Itaú Unibanco披露风险政策与资本管理政策
6-K - Itau Unibanco Holding S.A. (0001132597) (Filer)
Itaú Unibanco披露涵盖社会、环境与气候、市场、合规与操作、流动性、信用及资本管理的多项政策,其中信用风险政策和资本管理政策于2026年9月获董事会批准。资本管理政策列出监管最低资本要求:CET1为4.5%、一级资本为6.0%、总资本为8.0%;总资本加额外普通股缓冲为11.56%。政策还规定资本计划、压力测试及恢复与有序处置计划的管理和审查要求。
ITAÚ UNIBANCO HOLDING S.A. CNPJ 60.872.504/0001-23 Publicly-Held Company NIRE 35300010230 PUBLIC ACCESS REPORT – SOCIAL, ENVIRONMENTAL AND CLIMATE RISK POLICY 1. PURPOSE To establish the rules and responsibilities related to the management of Social, Environmental and Climate Risks of Itaú Unibanco Holding S.A. (“Itaú Unibanco”), in compliance with applicable regulations, in particular CMN Resolution 4,557/17, as amended by CMN Resolution 4,943/21 (“Res. 4,557/17”). 2. TARGET AUDIENCE This policy applies to the activities of Itaú Unibanco and its subsidiaries. 3. INTRODUCTION Itaú Unibanco recognizes the growing relevance of Social, Environmental and Climate Risks (“SEC” or “SEC Risks”) in the global context and their direct influence on financial operations and business sustainability. The proper management of these risks is essential to contribute to sustainable development and to meet regulatory requirements and stakeholder expectations. The approach adopted in this policy considers the integration of SEC Risks into the organization’s traditional risks, following the principles of relevance and proportionality. This ensures that strategic and operational decisions are geared towards mitigating negative impacts and maximizing opportunities associated with a sustainable economy. 4. DEFINITIONS AND CONCEPTS Pursuant to Res. 4,557/17, SEC Risks are understood as the possibility of causing losses to the institution, including those of a reputational nature. SEC Risks must be identified and managed based on criteria of relevance and proportionality, ensuring that the actions taken are appropriate and compatible with each risk. The dimensions considered are: - Social: Refers to events associated with the violation of fundamental rights and guarantees or with acts harmful to the Common Interest. This includes issues such as inadequate working conditions and negative impacts on local communities. Management must prioritize the protection of human rights and the promotion of social well-being. - Environmental: Involves events associated with the degradation of the environment and biodiversity, as well as the excessive use of natural resources. Examples include deforestation, pollution and depletion of water resources. The approach must focus on environmental conservation, the sustainable use of resources and the promotion of ecological practices. - Climate: Encompasses two main aspects: (i) the transition to a low-carbon economy, which aims to reduce or offset greenhouse gas emissions and preserve the natural mechanisms that capture these gases, such as forests and oceans; and (ii) adaptation to extreme weather events and long-term environmental changes, such as severe storms, prolonged droughts and sea-level rise, which are attributed to changes in climate patterns. Management must include mitigation and adaptation strategies to minimize the adverse impacts of climate change. 5. PRINCIPLES SEC Risks materialize within Traditional Risks, requiring each risk discipline to develop specific actions to identify, measure, assess, monitor, report, control and mitigate the potential adverse effects arising from their interactions with SEC Risks. The management of these risks must follow the guidelines set forth in this policy, as well as: i. The precepts and guidelines set forth in the Social, Environmental and Climate Responsibility Policy (“PRSAC”), in line with CMN Resolution 4,945/21, which establishes rules for incorporating sustainability
criteria into financial operations; ii. The provisions of the Risk Management Policy (Global) and the Risk Appetite Policy, which provide a comprehensive and consistent framework for the entire organization; iii. The principles of relevance and proportionality, ensuring that actions are appropriate to the magnitude and importance of each identified risk; iv. The provisions set forth in related Procedures (“PR”), which detail the processes and practices to be followed; v. The public commitments undertaken by Itaú Unibanco, which reflect the institution’s commitment to sustainability and corporate responsibility; vi. The regulations related to the topic, as well as market best practices and trends, ensuring that the bank is aligned with the most advanced and effective risk management standards. 6. SEC RISK MANAGEMENT GUIDELINES To identify the SEC Risks to be prioritized in Itaú Unibanco’s risk management, we adopt three interdependent perspectives: • Financial: This perspective considers events that have the potential to materialize into monetary losses for Itaú Unibanco. This includes direct impacts, such as credit provisions/losses, fines and penalties, as well as indirect impacts, such as the loss of business opportunities due to issues related to social, environmental and climate risks. • Reputational: When an event has the potential to generate a negative perception of Itaú Unibanco’s reputation among its stakeholders, according to the definition of reputational risk described in the Corporate Risk Dictionary (Global). • Legal: Involves risks related to the inadequacy or deficiency of contracts entered into by the institution, sanctions resulting from non-compliance with legal provisions, and indemnities for damages to third parties resulting from the bank’s activities. For the classification of SEC Risks, elements of probability and severity are used. This means assessing the probability of occurrence of a risk event and the severity of its potential impacts. This classification makes it possible to prioritize mitigation actions and allocate resources efficiently. In addition, Itaú Unibanco monitors concentrations of exposures to economic sectors and geographic regions that are more susceptible to suffering or causing SEC damage, and may establish specific limits for these exposures, in accordance with its Risk Appetite Policy and the Risk Management Policy (Global). Both classification and monitoring are continuous processes, and Itaú Unibanco keeps records of data relevant to their management, including, when available, losses from SEC events. The data and information resulting from these processes are used in preparing the management reports required by CMN Resolution No. 4,557/17, as well as in conducting the climate stress testing program, including scenario analyses that consider hypotheses of changes in climate and transition patterns, enabling Itaú Unibanco to make any necessary revisions to its strategies in order to respond to changes in the external and internal environment. SEC Criteria for Clients, Operations Subject to Credit Risk and Suppliers Itaú Unibanco’s SEC Risk management provides for methodologies and processes that consider SEC and governance criteria in the assessment of clients, operations subject to credit risk and suppliers. These methodologies may include: (i) In the social dimension, due diligence on working conditions, respect for human rights and impacts on traditional communities; (ii) In the environmental dimension, the assessment of the risk of disasters, contamination and degradation of biomes and natural resources; (iii) In the climate dimension, the assessment of physical risks (e.g., extreme weather events) and of transition risks associated with regulatory, technological or market changes;
(iv) In the governance dimension, the assessment of the counterparty’s transparency, the quality of its management bodies and its capacity to manage SEC risks. Itaú Unibanco considers specific criteria for the qualification and periodic assessment of counterparties according to their SEC risk profile, taking into account, among other factors, their sectors and geographic regions of operation, compliance with legislation and an adequate governance structure to mitigate potential credit losses arising from SEC events. Such criteria are applied from a client, operation and collateral sufficiency perspective, according to their relevance. SEC Criteria for Own Operations The management of SEC Risks arising directly from Itaú Unibanco’s operations comprises the identification, assessment, monitoring and mitigation of events that may emerge from the bank’s operational activities. These risks include potential social, environmental or climate impacts originating from internal activities, operational processes, contracted service providers or structures under the institution’s direct responsibility. From this perspective, each area must ensure that its operational processes are conducted in a manner that prevents damage, reduces exposures and ensures compliance with applicable internal and external regulations. In addition to identifying risks, operational areas must implement controls, record incidents and act on mitigation in a timely manner. The management of SEC Risks in operations must also consider the efficient use of resources, compliance with applicable socio-environmental requirements, the adoption of low-carbon practices and alignment with corporate sustainability guidelines, ensuring that the institution minimizes negative impacts and strengthens its responsible conduct. Training To ensure the effectiveness of SEC Risk management, employees involved in managing these risks in each of the Traditional Risk disciplines must regularly participate in capacity-building and training programs on the subject offered by the organization. These programs ensure continuous updating on best practices, new regulations and trends related to the topic. Stakeholder Engagement Itaú Unibanco adopts an integrated and collaborative approach in addressing SEC Risks, involving all stakeholders, including clients, investors, suppliers, regulators and society at large, to ensure that solutions are effective and sustainable in the long term. Transparency and clear communication about risks and the measures adopted are essential to build and strengthen trust and engagement with all parties involved. As part of the management of clients’ SEC Risks, in addition to the assessment for the approval or renewal of the credit relationship and the granting of financing, the Institution also engages its clients in the adoption of more sustainable practices, such as the transition to a clean and sustainable economy, and the improvement of the control of their supply chains and labor practices. This not only reduces the associated risks but also contributes to a broader positive impact on society and the environment. Itaú Unibanco has formal mechanisms for monitoring the perception of clients, the financial market and society at large regarding its conduct, including SEC topics, such as the analysis of complaints, satisfaction surveys, public statements, media and social networks. The information resulting from this monitoring is used to identify, in a timely manner, negative perceptions that may significantly impact the institution, feeding the risk management reports, the review of stakeholder engagement strategies and, where applicable, the processes for reviewing risk appetite levels and risk management policies. 7. GOVERNANCE Itaú Unibanco’s risk management organizational structure adopts the three lines of defense strategy and follows the guidelines set forth in Res. 4,557/17. This approach aims to ensure the adequate and sustainable development of the bank’s activities, promoting integrated, independent and robust risk management. Risk management governance is structured to ensure that all risk-related matters are widely discussed and analyzed. This is essential for informed decision-making and for the implementation of effective mitigation strategies.
