TABLE OF CONTENTS - Santander México · TABLE OF CONTENTS 1. Executive Summary 2. Introduction 2.1...

106

Transcript of TABLE OF CONTENTS - Santander México · TABLE OF CONTENTS 1. Executive Summary 2. Introduction 2.1...

2017 | RISK MANAGEMENT ANNUAL REPORT | 1

TABLE OF CONTENTS

1. Executive Summary

2. Introduction

2.1 Regulatory Environment

2.2 The Scope

2.3 Risk Policy Framework in Banco Santander (Mexico)

3. Integral Risk Management

3.1 Basic Principles of Integral Risk Management

3.2 Instruments for proper Integral Risk Management

3.3 Management and control of risks

3.4 Governance Structure for Integral Risk Management

3.5 Risk Information Management

3.6 Risk appetite

4. Credit Risk Management

4.1 General Aspects

4.2 Credit Risk Cycle

4.2.1 Risk Study

4.2.2 Planning and setting boundaries

4.2.3 Decision on operations

4.2.4 Monitoring

4.2.5 Measurement and Control

4.2.6 Recovery Procedure

4.3 Risk Mitigation Techniques

4.4 Methodologies for Calculating Reserves for Credit Risk

4.4.1 Regulatory framework

4.4.2 Portfolios Authorized to Banco Santander (Mexico) for the use

of internal Calculation of Reserves for Credit Risk

Methodologies

4.4.3 Principles of the Rating System Applied in Banco Santander

(Mexico)

4.4.4 Main Characteristics of Internal Methodologies with Foundation

Approach Authorized to Banco Santander (Mexico)

4.4.5 Main Characteristics of Internal Methodologies with Advanced

Approach allowed to Banco Santander (Mexico)

4.4.6 Internal Rating Systems Control

4.5 Counterparty Risk and Financial Instrument Transactions

2017 | RISK MANAGEMENT ANNUAL REPORT | 2

4.6 Securitization Exposures Information

4.7 Distribution of Exposures by Credit Risk

4.7.1 General Aspects

4.7.2 Exposure by Portfolio Type

4.7.3 Exposure by Remaining Term

4.7.4 Exposure by Federative Entity

4.7.5 Estimates of Credit Risk by Federative Entity

4.7.6 Portfolio Companies by Economic Sector Exposure

4.7.7 Estimates for Credit Risk by Economic Sector Portfolio

Companies

5. Market Risk Management Trading Activity

5.1 Activities Subject to Market Risk Trading

5.2 Basic Principles in Risk Management Market Trading

5.3 Key processes in Risk Management Market Trading

5.4 Trading Market Risk Control

A. Trading Market Risk Metrics

B. Trading Market Control Risk Procedures

C. Figures from the Reporting Period

5.5 Derivative Financial Instruments

6. Structural Risk Management

6.1 Activities subject to Structural Risk

6.2 Basic Principles on the Structural Risk Management

6.3 Key Processes in the Structural Risk Management

6.4 Control of structural risks

A. Figures from the Reporting Period

6.5 Structural Risk in the Equity Portfolio

7. Liquidity Risk Management

7.1 Activities subject to Liquidity Risk

7.2 Basic principles on Liquidity Risk Management

7.3 Key Procedures in the Liquidity Risk Management

7.4 Control of Liquidity Risk

A. Figures from the Reporting Period

2017 | RISK MANAGEMENT ANNUAL REPORT | 3

8. Operational Risk Management

8.1 General Aspects

8.2 Operational Risk Control

9. Capital

9.1 General Aspects

9.2 Function of the Capital

9.3 Calculation of the Capital Requirement for Credit Risk

9.4 Calculation of the Capital Requirement for Counterparty Risk

9.5 Calculation of the Capital Requirement for Market Risk

9.6 Calculation of the Capital Requirement for Operational Risk

9.7 Regulatory Capital

2017 | RISK MANAGEMENT ANNUAL REPORT | 4

1. Executive Summary

With the publication of this report, Banco Santander (Mexico) complies with the obligation set forth in Article

88 of the CUB where banking institutions are obliged to disclose to the public, through its website, information on the comprehensive risk management that takes place on a daily basis in the institution.

Specifically, banking institutions are required to publish the objectives and policies for managing each of

the different types of risk faced, including their strategies, processes, methodologies and levels of risk assumed. The information to be published is classified as both quantitative and qualitative. Quantitative

information shall be disclosed quarterly and qualitative information may be disclosed annually.

The views expressed in this report and statistical information included (unless otherwise stated) comprises

the following institutions:

a) Banco Santander (México), S.A., Institución de Banca Múltiple, Grupo Financiero Santander México. b) Santander Hipotecario, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada.

Grupo Financiero Santander México. c) Santander Vivienda, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada, Grupo

Financiero Santander México.

d) Santander Consumo, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada, Grupo Financiero Santander México.

e) Santander Inclusión Financiera, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada, Grupo Financiero Santander México1.

Through December 2016, the Extraordinary Stockholders General Assemblies of Santander Hipotecario S.A. de CV. and Santander Vivienda S.A de CV. took place, in which the merge of both entities was agreed,

Santander Hipotecario will be the merged company and Santander Vivienda the merger company.

This report is prepared in accordance with applicable mexican regulations in determining exposures, capital requirements for risks and reserve estimate.

Chapter 1 includes this Executive Summary.

Chapter 2 includes generally the Regulatory Framework for Risk within Banco Santander (Mexico).

Meanwhile Chapter 3 deals with Integral Risk Management, and outlines the basic principles and tools for

proper Risk Management. It stresses that for the management of risk inherent in the Bank's operations, it is essential to understand and determine the behaviour of its financial situation and for the creation of a

long-term value, fully attached to the regulatory requirements established by the CNBV (Spanish acronym

for National Banking and Exchange Commission) and Banco de Mexico.

It also delineates how the management and risk control is structured in three lines of defence to develop

three distinct functions:

a) First line of defence: Risk management from its genesis.

1 At the end of December 2017, 3 credits to 26 clients were given, reporting a total investment of MXN105,000, with

an expected loss of MXN2,798. In the information reported in this document, this figures are included in credit to individuals (consumer).

2017 | RISK MANAGEMENT ANNUAL REPORT | 5

b) Second line of defence: responsible for overseeing risk-taking activities across the bank and report

to senior management on risk related items.

c) Third line of defence: Independent review of the risk activity.

Banco Santander (Mexico) has an agile and efficient governance structure that, among other things,

ensures: (i) the participation in risk decisions and in monitoring and control of the governing bodies and senior management; (ii) coordination between the different lines of defence set the functions of

management and risk control; (iii) the alignment of objectives, the monitoring of compliance and the implementation of corrective measures, and (iv) the existence of an adequate environment management

and risk control.

Risk management and control require a high availability of hard data, capacity to analyse these data, and

solid reporting procedures. Banco Santander (Mexico) management of risk information is governed by principles such as responsibility; technology architecture; risk data reconciliation; availability data;

completeness and comprehensiveness; data quality indicators; quality control data; readiness; flexibility and adaptability; prospective approach and availability of documentation; data analysis and expert

judgment.

The third chapter also defines the risk appetite as the maximum level and type of risk that the organization is willing to take, within its risk capacity to achieve its strategic objectives and the development of its

business plan.

Chapter 4 describes major policies and fundamentals for credit risk management, as well as the detail of the key features of the methodologies to qualify the portfolios and determine the amount of the reserves

for credit risk.

From the point of view of credit risk management, segmentation is based on the distinction between three

types of customers:

Individuals: Includes all private persons, except those with an entrepreneurial activity. It

comprises portfolios of non-revolving mortgage loans for housing, credit card and consumer loan

not revolving portfolio.

SMEs, companies and institutions: involves natural and juridical persons with business activity,

as well as public and private entities of non-profit sector.

Global Corporate Banking (GCB): It consists of corporate, financial and sovereign institutions,

which make up a closed list, which is reviewed annually.

Credit Risk goes through a cycle or life process, whose phases are valid for any operation, notwithstanding the important differences that can be seen in the cycles of the risks of different segments, specifically

between the private persons and the companies. 2

Three stages are differentiated in the cycle of credit risk: pre-sale, sale and after-sales.

This process is constant feedback, joining into the study of the risk and into the pre-sale planning and the

2 The processes belonging to the pre-sale stage are those referring to the study of risk and are conducted as a prelude

to the credit risk approval step. The processes that belong to the sales phase are those that take place during the decision approving stage. Finally, the after-sales processes are those that take place after the approval of credit risk.

2017 | RISK MANAGEMENT ANNUAL REPORT | 6

results and conclusions of the after-sales phase.

The processes that take place in each of the above phases are:

a) Study of risk and credit rating procedure.

b) Planning and setting limits.

c) Decision on operations.

d) Monitoring.

e) Survey and Control.

f) Recovery management.

This chapter also details how credit risk is mitigated in general terms, through the use of securities. A

security is defined as a measure of reinforcement added to an operation of credit in order to mitigate the loss in breach of the payment. The security is a component that mitigates the severity of the operation in

case of default. The purpose of the security is to bring down the final operating loss, among other cases, where a long-term operation increases the risk of damage to the customer or because of possible and

relevant external events that could jeopardize the success of the operation and to the creditor, it is difficult

to manage.

Likewise, Chapter 4 explains clearly the criteria under which admission and security management are

governed:

a) Expressly, subsidiary, accessory and essential character of the sureties.

b) Prudent and expert assessment.

c) Rating upgrade.

d) Securities correct Instrumentation.

e) Cautions on the conservation and availability of security.

f) Capacity of execution and settlement of surety.

g) Security block.

h) Security amendment.

i) Security implementation.

j) Security expiration.

Based on CUB provisions, this chapter explains that in order to calculate the reserves for Credit Risk,

institutions may use:

a) Standard Method.

b) Some of the methods based on internal ratings, basic or advanced, provided prior authorization

from the CNBV.

Since 2012 the CNBV authorized Banco Santander to use internal methodologies with the Foundation

Approach3 to corporate businesses, Global Corporate Banking, financial institutions, banks and SME’s. In

3 Under internal Methodologies with Foundation Approach (FIRB), the institutions obtained the Probability of Default

on its positions subject to credit risk, while for the rest of the components of risk, the institutions must conform to the provisions in accordance to Paragraph C Section Three of CUB.

2017 | RISK MANAGEMENT ANNUAL REPORT | 7

October 2015, it allowed the use of internal methodologies with advanced approach4 for calculating credit

reserves for portfolios of SME’s and property developers.

The rest of the chapter details the main features of the internal methodologies authorized to Banco

Santander (Mexico) and includes quantitative information on major exposures of the institution to credit risk. There is also a section on the counterparty risk, which is the one that the institution assumes with

Government, government agencies, financial institutions, corporations, companies and individuals in its Treasury and correspondent banking activities. The survey and control of the credit risk on financial

instruments, counterparty risk, is conducted by a specialized unit and with organizational structure independent of the business areas and control of this type of risk is performed daily, which allows to know

the line of credit available with any counterparty.

Chapter 5 provides information on the activities subject to trading market risk and discusses its

development during this year. It also describes the different methodologies and metrics used in the institution. The perimeter of identification, measurement, control and monitoring of the market risk function

covers those operations that assume the equity risk. The survey of market risk quantifies the potential change in value of the positions taken as a result of changes in market risk factors. The risk arises from

changes in risk factors: interest rate, exchange rate, equity, credit spread and volatility of each of the above, and liquidity risk of the various products and markets in which it the institution operates.

Trading activities include both the provision of financial services to customers, in which the entity is the counterpart, as the activity of sale and own positioning in financial instruments. This heading provided the

positions, which the entity keeps in their trading books. The basic principles of the Trading Market Risk

Management are based on:

a. Independence of trading activities and balance sheet management.

b. Overview of risk assumed.

c. Definition of limits and allocations.

d. Control and monitoring.

e. Homogeneous and aggregated metrics.

f. Consistent and documented methodology.

Additionally, the Chapter 5 explains the metrics and processes used for the trading market risk control:

Metrics:

Value at Risk (VaR).

Stressed VaR.

Value at Earnings (VaE).

Scenario Analysis.

Trading Market Risk Limits Trading.

Proceedings:

Market data retrieval.

Analysis of the metrics and trading market risk positions.

Control of the excesses of limits and products authorized.

Control of insurance operations.

4 In the case of internal Methodologies with Advanced Approach (AIRB), the institutions estimate the Probability of

Default, Loss Given Default, Exposure at Default and Maturity Term.

2017 | RISK MANAGEMENT ANNUAL REPORT | 8

Control of assessment model.

Control of long and short positions.

Control of liquidity.

Price control.

Financial Settlement.

The rest of the chapter includes quantitative information on this type of risk.

Chapter 6 contains information very similar to the one presented in Chapter 5 but in reference to the structural risks. Structural risks consist of market risks inherent in the institution's balance sheet, excluding

negotiation portfolios. This risk includes both losses from price variation affecting the sale and maturity

portfolios available, as losses arising from the management of assets and liabilities. The main structural risks are the following:

Structural Interest Rate risk.

Structural Change Risk.

Structural Equity Risk.

Inflation risk.

Market Liquidity Risk.

Prepayment or Cancellation Risk.

As part of the financial management of the institution, Chapter 6 examines the sensitivity of the financial

margin and the equity value of the various items of the balance sheet against changes in interest rates. This sensitivity arises from gaps in the dates of maturity and modification of interest rates occurring in the

different categories of assets and liabilities. The rest of the chapter discusses the quantitative information on this type of risk.

Chapter 7 is very similar to the previous two chapters but deals with liquidity risk, which is fixed as the

possibility of defaulting obligations on time or with excessive costs. The types of losses caused by these risk losses include enforced sales of assets or impacts on margin by the mismatch between cash outflows and

inflows forecasts. This is the risk of loss of value of the buffer of liquid assets of the entity and is responsible

for the variation of its operating value (derivatives and securities, etc.) which may involve additional collateral requirements and, therefore, worsening liquidity. Liquidity risk is classified into the following

categories:

a) Financing Risk. b) Mismatch Risk.

c) Contingency Risk.

The metrics that Banco Santander (Mexico) used for monitoring and controlling of liquidity risk are:

Ratio of Structural Finance.

Liquidity horizon for a local systemic crisis.

Liquidity Risk Limits.

Liquidity Gap.

Available Liquidity.

Concentration of Funding Sources.

Stress Test.

Liquidity coverage ratio (LCR)

Net Stable Funding Ratio (NSFR)

2017 | RISK MANAGEMENT ANNUAL REPORT | 9

The rest of the chapter includes quantitative information on this type of risk.

Chapter 8 describes the main policies and principles for the management of the operational risk, covering

losses by failures or deficiencies in internal controls, errors in processing and storage operations or transmission of information, as well as adverse administrative and judicial resolutions, fraud or theft, and

comprises, among others, technological and legal risks.

For the identification and grouping of operational risks the different categories and business lines defined by both local regulators and the supervision of the institution they are used. The methodology is based on

the identification and documentation of risks, controls and related processes also uses quantitative and

qualitative tools such as self-assessment questionnaires, the development of historical databases and operating risk indicators, to name a few, both control and mitigation, and disclosure thereof.

For the calculation of regulatory capital required for operational risk the Basic Indicator Approach as defined

in the CUB, published by the CNBV it is used.

Chapter 9 of this report describes the main policies and principles for capital management of the institution and how to calculate the capital requirement. Special mention is made to the internal methodology

authorized for use by Banco Santander (Mexico) by the CNBV to calculate its capital requirement for credit risk.

Capital management in the institution seeks to ensure the solvency of the company and maximize

profitability, ensuring compliance with internal capital targets and regulatory requirements. It is an essential tool for making strategic decisions in their management using the established objectives in determining the

Appetite Risk, planning and Capital budget, as well as the use of metrics that allow to evaluate the

profitability and the creation of their business value.

Capital management begins with the following key aims:

1. Capital Budget.

2. Planning Capital.

3. Establishment of Risk Appetite.

4. Minimum criteria.

Capital policies that set the general guidelines are specified, which must govern the actions of the areas involved in the processes of management and control of capital.

Autonomy of the Capital.

Centralized Monitoring.

Proper distribution of own resources.

Strengthening Capital.

Capital Preservation.

Prudent management.

Maximizing value creation.

The rest of the chapter includes quantitative information on capital management and some metrics as the

probability of default and the credit risk weights.

2017 | RISK MANAGEMENT ANNUAL REPORT | 10

2. Introduction

2.1 Regulatory Environment

During 2017 a number of amendments to the general provisions applicable to credit institutions (Circular

Applicable to Credit Institutions, CUB) were made; mainly seeking stability and the correct functioning of the Financial System, also aiming to decrease cost of credit, enhance Bank’s security and continue aligning

the Mexican Regulation with international regulative standards (Basel)5.

Also in this year amendments were issued on:

Credit Risk: Revolving Consumption Credit Score Methodology

In order to better reflect the credit risk incurred by credit institutions:

The rating methodology of the non-revolving and mortgage credit portfolios and their

associated regulatory reports are updated by incorporating new dimensions of credit risk,

such as the level of indebtedness of each client, their payment behavior in other financial and non-financial entities, as well as the specific risk profile of each product.

A portfolio rating methodology for microcredits is established.

The loss severity estimation is specified for the calculation of preventive reserves, when the collateral guarantees are recognized, in order to reduce the amount of preventive reserves derived from the credit

portfolio rating, similarly, the term to constitute 100% of the amount of credit risk reserves that correspond to portfolios of non-revolving consumer, mortgage and microcredit is extended, in accordance with the new

applicable methodology, also the time Financial Institutions should disclose such information in their financial statements and through other public communications is specified.

Credit Risk: Agricultural loans credit score methodology

The prices’ coverage that some borrowers have is recognized in the calculation of preventive reserves for

credit risk for agricultural loans, in order to adequately reflect the risk incurred by the institutions.

Counterparty Risk

A weighted credit risk equal to 0% is established for the operations carried out by credit institutions with

Banco de Mexico, which are subject to an additional capital requirement due to credit valuation adjustments for derivative transactions.

Capital Risk

In order to align the applicable treatment to the implicit support scenario with the international standards

issued by the Basel Committee for Banking Supervision, and adequately reflect the risk incurred by credit institutions when they update the assumption of granting implicit support to securitization structures in

which they act as originators or transferors of the underlying assets, and avoid excessive capital

requirements when updating those assumptions, the obligation of maintaining capital for all the underlying

5 Reference: CNBV regulatory newsletter; released at www.cnbv.gob.mx

2017 | RISK MANAGEMENT ANNUAL REPORT | 11

assets of the current securitization schemes is limited only to the securitization structures for which implicit support had been granted.

Clarifications are made in the capital requirement definition which credit institutions must have to support

their credit risk; the treatment to be applied by credit institutions for the calculation of market risk capital

requirements is modified for the investments they make in social equity of brokerage houses and securities’ deposit institutions in order to reflect their risk as any other similar instrument; regarding the use of internal

models, credit risk measurement of portfolios granted to micro, small and medium enterprises is improved.

Market risk

The accounting criteria applicable to credit institutions’ held to maturity securities is adjusted extending the

period by which they may be sold or reclassified before their maturity, without affecting the ability to use

the securities’ category.

Additionally, in order to achieve greater adherence and consistency with the international regulations

established in the International Financial Reporting Standards, the requirements of isolated events that are outside the control of the credit institution are specified.

Operational Risk

The procedures and mechanisms that credit institutions use to identify any possible client identity

supplanting are strengthened.

Feasibility Plans

It is specified that only Banks classified as Domestic Systemically Important Banks, will be required to

update their contingency plans during March of each year, while the rest of the institutions must do it every two years.

2.2 Scope

The information in this report, as well as including statistical data (unless otherwise stated) comprises the

following institutions:

a) Banco Santander (México), S.A., Institución de Banca Múltiple, Grupo Financiero Santander México. b) Santander Hipotecario, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada.

Grupo Financiero Santander México. c) Santander Vivienda, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada, Grupo

Financiero Santander México.

d) Santander Consumo, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada, Grupo Financiero Santander México.

e) Santander Inclusión Financiera, S.A. de C.V., Sociedad Financiera de Objeto Múltiple, Entidad Regulada, Grupo Financiero Santander México.

2017 | RISK MANAGEMENT ANNUAL REPORT | 12

It is important to recall that through December 2016, the Extraordinary Stockholders General Assemblies of Santander Hipotecario S.A. de CV. And Santander Vivienda S.A de CV. took place, in which the merge of

both entities was agreed, Santander Hipotecario will be the merged company and Santander Vivienda the merger company.

This report is prepared in accordance with applicable Mexican regulations in determining exposures, capital

requirements for risks and reserve estimate.

Statistical information as well as accounting financial statements come from reports regulatory sent to the CNBV and the Banco de Mexico, for the characteristics of the portfolio of the institution (credit by credit

information). The CNBV, through its website, has recognized the high quality of the information sent by the institution, and recommends its use without restriction.

2.3 Risk Policy Framework in Banco Santander (Mexico)

The internal manuals for Risk Management are technical documents that contain policies, procedures, data

flow diagrams, models and methodologies necessary for the management and analysis of the different types

of risk and requirements processing systems of information.

The risk internal regulation of Banco Santander (Mexico) develops in the following types of documents:

1. Corporate Frameworks: reflected the general principles and define the framework for action to be

adjusted to other more concrete documents.

2. Models: develop frameworks or particular aspects thereof; specify the principles, processes and

responsibilities, governance and instruments of regulated activity.

3. Risk policies: set quantitative limits and qualitative criteria to be observed in the processes of risk

decision.

4. Regulations: meets the inner workings of the committees and other joint decision or deliberation

forums.

5. Procedures: detail the embodiment of a process or set of processes.

6. Guidelines: collect additional elements to the internal rules, necessary for a complete replication of

the process or for a better understanding of them.

The internal regulation of risk within Banco Santander (Mexico) provides documentation that Risk

Management be developed in compliance with the principles described in Table 1A.

2017 | RISK MANAGEMENT ANNUAL REPORT | 13

Table 1A Principles that complies the documentation of Banco Santander (Mexico)

Reflection of risk management All relevant activities of the risk function should be duly regulated. Internal risk regulations should reflect the way in

which risk is managed in the entity, but should also be used to encourage the evolution of activities towards best practices.

Responsibility of the regulations

Those responsible for the risk activities have to ensure that

their activity is regulated in accordance with the risk policy

model and in line with external regulations or standards.

Governance of the regulations Control (validation) and governance procedures have to be established to enable authorities to be assigned to approve each

document type at the pertinent level, including the due weighing up of opinions and consultation of all those involved.

Coordination of the regulations Producing consistent regulations, disseminating best practices,

transferring knowledge and ensuring efficiency in the development of internal regulations requires extensive

coordination in their development process, between both the

Group's different units and the affected functions.

Accessibility and knowledge of

the internal regulations

The internal risk regulations will be accessible to all affected staff

members, and the training activities necessary for awareness of

these should be promoted. Use of reference documents The regulatory development of those aspects for which there are

reference documents has to be based, insofar as possible, on these, in order to add consistency to the Group's regulations and

promote the use of best practices.

The governance of the internal regulations of risks is carried out through the support of several committees:

Board of Directors: responsible for approving and modifying the general risk policy.

Comprehensive Risk Management Committee (CRMC): responsible for validating and ratifying

frameworks, models and policies for comprehensive risk management, based on the objectives,

guidelines and policies established by the Board of Directors.

Risk Policy Committee: approver of the risk policy documents and its prior validation regarding

risks or others that may have implications for the risk area.

3. Integral Risk Management

3.1 Basic Principles of the Integral Risk Management

Risk management is considered by Banco Santander (Mexico) as a competitive element of strategic nature

with the purpose of maximizing the value for the stockholder. This management is defined, from a conceptual and organizational sense, as a comprehensive management of the different risks assumed by

2017 | RISK MANAGEMENT ANNUAL REPORT | 14

Banco Santander (Mexico) for the development of its activities. Managing the risk inherent in the operations of the Bank is essential to understand and determine the behavior of its financial situation and to create

long-term value; entirely, it is attached to the regulatory requirements established by the CNBV and Banco de Mexico.

The Integral Risk Management is defined as the set of actions required for identification, decision,

measurement, evaluation, monitoring and control of all risks.

On a fist level, the Risk Map that the institution has defined includes the following types of risk:

Credit Risk: this risk is caused by the possibility of losses arising from the total or partial

failure of the institution financial obligations by its customers or counterparts.

Counterparty Risk: is the risk that the counterparty to a financial contract will default prior

to the expiration of the contract and will not make all the payments required by the contract.

Counterparty risk applies to the following financial instruments: derivatives, repurchase

transactions, and securities lending.

Market Risk: risk incurred as a result of the possibility of changes in the market that affect

the value of the positions in trading portfolios.

Structural Risk: menace caused by the management of the different items of the balance

sheet, including those relating to the sufficiency of own resources and those arising from the

activities of insurance and pensions.

Liquidity Risk: crisis of failing to meet payment obligations on time or doing so with an

overcost.

Operational Risk: risk of losses by deficiencies in internal controls, errors in processing and

storage operations or transmission of information, as well as adverse administrative and legal Resolutions, fraud or theft; includes, among others, the technological and legal risks:

Legal Risk: potential loss by failure to comply with the applicable legal and

administrative provisions, the issuance of unfavorable administrative and judicial

resolutions, and the application of sanctions, in connection with the transactions which the institution carries out.

