← Back to ING filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
A.History and development of the company
General
ING Groep N.V. was established as a Naamloze Vennootschap (a Dutch
public limited liability company) on March 4, 1991. ING Groep N.V. is
incorporated under the laws of the Netherlands.
The corporate site of ING, www.ing.com, provides news, investor relations
and general information about the company.
ING is required to file certain documents and information with the United
States Securities and Exchange Commission (SEC). These filings relate
primarily to periodic reporting requirements applicable to issuers of
securities, as well as to beneficial ownership reporting requirements as a
holder of securities. The most common filings we submit to the SEC are
Forms 6-K and 20-F (periodic reporting requirements). The SEC maintains
an internet site that contains reports, proxy and information statements,
and other information regarding issuers that file electronically with the SEC
at http://www.sec.gov. ING’s electronic filings are available on the SEC’s
internet site under CIK ID 0001039765 (ING Groep NV).
The official address of ING Group is:
ING Groep N.V.
Bijlmerdreef 106
1102 CT Amsterdam
P.O. Box 1800,
1000 BV Amsterdam
The Netherlands
Telephone +31 20 563 9111
The name and address of ING Group’s agent for service of process in the
United States in connection with ING’s registration statement on Form F-3
is:
ING Financial Holdings Corporation
1133 Avenue of the Americas
New York, NY 10036
United States of America
Telephone +1 646 424 6000
Changes in the composition of the Group
There were no significant acquisitions and divestments in 2025, 2024 or
2023.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 29
B.Business Overview
Our strategy
As part of our 'Growing the difference' strategy
our ambition is to accelerate growth, increase
impact, and deliver value to become the best
European bank.
Growing the difference means expanding our scale and impact across
more markets and segments to become the most loved, most impactful
and most valued bank. We aim to increase our relevance by deepening
customer relationships, broadening services, and continuing to make
banking easier and more seamless. Our two main priorities are providing
superior customer value and putting sustainability at the heart of what we
do, supported by four key enablers.
This strategy translates into specific business goals: in Retail, we focus on
Private Individuals, including Gen Z and affluent customers, as well as
small and medium-sized enterprises through Business Banking, and high-
net-worth and investment clients via Private Banking & Wealth
Management. Each segment has a dedicated approach aligned with our
priorities: enhancing digital engagement for younger customers, offering
personalised solutions for affluent clients, and delivering superior value
across all relationships. In Wholesale Banking, we aim to create greater
value by reinforcing our role as a strategic partner and core bank for large
corporates, multinationals, and institutional clients. Guided by our purpose
to empower people to stay a step ahead, we help individuals and
businesses realise their vision for a better future.
Providing superior value for customers
Banking relies on strong relationships, and the strongest relationships are
those where people feel valued, confident, empowered and in control. This
is how we want our customers to feel throughout their journey with us.
Growing the difference means sharpening our focus on customer value,
moving beyond one-size-fits-all services towards more tailored solutions
for each customer segment. In Retail Banking, this is about offering the
right services, at the right time, in the right way. In Wholesale Banking, this
means leveraging our network, expertise and sustainability leadership.
Putting sustainability at the heart of what we do
Our sustainability strategy spans climate, nature and social agendas,
recognising their interdependencies and how they affect each other, both
positively and negatively, and taking into account the legal and regulatory
frameworks in the jurisdictions in which we operate. Each of these is a
complex and dynamic issue, so our response needs to be dynamic as well.
As scientific understanding is continually advancing, our approach will also
keep evolving. Therefore, our climate action has evolved to encompass
both mitigation and a growing emphasis on adaptation. Increasingly, we
are also exploring how we can play a role in halting and reversing nature
degradation and regenerating natural systems, while respecting human
rights and working to advance financial health and inclusion for customers
and communities.
Four enabling priorities
Providing seamless digital services
We can serve our customers better if we use ‘always-on’ channels,
providing data-enabled personalised experiences and end-to-end digital
processes, with human intervention only where needed or desired.
Using scalable technology and operations
A technology and operations foundation that is modular and scalable
brings many benefits, including superior customer experience and safety.
Staying safe and secure
Trust is fundamental for all stakeholders, especially at a digital-first bank
like ING. Customers rely on us to safeguard their money and data, and
maintaining this trust is essential.
Unlocking our people’s full potential
We aim to attract, develop, and retain future-ready talent and foster an
environment that enables employees to thrive, maximising their growth
and impact.
1 Operative customers
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 30
Superior value for customers
Providing superior value for customers is one of
our two overarching priorities, as we strive to
make banking easy, instant, personal and
relevant. For Retail Banking, delivering superior
customer value means making banking simple
and expertise accessible, offering the right
services, at the right time, in the right way.
For Wholesale Banking, delivering superior value
for customers means building on our network
strength, sector expertise, and sustainability
leadership.
Retail Banking
In Retail Banking, we service customers across three pillars: Private
Individuals, Business Banking, and Private Banking & Wealth Management.
Equipped with leading digital capabilities, we strive to provide a mobile-
first digital, frictionless, and relevant banking experience, shaped to
specific customer needs for all of these pillars.
Private Individuals
We serve nearly 41 million Private Individual customers1 across 10
markets: the Netherlands, Belgium, Luxembourg, Germany, Spain, Italy,
Türkiye, Poland, Romania and Australia.
ING offers a broad range of banking products and services for private
individuals, including savings accounts, payments, credit cards,
mortgages, unsecured lending, investment solutions and insurance
products. We seek to deliver banking that is easy, instant, personal and
relevant. We focus on simplifying our services, improving our digital
capabilities, and anticipating customer needs to help people manage their
financial lives. Our progress is reflected in customers choosing us as their
primary bank and in their willingness to recommend us, as indicated by
our leading NPS score in five out of ten retail markets.
ING aims to build primary relationships with customers. In Retail Banking,
we define this as customers holding an active payment account with
recurrent income, plus at least one other active product with us. Earning
primary relationships is a key driver of sustainable, profitable growth. It
leads to deeper loyalty, significantly higher engagement, greater
customer satisfaction and ultimately higher value, as customers choose
ING for a broader set of their financial needs.
Growing the difference means focusing even more on growing value for
customers. We continue to expand our offering by developing relevant
propositions for our various customer groups and applying a personalised
approach enabled by our digital banking capabilities. Our priorities include
becoming the bank of choice for Gen Z and affluent customers, expanding
subscription-based services that provide superior customer value,
diversifying our Private Individuals lending portfolio, and partnering to offer
full-service solutions that help homeowners make their homes more
sustainable. We are also broadening our investment and savings offering
to help customers protect and grow their wealth and manage their
financial health more effectively.
We strive to provide a seamless, mobile-first digital experience, engaging
customers across their daily banking activities and offering personalised
products and services supported by advanced technology and data-driven
insights. As mobile adoption continues to grow, customer expectations for
digital services are rising. In 2025, 87 percent of customers chose mobile
as their primary channel, up from 84 percent in 2024.
This growth has led to an increase in mobile primary customers – defined
as customers with at least one mobile interaction through our app or
mobile website per quarter. In 2025, in line with our mobile-first ambition,
we expanded our mobile primary customer base by over 1 million to 15.4
million.
In 2025, customers visited our digital platforms 8.8 billion times, an
increase of 6 percent compared to 2024.
Business Banking
For Business Banking clients, growing the difference means making banking
simple, frictionless, and tailored to their needs. Our ambition is to be the first
choice for entrepreneurs and businesses to manage and grow their
operations. We define success by delivering superior customer value
through digital innovation, expert advice, and sector-specific solutions.
Business Banking serves clients in nine markets: the Netherlands, Belgium,
Luxembourg, Germany, Türkiye, Poland, Romania, Australia, and most
recently Italy, where we began offering Business Banking services to a select
group of customers at the end of 2025 ahead of the wider commercial
launch in January 2026.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 31
Our service model addresses both basic and complex needs, offering
solutions through a mix of self-service digital platforms and remote or in-
person advisory. Through this approach, we aim to strengthen client
engagement and incorporate sector-specific expertise to support informed
decision-making.
Across all three segments – Self-Employed & Micro, SME, and Mid-Corps –
we focus on making banking effortless and accessible. As of 2025, we offer
digital onboarding journeys, and instant and fast-track lending across six
markets: the Netherlands, Belgium, Poland, Romania, Türkiye and Germany.
We aim to combine digital convenience with human expertise, making
sure every client, regardless of size, receives the support they need.
Private Banking & Wealth Management
Private Banking, Wealth Management & Investments combines our Private
Banking & Wealth Management activities with our total Retail investments
business across Private Individuals, Private Banking and Business Banking
clients. We do this through a scalable investments platform that we are
implementing across our Retail markets, designed to meet diverse client
needs.
Our Private Banking & Wealth Management offering provides tailored
banking solutions to ultra-high-net worth individuals and high-net-worth
individuals and their entities in the Netherlands, Belgium, Luxembourg,
and Poland. We provide clients with investment solutions focused on
managing, preserving, and growing their wealth. Beyond investments, we
offer solutions to meet specific client needs, including financial planning,
estate planning, real estate financing, and securities-based lending.
Our strategy builds on our strong Business Banking position to serve
entrepreneurs and their wealth needs. We continue to invest in digital
capabilities to enhance client engagement and provide actionable insights
through advanced analytics, while maintaining human expertise through
relationship managers supported by product specialists and portfolio
managers.
Our investments offering spans all Retail Banking countries, serving mass,
affluent, high-net-worth individuals and ultra-high-net worth individuals
through a differentiated approach. For Private Individual clients, we aim to
provide a fully digital experience with simple onboarding, intuitive tools,
and innovative features for first-time investors. For affluent clients, we
offer a hybrid model that combines digital convenience with personalised
support.
In line with our ambition to make investing personal and accessible
throughout Europe, total assets under management and e-brokerage
reached €278 billion in 2025, representing a 16 percent increase from
2024.
Wholesale Banking
Growing the difference for our customers means we strive to be the best –
and in this case, the best European wholesale bank. We define ‘best’ as
achieving a high net promoter score (NPS), ranking in the industry’s top
quartile, leading in sustainability, digital services and employer
attractiveness, while delivering sustainable returns. Our work starts with
providing corporate clients and financial institutions with the financial
solutions they need across their value chains.
In 2025, our Wholesale Banking team was recognised by Global Finance as
Best Bank for Payments in Western and Central & Eastern Europe, and the
Most Innovative Bank for Trade Finance globally. Treasury Management
International named ING as the 2025 Best Bank for Trade & Supply Chain
Finance in Europe, and Global Capital recognised ING as the 2025 Most
Impressive Investment Bank for Corporate ESG Capital Markets and Advice.
Global Reach
ING’s Wholesale Banking network serves clients around the world and
operates from 37 countries across three regions: EMEA, APAC and the
Americas.
Sector Expertise
Clients benefit from our sector knowledge of eight sectors and 29 sub-
sectors, including: commodities, food and agriculture; corporate sector
coverage; energy; financial institutions; infrastructure and real estate;
sustainable value chains; technology, media, telecom and healthcare; and
transport and logistics. By making use of our target sector research
capabilities and our client segmentation model, we aim to help clients
navigate the highs and lows of economic cycles. We provide them with
relevant advice, data-driven insights and customised, integrated solutions
that support their business ambitions.
How we aim to become the best European wholesale bank
We have identified several ‘must-win’ priorities for us to become the best
European wholesale bank and to drive impact for our clients. In
Transaction Services, we are expanding our product foundations to offer
more efficient cash management, trade finance, and payment solutions,
while diversifying our product mix to support clients’ global operations. In
Financial Markets, we are harmonising our product suite and increasing
access to green and conventional instruments, enabling clients to manage
risk and fund sustainable growth. And within Capital Markets & Advisory
(CMA), we are broadening our capabilities to deliver tailored financing and
advisory solutions, with more teams positioned close to clients for faster,
more relevant support.
In 2025 we took another step in strengthening our client offer with the
launch of a private markets unit. This will help clients access alternative
capital and diversify funding sources.
Alongside our focus on our three core differentiators, this year we also
worked towards achieving a fourth: digital. As such, we have advanced our
digitalisation efforts to enhance client experience. We expanded self-
service journeys on our InsideBusiness platform, streamlined processes,
and introduced new tools to make interactions simpler and faster. At the
same time, we equipped our front-office teams with integrated CRM and
GenAI capabilities, combining data, insights, and automation to deliver
proactive advice and deepen engagement.
We progressed our capital velocity strategy in 2025, and completed two
significant risk transfer (SRT) transactions, enabling us to deploy capital
more efficiently and expand our lending capacity. As a result, we are
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 32
better positioned to serve a wider range of clients and pursue new
business opportunities, while continuing to manage risks prudently.
Our NPS performance
One of the ways we measure our ability to deliver superior customer value
is through the net promoter score (NPS). The NPS indicates whether
customers would recommend ING to others. We compare our NPS to
selected peers in each market.
The net promoter score is a measure for customer satisfaction and loyalty.
The measure is derived from the survey question on the scale from 0 (not
at all) to 10 (extremely likely): 'How likely is it that you would recommend
a product or brand to a friend, family member or colleague?' (RB) and 'how
likely are you to recommend ING to a colleague or business partner?' (WB).
The score is calculated as the difference between the percentage of
promoters (who rate ING as 9 or 10), and detractors (rating ING with a
score of 6 or below).
Our ambition is to achieve a number one NPS ranking in all our Retail
markets. In 2025, ING ranked number one in 5 of our Retail markets:
Australia, Poland, Germany, Romania and Spain.
We ran an NPS programme in 32 Wholesale Banking (WB) markets
throughout 2025, to ensure a broad coverage of our client base, and
achieved a 69 percent response rate. ING’s WB NPS score rose to 77 (on a
scale of -100 to +100), compared to a score of 74 in 2024. The insights
from the survey showed how our sector expertise, global reach and local
experts are highly appreciated by clients and important reasons for why
they chose ING. We also asked clients how satisfied they were with our
product areas, people, processes and digital offering, with the highest
scores going to our product offering, relationship management and client
support. Off the back of these results, we will continue to prioritise building
strong relationships with excellent execution, simplifying and automating
our KYC processes and optimising our digital offering.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 33
How we are growing the difference
We focus and continue to work on our four key
enablers that will help us grow the difference:
providing seamless digital services, using scalable
technology and operations, staying safe and
secure, and unlocking our people’s full potential.
Providing seamless digital services
Through our ‘Growing the difference’ strategy, we continue to build on our
success of making banking easy. One of the ways we aim to do this is by
making banking as frictionless and relevant as possible. We can serve our
customers better through our ‘always-on’ channels, data-enabled
personalised experiences, and end-to-end digital processes, with human
intervention where needed or desired. For Private Individuals, our ING
Banking App enables customers to open accounts in minutes, manage
investments, and receive real-time spending insights. In Business Banking,
our Mijn ING Zakelijk platform helps SMEs manage payments and link
accounting packages seamlessly, while larger corporates benefit from the
InsideBusiness portal, providing self-service access to trade finance and
cash management globally. For Private Banking & Wealth Management,
clients enjoy secure digital portfolio management and personalised
advisory services through our app, which offers tailored dashboards and
seamless access to expert support.