Accordingly, the SEC Risk management structure includes governance composed of different collegiate bodies, from the Board of Directors (BoD) and Executive level to the Officer level, as set out in the item “Main Roles and Responsibilities”. These bodies have defined mandates and are responsible for specific deliberations and recommendations, ensuring the control and mitigation of risks. The objective is to keep exposure to SEC Risks at acceptable and safe levels for the institution, aligned with the Risk Appetite defined by the BoD. 8. MAIN ROLES AND RESPONSIBILITIES The SEC Risk management structure at Itaú is composed of areas and collegiate bodies that act in an integrated manner to ensure the identification, assessment and mitigation of risks, in compliance with regulatory and corporate guidelines. The responsibilities below reflect the strategic drivers: Risk Area (RA) - Provide guidelines and define governance for the identification, assessment, measurement, control and monitoring of SEC Risks through corporate policies and procedures. - Monitor the integration of SEC Risks into Traditional Risks and their eventual materialization. - Calculate, monitor and periodically report the consumption of the socio-environmental and climate Risk Appetite metrics, according to the defined limits, to the Executive Committee, the Risk and Capital Management Committee (CGRC) and the Board of Directors (BoD). - Support the Business Units in implementing controls and evolving SEC risk management practices. Chief Risk Officer (CRO) – Officer responsible for the Risk Area - Act in the integration of SEC Risks and in the institution’s global risk management, being accountable for the Social, Environmental and Climate Risk Policy and for interacting with regulators. Business Units (Brazil and International Units) - Incorporate SEC Risk management into business processes, ensuring that they comply with the defined guidelines. - Identify, measure, assess and manage SEC Risks, documenting and storing information on losses incurred. - Promptly notify the Risk Area whenever they identify potential risks not covered by existing controls. - Maintain procedure manuals with detailed descriptions of the responsibilities and duties of the processes and controls under their management. - Engage counterparties in improving their practices, aiming at the transition to a clean and sustainable economy. - International Units must maintain their own governance structure, in compliance with local legislation, ensuring alignment with the corporate guidelines established by the parent company. Collegiate Bodies: Board of Directors (BoD) Responsibilities set forth in the Risk Management Policy (Global) and the Corporate Governance Policy (Global). Audit Committee – CAud Responsibilities set forth in the Corporate Governance Policy (Global). Risk and Capital Management Committee (CGRC) Responsibilities set forth in the Corporate Governance Policy (Global) and in the Committee’s Internal Charter, available on the IR website. On SEC Risk management matters, the activities of the Risk and Capital Management Committee (CGRC) resulting from the application of this Policy will be coordinated with those of the Social, Environmental and Climate Responsibility Committee.
Social, Environmental and Climate Responsibility Committee Responsibilities set forth in a specific procedure. ESG Superior Commission Responsibilities set forth in a specific procedure. Superior Social, Environmental and Climate Risk Committee (Superior CRSAC) Responsibilities set forth in a specific procedure. Social, Environmental and Climate Risk Committee (CRSAC) Responsibilities set forth in a specific procedure. 9. RELATED EXTERNAL REGULATIONS - CMN Resolution 4,557/17 – Risk and capital management structure and information disclosure policy. - CMN Resolution 4,945/21 – Social, Environmental and Climate Responsibility Policy (PRSAC) and actions aimed at its effectiveness. - BCB Resolution No. 139, of 09/15/2021 – Disclosure of the Report on Social, Environmental and Climate Risks and Opportunities (GRSAC Report). - BCB Resolution No. 151, of 10/06/2021 – Submission of information on Social, Environmental and Climate Risks (DRSAC). - SARB Regulation 014/2014 and updates – Banking Self-Regulation (FEBRABAN) – Regulation on Social, Environmental and Climate Responsibility and Risk Management. - SARB Regulation 026/2023 – Banking Self-Regulation (FEBRABAN) – Management of the risk of illegal deforestation in the beef cattle supply chain. - SUSEP Circular No. 666, of June 27, 2022 – Sustainability requirements to be observed by insurance companies and capitalization companies. - CVM Resolution No. 193, of October 20, 2023 – Preparation and disclosure of the sustainability-related financial information report, based on the international standard issued by the International Sustainability Standards Board – ISSB. 10. GLOSSARY CGRC: Risk and Capital Management Committee Common Interest: that associated with a group of people legally or factually connected by the same cause or circumstance, when not related to the definition of environmental risk, climate transition risk or physical climate risk. PRSAC: Social, Environmental and Climate Responsibility Policy PR: Itaú Unibanco Internal Procedures PS/PC: Itaú Unibanco Internal Policies SEC Risks: Social, Environmental and Climate Risks Traditional Risks: the risk disciplines listed in items I to V of article 6 of CMN Resolution 4,557/17. Approved by the Board of Directors in May 2026.
ITAÚ UNIBANCO HOLDING S.A. CNPJ 60.872.504/0001-23 Publicly-Held Company NIRE 35300010230 PUBLIC ACCESS REPORT – MARKET RISK AND IRRBB MANAGEMENT AND CONTROL POLICY PURPOSE To establish the market risk and IRRBB management and control structure of Itaú Unibanco Holding S.A. (Itaú Unibanco), in compliance with applicable regulations and market best practices. TARGET AUDIENCE This policy applies to all employees and activities of the Conglomerate that result in exposure to market risk and IRRBB, with an impact on Itaú Unibanco Holding and its subsidiaries. Market risk and IRRBB control covers all positions in the portfolios of the financial and non-financial companies belonging to Itaú Unibanco, in Brazil and in the International Units. This policy does not apply to the market risk of client portfolios managed by the bank and/or under fiduciary administration (for example: Wealth Management & Services – WMS funds). INTRODUCTION For the purposes of this policy, market risk and interest rate risk in the banking book (IRRBB) are defined, in the prudential context, as follows: I. Market risk is the possibility of losses resulting from fluctuations in the market values of instruments held by the institution, including: a. the risk of changes in interest rates and equity prices, for instruments classified in the trading book; and b. the risk of changes in foreign exchange rates and commodity prices, for instruments classified in the trading book or in the banking book. II. IRRBB: the risk, current or prospective over the analysis horizon, of the impact of adverse movements in interest rates on the capital and earnings of the financial institution, for instruments classified in the banking book. The aforementioned risks depend on the behavior of the prices of risk factors in light of market conditions. In addition to Treasury, which operates by buying and selling securities, other areas may impact the market risk assumed by the bank. Examples include the procurement area, when it makes a purchase in foreign currency, or even the marketing area, when it commits to sponsoring an entity or event in foreign currency. Market risk and IRRBB controls are carried out according to metrics defined in an internal procedure. GUIDELINES Market risk and IRRBB control processes must strictly observe the principles defined in the Policy. These principles are reflected in the following guidelines, according to which Itaú Unibanco’s market risk management and control structure must: • Ensure the use of reliable databases that reflect the business transacted from duly approved products, with assurance of correct information and calculations, from recording through to accounting; • Apply models that reflect market best practices; • Ensure that portfolio pricing is preferably based on quotes observed in the financial markets, captured through reliable external sources. When no price is available, the calculation must be performed using a pricing model that represents the fair valuation of the positions. In such cases, these valuations must be consistent and verifiable, with the market benchmarks and data used in the valuation reviewed regularly;
• Calculate the results of marked-to-market portfolio positions in accordance with the Bank’s model governance; • Have risk control areas responsible for defining and applying pricing parameters, independent from the business areas; • Establish and ensure that the processes and systems adopted to measure, monitor and control exposure to market risk and IRRBB: • Are compatible with the nature of the operations, the complexity of the products and the size of the Institution’s exposure to market risk and IRRBB; • Cover all sources of market risk and IRRBB; and • Generate timely risk exposure reports for the business units, the Institution’s executive board and the Board of Directors. MAIN ROLES AND RESPONSIBILITIES The Market Risk and IRRBB control structure at Itaú Unibanco involves the parties indicated below, for which we highlight their roles in relation to this matter. Board of Directors: - define the institution’s risk appetite and review it annually. Superior Market and Liquidity Risk Commission: - define the approval authorities related to market risk and IRRBB control and review them annually. - monitor market risk and IRRBB indicators, taking the necessary decisions while respecting the risk appetite. Chief Risk Officer: - responsible for the management of market risk and IRRBB at Itaú Unibanco. Market Risk and IRRBB Control: - identify, measure, control, monitor and report exposure to market risk and IRRBB to the business areas and report to the superior commissions; - monitor the compliance of exposures with approved limits, trigger alerts and other market risk and IRRBB control measures, informing any breaches to the competent authorities and requesting an action plan to restore compliance; - maintain specialized and adequately sized teams to support the market risk and IRRBB processes and systems that are under its governance and development management. Daily Management Results Control: - calculate the management results of positions and disclose them to the competent areas, enabling monitoring and supporting decision-making. Treasury: At the most fundamental level, employees are expected to fully understand the nature of the risk in the portfolios under management and the effective management of this risk, ensuring its transparency to desk managers and compliance with the established limits. MARKET RISK AND IRRBB CONTROL Market Risk and IRRBB control at Itaú Unibanco is carried out through governance and processes that ensure compliance with the following determinations or parameters: • The Institution must operate in accordance with the risk appetite defined by the Board of Directors (BoD), reviewed and approved annually based on a structure of limits and alerts. Limits are sized by assessing the projected balance sheet results, the size of equity, liquidity, the complexity and volatility of markets, as well as the Institution’s risk appetite;
• Limit consumption must be reported by the Market Risk area to the Business Areas and to the bank’s executives. Alerts work as indicators of the pre-established limit; • The institution’s structure of limits and alerts is composed of aggregate metrics, which monitor and limit risk globally, and granular metrics, which aim to prevent excessive concentration of risk in specific risk factors; • Limits are values that the trading book desks and banking book desks must respect. Alerts, on the other hand, are metrics that send a signal to the institution, based on which, through a defined governance, procedures are established to be adopted if the alert is triggered; • The mark-to-market (pricing) process of positions must be carried out based on quotes captured from external sources or, if this is not possible, calculated using models developed and validated in accordance with guidelines established in specific policies; • Information on prices and traded positions is stored in a single corporate historical database, with controls that ensure its integrity and completeness, and with functionalities that allow historical information to be consulted; • The models used must capture the correct sensitivity and market fluctuations, based on the application of periodic backtesting to the total portfolio and sub-portfolios, including all risk categories. Their results must be analyzed and used to improve the models and manage the Institution’s risk. In addition, management results must be used to verify the adherence of market risk measurement models; • The measurement of potential risk in extreme market situations, complementing statistical risk measures, through the application of stress tests to all positions in the portfolios of financial and non-financial companies; • For portfolio positions that do not have prices directly observed in the market, that are illiquid or that are valued using an internal pricing model, particularly securities and derivatives, apply prudential adjustments that correct possible marking errors, observing relevance and materiality criteria. RELATED EXTERNAL REGULATIONS Central Bank of Brazil Circular 3,354/07, which establishes minimum criteria for classifying operations in the trading book. National Monetary Council Resolution 4,557/17, which provides for the implementation of a risk management structure. Approved by the Board of Directors on 04.25.2024.