Technological Risk: potential losses from damage, interruption, alteration or failures

derived from the use of hardware, software, systems, applications, networks and any other means of transmission in the provision of banking services to customers of the

institution.

Conduct Risk: risk occasioned by inadequate work placements and the relationship between

the bank and his clients, as well as the treatment of products offered to their clients, also the

customization of their products to their clients.

Model Risk: acknowledge of losses originated by decisions made mainly by the outcome of

the models, this comes because mistakes made in the inception, application and use of this

models.

Reputational Risk: damage made by the perception of the bank form the public opinion,

clients, investors, or any other stakeholder.

Risk Management at Banco Santander (Mexico) is governed by different principles, which are aligned with

the strategy and business model of the institution:

a) Incorporation of a Risk Culture.

2017 | RISK MANAGEMENT ANNUAL REPORT | 15

A strong risk culture, extending to all areas and employees and covers all types of risks is promoted. This culture includes a set of attitudes, values, skills and guidelines from the

dangers integrated into all processes, including decision making change management and strategic planning and business.

b) Involvement of senior management.

There is a direct participation of the governing bodies and senior management in the

development and implementation of risk culture, as well as in the management and control

thereof.

c) Independence of the risk function.

The risk function operates independently to other competitions, covering all risks and providing adequate separation between the generating areas of risk and those responsible

for its control and supervision. It has sufficient authority and direct access to the bodies responsible for setting and monitoring of the strategy and policies of management and

Government risks.

d) Definition of Risk Appetite.

A key aspect of risk management is the definition of the risk appetite that determines the

amount and type of risks considered reasonable to assume in the execution of its business strategy. The risk function boosts its definition, as well as its continuous control.

e) Comprehensive Consideration of Risks.

The identification and assessment of all risks that might impact on the income statement or

capital position are basic premises to enable its management and control. The management and risk processes cover all activities and businesses. Risk management considers both the

risks generated directly as those originating from outside the institution, but which may still

affect it.

f) Organizational Model and Governance.

A model assigned to all risks, responsible for management and control while preserving the principle of independence and with clear and consistent reporting mechanisms.

g) Decision in Collegiate Bodies.

Decision-making through collegiate bodies is an effective tool to facilitate a proper analysis

and different perspectives to be considered in risk management. The decision-making

process includes a neat contrast of opinions provided to the potential decision impact and

the complexity of the factors that may determine it. The risk governance model not only

identifies the different bodies that compose it, but also defines the granting of faculties and

powers of each of them.

h) Anticipation and Predictability.

Risk assessment is an eminently proactive vocation, in order to estimate the evolution of

risks in different scenarios and time horizons. Therefore, it focuses on the future projection of all those variables that determine the results. Whenever possible, the intention is that the

risk assessment should include its quantification or measurement. The quantification of the

risk is based on widespread use of models. In cases where this is not feasible, risk assessment aims to identify the elements of greater incidence on the probability of occurrence of a loss

event and its impact, in order to facilitate the implementation of mitigation measures and controls.

i) Risk Limitation.

All financial risks incurred are subject to objective, verifiable and consistent limits with risk

appetite, both in regard to the types of acceptable risk and its quantitative level. The limits

2017 | RISK MANAGEMENT ANNUAL REPORT | 16

are allocated to the various types of risk, as well as the different activities and businesses. For non-financial and cross-cutting risks consistent tolerance level is set with its nature.

3.2 Adequate tools for Risk Management

All risks in its various manifestations should have a responsible for control and management. Also, the

structure of the risk function is proportional to the nature, scale and complexity of its activities.

The institution has the following essential tools for a proper performance of Risk Management:

Table 3A Tools for Risk Management

A regular process for identifying

and assessing all risks

A periodic process simulation of the evolution of relevant risk factors and their impact on the capital

and results

A uniform risk reporting framework with common

standards and metrics

Periodic planning processes of capital

and liquidity

Periodic (technological and operational) contingency and

business continuity plans

Periodic plans of feasibility and,

where appropriate, of

resolution.

2017 | RISK MANAGEMENT ANNUAL REPORT | 17

3.3 Management and Control of Risks

The management and control of risks is structured in three lines of defense that developed three different functions:

a) First Line of Defense: Risk Management from its generation.

The first line of defense consists of lines of business or activities that originate the exposure

to risk in the institution as part of its activity. The generation of risk in the first line of defense is set to appetite and defined limits. To serve its function, they have the means to identify,

measure, manage and report the risks assumed. b) Second Line of Defense: Control and Consolidation of Risks, Monitoring its Management.

The second line of defense is made up of teams specialized in risk control and supervision of the management of them. This line is responsible for the effective control of risks and ensures

that they are managed according to the level of risk appetite defined by senior management;

is responsible for the identification, measurement, management and reporting of the risks involved, without prejudice the needs of the first line for a proper management. Promotes

the development of a common culture of risk, and provides guidance, advice and expert judgment in all matters related to risks, constituting the point of reference for the entity to

these themes, as well as to propose methodologies of measurement and analysis.

c) Third Line of Defense: Independent Review of Risk Activity.

As a third line of Defense, are Internal Audit processes. Periodically evaluates that the policies, methods and procedures are appropriate and checks that they are effectively

implemented in the operational management of the institution.

The management and control of risks includes processes of different natures which, according to their scope

and complexity, may differ in: (i) strategic management processes, which are those that form part of the

definition, implementation and monitoring of the risk strategy; (ii) the decision processes are taking place

to adopt and adequately implement concrete decisions that require management and risk control and (iii)

instrumental processes are necessary to make possible the above. An overview of these processes is

included in Table 3B.

2017 | RISK MANAGEMENT ANNUAL REPORT | 18

Table 3B: Risk Management Processes

Strategic Management Processes

Formulation and monitoring the Bank's risk appetite.

Defining the types and levels of risk consistent with the objectives.

Identification and implementation of strategies and activities to achieve and maintain

the desired risk profile.

Evaluation of the effectiveness of these deviations and the objectives pursued.

Setting targets and metrics to control it and follow it.

Decision Processes

Origination: They occur before effectively take the risk. These processes determine

whether to assume new risks.

Anticipation: they are intended to prevent situations of increased level of risk and

facilitate the adoption of corrective measures.

Mitigation: They cover the decisions to reduce the consequences of the events of loss,

both before and since such events occur. The key elements of mitigation processes

are anticipation and early identification of loss events; the development of specific

mechanisms for the management of these events and the agility in implementing these

mechanisms.

Instrumental Processes

Identification of the risks associated with operational activity or business.

Evaluation and measurement of risks, which aims to obtain an estimate of the

likelihood of different scenarios of loss as well as the potential impact of each.

Monitoring and control processes, ensures the continuous availability of updated

information on the levels of risk assumed in the development of a business. Also cover

policies and procedures compliance.

The information, which includes the generation, dissemination and provision of

relevant people the necessary information to know and assess the situation of the risks

and be able to take decisions and actions needed.

Governance Structure for Risk Management

Banco Santander (Mexico) has a structure of agile and efficient government that, among other things,

ensures: (i) participation in risk decisions and in monitoring and control of the governing bodies and senior management; (ii) coordination between the different lines of defense which set the functions of

management and risk control; (iii) alignment of objectives, monitoring compliance and implementation of corrective actions and (iv) existence of an adequate environment management and risk control.

To achieve these objectives, the scheme of the Committees Governance Model within the Bank is designed

to ensure adequate:

a) Structure: It implies, at least, the stratification according to the levels of relevance, balanced

capacity of delegation and the elevation of incidents protocols.

b) Composition: With members of sufficient level of dialogue and appropriate representation of

the business and support areas.

c) Operability, the frequency, level of minimum assistance and timely procedures.

2017 | RISK MANAGEMENT ANNUAL REPORT | 19

In Banco Santander (Mexico), risk decision-making bodies start from the Board of Directors towards the administrative units responsible for the management and control of each one of them.

Board of Directors

In terms of risks, among other things, the Board of Director is responsible for establishing the model

of management and control of risks and to formulate the appetite for risk of the entity and to conduct

a regular monitoring of the adequacy of the risk profile of the institution to the defined risk appetite.

It establishes the minimum requirements of balance between profitability and risk of business or

activities and makes decisions on operations or specific limits.

Comprehensive Risk Management Committee (CRMC)

The CRMC aims to manage the risks to which the institution is exposed, as well as monitor that the

operations, complies with the objectives, policies and procedures for the Integral Risk Management

(IRM) and the global limits of exposure to risk, that they have been previously approved by the Board

of Directors.

The functions of the Committee are:

Propose to the Board of Directors for approval: Objectives, guidelines and policies for IRM, as well as any modifications made to them.

Global limits of exposure to risk and specific risk exposure limits, considering:

− The Consolidated Risks, broken down by business unit or risk factor, cause or origin, as set out in Articles 79-85 of the CUB and, where appropriate, risk

tolerance levels. − The mechanisms for the implementation of correctives actions.

− The cases or special circumstances that may exceed both the global limits of exposure to risk as a specific risk exposure limits.

Approve:

An exceptional specific limits adjustment and secondary of the risk appetite was made, when the Board had the faculties and approval com the Executive risk Committee, the

risk levels tolerance (once a year), as well as the liquidity risk (article VIII).

Specific risk exposure limits, when the Board has delegated authority to do so, the levels of risk tolerance and liquidity risk indicators (Article 81 fraction VIII of the CUB).

Methods and procedures to identify, measure, monitor, limit, control, report and disclose the different types of risk to which the institution is exposed.

Models, parameters, scenarios, assumptions, including those relating to stress testing

established for liquidity risk (Annex 12-B CUB), to be used to carry out the assessment, measurement and control of risks to propose IRM.

Methodologies for the identification, evaluation, measurement and control of the risks of new operations, products and services that are intended to offer the market.

Corrective actions proposed by IRM as provided in section 69 of the CUB. Manuals for the CUB, according to the objectives, guidelines and policies established

by the Board. These must be technical documents containing, among others, policies,

procedures, data flow diagrams, models and methodologies necessary for the management of the various types of risk (Article 78 of the CUB).

Technical Evaluation of the AIR (Article 77 of the CUB) for presentation to the Board and Committee.

Report of Technical Evaluation (Article 77).

2017 | RISK MANAGEMENT ANNUAL REPORT | 20

Assign (remove), notifying the Board of Directors, the responsible for Comprehensive Risk Management Unit.

Report to the Board at least quarterly:

Risk profile of the institution. Exposure to risk assumed by the Institution.

The adverse effects which could occur in the operation thereof.

The non-compliance of the desired risk profile, limits of exposure to risk and levels of risk tolerance established.

Corrective actions implemented (Article 69 of the CUB).

Ensuring awareness by all personnel involved in taking risks:

Desired risk profile.

Limits of exposure to risk.

Levels of risk tolerance.

Report to the Board at least once a year:

Business Continuity Plan. Effectiveness test of the Business Continuity Plan.

Approve methodologies for estimating quantitative and qualitative impacts of operational contingency referred to in Article 74 fraction XI of the CUB.

Adjust or authorize the excess on specific risk exposure limits:

Exceptionally. Approval of the Board.

According to the objectives, guidelines and policies for Integral Risk Management When the conditions and environment of the institution so require.

Request to the board, the adjustment or the authorization to exceed, by way of

exception, the global risk exposure limits.

Executive Committee of Risks

The Executive Committee of Risks is intended for all the Bank's risks, ensuring the proper identification,

measurement, monitoring, control, reporting and risk mitigation, and the availability of means for adequate

risk management.

The Committee's functions are as follows:

Propose to the relevant committees of Bank risk appetite.

Approve the specific risks levels or secondary risk appetite when the conditions in the institution

environment requires, this will be informed to the board of directors

Propose the methodology of Risk Identification and Assessment (RIA) of the Bank.

Suggest risk management models.

Evaluate the procedures in risk according to the normative corporate models.

Approve the creation and modification of Risk Committees according to the corporate

governance

Follow the Bank Risk in all areas.

- Credit Risk: (i) Propose additional credit provisions required, (ii) approve credit operations

as deemed appropriate and (iii) follow operations/customers whose size could have a significant impact on the Bank's results.

- Market Risk: (i) Operational know as they consider appropriate, (ii) follow-up of limits whose size can have a relevant impact on the Bank's results.

2017 | RISK MANAGEMENT ANNUAL REPORT | 21

- Operational Risk: (i) Monitor the budget/size limits that may have a significant impact on

the Bank's results.

Take the necessary measures to comply with the recommendations of the regulator and the

auditors.

Approve the corresponding provisions models and monitor their proper implementation.

Supervise and approve the monthly calculation of provisions, ensuring the sufficiency of

provisions in accordance with the regulations, as well as follow up on the agreements or application plans that are defined in this regard, including those that refer to modify the final

amount in cases that he considers it convenient.

Committee of Risks Control

The Committee of Control Risks has the power to monitor and control the risks of the Bank, giving a comprehensive, regular and adequate monitoring of all risks identified in the risk map of the general

framework of risk, reporting and, if necessary, appropriate scaling the alerts to higher organisms.

The Committee's functions are as follows:

Review the determination of risk appetite and the defined strategy for its management.

Monitoring methodology Risk Identification and Assessment and monitoring the resulting

assessment.

Ensure the implementation of Organizational Model Lines of Defense, at three levels: Risk Managers, Risk Drivers and Audit, clearly defining roles and responsibilities.

Supervise the fulfillment of the normative model of risks and their specific principles, in

particular to define, evaluate and follow up the policies of risk deemed appropriate.

Validate the existence, updating and dissemination of Governance Risk Model, which defines

the risk decision-making bodies, their powers, members and delegated powers.

Assess scenarios and assumptions to be used in conducting stress tests.

Follow up on recommendations from the audits of regulators and auditors.

Inform to the Executive Committee of Risks about important deviations, identifying sources of

concern.

Committee of Information Management and Data Quality

The Committee of Information Management and Data Quality is the body responsible for ensuring compliance and periodic review of Risk Information Framework and the implementation of the actions

necessary to improve them, taking care to ensure the correct treatment of the information for the proper management and risk control of the unit, ensuring proper quality of data and processes necessary to their

availability, extraction, aggregation and analysis.

The Committee's functions are as follows:

Promote the preparation of documentation that supports the government of the data and its elevation to the corresponding statutory governing bodies for approval and ensure compliance.

Review and approve the relevant modifications in the data governance process.

Approve data quality objectives and follow-up reporting on compliance to government bodies

Approve certification reports, establish mitigation plans and send to the corporate counterpart

committee for ratification.

Propose, approve and supervise all activities related to the identification, evaluation and management of the quality of risk data and with the information and aggregation of risk data.

2017 | RISK MANAGEMENT ANNUAL REPORT | 22

Validate and communicate any limitation that prevents a complete aggregation of risk data in the reports.

Follow the status and quality indicators of the risk data and other properties thereof.

Assess the status of the risk information processes, reporting relevant incidents to the Risk

Executive Committee and executing the necessary measures to ensure that the required standards are maintained.

Ensure the execution of the measures determined by the highest administrative body in relation to the data aggregation processes and the presentation of risk reports, coordinating the

necessary functions and proposing other actions that may be necessary.

Propose and approve improvements and modifications applicable to the risk information model, governance of information and data and validate its application status and compliance with

regulatory principles and requirements, in accordance with the regulatory risk model.

Receive, prioritize and coordinate all requirements related to risk reports.

Approve local taxonomies of risk and data reports and their modifications; as well as adhering

to corporate taxonomies.

Approve the certification procedure and the risk information model, governance of information and data according to the regulatory risk model.

Review projects related to the aggregation processes and the generation of risk reports.

Committee of Operational Risk

The Committee of Operational Risk observe the identification, mitigation, monitoring and reporting of

operational risk, survey the compliance with the Framework of operational risk limits and risk tolerance policies and procedures in this subject. Oversees the identification and control of current, emerging and

operational risks, their impact on the risk profile and the integration of identification and management of operational risk in their decision-making processes.

The Committee's functions are as follows:

Promote and review the availability of the Framework and Model Operational Risk Management,

policies that develop and follow its implementation and development in the Institution.

Monitor the evolution of the operational risk profile through information provided by the

established tools (loss database, self-assessment questionnaires, risk indicators, business

environment, scenarios and metrics defined) as well as through other sources (customer claims, technological incidents, audit reports and supervisors, etc.) and check the evolution of the

established metrics, raising, where necessary, appropriate alarms.

Perform the monitoring of operational risk losses annual budgets.

Review the main events of each period, determining if they fit into the categories of operational

risk. In which case, analyze the causes and identify the controls set.

Advise on issues appetite and tolerance for operational risk.

Propose, approve or validate, as a result of the powers assigned, action plans, mitigation

measures and monitoring plans and identified current controls.

Recommend the beginning of thematic reviews on specific processes or sources of risk.

Understand, assess and monitor the observations and recommendations made by supervisory

authorities and by Internal Audit in relation to operational risk.

2017 | RISK MANAGEMENT ANNUAL REPORT | 23

Track changes and developments of the regulations related to operational risk, assess the

issuance of comments by the Bank in this regard and further plans of action for its

implementation.

Contribute to the development and implementation of the culture of operational risk

management in the organization, through training programs, meetings and other outreach

initiatives.

Monitor the implementation of programs and initiatives of a corporate nature and/or regulatory.

Participate in the revision and issue the opinion of different versions of the plans, like the

previous process to the presentation others committees if is the case, and the formal approval

of the government.

Assist the consultative committee regarding technical questions about the content plans

Define steps to be taken along with a responsible in order to reduce the operational risk

exposure for action drivers and issues identified by Operational Risk environment.

Guarantee that the business continuity plans and procedures are developed and updated for

Grupo Financiero Santander Mexico, as well as to ensure that the trials and drills as will be

effective according to the corporate policy and local regulation, ensuring an effective response

and continuity of the business in case any contingency will be presented.

Committee of Capital

The Capital Committee is responsible for the supervision, authorization and valuation of all aspects related

to the capital and the solvency of the Institution.

The functions of the Committee are the following:

a) Supervise:

The analysis of solvency and capital adequacy.

Compliance with budgets, capital planning and stress test analysis.

Monitoring of capital consumption, RORAC and EVA, of the institution and by businesses.

Monitoring of all aspects related to the implementation of advanced models.

Regarding capital management, the eventual decision to activate the Feasibility Plan in

terms of solvency, as this is established corporately, as it will be responsible for submitting

it to the CAIR.

b) Authorize:

Review and validation of capital planning and stress test exercises prior to their internal

and corporate approval or presentation to the corresponding supervisory authority.

Changes in capital models and methodologies, considered relevant for internal purposes,

accompanied by the report of the independent validation area, previously presented in the

Local and Corporate Models Committee for risks under the perimeter of competence of the

General Risk Department.

For the purposes of this framework, relevant changes are considered, those whose impact

exceeds a threshold of 1% of the Group's capital consumption. Annually, all the changes

made to capital models and methodology will be raised for consideration by CAIR.

Identification of proposals.

Capital objectives for the planning horizon contemplated in the Capital Self-Assessment

Report.

2017 | RISK MANAGEMENT ANNUAL REPORT | 24

Optimization of capital consumption.

Improvement of solvency ratios.

Improvement of capital models and the integration of these in management.

In terms of capital, this Committee coordinates the relationships with the supervisors and the flow

of information (Capital, RORAC and EVA) to the market.

3.4 Management of Risk Information

Risk management and control require high availability of hard data, ability to group and analyze these data as well as solid reporting procedures. The management of risk information in Banco Santander (Mexico) is

governed by the following principles:

a) Responsibility: The Board of Directors is ultimately responsible for ensuring the implementation

of the framework for managing Risk Information.

b) Technological Architecture: It has a technological architecture for each type of risk that ensures

that risk information and baseline data provide answers to the general requirements established

for the Institution and reporting risks.

c) Reconciliation of risk data: The risk information is reconciled with the accounting data to ensure

the accuracy of it, and, where appropriate, with other relevant sources that may exist.

d) Data Availability: data are available ensuring an appropriate level of detail for certain users

identified at all times through appropriate access credentials. The relevant users regarding risks

have full access to risk data to ensure that they can be added, validate and reconcile properly

with risk reports.

e) Completeness and Exhaustiveness: Reports of risk management and aggregation criteria cover

all material risks consistent with the risk map.

f) Indicators of Data Quality: They are defined quality indicators covering aspects such as accuracy,

integrity, completeness, tolerance and availability in both normal and stress situations.

g) Data Quality Controls: There are controls over processes in order to ensure data quality at all

levels.

h) Promptness: The reports should be available in the manner and time established, taking into

account the nature and volatility of the risk involved and the relevance of the report.

i) Flexibility and adaptability: The risk management reports are prepared according to the needs

of the organs and the key areas involved in risk management and monitoring.

j) Forward-looking Approach and availability of documentation: The risk reports contain, where

relevant, the likely path in the Bank's capital situation and risk profile thereof, and provide

information on estimates and forecasts in different scenarios, analyzing and identifying stress

levels and trends of emerging risks.

k) Data analysis and Expert judgement: The reports are both descriptive and prescriptive and

provide quantitative and qualitative data, including explanations, recommendations and

conclusions.

l) The above principles are developed through the implementation of various key processes in the

Information of Risk Management:

− Data availability: The aim is to have a common infrastructure, accurate and reconciled on

different variables to respond to multiple requests for information necessary. To do this,

the information requirements are set; selected data needed to satisfy these requirements

are identified; data source systems are extracted; the source data is transformed into the

required data and data stored in repositories available for the exploitation and use thereof.

2017 | RISK MANAGEMENT ANNUAL REPORT | 25

− Aggregation of Data: The aggregation process is driven by a particular data structure based

on different criteria and rules that allow a precise and homogeneous grouping of data in

order to generate different views of information, responding to needs analysis different

users.

− Analysis and use of information: The data and risk information are available for use in a

homogeneous, flexible and with sufficient granularity environment, also are easily

understandable and accessible in a timely manner for use, analysis and distribution. The

information is available for use in both the reporting and other requirements for the

management processes and risk control.

- Reporting and distribution to third parties: The process of reporting and distribution

guarantees it is available to all relevant parties. That provision, its form and frequency

depends on the relevance and materiality of informed risk and should be done on time and

according to established schedules.

The Committee of Information Management and Data Quality ensure adequate quality of the data and the processes needed for its availability, extraction, aggregation and analysis, and its main functions are:

a. Promote the development of the documentation supporting the government data.

b. Review and approve any significant changes in the process of government data.

c. Approve the data quality objectives (criticality, indicators, tolerances, quality plans).

d. Propose, approve and monitor all activities related to the identification, assessment and

management of data quality and risk information and risk data aggregation.

3.5 Risk Appetite

Risk appetite is the maximum level and type of risk the organization is willing to take, within its risk capacity

to achieve its strategic objectives and the development of its business plan.

The risk capacity is the maximum level and nature of risks that the company can assume without

compromising its viability, determined by the level of sufficient resources (capital, liquidity, asset and liability management systems and capabilities) to develop the activity the entity to the demands of

regulators, governments, shareholders, investors, customers, employees, suppliers and social community.

The Risk Appetite Framework (RAF) is the set of instruments that articulate the risk appetite of the institution. The risk appetite is expressed, in general, aggregate and by type of risk, in Risk Appetite

Statement (RAS). The RAS sets, using quantitative metrics and qualitative indicators, the criteria to be submitted to the Bank's risk exposure in both current conditions and under different future stressed

scenarios.

The criteria set by the RAS are taken into account and respected throughout the developing taken of the

other elements that constitute the RAF, which are developed to the level of detail necessary, policies, limits

and other criteria applicable in different lines of business and types of risk. The risk limits are all the

quantitative and qualitative limitations that distribute and move the restrictions set in the RAS to the different

business lines, specific categories of risk or any other relevant level of disaggregation.

The risk appetite considered desirable risk profile of both the present,medium and long term. When

analyzing the possible evolution of the risk profile, both considered the most likely circumstances as other

unfavorable situations (stress scenarios). It incorporates quantitative metrics and qualitative indicators

2017 | RISK MANAGEMENT ANNUAL REPORT | 26

relating to key performance indicators, which are aggregated, understood by the entire organization and

clearly reflect the reasons for taking or not taking risks in decision-making processes.

Risk appetite is integrated into the management through a dual approach bottom-up and top-down:

Top-Down Vision: The Board of Directors leads the fixing of risk appetite, ensuring its

disintegration and translation of specific limits that are set at portfolio level, business unit or

line.

Bottom-Up Vision: the risk profile that contrasted with risk appetite is determined by the

aggregation of measurements made at the portfolio level, unit or business line. The risk

appetite of the entity arising from the consideration of the business objectives and their

interaction with the potential risks to take and existing capabilities.

The maximum management body, The Board of Directors, is responsible for determining and approving

risk appetite; It promotes its articulation in the form of policies and limits to ensure its implementation, communication and monitoring. The Board of Directors and the Risk Management Authority, it is up to

formulate the risk appetite of the entity, identifying its development elements and assign responsibilities for it, and perform periodic monitoring of the adequacy of the risk profile of the entity risk appetite defined.

The Executive Risk Committee is responsible for ensuring the consistency of the actions of the Bank's risk

appetite determined by the Board of Directors, and approves actions on the level of risk in light of the analysis and monitoring of risk appetite.