We use data analytics and machine learning to personalise digital services,
delivering relevant, data-driven insights that help customers make
informed financial decisions. As data becomes increasingly central to
delivering personal and relevant services, privacy and data security are
more important than ever.
Scalable technology and operations
ING uses scalable technology and operations that enable us to reach the
market faster, achieve volume more quickly, maintain consistent and
higher quality, and enhance productivity. This also helps us attract and
retain talent by offering employees the opportunity to not only work with
technology but also collaborate across countries and make an impact
globally. Scalable technology enables ING to create specific, local
propositions that serve our customers, while leveraging ING’s scale in
engineering, security, and data expertise.
Scalable technology
ING's technology vision is anchored in the 'Scalable Tech Platform', a
unified, integrated foundation. The platform hosts the IT modular
components we (re)use across countries and business lines to build and
operate customer propositions. It allows ING countries and business lines
to introduce propositions quickly, easily, and safely.
To fully unlock the potential of this platform and advance our ambition of
'Banking with Impact', the ING Tech strategy sets out three goals under the
leadership of the chief technology officer: increase productivity, excel in
customer experience, and be a top employer for engineering talent.
In 2025, we translated these longer-term goals into clear priorities for the
years ahead:
§Operational excellence: Enhancing reliability, reinforcing cybersecurity,
and investing in our workforce to ensure resilient and secure
operations.
§Digital product governance: Advancing our digital product capabilities,
which contributes further to control, transparency, and strategic
alignment.
§Engineering: Driving an engineering way of working and innovation,
including AI-enabled coding.
§Transformation: Continuing the development and expansion of our
scalable technology platform.
§Data and AI development: Accelerating the responsible and effective
use of data and artificial intelligence to unlock new opportunities and
efficiencies.
Our scalable technology consists of three core components: ING’s private
cloud infrastructure (IPC), our engineering pipeline (OnePipeline), and our
banking technology platform.
IPC is where we store and manage applications and data such as channel
applications, core banking systems, and other banking applications. We
measure IPC adoption by the percentage of physical cores – also known as
processing cores or CPU cores – in IPC compared to the total number of
physical cores in ING data centres globally. By the end of 2025, 68 percent
(2024: 67 percent) of all physical cores in ING were on IPC. This is in line
with our objective to evolve towards a structural hybrid cloud set up, which
allows us to optimise our infrastructure landscape by using both private
and public cloud to run our applications.
OnePipeline, our continuous integration and delivery pipeline, provides
engineers with a consistent and secure global capability to develop, test,
and deploy software. At the end of 2025, 90 percent of applications were
onboarded to this pipeline (2024: 85 percent) out of the total number of
applications registered in our IT management platform across all ING
entities.
Touchpoint is part of our banking technology platform. It provides reusable
shared services that help engineers build products – like Instant Payments
and Open Banking – more quickly and easily. At the end of 2025,
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 34
approximately 81 percent of customer logins used Touchpoint (2024:
approximately 75 percent)
Digital access
In a digital society, customers expect to have round-the-clock access to
digital channels, including their banking services. To live up to their
expectations, we strive to provide uninterrupted access to our banking
services, while allowing for scheduled maintenance and downtime. For
2025, our Retail scope includes Belgium, Germany, and the Netherlands.
The combined digital channel availability for these three countries was
99.89 percent (2024: 99.86 percent).
For Wholesale Banking clients worldwide, the availability for our Inside
Business Payments channel was 99.97 percent (2024: 99.82 percent) and
for our Inside Business Connect channel (file transfer), 99.99 percent
(2024: 100 percent.
Scalable operations
Our scalable operations are driven by digitalisation and capability hubs,
focusing on becoming fully straight-through processing (STP), removing
friction towards a seamless experience for our customers in a safe and
secure way. In all we do, our customers are our point of departure. Our
processes, both digital and non-digital, are designed and executed to
embed excellent customer experience. We apply the same mindset to all
our employee journeys.
Digitalising key customer journeys allows us to enable superior customer
value at a reduced cost-to-serve, while measuring impact through NPS and
cost efficiency. In 2025, our digi index score was 81.8 percent (2024:78.1
percent). The digi index score reflects the average of STP rates of key
customer journeys that are handled without manual intervention.
Capability hubs provide shared services and solutions across ING
worldwide, leveraging expertise and using scale, and sharing productive,
quality services across the ING network. The hubs are located in the
Netherlands, Poland, Romania, Slovakia, the Philippines and Türkiye.
In November 2025, ING opened a new hub in Madrid, Spain.
Through expanded and improved digital services we have reduced friction
and increased self service options, including GenAI chatbots. In 2025, we
reduced inbound contacts to contact centres by 43 percent (2024: 26
percent).
Data analytics
In 2025, ING Analytics continued to drive our strategy forward by
embedding AI and GenAI into our products, process, and interaction in
Retail, Wholesale, and the associated operations. Building on the targeted
approach in five priority domains – contact centres, Know Your Customer
(KYC), hyper-personalisation, Wholesale Banking Lending, and software
engineering – we scaled solutions and explored new opportunities.
Key milestones include the first large language model (LLM) voicebot
experiment and the introduction of machine learning-based client due
diligence assessments in Retail Banking. In Wholesale Banking, we
prioritised front-office productivity by embedding AI tools, including
enhancing liquidity management through machine learning and providing
near real-time visibility into client data to support faster, more informed
decision‑making.
We continued to advance our platform capabilities in line with ING’s
broader transformation objectives. The introduction of a unified data,
analytics, AI and agentic environment marked an important milestone in
strengthening our data infrastructure. The platform delivers analytics
initiatives with greater consistency and efficiency, while simplifying risk
assessments and strengthening data governance.
As AI adoption accelerated across 2025, moving from pilots to day‑to‑day
use in areas such as analytics, software development and customer
service, we strengthened our governance to ensure we scale AI responsibly
by establishing a dedicated central AI Risk Committee to oversee emerging
risks in new domains such as voicebots and agentic AI capabilities.
We continue to empower our workforce by shifting from AI education to
hands-on enablement across three key groups: employees, specialists,
and leaders. This year’s data fluency training reached more than 8,700
individual participants across 18 functions in 14 countries. These initiatives
aim to ensure ING talent remains at the forefront of responsible and
innovative AI adoption.
In Retail Banking, we have introduced GenAI-powered campaigns to
improve customer engagement and support sales. These tools are
currently live in Belgium, Germany, Spain, Romania, and Poland. In Spain,
early results show positive campaign uplifts. We are also assessing the use
of GenAI for educational and awareness content, including illustrated
messaging.
In consumer lending, we use AI to assess applicants and process loan
applications automatically. We enhanced the mortgage credit decision
process in Australia by introducing machine learning-based scorecards.
This improvement enables a more digitised application experience and
ensures reliable assessments aligned with our risk appetite.
Our contact centres underwent a GenAI transformation, with chatbots
now live in seven countries (the Netherlands, Belgium, Germany, Spain,
Italy, Romania, and Australia).
We integrated analytics and AI into KYC processes across Retail and
Wholesale Banking. Our Secondary Analytics Transaction Monitoring
solution distinguishes between high- and low-risk activity, improving
investigations and supporting compliance. The model is live in Belgium,
the Netherlands, Romania, and Australia.
We introduced STP 2.0 and a new Risk Assessment Model for customer due
diligence, shifting from manual checks to AI-driven risk management.
These solutions are designed to streamline processes, support compliance,
and enable dynamic risk scoring and smarter decisions globally.
In engineering, we have implemented GenAI to accelerate software
development, improve code quality, and reduce communication overhead.
Staying safe and secure
At ING, trust is the foundation of everything we do. As a digital-first bank,
we are entrusted with our customers’ money and personal data.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 35
Safeguarding these assets is essential to maintaining the confidence of our
stakeholders.
We operate within a robust risk management framework designed to
identify, assess and manage material risks to our business. Our Risk
Appetite Framework (RAF) supports the execution of our ‘Growing the
difference’ strategy in a secure, compliant, and responsible manner,
ensuring we meet all regulatory obligations.
As we expand our customer base, we remain vigilant in protecting our
organisation, our clients and the broader financial system. Our anti-money
laundering (AML) activities include customer screening, due diligence and
transaction monitoring to detect and prevent suspicious activity. We also
continue to strengthen our fraud prevention capabilities, using innovative
technologies to reduce fraud-related harm to individuals and society.
Cybersecurity remains a top priority. We continuously monitor the threat
landscape and invest in capabilities across all cyber domains – prediction,
prevention, detection, response and recovery. In 2025, two Distributed
Denial of Service (DDoS) incidents were reported to the supervisors: one
impacted availability for individuals in Belgium, Italy, and the Netherlands,
and another caused temporary interruptions in third-party service
availability within the Polish mobile payment system. Our Chief
Information Security Office (CISO) organisation maintains 24/7 vigilance,
actively monitoring our environment, investigating emerging threats, and
taking timely action to protect our customers and essential services.
As a global financial institution, we process personal data from customers,
employees, suppliers, and partners. Protecting this data is critical. We
continuously evaluate our compliance with evolving data ethics standards
and regulatory requirements. We also foster a culture of integrity by
encouraging employees to report unethical or unlawful behaviour through
secure and anonymous channels.
For more information on ING’s policies and processes to stay safe and
secure, see.
Unlocking our people’s full potential
Unlocking our people’s full potential is a key enabler of our strategy as we
believe we have an abundance of talent and potential at ING. We attract,
develop, retain, and reward the right fit-for-future talents and skills. We
strive to deliver a superior employee experience to unlock our people’s
time and energy to grow the difference. We are dedicated to fostering a
safe and inclusive environment for our 60,000+ employees, as we aim to
create a friendly and collaborative workplace that mirrors the diverse
world we operate in. This is reinforced by our Orange Culture and Orange
Behaviours. We ask our people to act with honesty, prudence, and
responsibility, and that they strive to ‘take it on and make it happen’, ‘help
others be successful’, and are ‘always a step ahead’.
In 2025, we continued to focus on unlocking our people’s potential through
three strategic pillars: ‘talent & leadership’, ‘culture & organisation’ and
‘employee experience’.
Talent & leadership
To grow the difference and keep ING fit for the future, we need the right
people with the right skills and a readiness to learn and develop. In 2025,
we launched ING University, our new global learning platform. This brings
learning into one place for all ING employees worldwide, making
development more accessible, personal, and relevant – so everyone has
the skills to thrive today and tomorrow. Alongside this, we have continued
to empower employees to take ownership of their growth through tools
like the Individual Development Plan (IDP), available globally to help map
personal learning journeys. We also offer high-quality learning content
tailored to different roles and ambitions. Employee feedback on learning
content is positive, with colleagues actively exploring topics beyond
mandatory training – showing appetite for self-driven learning.
Our focused attention on training complements our efforts to build strong,
diverse talent pipelines. Through our annual strategic global talent reviews,
conducted for approximately 5,000 senior employees, each domain
evaluated their contributions to growing the difference and identified the
talent, leadership, and capability needs to advance our ING goals and help
future-proof our talent pipelines. In 2025, we enhanced this review cycle
by integrating near-term and forward-looking assessments of
organisational and people requirements, including future workforce needs,
skills, and capacity, as well as future leadership requirements.
One example of how we are building future-ready leaders is our Global
Leadership Accelerator, run in partnership with the IMD Business School,
where, following completion, participants are demonstrating increased
readiness for senior roles. As we strengthen the talent of today, we can
also look ahead with confidence: the International Talent Programme
continues to welcome new trainees to ING to develop their banking skills,
cultivate professional expertise and support their personal growth. This
rigorous, global two-year programme is just one of our investments in
strengthening our leadership pipeline.
Our commitment to a fair and transparent performance and rewards
process supports our talent and leadership goals. We retained the same
focus in 2025 of providing our employees with clarity and consistency.
ING follows a Pay for Performance approach, supported by a five-point
performance rating scale in our performance evaluation scheme,
introduced in 2024. Remuneration decisions are clearly linked to
performance outcomes.
ING began using a structured variable remuneration framework based on
our job architecture in 2025. This means all employees eligible for variable
remuneration have a variable remuneration target. This provides
managers with a decision framework for determining variable
remuneration rewards equitably, while having enough flexibility to
differentiate outcomes for individual performance. Employees see
increased transparency and can better understand how their personal
performance influences their variable remuneration.
Culture & organisation
At ING we aim to unlock our people's full potential through our inclusive
culture where everyone has the opportunity to develop and have impact
for our customers and society.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 36
Strong mental, social and physical wellbeing is essential for an inclusive
environment and a healthy, high-performing and engaged workforce.
We promote flexibility through hybrid working and have introduced
healthy 'Working Habits', for which we provide training and resources.
We have also included a Wellbeing Index in our Organisational Health
Index (OHI) survey to track how our people are doing, identify
improvement areas, and monitor the link between wellbeing and
performance. By prioritising wellbeing and leveraging these insights,
we aim to build a resilient workforce and drive a sustainable high-
performance culture.
Equally important is the role feedback plays in sustaining our Orange
Culture. We maintain a continuous listening framework, which gives our
people formal channels to provide feedback on our strategy, working
conditions, behaviours, and experiences. Our Organisational Health Index is
the most comprehensive of these listening tools. In 2025, we held two OHI
surveys and received feedback from 80 percent of our workforce. We saw
sustained strong organisational engagement among our employees
showing that it is desirable to continue with our Orange Culture. The
feedback showed that our people continue to value and appreciate their
colleagues, the ability to work hybrid, and the opportunities that support
their wellbeing.
Employee experience
Employee experience remains a top priority at ING. We believe that
delivering a great employee experience is essential to providing excellent
customer experience and to attract and retain talent. In 2025, ING
continued the collective efforts of the Employee Experience Design Board,
which brings together representatives from Human Resources, Facilities
Services, Operations, Information Technology, and Global Communications
to enhance the employee experience globally.
Throughout the year, this group focused on operational excellence and
service quality, enabling productivity from anywhere, and using data to
prioritise work that matters most. Initiatives included improving the office
environment, streamlining facility management ticketing, creating a
unified portal for employee support, and empowering employees to
be more self-sufficient by simplifying access to information. ING will
continue to focus on the moments that matter to deliver a superior
employee experience.
Competition
ING is a leading European universal bank with global activities. Our more
than 60,000 colleagues based in 40 countries serve nearly 41 million
individuals, corporates and financial institutions in 10 Retail Banking and
over 100 Wholesale Banking markets. ING’s purpose is to empower people
to stay a step ahead in life and in business.
