats across different tools
"What happens to CET1 if CRE losses increase 20%?" requires a three-day cross-functional working group
Connected EPM Environment
Credit risk assumptions flow automatically into the NII model
NII model feeds the management P&L
Management P&L generates the regulatory capital projection
Same scenario run in hours, not days
Single governed data model across all teams
Regulatory submission and board presentation from the same underlying data

The same principle applies in insurance. An insurer navigating the dual requirements of IFRS 17 and Solvency II — as examined in detail in EIOPA's 2024 implementation report — needs an EPM environment where actuarial cashflow projections, contractual service margin calculations, risk adjustment estimates, and Solvency II technical provisions all exist within a model that can reconcile the two frameworks and explain the differences to auditors, analysts, and regulators from the same underlying data.


The Five Design Principles for Financial Services EPM

Based on the regulatory environment, the structural planning gaps, and the implementation patterns that consistently deliver results in banking and insurance, five design principles distinguish EPM deployments that work in financial services from those that do not.

1
Design for regulatory traceability from day one
Every data point in a financial services EPM model needs to be traceable from source to regulatory submission. The BCBS 239 principles — which require banks to have strong data aggregation capabilities and risk reporting practices — apply not just to risk reporting but to the data architecture that feeds it. An EPM model built for management convenience first and regulatory traceability second will require significant rework when regulators scrutinise the data lineage.
2
Reconcile regulatory and management reporting within the same model
The goal is not to eliminate the difference between IFRS 17 and Solvency II, or between the management P&L and the regulatory capital return. The difference is real and structurally valid. The goal is to reconcile that difference automatically within the EPM model — so that a finance director can move from the IFRS 17 profit figure to the Solvency II own funds calculation with a single click, with the reconciling items documented and auditable. This connects directly to the data quality principles we examined in our post on why bad data is the real reason planning processes fail — in financial services, data quality is a regulatory requirement, not just a planning best practice.
3
Embed stress testing as a continuous capability, not a periodic project
The most mature financial services finance functions are not those that run stress tests well. They are those for which stress testing is a continuous planning capability — where a rate shock, a credit deterioration scenario, or a liquidity stress can be modelled within the standard planning cycle rather than as a separate mobilisation. This is exactly the scenario planning capability we described in our post on scenario planning at scale — applied specifically to the regulatory scenario requirements of banking and insurance.
4
Connect ALM and FP&A on shared assumptions
The 74% of banks that share assumptions between ALM and FP&A are already doing something right. The 67% that cannot integrate those processes automatically are carrying a structural risk that compounds every planning cycle. An EPM architecture in banking should include a shared assumption layer — interest rate paths, credit spread assumptions, balance sheet growth rates — that is visible to both the ALM team and the FP&A team and updated in the same place, rather than maintained independently and reconciled manually.
5
Govern the model as a regulatory asset
In financial services, the EPM model is not just a planning tool. It is part of the regulatory infrastructure. The data lineage, the model logic, the version history, and the approval workflows all need to meet the same documentation standards that apply to risk models and regulatory submissions. This governance discipline is non-negotiable — and it needs to be designed into the EPM architecture from the start, not retrofitted after an audit question surfaces a documentation gap.

The Role of EPM Platforms in Financial Services

Modern EPM platforms — Anaplan, Jedox, and OneStream, which Keansa implements across our partner ecosystem — all support the architectural requirements of financial services planning when correctly designed and governed. They provide the multi-dimensional data model, the audit trail, the workflow management, and the scenario planning capabilities that financial services EPM requires.

What they do not provide out of the box is the financial services-specific model design: the regulatory hierarchies, the IFRS 17 calculation logic, the Basel IV capital framework, the Solvency II reporting structure. That design work — translating regulatory requirements into EPM model architecture — is where implementation expertise in the sector matters most.

Keansa's FP&A and Banking and Insurance engagements consistently begin with a regulatory landscape mapping exercise: identifying which reporting frameworks apply, where the current data gaps sit, and how the EPM model needs to be architected to serve regulatory and management requirements simultaneously. That mapping determines the implementation sequence — and it is the work that most generic EPM implementations skip, which is why they end up building a management planning tool that cannot serve regulatory requirements without significant rework.

The EBA and ECB's 2027 stress test cycle is already coming into focus, as KPMG's guidance notes, with banks advised to begin data architecture preparation in the second half of 2026. That timeline makes the current period an unusually good moment for banking and insurance finance leaders to assess whether their EPM environment is built to serve both regulatory and management requirements — or whether they are running two parallel finance functions that will only get more expensive to maintain.