2017 | RISK MANAGEMENT ANNUAL REPORT | 27

4. Credit Risk Management

4.1 Overview

The credit risk arises from the possibility of losses derived from the total or partial failure to meet financial obligations to the institution by its clients or counterparties. The credit risk is caused by the possible failure

to pay by the accredited both in lending operations that have involved a payment and those that do not

involve any but whose performance is guaranteed by the Bank.

Segmentation from the point of view of credit risk management is based on the distinction between three

types of customers:

Individuals segment includes all natural person except for those with business people.

Includes holdings of residential mortgage, credit card and non-revolving consumer portfolio.

SME’S, Companies and Institutions including legal entities and individuals with business

activity. In addition to public sector entities and private sector entities nonprofit.

Global Corporate Banking (GCB) is composed of corporate, financial and sovereign

institutions, which make up a closed list reviewed annually. This list is determined by a

thorough analysis of the company.

The governance of the Credit Risk Management is a committee structure that are responsible, among other

things, the following functions:

The decisions on ratings, operations and risk limits, within the powers that have been granted

by the bodies envisaged in the general framework of risk and credit risk and its monitoring.

Validation and supervision of policies of credit portfolios.

Validation and monitoring of annual plans portfolios.

Monitoring the performance of exposures.

These committees, in appropriate cases, will have representatives of the business functions and may

delegate the functions they consider relevant in other organs, with the relevant regulations of these

committees to establish the process of granting powers and duties of each of them, including qualitative

and quantitative limits that define its scope and decision.

The credit risk is undoubtedly the most important risk in banking

Possible Causes: Insolvency of accredited.

Related-party transactions. Excessive concentration. Inadequate guarantees.

Other causes.

Table 4A Causes of Credit Risk

2017 | RISK MANAGEMENT ANNUAL REPORT | 28

4.2 Credit Risk Cycle

The risk management process consists in identify, analyze, control and decide, where appropriate, the risks incurred by operations of Banco Santander (Mexico). During the process involves both business areas and

senior management.

Credit Risk through a cycle or life process, whose phases are valid for any operation, notwithstanding the important differences that can be seen in the cycles of the risks of different segments, specifically between

Particular and Business.

In the Credit Risk Cycle three phases differ: Presale, sale and after-sales. The process is constantly fed back

incorporating the results and conclusions of the study phase to the sales risk and pre-planning. The following table lists the processes that take place in each of the mentioned phases.

Table 4B

Credit Risk Cycle in the credit process

4.2.1 Risk Study

In general, the risk assessment carry out in the analysis of the credit application consists to analyze the customer's payment capacity6 to meet its contractual obligations with the Bank. This involves

analyzing the credit quality thereof, its risk operations, solvency and profitability to obtain depending on the risk taken.

The risk analyst assesses the credit quality of each customer through a rating/score of the customer

and a valuation report associated with the rating/score that reflects those aspects that determine the

score. The rating/score is the basic tool of risk management, and together with the associated

evaluation reports are updated with a frequency that depends on the client's situation, at least once

a year.

All customers prior to the granting of a credit risk must be assigned an internal rating/score according

to the rating model previously defined and authorized. The rating/score reflects the credit quality of a customer, and is built with both quantitative information (financial, external and internal, etc.) and

qualitative (analyst expertise). This rating/score reflects the probability of customer default.

6 Includes confirmation that economic activity in the potential customer is not within the list of activities in which

the Bank has decided not to establish business relationship (eg. trade and distribution of weapons, people whom deduct may be related whit criminal activities).

Pre

sa

le Study of risk and credit rating process

Planning and setting limits

Sa

le Decision on operations

Aft

er-

sa

les Monitoring

Measurement and Control

Recovery management

2017 | RISK MANAGEMENT ANNUAL REPORT | 29

To manage properly the credit risk must be reached a near vision to the client, both in quantitative

and qualitative aspects, in order to meet their needs and anticipate risks that might affect the good

end of the contracted operations. Customer allocation to a risk analyst has the primary goal that the

analysts have an intimate knowledge of him.

The ratings accorded to customers are regularly reviewed, at least once a year, incorporating new

financial information and experience in the development of the banking relationship. The frequency of review is increased in the case of clients who reach certain levels in the automatic warning systems

and in those classified as special monitoring. Similarly, the tools of rating are reviewed to be able to

adjust the accuracy of the rating given 7.

Against the use of ratings in the wholesale world and the rest of the companies and institutions, in

particular the individuals segment dominated the scoring techniques, which almost always,

automatically assigned a valuation of transactions that occur and have designed to identify the credit

quality of customers, in addition to estimating the probability of default. This process is aided by

origination tool for high-volume applications and seeks to discriminate in the best way possible to the

good from the bad payers.

4.2.2 Planning and setting limits

The commercial strategic planning is implemented through the Strategic Business Plan. This plan is

the union of the business plan with the credit policy and the means required for their achievement on which the business budget is based and must be approved prior to the budget. The three elements

are closely connected and feed each other:

Business plan: set goals in exercise and specific action plan to be implemented to achieve the budget.

Credit Policy: moved the risk appetite to each business line in the form of portfolio

policies, policies for the granting, management and credit recovery and decision rules.

Media Plan (infrastructure): lists the models, systems and resources required for the implementation of planned actions.

The commercial and strategic planning should include safeguard, first of all, the principles established

in the General Corporate Framework of Risks. It is also ruled by principles that are structured in the following categories:

a) Principles of integration and consistency with other management tools. b) Principles concerning the scope of planning.

c) Organizational and governance principles.

Within the annual planning, the levels of risk the bank assumes limited in an efficient and comprehensive and budgets of each of the Bank's business are set out in terms of objectives and

limits on portfolio level, within defined limits risk appetite and risk policies established, defining the

scope of the entity's risk management, and media (models, resources, processes and systems) needed for the annual achievement of these objectives are set.

7 Banco Santander (Mexico) has an internal area of Risk Methodology, responsible for the development, review and

calibration tools.

2017 | RISK MANAGEMENT ANNUAL REPORT | 30

The credit policies moved the risk appetite to each business line, setting the scope of the annual plan. The definition of the general, policies and portfolio approval policies, management and recovery

of credit policies are the responsibility of the risk function, and its approval competence of the governing bodies established for the purpose of risk.

The annual process of setting limits is a dynamic process that determines the willingness to take

risks with each client. This limit is consistent with the budget, and with the risk appetite for which

they have tools and/or processes that allow, among other things, define the limits (joint responsibility

for the functions of risks and commercial), approving (according to the corporate governance and

committee established) and control.

The management limits are intended to avoid unexpected negative impacts on the income statement.

Define the boundary of acceptable risk for the unit and its definition is not conditional on the budget

for year. The indicators subject to define a limit, determinates an Alert threshold and a threshold Stop that are easily understood and measurable.

At the wholesale level and other companies and institutions, an analysis is done at the client level.

When certain features occur, the customer is the subject of establishing an individual limit (pre-classification). The result of the pre-qualification is the highest level of risk that can be assumed with

a customer or group of customers in terms of amount or period. In the corporate segment, a more simplified model for those customers who meet certain requirements (high knowledge, rating, among

others) is used.

4.2.3 Decision on operations

This process aims at the analysis and resolution of operations, approval risks being a prerequisite before any operation risk hiring, being the risk approval a prerequisite before hiring any risk

operation. This process should take into account the defined policies of approval and take into account

both risk appetite and those elements of the operation that are relevant to achieve the balance between risk and return.

The staff of the business areas performing loans promotion does not participate the approval process.

Also, it is strictly forbidden employees, officers and directors of the institution involved in approving loans in which they have or may have conflicts of interest. The decisions taken in the credit approval

process should be duly documented in the minutes of the Committee session and/or official authority responsible for the decision, which must be jointly signed by the participating members.

The loan approval is the responsibility of the Board, which delegated this function to the Committees.

Credit Committees have as a priority that studied, discussed and appropriate decisions, allowing

healthy growth and stability risks.

In the area of smaller individuals and SME’s it facilitates the management of large volumes of credit

transactions with the use of automatic decision models that qualify binomial customer/operation.

With them, the investment is organized into homogeneous risk groups from the classification that the model gives to the operation, according to the information on the characteristics of the operation and

characteristics of the owner.

In the Personal Risk assessment, analysis and approval it is done through an automatic decision model, which considers the assessment of minimum admission criteria, scores, limiting rules and

calculation amount.

2017 | RISK MANAGEMENT ANNUAL REPORT | 31

In the field of business there are two types of decision:

Automatic Decision, in which it is verified by the business area if the proposed

transaction has no place (in sum, product, term and other conditions) within the limits

allowed under the prequalification.

Decision requires authorization from the analyst, although fit in amount, term and

other conditions in the pre-settlement limits. This process applies to retail banking pre-

classification.

In GCB, the management of the operations attends a global relation model using global systems for

the production of the rating and the pre classifications of the clients; the operations’ authorization

decisions are submitted to the local and global Credit Committees. The authorization of the pre

classifications of the clients is delegated to the Global Account Officer (GAO's) for the administration

of the credit limits in its different products.

Although they are relevant in all phases of credit risk in the decision on operations plays an especially

important role considering mitigation techniques.

It is important to point out that in addition within the institution, is a continuous monitoring of the

models of decision on operations, with the aim of ensuring that systems remain effective and robust.

The aspects discussed in the follow-up to decision models are:

Stability. Effect of changes in the composition of the target population as a result of

commercial actions, adding new customers and current characteristics variation.

Performance. Evaluation of the ability of the model of decision to discriminate between

different risk profiles and predict its evolution.

The findings of the follow-up decision models lead to actions whose main objective is to improve the

quality of the final resolutions, through amendments to the decision models and improvements to the capture and quality of information.

4.2.4 Monitoring

After the admissions process and decision, once the risk is incorporated in the portfolio, it is necessary

to conduct a continuous process of risk assessment undertaken in order to anticipate situations of

risk and possible deterioration of the measures and preventive and corrective actions.

The risk monitoring allows evaluate the development of all the elements that can affect the quality

of the risks contracted operations or in the effectiveness of the instruments and mechanisms used in

risk management. The monitoring is based on customer segmentation and performed by risk teams,

complemented by the work of internal audit. The function is specified in the identification and

monitoring of special surveillance firms, regular reviews of credit ratings and scores initially assigned

to customers, in addition to the continuous monitoring of indicators and metrics.

The continuous monitoring aims the proactive and preventive advance through periodic review of all

customers over the predefined actions associated with each situation and its implementation, in a

shared manner between the business and risks functions.

The system named companies in special surveillance (FEVE) distinguishes different degrees depending

on the level of concern of the circumstances observed (extinguish, secure, reduce and follow). Including a FEVE position does not mean have been defaults, but the advisability of adopting a specific

2017 | RISK MANAGEMENT ANNUAL REPORT | 32

policy with it. Customers classified as FEVE are reviewed at least every six months or quarterly for more serious degrees.

The revision of the allocated ratings is performed at least once a year, but if weaknesses are detected

are performed more regularly. For risks of individuals and SME’s of lower turnover, a monitor of key indicator is conducted in order to detect deviations in the behavior of the loan portfolio with respect

to the forecasts made in the Strategic Business Plan.

The process of managing customer base of the perimeters companies, SMEs and individuals can

observe the portfolio from a global perspective to analyze the observed deviations from planning and

risk factors, and project its impact on portfolio performance regarding the expectations about it and

establishing action plans.

The primarily responsible for the portfolio executive process is the portfolio manager of each of the

segments. Within the portfolio management it has been identified the Commercial Strategic Plan as

a key tool. This Plan is the conjunction of the business plan; credit policy and the means required for their achievement and consist in a policy-based management and strategic planning.

This monitoring process through the Bank’s Plan ensures that policies referred to therein are met,

the business goals (budget) and recovery strategies. If significant deviations occur, the necessary measures are taken to bring them back.

The portfolio management is a continuous process analysis in order to collect common elements of

the environment and portfolio, and if necessary, modify the policy. Projective metrics and scenarios are used, analyzing deviations from planning and identifying sources of concern. Anticipation is the

key element along the analysis of risks and possible impacts on profitability. The anticipation is

focused on the identification of potential deterioration of the risk profile, adverse situations or business opportunities.

Within portfolio monitoring, the portfolio manager carries out a follow up the evolution of the

macroeconomic environment and the political and economics one of the country. Likewise, also it analyzes the commercial processing and risk (strategies, prices and offers, among others) of the

competitors.

On the other hand, performs the simulation of adverse scenarios. These scenarios are often historical or hypothetical, built based on regulatory and management information, for which projected risk

parameters are calculated.

This analysis of the environment and the market is performed in order to assess the financial situation of the entity under different circumstances; ensure that planning and strategies defined in the entity

take into account the market situation; detecting whether the strategies defined are suited to the

current macroeconomic conditions and establish the necessary preventive measures adapted where necessary to specific sectors. The portfolio manager, as appropriate, restates the definition of new

strategies or adapts existing strategies.

Another phase of portfolio monitoring is to analyze the portfolio in terms of both structure and indicators. The portfolio manager performs this analysis. To do this, evaluates the structure of the

portfolio using different criteria (concentrations of term, of risk per customer –in the case of companies- and sectorial, inter alia).

2017 | RISK MANAGEMENT ANNUAL REPORT | 33

4.2.5 Measurement and Control

In addition to monitoring the creditworthiness of customers, Banco Santander (Mexico) established

control procedures necessary to analyze the current portfolio credit risk and its evolution through the

various stages of Credit Risk.

The function is developed evaluating the risks from different perspectives, establishing as the main

elements control by geographical area, business areas, management models, products, etc.

facilitating early detection of outbreaks of specific attention, and the development of action plans to

correct any damage.

Moreover, there is in this process a periodic review of risk limits, which are approved and reviewed

at least once a year, unless significant changes occur in the economic environment and/or in the

company and/or with the individual, or when required by the highest management body, it is

promoted by the responsible for controlling these risks function or any function involved in the

management of these limits (business function or risk).

Each control shaft supports two types of analysis:

Quantitative and Qualitative Analysis of the Portfolio

The evolution of risk is controlled permanently and systematically regarding to budgets,

limits and standards of reference, evaluating the effects to both exogenous future situations

such as those arising from strategic decisions, in order to establish measures that put the

profile and volume the risk portfolio within the parameters set.

Assessing the control processes

Includes the systematic and periodic review of the procedures and methodology developed

through the entire cycle of credit risk, to ensure its effectiveness and validity. The existence

and policy compliance is verified and they allow the execution of business plans defined

under the established risk appetite.

The Internal Audit is responsible for ensuring that the policies, methods and procedures are adequate,

effectively implemented and reviewed regularly. It is verified that the methods, actions, and means

related risk management is adequate, applied and perform their function efficiently within the

expected standards.

4.2.6 Recovery Management

The Credit Risk manifests after the granting of credit under a double circumstance:

a) Default on the operation, as an objective and early sign of its possible future and final

accident rates.

b) Insolvency of the holder, observable by the change in his financial position and/or the

appearance of signs on his credit behavior in public databases.

The process of recovery management includes those activities designed to mitigate the consequences of loss events, both before they (management of irregularity or early default) occur as after such

events occur (recovery of bad debts and foreclosed assets management).

Recovery management through its focus on preventive management is linked to monitoring

processes, to anticipate the event of default and taking with it the most corrective measures appropriate to each situation.

2017 | RISK MANAGEMENT ANNUAL REPORT | 34

Areas of recoveries are business areas and direct customer management, whose its creation of value is based on the effective and efficient management of the collection, either by regularizing

outstanding balances or total recovery. It requires proper coordination of all areas of management and is subject to ongoing review and continuous improvement of processes and management

methodology that underpin.

A proper recovery management act in four main phases: early irregularity or default, recovery of bad

debts, default recovery and management of foreclosed assets. The scope of this function begins even before the first default, when the client shows signs of deterioration and ends when the same debt

has been paid or regularized. The recovery function aims to advance the event of default and focuses on preventive management.

The recovery activity is structured based on the following four pillars or elements:

Policy of risks recoveries.

Strategies of Management.

Implementation and monitoring of the business.

Control and monitoring of integrated business risk.

Recovery management is subject to political control and an environment defined by the risk function.

As business activity, recovery management policies are subject to an environment defined by the risk function.

Are particularly applicable risk policies that rules the key recovery management strategies (remove,

nonrecourse, sales, portfolio and reconductions) or those that rules customer recovery management at different stages, depending on the status of their payments (irregular, doubtful or failed).

Apart from measures aimed at adapting operations to the customer's payment capacity, deserves

special mention recovery management, where alternatives to law for early payment of debt are sought. The main forms of recovery are presented:

Cash collection: It should always be the first option for recovery. The regularization of debt by

charging involves the total or partial cancellation of debt.

Reconducting or Restructuring: These are the operations that due to financial difficulties of the

customer, current or expected to meet their payment obligations to the Group in the

contractual terms in force it is necessary to modify, cancel and/or formalizing a new operation with assumable conditions of the client.

Reductions or Write-Offs: They are a finalist loan recovery strategy consisting of an agreement

between the company and the customer, whereby the customer is exempt from payment of the amounts for interest, ordinary or remunerative and/or equity or principal. Usually

performed in Exchange for the cancellation of the rest of the debt, thus giving a definitive solution to the issue in management, either, as according to term, offering the customer a

reorganization of their payments with the entity so that allow or encourage meet their payment

commitments. Nonrecourse: is the act of cancellation of all or part of the debtor's obligation to the entity by

providing certain goods or rights other than those due as a result of a bilateral agreement. It

is a strategy that arises when the client has a capacity of very impaired or no payment. Portfolio/Credit Sale: these are the transactions which are transferred by or transmitted to a

third party (buyer) certain loans to the entity or entities of the Group have towards their

customers, or cash flows of certain receivables that the entity has against its customers, for a

specified price.

2017 | RISK MANAGEMENT ANNUAL REPORT | 35

Allocation: is consistently acted in the cancellation of the debtor's obligation to the entity, in

whole or in part, by providing certain goods or rights other than those due as a result of a court ruling.

While these strategies are defined by the function of recoveries, running at all times under the

provisions of the respective policies regulating risk.

4.3 Risk mitigation techniques

The credit risk is mitigated in general terms through the use of guarantees. A guarantee is defined as a

measure of reinforcement added to a credit operation in order to mitigate the loss by failure to pay. The

guarantee is an element for mitigating the severity of the operation in case of default. Its purpose is to reduce the final operating loss, among other cases, where the long-term operation increases the risk of

damage to the customer or because of possible and relevant external events that could jeopardize the success of the operation and are hardly manageable by creditor.

The guarantees accepted by the institution are classified:

Admission and management of securities shall be governed in any case under the following criteria:

a. Express, subsidiary, accessory and essential character of the securities

The constitution of securities in contracts must be express, trying to set a clear and precise legal nature and scope. The guarantee is subsidiary because the creditor takes with it the right to demand

payment, both the debtor and the guarantor, but the claim to it is subordinate to the former does not comply. The security is ancillary because it presupposes the existence of a valid principal

obligation and current call. If he dies, the guarantee disappears. The admission of any operation is

based on the debtor's ability to pay and in the economic sense of the operation; however, the guarantee is an essential element in reducing the cost of funds to the client. To the extent that the

provision of guarantee reduces the eventual loss of all operations, facilitate access to financing on terms more favorable.

Personal Guarantees:

Gives the creditor a right of personal nature or

ability that targets the own assets of the guarantor. This kind of security will be provided

by parties other than the debtor, and in the

credit agreement itself or in a separate contract (reliable firm and credit derivatives).

Real Guarantees:

Those that are constituted on real assets

(equipment or real state) or specific and certain rights. These are rights that secure the

creditor the performance of the principal

obligation through a special link of an asset. Because of this special relationship, in case of

default of the secured obligation, the creditor can realize the economic value of the asset

through a procedure regulated and charged with the proceeds being opposable preference

in the collection in this way against other

creditors.

2017 | RISK MANAGEMENT ANNUAL REPORT | 36

b. Careful and Expert Assessment

The valuation of the guarantees must use conservative criteria and suitable for the time horizon of

the secured transaction and realized with processes that minimize the risk of valuation of them. The assessment should always be made in view of the purpose of the operation, according to

objective criteria of truth and transparency, and respecting the rules that will result from

implementing and caring for their formal and structural aspects.

The time value of the security offered and its possible change in the nature or value risk reduction, amortization or disappearance, should be appropriate to the maturity and payment flows of the

main transaction.

In Table 4C key elements required for the valuation of securities are presented.

Table 4C: Elements required for the valuation of the securities

Real Estate Guarantees:

They must be valued by an independent third party to the operation8, with specific expertise in this subject, ensuring that assessments meet the legal requirements that exist in this regard,

and they must contain:

The legal purpose of the valuation and the valuation method used Registration of property ownership and characteristics of the guarantee.

Load situation, reservations, liens, and limitations of domain.

This reference is essential in assessing, for the property or rights where an organized and sufficiently liquid market exists. For those who are considered unusual by its nature, an

independent evaluation by a third specialist with proven experience and credibility in the sector must be obtained that the case.

Personal Guarantees:

The updated documentation of guarantors that allows quantify its financial solvency is collected. In any case, joint obligors, guarantors or sureties should be equally valued by the

current system of internal risk assessment according to their characteristics.

c. Valuation Update

The value of securities could be subject to significant changes over the life of credit operations. The

proper management of guarantees requires full registration in the systems of the institution,

allowing:

Conduct joint evaluations of portfolios subject to certain guarantees, either to changes

in actual market data or to possible future scenarios.

Identify operations associated with certain safeguards and, where appropriate,

implement concrete actions on them.

Run processes of assessment indexes or other formulas that identify operations that

exceed certain levels of alert.

8 Banco Santander (Mexico) has an internal area of Technical Evaluation of Real Estate Projects in charge of the

valuation of real estate securities for commercial loans.

2017 | RISK MANAGEMENT ANNUAL REPORT | 37

d. Correct instrumentation of securities

The correct implementation of the operation that gave rise to the guarantee is necessary and

indispensable premise for its existence, so that all are extreme care to ensure that the guarantee

is valid and fully effective.

e. Cautions on the conservation and availability of security

Guarantees can change its value by market conditions, but can also undergo significant changes in

value for its own preservation. Therefore, it is essential to observe certain criteria about. In the

case of security, the client must be agreed with the subscription of compulsory insurance to ensure

the reinstatement of the asset value to events that could cause its impairment. In the case of

security interests, to the extent that the business permits without altering its normal operation,

must be deposited the guarantee in the bank itself or held by an independent third party,

establishing safeguards that will strengthen the duties of conservation and maintenance of the item.

f. Capacity of Execution and Clearing of Guarantee

The possibility and feasibility of execution of the guarantee and their settlement should be

considered. Among the aspects to be evaluated are:

The full title of the total ownership of the domain is an essential element in the ability to

liquidate the security in case of need.

The order of priority in the implementation of the guarantee. The existence of prior rights

on the guarantee prevents its correct valuation.

The existence of a deep and liquid market where redeem the guarantee.

Be careful with the securities on shares of companies whose law precludes negotiation or

not quoted on organized markets.

The feasibility and settlement in the case of special projects, where the guarantees on rights

related to the project itself are subject to its feasibility.

g. Security Blocking

Blocking the guarantee involves limiting the right to dispose of assets or rights pledged as collateral

security by the guarantor. The policy is limit or block the availability on the security, with greater emphasis on anything that may be subject to fraud. Therefore, unless authorized should:

In the case of financial stocks, mark the values pertaining to the guarantee in the entity

or released to the depository institution.

In the case of property or rights on which there is a public record, make the appropriate

entry or retention of title in the register against third parties.

In the case of third party depositary of good, ensures the communication and decision

by the third party in right of preemption on the goods provided as security, its duty of

care and maintenance that affect them.

In the case of financial assets, pledges and trusts are prior to the availability of

resources, and in the case of mortgages may be delayed up to an average of 6 months,

as recorded in the Public Registry of Property.

h. Amendment of the Guarantee

If at the request of the company or customer, the ability to modify the guarantee arises, the request

is handled as a new guaranty claim and must be authorized by the committee with authority to do so.

2017 | RISK MANAGEMENT ANNUAL REPORT | 38

i. Execution of the Guarantee

The failure of the secured obligation gives the entity the possibility of requiring the execution of the

guarantee in accordance with the agreement in the contract.

j. Extinction of the Guarantee

The guarantee is void for the reasons specified in the instruments to which it is formalized, and the legally established causes. Generally, these causes are:

By the extinction of the principal obligation for pay, compensation, confusion, forgiveness or

other institutions that apply in each legislation.

For the loss or destruction of the property contributed as guarantee.

The course of the security period, regardless of subsisting or not an obligation or guaranteed.

In the calculation of the regulatory capital, the mitigation techniques of the credit risk impacts on the

value of the risk parameters and thus in the capital, distinguished by type of guarantees, including

secured and personal.

Personal guarantees impact on the value of the probability of default (PD) by replacing the PD of the

counterparty to the transaction by the PD of the guarantor or credit derivative counterparty.

When internal methodologies used, securities impact on the value of the loss given default (LGD).

Mitigation consist in to associate to the operation guaranteed a specific LGD according to their security,

taking into account also other factors such as the type of product, the balance of the operation and

others. In the case of mortgages, the LGD of the operation will depend on the Loan to Value (LTV), plus

the time that the operation carried on the balance sheet of the bank. If eligible financial guarantee, LGD

zero is assigned to the part of the exposure covered by the security value after applying a regulatory

haircut.