Our Retail Banking business, which consists of Private Individuals, Business
Banking, and Private Banking & Wealth Management, offers individuals,
small to medium-sized businesses (SMEs) and mid-corporates a full range
of products and services covering payments, savings, insurance,
investments, mortgages, trade finance, structured finance and financial
markets solutions, among others. In Wholesale Banking we provide
corporate clients and financial institutions with specialised lending, tailored
corporate finance, debt & equity market solutions and sustainable finance
solutions. We also offer daily banking services such as payments & cash
management and trade & treasury services.
There is substantial competition in the countries in which we do business
for the types of Wholesale Banking, Retail Banking, Business Banking and
other products and services we provide. In recent years, competition has
further increased in both developed and emerging markets. Our largest
market is the Netherlands, where our main competitors are ABN AMRO
Bank and Rabobank.
Traditional banks are no longer the sole providers of financial services.
Digital innovation and AI-driven low-cost models are driving competition
from fintechs, non-bank lenders, and technology companies. Digital banks
are competing for retail customers with user-friendly platforms and low
fees, while private lenders – including big tech companies – are taking a
growing share of business lending. At the same time, innovations such as
digital tokens and stablecoins are reshaping payment systems, moving
them beyond traditional banking channels.
In this competitive landscape, where banking products and services have
mostly become commodified, the main differentiator is being able to
provide superior value for customers. For Retail Banking, delivering superior
customer value means making banking simple and expertise accessible,
offering the right products, at the right time, in the right way. Businesses
too want to benefit from gains in speed, transparency, security and
efficiency created by technologies such as blockchain and artificial
intelligence. Winners will be those with a strong trusted brand and a
superior digital experience, taking the effort out of managing finances and
offering personalised, real-time advice, products and services for all
financial needs.
Statements regarding ING’s competitive position reflect the assessment of
ING’s management about the general competitive landscape in which ING
operates.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 37
Sustainability
ING aims to leverage our role as a global bank to
support clients in addressing environmental
challenges, including climate-related and nature-
related risks, because it matters to our company,
our customers, society, and the environment.
For ING, ensuring the resilience and commercial success of our business
includes managing climate-related risks while also seizing the
opportunities that come with financing the transition.
Climate change mitigation
Climate change mitigation means reducing GHG emissions to limit global
warming to 1.5 °C above pre-industrial levels, in line with the Paris
Agreement. For ING, this involves managing the emissions linked to our
financing activities.
Climate change adaptation
Climate change adaptation refers to the process of adjusting to current
and anticipated climate change and its impacts. It is intrinsically linked to
physical risk, as it involves implementing strategies to manage and
mitigate the effects of climate-related physical events.
These physical risks can increase the likelihood of defaults and non-
performing loans, exposing ING to financial vulnerabilities through various
channels:
§Wholesale and Business Banking: Damage to infrastructure, operational
disruptions, rising costs, and reduced customer demand can lead to
lower borrower income and higher insurance premiums, increasing the
risk of default.
§Residential real estate: More frequent and severe climate events may
reduce property values, limit insurance availability in high-risk areas,
and impair borrowers’ ability to repay mortgages or access renovation
financing.
Policies, actions and performance
This section includes the relevant policies and guidelines to address the
material impacts, risks and opportunities and the related actions to
execute those policies and guidelines.
The Environmental, Social, and Governance (ESG) Risk Policy
The ESG Risk Framework, described in the 'ESG risk’ section, sets out ING’s
approach to managing ESG risks as drivers of existing risk types. It is
supported by the double materiality assessment (DMA) and the ESG Risk
Policy, which are designed to ensure the implementation of obligations,
processes, and control requirements from the framework.
The ESG Risk Policy explains how ING identifies, assesses, mitigates,
monitors, and reports ESG-related risks in line with our risk appetite, by
considering applicable and material risks and negative impacts across the
value chain. It applies to ING Groep N.V. and all majority-owned entities,
unless local laws require deviations. The policy considers relevant
legislation and guidance, including EBA guidelines on ESG risk
management, EBA ITS on Pillar 3 ESG disclosures, CSRD, EU Taxonomy, and
SFDR. It sets objectives, references applicable regulations, and outlines
high-level obligations and control objectives for managing ESG risks across
the value chain. The ESG Risk Department oversees implementation and
compliance.
ESG risks influence financial and non-financial risk types. Therefore, ESG
risk management is embedded in existing processes such as credit
granting, risk appetite steering, and credit risk management. Local entities
adapt global requirements to local regulations and practices, mainly
through lending criteria, loan-management systems, and sales
procedures.
Actions related to ESG Risk Policy
As part of our risk management cycle (see ‘ESG risk section’), ING
proactively mitigates identified risks and negative impacts within its risk
appetite. We apply strategies such as reducing, avoiding, accepting, or
transferring risk, embedding these measures into policy and procedure
updates across risk categories. It is ING’s policy to act in compliance with
applicable laws and regulations. The following paragraphs outline key
initiatives in business lines where climate change is a material risk.
Retail Banking: Residential mortgages
ING integrates transition and physical climate risks into its mortgage
portfolio strategy, risk appetite, lending criteria, and collateral valuation.
Local entities apply the ESG Risk Policy using global guidance, adapting to
local regulations and practices.
Key actions include:
§Customer engagement: Advisory services and duty-of-care procedures
promote interest in low-emission buildings.
§Data collection: ING implemented controls to ensure the mandatory
collection of EPC data for new loans and enhancement of existing
portfolios through proxy models.
§Risk appetite: Aligned with business strategy and metrics for managing
low-quality EPCs at origination are monitored under the Risk Appetite
Framework, with escalation to the ESG Risk Committee when needed.
Retail Banking: Business Banking lending
ING identifies sectors with higher climate-related risk exposure and
supports these through dedicated lending criteria, data controls (e.g., EPC
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 38
data for real estate), and regular monitoring. We engage with clients to
understand their business plans and transition-related risk considerations.
In line with our risk appetite, we accept certain transition risks but monitor
and manage them through client-specific assessments, exposure limits,
and key risk indicators (KRIs). Risks outside our appetite must be mitigated
or may not be accepted. Mitigation measures include insurance for
physical risks, covenants addressing risk mitigation measures, and
incorporating climate risks into collateral valuation. Sector-specific lending
policies and data collection enable accurate portfolio assessment and
active management.
Wholesale Banking lending
While climate transition-related risks may be more pronounced in certain
carbon-intensive sectors, we manage climate-related risks across the
entire Wholesale Banking portfolio through the ESG Risk Framework,
lending policies, and due-diligence processes. These efforts are supported
by quantification methodologies and advanced tools, ensuring that risks
are identified, assessed, and managed throughout the full origination-to-
monitoring cycle. Key actions include:
§Climate Risk Appetite: We assess transition risks at the client level,
considering emissions, financial capacity, and transition plans. High-risk
clients are managed through risk appetite limits and growth
constraints.
§Lending policies and steering: Sector lending policies reference the ESG
Risk Policy and apply its minimum requirements. They include ESG
factors and transmission channels relevant to each sector, detailing
acceptable mitigants to address potential financial risks from ESG
factors. Relevant sector considerations may inform lending decisions.
§ESG risk assessment tool: In 2025, we launched an enhanced ESG risk
assessment platform that integrates environmental, social, and
governance factors, replacing the previous ESR framework. The tool
improves efficiency and consistency in credit granting by enabling
users to input supplementary ESG data and automating integration
into the assessment process. Further automation and data
enhancements are planned for 2026. The assessment process includes:
–Materiality check: Determines if a client or transaction is likely to
have significant ESG impacts or dependencies based on sector data.
–Initial assessment: Evaluates ESG and reputational risks for material
factors.
–Qualitative review: Front office identifies mitigants and checks
compliance with sector standards and restricted activities.
–High-risk escalation: ESR desk performs due diligence and provides
binding advice, which may include additional conditions or a go/no-
go decision.
–Credit risk review: Experts validate ESG factor assessments and
mitigants relevant to credit risk.
§Client engagement and data infrastructure: We engage clients to
understand and manage climate-related risks and continuously
enhance ESG data infrastructure by integrating internal and external
sources. This provides granular insights for portfolio management and
supports data-driven solutions.
§Collateral valuation: Climate risks affecting property values are
embedded in valuation, monitoring, and revaluation processes for
commercial real estate.
Guidelines and actions addressing our opportunities
Our approach to sustainability-related opportunities is integrated into
ING’s business strategy. This strategic approach ensures that our actions
align with our long-term ambitions. Sustainable lending represents a key
opportunity for us to grow and differentiate in the market. It enables us to
increase sustainable volumes mobilised, expand our renewable energy
financing portfolio, and support clients in purchasing energy-efficient
homes. In addition, our green funding framework supports eligible
financing activities and funding diversification.
To help guide these opportunities and safeguard against greenwashing
risks, we have sustainable finance guidelines and implement mandatory
instructions that set clear criteria and provide practical guidance tailored
to each business line. These instructions ensure reliable and transparent
reporting. Where they are still being embedded, we apply additional
controls to maintain accuracy and prevent greenwashing.
Wholesale Banking
The Sustainable Finance Guidelines provide ING colleagues with a clear
framework for engaging with clients and offering sustainable finance
products and solutions. These guidelines are to be followed by all relevant
business units when advising clients and structuring products.
All products included in our Sustainable Finance Guidelines must comply
with the criteria set out in the mandatory instructions, which define the
conditions under which a product can be classified as sustainable. While
we are still in the process of fully embedding these instructions, the
guidelines are continuously being updated to reflect new product
developments and evolving regulatory requirements.
Wholesale Banking offers financing and advisory services tailored to client
needs in areas where sustainability-related risk considerations are
relevant.
In 2025 we recorded €166 billion of volumes mobilised (2024: €130 billion).
We also see opportunities in financing our clients meeting their energy
transition objectives, by financing renewable power generation. Volumes
mobilised refer to the total amount of financing, investment and related
financial activity that we enable for clients through our products and
services, where we plays a role in originating, structuring, coordinating or
participating in the transaction. Volumes are measured based on ING’s role
in each transaction, with full or pro‑rata recognition when acting as ESG
lead to reflect its contribution to mobilising sustainable finance, and
recognition of the bank’s own share when participating without a lead role.
Retail Banking
Retail Banking has significant opportunities related to green mortgages
and energy-efficient housing. For private individuals, by offering
preferential pricing and mortgage extensions or top-ups for properties with
better EPC ratings, we can attract customers seeking energy-efficient
homes and differentiate our offering in a growing market segment.
Moreover, we can create opportunities by financing renovations that
improve energy performance, such as insulation upgrades or installing
solar panels, enabling customers to enhance property value and reduce
emissions. This not only supports environmental goals but also
strengthens borrowers’ financial resilience, as energy-efficient homes
typically have lower energy bills contributing to a more robust credit
profile.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 39
Similarly, Business Banking lending presents financing products that may
support client investments in energy efficiency or renewable energy.
Treasury
Our Global Green Funding Framework promotes opportunities for ING, its
investors, and clients on both sides of the balance sheet. On the asset side,
we finance eligible green buildings and renewable energy portfolios. On
the liability side, we issue green bonds and other funding instruments to
diversify funding sources.
The framework aligns with the EU Taxonomy and includes a sustainable
asset classification system. As of 31 December 2025, ING Group has € 14.9
billion in green bonds outstanding (2024: € 15.3 billion).
1Own workforce refers to our employees and non-employees (contractors and individuals engaged via employment agencies), also referred to as our 'employees'.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 40
Own workforce
As an employer, we aim to provide a safe and
inclusive workplace. We believe financially healthy
people contribute to a healthy economy and drive
social progress, which is why we aim to support
customers in meeting their financial commitments
now, while building their financial security for
tomorrow. We believe every person deserves to be
treated with dignity and have their interests
considered equally, whether it concerns people in
our own workforce or our consumers and end-
users.
Our own workforce1 is our greatest asset. Unlocking our people’s full
potential is a key enabler of our ‘Growing the difference’ strategy as we
believe we have an abundance of talent and potential at ING. We succeed
when we equip our workforce with the skills and capabilities they need to
make significant contributions to the continued and sustainable growth of
our business. We seek to create a safe, non-discriminatory and inclusive
environment that reflects the world we operate in, and where our
employees feel they can belong and thrive.
Own workforce strategy – Unlocking our people’s full
potential
ING strives to provide a safe, non-discriminatory and inclusive workplace
where everyone has the potential to grow and develop. This is supported
by internal policies, controls and workforce processes, taking into account
applicable legal and regulatory frameworks in the jurisdictions in which we
operate. We consider both external and internal factors, such as
geopolitical forces, evolving technology, and changing employee
expectations, as these trends shape our business needs and,
consequently, our strategy. For more on ‘unlocking our people’s full
potential’, see our ‘How we are growing the difference'’ section.
The governance of our policies regarding harassment and violence, and of
our initiatives supporting wellbeing, employment, and the inclusion of
persons with disabilities, is structured in such a way that ING can address
its material risks and impacts in a timely and effective manner. These risks,
such as harassment and violence, can result in lower employee morale,
reduced productivity and harm to ING’s overall reputation and operational
instability, as well as potential legal claims with financial consequences. To
strengthen our adaptability and resilience, tools and the Organizational
Health Index provide valuable insights that guide the refinement of our
policies, inform strategic direction, and support the implementation of
regulatory changes. Through ongoing policy reviews, residual risk
assessments, and the alignment of processes with evolving regulations,
we continuously enhance our capacity to manage both current and
emerging risks effectively.
ING maintains policies and procedures intended to address accessibility
requirements where applicable.
Policies, actions and performance
As a globally operating bank, we are continuously navigating the
complexities of global and local regulations. In some instances, we set
general, globally applicable policies to help address the material risks and
material negative impacts our workforce may face, with consideration for
local laws and regulations which may necessitate tailored local policies to
ensure full compliance. ING maintains workforce-related policies designed
to mitigate discrimination, misconduct and other workforce-related risks. It
is ING’s policy to act in compliance with applicable laws and regulations.
At ING, we denounce all forms of discrimination. Any distinction, exclusion,
or preference not based on the inherent requirements of the job is deemed
as discrimination.
ING’s workforce policies are aligned with local labour laws and regulations
in all countries where we have operations. In countries where local
legislation goes further than the principles set out by the Universal
Declaration of Human Rights and ILO Core Conventions, we also apply
additional and stricter requirements. In addition, we seek alignment with
international standards on human rights (such as the UNGPs) through the
implementation of EU directives and the development of internal policies.
We take various actions to further understand the impacts coming from
outside ING, and we continuously inform our workforce and leaders on
best practices related to developments and learnings. This is exemplified in
our collaboration with external organisations to understand the impact of
global events, socio-economic movements, and changes in legislation.