ITAÚ UNIBANCO HOLDING S.A. CNPJ 60.872.504/0001-23 Publicly-Held Company NIRE 35300010230 PUBLIC ACCESS REPORT – INTEGRATED COMPLIANCE AND OPERATIONAL RISK MANAGEMENT POLICY 1. PURPOSE To establish the principles that guide the integrated management of compliance and operational risk, under the terms of applicable regulations and in accordance with good market practices, ensuring the efficiency and effectiveness of operations, the reliability of information and compliance with laws, regulations and internal rules. 2. TARGET AUDIENCE Applies to Itaú Unibanco Holding S.A. and its subsidiaries in Brazil and abroad (Itaú), as well as to all of its management members, employees and relevant outsourced service providers. In investee companies, oversight is ensured by governance mechanisms provided for in the respective shareholders’ agreements, according to a specific policy. Foundations and Institutes have their own risk management structures, and activities provided by relevant third parties are subject to the Procurement and Supplier Payment Policy. 3. DEFINITIONS • Compliance risk: risk of sanctions, financial losses or reputational damage arising from non-compliance with legal and regulatory provisions, local and international market rules, commitments to regulators, public commitments, self-regulatory codes and codes of conduct adhered to by Itaú. • Operational risk: possibility of losses resulting from failures, deficiencies or inadequacies of internal processes, people and systems, or from external events, including legal risk associated with the inadequacy or deficiency of contracts, sanctions for non-compliance with legal provisions and indemnities to third parties. The taxonomy adopted for classifying operational risk events follows the seven categories of the Basel Committee: (i) internal fraud; (ii) external fraud; (iii) employment practices and workplace safety; (iv) clients, products and business practices; (v) damage to physical assets owned or used by the institution; (vi) business disruption; and (vii) failures in information technology systems, processes or infrastructure. • Risk appetite: defines the nature and level of risks acceptable to the organization, considering the capacity to manage them effectively and prudently, strategic objectives, competitive conditions and the regulatory environment. • Control environment: set of rules, processes and structures that form the basis for the execution of internal controls in the institution. • Inherent risk: risk in the absence of any actions that management may take to alter its probability or impact. • Residual risk: risk remaining after the application of controls and mitigating actions, reflecting the institution’s effective exposure. 4. PRINCIPLES The integrated management of compliance and operational risk observes the following principles: • Integration: compliance and operational risks are managed in an integrated and continuous manner, under the coordination of the Compliance & OpRisk Department (DCOR), in alignment with the institution’s other risks. • Independence: the function is performed with hierarchical and functional independence, reporting directly to the Chief Risk Officer (CRO), with direct communication with management members, the
Risk and Capital Management Committee (CGRC), the Audit Committee and the Board of Directors, and with access to any information necessary for the performance of its activities; the setting of targets or incentives that may compromise its independence or generate potential conflicts of interest is expressly prohibited. • Risk-based approach: the prioritization of actions considers impact, probability and the risk appetite defined by the organization. The approach must be continuously reviewed, considering internal and external changes. • Regulatory adherence: activities, products and services, whether own or relevant outsourced ones, observe external and internal regulations, commitments made with regulators and Itaú’s Code of Ethics and Conduct, and are periodically tested and assessed for compliance, considering a risk-based approach. In addition, specific guidelines are observed: the Social, Environmental and Climate Responsibility Policy (PRSAC); the General Personal Data Protection Law (LGPD) and the Corporate Information Security and Cyber Security Policy, in the processing of biometric data and other sensitive data; and the Corporate Policy for the Prevention of Illicit Acts, in fraud prevention and in the prevention of money laundering and terrorist financing (AML/CFT), in alignment with applicable regulatory requirements. • Client centricity, integrity and ethics: client centricity, integrity and ethics standards are disseminated as elements of the institutional culture, with individual and collective responsibility for risk management. • Transparency and timeliness: reports to governance bodies and regulators are clear, objective and timely, supported, whenever possible, by data analysis and exploration at a granular level. • Resilience, root-cause view and continuous improvement: the integrated management of compliance and operational risk is maintained in the face of disruptive events, so as to preserve the continuity of processes and governance. It is periodically reviewed to incorporate lessons learned, regulatory developments and changes in the internal and external environment. When a relevant risk is identified in a given process, similar processes are screened in order to ensure consistent mitigation of the respective root cause and continuous improvement. • Three lines model: risk management is distributed according to the three lines model published by the Institute of Internal Auditors (IIA), with clear and segregated roles and responsibilities, free of conflicts of interest. The first line is represented by the Business, Support and Communities Areas, the second by the Risk Area and the third by Internal Audit. 5. MANAGEMENT CYCLE The integrated management of compliance and operational risk follows a continuous cycle, as described below: • Identification: recognition of internal and external events, including changes in the regulatory environment, that may adversely impact Itaú’s strategic objectives. • Assessment and Measurement: definition of residual risk, considering the inherent impact, the quality and effectiveness of the control environment and relevant changes in the internal and external environments. This stage is carried out through self-assessment by the first line, and the result is challenged based on data by the second line. Measurement includes tail scenarios and the quantification of operational risk for regulatory and economic capital purposes, according to the Capital Management and Model Risk policies. • Response: conscious and structured decisions to accept (assume), avoid, transfer or mitigate the risk, aiming to keep residual risk within the limits established in the Risk Appetite Statement (RAS). The risk response includes physical, logical and organizational controls, including segregation of duties, approval authorities and procedures, as well as business continuity and recovery plans, conducted under Itaú’s Organizational Resilience Program. • Monitoring: monitoring of the effectiveness of controls and regulatory adherence, with timely addressing of failures and correction of root causes, including the assessment of operational losses
and other indicators of the control and regulatory environment, supported by system audit trails and technology security testing. • Reporting: escalation of events, deficiencies and breaches, observing formal criteria of materiality, criticality and maximum communication deadlines, ensuring timely reporting to the competent authorities, the Audit Committee, the Risk and Capital Management Committee (CGRC), the Board of Directors and, where applicable, regulators. 6. ROLES AND RESPONSIBILITIES 6.1. Board of Directors Approves this Policy and the positioning of DCOR within the organizational structure, so as to preserve its independence and avoid potential conflicts of interest; provides the means necessary for the proper performance of the integrated compliance and operational risk management functions, including the availability of resources to allocate a sufficient number of staff with the necessary training and experience; ensures the proper management, effectiveness and communication of the Policy to the target audience, as well as the dissemination of integrity and ethical conduct standards as part of the institution’s culture and the adoption of corrective measures when failures are identified. 6.2. Audit Committee Validates this Policy prior to its submission to the Board of Directors; assesses, at least annually, the structure, effectiveness and regulatory adherence of the integrated compliance and operational risk management function, including the clear definition of roles and responsibilities, independence and the adequacy of resources to the activities performed; verifies the communication of this Policy to the target audience, the dissemination of integrity and ethical conduct standards as part of the institution’s culture, and the adoption of corrective measures when failures are identified. 6.3. First Line: Business, Support and Communities Areas Represented by the Business, Support and Communities Areas, it has primary responsibility for the integrated management of compliance and operational risk, according to the management cycle: identification, through the mapping of processes, risks and controls associated with its activities; assessment and measurement, based on the Compliance & OpRisk methodology; risk response, which includes mitigation, through the definition and implementation of action plans for non-compliance findings, or risk acceptance approved by the competent authority, always in alignment with Itaú’s risk appetite, as well as the training of its employees as a structuring mitigating action that cuts across the entire risk management cycle; timely monitoring and reporting to the competent authorities of identified changes or breaches, as well as the relationship with regulatory bodies, according to a specific policy, with the objective of maintaining an effective control environment, consistent with the nature, size, complexity and risk profile of the operations. 