2017 | RISK MANAGEMENT ANNUAL REPORT | 39

Table 4D

Loan portfolio covered by guarantees 9

9 Guarantee data used for the calculation of reserves.

Financial collateral 39,481 65,034

Non financial collateral 47,301 40,397

Total guarantees 86,782 105,431

Portfolio coverd with guarantees 59,593 63,815

Total loan portfolio 223,702 212,947

Financial collateral 19,458 26,840

Non financial collateral 110,250 103,409

Total guarantees 129,708 130,249

Portfolio coverd with guarantees 63,944 62,524

Total loan portfolio 102,374 103,683

Non financial collateral 18,999 28,468

Total guarantees 18,999 28,468

Portfolio coverd with guarantees 19,693 27,089

Total loan portfolio 20,350 27,968

* It does not include loans to government agencies, parastatals, and productive state

enterprises.

* It does not include loans to government agencies, parastatals, and productive state

enterprises and comercial.

Companies with annual sales equal or greater

than 14 millions of UDIS*

millions of pesos

Concept Sep-17 Dec-17

Companies with annual sales of less

than 14 millions of UDIS*millions of pesos

Concept Sep-17 Dec-17

States and municipalities loans millions of pesos

Concept Sep-17 Dec-17

2017 | RISK MANAGEMENT ANNUAL REPORT | 40

4.4 Methodologies for calculating Reserves for Credit Risk

4.4.1 Regulatory Framework

In accordance with the provisions of the CUB to calculate the reserves for credit risk, institutions may use:

a) The Standard Method by which the institutions in order to determine their reserves for the credit

risk, must use the parameters and formulas established in the regulation to determine the

probability of default (PD), the LGD AND Exposure at Default (EAD).

b) Any of the Methods Based on Internal Ratings, foundation or advanced, provided they obtain prior

authorization from the CNBV.

Consumer Credit Portfolio, Mortgage Portfolio and Commercial Portfolio, the Internal

Methodology with Advanced Approach (AIRB), according to the institutions will obtain the

allowances using their own estimates of PD, LGD, y EAD.

For Commercial Portfolio, the institution may use the Internal Methodology with Foundation

Approach (FIRB), according to the allowances using their own estimates of PD for each

borrower and using the LGD and EAD settled in the regulation.

4.4.2 Portfolios authorized to Banco Santander (Mexico) for the use of Internal

Methodologies for the Calculation of Reserves for Credit Risk

Since 2012, the CNBV authorized Banco Santander (Mexico) to use Internal Methodologies with Foundation

Approach (FIRB) for calculating credit reserves and minimum capital10 requirements for portfolios of Global

Corporate Banking Firms and Banks and Financial Institutions.

In October 2015, the CNBV authorized Banco Santander (Mexico) to use Internal Methodologies with

Advanced Approach (AIRB) for calculating credit reserves and minimum capital11 for Corporate and Real

Estate Developers.

Table 4E

Internal Methodologies Outstanding at

December 31, 2016

Foundation Approach

Advanced Approach

Business Global Corporate Banking

Corporate

Banks Financial Institutions Promoters Real Estate

10 The Chapter about Capital detailed the use of internal methodologies (FIRB) for the calculation of capital requirement for credit risk. 11 The Chapter about Capital detailed the use of internal methodologies (AIRB) for the calculation of capital requirement for credit risk.

2017 | RISK MANAGEMENT ANNUAL REPORT | 41

Business Global Corporate Banking (GCB). This portfolio segment consists of a closed list of companies and groups that is reviewed

annually. This list is determined by a thorough analysis of the company (business, countries in which it operates, product types used and more).

Banks Financial Institutions.

They are all customers whose current exhibition, more lines or requested risks of the commercial

portfolio by firm or economic group, exceed 8 million pesos.

Corporate12.

They are all customers whose current exhibition, more lines or requested risks of the commercial

portfolio by firm or economic group, exceed 8 million pesos. Exceptionally, individualized

management are considered those that do not exceed 8 million pesos according to the above

criteria, but that potential and foreseeable reach it in a maximum period of one year. Among

the types of companies to find within this segment, the following customers are recognized:

Juridical Persons and Natural Persons with business activity, including

Agribusiness.

Corporations that are not included in the Global Corporate Banking.

Natural Persons who are shareholders or directors of the entities individualized or

customers of Private Banking.

Real Estate Companies (Property Developers)

It comprising the operations financed construction projects for further promotion (vertical and

horizontal housing, shopping malls, hotels, offices and more). It is important to note that, generally, the Bank's financing in this sector often have the mortgage to finance property, to

win, therefore, especial importance the proper valuation of property and its tracking, because usually that property will own income generator intended for credit repayment, being, also,

secondary source of repayment in the event of having to enforce the security.

Natural Persons and Juridical Persons comprise the domestic segment of Real Estate Companies

with business activity whose core activity is a source of Real Estate Risk (The credit risk which arises in lending transactions is maintained with clients whose main business is real estate

activity). The real estate sector is a very broad activity that includes many activities and sub activities. In this sense, the different types of property risk identified in the institution are:

Property Development: Development and construction of buildings/properties for

resale, usually housing/residential but also other commercial uses (premises, offices,

other).

Properties that Produce Income: The construction or purchase of a property is financed

by a loan whose repayment source consists in renting of the offices, premises or

housing spaces. In the case of financing the purchase of a property already constructed

it is normal that the rents are already in force.

Others Minority Risks of Property: Included in this section all those real estate risks of

different types to those detailed in the above and for which no study or specific referred

12 For Corporates, since 2012, the CNBV authorized Banco Santander to use models based in internal ratings

by the Foundation Approach. Then, in October 2015, the CNBV authorized the use of an Internal Model with

Advanced Approach.

2017 | RISK MANAGEMENT ANNUAL REPORT | 42

is necessary for being minority risks in the portfolios of the Retail Banking Industrialized

Risk. While behind these businesses are real estate assets, it is usually business whose

analysis for other types of expertise are required.

Table 4F

4.4.3 Principles of valuation system authorized for internal models applied in Banco

Santander (Mexico)

The valuation system of Banco Santander (Mexico) quantifies the probability of default of each counterparty (company or group) and is the basic tool of risk management of the Bank and its main objectives are:

a) Report any risk decision (approval of limits and operations, risk policies, and monitoring of

customer, among other).

b) Estimate the fair price for each operation.

c) Determine the reserves and equity consumption for each operation (in the case of approval

of internal models).

The resulting valuation calculates the probability of default, defined as arrears in the next 12 months. There

is a one to one correspondence between rating and probability of default.

Table 4G Characteristics of Valuation System of Banco Santander (Mexico)

Predictive:

• It is a reflection on the probability of default (PD) of analyzed customer.

• Includes all the quantitative and qualitative aspects that PD defines.

Homogeneous:

• Analysts use the same criteria wherever they are.

• It has a definite style used by all.

Specific:

• It caters for the specificities of each company, mainly its sector, country,

environment.

Foundation

Approach

Advance

Approach

States and Munucipalities 27,968 - - 27,968

Financial Institutions 13,181 2,678 691 16,551

Companies with annual Sales equal or greater than 14 millions of UDIS* 11,963 72,112 128,872 212,947

Companies with annual sales of less than 14 millions of UDIS 84,343 4,654 14,686 103,683

Project Finance 20,047 - - 20,047

Residential Mortgage 130,492 - - 130,492

Non - revolving Consumer 52,492 - - 52,492

Credit Card 54,372 - - 54,372

Subtotal 394,858 79,444 144,250 618,552

Interest Collected in Advance 527-

Financial Burder Leasing Operations 154-

Total 394,858 79,444 144,250 617,870

* The information of companies loans includes loans to government agencies, parastatals, and productive state enterprises.

Gross exposures acordding to rating methodology

December 2017millions of pesos

Loan TypesStandard

Method

Internal Methodology

Total

2017 | RISK MANAGEMENT ANNUAL REPORT | 43

Validated:

• It is officially accepted by regulators, internal and external audits, rating

agencies.

Efficient:

• The effort is proportional to the benefit received.

Relevant:

• It provides useful information for decision-making.

• It addresses the most relevant points for each company from the point of

view of risks.

Among the general principles of the institution valuation system, are:

a. Sectoral Approach: Industry knowledge is critical as much of the value of a company depends

on its sector. The sector risk is a reference of the maximum value that can suck a company in

this sector.

b. Forward-Looking Approach: It is to measure the probability of default in the future. It required

analyzing and assessing the perspectives of both the industry and the company.

c. Comparable: Assessment must always be justified in comparison to other companies within

and across sectors, domestic and abroad.

d. Consistency in the Cycle: The assessment should be consistent throughout an economic cycle.

It must take into account the current situation of the company, as the expectation of cycle

change.

e. Quantitative Approach: Each of the above must be accompanied by metrics and quantitative

information regarding the client's financial statements, the economic sector. Competition and

other macroeconomic variables.

f. Knowledge-based Opinion: Valuation should therefore reflect the opinion of the Analyst Risk

on the creditworthiness of the company, for which it will rely on the analysis of the company

and its knowledge of the sector, the economic environment of the company, the financial

characteristics business and possible uncertainties about its future performance.

4.4.4 Main Characteristic of Internal Methodologies with Foundation Approach Authorized by the CNBV to Banco Santander (Mexico)

Since 2012, the CNBV authorized Banco Santander (Mexico) to use models based in internal ratings by the

Foundation Approach in order to calculate loan loss reserves and capital requirements for credit risk of the

following credit portfolios13:

a. Business Global Corporate Banking (GCB).

b. Banks Financial Institutions.

13 For Corporates, since 2012, the CNBV authorized Banco Santander to use models based in internal ratings

by the Foundation Approach. Then, in October 2015, the CNBV authorized the use of an Internal Model with

Advanced Approach

2017 | RISK MANAGEMENT ANNUAL REPORT | 44

The Internal Methodology with Foundation Approach is based on determining the probability of default by rating process that includes a quantitative or statistical module based on the financial reasons information

of the customer (company in the case of GCB and the bank in case of the financial intermediation institutions (FII's bank)) and a qualitative or expert module, based on the opinion of the analyst, who rate the model

variables according to their experience and according to the expert and financial analysis of the entity.

The rating assignment process is schematically summarized as:

Table 4H General Outline Rating

The rating thus obtained is called rating adjusted or final rating, in the event that no further required

adjustments (special cases holding company or support required external).

Quantitative module is a linear regression transformed model whose variables are made for financial reasons. The list of financial ratios used in the model was proposed by analysts for admission of risks that

based on his experience in analyzing counterparts, choose those they consider the most significant in

predicting the probability of bankruptcy.

The quantitative module is calibrated based on the market price of credit derivatives or credit default swaps. The probability of default implied premium quoted by the market is extracted and also builds a model

relating said probability of default to customer balance information, so that from this information can obtain the probability of default even without liquid entities trading on these instruments.

The main elements of the model are included in table’s 4I y 4J.

Table 4I

Types of Financial Ratios Included in the Statistical Model

GCB FII’s Banks

Resources Generation Asset Quality

Size Capitalization

Profitability Transactions

Solvency Liquidity

Liquidity

2017 | RISK MANAGEMENT ANNUAL REPORT | 45

After obtaining statistical rating, the analyst takes this information as a reference, but reviewed and adjusted to obtain the final rating, which is thus markedly expert. Sometimes also adjusts ratings in cases where the

valued customer belongs to a group that receive explicit support.

Table 4J Valuation Areas

For Qualitative Model

GCB FII’s Banks

Market Asset Quality

Management Management/Regulation

Access to Credit Reputational

Profitability

Resources Generation

Solvency

The ratings accorded to customers are regularly reviewed to incorporate new financial information available.

The timing of the reviews increases when certain automatic warning systems are activated. Likewise, also

reviewed the rating tools to go adjusting the accuracy of the rating given.

Thus the calculation of the probability of default by the borrower meets all regulatory requirements, among

which are:

• Use of information and techniques that consider the long-term experience in estimating the

average PD in each classification.

• Allocations used not only expert judgment.

Banco Santander (Mexico) executes a series of internal controls in order to ensure consistency of the

concession process, the reliability of the data used, and in any case the proper management and control of the risks of all exposures. Conducting risk processes ensures that each step is done properly, data operations

and market positions used are correct and that the generated data and information risk are reliable.

4.4.5 Main Characteristic of Internal Methodologies with Advanced Approach Authorized by

the CNBV to Banco Santander

In October 2015, the CNBV authorized Banco Santander to use models based in Internal rating in order to

calculate the minimum capital requirements for credit risk by the advanced method (AIRB), as well as

determine the allowance for credit risk of exposures to:

a) Corporate.

b) Real Estate Companies (Property Developers).

The determination of the probability of default by determining rating is based on an automated module that

collects the first intervention of the analyst and that may or may not be supplemented later.

The automatic model determines the rating in two phases, a quantitative and a qualitative based on a

corrective questionnaire, which enables the analyst to modify the automatic scoring by a limited number of

rating points.

2017 | RISK MANAGEMENT ANNUAL REPORT | 46

The automatic evaluation is obtained from a multivariate linear regression model whose variables are composed of financial ratios and credit bureau data14, plus the answers of a closed questionnaire, which

the Analyst performs. The variables used were previously identified as the most predictive power failure capacity of a company.

Automatic assessment provides a global credit rating ("rating") for the company, collecting thus quantitative

and qualitative aspects. The algorithm for obtaining this score is made as the sum of the product of the

score and the percentage weighting assigned to each of these areas.

This is a client portfolio manager with sufficient experience and associated internal defaults; the estimate

is based on that inner experience of the institution. The PD is calculated by observing the entries in

delinquency of the portfolios and putting those entries in relation to the rating assigned to customers.

The matrix of qualitative information that analyst rate, consists in a questionnaire with different areas of

valuation:

Product and Market.

Profitability.

Solvency

Administration.

Access to credit.

When real estate companies are a special purpose vehicle (SPV) and concentrated real risk, there two types of slightly different rating models applied to automatic Rating Model described in previous paragraph.

Rating SPV Model of Recent Creation

Applies to property risk operations for which financing is provided a SPV. This is a project planning or construction stage where the repayment of the operation rests solely on the future cash flows

to be generated by the real estate asset that guarantees the operation or lack of income. A manual

model whose rating is obtained as a result of the analysis and rating of three areas of valuation, subjectively evaluated by each analyst of the Project: Product/demand/market; access to credit

and professionalism of managers.

Rating SPV Model Underway It is isolated projects where repayment of the operation rests solely on the cash flows generated

by the property assets that guarantee the operation already in operation or operating stage and

generate recurring income (at least one full year). A manual and expert model based on the knowledge and experience of the construction credit analyst is applied, with the main objective to

establish the ability of the project/company to meet the payment obligations with the bank through the funds generated by the project. Rating assessment is done through six valuation

areas: product/demand/market; management; access to credit; cost effectiveness; resource generation and solvency.

Within the Internal Methodology with Advanced Approach, calculating LGD meets the following

requirements:

Calculate based on the internal experience of recovery flows in breach contracts.

Be adjusted to the worst moment in the cycle, so it is considered as a severe downturn

14 Incorporate Credit Bureau data, gives the model a higher discriminating power and greater robustness, to include

other aspects that are not collected, or do so with lower sensitivity, in purely financial information.

2017 | RISK MANAGEMENT ANNUAL REPORT | 47

Be consistent with the definition of default given by Basel and the CNBV.

Comply with the requirements established by the CUB from the CNBV to reflect the severity of

the loss, considering the unfavorable economic conditions15.

In this sense, the LGD is defined, as the expected percentage loss of such an operation would have for

breach. The estimated LGD is, therefore, the expectation of the random variable “percentage loss given default”.

The calculation is based on observing the recovery process credit operations and takes into consideration

not only the accounting records of income and expenses associated with the recovery process, but also the time when these occur, to calculate their present value, and indirect costs associated with this process.

To estimate LGD is used the recovery movements, expenses and nonrecourse or awards observed from the

operations that have entered into a state of "default" within the observation period. The Recovery Unit is responsible for integrating information related to recovery flows of records that have fallen into arrears after

it enters in default until the end of the recovery process marked by the normalization of the contract or the

settlement thereof.

The process involves discounting all flows of recovery to date when the breach occurred; the loss observed

for each operation in default is defined by the following variables:

Amount in debt at the time of default.

Date default.

Flows of recovery.

Flow of expenditure incurred in recovery.

Flow derived from nonrecourse in payment or award.

The LGD finally assigned to each operation must be compatible with the requirements of the CUB, in the

sense of reflecting the severity of loss given unfavorable economic conditions. This means that the expected loss should be conditional on the worst moments of the cycle in order to calculate a "downturn LGD" which

will eventually be used for purposes of calculating regulatory principal. Calculating a "long-run LGD" or LGD cyclically adjusted, which is used for calculating economic capital and loss reserves estimation also it is

included.

In Banco Santander México most of credit contracts contain a Clause of Denunciation or Restriction of

Contract that establishes "the Accredited is appropriate that the Bank remains authorized to restrict the amount of the credit or the term to use the same one, or both simultaneously, as well as to denounce the

contract in any time, using simple communication in writing directed the Accredited, staying consequently, limited or extinguished as it is the case, the right of this to use the amount undrawn". This faculty of the

Bank is realized in conformity by the established in the article 294 of the “Ley de Títulos y Operaciones de

crédito”.

For Corporates, Real-estate Companies and States, Municipal Governments and Public Organisms, Banco Santander México possesses an immaterial percentage of committed irrevocable credit lines.

15 For calculating loss reserves a Long Run LGD (average economic cycle referred to in the estimate) is applied while

the capital requirement for the use LGD Downturn (estimate considering the worst moment of the economic cycle referred to in the estimation).

2017 | RISK MANAGEMENT ANNUAL REPORT | 48

In not retail portfolio only possesses available balances of credit assessed for some accredited in the portfolios of Financing Specializes and Global Corporate Banking being the latter considered for the Internal

Methodology with Foundation Approach and others for Corporate and Real estate developers for the Internal Methodology with Advanced Approach.

On not having possessed available balance material assessed in credit operations, the application of Credit

Conversion Factor (CCF) corresponding to the Methodology by Foundation Approach of the Agreement of

Basel will be considered.

For the rest of the contingent off-balance sheet items, other than unused credit lines such as: financial

guarantees, commercial guarantees, documentary credits, etc., conversion factors (CCF) established in the

regulation apply

4.4.6 Control of internal rating systems

Banco Santander (Mexico) internal validation covers all model used in the risk function. The scope of

validation includes not only the theoretical and methodological aspects, but also, technological systems and

the quality of the data that enable and where their effective functioning is based and, in general, all relevant

aspects of management (controls, reporting, uses, involvement of senior management, other).

The result of the validation of the quality of a model is summarized in a final risk rating indicates the model

according to the following scale:

1. Low: The behavior of the model and its use is appropriate. The quality of the information used in

the development is good. The methodology used complies with the standards and best practices

defined. Documentation, processes and regulations in relation to the model is clear and complete.

Any deficiency is of little relevance and does not affect the performance of the model.

2. Moderate-Low: The behavior of the model and its use is appropriate. The assumptions considered

in the development of the model are reasonable. There are areas for improvement, but they are

not keys or relevant. Do not expect any problems in the implementation and use of the model.

Changes in the model should be considered if the benefits outweigh the cost of change.

3. Moderate: The behavior of the model and its use is appropriate. The assumptions considered in the

development of the model are reasonable. There are areas for improvement in the model.

Corrections of deficiencies must be made in the medium term or must analyze the cost benefit

changes.

4. Moderate-High: There are deficiencies in the model behavior or use. The assumptions of the model,

the qualities of the sample information or predictions development thereof are questionable. Prior

to the implementation or use of the model is highly recommended that some deficiencies are

planned or remedied for its correction in the short term. Others alternatives in the development to

mitigate risk model should be considered.

5. High: The behavior of the model is not suitable, and it is not being used for the purpose for which

it was developed or model assumptions are incorrect. Some aspects need to be corrected

immediately. It is recommended not to implement or use the model as it has been presented.

2017 | RISK MANAGEMENT ANNUAL REPORT | 49

4.5 Counterparty Risk

Within the set of credit risk, there is a concept, which, by its peculiarity, requires specialized management: Counterparty Risk. The counterparty risk of a transaction is the probability a counterparty do not comply in

time or manner with its contractual obligations to the Bank during the life of the transaction. The financial instruments that have Counterparty Risk are the Derivative Instruments, Securities Lending and the Repos.

The measurement and control of counterparty risk, is in charge of a specialized risk unit that is independent

from the business units.

The counterparty risk control is performed daily by a computer system, which identifies the credit line available with any counterparty, in any product and term. To control counterparty lines, the Equivalent

Credit Risk (REC) is used. if such counterparty commits a default in any moment until the maturity date of

transactions. REC takes into account the Current Credit Exposure, which is defined as the cost to substitute the transaction at market value provided that this value is positive for the Bank, and it is measured as the

market value of the transaction (“MtM”).

In addition, REC includes the Potential Credit Exposure or Potential Additional Risk (“RPA”), which represents the possible evolution of the current credit exposure until maturity, given the characteristics of the

transaction and the possible variations in the market factors.

REC calculation takes into account collateral received to mitigate risk. Usual mitigants are cash and bonds. Every month a "Backtesting" is done comparing the estimated exposure and the one actually observed.

In addition to the Counterparty Risk, there is the Settlement Risk, which is present in every transaction at

its maturity date, when the possibility that the counterparty does not comply with its payment obligations arises, once Banco Santander (Mexico) has complied with its obligations by issuing payment directions.

For the process of control for this risk, the Deputy General Direction of Financial Risks oversees on a daily

basis the compliance with the limits on counterparty credit risks by product, term and other conditions stipulated in the authorization for financial markets. Likewise, it is the responsible for communicating on a

daily base, the limits, consumptions and any incurred deviation or excess.

On a monthly basis, a report is presented to the Integral Risk Management Committee. The aggregated

Counterparty Risks, Issuer Risks and Sovereign risk are presented. In addition, excesses to established

limits are presented to the Corporate Banking Credit Committee and Commercial Credit Committee.

Expected Loss at month end for current transactions in financial markets under several stress scenarios are

presented to the Integral Risk Management Committee.

Currently, we have approved lines of Counterparty Risks in the Institution for the following segments:

Mexican Sovereign Risk and Domestic Development Banking, Foreign Financial Institutions, Mexican

Financial Institutions, Corporations, Companies Banking-SGC, Institutional Banking, Large Enterprises Unit, Project Finance.

Equivalent Net Credit Risk of the lines of Counterparty Risk and Issuer Risk of Banco Santander (Mexico)

for the last quarter:

2017 | RISK MANAGEMENT ANNUAL REPORT | 50

Table 4K

The equivalent credit risk lines maximum gross counterparty risk of the Bank at the last quarter, which

corresponds to derivatives transactions, is distributed depending on the type of derivative:

Table 4L

The expected loss at the end of the fourth quarter and the quarterly average of the expected loss of the lines of Counterpart risk and issuer risk of Banco Santander (Mexico) are:

Table 4M

Segments of Mexican financial institutions with foreign financial institutions are very active counterparties

with whom Banco Santander (Mexico) has current positions of financial instruments with Counterparty Credit Risk.

Segment Oct-17 Nov-17 Dec-17 Average

Sovereign Risk, Development Banking

and Financial Institutions 17,826 18,970 18,517 18,438

Corporates 1,060 1,122 974 1,052

Companies 124 147 121 131

Equivalente net credit riskmillions of american dollars

Type of DerivativeEnd of fourth

quarter of 2017

Interest Rate Derivatives                      

16,463.37

Exchange Rate Derivatives                      

40,538.25

Bonds Derivatives                            

         -

Equity Derivatives                           

497.53

TOTAL                      

57,499.15

Equivalente gross credit riskmillions of american dollars

Segment Oct-17 Nov-17 Dec-17 Average

Sovereign Risk, Development Banking

and Financial Institutions 18.11 18.29 18.11 18.17

Corporates 2.2 2.34 2.06 2.2

Companies 1.4 1.54 2.74 1.89

Expected loss of the lines of counterpartymillions of american dollars

2017 | RISK MANAGEMENT ANNUAL REPORT | 51

Respect to total collateral received for derivatives transactions as of the year end:

Table 4N

Regarding the management of securities, collateral, in the case of instruments derivatives, the transactions

subject to collateral agreements are valued according to the frequency indicated in the collateral

agreement; all agreements have now established daily basis. In this assessment, the agreed parameters

are applied in the collateral agreement so that the amount to give or receive from the counterpart is

obtained. These amounts (margin calls) are requested by the party entitled to receive collateral, usually on

a daily basis, as stipulated by the agreement collateral. The counterpart that receives delivery of the

collateral requirement checks assessment, and may arise discrepancies in this process.

On the other hand, the correlation might exist between increased exposure to a client and its

creditworthiness is analyzed by the admission area and limited by the amount of counterparty credit line

and/or REC amount of specific approvals, established in the authorization line process; among many

aspects Admission verifies that transactions in derivative for corporate, companies and individuals be

hedging purposes and not speculative.

Regarding the correlation between the collateral received and the guarantor in derivatives transactions, it

is confirmed that to date, government bonds and/or cash as collateral are received only, which means that

there is practically no risk of adverse effects because the existence of correlations.