Where appropriate, we participate in external assessments to understand
our maturity on specific areas and our need for focus and improvement in
others. In 2025, ING continued its ‘Advocate’ status in the annual
Workplace Pride global benchmark, the highest ranking possible for an
organisation.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 41
Actions on training and skill development
Through our engagement with our workforce, we understand that to drive
meaningful change, we must attract, develop, and retain fit-for-future
talents. That is why we offer both scalable and curated learning and
development opportunities tailored to our employees’ roles and growth,
helping us meet our current and future skills and capability needs. In 2025,
we launched our internal ING University - a global learning platform
powered by a newly introduced learning technology. It brings learning into
one place for all employees, including domain-level academies,
mandatory and non-mandatory learnings (online and in-person) and both
formal and informal development opportunities. In 2025, we continued our
focus on talent development. This year, we performed strategic talent
reviews across the bank for more than 5,000 senior roles in order to better
identify and understand the leadership, skill, and capability needs of our
domains to grow the difference.
Workforce characteristics
ING has no employees with non-guaranteed working hours, as employees
with on-call agreements have agreed fixed hours and are treated as full-
time or part-time employees. We also examine other contextual
information and methodologies for data compilation to aid in
understanding our workforce characteristics. For example, we measure
turnover on a monthly basis as it has the potential to impact operational
effectiveness. In 2025 total turnover was 9 percent, no change compared
to 2024. Additional disclosures include breakdowns by region for full-time
and part-time employees, in order to obtain a comprehensive insight into
our employment practices and impacts. The related staff expenses and
the number of own employees are disclosed in note Note 25 'Staff
expenses' to the consolidated statement of profit or loss.
Actions on privacy
With regard to safeguarding our employees' wellbeing against the risk of
unauthorised access, misuse, or exposure of personal data like address,
remuneration, review assessment scores, outside interests or concerns
raised, we have a Global Personal Data Protection Internal Policy in place.
See the 'Consumers and End Users' section for more details on our policy
and actions regarding privacy.
Whistleblower Policy
Regarding the risks and negative impacts related to ‘measures against
violence and harassment’, our Whistleblower Policy provides instructions
on treating concerns in a careful and proportionate manner, aimed at
ensuring that ING takes appropriate, lawful, and timely action in case of
concerns related to human rights by or within ING. Read more about our
Whistleblower Policy in the ‘Business conduct’ section.
Our actions against violence and harassment in the workplace
We are committed to upholding both the requirements set by human
rights, laws, and regulations, as well as the exacting standards of our
Orange Code and Global Code of Conduct, through which we can fulfil our
purpose of empowering people while countering potential negative
impacts and risks related to, for example, violence and harassment. Read
more about our Global Code of Conduct in the 'Business conduct' section.
In line with our Whistleblower Policy and related control standards, we
categorise and monitor all reported concerns. This overview reflects issues
raised through our dedicated whistleblower channel concerning our own
workforce. All whistleblower reports received and addressed are reported
quarterly by the ING Group Chief Compliance Officer to the Supervisory
Board Risk Committee.
Whistleblower concerns are grouped into categories that link to
internationally recognised human rights:
§Discrimination;
§Aggression, violence, and bullying;
§Breach of confidentiality and data privacy related to an employee;
§(Sexual) Harassment;
§Work-pressure/unrealistic targets; and
§Retaliation
To understand if any of the whistleblower cases concern a severe human
rights incident, we apply three elements of severity: scale, scope, and the
remediability of the impact to the whistleblower categories mentioned
above. Based on our assessment, no severe human rights incidents
connected to our own workforce were identified in the reporting period
(2024: nil).
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 42
Consumers and end-users
Consumers and end-users of ING’s services include companies and private
individuals who we provide our services to. We focus in this section on
private individual customers within our Retail Banking domain, also
referred to as our ‘customers’. At ING, we strive to make access to our
products fair and our communication transparent, and to respect the
rights of our customers when providing our services. This includes
mitigating impacts and risks related to access to quality information, social
inclusion, and privacy.
We are committed to ensure fair access, transparent communication, and
respect for customer rights, while mitigating risks related to information
access, social inclusion, and privacy. These topics are especially relevant
for customers in vulnerable positions, such as elderly individuals or those
with temporary or permanent disabilities, chronic illness, or reading
difficulties, who may be more susceptible to harm or exclusion without
appropriate care.
Customer strategy: Superior customer value
We strive to make banking easy, instant, personal, and relevant so
customers can stay up to date with all that ING offers. We aim to clearly
price products and services, avoid complicated jargon, and always be
accessible. And as part of our accessibility strategy of ‘Leave no one behind’,
we strive for the inclusion of all our customers, with and without disabilities.
Access to quality information and social inclusion is important in
promoting financial health and accessibility. Enhancing financial literacy is
also essential to empower customers to make informed decisions. These
topics, along with related issues such as non-discrimination, access to
products and services, and responsible marketing, are validated through
our customer-centric compliance risk assessment.
Additionally, safeguarding customer privacy and data security is a key
compliance and reputational priority, reflecting our responsibility to
protect personal information. We manage related risks by continuously
assessing the regulatory environment for updates and implementing
these in line with our governance measures. This ensures we remain
compliant while safeguarding our strategy to provide superior customer
value. The processes for managing our risks and impacts, as laid out in this
section, are integrated into existing risk management and compliance
processes.
Policies, actions and performance
Customer Centricity Policy
ING offers customers a large variety of financial products and services, so
we face different risks and are subject to a multitude of regulations. Our
Customer Centricity Policy (CCP) helps in preventing and mitigating
impacts and risks regarding the topics of social inclusion and access to
quality information, including mis-selling and unfair customer treatment.
For instance, we want all our customers to have equitable access to our
products and services, including persons with disabilities, which is why we
strive to comply with the procedures of our policies and apply controls.
After rolling out the first version of the CCP in 2024, we updated the policy
this year to bring elements such as discrimination and access to banking
into the Compliance Risk Framework. In practice, this means we apply
global minimum standards for these issues, which aim to support us in
identifying severe human-rights incidents in the future. Our governance
framework, supported by continuous policy reviews, risk assessments, and
regulatory change implementation, enables us to address material risks
related to discrimination, inclusivity, and access to information in a timely
and effective manner.
The CCP defines high-level obligations to ensure ING handles risks
appropriately and in line with regulations. We want to offer products and
services suitable for our customers throughout the whole relationship
lifecycle at a fair price, considering the market, costs, and risks. We
monitor internal controls and processes, such as our Product Review and
Approval Process (PARP), in which relevant elements of customer centricity
are considered and challenged. The CCP requires us to communicate
information on products and services in a clear and non-misleading
manner, and provide services and trusted advice through professionals
with the necessary knowledge and expertise. In doing so, we also consider
the ESG risks and impact of our products and services on customers.
Having a global CCP enables us to align and assess whether customer
centricity is applied to all products and customers across ING. Norms we
formalised into minimum standards include the need to only create and
sell products that are in the interests of customers and society, an aligned
standard on complaints processes, the provision of clear and accessible
information that is at all times fair and not misleading, and the
assessment of the needs of individual customers – both when we sell a
product and when the customer uses a product. With these, we aim to
mitigate potential and actual financial distress for individual customers,
resulting from not having access to products, services and/or quality
information.
Complaints and remediation process
In addition to our general engagement activities, we use our complaints
channels to gain a clearer picture of the impacts we have on our
customers. The insights we gain from complaints help us implement
structural improvements in our products and processes. The CCP sets out
the minimum requirements for complaints procedures across all ING
entities, including the need for transparency about the process and
keeping customers informed of the progress in handling their complaint.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 43
All complaints must be assessed regularly, and root cause analyses must
be carried out to mitigate the risks of customer harm. The CCP also aims
to ensure that customers can raise complaints about ING’s financial
products through third parties, including distributors, brokers, and
manufacturers. There are several ways our customers can file a
complaint. Within nearly all our Retail markets there is at least one
assisted channel available (e.g. call centre, branch, human chat, social
media), and at least one self-service channel (e.g. mail, e-mail, online
channels app and web) where customers can file a complaint, which will
then be handled by a human agent.
Customers are made aware of these channels via publicly available
information e.g. ING websites (FAQs and search engine) and via the Terms
& Conditions provided to customers during onboarding. Furthermore, a call
centre, branch and/or a chat agent can provide further information
regarding the complaints processes when a customer contacts ING. We
value our customers and take their concerns seriously. While this is not
embedded in our customer-focused policies, we do not tolerate retaliation
by any employee. For our anti-retaliation measures included in our
Whistleblower Policy, see the ‘Business conduct’ section.
We manage complaints primarily through contact centres and when
possible complaints are solved on initial contact. If unresolved, they
escalate to specialised teams. We evaluate the complaints handling
process, for instance, through an assessment of the time it takes to resolve
complaints and how frequently we do so. A change in products, financial
compensation, and/or apologies can help to address any negative impacts
on customers. We analyse complaints to implement structural changes in
products, processes, policies, procedures, and communication, and involve
relevant risk parties and internal stakeholders as needed. We have
established channels and procedures to ensure that customers are aware
of and have confidence in our complaints procedures. However, we do not
assess this confidence separately. Instead, if concerns about our
complaints procedures are raised, we consider these within our broader
evaluation of customer concerns.
Over the course of 2025, ING implemented a minimum set of
standardised labels on human rights (like discrimination, accessibility,
privacy), customer centricity and ESG. These labels are applied to
complaints, further enabling us to perform root-cause analyses and to
rectify service breakdowns, improve the customer journey, address
potential human rights issues and provide appropriate remedy, help
senior management better understand customer protection and further
strengthen customer trust.
An assessment for severe incidents was conducted using our internal issue
management system. Through this process no severe human rights
incidents were identified in 2025.
Actions on access to quality information and social inclusion
ING has implemented the requirements of the European Accessibility Act
and remains committed to further optimising and improving accessibility
across all customer‑facing services in our EU Retail Banking countries. This
implementation is supported by a dedicated accessibility team, whose
main objectives are to safeguard accessibility within ING, raise awareness
of this topic, and provide advice and coordination across countries.
We strive to make ING more accessible and inclusive for our customers. For
example, we have introduced voice-activated ATMs in certain countries to
help people with visual impairments to withdraw money. We also issue
bank cards with a physical notch that allows customers with visual
impairments to quickly identify the correct card by touch. In certain
countries, customers with visual impairments can also use screen readers
– software applications that read aloud on-screen information.
To further mitigate potential material negative impacts and risks related to
social inclusion, we are collaborating with the United Nations Environment
Programme Finance Initiative (UNEP FI) under the Principles for Responsible
Banking to contribute to setting a measurement standard for financial
health impact for our industry. As a founding signatory of the
Commitment to Financial Health and Inclusion, we aim to reduce
financially vulnerable or unhealthy households. We use technology to
create innovative digital tools that encourage customers to build savings
and manage their expenses, which have been implemented in multiple
European locations. For more information on financial health, see ing.com.
Compliance policies, such as the CCP, are implemented in the locations we
operate in. Outcomes of our monitoring, complaints analyses, event
analysis or regulatory interactions, are recorded as an issue in our global
database. We monitor and address issues on a local and global level. In
addition, CCP standards and compliance risks are subject to continuous
monitoring and, in line with our risk-based approach, undergo periodic
assessment and measurement. In relation to products and services, we
perform periodic reviews in the context of the Product Approval and
Review Process, which may lead to the remediation of a product if, for
example, it is considered unfit for our customers.
Global Personal Data Protection Policy
Just as we strive to enable customers to engage with ING without issue or
interruption, we aim to protect the personal data they provide to us
throughout their ING journey. In line with the EU's General Data Protection
Regulation (GDPR) and other applicable data protection requirements, ING
aims to only process personal data for a specific business purpose in a fair
and lawful manner, observing the rights and liberties of data subjects in
scope of our activities. To fulfil this ambition, ING has implemented a
Global Personal Data Protection Policy (GPDP), which reflects the
requirements based on laws and regulations, industry standards, and ING’s
internal risk appetite. This GPDP contains specific requirements and
controls, which ensure the necessity and accuracy of the personal data
ING is processing. The GPDP helps in preventing and mitigating impacts
and risks regarding the topic of (data) privacy.
It is our policy to have operational flows in place regarding data subject
rights (such as the right to access personal data, right to erase personal
data that no longer needs to be retained, right to object to data processing
etc.), and to ensure that these rights are adequately provided to all
individuals whose personal data is subject to processing. This means ING
has implemented operational flows to handle requests – such as access to
personal data, amendments/corrections, or objections to data processing –
promptly and in line with regulatory requirements.
In accordance with our policies, we strive to be transparent about what we
do with the personal data of customers, employees, suppliers and business
partners, as well as who we share personal data with and why. We want
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 44
our business entities, support functions, and the third parties we engage
with, to grant a level of protection to the data subject equivalent to that
guaranteed by the GDPR, especially if personal data is transferred outside
of the European Economic Area. Part of the data protection scope is that
personal data is managed in a safe and secure manner, in line with current
information security standards. For more information, see the Privacy
Statement on ing.com.
Actions regarding Privacy
ING manages personal data protection and retention risks and impacts via
the Global Data Protection and Global Record Retention and Deletion
frameworks and control standards. Potential material impacts are
identified and addressed by relevant data protection risk assessments
such as:
§The Data Protection Impact Assessment – performed at processing
activity level and allows for an in-depth scrutiny of personal data
processing activities in line with applicable regulations and data
protection principles;
§The Legitimate Interest Assessment – performed to assess whether ING
can rely on legitimate interest as a lawful basis in case of certain
personal data processing activities. In the case of this assessment the
legitimate interests of ING are considered and balanced against the
interests and rights of individuals in scope of the processing; and
§The Transfer Impact Assessment – performed in case personal data is
transferred to a non-EEA country. In this case the soundness of
contractual and technical protective measures and controls is
assessed.
All assessments mentioned lead to concrete risk identification and impact
mitigation measures, which are implemented on a granular level (business
process- or IT asset-level). This enables ING to continuously identify,
manage and limit relevant data protection risks, as data protection risk
assessments represent an integral part of defining new business processes
or introducing changes to existing ones.
Equally, personal data protection considerations are assessed and
documented at product level, within the PARP process. The data protection
framework includes policies and control standards that are continuously
monitored and, in line with our risk-based approach, periodically assessed
and measured.
In the case of security incidents impacting personal data (e.g. data
breaches) it is our policy to take the necessary containment and
mitigation measures as soon as possible after identifying such an
occurrence. As part of this policy we assess related data protection risks
and impacts, and determine whether external reporting to supervisors is
required, ensuring compliance with regulatory requirements. Based on the
incident’s impact and risk, we conduct ‘lessons learned’ sessions to
improve workflows and prevent similar future occurrences, strengthening
the protection of customer personal data. These lessons learned take into
account, first and foremost, the potential or actual impact of a data
breach occurrence on affected customers.