6.4. Second Line: Risk Area Represented by the departments of the Risk Area, without business management responsibilities or incentives that could compromise its independence, and with activities fully segregated from the Internal Audit Area. DCOR’s mission is to enable the management of operational and regulatory risks, independently supporting the first line and supporting decisions that maximize sustainable value for the bank, ensuring compliance and client centricity. Its duties include: • defining guidelines for the integrated management of compliance and operational risk, including exception governance. • issuing an independent opinion on the quality of the control environment, using the Compliance & OpRisk methodology and challenging the performance of the first line. • systematically and timely reporting to the Audit Committee, the Risk and Capital Management Committee (CGRC), the Board of Directors and, where applicable, regulators, any non-compliance
identified or significant changes in the integrated management of compliance and operational risk. • coordinating the relationship with the main regulatory and supervisory bodies, such as Bacen, CVM and SUSEP. • managing the Integrity and Ethics Program, ensuring the dissemination of standards through training and communications, as well as the assessment of its effectiveness and continuous improvement, in accordance with the Code of Ethics and Conduct. • designing the guidelines for DCOR’s products and services, as well as ensuring the regulatory adherence of such products. • coordinating the governance of Itaú’s policies and procedures with regard to review frequency and approval authorities. • submitting an annual report on compliance and operational risk management to the Audit Committee, the Risk and Capital Management Committee and the Board of Directors, containing, at a minimum: (i) a summary of the activities carried out in the period by the compliance function and by operational risk management, including tests, monitoring, controls and other actions; (ii) compliance and operational risk deficiencies identified, with their respective materiality and risk classification; (iii) recommendations issued by DCOR to address the deficiencies; and (iv) measures adopted by management members and other areas to correct the deficiencies identified, including the status of the related action plans. The documents and other information evidencing integrated management will be kept available to the Central Bank of Brazil for a minimum period of five years. • distributing the Compliance & OpRisk methodology to the International Units. 6.5. Chief Risk Officer (CRO) Approves DCOR’s mission, strategic objectives and scope of action, informing the CEO. In the International Units, the Local and Regional CROs are responsible for the local application of this Policy, under the coordination of the CRO, according to a specific procedure on roles and responsibilities. 6.6. Third Line: Internal Audit Responsibilities are detailed in the Internal Audit Policy (Global), with emphasis on the independent and recurring assessment of the adequacy and effectiveness of governance, risk management and internal controls of the organization and of the quality of the execution of the responsibilities assigned to achieve the goals established by the organization. Coordination between DCOR and Internal Audit is carried out in a structured manner, through the Combined Assurance front, observing the independence of each function and the prohibition of conflicts of interest. Approved by the Board of Directors in June 2026.
ITAÚ UNIBANCO HOLDING S.A. CNPJ 60.872.504/0001-23 Publicly-Held Company NIRE 35300010230 PUBLIC ACCESS REPORT – CORPORATE LIQUIDITY RISK MANAGEMENT AND CONTROL POLICY This policy presents the liquidity risk management and control structure of Itaú Unibanco Holding S.A., in compliance with applicable regulations and market best practices. It applies to all activities of the conglomerate that result in exposure to liquidity risk, including all financial companies controlled by Itaú Unibanco in Brazil and abroad, except for the liquidity risk of client portfolios managed or administered by the bank (Wealth Management & Services – WMS funds). 1. Concept Liquidity risk is defined as the possibility that the Institution will not be able to meet its financial obligations efficiently and in a timely manner. This risk may occur when there is a mismatch between cash flows (assets and liabilities) that affects its operations or produces significant losses. The liquidity risk appetite and the entire limit structure are established by the Board of Directors and the Superior Commissions. Based on these parameters, control is carried out by an independent area and aims to compare assets (generally the most liquid ones) with financial obligations (generally those with shorter maturities), ensuring that Itaú Unibanco’s cash availability is sufficient to meet its obligations. 2. Specific Guidelines: Measurement: the measurement of exposure to liquidity risk is based on the daily analysis of the evolution of cash flows and compliance with regulatory ratios. It must cover all financial operations of Itaú Unibanco’s companies, as well as possible contingent exposures (exposure situations with no expected date of occurrence) or unexpected exposures (changes in cash inflows or outflows). These situations commonly arise from settlement services, the provision of sureties and guarantees, contracted and undrawn credit lines, the occurrence of adverse events that impact technical provisions, etc. Another fundamental aspect is Itaú Unibanco’s capacity to hold liquid assets and cash availability. Liquid assets comprise cash availability in Brazil and abroad and all assets immediately convertible (D0) into means of payment. Main Controls and Metrics: • Liquidity Coverage Ratio (LCR): measures whether the volume of high-quality liquid assets of the prudential conglomerate is sufficient to withstand a severe liquidity crisis for a period of 30 days, according to assumptions defined by the Central Bank of Brazil; • Net Stable Funding Ratio (NSFR): measures whether the prudential conglomerate has available stable funding in excess of that required by cash outflows in a one-year stress scenario; • Concentration of Funding Providers: demonstrates that the prudential conglomerate has a diversified exposure to liquidity-providing counterparties; • Contingency, Recovery and Orderly Resolution Plans (PRSO): aim to restore adequate liquidity levels and preserve the bank’s viability in response to stress situations. The plans must contain the list of actions, with the respective volumes, deadlines and owners; Note: The actions in the plans must include a gradation by level of criticality, and the order of the actions must be determined by ease of implementation and market conditions; • Projected cash flow (Business Continuity Scenario): shows the expected cash flows, considering the continuity of business under normal conditions; • Social Media Monitoring: monitoring of social media events by the marketing team (specific document). Should there be any indication of an impact on the bank’s liquidity, liquidity maps and indicators will be monitored daily, and action plans approved by the Crisis Committee (specific document) may be executed;
• Foreign Currency Portfolio Run-off Scenario: shows the expected cash flows, considering the liquidation of current portfolios and the discontinuity of business; • SUSEP Portfolio Liquidation Scenario and Own Risk and Solvency Assessment (ORSA), in compliance with (CNSP) Resolution No. 471/24: show cash flows under normal and adverse scenarios for companies regulated by Susep. Breaches of defined limits: must be reported by liquidity risk control to senior management, to the relevant areas for immediate restoration of exposure within limits, and to the pertinent committees. 3. Responsibilities The Liquidity Risk process at Itaú Unibanco begins with the limit approval governance and extends to the execution of cash inflows and outflows. Limit Approval Governance: the Board of Directors annually defines the liquidity risk appetite and the contingency and recovery plans. The other approval forums, depending on the level of granularity of the metric, range from the CSRML (Superior Market and Liquidity Risk Commission) to approvals by the Officers of the Risk and Treasury Areas. Liquidity Risk Management, Control and Execution: involves the dynamics of several Itaú Unibanco areas: Treasury ALM / GCP, which carries out cash strategy and planning; Liquidity Risk, which carries out the control, monitoring and predictability of liquidity; the Reserve Pilots, who calculate the reserve balance and monitor the bank’s debit and/or credit entries; and Information Technology, which supports liquidity risk processes and systems. In the case of SUSEP-supervised entities, GIS (Global Institutional Solutions) is also involved, being responsible for the liquidity management of proprietary portfolios and technical reserve portfolios. 4. Review and Update: This policy is the responsibility of the DCRML (Capital, Market Risk and Liquidity Department) and is approved annually by the Board of Directors. Approved by the Board of Directors in May 2026.