Faced with the possibility of a drop in the credit rating of Banco Santander (Mexico) and the possible effect

it would have on a real increase in supply guarantees, it is estimated that the impact of collateral that the

Bank would have to provide if one reduction in its credit rating would not be significant. This is because

some insignificant percentage of collateral agreements is conditional on the rating of bank.

4.6 Information regarding securitization exposures

To fulfill the obligation set forth in Article 88 of the CUB, Banco Santander (Mexico) reported that they have

no significant position in this type of transaction.

4.7 Exposures by Credit Risk

In this subsection information on exposures to credit risk it is shown in the following breakdowns:

General profile of bank exposures

Exposures by type of portfolio and calculation methodology for regulatory capital

Exposures by remaining term

Exposures and reserves by State

Cash collateral 92.80%

Collateral refer to bonds issued by the

Mexican Federal Government7.20%

Total collateral received for derivatives

transactions

2017 | RISK MANAGEMENT ANNUAL REPORT | 52

Exposures and reserves by economic activity (in the case of commercial loans)

4.7.1 Overview

Table 4O

Table 4P

millions of pesos

Loan portfolio evolution

It does not include:

Interest Collected in advance

Financial Burden Leasing Operations

592 585 591 614 619

dic-16 mar-17 jun-17 sep-17 dic-17

4%

Companies rating distribution

2%

28%

68%

2%

Óptimo(9)

Muy Bueno (7-8)

Bueno (5-6)

Deficiente (3-4)

2017 | RISK MANAGEMENT ANNUAL REPORT | 53

4.7.2 Exposure by Type of Portfolio

Table 1

Table 2

Balance at the

end of quarter

Quarter

average

monthly

balance

PerformingNom

Performing Performing

Nom

Performing

Balance at the

end of quarter

Past quarter

Balance

(September)

Variation

States and Munucipalities 27,968 23,229 27,968 0 0 0 160 132 27 0

Financial Institutions 16,551 15,018 16,551 0 0 0 178 122 56 0

Companies with annual Sales equal or greater than

14 millions of UDIS 212,947 212,360 209,686 24 1,696 1,541 2,723 2,919 -196 369

Companies with annual sales of less than 14

millions of UDIS 1

103,683 112,560 98,663 287 1,247 3,487 2,883 3,153 -270 1,753

Project Finance 20,047 19,828 20,047 0 0 0 102 107 -4 205

Residential Mortgage 130,492 129,739 124,372 1,749 580 3,791 1,934 1,853 81 175

Non - revolving Consumer 52,492 52,557 47,835 0 2,505 2,151 4,595 4,608 -13 1,475

Credit Card 54,372 54,675 49,044 101 2,685 2,541 7,475 7,547 -72 1,959

Subtotal 618,552 619,967 594,167 2,161 8,713 13,511 20,051 20,441 -391 5,935

Interest Collected in advance -527

Financial Burden Leasing Operations -154

Total 617,870

1/ It does include loans to government agencies, parastatals, and productive state enterprises.

2/ Register during the reported quarter

Gross Exposures

December 2017

millions of pesos

Type of Portfolio

Total Loan PortfolioCredit Status

Allowance for Loan Losser

Write Offs 2

Nom Impaired Impaired

Concept Sep-17 Dec-17

Total Loan Portfolio

Performing Loans (Non Impaired) 220,309 209,686

Performing Loans (Impaired) 2,661 1,696

Non Performing Loans (Non Impaired) 9 24

Non Performing Loans (Impaired) 723 1,541

Total 223,702 212,947

Exposure at Default

Performing Loans (Non Impaired) 222,517 209,984

Performing Loans (Impaired) 2,661 1,696

Non Performing Loans (Non Impaired) 9 24

Non Performing Loans (Impaired) 723 1,541

Total 225,910 213,245

Allowance for Loan Loss

Balance 2,919 2,724

Standard Methodology

Performing Loans (Non Impaired) 11,101 11,994

Performing Loans (Impaired) 8 26

Non Performing Loans (Non Impaired) 9 17

Non Performing Loans (Impaired) 48 69

Total 11,167 12,106

Internal Rating Methodology

Performing Loans (Non Impaired) 211,416 197,990

Performing Loans (Impaired) 2,652 1,670

Non Performing Loans (Non Impaired) 0 6

Non Performing Loans (Impaired) 675 1,472

Total 214,744 201,139

Companies with annual sales equal or greater than 14 millions of UDIS*

Exposure at Default According to Risk Rating Methodology

millions of pesos

* It does not include loans to government agencies, parastatals, and productive state enterprises.

2017 | RISK MANAGEMENT ANNUAL REPORT | 54

Table 3

Table 4

Concept Sep-17 Dec-17

Total Loan Portfolio

Performing Loans (Non Impaired) 97,300 98,663

Performing Loans (Impaired) 1,680 1,247

Non Performing Loans (Non Impaired) 257 287

Non Performing Loans (Impaired) 3,206 3,487

Total 102,443 103,683

Exposure at Default

Performing Loans (Non Impaired) 100,138 101,213

Performing Loans (Impaired) 1,693 1,260

Non Performing Loans (Non Impaired) 257 331

Non Performing Loans (Impaired) 3,154 3,442

Total 105,243 106,246

Allowance for Loan Loss

Balance 3,153 2,883

Standard Methodology

Performing Loans (Non Impaired) 81,816 84,131

Performing Loans (Impaired) 1,083 955

Non Performing Loans (Non Impaired) 216 287

Non Performing Loans (Impaired) 1,310 1,465

Total 84,426 86,838

Internal Rating Methodology

Performing Loans (Non Impaired) 18,322 17,081

Performing Loans (Impaired) 610 305

Non Performing Loans (Non Impaired) 41 44

Non Performing Loans (Impaired) 1,844 1,978

Total 20,816 19,408

* It does not include loans to government agencies, parastatals, and productive state enterprises.

Companies with annual sales of less than 14 millions of UDIS*

Exposure at Default According to Risk Rating Methodology

millions of pesos

Concept Sep-17 Dec-17

Total Loan Portfolio

Performing 20,350 27,968

Non Performing

Total 20,350 27,968

Exposure at Default 20,350 29,469

Allowance for Loan Loss 132 160

States and municipalities loansmillions of pesos

2017 | RISK MANAGEMENT ANNUAL REPORT | 55

Table 5

Table 6

Table 7

Table 8

Concept Sep-17 Dec-17

Performing Loans

Total Loan Portfolio 13,951 16,551

Exposure at Default 13,951 16,551

Allowance for Loan Loss

Balance 122 178

Standard Methodology 11,106 13,181

Internal Rating Methodology 2,845 3,370

Total 13,951 16,551

Exposure at Default According to Risk Rating Methodology

Financial institutions loansmillions of pesos

Concept Sep-17 Dec-17

Total loan portfolio

Performing 123,731 124,952

Non performing 5,153 5,540

Total 128,884 130,492

Allowance for loan loss 1,853 1,934

millions of pesos

Mortagage loans

Concept Sep-17 Dec-17

Total loan portfolio

Performing 50,363 50,341

Non performing 2,013 2,151

Total 52,376 52,492

Allowance for loan loss 4,608 4,595

Non revolving consumermillions of pesos

Concept Sep-17 Dec-17

Total loan portfolio

Performing 50,714 51,729

Non performing 2,506 2,643

Total 53,220 54,372

Allowance for loan loss 7,547 7,475

Credit cards loans*millions of pesos

*It does not include cards issued to legal entities

2017 | RISK MANAGEMENT ANNUAL REPORT | 56

4.7.3 Remaining Term Exposure

Table 9

Table 10

September 17 % December 17 %

1 year 143,808 23% 134,692 22% -9,115

3 years 173,377 28% 171,856 28% -1,520

5 years 93,501 15% 99,154 16% 5,653

10 years 76,080 12% 75,975 12% -105

>10 years 127,184 21% 136,875 22% 9,691

sep 17 vs

dec17

It does not include:

Interest Collected in advance

Financial Burden Leasing Operations

1 year22%

3 years28%

5 years15%

10 years12%

>10 years 22%

Loan Portfolio

618,552 mdp

Remaining term Sep-17 Dec-17

Up to 1 year 83,905 71,490

More than 1 year and up to 3 years 39,557 40,507

More than 3 years and up to 5 years 40,693 42,844

More than 5 years and up to 10 years 33,866 33,431

More tha 10 years - -

Revolving 25,681 24,673

Total 223,702 212,947

Total loan portfolio

millions of pesos

Companies with annual sales equal or greater than

14 millions of UDIS

* It does not include loans to government agencies, parastatals,

and productive state enterprises.

2017 | RISK MANAGEMENT ANNUAL REPORT | 57

Table 11

Table 12

Table 13

Remaining term Sep-17 Dec-17

Up to 1 year 26,312 24,907

More than 1 year and up to 3 years 29,091 28,883

More than 3 years and up to 5 years 20,022 23,151

More than 5 years and up to 10 years 4,844 5,004

More than 10 years 22,173 21,738

Revolving

Total 102,443 103,683

Total loan portfolio

millions of pesos

Companies with annual sales of less than 14 millions of

* It does not include loans to government agencies, parastatals, and

productive state enterprises and comercial.

Remaining term Sep-17 Dec-17

Up to 1 year 148 153

More than 1 year and up to 3 years 598 654

More than 3 years and up to 5 years 1,962 2,066

More than 5 years and up to 10 years 16,779 17,665

More than 10 years 109,397 109,954

Total 128,884 130,492

Total loan portfolio

millions of pesos

Mortgage loans

Remaining term Sep-17 Dec-17

Up to 1 year 2,469 1,618

More than 1 year and up to 3 years 25,482 21,858

More than 3 years and up to 5 years 24,361 28,920

More than 5 years and up to 10 years 64 96

More than 10 years 0 0

Total 52,376 52,492

Total loan portfolio

millions of pesos

Non revolving consumer

2017 | RISK MANAGEMENT ANNUAL REPORT | 58

4.7.4 Exposure by State

Table 14

Table 15

Performing Non

Performing Total Performing

Non

Performing Total

Ciudad de Mexico 63,186 9 63,194 63,636 68 63,704

Nuevo Leon 23,203 525 23,728 19,467 567 20,034

Jalisco 11,974 2 11,976 12,770 76 12,846

Sinaloa 5,160 16 5,176 5,735 12 5,747

Veracruz 6,252 - 6,252 5,668 31 5,699

México 15,618 96 15,714 9,002 106 9,109

Quintana Roo 1,963 3 1,966 2,516 19 2,535

Chihuahua 4,455 4 4,459 5,992 - 5,992

Querétaro 2,350 2 2,352 2,399 3 2,403

Coahuila 6,639 5 6,644 7,367 11 7,377

Other Satates 82,170 70 82,240 76,829 671 77,500

Total 222,970 732 223,702 211,382 1,565 212,947

The allocation of entities is aligned to the reports sent to the CNBV.

* It does not include loans to government agencies, parastatals, and productive state enterprises.

Dec-17

Total loan portfolio by state

millions of pesos

Companies with annual sales equal or greater than 14 millions of UDIS*

State

Sep-17

Performing Non Performing Total Performing Non Performing Total

Ciudad de Mexico 21,449 672 22,122 22,828 1,805 24,634

México 5,197 118 5,315 5,315 91 5,407

Nuevo León 5,791 66 5,857 5,506 117 5,623

Jalisco 9,802 147 9,949 10,093 141 10,233

Veracruz 2,025 90 2,115 2,196 84 2,280

Sinaloa 1,555 52 1,607 1,908 70 1,978

Coahuila 2,276 51 2,327 2,059 53 2,112

Chihuahua 2,343 23 2,366 2,502 33 2,536

Guanajuato 1,785 73 1,858 2,618 92 2,710

Baja California 6,496 527 7,023 5,106 161 5,267

Other Satates 40,262 1,640 41,902 39,779 1,125 40,904

Total 98,980 3,461 102,441 99,910 3,774 103,683

The allocation of entities is aligned to the reports sent to the CNBV.

* It does not include loans to government agencies, parastatals, and productive state enterprises.

Dec-17

Companies with annual sales of less than 14 millions of UDIS*Total loan portfolio by state

millions of pesos

State

Sep-17

2017 | RISK MANAGEMENT ANNUAL REPORT | 59

Table 16

Table 17

Performing Non

Performing Total Performing

Non

Performing Total

Ciudad de Mexico 28,337 629 28,966 28,506 704 29,210

México 14,517 547 15,065 14,683 636 15,320

Jalisco 10,992 539 11,531 10,953 567 11,520

Nuevo León 11,138 392 11,531 11,217 405 11,622

Baja California 5,533 218 5,751 5,533 239 5,772

Querétaro 5,588 174 5,761 5,910 166 6,076

Veracruz 4,555 388 4,943 4,580 403 4,983

Guanajuato 4,189 145 4,334 4,257 150 4,407

Puebla 3,828 234 4,062 3,861 277 4,137

Chihuahua 3,640 131 3,771 3,679 136 3,815

Other Satates 31,414 1,755 33,169 31,773 1,857 33,631

Total 123,731 5,153 128,884 124,952 5,540 130,492

The allocation of entities is aligned to the reports sent to the CNBV.

Mortgage loans

millions of pesos

State

Sep-17 Dec-17

Total loan portfolio by state

Performing Non

Performing Total Performing

Non

Performing Total

Ciudad de Mexico 7,838 326 8,164 7,824 380 8,204

México 5,577 267 5,845 5,592 278 5,870

Veracruz 4,484 159 4,643 4,510 158 4,668

Jalisco 3,742 147 3,889 3,756 145 3,900

Nuevo León 2,996 133 3,129 2,928 145 3,073

Tamaulipas 2,162 96 2,258 2,185 84 2,269

Puebla 2,348 80 2,428 2,356 103 2,458

Baja California 1,541 53 1,594 1,525 61 1,586

Chihuahua 1,693 69 1,761 1,710 68 1,778

Guanajuato 1,631 62 1,693 1,641 69 1,710

Other Satates 16,352 621 16,973 16,315 661 16,976

Total 50,363 2,013 52,376 50,341 2,151 52,492

The allocation of entities is aligned to the reports sent to the CNBV.

Non revolving consumerTotal loan portfolio by state

millions of pesos

StateSep-17 Dec-17

2017 | RISK MANAGEMENT ANNUAL REPORT | 60

Table 18

4.7.5 Estimates of Credit Risk by State

Table 19

Performing Non

Performing Total Performing

Non

Performing Total

Ciudad de Mexico 14,117 715 14,832 11,214 563 11,777

México 5,145 295 5,439 5,794 344 6,138

Jalisco 3,491 169 3,660 4,099 193 4,292

Nuevo León 3,151 129 3,280 3,606 166 3,772

Veracruz 2,604 152 2,756 2,868 171 3,039

Tamaulipas 1,450 68 1,518 1,724 90 1,814

Puebla 1,500 76 1,576 1,695 93 1,788

Guanajuato 1,507 64 1,571 1,624 74 1,697

Chihuahua 1,471 66 1,537 1,684 83 1,767

Baja California 1,306 58 1,363 1,457 69 1,526

Other Satates 14,972 716 15,687 15,966 797 16,762

Total 50,714 2,506 53,220 51,729 2,643 54,372

*It does not include cards issued to legal entities

The allocation of entities is aligned to the reports sent to the CNBV.

Credit card*

millions of pesos

State

Sep-17 Dec-17

Total loan portfolio by state

State Sep-17 Dec-17

Ciudad de Mexico 414 472

Nuevo León 376 367

Baja California 70 81

México 901 255

Jalisco 111 148

Veracruz 82 84

Sinaloa 39 46

Campeche 96 68

Quintana Roo 21 33

Chihuahua 40 57

Other Satates 769 1,114

Total 2,919 2,724

Allowance for loan losses and by state

millions of pesos

Companies with annual Sales equal or greater

than 14 millions of UDIS*

* It does not include loans to government agencies,

parastatals, and productive state enterprises.

The allocation of entities is aligned to the reports sent to the

CNBV.

2017 | RISK MANAGEMENT ANNUAL REPORT | 61

Table 20

Table 21

State Sep-17 Dec-17

Ciudad de Mexico 503 1,019

Yucatán 11 11

Sinaloa 63 68

Baja California 416 149

Nuevo León 98 101

Veracruz 84 85

Jalisco 188 171

México 135 120

Sonora 39 36

Tamaulipas 40 40

Other Satates 1,577 1,082

Total 3,153 2,883

Companies with annual sales of less

than 14 millions of UDIS*Allowance for loan losses and by state

millions of pesos

* It does not include loans to government agencies,

parastatals, and productive state enterprises.

The allocation of entities is aligned to the reports sent

to the CNBV.

State Sep-17 Dec-17

Jalisco 180 185

Ciudad de Mexico 277 277

México 217 227

Nuevo León 143 141

Baja California 81 88

Quintana Roo 57 58

Veracruz 120 131

Puebla 69 72

Querétaro 70 68

Sonora 36 38

Other Satates 604 648

Total 1,853 1,934

Mortgage Loans Allowance for loan losses and by state

millions of pesos

The allocation of entities is aligned to the

reports sent to the CNBV.

2017 | RISK MANAGEMENT ANNUAL REPORT | 62

Table 22

Table 23

State Sep-17 Dec-17

Ciudad de Mexico 743 750

México 550 534

Veracruz 371 372

Jalisco 326 316

Nuevo León 292 289

Tamaulipas 202 198

Puebla 209 213

Baja California 128 127

Guanajuato 146 150

Chihuahua 152 150

Other Satates 1,489 1,494

Total 4,608 4,595

Non Revolving ConsumerAllowance for loan losses and by state

millions of pesos

The allocation of entities is aligned to the reports

sent to the CNBV.

State Sep-17 Dec-17

Ciudad de Mexico 2,196 1,607

México 796 872

Jalisco 494 554

Nuevo León 429 492

Veracruz 425 456

Tamaulipas 219 253

Puebla 226 253

Guanajuato 209 222

Baja California 190 213

Chihuahua 205 230

Other Satates 2,159 2,322

Total 7,547 7,475

*It does not include cards issued to legal entities

Credit Card Loans*Allowance for loan losses and by state

millions of pesos

The allocation of entities is aligned to the reports

sent to the CNBV.

2017 | RISK MANAGEMENT ANNUAL REPORT | 63

4.7.6 Exposure of Corporate Portfolio by Economic Sector

Table 24

Table 25

Performing Non

Performing Total Performing

Non

Performing Total

Professional, scientific and technical services 23,758 37 23,795 31,830 25 31,854

Construction 25,020 16 25,036 23,365 118 23,484

Wholesale trade 30,856 39 30,895 22,352 42 22,394

Transportation 11,867 0 11,867 12,690 71 12,760

Retail trade 17,648 13 17,661 17,895 36 17,931

Agriculture, animal breeding and production 9,303 4 9,307 10,972 4 10,976

Nonmetallic mineral products manufacturing 4,975 - 4,975 5,341 - 5,341

Mass media information 5,295 - 5,295 5,748 53 5,801

Food industry 7,327 - 7,327 6,373 - 6,373

Basic metal industry 4,132 66 4,198 5,286 84 5,370

Chemical industry 7,531 6 7,537 6,210 32 6,242

Other manufacturing industries 2,012 - 2,012 2,091 0 2,091

Temporary accomodation services 2,372 6 2,378 2,693 6 2,699

Metal products manufacturing 3,732 - 3,732 4,229 11 4,241

Others 67,140 545 67,685 54,308 1,082 55,390

Total 222,970 732 223,702 211,382 1,565 212,947

* It does not include loans to government agencies, parastatals, and productive state enterprises.

The sectorization is aligned to the reports sent to the CNBV.

Companies with annual Sales equal or greater than 14 millions of UDIS*Total loan portfolio by economic sector

millions of pesos

Economic sector

Sep-17 Dec-17

Performing Non

Performing Total Performing

Non

Performing Total

Professional, scientific and technical services 16,772 478 17,250 16,046 436 16,482

Construction 16,363 1,503 17,866 15,641 1,876 17,517

Retail trade 8,850 165 9,015 9,352 173 9,525

Wholesale trade 10,292 307 10,599 10,544 330 10,873

Agriculture, animal breeding and production 4,208 103 4,311 4,773 102 4,875

Beverage and tobacco industries 213 6 219 226 7 233

Business support services 10,120 234 10,354 9,745 247 9,992

Transportation 3,495 49 3,545 4,016 57 4,073

Food industry 1,790 34 1,824 1,741 46 1,787

Machinery and equipment manufacturing 826 25 850 825 13 839

Chemical industry 2,929 43 2,972 3,017 39 3,056

Other manufacturing industries 1,638 40 1,678 1,493 19 1,512

Temporary accomodation services 811 11 822 772 15 786

Health care and social assistance services 788 5 792 764 9 773

Plastic and rubber industry 1,101 15 1,116 1,159 26 1,185

Others 18,784 445 19,229 19,797 378 20,175

Total 98,980 3,463 102,443 99,910 3,774 103,683

The sectorization is aligned to the reports sent to the CNBV.

* It does not include loans to government agencies, parastatals, and productive state enterprises.

Companies with annual sales of less than 14 millions of UDIS*

millions of pesos

Economic Sector

Sep-17 Dec-17

Total loan portfolio by economic sector

2017 | RISK MANAGEMENT ANNUAL REPORT | 64

4.7.7 Estimate for Credit Risk in Corporate Portfolio by Economic Sector

Table 26

Table 27

Economic sector Sep-17 Dec-17

Professional, scientific and technical services 147 230

Construction 453 346

Retail trade 82 141

Wholesale trade 164 268

Clothing Industry 8 12

Transportation 47 100

Nonmetallic mineral products manufacturing 10 49

Agriculture, animal breeding and production 48 83

Mass media information 59 138

Food industry 33 54

Chemical industry 49 93

Basic metal industry 39 115

Other manufacturing industries 9 18

Metal products manufacturing 10 37

Temporary accomodation services 16 20

Others 1,745 1,018

Total 2,919 2,724

Companies with annual Sales equal or greater than 14

millions of UDIS*Allowance for loan losses

millions of pesos

* It does not include loans to government agencies, parastatals, and productive

state enterprises.

The sectorization is aligned to the reports sent to the CNBV.

Economic sector Sep-17 Dec-17

Construction 1,080 1,103

Professional, scientific and technical services 528 389

Nonmetallic mineral products manufacturing 4 4

Retail trade 198 206

Wholesale trade 263 264

Agriculture, animal breeding and production 112 114

Paper industry 10 9

Other manufacturing industries 36 29

Business support services 245 176

Food industry 39 41

Transportation 77 85

Machinery and equipment manufacturing 28 20

Beverage and tobacco industries 5 5

Plastic and rubber industry 26 29

Temporary accomodation service 15 16

Others 488 394

Total 3,153 2,883

Companies with annual sales of less than 14 millions of

UDIS*Allowance for loan losses

millions of pesos

* It includes Project Finance. It does not include loans to government

agencies, parastatals, and productive state enterprises.

The sectorization is aligned to the reports sent to the CNBV.

2017 | RISK MANAGEMENT ANNUAL REPORT | 65

Table 28

Loan

Portfolio

Allowance for

loan losses

Impaired September 2017 23,672 10,506

Increase by new origination + 9,271 3,992

Increase/decrease by balance variation -/+ -3,847 -2,214

Decrease because rating improvement - -3,823 -349

Decrease because of write offs - -2,803 -1,796

Decrease beause of payoffs - -247 -90

Impaired December 2017 22,224 10,049

millions of pesos

Impaired LoansDecember 2017

2017 | RISK MANAGEMENT ANNUAL REPORT | 66

5. Management of Trading Market Risk

This chapter provides information on the activities subject to trading market risk and its evolution in the

last year. Different metrics and methodologies employed in the institution are also described.

5.1 Activities Subject to Trading Market Risk

The perimeter of identification, measurement, control and monitoring function of Market risk covers those

operations where equity risk is assumed. The measurement of market risk quantifies the potential change in value of the positions taken as a result of changes in market risk factors. The risk arises from changes

in risk factors: interest rate, exchange rate, equity, credit spread and volatility of each of the above, and

liquidity risk of the various products and markets in which it operates Institution.

Trading activities include both the provision of financial services to customers, in which the entity is the counterparty, as buying and selling activity and proper positioning in financial instruments. This heading

provided the positions which the entity keeps in their trading book.

Table 5A: Trading Market Risk function of the variable that generates

Interest Rate Risk: The possibility that variations in rates may adversely affect the value of

a financial instrument.

Equity Risk: The possibility that variations in the price of a stock may adversely affect the value of one share certificate and / or a financial instrument.

Credit spread risk: The possibility that changes in credit spread curves associated with issuers

and types of debt could adversely affect the value of a financial instrument.

Volatility Risk: The possibility that variations in the listed volatility of market variables may adversely affect the value of a financial instrument.

Cancellation or prepayment risk: The possibility of early termination without negotiation, on

transactions whose contractual relationship permitted explicitly or implicitly, to generate cash flows that must be reinvested at an interest rate potentially lower.

When significant risks are identified, they measured and allocated limits in order to ensure an adequate control. Global risk measurement is done through a combination of methodologies applied to trading books.