The effectiveness of our data protection and retention controls is
monitored and tested periodically as part of the ING Key Control Testing
framework. Data protection and retention controls are managed in line
with implemented data protection governance. Dedicated first- and
second-line teams, along with the Data Protection Executive Office and
Data Protection Compliance, support relevant business process, asset and
contract owners in identifying and managing data protection and
retention risks, including implementing appropriate mitigation measures.
For 2025, we delivered relevant improvements of the personal data
protection framework, focusing on implementing controls for data
retention and deletion, and enhancing the Data Protection Policy. We
continuously optimise data protection processes to ensure data protection
requirements are embedded in relevant business processes in full
compliance.
Metrics and targets
We aim to limit the number of complaints and/or breaches related to
access to quality information, social inclusion, data privacy, and associated
reputational risks. If these occur, we take actions to remediate risks and
impacts, as described in the previous paragraph. For our reputational risks,
we have a Compliance Risk Framework, which contains risk appetite
indicators used for internal monitoring.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 45
Business conduct
Our culture drives the way we do business and
impacts all our stakeholders. We are guided by
ING’s Orange Code, which sets our values and
behaviours and ensures we work with integrity,
transparency, and high standards of business
ethics. Our employees are encouraged to speak up
and report concerns, and have a zero-tolerance
approach to any form of bribery and corruption.
Business conduct refers to the way we do business. Our Global Code of
Conduct reflects the standards we must adhere to, and includes our
values, principles, and ethical standards. Business conduct includes
matters such as business ethics and corporate culture, including anti-
corruption and anti-bribery, and the protection of whistleblowers – and
these are the specific sustainability matters we have identified.
Policies, actions and performance
Corporate culture – integrity above all
Our operations touch many lives: customers, employees, shareholders,
and society at large. Everyone within these groups has a reasonable
expectation that we act with integrity. At ING, we all have a duty to put
integrity above all we do and to live up to the values we hold. We will not
ignore, tolerate or excuse behaviour that breaches our values. To do so
would break the trust of society and the thousands of great colleagues
who do the right thing to take this company forward every day.
Our corporate culture starts with the Orange Code – it is a declaration of
who we are, with the overarching principle of ‘integrity above all’. While
the Orange Code sets out general values and behaviours, the ING policies
and guidelines are much more specific and state the rules in more detail.
The ING Global Code of Conduct is the link between the Orange Code and
the main ING policies and guidelines.
Our values and behaviours Main ING policies and procedures
Business Conduct Framework
The Orange Code is a manifesto that describes our way of working. It comprises our values and behaviours Orange Code ING Global Code of Conduct Whistleblower Policy
Global Investigations Charter
Zero tolerance on corruption and bribery Anti-bribery and Corruption Policy ABC High-Risk Roles Guidance Global Event Management Procedure
The table above outlines the main policies and procedures within ING's
Business Conduct Framework, with key policies highlighted in bold. All
policies are subject to Internal Control Binding Principles (ICBP), which set
the standard for the entire lifecycle of the policy and apply to all ING
Business Units (i.e. all branches and majority-owned subsidiaries of ING
Groep N.V.). In accordance with ICBP, policies are reviewed in full at a
minimum every three years (unless otherwise approved), and checked, at
least annually, for alignment with relevant laws and regulations and
current practice. Policies, procedures and guidelines are available and
easily accessible for all staff on the ING intranet. The Orange Code and
Global Code of Conduct are available for external stakeholders on ing.com.
In addition to the abovementioned policies, ING has several internal
processes and guidelines in place to provide guidance towards the actions
and monitoring of the risks and policies.
The following processes and guidelines are linked to the global policies:
§The Global Investigations Charter specifies which incidents are to be
investigated under the local or global responsibility of Corporate Special
Investigations (CSI), and how the investigation is to be initiated,
conducted, and resolved. It defines the governing principles for
organising, managing, and conducting the investigations function
within ING.
§The Global Event Management Procedure outlines the processes for the
management of operational risk events, as well as the roles and
responsibilities for mitigating the impact of such identified events and
their related reporting.
§The AB&C High-Risk Role Guidance defines job activities considered to
be at risk or vulnerable from the bribery and corruption risk perspective,
and provides the basis for enrolment to the AB&C HRR training.
Training and awareness are of great importance for policies to be effective.
To this end, we have developed global mandatory training for business
conduct-related policies.
The Orange Code
The Orange Code describes what we can expect from each other when we
turn up to work each day. It is a set of standards that we collectively value,
strive to live up to, and invite others to measure us by. The Orange Code
comprises the ING values and the ING behaviours:
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 46
Values Behaviours
We are honest You take it on and make it happen.
We are prudent You help others to be successful.
We are responsible You are always a step ahead.
The Orange Behaviours are embedded in commitments we make to each
other and the standards by which we measure each other’s performance.
ING’s Global Code of Conduct
Building on the values and behaviours of our Orange Code, the ING Global
Code of Conduct outlines the 10 conduct principles expected from
employees. The Global Code of Conduct aims to prevent and protect our
employees from making unethical and/or illegal decisions within ING’s
day-to-day business. Prevention of bribery & corruption (AB&C), and
whistleblowing (speaking up), are among those 10 core principles. Conduct
principles are further governed via their respective policy frameworks.
ING launched a new global mandatory training on the Global Code of
Conduct in 2025, and new joiners are expected to undertake the training
upon joining ING. At the conclusion of the e‑learning module, employees
are required to acknowledge their understanding of and commitment to
complying with the Global Code of Conduct, which is actively monitored.
Risk culture
At ING, we attach great importance to a sound risk culture, which is
essential for performing our role in society responsibly and for keeping the
bank safe and secure. We determine our risk culture as: the way in which
employees identify, understand, discuss, and act on many financial and
non-financial risks we are confronted with every day. On an annual basis,
we monitor the progress of our risk culture maturity and furthermore, risk
culture is actively discussed by the Management Board Banking and the
Supervisory Board on a bi-annual basis. In 2025, ING further strengthened
its risk culture by promoting organisational learning as a bank-wide
priority with a key focus on enhancing lessons learned practices.
Behavioural risk
Behavioural risk is an increasingly important area for ING and across the
financial industry. It arises when behavioural patterns are at the root of
financial and non-financial risks in the organisation. The complexity of this
type of risk is that it is less tangible compared to other risk areas because it
focuses on behavioural patterns and their drivers. There are patterns in how
decisions are made, how people communicate, and whether they can and
are willing to take ownership. Behaviour is driven by formal and informal
mechanisms. Examples of formal drivers are the processes ING applies and
how its governance is structured. Informal drivers are less tangible, such as
group dynamics or underlying beliefs that influence behaviour.
Behavioural risk assessments
Behavioural risk assessments identify and analyse undesired behaviours
within ING and provide management with specific direction on how to
change these behaviours. They focus on the effectiveness of groups rather
than individuals, the role of leadership, and on less visible aspects such as
team dynamics and unwritten social norms. The goal is to understand and
systematically assess what drives undesired habits at ING. The behavioural
risk management framework is used as a guide across ING to identify
behavioural risks in the organisation that require deeper investigation.
Behavioural risk interventions
Based on the results of the executed behavioural risk assessments,
interventions are taken to mitigate the behavioural risks in a focused
manner. Effective mitigation requires a deep understanding of what drives
undesirable behaviours. Behavioural and organisational science theories
and evidence-based techniques and tools play an important role in
designing and facilitating interventions.
Whistleblower Policy
At ING we systematically look for ways to enhance and harmonise our
‘speak up’ channels. Speak-up concerns can be reported via a variety of
channels, in particular to managers, HR, confidential advisers,
Whistleblower Reporting Officers or via our (anonymous) whistleblower
reporting platform. We want our employees to feel safe to raise concerns
and to be confident that we will adequately address reported concerns.
We encourage and support employees in raising whistleblower concerns
through any reporting channel. All reports are handled with the highest
level of confidentiality, and we clearly communicate reporters’ rights and
responsibilities. Concerns reported via a whistleblowing channel are, when
in scope of the Whistleblower policy, reviewed by an ING Whistleblower
Reporting Officer to assess if there is sufficient ground for an investigation.
The global Whistleblower Policy and procedure, together with the Global
Investigations Charter, set out the minimum requirements to ensure
concerns are handled fairly, timely, proportionately, and with care.
Robust anti-retaliation measures are in place to protect whistleblowers.
ING does not tolerate any form of retaliation by any employee, including
(senior) management. It is strictly prohibited to retaliate against a reporter
or anyone providing information or assisting in an investigation.
External parties can report suspicions and complaints on misconduct or
behaviour via the pages ‘Whistleblower policy’ (shareholders and suppliers)
and 'Complaints about our conduct' (customers and other stakeholders)
on ing.com.
There is a global mandatory training for employees to educate them on
the whistleblower channel, anonymity and confidentiality, their rights and
responsibilities as reporters, the importance of awareness on retaliation,
and how the follow-up on concerns is handled. We actively monitor the
timely completion of the e-learning. Alongside the global support
community, a specialist learning journey provides Whistleblower Reporting
Officers with a one‑stop resource for mandatory obligations, investigative
interviewing, guidance, and templates.
ING entities have created local policy annexes where necessary in case of
specific local legal requirements based on the transposition of the EU
Directive 2019/1937 on the protection of persons who report breaches of
Union law/Whistleblowing into national law.
Anti-bribery and Corruption Policy
We are committed to doing business in an honest, prudent and
responsible manner and aim to ensure compliance with applicable AB&C
laws and regulations. ING’s AB&C Policy outlines the obligations, key risks,
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 47
and control objectives that are necessary to ensure that bribery and
corruption risks are identified, assessed, managed, and monitored
accordingly.
ING has a zero-tolerance approach to bribery and corruption in all its
relationships and business dealings. ING does not permit accepting or
paying bribes or offering improper inducements or anything that could be
perceived as such. ING expects the same from its business partners and
third parties that perform services or deliver business on its behalf.
Investigations into possible breaches of anti-bribery regulations are the
responsibility of CSI, as we want to ensure independence, objectivity,
impartiality, and confidentiality. ING entities are required to report
instances of bribery and/or corruption, in accordance with the Global Event
Management Procedure. This includes reporting to the Management Board
Banking and chairperson of the Supervisory Board.
ING has a key risk indicator in place to monitor its zero-tolerance policy on
bribery and corruption by ING employees or third parties on a monthly
basis. Reporting is based on event data from ING’s Non-Financial Risk (NFR)
Management tool, iRisk, which captures NFR-related events and provides
standard reports for risk monitoring.
During 2025, there were no instances of convictions and fines related to
violations of AB&C laws (2024: nil).
ING published an updated AB&C Policy, effective 1 July 2025, on our
intranet and on ing.com. The policy is aligned with relevant local and
international laws, including the US Foreign Corrupt Practices Act and the
UK Bribery Act.
Global mandatory training on AB&C has been designed to provide all
employees, including contingent workers, with an understanding of the
bribery and corruption risks faced by ING, the risks they may be exposed
to, and how ING manages these risks. New joiners are expected to
undertake the training on joining ING. The goal of the training is to enable
the learners to:
§recognise the importance of our role in fighting bribery and corruption;
§understand the consequences of bribery and corruption on society and
the organisation;
§recognise how we identify, manage, and mitigate potential bribery and
corruption risks; and
§escalate any suspicious behaviour or suspicions of potential bribery or
corruption risks through appropriate channels.
ING has an approach to identify the roles with an increased exposure to
bribery and corruption risks, known as High-Risk Roles (HRR's). The HRR
Guidance defines, in detail, the job activities considered to be at risk or
vulnerable from a bribery and corruption risk perspective. For more
information on the criteria, see ‘Definitions of our environment, social and
governance metrics’ in the Appendix to the Executive Board report.
Employees in a High Risk Role (HRR) are enrolled in a targeted e-learning
(updated November 2025). It covers the following key areas of activity:
§AB&C regulatory requirements relating to anti-bribery and corruption,
the risks for the financial industry, and the impact of a regulatory
breach;
§ING gifts & entertainment rules;
§enhanced risks associated with public officials; and
§bribery and corruption risks in the hiring process; and when engaging
with third parties.
Both the global mandatory and HRR training completion by employees is
monitored. In 2025 97 percentof employees completed the global
mandatory training on AB&C (2024: 98 percent and 89 percentof eligible
employees completed the HRR training (2024: 89 percent).
In 2025 the management boards and Supervisory B were offered a training
session that:
§provided an overview of global AB&C laws along with business activities
vulnerable to bribery and corruption risks;
§reinforced the critical role of leadership in upholding ING’s zero-
tolerance stance on bribery and corruption; and
§fostered interactive group discussions that highlighted bribery and
corruption risks.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 48
Regulation and Supervision
The banking and broker-dealer businesses of ING are subject to detailed
and comprehensive supervision in all of the jurisdictions in which ING
conducts business.
Regulatory agencies and supervisors have broad administrative power and
enforcement capabilities over many aspects of our business, which may
include liquidity, capital adequacy, permitted investments, ethical issues,
money laundering, anti-terrorism measures, privacy, recordkeeping,
product and sale suitability, marketing and sales practices, ESG,
remuneration policies, personal conduct and our own internal governance
practices. Also, regulators and other supervisory authorities in the EU, the
US and elsewhere continue to scrutinise payment processing and other
transactions and activities of the financial services industry through laws
and regulations governing such matters as money laundering, anti-
terrorism financing, tax evasion, prohibited transactions with countries or
persons subject to sanctions, and bribery or other anti-corruption
measures.
As discussed under “Item 3. Key Information - Risk Factors”, as a large
multinational financial institution we are subject to reputational and other
risks in connection with regulatory and compliance matters involving these
countries.
European Regulatory framework
The Single Supervisory Mechanism (“SSM”) is the first pillar of the Banking
Union and has been operational since 4 November 2014. The SSM consists
of the European Central Bank (“ECB”) and the national competent
authorities of the participating EU member states. The main objective of
European banking supervision is to ensure the safety and soundness of the
European banking system, enhance financial integration and stability and
ensure consistent supervision. Under the SSM, the ECB is the main
prudential supervisor of ING Group and ING Bank. The ECB's responsibilities
include tasks such as market access, compliance with capital and liquidity
requirements and governance arrangements. National competent
authorities, including the Dutch Central Bank (De Nederlandsche Bank or
“DNB”) for ING Group and ING Bank, remain responsible for supervising
tasks not transferred to the ECB such as financial crime and payment
supervision.
The SSM is complemented by the second pillar of the Banking Union, the
Single Resolution Mechanism (“SRM”), which consists of the Single
Resolution Board (“SRB”) and the national resolution authorities. The SRM
has been fully responsible for the resolution of banks within the Eurozone
since 1 January 2016.