ITAÚ UNIBANCO HOLDING S.A. CNPJ 60.872.504/0001-23 Publicly-Held Company NIRE 35300010230 PUBLIC ACCESS REPORT – CREDIT RISK MANAGEMENT AND CONTROL POLICY 1. PURPOSE To establish the guidelines, governance and control mechanisms for credit risk management at Itaú Unibanco. 2. TARGET AUDIENCE Financial institutions controlled by Itaú Unibanco Holding S.A. (Itaú Unibanco), in Brazil and abroad1, that incur credit risk, covering all segments (individuals and legal entities). 3. INTRODUCTION This policy establishes the framework for the identification, measurement, assessment, monitoring, control and mitigation of credit risk, being applied in an integrated manner with the other risk disciplines and aligned with the risk appetite, according to the Risk Appetite Statement (RAS) approved by the Board of Directors. Credit risk is considered to be the possibility of losses associated with the failure of borrowers, issuers or counterparties to meet financial obligations, the deterioration of their credit quality, recovery costs, renegotiations and reputational impacts, including those arising from social, environmental and climate aspects (specific document). Credit risk management at Itaú Unibanco is conducted through a continuous and integrated management structure, compatible with the business model, the nature of the operations and the complexity of the products and services offered by the institution. This structure is sized in proportion to the relevance of credit risk exposures and is appropriate to the institution’s risk profile and systemic importance, incorporating a forward-looking stance in risk management (specific documents). The credit risk rating system is integrated into the management structure, supporting the decisions and procedures arising from the policies and strategies adopted. For the Wholesale segment, the guidelines are set out in the specific document. For the purposes of this Policy, the Unit of Observation corresponds to the lowest level of aggregation for the identification, measurement, monitoring and reporting of risks, and may be defined at the contract level in Retail and at the conglomerate or subgroup level in Wholesale, according to the nature and sharing of credit risk. The credit risk management process is supported by specific governance for the formation and modification of economic conglomerates and subgroups, according to a specific document. 4. CREDIT RISK MANAGEMENT GOVERNANCE Credit risk management is conducted through an independent organizational structure, with clear segregation between the areas responsible for taking, measuring and controlling credit risk. The established governance ensures the adequate identification, assessment, measurement, control, mitigation, monitoring and reporting of risks, in alignment with the Risk Appetite levels defined by the Board of Directors in the Risk Appetite Statement (RAS) and with the guidelines of CMN Resolution No. 4,557/2017. The credit risk management process includes specific governance for the formation, modification and monitoring of economic conglomerates and subgroups, applicable to all commercial segments that grant or manage credit, including international units. The guidelines, criteria and procedures are detailed in the specific document. The Board of Directors, supported by the Risk and Capital Management Committee, is responsible for approving and reviewing the Risk Appetite Statement (RAS), defining the Risk Appetite and its limits, and overseeing the development, implementation and performance of the risk management structure, including
credit risk (specific documents). The risk collegiate bodies are responsible for deliberating on relevant matters related to credit risk, including policies, strategies, limits and corrective actions, ensuring adherence to the Risk Appetite (specific documents). This structure covers operations classified both in the trading book and in the non-trading book. In the foreign units, the independent risk control structure is the responsibility of the Local Chief Risk Officers (CROs), who report to the respective Local CEOs and to the Regional CROs. Their activities are coordinated and aligned with the Credit Risk and Modeling Departments — Wholesale (DRCMA) and Retail (DRCMV). The Regional CROs are responsible for the integrated and preventive management of the risks in their region, reporting the status to the CRO of Itaú Unibanco Holding. The roles and responsibilities of the Holding, Regional and Local CROs are defined in the specific document. Credit risk control is carried out in a centralized and independent manner by the Risk Area, segregated from the business units and internal audit, ensuring methodological consistency and adherence to institutional guidelines (specific documents). For new products and relevant changes to existing products, there is a process for credit risk governance. Credit risk validation is conducted with an integrated view of risk, covering all major risks, considering internal and external factors and determining whether or not the risks are controllable. Further information on the management of new products and relevant changes to products is described in specific documents. 4.1. Assessment and Approval of Credit Policies and Risk Parameters Credit risk management includes a specific governance structure for the assessment and approval of changes to credit policies and business rules that impact credit risk exposure, limit consumption or allocated economic capital. For proprietary portfolios, credit policies cover the criteria for granting and maintaining credit, as well as the acquisition, in the market, of instruments with credit risk. For third-party portfolios, the policies address the rules applicable to discretionary decision-making on assets with credit risk. Credit policies may be classified as: i. Credit granting and maintenance policies, including changes to models, new products, segmentations, income or revenue, approval authorities, cut-off points and internal re-segmentations; ii. Risk measurement policies, including criteria for mitigation through collateral, the application of potential credit risk models and the definition of parameters for calculating capital and limit consumption; iii. Global Credit Policy, which establishes maximum or minimum levels for indicators and variables that reflect the institution’s credit risk and must be observed by all retail segment policies. The specific definitions of credit policies, collection strategies, approval processes and authorities, as well as the monitoring and responsibilities of the departments involved, are detailed in specific documents. 5. GENERAL CREDIT RISK MANAGEMENT GUIDELINES The credit risk management process covers the complete cycle of identification, assessment, measurement, control, mitigation and monitoring of exposures, and is conducted in a continuous, integrated manner compatible with the nature, complexity and relevance of the products, operations and counterparties. It comprises the following stages: • Counterparty analysis: assessment of the risk profile based on economic and financial information, relationship history, sector of activity and other relevant factors, observing the institutionally defined unit of observation. • Risk rating: assignment of a rating through internal systems and methodologies compatible with the nature and complexity of the exposures, based on quantitative and qualitative criteria, integrated into the risk management structure and the institution’s decision-making processes. • Credit granting: decision based on technical criteria, observing the limits per counterparty, the competent approval authorities, the risk appetite approved by management and, where applicable, the
analysis of collateral, adverse scenarios and other conditions of the operation. • Continuous monitoring: monitoring of exposures, the counterparty’s credit quality, the risk rating and the effectiveness of mitigants, with periodic reviews and timely adoption of corrective measures in the face of changes in the risk profile or market conditions, adopting a forward-looking stance in identifying emerging risks (specific document). • Treatment of deterioration: management of exposures with deteriorating credit quality, including the identification, monitoring and control of problem assets, as well as renegotiation and recovery processes, in accordance with applicable internal regulations and current recognition and measurement criteria (specific documents). Relevant changes in products, processes, strategies or business model must be assessed in advance as to their impacts on credit risk management, ensuring the identification of inherent risks before their implementation. Within the Wholesale and Corporate Real Estate segments, the specific regulations in force additionally apply, including the specific document. 6. MEASUREMENT, MODELS AND PARAMETERS Credit risk is measured through consistent methodologies, models and parameters, compatible with the nature, complexity and relevance of the exposures, integrated into the risk management structure and subject to governance, independent validation and periodic reviews. The measurement process covers: • Risk models and parameters: development, maintenance and improvement of internal measurement models — including, where applicable, PD, LGD, EAD and CCF — observing the institution’s methodological standards and current regulatory requirements. The definition, documentation and updating of parameters and assumptions must ensure segregation of duties, formalization and traceability of the changes made. • Validation and performance monitoring: conduct of independent validation processes, backtesting, continuous performance monitoring and stress testing, with the objective of assessing the adherence, predictive capacity and resilience of the models under different scenarios, identifying in a timely manner the need for recalibrations or replacements. • Credit risk mitigants: assessment of mitigation instruments as to their effectiveness, regulatory eligibility, sufficiency, legal enforceability and operational feasibility, observing, where applicable, the recognition criteria, prudential adjustments and accepted contractual netting instruments. Collateral is classified as eligible and non-eligible, according to the applicable regulatory criteria, with eligible collateral being recognized for the purpose of reducing regulatory capital. The use of regulatory haircuts and netting agreements is incorporated into the process, ensuring prudent adjustment of collateral values (specific document). The use of models and parameters must observe the guidelines of the specific document and other applicable internal regulations, ensuring effective use in decision-making processes and adherence to current regulations. 6.1. Updating and Development of Risk Parameters for Provisioning and Capital The risk parameters used for provisioning and capital purposes are assigned by the Parameter Developing Units (UDPs), based on assumptions and methodologies aimed at ensuring the institution’s solvency in the face of past, current and prospective scenarios. The definitions, assumptions and concepts of each parameter must be aligned between the UDP and the Parameter User Unit (UUP), ensuring consistency between risk measurement, use in decision-making processes and regulatory reporting. The governance, development, validation, monitoring and updating of parameters observe the applicable internal regulations, including specific documents, among others.