5.2 Basic Principles on the Trading Market Risk Management

a. Independence of trading activities and balance sheet management. The management and control

of the trading books and balance are clearly differentiated Procedures for each of the activities and

processes already exist.

b. Overview of risk assumed. Aggregate overview of all the risks assumed by the institution, in trading

activities and in the management of balance, for effective, efficient and consistent management of

the Trading Market Risk and Structural Risk.

c. Definition of limits and allocations. The Board of Directors is responsible for setting limits of risk

which the institution is willing to take, according to risk appetite. The limits clearly define the types

of activities, segments, products, risks that can be incurred and decisions can be taken regarding

risks.

2017 | RISK MANAGEMENT ANNUAL REPORT | 67

g. Control and supervision. Control mechanisms considered all the risks and its comparison with the

structure of limits.

h. Homogeneous and aggregated metrics. They identify and define the appropriate metric for

management and control of Trading Market Risk and Structural Risk. Evaluation of Trading Market

Risk and Structural Risk assumed is based on a process of measuring them. The measures take into

account all relevant risk components in their life cycle.

i. Homogeneous and documented methodology. The valuation of the instruments and their risks is a

central element in the key processes of management and risk control.

El adecuado desarrollo de la función de admisión y control de Riesgos de Mercado de Negociación se encuentra dentro de una estructura de órganos de gobierno ágil y eficiente que asegura la participación de

todas las partes implicadas y hace compatible el adecuado desarrollo de la función.

The adequate development of the design and control of market risk management is found within a governance structure that is agile and efficient, allowing for the participation of all involved.

To ensure proper management of Trading Market Risk, there is a Committee of Risk Control with the

following terms:

a. Propose methodology applicable of Trading Market Risk, including one that corresponds to calculation models of Trading Market Risk and valuation of financial products subject to market

valuation.

b. Understand and analyze Trading Market Risk exposures of the Institution. c. Supervisar el diseño y funcionamiento de los modelos internos de Riesgos de Mercado de

Negociación. Supervise the design and functioning of the internal models of market risk management

d. Control measures of Trading Market Risk.

e. Develop proposals for Trading Market Risk limitis, new products, and underlying terms for its approval.

f. Accept the proposed modifications of Trading Market Risk limits, in terms of deadlines, products and underlying.

g. Review the regulations applicable to Trading Market Risk and formulate proposals for improvement.

The area of Trading Market Risk Management Unit within Risk Management has the responsibility to recommend administration policies Trading Market Risk of the Institution, establishing parameters for

measuring risks and delivering reports, analyzes and evaluations to the senior management, Committee of

Integrated Risk Management and to the Board of Directors.

5.3 Key processes in the Trading Market Risk Management

The admission and control of Trading Market Risks is based on the following key processes:

a. Definition of Limits, Products and Underlying.

Fixing Trading Market Risk limits, it is essential to maintain risk levels within the risk appetite of the

institution. This limits admission includes both the underlying process of setting annual limits, as

well as the approval of amendments to the previously established limits and approval of new

products and underlying.

2017 | RISK MANAGEMENT ANNUAL REPORT | 68

b. Definition, Capture, Validation and Distribution of Market Data.

Market data are the basis for Trading Market Risk management. Decisions on sources of information

capture, calculation methodologies or processed data on the use of approximations when there is

no specific information corresponding to the risk function.

c. Measurement, Analysis and Control of Trading Market Risks.

Agrupa todas aquellas funciones que tienen como material de trabajo las métricas de Riesgos de

Mercado de negociación utilizadas con el objetivo de conocer y anticipar los riesgos. Group all these functions that have as work materials the metrics of market risk that are used to

identify and anticipate risks.

d. Calculation, Analysis, Explanation and Reconciliation of Management Results.

Reconciliation of operating results, besides being the essential element in the evaluation of the management of risk takers, is a piece of information needed to understand the Trading Market Risk

is being taken in the different activities.

e. Consolidated information.

The consolidated information allows to manage the level of Trading Market Risk assumed by the

institution and transform isolated measures of risk and return on consolidated figures that

incorporate diversification effects. The consolidation process includes the calculation and analysis of the consumption of regulatory capital in accordance with the provisions of the equity framework.

5.4 Control of Trading Market Risk

A. Metrics de Trading Market Risk

Value at Risk (VaR)

It is the standard used by the market to measure, using statistical techniques, the potential

maximum loss in market value under normal conditions, can generate a certain position or portfolio

for a given degree of statistical certainty (confidence level) and a defined time horizon.

The VaR provides a universal measure of the level of exposure of the various portfolios of risk and allows comparison of the level of risk assumed among different instruments and markets by

expressing the level of each portfolio through a unique figure in economic units.

The VaR is calculated using historical simulation with a window of 521 working days (520 percentage changes) and a one-day horizon. The calculation is based on the number of simulated losses and

profits as 1% percentile with constant pesos and with pesos decreasing exponentially with a factor of decay that is reviewed annually, reporting the measure that is more conservative. A confidence

level of 99% is assumed.

Stressed VaR

It consists in obtaining a weighted daily VaR at 99% confidence level and considering a time series

of 260 data that takes into account a period of turbulence in the relevant markets for the trading portfolio of the institution.

Value at Earnings (VaE)

Statistical measure complementary to VaR to measure the benefit that could be obtained under normal market conditions in a time interval and confidence level.

2017 | RISK MANAGEMENT ANNUAL REPORT | 69

Scenario Analysis

It is to define alternative performance of different financial variables and obtain the impact on

results when applied to trading activities. These scenarios can replicate past events (such as crises) or, conversely, may identify feasible alternatives that do not correspond to past events. Three types

of scenarios are defined as a minimum: probable, possible and remote, getting along with the VaR a more complete spectrum of the risk profile.

Trading Market Risk Limits

It refers to the thresholds defined by the institution, according to the level of disaggregation of risk

appetite, with the aim of controlling and managing the different factors of market risk to which the

products and underlying the trading book are exposed.

The limits are used to control the Trading Market Risk of the Institution, from each of their portfolios and books. The structure of limits applies to control exposures and establish the total risk granted

to the business units. These limits are set for VaR, Loss Trigger, Stop Loss, equivalent volume of interest rate, equity equivalent volume and open currency positions. Also, it has a structure of

limits for sensitivities Market Risk factors noted above.

B. Process control of Trading Market Risk

a) Data collection

The data corresponding to the position of the trading book are found on the institution electronic

platform and from there travel to market risk calculation engine. Additionally, the function of market

data through the tool of prices, sends those prices to the mentioned calculation engine.

With exposures and prices, the compute engine Market Risk generates the following information:

Positions Metrics, considering the different types of sensitivities.

Risk Market Metrics, considering VaR and Stressed VaR.

b) Analysis of the metric and positions of Trading Market Risk

The Market Risk function performs a daily analysis of the metric and its variation on the previous

day. It performs an analysis of sensitivities by position, to identify the products in which the variation occurs in order to determine the causes of the changes in the various metrics used.

On the other hand, the Market Risk function performs an analysis of VaR and Stressed VaR in a

daily basis, additionally, comparing them in order to observe how responsive the positions and

changes to these two scenarios. In the case that there are 20 consecutive exceptions that occur for

which the VaR percentile is greater than the Stressed VaR, the Market Risk function analyzes the

vectors of loses and gains in light of the metrics that have been calculated in order to identify

positions and market movements that have been generated.

The analysis performed aims to identify and remove the causes of exceptions into two basic

categories:

Market Movements: in this case the revision of the window used for calculating the Stressed

VaR may become necessary.

2017 | RISK MANAGEMENT ANNUAL REPORT | 70

Significant changes in the composition of the portfolio: in this case the function of market

risk analyzes, together with the business functions, if new positions are permanent or is it

specific operations, in order to decide whether to revise the window used for calculating

the Stressed VaR.

In the event that it is necessary to check the window marked (the window review occurs, at least, on a quarterly basis), the market risk function performs simulations that include long periods

(performed in 2008 to the date of execution of VaR) in order to verify which is the suitable window.

c) Control of the excesses of limits and products authorized

If as a result of the analysis of the level of VaR excesses occur within the limits of market risk or

hiring a product term or unauthorized underlying is detected, the Market Risk function release such

excess to the business functions involved, who develops an action plan that details the actions to

take to reduce the levels of risk assumed.

d) Control of insurance operations

Financial risk function conducts a monthly control to confirm that all operations of fixed income

underwriting and equities in which the business functions have been involved, have their proposed

model and resolution insurance operations in markets.

e) Assessment Model

The control objective is to ensure models of product assessment mitigate the risk of erroneously

rating or no rating certain operations. Monthly, it verifies that the parameters of the assessment

models are within the recommended values.

f) Control of Long and Short Positions

The aim is to control long and short positions (no net) for products and underlying that are traded

on the negotiating table. To this end, quarterly, the Market Risk function reviews the consumption

and liquidity levels with the business function for fixed income products, equities and foreign

exchange.

g) Control of Liquidity

The control objective is to establish limits and control the liquidity of the positions held by the tables

to cover the risk of losses because they cannot cover or break a position within a specified term.

h) Control of prices

The aim of control is to ensure correct capture and validation of market prices for its use in the

various systems, in order to cover the risk of improper valuation of products and perform

transactions with different prices to market prices. The price control is regulated in the data

processing market.

i) Financial Reconciliation

The aim of surveillance is to ensure that risk and estimated results are correct, ensuring consistency

of information between the accounting and management systems.

2017 | RISK MANAGEMENT ANNUAL REPORT | 71

C. Data of the reported period

a. VAR

The Value at Risk for the close of the fourth quarter 2016 (unaudited) amounted to:

Table 5B

The Value at risk corresponding to the average of the fourth quarter of the last year (unaudited) amounted to:

Table 5C

VaR

(Thousand of

mexican pesos)

Trading Desks 128,609.10 0.11%

Market Making 134,323.11 0.12%

Propietary Trading 16,562.56 0.01%

Risk factor

Interest rate 125,199.87 0.11%

Foreign exchange 25,343.92 0.02%

Equity 5,074.85 0.00%

* % of VaR with respect to Net Capital

VaR at the end of the fourth quarter of 2017

%

VaR

(Thousand of

mexican pesos)

Trading Desks 114,747.98 0.10%

Market Making 117,723.72 0.10%

Propietary Trading 27,016.67 0.02%

Risk factor

Interest rate 129,352.12 0.11%

Foreign exchange 43,670.77 0.04%

Equity 5,836.38 0.01%

* % of VaR with respect to Net Capital

%

Average VaR fourth quarter of 2017

2017 | RISK MANAGEMENT ANNUAL REPORT | 72

b. Sensitivity Analysis

The measure of sensitivity Trading Market Risk is a measure of the variation (sensitivity) of the

market value of the financial instrument in question, to changes in each of the risk factors associated with it. The sensitivity of the value of a financial instrument to changes in market factors,

is obtained by full revaluation of the financial instrument.

The following sensitivities are listed under each risk factor and the associated historical

consumption of trading book.

1. Sensitivity to Risk Factor “Equity” (“Delta EQ”) The EQ Delta shows the change in the portfolio's value in relation to changes in the prices of

equities. The EQ Delta calculated for the case of derivative financial instruments considered

the relative change of 1% in the prices of the underlying assets in equities, in the case of equities, this considers the relative variation of 1% of market price title.

2. Sensitivity to Risk Factor “Foreign Exchange” (“Delta FX”)

The FX Delta shows the change in the portfolio's value in relation to changes in asset prices

exchange rate. The FX Delta calculated for the case of derivative financial instruments

considered the relative change of 1% in the prices of the underlying assets of the exchange

rate, In the case of currency positions, this considers the relative variation of 1%of the

corresponding exchange rate.

3. Sensitivity to Risk Factor “Volatility” (“Vega”)

Vega sensitivity is the measure resulting from changes in the volatility of the underlying asset (the reference asset). Vega risk is the risk that a change in the volatility of the underlying

asset value, that results in a change in the market value of the derivative. The calculation of

Vega sensitivity, considers the absolute change of 1% in the volatility of the underlying asset value.

4. Sensitivity to Risk Factor “Interest Rate” (“Rho”)

This sensitivity quantifies the change in value of financial instruments for the trading

portfolio in the face of a parallel increase in the interest rate curves of a basis point.

The table below presents the sensitivities described above corresponding to the position of the

trading portfolio, as of the end year of the fourth quarter:

2017 | RISK MANAGEMENT ANNUAL REPORT | 73

Table 5D

On the basis of the aforementioned. This reflects a prudent management of the Bank’s portfolio with respect to risk factors.

c. Stress Test

Also, monthly simulations of gains or losses of portfolios by revaluations of them under different

scenarios (Stress Test) are performed. These estimates are generated in two ways:

Applying to market risk factors observed percentage changes in certain period of history,

which includes significant market turbulence.

Applying Market Risk factors changes depending on the volatility of each of these.

Then different scenarios are shown stress test considering various scenarios calculated for the

trading book of the institution.

Probable scenario

This scenario was defined based in the movements derived from a standard deviation, with respect to risk factors that have an influence over the valuation of financial instruments. Specifically:

Risk factors of Interest Rate (“IR”), volatility (“Vol”) and rate of Exchange (“FX”) were

incremented in a standard deviation.

Risk factors with respect to stock market (“EQ”) were decreased in a standard deviation.

Possible scenario

Under this scenario, as requested in the official letter, risk factors were modified in 25%.

Specifically:

Risk factors: IR, Vol and FX were multiplied by 1.25 that means, they were incremented in

25%.

Risk factor EQ was multiplied by 0.75 that means, it was decreased in 25%.

Remote scenario

Under this scenario, as requested in the official letter, risk factors were modified in 50%.

Specifically:

PesosOtras

DivisasEQ FX IR EQ FX

1.54 10.09 1.67 2.09 (1.39) (0.32) 10.08

Sensitivity analysismillions of pesos

Vega risk factor Delta risk factorInterest rate

sensitivity(1pb)

2017 | RISK MANAGEMENT ANNUAL REPORT | 74

Risk factors IR, Vol and FX are multiplied by 1.50, that is, they were incremented in 50%.

Risk factor EQ was multiplied by 0.5, that is, it was decreased a 50%.

The following table shows the possible income (loss) for the trading book of the institution, according to each stress scenario at the end year of the fourth quarter:

Table 5E

d. Backtesting

The overall objective of the backtesting is to contrast the goodness of the VaR calculation model.

That is, accept or reject the model used to estimate the maximum loss on a portfolio for a certain

level of confidence and a time horizon determined.

On a monthly basis, these backtesting are conducted to compare the daily gains and losses which would have been observed if the same positions had remained, considering only the change in

value due to market movements, against the calculation of value at risk and therefore to calibrate the models used. These reports, even if they are made monthly, include daily tests.

5.5 Derivates Financial Instruments

The Global Corporate Banking offers its customers, derivative products in order to mitigate the financial risk. Derivatives are financial instruments or contracts whose value depends mainly on the behavior of the

price of one or more underlying assets:

Swaps: A contract through which two parties agree to exchange a series of cash flows at a future

date. There are various types of swaps: Interest Rate, Foreign Exchange, UDIs, Equity swaps.

Forwards: A forward contract whose settlement is deferred until a later date specified therein.

Unlike futures contracts, they are not traded on a market. They are private agreements between two financial institutions or between a financial institution and one of its corporate clients.

Futures: A futures contract is a kind of forward contract, but standardized and negotiable on a

regulated market. This type of contract has margins and capital that supports its integrity and

includes details such as quantity, quality, delivery date, delivery method, among others. All positions handled in these contracts, are between a participant on one side and the clearing on the

other.

Risk profile Stress all factors

Probable Scenario 0.34

Remote Scenario 282.81

Possible Scenario 22.58

Possible lncome (loss)Stress test

millions of pesos

2017 | RISK MANAGEMENT ANNUAL REPORT | 75

Options: It is a standardized contract in which the buyer pays a premium and acquires the right, but not the obligation, to buy (call) or sell (put) an underlying asset (which can be shares, stock

market indices, etc.) an agreed price (strike or exercise price) at a predetermined future date at a

set period (maturity).

The Bank may enter into derivatives transactions with the following financial intermediaries:

Decentralized agencies, credit institutions and brokerage firms authorized to operate as participants

and / or intermediaries in the derivatives markets.

It can also operate with domestic and foreign companies with no legal impediment and that

demonstrate high moral and financial solvency, which satisfy the minimum requirements of process analysis and risk assessment.

To celebrate derivatives transactions, customers must have a credit line with or without guarantees for the

operation and shall not in any case exceed the ceiling of the authorized line. To assess exposure to credit risk of derivatives is taken into account implied volatility in the value of the instruments, in order to

determine the maximum possible loss that can assume the counterparty (REC) and relate to the amount total credit line. Derivatives operations conducted with clients and intermediaries shall be documented by

establishing framework contracts.

Derivative financial securities are valued at reasonable value, according to the accounting rules established in the Circular Letter for Credit Institutions issued by the National Banking and Exchange Commission, in

Principle B-5 “Derivative Financial Instruments and hedging Transactions” and the provisions in Principle A-2 “Application of specific rules”, and the provisions in the specific rule included in Bulletin C-10 of the

Financial Information Rules.

A. Methodology of Valuation 1. Trading Purposes

a. Organized Markets

The valuation is made at the relevant market closing price. Prices are provided by the

supplier of prices.

b. Over the Counter Market

Derivative financial instruments with optionality:

In the majority of the cases, a general form of the Black & Scholes model is used.

Such model assumes that the underlying product follows a lognormal distribution.

For exotic products or when payment depends on the trajectory of any market

variable, MonteCarlo simulations are used. In this case, it is assumed that

logarithms of the different variables follow a multi-varied normal distribution.

Derivative financial instruments without optionality:

The valuation technique is to obtain the present value of the estimated future flows

In all cases the institution carries out the valuation of its positions and registers the corresponding value. In some cases, a different calculation agent is designated, and such

calculation agent may be the counterparty or a third party.

2. Hedging Purposes

In the performance of its commercial banking activities, the institution has tried to cover the

evolution of the financial margin of structured portfolios that are exposed to adverse movements

2017 | RISK MANAGEMENT ANNUAL REPORT | 76

in interest rates. The ALCO, the body responsible for the management of long-term assets and

liabilities, has constituted the portfolio via which the Bank achieves such hedge.

An accounting hedge is defined as a transaction that complies with the following conditions:

a. A hedge relationship is designated and documented from the beginning in an

individual file, where its objective and strategy is established.

b. The hedge is effective for the compensation of variations in the reasonable value

or in the cash flows attributed to such risk, according to the risk management

documented at the beginning.

The Management of Banco Santander (Mexico) performs derivative transactions for hedging

purposes with swaps. Derivatives for hedging purposes are valued at market value, and the

effect is recognized depending on the type of accounting hedge, pursuant to the following:

a. In the case of fair value hedges, they are valued at market value for the risk

covered, the primary position and the hedging derivative instrument, and the net

effect is registered in the statement of income of the corresponding period.

b. In the case of cash flow hedges, the hedging derivative instrument is valued at

market value. The effective portion of the hedge is registered in the

comprehensive income account, within the stockholders’ equity, and the

ineffective portion is registered in the statement of income.

The Institution ceases the recording of hedges at the maturity date of the derivative, or when

such derivative is sold, cancelled or exercised; when the derivative does not reach a high

efficiency in compensating the changes in the reasonable value or the cash flows of the covered

item, or when Banco Santander (Mexico) decides to cancel the hedge.

It shall be fully evidenced that the hedge fulfills the objective for which derivatives were

contracted for. This effectiveness requirement assumes that the hedge must comply with a

maximum range of deviation with respect to the initial objective of 80% to 125%.

In order to demonstrate the efficacy of hedges, two tests are to be carried out:

a) Forward-looking Test: it is demonstrated that, in the future, the hedge will be

within the aforementioned range of deviation.

b) Retrospective Test: This test reviews if, in the past, from its initial date to now,

the hedge has been maintained within the allowed range of deviation.

In the cases of Fair Value Hedges and the Cash Flow Hedges, they are

retrospective and forward-looking efficient and within the allowed maximum

range of deviation.

B. Overview of the Position

The most relevant reference variables are Exchange Rates, Interest Rates, Stocks, baskets and

market indexes. The frequency with which financial products trading and hedging purposes are valued is daily.

2017 | RISK MANAGEMENT ANNUAL REPORT | 77

At the end year of the fourth quarter, the institution has no situation or contingency such as changes in the value of the underlying asset or the reference variables, that may cause the use

of the derivative financial instruments to be different to their original intended use, a significant change in their scheme or the total or partial loss of the hedge, requiring the Issuer to assume

new obligations, commitments or variations in its cash flow or affecting its liquidity (day trade

calls), nor contingencies or events known or expected by the Management that may affect future reports.

Table 5F

Actual

Quarter

Previous

Quarter

Forwards Bonds Trading 0 0 0

Forwards Foreingn Currency Trading 231,334 273 2,199

Forwards Equity Trading 15,486 1 -69

Futures Foreingn Currency Trading 6,263 0 -184

Futures Market Index Trading 190 0 66

Futures Interest Rate Trading 5,005 0 -6

Futures Equity Trading 0 0 -5

Options Equity Trading 214.239579 -28 -28

Options Foreingn Currency Trading 227,560 92 880

Options Market Index Trading 20,725 274 373

Options Interest Rate Trading 243,098 -169 -164

Swaps Cross Currency Trading 896,310 -5,219 -4,135

Swaps Interest Rate Trading 5,346,429 -2,330 -1,802

Swaps Equity Trading 1,674 267 103

Forwards Foreingn Currency Hedging 53,823 1,669 2,504

Swaps Cross Currency Hedging 66,611 2,226 4,015

Swaps Interest Rate Hedging 6,839 150 -34

Summary of derivative financial instrumentsmillion of mexican pesos as of December 31, 2017

Type of Derivative UnderlyingNotional

amount

Fair ValuePurpose of

Derivative

2017 | RISK MANAGEMENT ANNUAL REPORT | 78

The institution, at the execution of transactions of OTC derivative financial instruments, has Collateral formalized agreements with many of its counterparties, which function as market value

guarantee of the derivative transactions, and it is determined based on the exposure of the net position on risk with each opposing party. The managed Collateral consists mainly in cash

deposits, whereat there is not a deterioration situation.

There are no derivative financial instruments whose underlying assets are treasury shares or securities representing them during the quarter.

Tabla 5G

Description MaturitiesClosed

Positions

Caps and Floors 447 27

Equity Forward 10 10

OTC Equity 248 0

OTC Fx 1,832 0

Swaptions 1 0

Forward 746 21

IRS 1208 801

CCS 92 43

Number of expired derivative financial

instruments and closed positions

2017 | RISK MANAGEMENT ANNUAL REPORT | 79

6. Structural Risk Management

This chapter provides information on the activities subject to Structural Risks and expose its evolution

during the last year. Different metrics and methodologies employed in the institution are also described.

6.1 Activities subject to Structural Risk

The perimeter of identification, measurement, control and monitoring function of market risk covers those

operations where equity risk is assumed. The measurement of market risk quantifies the potential change in value of the positions taken as a result of changes in market risk factors. The risk arises from changes

in risk factors: interest rate, exchange rate, equity, credit spread and volatility of each of the above, and liquidity risk of the various products and markets in which it operates the institution.

The structural risks consist of market risks inherent in the balance sheet of the institution, excluding

trading portfolios. This risk includes both losses from price changes affecting the portfolios available for sale and held to maturity, as well as losses from the management of recorded assets and liabilities (banking

book).

The main structural risks are the following:

Structural Interest Rate Risk: It arises from mismatches between maturities and repricing of

assets and liabilities in the balance.

Structural Exchange Rate Risk: Exchange rate risk is a result of operating in a currency other

than the Mexican Peso.

Structural Risk in the Equity Portfolio: Includes investments through equity to non-consolidated

financial and non-financial, such as portfolios available for sale consist of equity positions.

Inflation Risk: The possibility that changes in inflation rates may adversely affect the value of

a financial instrument or portfolio.

Market Liquidity Risk: The possibility that the institution is unable to reverse or close a position

in time without impacting the market price or in the cost of the transaction.

Prepayment or Cancellation Risk: The possibility of early termination without negotiation in

transactions whose contractual relationship so permits, explicitly or implicitly, to generate cash

flows must be reinvested at an interest rate potentially lower.

When significant risks are identified, they measured and allocated limits in order to ensure proper control.

The overall measurement of Structural Risk is made through a combination of methodology applied to the Portfolio of Management Balance-Sheet.

6.2 Basic Principles on the Structural Risk Management

a. Independence of the Trading Activities and Balance-Sheet Management. The management and the

control of trading books and balance-sheet portfolios are clearly differentiated. There are

procedures for each of the activities and processes.

b. Overview of risk assumed. There is an aggregate overview of all the risks assumed by the institution,

in trading activities and in the management of balance-sheet, for effective, efficient and consistent

management of the Trading Market Risk and Structural Risk.

c. Definition of limits and allocations. The Board of Directors is responsible for setting risk limits that

the Institution is willing to assume, according to risk appetite. The limits clearly define the types of

activities, segments, products, risks that can be incurred and decisions can be taken regarding risks.

2017 | RISK MANAGEMENT ANNUAL REPORT | 80

d. Control and supervision. The mechanisms of control that considers all the risks and compares these

with the structure of limits.

e. Homogeneous and Aggregated Metrics. They identify and define the appropriate metric for

management and control of Trading Market Risk and Structural Risk. The evaluation of the Trading

Market Risk and Structural Risk assumed is based on a measurement of the same process. The

measures take into account all relevant risk components in their life cycle.

f. Homogeneous Methodology and documented. The valuation of the instruments and their risks is a

central element in the key processes of management and risk control.