As the third pillar of the Banking Union, the EU wants to further harmonise
the regulation for Deposit Guarantee Schemes (DGS). One of the key
elements is the creation of ex-ante funded DGS funds, financed by risk-
weighted contributions from banks. Since 2015, the EU has been
discussing a pan-European (or pan-banking union) DGS (the European
Deposit Insurance Scheme (EDIS)), which would (partly) replace or
complement national compensation schemes, but there is no EDIS yet as
political negotiations have stalled. On 18 April 2023, the European
Commission published the proposals for the revision of the common
framework for bank crisis management and deposit insurance (CMDI) that
focuses on small and medium-sized banks, but will affect all banks in the
EU. The CMDI framework consists of the Bank Recovery and Resolution
Directive (BRRD), the Single Resolution Mechanism Regulation (SRMR) and
the Deposit Guarantee Schemes Directive (DGSD). On 25 June 2025, the
Council and the European Parliament reached political agreement on the
reformed CMDI framework. The co-legislators are now expected to finalise
the legal text, after which the revised framework will be formally adopted
and enter into force.
Dutch Regulatory Framework
The Dutch regulatory system for financial supervision consists of
prudential supervision – monitoring the soundness of financial institutions
and the financial sector, and conduct-of-business supervision – regulating
institutions’ conduct in the financial markets. To the extent that prudential
supervision is not transferred to the ECB, it is carried out by the Dutch
Central Bank (De Nederlandsche Bank or “DNB”), while conduct-of-business
supervision is carried out by the Dutch Authority for the Financial Markets
(Autoriteit Financiële Markten or “AFM”).
Global Regulatory Environment
There are several legislative and regulatory proposals that could impact
ING globally, in particular the proposals of the Financial Stability Board and
the Basel Committee on Banking Supervision at the transnational level and
a growing set of supranational directives and national legislation in the
European Union (see “Item 3. Key Information - Risk Factors - We operate
in highly regulated industries. Changes in laws and/or regulations
governing financial services or financial institutions or the application of
such laws and/or regulations governing our business may reduce our
profitability"). The aggregated impact and possible interaction of all these
proposals is difficult to determine, and it may be difficult to reconcile them
if they are not aligned. The financial industry has also taken initiatives
through guidelines and self-regulatory initiatives.
Dodd-Frank Act and other US Regulations
ING Bank has a limited direct presence in the United States through the
ING Bank Representative Offices in New York, Dallas, Houston, and Los
Angeles. Although the offices’ activities are strictly limited to essentially
that of a marketing agent of lending and other similar products (i.e. the
offices may not take deposits or execute any transactions), the offices are
subject to the regulation of the State of New York Department of Financial
Services, the State of Texas Department of Banking, the California
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 49
Department of Financial Protection and Innovation, respectively, as well as
the Federal Reserve. ING Bank also has a subsidiary in the United States,
ING Financial Holdings Corporation, which through several operating
subsidiaries offers various financial products, including lending, and
financial markets products. These entities do not accept deposits in the
United States on their own behalf or on behalf of ING Bank N.V.
The ING subsidiary, ING Capital Markets LLC, is registered as a U.S. swap
dealer and subject to a statutory regulatory regime and CFTC rules and
oversight. As a result, it is subject to, among others, business conduct,
record-keeping and reporting requirements, as well as margin
requirements and capital requirements. In addition to the obligations
imposed on registrants (such as swap dealers), other requirements relating
to reporting, clearing, and on-facility trading have been imposed for much
of the off-exchange derivatives market and new risk management
requirements have been proposed focused on business continuity
generally. The proposed new risk management requirements could impose
significant compliance costs to the extent inconsistent with the existing
group-wide framework.
ING Capital Markets LLC is also registered as a security-based swap dealer
and is subject to a statutory regulatory regime and SEC rules and
oversight. The SEC has adopted regulations, among others, establishing
registration, reporting, risk management, business conduct, and margin
and capital requirements for security-based swaps. While ING Capital
Markets LLC, as a security-based swap dealer, is required to comply with
SEC rules with respect to most of these requirements, SEC rules have
permitted an “Alternative Compliance Mechanism” that allows for
compliance, subject to eligibility requirements, with CFTC capital and
margin rules applying to swap dealers in lieu of SEC capital and margin
rules applying to security-based swap dealers. ING Capital Markets LLC has
elected to use the Alternative Compliance Mechanism. However, should
ING Capital Markets LLC in the future be ineligible for the “Alternative
Compliance Mechanism”, it would be subject to SEC security-based swap
dealer rules for margin, capital, and related financial reporting instead of
the CFTC swap dealer rules applied to security-based swaps with respect to
margin, capital, and related financial reporting.
The Dodd-Frank Act also created an agency, the Financial Stability
Oversight Council (FSOC), an interagency body that is responsible for
monitoring the activities of the U.S. financial system, designating
systemically significant financial services firms and recommending a
framework for substantially increased regulation of such firms, including
systemically important non-bank financial companies that could consist of
securities firms, insurance companies and other providers of financial
services, including non-U.S. companies. ING has not been designated a
systemically significant non-bank financial company by FSOC and FSOC
initiating such a designation currently is deemed unlikely.
Dodd-Frank continues to impose significant requirements on us, some of
which may have a material impact on our operations and results, as
discussed further under “Item 3. Key Information - Risk Factors - We
operate in highly regulated industries. Changes in laws and/or regulations
governing financial services or financial institutions or the application of
such laws and/or regulations governing our business may reduce our
profitability”.
Basel III has been implemented in the EU and is currently applied
by ING
In all jurisdictions where the bank operates through a separate legal entity
that is a credit institution, ING must meet the local implementation of
Basel requirements. ING uses the Advanced and Foundation IRB Approach
for credit risk, the Internal Model Approach for its trading book exposures
and the Standardised Measurement Approach for operational risk. A small
number of portfolios including certain sovereign exposures are reported
under the Standardized Approach for credit risk.
In December 2010, the Basel Committee on Banking Supervision
announced higher global minimum capital standards for banks, and
introduced a new global liquidity standard and a new leverage ratio (LR).
The Basel Committee's package of reforms, collectively referred to as the
“Basel III” rules, among other requirements, increased the amount of
common equity required to be held by subject banking institutions,
prescribed the amount of liquid assets and the long term funding a subject
banking institution must hold at any given moment, and limited leverage.
Banks are required to hold a “capital conservation buffer” to withstand
future periods of stress. Basel III also introduced a “countercyclical buffer”
as an extension of the capital conservation buffer, which permits national
regulators to require banks to hold more capital during periods of high
credit growth (to strengthen capital reserves and moderate the debt
markets). Further, Basel III strengthened the definition of capital that had
the effect of disqualifying many hybrid securities, as well as increased
capital requirements associated with certain business conditions (for
example, for credit value adjustments (CVAs) and illiquid collateral) as part
of a number of reforms to the Basel II framework. In addition, the Basel
Committee and Financial Stability Board (“FSB”) published measures that
have had the effect of requiring higher loss absorbency capacity, liquidity
surcharges, exposure limits and special resolution regimes for, and
instituting more intensive and effective supervision of, “systemically
important financial institutions” (SIFIs), in addition to the Basel III
requirements otherwise applicable to most financial institutions. One such
measure, published by the FSB in November 2015, is the Final Total-Loss
Absorbing Capacity (TLAC) standard for G-SIFIs, which aims for G-SIFIs to
have sufficient loss-absorbing and recapitalisation capacity available in
resolution. Since 2011, ING has been designated by the Basel Committee
and FSB as a so-called “Global Systemically Important Bank” (G-SIB, or
Global Systemically Important Institution - G-SII in the European
legislation), and by DNB and the Dutch Ministry of Finance as a “other
SII” (O-SII) . Since December 2020 DNB has required ING Group to hold O-SII
Buffer in addition to the capital conservation buffer and the countercyclical
buffer described above. ING Group is subject to O-SII Buffer of 2.0% (from
31 May 2024 when DNB lowered it from 2.5% that applied previously). In
December 2025 DNB announced that it reviewed the identification and
buffer requirements for systemically important banks, and maintained
2.0% O-SII Buffer requirement for ING. The higher of G-SIB or O-SII buffers
applies, hence ING Group's risk-based capital requirements are not
affected by G-SII Buffer of 1%. However 50% of G-SII buffer increases ING's
Leverage Ratio requirement from a regular 3.0% (3.1% with 0.1% Pillar 2
requirement from 1 January 2026) that applies to non G-SII banks to 3.5%
(3.6 % including 0.1% Pillar 2 requirement from 1 January 2026).
For European banks the Basel III requirements have been implemented
through the Capital Requirement Regulation (CRR) and the Capital
Requirement Directive (CRD). The CRD IV regime entered into effect in
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 50
August 2014 in the Netherlands, but not all requirements were
implemented all at once. Having started in 2014, the requirements have
been gradually tightened, mostly before 2019, until the Basel III migration
process was completed.
CRD IV has not only resulted in new quantitative requirements but has also
led to the setting of new standards and evolving regulatory and
supervisory expectations in the area of governance, including with regard
to topics like conduct and culture, strategy and business models,
outsourcing and reporting accuracy.
CRR II / CRD V and BRRD II
On 27 June 2019, a series of measures referred to as the Banking Reform
Package (including certain amendments to CRR and CRDIV commonly
referred to as ‘CRR II’ and CRD V’) came into force, subject to various
transitional and staged timetables. The adoption of the Banking Reform
Package concluded a process that began in November 2016 and marked
an important step toward the completion of the European post-crisis
regulatory reforms, drawing on a number of international standards
agreed by the Basel Committee, the Financial Stability Board and the G20.
CRDV was implemented in Dutch law in 2020. The Banking Reform Package
introduced changes to the CRR, CRD IV, the Bank Recovery and Resolution
Directive (BRRD) and the Single Resolution Mechanism Regulation (SRMR).
The Banking Reform Package covered multiple areas, including the Pillar 2
framework, the introduction of a leverage ratio requirement of 3% and a
leverage ratio buffer requirement of 50% of the G-SIB buffer requirement
(applicable per 1 January 2023), a binding Net Stable Funding (NSFR) ratio
based on the Basel NSFR standard (including adjustments with regard to
e.g. pass-through models and covered bonds issuance), mandatory
restrictions on distributions, permission for reducing own funds and eligible
liabilities, macroprudential tools, a new category of ‘non-preferred’ senior
debt, the minimum requirement for own funds and eligible liabilities
(MREL) and the integration of the TLAC standard into EU legislation.
Further, the EBA obtained a mandate to investigate how to incorporate
environmental, social, and governance (ESG) risks into the supervisory
process and what the prudential treatment of assets associated with
environmental or social objectives should look like.
Whilst the Banking Reform Package was being developed, the ECB
introduced the Targeted Review of Internal Models (TRIM) in June 2017 to
assess reliability and comparability between banks’ models for calculating
each bank’s risk-weighted assets (‘RWA’) used for determining certain of
such bank’s capital requirements. In July 2019, the ECB published the final
chapters of the guide to internal models, covering credit risk, market risk
and counterparty credit risk. These risk type-specific chapters are intended
to ensure a common and consistent approach to the most relevant
aspects of the regulations on internal models for banks directly supervised
by the ECB. Additionally, they provided transparency on how the ECB
understands the regulations on the use of internal models to calculate
own funds requirements for the three risk types. Impact on ING is through
more stringent regulation on the end-to-end process and governance
around internal models as well as an increase of risk weighted assets
(RWA).
In 2020, the last TRIM ECB inspection ended. Most of the remedial actions
triggered by the TRIM assessments resulted in the redevelopment of the
credit risk models and were addressed. Most remedial actions have been
implemented, with limited remaining.
CRR “quick fix” in response to the Covid‐19 pandemic
On 26 June 2020 Regulation (EU) 2020/873 of the European Parliament
and of the Council of 24 June 2020 amending Regulations CRR as regards
certain adjustments in response to the COVID-19 pandemic (commonly
referred to as CRR ”quick fix”) was published.
The CRR ‘quick fix’ introduced certain adjustments to the CRR, including
temporary measures and measures that early adopt changes in the
regulations that were intended to become effective at a future date. This
notably included reduced capital requirement for certain exposures to
small- and medium sized enterprises (SMEs), a more favourable prudential
treatment for certain software assets, one year delay in the application of
the leverage ratio buffer requirement of 50% of the G-SIB buffer (to 1
January 2023). Also, the ‘quick fix’ extended by 2 years transitional
arrangements for mitigating the impact on own funds of the introduction
of IFRS 9 (Article 473a (8) of CRR).
CRR III / CRD VI
On 27 October 2021, the European Commission published a legislative
proposal to review the EU’s CRD/CRR framework. The review consisted of
the following legislative elements: a proposal to amend CRD V ("CRD VI"), a
proposal to amend CRR II ("CRR III"), and a separate, targeted proposal to
amend CRR II in the area of resolution.
This proposed legislative review was to implement the final Basel III
framework – agreed at the end of 2017 - in the EU. The revisions mainly
related to the prudential standards for credit, market, operational and
credit valuation adjustment (CVA) risk as well as the introduction of an
output floor. Key changes comprise the reduced use of internal models
and more risk-sensitive and granular standardised approaches. It aimed to
increase consistency in risk-weighted asset calculations and improve
comparability of bank capital ratios. The Commission’s proposal remained
close to the 2017 Basel agreement, but in some areas included targeted
measures to account for specificities of the EU banking sector. These
measures mitigate until 2030-2032 the impact of the Output Floor for
lending to unrated corporates, low risk mortgages, and some other
categories.
While most CRR III amendments entered into force on 1 January 2025,
some provisions will be phased-in over subsequent year. Specifically, the
output floor will be generally phased in over 5 years with some of the
output floor and general phase-in provisions lasting until 2032. CRR III also
requires secondary legislation, much of which has yet to be finalized.
CRD VI requires EU Member States to transpose its provisions into national
law by 10 January 2026, with most measures applying from 11 January
2026. In the Netherlands, a draft legislation was published in April 2025,
followed by a revised version in October 2025. However, legislation has not
yet been finalised or enacted.
Capital requirements applicable to ING Group at a consolidated level
In accordance with the CRR the minimum Pillar 1 capital requirements
applicable to ING Group are:
§in terms of the Risk Weighted Assets (RWA): 4.5% of Common Equity
Tier 1 (CET1), 6% of Tier 1 and 8% of Total capital.
§in terms of the Leverage Exposure: 3% of Tier 1.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 51
For the Leverage Exposure, the overall Pillar I requirement is 3.5% of Tier 1
(including 0.50% G-SIII buffer).
In terms of the risk weighted capital requirements, ING Group is also
subject to the Combined Buffer Requirement that consists of the Capital
Conservation Buffer of 2.5%, the O-SII buffer (buffer for Other Systemically
Important Institutions) of 2.0%, the Countercyclical Buffer (CCyB) of 0.93%
and Systemic Risk Buffer (SyRB) of 0.16%. ING Group is subject to SyRB
because: 1) ING Group has exposures in Germany, Belgium and Norway
that are in scope of SyRB set in those countries, and 2) De Nederlandsche
Bank (DNB) recognised SyRB set in those countries (while initially the
recognition did not apply at the consolidated level, DNB adjusted it so that
it applies at consolidated level from December 2025).