Conclusion

Banking and insurance FP&A is not harder than other sectors because the numbers are more complex. It is harder because the same numbers need to serve multiple frameworks simultaneously — management decision-making, regulatory capital planning, stress testing, statutory reporting — and any gap between those frameworks creates reconciliation cost, audit risk, and strategic blind spots.

The finance functions that are ahead in financial services EPM are not those that have automated the fastest or deployed the most AI. They are those that answered a deceptively simple architecture question early: can our planning model serve regulatory and management requirements from the same underlying data — or are we maintaining two parallel versions of our financial position and hoping nobody asks for them at the same time?

In banking and insurance, somebody always asks. The 2027 stress test cycle is already being planned. IFRS 17 is entering its second full year of implementation. Basel IV capital requirements are reshaping how banks plan their balance sheet growth.

The organisations that build the integrated architecture now will produce those submissions faster, with greater confidence, and with more time left over for the strategic finance work that regulatory compliance was never supposed to crowd out.


Frequently Asked Questions

Q What is EPM for banking and insurance?
EPM for banking and insurance refers to Enterprise Performance Management implemented specifically for the regulatory and operational requirements of financial services institutions. Unlike generic EPM, banking and insurance EPM must simultaneously support management reporting, regulatory capital planning (Basel IV), stress testing, IFRS 9/17 financial reporting, Solvency II returns for insurers, and liquidity planning — all from a single governed data architecture. The design requirements are fundamentally different from those of EPM in manufacturing or retail.
Q Why is FP&A harder in banking and insurance than in other sectors?
The primary challenge is the dual reporting requirement. Banking and insurance finance functions must produce management accounts and regulatory submissions that are based on the same underlying data but apply different valuation methodologies, aggregation hierarchies, and reporting frameworks. According to Empyrean's 2025 Bank Risk and Performance Survey, 35% of financial institutions cite planning and budgeting tools as their biggest FP&A challenge — reflecting the difficulty of serving both audiences from a single planning environment.
Q What is the connection between IFRS 17 and Solvency II in insurance EPM?
IFRS 17, which replaced IFRS 4 for insurance contracts in January 2023, and Solvency II are two different frameworks for valuing insurance liabilities. EIOPA's 2024 implementation study found that IFRS 17 insurance liabilities were on average 2.5% lower than Solvency II technical provisions — a difference that needs to be reconciled at group level across multiple entities, lines of business, and currencies. An effective insurance EPM model produces both sets of figures from the same underlying actuarial data and explains the reconciling differences automatically, rather than requiring manual bridging at each reporting period.
Q How does stress testing connect to EPM in banking?
Stress testing and financial planning should share the same model architecture — so that regulatory stress scenarios feed into the management budget and the capital plan, rather than being produced by a separate team using separate assumptions. KPMG's 2026 guidance to banks ahead of the 2027 EBA/ECB stress test specifically advises institutions to resolve BCBS 239 data quality issues and align stress test data with COREP and FINREP standards. An EPM environment that embeds stress testing as a continuous capability — rather than treating it as an annual project — reduces submission effort and improves the strategic value of the analysis.
Q What EPM platforms are most suited to banking and insurance?
Anaplan, Jedox, and OneStream all support financial services EPM requirements including multi-entity consolidation, regulatory hierarchy management, scenario modelling, and audit trail documentation. The platform choice depends on the specific regulatory frameworks applicable, the existing ERP and risk system landscape, and the scale of the planning environment. Keansa's Banking and Insurance practice conducts platform-agnostic assessments to identify which solution best fits the specific regulatory and management reporting context.
Q How should a banking or insurance CFO approach an EPM implementation?
Start with regulatory landscape mapping before selecting a platform. Identify which reporting frameworks apply — IFRS 9, IFRS 17, Basel IV, Solvency II, stress testing requirements — and map the current data gaps between regulatory and management reporting. Design the EPM data architecture to reconcile both requirements from the same source data before configuring the platform. Establish governance standards that meet regulatory documentation requirements from day one. And treat data quality as a regulatory requirement, not a planning preference — the same BCBS 239 principles that govern risk reporting data should govern the data feeding the EPM model.

Related Resources

Regulatory reporting and management planning are not two separate problems. In banking and insurance, they are the same problem — and the organisations that solve them together spend less time on compliance and more time on the decisions that actually move the business forward.

Book a Free Planning Assessment →