The proper development of the function of admission and Structural Risk control is within an agile and efficient structure of governance bodies that ensures the participation of all parties and makes compatible

the appropriate function development.

To ensure proper management of structural risks, there is a Committee of Risk Control with the following

terms:

a. Propose a methodology of Structural Risks applicable, including that corresponds to calculation

models of Structural Risk and valuation of financial products subject to the market assessment. b. Understand and analyze exposure to Institutional Structural Risks.

c. Supervise the design and operation of internal models of Structural Risks. d. Control of Structural Risk Measures.

e. Develop proposals for Structural Risk limits, new products, and underlying terms for its approval. f. Admit the proposed amendments to Structural Risk limits, in terms of deadlines, products and

underlying.

g. Review the regulations implementing to Structural Risks and formulate proposals for improvement.

The area of Structural Risk Management within the Unit of Integrated Risk Management, is responsible for recommending policies of structural risk management of the Institution, establishing risk measurement

parameters, and providing reports, analyzes and evaluations to the Senior Management, Integrated Risk Management Committee and the Board of Directors.

6.3 Key Processes in the Structural Risk Management

The admission and control of structural risks is based on the following key processes:

a. Definition of limits, products and underlying.

a. The fixing of the Structural Risk limits is key to maintaining the risk levels within the risk

appetite of the institution. This admission of the limits includes both the process of setting

annual limits, as well as the approval of amendments to the previously set limits and

approval of new products and underlying.

b. Definition, capture, validation and distribution of market data.

a. Market data are the basis for the management of Structural Risk. Decisions on sources of

information capture, calculation processed data methodologies on the use of the approximations when there is no specific information corresponding to the risk function.

c. Measurement, Analysis and Control of Structural Risks.

a. It brings together all those functions whose work material Structural Risk metrics used in order to understand and anticipate the risks.

d. Calculation, Analysis, Explanation and Reconciliation of Management Results.

a. Reconciliation of operating results, besides being the essential element in the evaluation of

the management risk-taking areas, is a key piece of information to know the structural risks

that are being made in the different activities.

2017 | RISK MANAGEMENT ANNUAL REPORT | 81

e. Consolidated information.

a. The consolidated information to manage the level of structural risks assumed by the

institution and transform isolated measures of risk and return on consolidated figures that incorporate diversification effects.

6.4 Control of Structural Risk

Banco Santander (Mexico) commercial banking activity generates significant account balances that are recorded on the balance sheet. The Committee of Asset and Liabilities (ALCO) is responsible for determining

the risk management guidelines of financial margin, equity value and liquidity, whose must to be followed

in the different commercial portfolios. Under this approach, the Corporate Finance Department is responsible for implementing the strategies defined in the Committee of Assets and Liabilities in order to change the

risk profile of the trade balance by following established policies, for which it is essential to take the information requirements for interest rate risk, exchange rate risk and liquidity risk.

A. Structural Risk Metrics

As part of the financial management of the institution, the sensitivity of financial margin and equity value

of the different balance-sheet, against changes in interest rates, is analyzed. This sensitivity arises from gaps in maturity dates and modification of interest rates occurring in the different categories of assets and

liabilities.

Sensitivity to Net Interest Income (NIM)

The sensitivity of the Net Interest Income measures the change in the expected accruals for a

specific period (12 months) given a shift in the interest rate curve. The calculation of this sensitivity is done by simulating the margin both for a scenario of changes in the rate curve as well as the

current situation, the sensitivity being the difference between the two margins calculated.

As part of the control system of structural risk derived from changes in the interest rate set a limit of sensitivity of the Net Interest Income to one year. In case of exceeding this limit occur, those

responsible for risk management must explain the reasons for it and facilitate action plan to correct it.

Sensitivity to Market Value Equity (MVE)

The Sensitivity of Market Value Equity is a measure of the sensitivity of the financial margin and measures the interest risk implicit in the equity value (own resources) on the basis of the incidence

that has a variation of interest rates at current values assets and liabilities.

The analysis is based on the classification of each item sensitive to interest rates over time, according to their date of redemption, expiration, or contractual modification of the interest rate

applicable.

As part of the control system of Structural Risk deriving from changes in the interest rate set a limit on the MVE. In case of exceeding this limit occur, those responsible for risk management must

explain the reasons for it and facilitate action plan to correct it.

Treatment of liabilities without defined maturity

The volume of account balances without specific maturity is divided between stable and unstable

balances. This separation is obtained using a model based on the relationship between the account balance and fluctuating averages. From this monthly cash flows are obtained.

2017 | RISK MANAGEMENT ANNUAL REPORT | 82

The model requires different inputs among which are: own product parameters, parameters of customer behavior, market data and historical data from its own portfolio.

B. Data from the reporting period

This sensitivity is derived from the difference between maturity dates of assets and liabilities and the dates

interest rates are modified. The analysis is performed from the classification of each item sensitive to interest

rate throughout time, according to their repayment, maturity or contractual modification of the applicable

interest rate:

Table 6A

Using simulation techniques, the predictable change of the net interest income and the market value of

equity are measured in different interest rate scenarios, and their sensitivity under extreme movement of

such scenarios, as the end of year:

Table 6B

The Committee of Assets and Liabilities adopts investment and hedging strategies to maintain these

sensitivities within the target range.

Oct-17 Nov-17 Dec-17 Promedio Oct-17 Nov-17 Dec-17 Promedio

Balance MXN GAP 33% 37% 49% 40% 51% 50% 44% 48%

Scenario -100 -100 -100 N/A 100 100 100 N/A

Balance USD GAP 67% 62% 66% 65% 24% 17% 26% 22%

Scenario -100 -100 -100 N/A -100 -50 -50 N/A

Sensitivity analysismillions of pesos

Sensitivity NIM Sensitivity MVE

Scenario Total DerivativesNon

DerivativesScenario Total Derivatives

Non

Derivatives

Balance MXN GAP -100 -739 -541 -197 100 -2,326 266 -2,593

Balance USD GAP -100 -261 231 -493 -50 -335 -673 338

Thousand of millions pesos

Sensitivity NIM Sensitivity MVE

Sensitivity NIM & MVE. Derivatives and non derivatives

2017 | RISK MANAGEMENT ANNUAL REPORT | 83

6.5 Structural Risk in the Equity Portfolio

At ended December the Bank has equity positions in its banking book. These positions are maintained as shares and registered in the account: “Permanent Investments in Shares”.

This position is valued at its fair value using market values. If the market value cannot be obtained reliably,

or if it is not representative, taking into account the event that there is no frequent activity in the market in which it negotiated the title, an insignificant volume is traded or its price is suspended, the fair value is

determined based on the equity method and/or based on the acquisition cost adjusted by updating factors,

or to last determined fair value.

In the case of equity securities valued at acquisition cost, they are adjusted to net realizable value when it is less than the updated cost. This value shall be determined based on formal valuation techniques. The

amount by which the value of debt and equity is reduced, should be recognized against income for the year.

If at a later date to the value of a security was decreased, there is certainty that the issuer will cover a

larger amount than in books, it may make a new estimate of its value. The effect of this revaluation should be recognized in the results when it happens. Under no circumstances should this reassessment may exceed

book value at that date would have the title if it had not been adjusted for the decrease decrement.

Table 6C

The capital requirement for the equity position of Banco Santander (Mexico) at the end of year amounted

to $80 Millions of pesos.

POSITIONS HELD FOR PROFIT

Publicly Traded Positions 2,560 2,560 2,560 54 -

Publicly No-Traded Positions

POSICITIONS HELD FOR OTHER REASONS

Publicly Traded Positions 493 493 493 27

Publicly No-Traded Positions 25,345 25,345 25,345

REVALUATION

PROFITS

UNREALISED

STOCK POSITIONDecember 2017

VALUE OF THE TOTAL POSITION IN BALANCE

millions of pesos

CONCEPTBALANCE

VALUEFAIR VALUE

MARKET

VALKUE

CAPITAL

GAIN MAID

UNREALISED

GAIN

2017 | RISK MANAGEMENT ANNUAL REPORT | 84

7. Liquidity Risk Management

7.1 Activities subject to Liquidity Risk

Liquidity risk is defined as the possibility of failing to meet payment obligations on time or to do so at

excessive cost. The types of losses that are caused by this risk include forced sales of assets or impacts on

margin mismatch between the forecasts of cash outflows and inflows. It is the risk of loss of value of the buffer of liquid assets of the entity and the change in value of the operations of the entity (derivatives and

guarantees, among others) which may involve additional collateral requirements and thus worsening liquidity.

Additionally, it includes the risk of being unable to meet payment obligations as a result of timing differences

in cash flows, cash unforeseen needs, inadequate liquidity structure of assets and liabilities or concentration

in finance providers. Under this, the Liquidity Risk is classified into the following categories:

a. Financing Risk: It identifies the possibility that the entity is unable to meet its obligations

as a result of an inability to sell assets or obtain financing. The funding liquidity risk arises

from the time lag in the cash flows or unforeseen cash requirements, either by improper design of active and passive operations, or unforeseen liquidity needs.

b. Mismatch Risk: It identifies the possibility that the differences between the structures of

maturities of assets and liabilities generate an additional cost to the entity.

c. Contingency Risk: Refers to extraordinary liquidity needs and identifies the possibility of not having elements of management adequate for obtaining liquidity as a result of an extreme

event involving major needs of financing or collateral to obtain the same.

7.2 Basic Principles on Liquidity Risk Management

Admission, control, consolidation and Liquidity Risk reporter contemplate and safeguard the principles established in the framework of the Integrated Risk Management and is governed by the following

principles:

Financial Autonomy Banco Santander (Mexico) independently handles its liquidity, which means that the Bank must capture

and manage its own financial resources and maintain liquidity levels required internally at the entity level and by supervisors and regulators.

Using homogeneous and aggregated metrics The assessment of the risks taken is based on a process of quantifying or measuring of them. The

measures take into account all relevant components and dimensions of risk throughout their life cycle. The company ensures the identification, definition and knowledge of the appropriate management

metrics and control of liquidity risk. The determination of the maturity of the derivative financial

instruments is a key element in the processes of Liquidity Risk, particularly for those without a contractual behavior defined and/or dependent on the behavior of customers. Therefore, all flow

calculation methodologies are homogeneous, are adequately documented and approved by the relevant bodies and are subjected to appropriate validation processes.

2017 | RISK MANAGEMENT ANNUAL REPORT | 85

Establishment and adaptability of limits Setting limits is to meet, efficiently and comprehensively, levels of Liquidity Risk that Banco Santander

(Mexico) is willing to assume, according to the risk appetite set by its board of directors, and according to the capacity of managers, the infrastructure available for the management and control, knowledge

of the liquidity of the products and information available at appropriate times. Additionally, agile

mechanisms of modification of boundaries can adapt to extreme or adverse market situations, as well as responding to normal opportunities.

Regulatory Environment

Banco Santander (Mexico) must meet not only the requirements set by the regulator, but also must

meet the requirements of the corporation so that it can adequately respond to the scrutiny supervisor on a consolidated basis.

7.3 Key Process in Liquidity Risk Management

The model of Liquidity Risk in Banco Santander (Mexico) is based on the following key processes:

a) Admission

Setting limits and approval of new products and specific operations. Prior to admission of Liquidity Risk, the financial management function defines the perimeter of trading activity and balance sheet

management of the entity, that is, the determination of the geographical segments, business and associated portfolios.

b) Provisioning of Information

As a preliminary step to the realization of control the risk of liquidity, information is collected on the principal items of the balance sheet of the entity (Expiries, stock of liquid assets, issues,

commitments, among others). In this process, the function of Liquidity Risk obtains information from market data provided by market data function, which performs the following steps:

Capture: obtaining market variables.

Calculation: modification, transformation and interpolation of data captured from

information systems.

Validation: filtering the data according to defined quality requirements.

Certification: generation of end of day prices and official data used in the process.

Dissemination: setting the certified data available to different systems

c) Liquidity risk control

Measurement, analysis and control of liquidity risk is to ensure that the level of balance sheet

liquidity is consistent with the approved limits and risk appetite established by the governing body

of the entity. This process aims:

Understand, analyze, control and monitor continuously the situation, evolution and

trends in liquidity risk generated by the balance, reporting periodically to the address

and requesting measures to be taken.

Conduct analysis and control liquidity risk in the different axes, and levels and defined

metrics.

Understand, analyze, control and monitor the possible concentrations in funding sources

or suppliers.

2017 | RISK MANAGEMENT ANNUAL REPORT | 86

Monitoring and analysis of Liquidity Risk excess, regarding the approved limits, notifying

the excesses of risk-taking functions and requesting, where appropriate, actions that

serve to its regularization.

Respond in a timely manner to the requirements set by regulators, filling information

Liquidity risk of the entire balance sheet.

7.4 Liquidity Risk Control

As already mentioned, the liquidity risk is associated with the ability that Bank Santander (Mexico) has to

finance its commitments undertaken, at reasonable market prices and to carry out its business plans with

stable sources of funding. The factors that influence can be external (liquidity crisis) and internal due to

excessive concentration of maturities.

Bank Santander (Mexico) hits a coordinated management of the maturities of assets and liabilities, monitoring the maximum gap profiles. This surveillance is based on analysis of maturities of assets and

liabilities both contractual and management. The Bank performs a control for maintaining sufficient liquid assets to ensure survival horizon for a minimum of days faced a liquidity stress scenario without resorting

to additional sources of funding. Liquidity risk is limited in terms of a minimum of days established for local

and foreign currencies in consolidated form.

A. Liquidity Risk Metrics

Structural Finance Ratio.

After analyzing the components of the balance sheet, for those whose treatment is affected by variations and balances, the institution calculates the ratio of structural finance in order to

measure the excess or deficit of liquidity structural in the balance. The structural liquidity analysis allows to determine how are funding the structural needs and if there is a high reliance

on the use of instruments considered volatile or highly correlated with market variables.

Liquidity Risk Limits.

The limits of liquidity risk refer to those minimum thresholds defined by the entity in order to

control and manage the risks relating to liquidity, balance sheet structure to which the entity

is exposed.

Liquidity Gap.

Shows the liquidity risk profile or mismatches in the cash flows, assuming a normal course of

business and stable market conditions. It consists of the contractual gap, coupled with the best

estimate available of the flows that could affect the liquidity situation of the entity from the

trade balance, other balance sheet items and other inputs and outputs known.

Liquidity Available.

It is defined as the amount of the public debt plus cash and other liquid assets without pledged

and which can become almost immediately liquidity by direct sale on the market, without

significantly affecting its price or to serve as collateral in operations of temporary assignment

of assets (or other financing collateral) with reasonable haircuts.

Concentration of Funding Sources.

Shows the main funding sources or suppliers, volumes and terms of financing. The analysis of

this information allows evaluate possible concentrations and effects faced possible changes in

the sources or suppliers or its availability to provide it.

2017 | RISK MANAGEMENT ANNUAL REPORT | 87

Stress Test.

Metrics by which the time horizon of liquidity stress scenarios is obtained, such as wholesale

liquidity metrics (wholesale stress scenario), and stressed liquidity metrics (applying stress

scenarios of local crisis, global crisis and idiosyncratic crisis). This metric provides information

about how long the entity could survive without requesting funds to markets and what is the

quantity and minimum time to obtain funds to cover the liquidity needs.

Liquidity Coverage Ratio (LCR)

The LCR shown resistance to short-term of the liquidity risk profile of the Bank, ensuring that it has sufficient high-quality liquid assets to overcome an episode of significant stress for 30

calendar days. The severity of stress period stated in the CUB issued by the CNBV.

Net Stable Funding Ratio (NSFR)

The NSFR is set as a long-term financing ratio which is facing structural funding needs against

financing sources of a stable entity. This requires banks to maintain a stable funding profile in

relation to the composition of its assets and off-balance sheet activities.

B. Data from the reporting period

Structural Gap

Table 7A Million pesos

LCR Y NSFR

Table 7B

Total 1D 1S 1M 3M 6M 9M 1A 5A >5A

Structural GAP 202,158 40,502 112,843 11,895 32,613 38,345 29,174 26,833 219,577 -309,623

Non Derivatives 187,149 40,522 110,373 11,201 32,017 38,228 28,747 26,661 208,064 -308,665

Derivatives 15,009 -21 2,470 694 596 117 428 172 11,513 -959

STRUCTURAL GAP

2017 | RISK MANAGEMENT ANNUAL REPORT | 88

Structural Finance Ratio

Table 7C

dic-17

Structural Funding Ratio 118%

Structural Funding Ratio 759,849

1. Clients funds 518,281

2. Issuance 125,435

3. RRPP 116,133

Structural financing needs 645,563

1. Lending 605,749

2. Investments in group companies 73

3. Reserve Requirements 28,093

4. Other financing needs 11,648

STRUCTURAL FUNDING RATIO

2017 | RISK MANAGEMENT ANNUAL REPORT | 89

8. Operational Risk Management

8.1 Overview

The Operational Risk is the risk of loss due to failures or deficiencies in internal controls resulting from errors in processing and storage operations, or in the transmission of information, inadequate or failed internal

processes, people and internal systems or from external events as well as adverse administrative or legal

resolutions, frauds or theft and includes, among others, Technological Risk and Legal Risk.

This risk is inherent in all products, activities, processes and systems and is generated in all areas of business

and support. Therefore, all employees are responsible for managing and controlling operational risks

generated in its scope, from branches to support functions every employee of Santander is bounded to comply operational risk management.

In terms of operational risk, Banco Santander (Mexico), aligned with the corporate methodology, has

policies, procedures and methodologies for identification, control, mitigation, monitoring and disclosure of operational risks which are reviewed yearly

In order to identify and group the operational risk use is made of distinct categories and business lines

defined by the regulatory authorities, both local and as per the supervision of the institution. The

methodology is based on the identification and documentation of risks, controls and related processes and

uses quantitative and qualitative tools such as risk control self-assessment process, the development of

historical databases and operational risk indicators, among others, for both the control and mitigation and

disclosure requirements.

Among the operational risks, is technological risk, which is defined as the potential losses from damage,

interruption, alteration or failures derived from the use or reliance on hardware, software, systems, applications, networks and any other distribution channel of the information in providing banking services

to customers of Banco Santander (Mexico).

The Bank has adopted a corporate model for technological risk management, which is integrated into the processes of service and support of computer areas to identify, monitor, control, mitigate and report risks

to Information Technology. This is designed to prioritize the establishment of control measures that reduce

the likelihood of risks materializing.

Another operational risk is legal risk, which is defined as the potential loss due to noncompliance with legal and administrative provisions, issuance of adverse administrative and judicial decisions and sanctions,

related to bank operations.

In fulfillment of the steps outlined in the administration of risks, the following functions have been

developed:

a) Establish a 3 Line of Defense Model for Operational Risk Management.

b) Establish policies and procedures to identify, analyze, control and report Operational Risk,

which are reviewed on periodically basis.

c) Analyze the amount of direct or/and potential losses, resulting from the materialization of the

latent operational risks.

d) Disseminate within managers and employees, legal and administrative provisions applicable

to operations.

e) Mandatory annual training regarding Operational Risk for all employees.

f) Perform internal legal audits at least once a year.

2017 | RISK MANAGEMENT ANNUAL REPORT | 90

For the calculation of regulatory capital required for operational risk since November 2016, the Alternate Standard Approach defined in CUB is used.

Thus, to calculate the capital requirement for its exposure to operational risk, just as in the standard method,

for each line of business a percentage was established on the income, but it determines that for the commercial and retail banks the income shall be substituted by the amount of loans and total amount each

line of business.

Operational losses were, during 2017, below the budget; as a result of an improvement of the control environment, strengthening of policies and recoveries through the year.

Figure 1 2017 Operational Risk Losses

Santander Mexico has no appetite to have more than 2% of the gross margin of operational losses. For 2017 the ratio stayed monthly below 1%

Figure 2 Operational Risk Losses between Gross Margin Ratio

-20

0

20

40

60

80

100

120

Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec

Mill

ion

s

Budget Losses

0.5%

1.0%

1.5%

2.0%

Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec

Ratio Alert Limit

2017 | RISK MANAGEMENT ANNUAL REPORT | 91

8.2 Operational Risk Control

Operational risk management is developed taking the following elements:

a. Identify the operational risk inherent in all activities, products, processes and systems.

b. Define the operational risk profile specifying unit strategies and time horizon, through the establishment of appetite and risk tolerance, and budget monitoring.

c. Promote the involvement of all employees in operational risk culture.

d. Measure and evaluate the Operational Risk continuously and consistently with regulatory standards. e. Deploy control procedures.

f. Monitor, verify and suggest mitigation measures that minimize operational risk. g. Identify the real operational risk exposure of Santander Mexico.

h. Produce regular reports on the exposure to operational risk and level of control of both internally

and to the market and regulators bodies.

For each of these elements, Banco Stander (Mexico) should define and deploy systems to monitor and control operational risk exposures, integrated in the daily management of the bank, taking advantage of

existing technology.

Table 8A Properties model management and control of operational risk

implemented in Banco Santander (Mexico)

Promotes the development of operational risk culture

Allows a comprehensive and effective operational risk management (identification,

measurement, assessment, control, mitigation and information).

Improves the coordination between departments to identify, communicate risks and

boost efforts for the control.

Operational risk information helps to improve the processes and controls, reduce

losses and income volatility.

Deliver information to the General Management for decision making.

Facilitates the establishment of limits for operational risk appetite.

2017 | RISK MANAGEMENT ANNUAL REPORT | 92

9. Capital

9.1 Overview

Capital management in the institution seeks to ensure the solvency of the company and maximize profitability, ensuring compliance with internal capital targets and regulatory requirements. It is an essential

tool for making strategic decisions using their management objectives established for determining risk appetite, planning and capital budgeting, and the use of metrics to evaluate the profitability and value

creation business.

To carry out this management is part of the following key objectives:

1. Capital Budget: It is held annually determining a set of target values for each of the months

of the following year, which ensure that capital levels are adequate at all times with the

risk profile of the entity and regulatory minimum requirements.

2. Capital Planning: It is made considering applicable regulatory requirements, and in it the

sufficiency of current and future capital is analyzed by capital projections under different

macroeconomic scenarios.

3. Establishment of Risk Appetite: Budget processes and capital planning must be aligned and

coordinated with the establishment of risk appetite.

4. Minimum Criteria: In preparing proposals for capital targets should be considered:

All material risks to which the institution is exposed and are consistent with its risk

profile referred.

They are consistent with the budgets, strategic plans and business results forecasts,

and liquidity and ability obtain funding from various sources, taking into account

the correlation and dependency thereof.

Incorporate risk factors external to the entity, arising from the regulatory, legal

environment, economic or business.

All applicable regulatory requirements are met.

To be considered plausible stress scenarios in addition to the regular scenarios.

That the objectives include at least quality and composition of capital (equity mix),

ratios or levels of solvency, dividend policy and target values metric of profitability

of invested capital and creating value by product segments, business and/or units.

9.2 Function of Capital

Capital policies set general guidelines that should govern the actions of the areas involved in the processes

of management and control of equity.

9.2.1 Capital Strategic Policies

Autonomy of Capital: Banco Santander (Mexico) is endowed with the capital required to

autonomously develop their activity and meet regulatory requirements on capital and

liquidity.

Central Monitoring: The capital management model ensures a comprehensive view, so that

the control exercised primarily by Banco Santander (Mexico) is complemented by the

monitoring provided by the corporate unit.

2017 | RISK MANAGEMENT ANNUAL REPORT | 93

Proper Distribution of own Resources: Banco Santander (Mexico) should monitor their

adequate capitalization (including its subsidiaries) and the adoption of balanced approach in

the allocation of own resources to optimize the relationship between solvency and

profitability.

Reinforcement of Capital: Regardless of the need to operate with an adequate level of own

funds (capital available) to meet legal and regulatory requirements, It ensures proper

composition promoting the choice of computable elements of the highest possible quality

(according to their ability to absorb losses, the retention time in the balance sheet of the

entity and priority in the authorization) in order to guarantee its stability.

Capital Preservation: The capital is a very scarce resource that must be used in the most

efficient way possible. In this regard Banco Santander (Mexico) has mechanisms for

continuous monitoring of capital consumption optimization.

Sound Management: The capital management is based on ensuring the solvency based on

an acceptable level of profitability on invested capital. This management is based on equity

targets consistent with the risk profile of the institution limiting the levels and types of risks

that the institution is willing to take on the development of its activity and ensuring the

maintenance of adequate capitalization.

Maximizing Value Creation: Investment decisions are aimed at optimizing the creation of

value on invested capital, enabling management to align the business with capital

management from analysis and monitoring of a set of metrics that relate the capital cost of

resources to the benefit obtained by reversing the investment of them, that make it possible

to compare performance on a standardized basis of operations, clients, portfolios and

businesses.

Stress Test: Banco Santander (Mexico) periodically performs stress tests under adverse

scenarios to assess that capitalization remains solid and above risk appetite limits, approved

and established by the corporate governance entities.

9.2.2 Management and Control Policies

Objective of analysis and derivative actions: The main objective of the monthly monitoring

and measurement metrics, is to help senior management in the process of making strategic

decisions on solvency, capitalization and profitability of business.

Minimum Frequency: At least once a month takes place a process of control and monitoring

of the evolution of the different metrics of capital through various reports that are distributed

to senior management and internal and corporate areas.