These buffers rates may fluctuate. Specifically, the following authorities
adjusted the CCyB recently: De Nederlandsche Bank (DNB; for exposures in
the Netherlands), Narodowy Bank Polski (NBP; for exposures in Poland)
Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin; for exposures in
Germany) and National Bank of Belgium (NBB; for exposures in Belgium).
DNB increased the CCyB to 2% from May 2024. NBP increased the CCyB to
1% from September 2025 (planned increase to 2% from September 2026).
DNB and NBP intend to apply a 2% CcyB in a standard risk environment.
BaFin decided to set the CCyB at 0.75% from February 2023. NBB increased
the CCyB to 1% from October 2024 (planned increase to 1.25% from July
2026). Other authorities announced increases too.
For more information reference is made to Note 46 ‘Capital management’
and ‘Capital management’ in Additional Information.
In accordance with the CRD IV, ING Group is also subject to Pillar 2 capital
requirements that supplement Pillar I capital requirements. Pillar 2
requirements are bank specific and for ING Group they are determined by
the ECB. As of 31 December 2025, Pillar II capital requirement for ING
Group are in terms of the Risk Weighted Assets (RWA) is 0.93% of Common
Equity Tier 1 (CET1), 1.24% of Tier 1, 1.65% of Total capital. As of 1 January
2026, these will increase to 0.96%, 1.28%, 1.70%, respectively.
Additionally, from 1 January 2026, ING group will be subject to Pillar II
requirement in terms of the Leverage Exposure of 0.1% of Tier 1. The ECB
reviews Pillar II requirements every year.
Bank recovery and resolution directive
The BRRD aims to safeguard financial stability and minimise the use of
public funds in case banks face financial distress or fail to comply with the
BRRD. Since 2014 banks across the EU need to have recovery plans in place
and need to cooperate with resolution authorities to determine, and make
feasible, the preferred resolution strategy. The banking reform which came
into force on 27 June 2019 includes changes to the minimum requirement
for own funds and eligible liabilities (MREL) to ensure an effective bail in
process. It also includes new competences for resolution authorities and
requires G-SIBs and other banks to build up loss-absorbing and
recapitalization capacity.
In April 2023 the European Commission published a legislative proposal to
review the EU’s existing bank crisis management and deposit insurance
(CMDI) framework, with a focus on medium-sized and smaller banks. Based
on the political agreement of co-legislators from June 2025: 1) DGS or
resolution funds could be used to finance the resolution as a last resort, 2)
criteria for assessment whether the resolution can be initiated would be
broadened, 3) assessment to determine whether a bank should be able to
use the resources of the DGS will be harmonised, 4) current preference of
DGS protected deposits is maintained with a second tier of deposits of
households and SME depositors not covered by the DGS. Based on the
initial draft proposal, majority of the changes would apply from 18 months
from the date of entry into force. Final legislation is yet to be published.
ING has had a recovery plan in place since 2012. The plan includes
information on crisis governance, recovery indicators, recovery options,
and operational stability and communication measures. The plan
enhances the bank’s readiness and decisiveness in case of a financial crisis.
The plan is updated annually to make sure it stays fit for purpose. The
completeness, quality and credibility of the updated plan is assessed each
year by ING’s regulators.
The Single Resolution Board (SRB) confirmed to ING in 2017 that a single-
point-of-entry (SPE) strategy is ING’s preferred resolution strategy, with
ING Groep N.V. as the resolution entity.
In July 2025, ING Group received an updated formal notification from De
Nederlandsche Bank (DNB) of its MREL requirements. The MREL
requirement has been established to ensure that banks in the European
Union have sufficient own funds and eligible liabilities to absorb losses and
to recapitalize bank in the case of a resolution. The MREL requirement is
set for ING Group at a consolidated level, as determined each year by the
Single Resolution Board (SRB). The following MREL requirements for ING
Group were applicable on 31 December 2025: 22.62% of RWA, and 7.24%
of LR exposure. MREL requirements are updated every year.
CRR II implements the Financial Stability Board’s total loss absorbing (TLAC)
requirement for Global Systemically Important Institutions (G-SII), which is
the EU equivalent of a G-SIB. The transitional requirement - the higher of
16% of the resolution group’s RWA or 6% of the leverage ratio exposure
measure - applied immediately. The higher requirement - 18% and 6.75%,
respectively - came into effect as of 1 January 2022. ING is required to
meet both the TLAC and requirement.
On top of MREL and TLAC RWA requirements, ING Group is required to
meet the Combined Buffer Requirement (CBR) of 5.60% of CET1 (as of 31
December 2025). Fully loaded CBR (that reflects measures already known
on 31 December 2025 but not yet applicable) would amount to 5.63%. ING
Group meets these requirements. If ING Group breaches the CBR on top of
MREL/TLAC (M-MDA), ING may face restrictions on dividend payments, AT1
instruments coupons and payment of variable remuneration.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 52
In addition to the requirements for the Group on a consolidated level,
internal MREL requirements are also set for individual ING subsidiaries in
the EU.
Regulatory liquidity ratios
In line with the CRR, ING Group is required to comply with:
§the Liquidity Coverage Requirement (LCR) that is designed to ensure
that banks hold enough liquidity assets to cover for net liquidity
outflows under stressed conditions over 30 days. The required LCR ratio
is 100%.
§The Net Stable Funding Requirement (NSFR) that is designed to ensure
that banks hold sufficient stable funding to meet their funding needs
over a one-year horizon under both normal and stressed conditions.
The required NSFR ratio is 100%.
For more information reference is made to "Funding and liquidity risk"
section in Additional Information.
Simplification of EU banking rules
In December 2025 the European Central Bank published recommendations
on how to simplify the EU banking rules: 1) to reduce the numbers of
elements in the framework, 2) to introduce a simpler regime for smaller
banks, 3) to introduce a new European governance with holistic view of the
capital requirements, and 4) to finalise the saving and investment union,
including completion of the banking union. These recommendations are
not binding, but might be considered by legislators. The European
Commission is expected to publish a Report on possible simplification
measures in 2026.
Stress testing
Stress testing is an important risk management tool that provides input for
strategic decisions and capital planning. The purpose of stress testing is to
assess the impact of plausible but severe stress scenarios on ING’s capital
and liquidity position. Stress tests provide complementary and forward-
looking insights into the vulnerabilities of certain portfolios, with regards to
adverse macroeconomic circumstances, stressed financial markets, and
changes in the (geo)political climate. In addition to assessing P&L, capital
and liquidity positions of ING for a range of different scenarios,
idiosyncratic risks are also included. The outcome of these stress tests help
management get insight into the potential impact and define actions to
mitigate this potential impact.
In addition to running internal stress test scenarios to reflect the outcomes
of the annual risk assessment, ING also participates in regulatory stress
test exercises. ING participated in the 2025 EU-wide stress test. The
exercise has been coordinated by the European Banking Authority (EBA)
and carried out in cooperation with the European Central Bank (ECB), the
European Systemic Risk Board (ESRB), the European Commission (EC) and
the Competent Authorities (CAs) from all relevant national jurisdictions.
The baseline macro-financial scenario is based on the projections from the
EU national central banks, IMF and OECD. The adverse stress test scenario
was developed by the ESRB. Both the scenario covers the three years from
2025 to 2027 in line with the EBA methodology.
The 2025 EU-wide stress test exercise was carried out applying a static
balance sheet assumption as of December 2024, and therefore does not
take into account current or future business strategies and mitigating
actions. The results of the EBA stress test shows that even under the
severe but hypothetical scenario ING’s is able to withstand these
circumstances even when no mitigating actions have been taken into
account. Under the hypothetical baseline scenario and EBA’s
methodological instructions, ING Group would have a transitional common
equity Tier 1 capital ratio (CET1) of 12.90% in 2027 and a fully loaded CET1
ratio of 11.85% in 2027. Under the hypothetical adverse scenario and
EBA’s methodological instructions, ING Group would have a transitional
CET1 ratio of 10.63% in 2027 and a fully loaded CET1 ratio of 10.41% in
2027. Our commitment to maintain a robust, fully loaded Group common
equity Tier 1 (CET1) ratio in excess of prevailing requirements remains. ING
Group published an actual CET1 ratio of 13.56% per 31 December 2024
(the reference date for the stress test), and 13.08% per 31 December 2025.
The next EBA EU-wide stress test will be held in 2027.
Deposit Schemes
In the Netherlands and other jurisdictions, deposit guarantee schemes and
similar funds (‘Compensation Schemes’) have been implemented to ensure
depositor pay-out to customers if a deposit taking institution is unable, or
unlikely to pay, claims against it. These Compensation Schemes are
funded, directly or indirectly, by financial services firms operating and/or
licensed in the relevant jurisdiction.
Dutch Deposit Guarantee Scheme (‘DGS’):, ING Bank participates in the
Dutch Deposit Guarantee Scheme (DGS) which guarantees an amount of
EUR 100,000 per person per bank, regardless of the number of accounts
held. Based on the EU Directive on deposit guarantee schemes, ING pays
quarterly risk-based contributions into a DGS-fund. The Dutch DGS fund
reached its target size of 0.8% of all deposits guaranteed under the DGS in
July 2024.
In the event of a Dutch bank's failure, depositor compensation is paid from
the DGS-fund. If the available financial means of the fund are insufficient,
Dutch banks, including ING, may be required to pay extraordinary ex-post
contributions not exceeding 0.5% of their covered deposits per calendar
year. In exceptional circumstances and with the consent of the competent
authority, higher contributions may be required. However, extraordinary
ex-post contributions may be temporarily deferred if they would
jeopardise the solvency or liquidity of a bank.
Since 2015, the EU has been discussing the introduction of a pan-European
Deposit Guarantee Scheme (EDIS), but no political agreement has been
reached on its creation.
Instant Payments and the Payment Services Regulation/PSD3
In January and October 2025, key provisions of the EU instant payments
regulation entered into force. The regulation aims to ensure that instant
payments in euro are affordable, secure and without hindrance across the
European Union. Instant Payments are to be credited to the account of the
beneficiary within 10 seconds after receipt of the payment order by the
payer’s payment service provider and shall be available 24 hours a day all
year round. The regulation has introduced a service to be provided by
payment service providers to payers to verify the match between the bank
account number and the name of the beneficiary provided by the payer to
prevent mistakes or fraud.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 53
In June 2023 the European Commission launched its proposal for the
Payment Services Regulation (PSR) and Payment Services Directive 3,
which together will succeed the current directive for payment services
(PSD2). The main proposed changes relate to fraud, further development
of open banking, the granting of access to payment systems by non-bank
payment service providers, and further improving consumer rights and
obligations.
The PSR is in the final stages of negotiation among the European
Parliament and EU member states. The combat of fraud stands out and
addresses new fraud types, such as impersonation fraud. To that end
priorities emerging from PSR negotiation include: an obligation for
electronic communications services providers to contribute to the
collective fight against fraud, the IBAN/name check, a legal basis for
payment service providers to share fraud related data, and intensified
transaction monitoring. Political consensus is emerging that all actors in
the ecosystem must contribute to the combat of fraud. PSR may grant
certain refund rights to consumers that suffered damages from the failure
of the IBAN/name verification or that are a victim of specific types of fraud.
Agreement on final texts has not yet been reached.
The single currency package: the digital euro and access to cash
In October 2025 the ECB’s governing council concluded its preparation
phase for the digital euro, and announced further preparations, in
anticipation of a political agreement on the digital euro. In June 2023 the
European Commission launched its legislative proposal establishing the
legal framework for such euro. It will ensure that people and business
when paying with central bank money also have the possibility to pay
digitally, online and/or offline, in addition to coins and banknotes. The
legislative proposal on the legal tender status of euro cash safeguards the
role of cash, it shall continue to be a means of payment and should
continue to be easily accessible. If enacted, the digital euro could have an
impact on ING’s deposit funding, as a portion of our clients may transfer
part of their deposits held at ING, to digital euros. In addition, depending
on the set-up of the digital euro, which is still being negotiated by
European co-legislators, it could have an impact on the competitive
landscape between banks and non-bank financial services providers, as
well as on private sector-provided payment solutions.
Benchmarks Regulation
The EU Benchmarks Regulation (BMR), adopted in 2016 and effective since
January 2018, was amended in May 2025, effective as per 01.01.2026, to
streamline its scope and strengthen governance. Under the revised
framework, only critical and significant benchmarks, EU Climate Transition
and Paris-Aligned benchmarks, and certain commodity benchmarks
remain subject to the regulation, while non-significant benchmarks have
largely been removed, reducing compliance complexity. The ESMA
Benchmarks Register will serve as the single authoritative source for
benchmark and administrator information.
Benchmarks based on contributor input must have a code of conduct in
place to safeguard data integrity, address key areas such as conflicts of
interest management, internal controls, and benchmark methodologies.
Financial contracts and instruments referencing benchmarks are required
to include clear fallback provisions to ensure continuity in case of
benchmark cessation.
ING has established a Global Benchmarks Transition Office to oversee
benchmark transitions with global impact (e.g. WIBOR), ensuring controlled
execution of all transition elements. For qualitative and quantitative
disclosures on IBOR transition refer to “Additional information – ING Group
Risk Management – Market Risk”.
KYC Requirements
Financial institutions continue to face new and increasingly complex
regulatory requirements, contributing to increasing costs of compliance, in
the context of heightened regulatory scrutiny. Generally, we expect the
scope and extent of regulations in the jurisdictions in which we operate to
continue to increase.
The evolving regulatory landscape drives the need for continuous change
in the various processes, procedures and systems of the bank. Where the
timeline for implementation of new or revised requirements is sometimes
quite short, this presents challenges to financial institutions in general. In
addition, in some instances, the complexity of the regulatory landscape
gives rise to potential tension between applicable laws and regulations at a
local and/or global level. For example, there is the potential tension
between data privacy (GDPR) and AML/CFT and anti-corruption laws and
regulations; including the requirement to share information relating to
financial crime concerns to manage risk exposure across the group, while
complying with the legislative requirements relating to data, which can
differ significantly depending on the jurisdiction. In contrast, the European
Union’s proposed Anti-Money Laundering Regulation (AMLR) seeks to
create a harmonized framework across EU member states, enhancing
consistency in anti-money laundering and counter-terrorist financing
efforts when it is implemented in 2027.
ING is focused on continuing to embed applicable requirements in our
processes and procedures, including in our IT systems and data sources, in
a robust and sustainable way; driving a business environment which is
compliant by desire and design. The bank also executes ongoing training
and awareness to develop its people to have the right knowledge and
skills.
In addition, ING aims to continuously monitor regulatory developments, as
well as considering emerging and evolving risks. This supports assessment
of the risks that ING may be exposed to and of the associated controls and
processes ING has in place, so we can appropriately manage these risks in
accordance with our risk appetite.