6.2. Stress Tests Applied to Credit Risk The institution maintains a stress testing program applied to credit risk, with the objective of assessing the resilience of exposures and the adequacy of capital in the face of adverse scenarios, in accordance with the requirements of CMN Resolution No. 4,557/2017. The program includes, among others, sensitivity analyses, scenario analyses and reverse stress tests, applied to credit portfolios and risk parameters, with a frequency and scope compatible with the relevance and materiality of the exposures. The results of the stress tests are submitted to senior management and the Board of Directors, supporting the review of credit risk management limits, policies and strategies, as well as capital planning and the assessment of the adequacy of Regulatory Capital. The governance, methodologies, documentation and procedures of the stress testing program observe the guidelines of the specific document and other applicable internal regulations. 7. SPECIFIC RISKS Credit risk management must additionally consider specific risks that may affect the quality of exposures, the payment capacity of counterparties and the adequacy of the management carried out by the institution. • Counterparty credit risk: Risk of a given counterparty failing to meet obligations relating to the settlement of transactions involving the trading of financial assets with bilateral risk, before the final settlement of the agreed financial flows. It covers derivative financial instruments, securities lending, forward foreign exchange, repurchase agreements and bilateral energy contracts. The measurement of counterparty credit risk involves its conversion into an equivalent credit risk exposure, using, where applicable, Potential Credit Risk (PCR) models. The specific criteria, methodologies and procedures are detailed in the specific document. • Country Risk: risk of losses arising from economic, political, social or institutional events or conditions in a given country, capable of affecting the payment capacity of counterparties or the value of exposures. It is subdivided into: (a) Sovereign Risk – the inability of central governments to honor their commitments; and (b) Transfer Risk – the impossibility of transferring assets from a foreign jurisdiction to an Itaú Unibanco legal vehicle due to foreign exchange restrictions. Control is carried out through sovereign ratings, limits and maximum terms, reviewed periodically. The following are not part of this flow: Credit Risk of Foreign Units, Convertibility Risk, Investment abroad (Equity) and Indirect country risk. Details in the specific document. • Social, environmental and climate risk: risk of losses associated with events or conditions of a social, environmental or climate nature that may impact the counterparty, the operation or the collateral, with the potential to generate financial, reputational and/or legal impacts; it must be considered throughout the credit cycle, observing the applicable specific regulations and the principles of relevance and proportionality. Details in specific documents. • Concentration risk: risk arising from relevant exposures to the same counterparty, economic subgroup, sector, region, product or risk factor, with the potential to amplify losses in the event of adverse deterioration. Concentration risk is monitored through indicators that are part of the institution’s Risk Appetite, covering, among others, the following dimensions: individual concentration, top 10 largest exposures, by country, by economic sector, by the institution’s business segment and of the wholesale renegotiation/restructuring portfolio. These indicators are monitored monthly by the Executive Board, the Risk Committee and the Board of Directors, which are also responsible for calibrating and approving the metrics and respective limits. The limits defined for each metric, as well as details on the calculation methodologies, are contained in the Risk Appetite Manual. These risks must be identified, assessed, measured, controlled and monitored through metrics, limits and processes compatible with their nature, relevance and materiality, in alignment with the institution’s Risk Appetite.
8. MONITORING, REPORTING AND CONTROL Credit risk monitoring, reporting and control must ensure that exposures adhere to the institution’s Risk Appetite, the timely identification of relevant deviations and the adoption of corrective measures compatible with the nature, relevance and materiality of the risks. This process includes, among other aspects: • continuous monitoring of exposures, portfolio quality and risk and performance indicators; • preparation and submission of periodic reports to governance bodies and senior management, with sufficient information to support decision-making; • identification, reporting, treatment and monitoring of deviations, exceptions, non-compliance and limit breaches, with the definition of corrective measures and owners. Risk control of credit card issuers follows the same monitoring, reporting and control process described above. The specific points of this monitoring are described in the specific document. Monitoring and controls are periodically reported to the Retail Credit Risk Policies Committee (CPRC). The results of monitoring and control are reported to appropriate governance forums and bodies, including, among others: the Superior Retail Credit and Collection Commission (CSCCV), on a monthly basis; the Superior Wholesale Credit and Collection Commission (CSCCA), on a quarterly basis, which may be changed as needed; and the International Units Risk Committee (CRUI-R), with the participation of the Holding, Regional and Local CROs. The reporting frequency is compatible with the relevance, materiality and dynamics of the risks monitored. Details on monitoring procedures are described in the specific document. 9. ROLES AND RESPONSIBILITIES – CREDIT RISK MANAGEMENT 9.1. Risk Area • Define and keep up to date the credit risk management policies, strategies, methodologies, limits and procedures, ensuring that exposures remain compatible with the risk appetite approved by management. • Periodically review the policies and strategies in force in light of changes in the risk profile, market conditions and the regulatory environment, submitting updates to the competent authorities for approval. • Maintain a centralized and independent environment for the identification, measurement, monitoring, control, mitigation and reporting of credit risk. • Continuously monitor the adherence of exposures to established limits, adopting a forward-looking stance in identifying emerging risks and anticipating adverse scenarios. • Periodically assess the adequacy of credit risk management systems, routines and procedures, promoting the necessary improvements. • Ensure the adequacy of credit risk rating systems, including the parameters and criteria used in assigning internal ratings, including for new products. • Periodically report to senior management, the Board of Directors and the risk collegiate bodies the exposure profile, the evolution of indicators and any breaches of limits or policies. • Disseminate credit risk policies, decisions and strategies to the Business Units and to the CROs of the International Units, ensuring compliance throughout the organization. • Maintain up-to-date documentation of policies, methodologies, models and procedures, ensuring the traceability of decisions and regulatory compliance. Credit Risk Modeling • Develop, maintain and improve internal credit risk measurement models — including PD, LGD and EAD — in accordance with regulatory requirements and the institution’s methodological standards. • Carry out backtesting processes and continuous monitoring of model performance, identifying in a timely manner the need for recalibrations or replacements.
• Observe the duties set forth in the specific document, ensuring that models are appropriate to the complexity and materiality of the portfolios. • Document in a structured manner the methodologies, assumptions, limitations and results of the models, ensuring transparency for internal governance and regulatory supervision purposes. Independent Model Validation • Perform the independent validation of internal credit risk measurement models, assessing the conceptual soundness, methodological robustness and predictive capacity of the PD, LGD and EAD models. • Verify the integrity of the data, assumptions and parameters used in the development and calibration of the models, identifying potential weaknesses or biases. • Issue independent technical opinions on the models assessed, including recommendations for adjustments, restrictions on use or the need for replacement, and monitor the implementation of the recommendations issued. • Periodically assess the adherence of the models to regulatory requirements and market best practices, with emphasis on effective use requirements (use test) and on consistency between the models used for regulatory and management purposes. • Report validation results to senior management and the competent collegiate bodies, supporting decision-making on the maintenance, adjustment or discontinuation of models. • Act in a manner segregated from the areas responsible for the development and use of the models, preserving the independence and objectivity of the validation process. 9.2. Finance and Capital The Finance area • Establish the accounting criteria and procedures for recording, measuring and projecting provisions and the financial impacts of credit risk, based on the parameters provided by Risk and in adherence to accounting and regulatory standards. • Prepare and publish financial statements and financial reports that support credit risk management, including provisions, expected losses and impacts on regulatory capital. • Ensure consistency between accounting information and the institution’s credit risk metrics. The Capital area • Centralize capital management, providing senior management and the Board of Directors with an integrated and forward-looking view of the adequacy of capital in relation to the risks incurred. • Calculate Regulatory Capital (PR), capital ratios (Common Equity Tier 1, Tier I and Total Capital) and the credit risk-weighted asset portions (RWA CPAD and RWA CIRB ). • Continuously monitor the regulatory capital of the Holding and the international units. • Prepare and keep up to date the Capital Plan, the Capital Contingency Plan and the Recovery and Orderly Resolution Plan (PRSO), incorporating projections under normal and stress scenarios, aligned with the risk appetite and strategic planning. • Conduct the Internal Capital Adequacy Assessment Process (ICAAP) and capital stress tests, submitting the results to the Board of Directors. • Prepare the quarterly Risk and Capital Management report (Pillar 3), ensuring adherence to the requirements of regulatory bodies. • Disseminate capital management policies and decisions to the impacted areas and units. Information-providing areas must supply complete and consistent data for the identification of risks, the measurement of required capital and the preparation of regulatory and management plans and reports.
9.3. Risk Area Collegiate Bodies • Deliberate on relevant credit risk matters — policies, strategies, limits, corrective actions and exceptions — according to the authority and specificity of each forum. • Ensure that decisions promote risk mitigation and keep exposures compatible with the risk appetite approved by the Board of Directors. • Periodically assess the credit risk metrics under their purview, promoting the timely escalation of issues requiring the intervention of senior management. The Board of Directors defines the credit Risk Appetite. The Superior Commissions are responsible for the governance, monitoring and management of the metrics and indicators under their purview, acting as intermediate supervisory bodies. 9.4. Business Units (Brazil and Foreign Units) • Ensure the visibility of the credit risk incurred in their operations and compliance with the policies, rules and limits defined by the Risk Area. • Execute credit granting, monitoring and recovery procedures in accordance with current institutional and regulatory guidelines. • Maintain up-to-date procedure manuals with descriptions of the responsibilities, processes and controls under their management. • Promptly notify the Risk Area of any events, exceptions or deviations that may impact the credit risk profile of their portfolios. 9.5. Internal Audit • Independently assess the effectiveness of internal controls, the credit risk management structure and compliance with applicable policies and regulations. • Conduct its activities with impartiality and objectivity, providing a comprehensive view of the adequacy of credit risk management processes and systems. • Report the results of assessments to the Board of Directors and the competent collegiate bodies, including recommendations for improving controls and governance. The Board of Directors oversees the effectiveness of internal controls, using Internal Audit reports and recommendations as the basis for strategic decisions and for strengthening the risk management structure. 10. RELATED EXTERNAL REGULATIONS • CMN Resolution No. 4,557/2017. • BCB Resolution No. 303/2023 (IRB approaches). • CMN Resolution No. 4,966/2021. • CMN Resolution No. 4,945/2021. • CMN Resolution No. 5,089/2023. • CMN Resolution No. 4,677/2018. • Other applicable regulations. Approved by the Board of Directors in September 2026. 1 Also including representative offices.