Content of the Analyses: The causes of the variations in the amounts and/or deviations from

budget or for business, changes in markets or economic variables, changes in the

methodology of the models or parameters, changes in legislation or otherwise nature are

studied Specifically, the main analyzes carried out with recurring basis are:

Analysis of solvency and its evolution, comparing domestic capital base with

regulatory capital requirements.

Development of key capital metrics and analysis of the major monthly variations.

Analysis of the volume of required capital and risk weighted assets based on risks

other than credit risk.

2017 | RISK MANAGEMENT ANNUAL REPORT | 94

Analysis of the impact produced by recalibration, methodological changes in the

patterns and changes in legislation.

Analysis of the composition of capital in order to maintain a strong capital level,

both in amount and composition thereof.

9.2.3 Organizational Structure and Governance Model

The proper development of the function of capital, both in terms of decision-making and in terms of

supervision and control, it needs a structure of agile and efficient governance organs to ensure the participation of relevant stakeholders, and ensure the necessary involvement of senior management.

Table 9A

Banco Santander (Mexico) Structure for Capital Management

Comprehensive Risk Management Committee (CRMC):

CRMC is responsible for submitting to the Board of Directors the following aspects of equity:

a. Communications with the controller information on aspects relating to solvency and capital;

evolution of figures of capital, return on capital, adjusted for risk; compliance with capital and

budget plans associated with the implementation of internal models.

b. Application for approval of objectives, guidelines, policies of capital:

Minimum level of solvency of the entity.

Minimum requirements for return on equity of business or transactions.

2017 | RISK MANAGEMENT ANNUAL REPORT | 95

Allocation of capital needed to the business units.

Transactions with significant impact on the management of capital and solvency levels.

Stress tests carried out to assess the sensitivity of capital to unlikely but plausible

scenarios that affect business planning and its capital required, and the necessary

measures to ensure minimum levels of solvency in the event of stress scenarios posed occur.

Board of Directors

In terms of capital, performs the functions of:

a. Capital Budget.

b. Briefing of the main decisions taken by the Committee of Capital. c. Periodic review of the capital figures of the institution and business.

d. Monitoring of projects associated with the effective implementation of policies and tools relating to capital.

INTEGRANTES

Committee of Capital

The Committee of Capital is responsible for the supervision, approval, and valuation of all aspects of capital and solvency of the institution whose primary responsibilities are:

a. In terms of supervision:

Analysis of the solvency and capital adequacy.

Monitoring of compliance with budgets, capital planning and stress test analysis.

Monitoring the use of capital, RORAC and RORWA, of the institution and business.

Supervision and monitoring of all aspects related to the implementation of internal

models.

With respect to capital management, will be responsible for raising the CAIR eventual

decision to activate the viability plan in terms relating to the solvency.

Presentation and major decisions taken by the Committee of Capital to CAIR on solvency

and capital adequacy.

b. In terms of authorization:

Review and validation of the planning exercises and capital stress test prior to internal

approval or presentation to the relevant supervisory authority.

Approval of changes in capital models and methodologies, considered as relevant for

internal purposes, together with the report of the independent validation area.

c. In terms of identification of proposals:

Objectives of capital for the planning horizon.

Optimization of capital consumption.

Improvement of solvency ratios.

Improved capital models and their integration in management.

In terms of capital, this Committee coordinates relations with supervisors and the flow of information to the

market.

2017 | RISK MANAGEMENT ANNUAL REPORT | 96

9.3 Calculation of the Capital Requirement for Credit Risk

In accordance with the provisions of the CACI, to calculate their capital requirements for credit risk, the

institution may use:

a. The standard method by which the institutions in order to determine their capital requirements for

credit risk shall classify their operations Subject to credit risk in any of the groups established in the

regulation, according to the issuer or counterparty or, where applicable, the type of credit of the

case.

b. Some of the methods based on internal, basic or advanced ratings, provided they obtain prior

authorization from the Commission to the effect. To use internal methodologies to calculate capital

requirements for credit risk, must be used own estimates of risk components in their positions

subject to credit risk:

Being an Internal Methodology with Foundation Approach, obtaining the probability of

default (PD) of their positions subject to risk based on own estimates and for the rest of

the components of credit risk, institutions shall comply with the provisions of the CUB.

In the case of an internal methodology with advanced approach, using proprietary

Probability of Default (PD) estimates, the Severity of Loss Given Default (LGD), Exposure

at Default (EAD) and the Term Cash or expiration of their positions subject to credit risk.

To calculate the capital requirement for credit risk under the standard method, the transactions subject to

credit risk according to the issuer or counterparty to the transaction or, where applicable, the type of credit that are classified concerned:

Group 1-A: Cash, federal government and IPAB.

Group 1-B: Derivatives. Group 2: Sovereign and multinational development banks.

Group 3: Financial Entities and brokerages.

Group 4: Development banks, trusts and parastatal. Group 5: States and Municipalities.

Group 6: Credit to individuals (Mortgage for housing and consumption). Group 7: Credit to business.

Group 8: Past-due portfolio. Group 9: Other assets.

Based on these groups of risk weights to be used in each different group for the calculation of capital

requirements16 are defined. To determine the degree of risk of each of the loans making up these portfolios,

ratings apply to all operations whose counterparty credit risk or issue is rated by rating agencies duly

authorized by the CNBV. The Institution Standard and Poors, Fitch, Moody’s and HR Ratings use the

ratings.17

16 Risk levels indicated in the tables of correspondence of ratings and degrees of risk, long term and short term, for both global and for Mexico scale, included in Annex 1-B of the CUB and are required to determining the average weight for credit risk.

17 It should be noted that the institution does not assign public ratings to comparable assets that are unrated.

2017 | RISK MANAGEMENT ANNUAL REPORT | 97

The organization uses risk mitigation techniques using both collateral and personal securities, complying at all times with the principles set out in Section 4.3 of this chapter.

In particular, the results of the risk mitigation process for calculating the capital requirement for credit risk

of rated portfolio with the standard method at the end year of the fourth quarter, is presented in the table below.

Table 9B

Standard Method. Risk Mitigation

Since 2012, the CNBV authorizes Banco Santander (Mexico) using methods based on basic internal rating

to calculate the capital requirement for credit risk of the loan portfolios following:

Business Global Corporate Bank (GCB).

Financial Institutions Banks.

Corporate18.

The application of this methodology for these portfolios is implemented in the calculation of capital in

December 2013.

The following tables can be seen quantitative information corresponding to key metrics of the internal

methodology with Foundation Approach by regulatory segment:

18 For the Corporate, in 2012 the CNBV authorized Banco Santander (Mexico) the use of internal ratings-based

method for the Basic model. In October 2015 this model migrated to an advanced internal model approach

after authorization from the CNBV.

Standard Methodology. millions of pesos

Standard Credit Risk Groups EAD covered by

personal guarantees

EAD covered by

collateral - Simple

Method

EAD covered by

collateral - Integral

Method

Grupo I 4,222

Grupo II

Grupo III 7,449

Grupo IV 942

Grupo V

Grupo VI

Grupo VII 3,857 35,849

Grupo VIII

Grupo IX 12,979

Grupo X

Total December 2017 21,058 44,240 0

Total September 2017 18,250 26,127 0

2017 | RISK MANAGEMENT ANNUAL REPORT | 98

Table 9C

PD, EAD, LGD by interval of probability of default

(Foundation Internal Rating Based-FIRB)

FOUNDATION INTERNAL RATING BASED. FINANCIAL INSTITUTIONS

PD Interval Levels

S&P

Balance

Million of pesos

EAD

Millions of

pesos

PD weighted by

EAD

LGD weighted

by EAD

RWA / EAD

Credit Risk

weight

Expected loss /

EAD

Write offs (1)

Million of pesos

Recoveries (2)

Million of pesos

Provisions (3)

Millions of

pesos

[0,00296;0,00769) AAA

[0,00769;0,01474) AA+

[0,01474;0,025) AA

[0,025;0,045) AA-

[0,045;0,065) A+

[0,065;0,075) A

[0,075;0,11) A-

[0,11;0,17) BBB+

[0,17;0,26) BBB 205 205 0.26% 40.83% 32.63% 0.10%

[0,26;0,375) BBB-

[0,375;0,555) BB+

[0,555;0,905) BB

[0,905;1,72) BB- 486 486 1.01% 40.83% 66.77% 0.41%

[1,72;3,52) B+

[3,52; 6,325) B

[6,325;17,395) B-

[17,395;100) CCC/C

100.00000 D

Total December 2017 691 691 0.79% 40.83% 56.65% 0.32% 0 0

Total September 2017 1,100 1,100 0.48% 40.83% 48.16% 0.20% 0 0

Total December 2016 28

PD Interval Levels

S&P

Balance

Million of pesos

EAD

Millions of

pesos

PD weighted by

EAD

LGD weighted

by EAD

RWA / EAD

Credit Risk

weight

Expected loss /

EAD

Write offs (1)

Million of pesos

Recoveries (2)

Million of pesos

Provisions (3)

Millions of

pesos

[0,00296;0,00769) AAA

[0,00769;0,01474) AA+

[0,01474;0,025) AA

[0,025;0,045) AA-

[0,045;0,065) A+

[0,065;0,075) A

[0,075;0,11) A-

[0,11;0,17) BBB+

[0,17;0,26) BBB 14,981 14,995 0.26% 40.83% 42.00% 0.10%

[0,26;0,375) BBB-

[0,375;0,555) BB+ 16,682 19,333 0.38% 40.83% 55.41% 0.15%

[0,555;0,905) BB

[0,905;1,72) BB- 89,907 96,847 1.11% 40.83% 73.35% 0.45%

[1,72;3,52) B+ 3,845 3,945 2.92% 40.83% 98.20% 1.19%

[3,52; 6,325) B

[6,325;17,395) B- 2,204 2,215 6.43% 40.83% 139.93% 2.61%

[17,395;100) CCC/C 52 52 24.20% 40.83% 221.37% 9.88%

100.00000 D 1,200 1,203 100.00% 43.69% 28.16% 41.43%

Total December 2017 128,872 138,591 1.92% 40.86% 68.89% 0.79% 243 10

Total September 2017 123,585 133,613 1.60% 40.84% 70.94% 0.65% 83 10

Total December 2016 1,335

FOUNDATION INTERNAL RATING BASED

COMPANIES WITH ANNUAL SALES EQUAL OR GREATER THAN 14 MILLIONS OF UDIS

2017 | RISK MANAGEMENT ANNUAL REPORT | 99

In October 2015, the CNBV authorized Banco Santander (Mexico) using models based on internal ratings

for the calculation of minimum capital requirements for credit risk by the advanced method for the next

portfolios:

Corporate.

Real Estate Companies (Property Developer).

This methodology with advanced approach is implemented in calculating capital in October 2015.

The following tables can be seen quantitative information corresponding to key metrics of the internal methodology with advanced approach by regulatory segment:

PD Interval Levels

S&P

Balance

Million of pesos

EAD

Millions of

pesos

PD weighted by

EAD

LGD weighted

by EAD

RWA / EAD

Credit Risk

weight

Expected loss /

EAD

Write offs (1)

Million of pesos

Recoveries (2)

Million of pesos

Provisions (3)

Millions of

pesos

[0,00296;0,00769) AAA

[0,00769;0,01474) AA+

[0,01474;0,025) AA

[0,025;0,045) AA-

[0,045;0,065) A+

[0,065;0,075) A

[0,075;0,11) A-

[0,11;0,17) BBB+

[0,17;0,26) BBB 2,012 2,012 0.26% 40.83% 43.63% 0.10%

[0,26;0,375) BBB-

[0,375;0,555) BB+ 347 347 0.38% 40.83% 54.30% 0.15%

[0,555;0,905) BB

[0,905;1,72) BB- 9,491 9,960 1.27% 40.83% 87.25% 0.52%

[1,72;3,52) B+ 646 694 2.95% 40.83% 109.81% 1.20%

[3,52; 6,325) B

[6,325;17,395) B- 1,527 1,529 6.37% 40.83% 136.67% 2.59%

[17,395;100) CCC/C

100.00000 D 659 716 100.00% 53.60% 27.22% 51.42%

Total December 2017 14,682 15,256 6.33% 41.43% 83.91% 3.08% 482 20

Total September 2017 14,495 15,034 8.91% 41.86% 82.88% 4.57% 594 46

Total December 2016 734

1/ It refers to the charged off amount during the last year that correspond to the clients with exposure to the end of the previous year.

2/ It refers to the recovered amount of the charged off portfolio during the last year that correspond to the clients with exposure to the end of the previous year.

3/ It refers to the reserves amount (Expected loss) that correspond to the clients with exposure at the end of last year.

FOUNDATION INTERNAL RATING BASED

COMPANIES WITH ANNUAL SALES OF LESS THAN 14 MILLIONS OF UDIS

2017 | RISK MANAGEMENT ANNUAL REPORT | 100

Table 9D PD, EAD, LGD by interval of probability of default

(Advanced Internal Rating Based-AIRB)

PD Interval Levels

S&P

Balance

Million of pesos

EAD

Millions of pesos

PD weighted by

EAD

LGD weighted by

EAD

RWA / EAD

Credit Risk

weight

Expected loss /

EAD

Write offs (1)

Million of pesos

Recoveries (2)

Million of pesos

Provisions (3)

Millions of pesos

[0,00296;0,00769) AAA

[0,00769;0,01474) AA+

[0,01474;0,025) AA

[0,025;0,045) AA- 0 5,533 0.03% 45.00% 19.58% 0.01%

[0,045;0,065) A+ 0 2,156 0.05% 45.00% 27.59% 0.02%

[0,065;0,075) A

[0,075;0,11) A- 1,370 9,140 0.09% 45.00% 28.26% 0.04%

[0,11;0,17) BBB+ 565 1,280 0.14% 45.00% 35.95% 0.07%

[0,17;0,26) BBB 0 36 0.25% 45.00% 45.05% 0.11%

[0,26;0,375) BBB-

[0,375;0,555) BB+ 232 264 0.51% 45.00% 74.29% 0.23%

[0,555;0,905) BB 511 556 0.72% 45.00% 77.24% 0.32%

[0,905;1,72) BB-

[1,72;3,52) B+

[3,52; 6,325) B

[6,325;17,395) B-

[17,395;100) CCC/C

100.00000 D

Total December 2017 2,678 18,964 0.09% 45.00% 28.28% 0.04% 0 0

Total September 2017 1,746 16,235 0.08% 45.00% 26.97% 0.04% 0 0

Total December 2016 1

ADVANCED INTERNAL RATING BASED. FINANCIAL INSTIUTUTIONS

PD Interval Levels

S&P

Balance

Million of pesos

EAD

Millions of pesos

PD weighted by

EAD

LGD weighted by

EAD

RWA / EAD

Credit Risk

weight

Expected loss /

EAD

Write offs (1)

Million of pesos

Recoveries (2)

Million of pesos

Provisions (3)

Millions of pesos

[0,00296;0,00769) AAA

[0,00769;0,01474) AA+

[0,01474;0,025) AA

[0,025;0,045) AA- 0 313 0.03% 45.00% 15.01% 0.01%

[0,045;0,065) A+ 23,635 35,893 0.06% 45.00% 21.04% 0.03%

[0,065;0,075) A

[0,075;0,11) A- 8,775 10,180 0.10% 45.00% 28.06% 0.04%

[0,11;0,17) BBB+

[0,17;0,26) BBB 15,098 27,354 0.17% 45.00% 36.40% 0.08%

[0,26;0,375) BBB- 10,941 13,314 0.30% 45.00% 50.42% 0.14%

[0,375;0,555) BB+ 5,746 7,565 0.52% 45.00% 61.20% 0.24%

[0,555;0,905) BB

[0,905;1,72) BB- 7,349 9,023 0.94% 45.00% 89.93% 0.42%

[1,72;3,52) B+

[3,52; 6,325) B 0 0 4.69% 45.00% 125.60% 2.11%

[6,325;17,395) B-

[17,395;100) CCC/C 0 75 20.76% 45.00% 254.38% 9.34%

100.00000 D 608 608 100.00% 45.00% 0.00% 45.00%

Total December 2017 72,153 104,327 0.83% 45.00% 38.40% 0.37% 267 0

Total September 2017 89,333 115,066 0.87% 45.02% 35.70% 0.41% 0 0

Total December 2016 708

ADVANCED INTERNAL RATING BASED. COMPANIES WITH ANNUAL SALES EQUAL OR GREATER THAN 14 MILLIONS OF UDIS

PD Interval Levels

S&P

Balance

Million of pesos

EAD

Millions of pesos

PD weighted by

EAD

LGD weighted by

EAD

RWA / EAD

Credit Risk

weight

Expected loss /

EAD

Write offs (1)

Million of pesos

Recoveries (2)

Million of pesos

Provisions (3)

Millions of pesos

[0,00296;0,00769) AAA

[0,00769;0,01474) AA+

[0,01474;0,025) AA

[0,025;0,045) AA- 0 1287 0.03% 45.00% 15.98% 0.01%

[0,045;0,065) A+ 0 678 0.06% 45.00% 12.98% 0.03%

[0,065;0,075) A

[0,075;0,11) A- 1822 1873 0.10% 45.00% 13.22% 0.04%

[0,11;0,17) BBB+

[0,17;0,26) BBB 70 119 0.17% 45.00% 32.10% 0.08%

[0,26;0,375) BBB- 211 221 0.30% 45.00% 48.80% 0.14%

[0,375;0,555) BB+ 351 450 0.52% 45.00% 63.01% 0.24%

[0,555;0,905) BB

[0,905;1,72) BB- 618 978 0.91% 45.00% 86.47% 0.41%

[1,72;3,52) B+

[3,52; 6,325) B

[6,325;17,395) B-

[17,395;100) CCC/C

100.00000 D 1539 1539 100.00% 45.00% 0.00% 45.00%

Total September 2017 4,611 7,145 21.75% 45.00% 25.42% 9.79% 1,149 2

Total June 2017 5,797 7,158 15.07% 48.08% 35.56% 9.86% 2,037 0

Total September 2016 1,159

ADVANCED INTERNAL RATING BASED. COMPANIES WITH ANNUAL SALES OF LESS THAN 14 MILLIONS OF UDIS

2017 | RISK MANAGEMENT ANNUAL REPORT | 101

Table 9E

Similarly to, what was said to the standard method, the Bank uses risk mitigation techniques complying at

all times with the principles set out in Section 4.3 of this chapter. In particular, the results of the risk mitigation process for calculating the capital requirement for credit risk of ratings portfolio with basic internal

method at the end year of fourth quarter, are presented in the following table:

EAD (million of pesos)

Type Sep-17 Dec-17

Financial Instituitions 17,334 19,656

Companies > 14 MM 228,012 242,917

Companies < 14 MM 42,859 22,402

PD weighted by EAD

Type Sep-17 Dec-17

Financial Instituitions 0.10% 0.12%

Companies > 14 MM 1.37% 1.45%

Companies < 14 MM 5.67% 11.25%

LGD weighted by EAD

Type Sep-17 Dec-17

Financial Instituitions 44.74% 44.85%

Companies > 14 MM 42.57% 42.64%

Companies < 14 MM 44.41% 42.57%

RWA / EAD

Type Sep-17 Dec-17

Financial Instituitions 28.31% 29.28%

Companies > 14 MM 57.98% 55.80%

Companies < 14 MM 43.54% 65.25%

PE / EAD

Type Sep-17 Dec-17

Financial Instituitions 0.05% 0.05%

Companies > 14 MM 0.59% 0.61%

Companies < 14 MM 3.26% 5.22%

RISK PARAMETERS EVOLUTION

2017 | RISK MANAGEMENT ANNUAL REPORT | 102

Table 9F

It is noteworthy that the main characteristics of the parameters of internal methodologies are detailed in the section on Credit Risk.

9.4 Capital Requirement Calculation of Counterparty Risk

In calculating capital requirements for counterparty risk under the standard method, prior to credit risk

weight, a value of conversion to credit risk is determined. In the case of derivative transactions, the value

is the positive amount of the subtract of the fair value of the active part of the operation, less the fair value

of the passive part plus an additional factor to reflect potential future exposure over the remaining term of

the operation (one year or less, from one to five years and over five years) and the type of the underlying

(interest rates, currencies, equities, precious metals, other).

After obtaining the conversion value, the risk weight is determined according to the form that contractually

has defined for settlement.

Derivatives operations have a weighting factor of 2% when settled by a clearinghouse authorized by the

Secretaria de Hacienda y Crédito Público or when settled in clearinghouses abroad, the Banco de Mexico

recognizes them.

When the institution can’t perform operations directly on their own to a clearing house and acts through a

clearing partner for the clearing house, these operations have a weighting of 4% if the institution is not

protected against breach of the clearing partner or 2% when it is protected.

Personal Collateral Average weighted PD by EAD

before mitigation

Average weighted PD by EAD

after mitigation

Financial Instituitions 0.12% 0.12%

Companies > 14 MM 1.69% 1.51%

Companies < 14 MM 8.04% 7.74%

Effective Collateral - Integral

Method

Average weighted LGD by

EAD before mitigation

Average weighted LGD by

EAD after mitigation

Financial Instituitions 44.85% 44.85%

Companies > 14 MM 42.53% 42.53%

Companies < 14 MM 43.33% 43.33%

FIRB & AIRB

December 2017

PD y LGD WITH RISK MITIGATION

2017 | RISK MANAGEMENT ANNUAL REPORT | 103

Table 9G

Counterparty risk exposure

9.5 Calculating the capital requirement for market risk

To calculate the capital requirement for market risk, the methodology established in the CUB is followed,

and operations are classified according to the type of market risk incurred (type of interest rate, exchange rate, inflation, minimum wage and others):

a) Transactions with nominal interest rate.

b) Transactions with real interest rate.

c) Transactions indexed to minimum wage.

d) Transactions indexed to the exchange rate.

e) Transactions indexed to inflation.

f) Transactions with shares or referred to a stock index.

g) Transactions with goods.

In each of these cases the asset and liability positions classified in the band that corresponds to its term to maturity or duration, and multiplied by the coefficient of charge for market risk, once the compensation

allowed by the regulation is done:

Net position of each band.

Compensation within the bands.

Compensation between bands of the same area.

Compensation between bands of different area.

millIons of pesos Dec-17

Total 63,735

Of: Derivatives 63,184

Exposure in derivatives. Effect of Netting and Collaterales Dec-17

(A) Gross Positive fair value of the contracts 180,288

(B) Add-on 103,018

(C) Positive effects as a result of the mitigation of netting agreements. 175,881

(D) Current credit exposure after netting. 107,424

(D.1) Addon net 41,207

(D.2) MtM net 66,217

(E) Collateral received 44,240

(F) Credit exposure in derivatives 63,184

Total exposure to counterparty risk

(Standard Method)

Exposure in derivatives (Standard Method )

2017 | RISK MANAGEMENT ANNUAL REPORT | 104

Specifically, in the operations of options and warrants, apply the formulas set out in the regulation to calculate the capital requirement for market risk by measuring the gamma impact (depending on the

variability of the underlying) and Vega impact (depending on the volatility of the option).

From September 2016, the CNBV approved the usage of the internal “Stability and Sensitivity of Demand Deposits” model, that statistically determines the stability of MXN demand deposits and the sensitivity to

the paid rate compared to the market rates, in accordance with Annex 1-A, paragraph 1, numeral 1.1 of

the Circular Única de Bancos (Circular applicable to Credit Institutions).

9.6 Calculation of the Capital Requirement for Operational Risk

The calculation of the Operational Risk Capital Requirement is based on the Alternative Standard Approach,

approved by the CNBV during 2016 in accordance with Title First Bis – Chapter V – Article 2 Bis 114 of the

Circular Única de Bancos, Banco Santander (Mexico) complied with the requirements described in the Annex 1D of the same.

9.7 Regulatory Capital

The integration of net capital is determined according to the provisions of Chapter II of Title First Bis and

then the corresponding integration is presented to December.

Table 9H

Sep 17 Dic 17

Tier 1 Capital 90,730 89,267

Preferential shares 34,798 34,798

Retained profits 59,982 55,165

Other profit elements 22,456 26,163

Goodwill -1,735 -1,735

Other intangibles -4,423 -5,151

Investments in related companies -22,753 -23,541

Investments in subordinated debt instruments -923 -350

Other regulatory adjustments -5,732 -5,893

Capitalization instruments CET 1 9,061 9,812

Tier 2 Capital 23,812 26,054

Capitalization instruments 23,693 26,054

Reserves 119 0

Capital Neto 114,542 115,321

Total weighted assets by credit risk 707,365 733,036

Tier 1 capital to risk-weighted assets 12.83% 12.18%

Capital Ratio (ICAP) 16.19% 15.73%

Regulatory Capital

millions of pesos

Concept

2017 | RISK MANAGEMENT ANNUAL REPORT | 105

The following table can be seen quantitative information corresponding to the distribution of capital requirements by type of risk, as well as the evolution of each of the previous quarter to the current:

Table 9I

Capital Requirements - Market Risk

Capital Requirements - Credit Risk Capital Requirements - Operational Risk

18%

76

6%

Market Risk 19%

Credit Risk 75%

Operational Risk 6%

Sep 17

Dec17

10,309

11,053

Sep17 Dic17

43,213

44,274

Sep17 Dic17

3,069

3,315

Sep17 Dic17