ITAÚ UNIBANCO HOLDING S.A. CNPJ 60.872.504/0001-23 Publicly-Held Company NIRE 35300010230 PUBLIC ACCESS REPORT – CAPITAL MANAGEMENT POLICY 1 PURPOSE To establish the principles, guidelines, responsibilities and processes related to the capital management of Itaú Unibanco Holding S.A., ensuring the maintenance of capital levels compatible with its risk profile, risk appetite, strategic planning and current regulatory requirements, in particular those arising from CMN Resolution No. 4,557 and the Basel accords. 2 TARGET AUDIENCE The capital management process must cover all companies of the conglomerate controlled by Itaú Unibanco in Brazil and abroad. 3 INTRODUCTION For financial institutions, the Central Bank of Brazil requires a minimum capital (required capital), which is the capital needed to cover the risks to which the institution is exposed, ensuring its solvency. Capital management is a fundamental instrument for the sustainability of the financial system. The methods for identifying, assessing, controlling, mitigating and monitoring risks support financial institutions in adverse times. Itaú Unibanco considers capital management fundamental to the decision-making process, contributing to the optimization and efficiency of the use of Capital in its operations. This management considers Itaú Unibanco’s companies in Brazil and abroad. Changes in the global financial environment, such as the integration of markets, the emergence of new transactions and products, increased technological sophistication and new regulations, have made financial activities and their risks increasingly complex. Additionally, lessons from financial crises reinforce the importance of risk management (Public Access Report – Risk) and capital management in strengthening the financial health of the banking industry. Brazil’s participation in the Basel Committee on Banking Supervision (BCBS – Basel Committee on Banking Supervision) encourages the timely implementation of international prudential standards in the Brazilian regulatory framework. In line with this perspective, Itaú Unibanco invests in the continuous improvement of capital management processes and practices, in accordance with international market, regulatory and supervisory benchmarks. Itaú Unibanco’s capital management consists of a continuous process of planning, assessing, controlling and monitoring the capital needed to cover the Conglomerate’s relevant risks and to support the capital requirements set by the regulator, or those defined internally by the Institution, with the objective of optimizing capital allocation. The areas defined in the capital management structure, together with the support of certain areas specific to each topic, are jointly or individually responsible for: a. Identifying the risks to which the institution is exposed and analyzing their materiality; b. Assessing the capital needed to support the risks; c. Developing methodologies for quantifying additional capital; d. Quantifying capital and internally assessing capital adequacy; e. Internal Capital Adequacy Assessment Process (ICAAP); f. Own Risk and Solvency Assessment (ORSA), for the group’s insurance companies; g. Projecting capital ratios; h. Calculating regulatory capital (PR) and capital ratios;
i. Preparing the capital plan and the contingency plan; j. Preparing the recovery and orderly resolution plan; k. Monitoring the solvency and liquidity regularization plan of SUSEP companies; l. Capital stress testing; m. Calculating the Global Systemic Importance Index (GSI); n. Preparing the quarterly risk and capital management report – Pillar 3; o. Monitoring the cost of capital of the Holding and the foreign units; p. Monitoring the capital of the foreign units. Itaú Unibanco’s capital management structure enables the monitoring and control of the capital held by the Institution, the assessment of the capital needed to cover the risks to which the Institution is exposed, and the planning of capital targets and needs, considering the Institution’s strategic objectives and/or adverse situations. In this way, Itaú Unibanco adopts a forward-looking stance, anticipating the need for capital arising from possible changes in market conditions. Itaú Unibanco’s capital management is structured from the perspective of Pillar 2 of the Basel Accord, with the Internal Capital Adequacy Assessment Process (ICAAP) as the central instrument for identifying, assessing and monitoring relevant risks and for determining the sufficiency of the Institution’s capital on a forward-looking basis. Additionally, due to its sensitivity and specificity, a specific document was created, which is reviewed periodically. 3.1 Concepts Required capital: is the capital needed to cover the risks to which the institution is exposed, ensuring its solvency and including the international units. The requirements are regulated by BACEN for Brazil and by local regulatory bodies in the international units. These requirements are expressed in the form of ratios that relate available capital to total risk-weighted assets (RWA – Risk Weighted Assets). The Regulatory Capital (PR) used to verify compliance with the operating limits imposed by BACEN consists of the sum of three items, namely: . Common Equity Tier 1 (CET1): sum of share capital, reserves and retained earnings, less deductions and prudential adjustments; . Additional Tier 1 Capital: composed of perpetual instruments that meet eligibility requirements. Added to CET1, it makes up Tier I; . Tier II: composed of subordinated debt instruments with a defined maturity that meet eligibility requirements. Added to CET1 and Additional Tier 1 Capital, it makes up the PR (Total Capital). For the purpose of calculating these minimum capital requirements, the total RWA amount is determined by the sum of the portions of assets weighted by credit, market and operational risks (according to CMN Res. No. 4,958): RWA = RWA CPAD + RWA CIRB + RWA MPAD + RWA MINT + RWA OPAD + RWA DRC + RWA CVA RWA CPAD = portion relating to credit risk exposures, calculated using the standardized approach; RWA CIRB = portion relating to credit risk exposures calculated using internal credit risk rating systems (IRB approaches – Internal Ratings-Based), authorized by the Central Bank of Brazil; RWA MPAD = portion relating to the capital required for market risk, calculated using the standardized approach; RWA MINT = portion relating to the capital required for market risk, calculated using internal model approaches authorized by the Central Bank of Brazil; RWA OPAD = portion relating to the capital required for operational risk, calculated using the standardized approach;
RWA DRC = portion relating to credit risk exposures of financial instruments classified in the trading book; and RWA CVA = portion relating to exposures to the risk of changes in the value of derivative financial instruments as a result of changes in the counterparty’s credit quality. In addition to the regulatory minimums, BACEN regulations establish the Additional Common Equity Buffer (ACP), corresponding to the sum of the ACPConservation, ACPCountercyclical and ACPSystemic portions which, together with the aforementioned requirements, increase the capital requirement: . ACPConservation: represents an extra capital “cushion” to absorb possible losses . ACPCountercyclical: is an additional capital buffer to be accumulated during the expansion phase of the credit cycle and to be consumed during its contraction phase . ACPSystemic: institutions of systemic importance are required to hold additional capital to cover systemic risk. The values of each portion and the regulatory minimums, as defined in CMN Resolution No. 4,958, are described in the table below: Common Equity Tier 1 4.5% Tier I 6.0% Total Capital 8.0% Additional Common Equity Buffer (ACP) 3.56% conservation 2.50% countercyclical (1) 0.06% systemic 1.00% Common Equity Tier 1 + ACP 8.06% Total Capital + ACP 11.56% (1) ACPcountercyclical is set by the Financial Stability Committee (Comef) based on discussions on the pace of credit expansion, and is currently set at zero. In the event of an increase in the requirement, the new percentage will take effect twelve months after its disclosure. When the ACPCountercyclical is activated in jurisdictions where the institution has exposures on its balance sheet, the calculation of the buffer must follow BCB Circular No. 3,769, increasing the regulatory minimum required of the conglomerate. Internal Capital Adequacy Assessment Process (ICAAP) Annual exercise required by BACEN whose objective is to assess the capital adequacy of Itaú Unibanco, thus providing a general and comprehensive view of the institution’s risk and capital management and demonstrating the results of the self-assessment of the adequacy of its capital level in light of its risk profile. The ICAAP comprises the Capital Plan and the Contingency Plan, described below: Capital Plan The capital plan is a section of the ICAAP whose objective is to describe how the bank’s capital planning is carried out to maintain an adequate and sustainable level of capital, incorporating in its preparation the limits established by the risk appetite and analyses of the economic and regulatory environments. Additionally, it is structured consistently with Itaú Unibanco’s strategic planning. This plan presents financial and capital projections in the short and medium term (at least the three years following the base-date year), under both normal and stress scenarios, together with its main sources of capital, the earnings distribution policy and the contingency plan. Capital Contingency Plan Itaú Unibanco has a capital contingency plan for cases in which at least one of the capital ratios falls below those defined by the Board of Directors (BoD) and the Executive Committee (EC), or for cases of unforeseen events that may affect the institution’s capital adequacy.
The plan includes a set of contingency actions and their owners, which allows Itaú Unibanco to increase its capitalization levels, and must contain, at a minimum, the definition of the capital limits that trigger its activation and the corresponding governance, aiming to maintain an adequate level of capitalization of Itaú Unibanco in an adverse situation. Recovery and Orderly Resolution Plan (PRSO) Itaú Unibanco has a Recovery and Orderly Resolution Plan whose objective is to restore adequate levels of capital and liquidity above regulatory operating limits, in the face of severe stress shocks of a systemic or idiosyncratic nature, in order to: • Recovery Plan: preserve its financial viability, while mitigating the impact on the National Financial System. • Orderly Resolution: carry out the liquidation of the bank in an orderly manner with minimum impact on the real economy / National Financial System. The PRSO covers the entire conglomerate, is reviewed every two years or as determined by BACEN, and is submitted to the Board of Directors for approval. Its regulatory basis is CMN Resolution No. 5,187, and it contains the critical functions and essential services provided by Itaú Unibanco that may impact the National Financial System and the institution’s own viability. Additionally, it addresses stress scenarios, communication plans with stakeholders, governance mechanisms necessary for the coordination and execution of the plan, and a self-assessment of recovery capacity and resolvability. Stress Test The stress test, an integral part of the Institution’s Capital Plan, is a process of simulating the effects of extreme economic and market conditions on the institution’s results, capital and liquidity. Stress scenarios must be approved by the Board of Directors, and their results must be considered in defining Itaú Unibanco’s business and capital strategy. For Itaú Unibanco, stress testing can be divided into internal and regulatory. The former seeks to measure the vulnerability and soundness of the conglomerate under hypothetical but plausible economic crisis scenarios based on simulations and macroeconomic projections developed by the institution itself. The regulatory stress test has the same objective but uses a scenario developed by the Central Bank. In both processes, the main analyses concern the Bank’s results (income statement), their distribution among the conglomerate’s portfolios and activities, and the institution’s level of capital and liquidity. Additionally, to complement the results obtained in accordance with the processes described above, sensitivity analyses and reverse stress tests are carried out annually. The capital management structure must provide for assessments of the impacts on capital based on the definition of severe scenarios chosen by the institution and include them in the results of the stress testing program. Finally, the results of the stress tests must be used as a relevant input for defining risk appetite limits, for capital planning and for assessing any need for capital management actions. Solvency and Liquidity Regularization Plan – SUSEP This plan addresses the minimum capital required for the operation of insurance and reinsurance companies, with monthly monitoring of the capital sufficiency indicator. Once insufficiency is identified, measures to regularize the solvency and liquidity ratios of the companies subject to SUSEP guidelines are defined together with the asset management areas of the insurance group. Own Risk and Solvency Assessment Process (ORSA) The Own Risk and Solvency Assessment (ORSA) process is a periodic exercise required by the regulations applicable to the Conglomerate’s insurance and reinsurance companies, whose objective is to assess the capital and solvency adequacy of these entities in relation to their risk profile, business strategy and respective risk appetite.
The ORSA provides an integrated and forward-looking view of risk and capital management, considering both normal and adverse stress scenarios, and constitutes a fundamental instrument supporting the decision-making process of senior management and the Board of Directors, ensuring the financial sustainability of operations and compliance with the prudential requirements established by SUSEP. Global Systemic Importance Index (GSI) A methodology defined by the Bank for International Settlements (BIS) and ratified by the Financial Stability Board, this index measures the importance of each financial institution in the global market whose failure could pose an international threat to the financial system, and is composed of five main indicators: - Size: reflects the institution’s relative share of global activity; - Cross-jurisdictional activity: the institution’s relative share of international activities; - Interconnectedness: the institution’s relative share of the interbank market and the global capital market; - Substitutability: the institution’s relative share of the global supply of financial services; - Complexity: the institution’s relative share of complex or illiquid instruments. Information on the GSI calculation is disclosed annually on the Investor Relations website, in accordance with BACEN Resolution No. 171. Risk and Capital Management Report – Pillar 3 This is a report containing information on prudential indicators and risk management, a comparison between accounting and prudential information, capital composition, macroprudential indicators, leverage ratio, liquidity indicators, credit risk, counterparty credit risk, securitization exposures, market risk, interest rate risk in instruments classified in the banking book and management compensation, disclosed quarterly on the Institution’s Investor Relations website (Pillar 3), in accordance with BCB Resolution No. 54. 4 GUIDELINES Capital management must support the institution in accordance with the principles defined in the Risk Management policy and those defined in this policy. These principles are reflected in the following guidelines, according to which Itaú Unibanco’s capital management structure must: - Define and monitor capital levels that act as management triggers (capital triggers), including, at a minimum, alert, contingency and recovery levels, as well as the management actions and governance bodies associated with each level. - Ensure that capital management policies and strategies are clearly documented and establish mechanisms and procedures designed to maintain Regulatory Capital (PR), Tier I, Common Equity Tier 1 and the leverage ratio compatible with the risks incurred by the institution, whether from a prudential or solo basis perspective. - Be compatible with the nature of its operations, the complexity of the products and services offered and the size of its risk exposure. - Ensure that capital management policies and strategies, as well as the capital plan, are submitted for approval and review, at least annually, by the Board of Directors, in order to determine their compatibility with the institution’s strategic planning and market conditions. - Generate reports for the institution’s executive board, the Risk and Capital Management Committee (CGRC) and/or the Board of Directors (BoD) indicating the adequacy of the levels of PR, Tier I, Common Equity Tier 1 and the leverage ratio to the risks incurred, or any deficiencies in the capital management structure, as well as actions to correct them. - Ensure that the Solvency and Liquidity Regularization Plan required by SUSEP is complied with in the event of insolvency or illiquidity on the part of one or more insurance companies, ensuring that the areas involved in managing the assets of these companies are engaged to define a
proposed corrective action, and submit it to an impact assessment. - Define the governance and responsibilities of the capital management process, and disclose decisions and policies related to this process to the impacted areas, as well as monitor the regulatory capital of Itaú Unibanco and the international units. - The business units and international units must ensure that approved decisions and policies are duly implemented. - Ensure that the information disclosed in the Risk and Capital Management report – Pillar 3 has a level of detail appropriate to the scope, the complexity of operations, the sophistication of systems and the institution’s risk management processes, and ensure that any relevant differences in relation to other information disclosed by the institution are clarified; - Ensure that the published information complies with the current rules established by regulatory bodies. 5 MAIN ROLES AND RESPONSIBILITIES Itaú Unibanco’s management is directly involved in the internal capital adequacy assessment process and its risk assessment. Among the committees and commissions (specific document) that discuss the capital management process, the following stand out: . Board of Directors (BoD) The Board of Directors is responsible for approving the risk appetite, the capital policy, the ICAAP, the capital plan, the contingency plan and the recovery and orderly resolution plan, as well as periodically monitoring the adequacy of capital in relation to the Institution’s risk profile. . Risk and Capital Management Committee (CGRC) The CGRC supports the Board of Directors in the performance of its responsibilities relating to the risk and capital management of IUH, submitting reports and recommendations for the Board’s deliberation with regard to the risk appetite, the capital policy, the ICAAP, the capital plan, the contingency plan and the recovery and orderly resolution plan. . Asset Liability Capital Committee (ALCCO) Assesses, monitors and approves matters related to the regulatory and economic capital management of the entire Itaú Unibanco conglomerate, and also assesses the portfolio in light of active Capital and Liquidity constraints. Risk Area: The Risk Area aims to ensure that Itaú Unibanco’s risks are managed in accordance with established policies and procedures, in addition to being responsible for centralizing the institution’s capital management. The objective of centralized control is to provide the Board of Directors and senior management with a global view of Itaú Unibanco’s risk exposures, as well as a forward-looking view of the adequacy of its capital, in order to optimize and expedite corporate decisions. Information-Providing Areas: At the most fundamental level, the areas are expected to provide the information necessary for identifying risks, analyzing their materiality and measuring required capital, as well as for preparing the capital budget, the capital plan, the contingency plan, the recovery and orderly resolution plan, the risk and capital management report – Pillar 3, the ORSA and other regulatory and management reports, ensuring their completeness, integrity and consistency and considering both the expected growth and the evolution of the risk profile of the unit’s businesses. The areas involved in the capital management process must be able to carry out the required actions whenever called upon. The responsibilities of each of the areas involved in the capital management process are detailed in the procedures (specific document). 6 RELATED EXTERNAL REGULATIONS Bacen Circular 3,911, of 08/31/2018.
BCB Normative Instruction 322, of 11/11/2022. CMN Resolution 4,557, of 02/23/2017. CNSP Resolution 471, of 2024. Bacen website with all Prudential Regulation: https://www.bcb.gov.br/estabilidadefinanceira/regprudencialsegmentacao Approved by the Board of Directors in September 2026.
来源:SEC EDGAR · 本站存档