AML/CTF-related developments
The Authority for Anti-Money Laundering and Countering the Financing of
Terrorism (AMLA) is the newly established EU agency tasked with
transforming AML/CFT supervision across the European Union. Following its
formal adoption in mid-2024, AMLA officially commenced operations on 1
July 2025, headquartered in Frankfurt. Its mandate includes harmonising
enforcement, coordinating national authorities, and enhancing
collaboration among financial intelligence units (FIUs).
AMLA’s 2025 Work Programme outlines its phased operational rollout, with
full supervisory powers expected by 1 January 2028. The agency will
directly supervise up to 40 high-risk financial institutions operating across
multiple EU member states, with selection criteria to be finalised by the
end of 2025. ING continues to monitor developments closely, as its cross-
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 54
border footprint and risk profile suggest a strong likelihood of being
designated for direct supervision.
Policy with respect to certain countries
As a result of frequent evaluation of all businesses from economic,
strategic and risk perspective ING continues to believe that for business
reasons doing business involving certain specified countries should be
discontinued. In that respect, ING has a policy not to enter into new
relationships with clients from these countries and processes remain in
place to discontinue existing relationships involving these countries. At
present these countries are Cuba, Iran, North Korea, Sudan and Syria, as
well as the Crimea region.
ING Group maintains a limited legacy portfolio of guarantees, accounts,
and loans that involve various entities with a connection to Iran. These
positions remain on the books but certain accounts related thereto are
‘frozen’ where prescribed by applicable laws and procedures and in all
cases subject to increased scrutiny within ING Group. ING Group may
receive loan repayments, duly authorised by the relevant competent
authorities where prescribed by applicable laws. For the calendar year
2025, ING Group had limited revenues and no net profit is made as there
were no repayments made in 2025.
Sanctions related developments
With respect to sanctions, as a result of Russia’s continued occupation of
parts of Ukraine and the associated conflict there has been a continued
focus of the EU, US, and other governments to impose additional sanctions
and combat the potential circumvention of sanctions against Russia. In
addition to several new sanctions packages there has been an increased
focus on the roles of third countries and companies in facilitating the
circumvention or undermining of such sanction’s measures.
Accordingly, as part of ING’s Know Your Customer and compliance risk
governance and procedures, ING is continuously monitoring the situation
to stay abreast on all relevant updates to implement effective and
appropriate additional control measures and to manage the increased risk
and financial impacts of these developments.
Operationally, the impact of these enhancements has resulted in the need
for additional staff members to review and apply greater scrutiny of
transactions alerted for heightened risk of non-compliance with applicable
sanctions.
For additional information regarding regulatory developments, see also
this Form 20-F 2025, under “Additional Information – ING Group Risk
Management- Compliance Risk”.
ESG Reporting Regulations
Environmental, Social and Governance (ESG) metrics and disclosures are
an increasing focus for businesses as they respond to a wave of scrutiny
from all manner of stakeholders, from investors and regulators to
employees and customers. There’s an expectation that ESG disclosures will
comply with mandatory and voluntary reporting requirements and be
reliable, verifiable and comparable to allow those stakeholders to make
decisions that matter to them.
There is currently a legislative initiative ongoing at the European
Commission level (i.e the EU Omnibus Regulation) which aims to
streamline and simplify certain sustainability regulations, such as the
CSDDD, CSRD and EU Taxonomy. The outcome of this initiative may impact
the interpretation and implementation of these regulations in the future.
Non-Financial Reporting Directive (NFRD)
Since 2018, companies like ING within the scope of the NFRD (Directive
2014/95/EU) have been required to disclose information on non-financial
matters (environmental, social and employee matters, human rights,
bribery and corruption). The objective of the NFRD is to improve the quality
and quantity of corporate non-financial information reporting.
Under the NFRD, large, listed companies, banks and insurance companies
('public interest entities') with more than 500 employees are required to
publish reports on the policies they implement in relation to social
responsibility and treatment of employees; respect for human rights; anti-
corruption and bribery; and diversity on company boards (in terms of age,
gender, educational and professional background). In particular, the NFRD
requires companies to disclose information about their business models,
policies (including implemented due diligence processes), outcomes, risks
and risk management, and Key Performance Indicators relevant to the
business.
Corporate Sustainability Reporting Directive (CSRD)
The CSRD (directive (EU) 2022/2464) was published in December 2022 in
the Official Journal of the European Union and should have been
transposed into national law by 6 July 2024. Currently several European
Union Member States, including the Netherlands, have not yet notified the
European Commission on the full transposition of the CSRD into national
law and missed the deadline of July 6, 2024. This situation creates an
ambiguity in terms of legal enforcement of the CSRD in local context(s). On
26 September, 2024, the European Commission has opened infringement
procedures for those countries by sending a letter of formal notice due to
the absence of measures taken to transpose EU directives into national
law. Legislative initiatives are currently underway in the Netherlands, as
well as in other jurisdictions that have yet to adopt the regulation;
however, the implementation timelines remain uncertain at this stage.
CSRD profoundly revises the ESG reporting requirements, and it is designed
to bring sustainability reporting on par with financial reporting over time
and monitor the progress of companies’ activities in relation to
sustainability matters. With the CSRD, the existing sustainability matters of
ESG reporting will be expanded and standardized. Its aims are to:
§harmonize and improve the quality of information published by
undertakings, particularly information on ESG (sustainability-related
information);
§provide financial undertakings, investors, relevant stakeholders and the
general public with relevant, comparable and reliable sustainability
information;
§encourage investment that supports the transition to a sustainable
economy in line with the European Green Deal.
Undertakings falling within its scope are required to report detailed
disclosure requirements that are specified under the European
Sustainability Reporting Standards (ESRS).
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 55
CSRD introduced a phased-in approach for the application, where
undertakings that are subject to the NFRD were required to provide
sustainability related information for financial years beginning on or after
1 January 2024. These companies would be later joined by large non-listed
companies (2025), listed SMEs (2026) and certain European subsidiaries of
non-EU groups. ING Group, as well as some of its subsidiaries in scope,
have disclosed their sustainability related information in their 2024
Management Board report for the first time in 2025.
Subsequently, the European Commission introduced an Omnibus
Simplification Package which includes simplification measures on the
CSRD. The first component, known as the Stop-the-Clock Directive
(Directive (EU) 2025/794), published in the Official Journal on 16 April 2025,
postpones CSRD reporting by two years for companies scheduled to start
in 2026 and 2027. This measure prevents reporting obligations from taking
effect while simplification efforts are ongoing. The second component
introduces major amendments to CSRD which includes amongst other
narrowing the scope of undertakings required to report (incl. removing in
scope subsidiaries from reporting obligations), removing sector-specific
standards and removing the future move to reasonable assurance from
limited assurance. On 9 December 2025, a political agreement was
reached between the European Parliament and Council on the legislative
package introducing these amendments, which is currently awaiting its
publication in the Official Journal of the EU. Besides these, the Commission
has also adopted a quick-fix regulation (Delegated Regulation (EU)
2025/1416) to extend transitional provisions of specific disclosures
requirements to avoid additional burden during regulatory change. ING is
closely monitoring regulatory developments.
European Sustainability Reporting Standards (ESRS)
In July 2023, the European Commission has adopted the final delegated
act of the European Sustainability Reporting Standards (ESRS). Companies
subject to the CSRD shall report according to the ESRS, starting from 2025,
over financial year 2024, based on a phased-in approach.
The ESRS specify the sector-agnostic sustainability reporting requirements
based on the CSRD, covering the full range of sustainability matters
(Environment, Social and Governance). The overall architecture of the ESRS
is designed to ensure that sustainability information is reported in the
companies’ management report based on a double materiality
assessment (i.e. impact and financial materiality) and is based on the
following reporting structure:
1.Governance: the governance processes, controls and procedures used
to monitor and manage impacts, risks and opportunities
2.Strategy: how the undertaking’s strategy and business model(s)
interact with its material impacts, risks and opportunities, including the
strategy for addressing them
3.Impact, risk and opportunity management: the process(es) by which
impacts, risks and opportunities are identified, assessed and managed
through policies and actions
4.Metrics and targets: how the undertaking measures its performance,
including progress toward the targets it has set.
The cross-cutting standards consist of:
§ESRS 1 which prescribes the mandatory concepts and principles to be
applied when preparing sustainability statements under the CSRD.
§ESRS 2 is on general, strategy, governance, and materiality assessment
disclosure requirements.
The topical standards consist of:
§Environment topical standards (ESRS E1–E5) outline disclosure
requirements for companies to report on matters related to climate
change, pollution, water and marine resources, biodiversity and
ecosystems, and resource use and circular economy.
§Social topical standards (ESRS S1–S4) provide a framework for entities
to report on topics related to their own workforce, the workers in their
value chains, the communities impacted by their operations and the
consumers and end-users of their products or services.
§Governance topical standards (ESRS G1) set out disclosure
requirements that seek to enhance users’ understanding of a
company’s governance structure, its internal control and risk
management system, the company’s strategy and approach, and the
processes, procedures and performance in relation to their business
conduct.
As part of the Omnibus initiative, the European Commission aims to revise
the ESRS to reduce the reporting burden while maintaining consistency
with the EU sustainability objectives and ensuring interoperability with
global frameworks. The European Commission has mandated the EFRAG to
provide a technical advice on this initiative. EFRAG has consulted the public
and submitted its work to the Commission by the end of November 2025.
The key changes include the reduction of mandatory data points, removal
of majority of voluntary data points, simplification of the double
materiality assessment and enhanced alignment with the ISSB. Adoption
of the revised ESRS by the Commission is expected by the of the first half
of 2026 with mandatory application for the reporting year 2027.
EU Taxonomy
The EU Taxonomy Regulation (EU Taxonomy), published in the Official
Journal of the EU in 2020, is a classification system, establishing a list of
‘environmentally sustainable’ economic activities and introducing
reporting requirements. The EU Taxonomy provides companies, investors
and policymakers with appropriate definitions for which economic
activities can be considered ‘environmentally sustainable’ and can be
reported accordingly. In this way, it creates security for investors and
protects private investors from greenwashing. For economic activities to be
recognized as ‘environmentally sustainable”, they should meet the
following criteria:
§Substantially contributing to one of the six EU environmental
objectives:
–Climate change mitigation
–Climate change adaptation
–Sustainable use and protection of water and marine resources
–Transition to a circular economy
–Pollution prevention and control
–Protection and restoration of biodiversity and ecosystems
§Do not significantly harm to any of the other 5 objectives
§Meeting minimum safeguards, including OECD Guidelines for
Multinational Enterprises and the UN Guiding Principles on Business, ILO
standards and Human Rights.
For disclosure requirements under the EU Taxonomy, a delegated act
supplementing Article 8 of the Taxonomy is applicable since January 2022.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 56
Article 8 of the EU Taxonomy aims to increase transparency in the market
and help prevent greenwashing by providing information to investors
about the environmental performance of assets and economic activities of
financial and non-financial undertakings in scope. This delegated act
specifies the content, methodology and presentation of information to be
disclosed concerning the proportion of environmentally sustainable
economic activities in their businesses, depending on the type of the
company (i.e. non-financial/financial). Within the scope of Article 8
delegated act, in-scope credit institutions are required disclose the Green
Asset Ratio (GAR) which measures the share of a credit institution's
taxonomy-aligned exposure against total covered assets, amongst other
detailed disclosures.
As part of the Omnibus Simplification Package, the European Commission
has adopted a delegated act introducing amendments to improve the
effectiveness of EU Taxonomy disclosures by reducing complexity and
burden. The amendment introduces key changes such as recalibrating the
GAR to ensure symmetry within the numerator and denominator,
introducing materiality thresholds and removing or simplifying certain
templates to ease administrative burden. Revised rules have entered into
force and can already be applied from 1 January 2026 per the delegated
act.
Pillar 3 ESG Disclosures
Article 449a of Regulation (EU) No 575/2013 (CRR) requires institutions to
disclose prudential information on environmental, social and governance
risks, including physical risks and transition risks, as defined in Article 4 of
the same regulation. Under CRR III, the scope of application has been
extended beyond large and listed institutions to cover all institutions,
including large subsidiaries of parent institutions. Article 434a CRR
mandates the EBA to develop draft implementing technical standards (ITS)
specifying uniform formats and associated instructions for these
disclosures.
The current ITS on Pillar III disclosures on Environmental, Social and
Governance (ESG) risks, which is applicable to large and listed institutions,
was adopted by the European Commission in November 2022, published in
the Official Journal of the EU in December 2022 with a first reporting date
in 2023 (reference date: 31 December 2022). The ESG Pillar 3 requires
credit institutions such as ING to disclose the following information:
§Climate risks: how climate change may exacerbate other risks within
banks' balance sheets.
§Mitigating actions: what mitigating actions banks have in place to
address those risks, including financing activities that reduce carbon
emissions.
§Green Asset ratio and Banking Book Taxonomy Alignment ratio: to
understand how banks are financing activities that will meet the
publicly agreed Paris agreement objectives of climate change
mitigation and adaptation based on the EU taxonomy of green
activities.
The EBA ESG Pillar 3 requirements features (i) a set of 10 quantitative
templates that request banks to disclose climate-related risks and actions
to mitigate them, together with exposure to assets that support the
climate change mitigation and adaptation and (ii) qualitative information
on their ESG strategies, governance and risk management arrangements
with regard to ESG risk.
As the CRR III extends the scope of application to all institutions, including
large subsidiaries on an individual, or where applicable on a sub-
consolidated basis, the EBA launched a consultation on 22 May 2025
proposing amendments to the current ITS as mandated by the CRR III in
order to lay down proportionate requirements for new in-scope entities, as
well as modifying certain requirements for already in-scope entities.
Proposed amendments include, amongst others, reduced templates and
frequency for newly in-scope entities, certain modifications and
simplifications on current templates, allowing annual reporting for certain
templates subject to materiality assessment and the full alignment with
the EU Taxonomy Regulation. In addition, amendments include
transitional provisions that suspend disclosures of certain templates until
31 December 2026 and defer disclosures by newly in-scope entities to the
same date. EBA has published a no-action letter advising supervisors not
to enforce these suspended requirements to provide regulatory certainty
during the transition.
Sustainable Finance Disclosure Regulation
The Sustainable Finance Disclosure Regulation (SFDR) is a European
regulation intended to improve financial sector transparency for certain
sustainable investment products, via website and pre-contractual
disclosures. It also aims to prevent greenwashing and to increase
transparency around sustainability claims made by financial sector
participants. The SFDR imposes sustainability disclosure requirements on
certain financial actors who are offering certain type of financial products
or investment advice in the EU covering a broad range of environmental,
social and governance (ESG) metrics at both entity- and product-level.
Subsidiaries of ING Groep N.V. in the European Union are, or may be,
subject to the SFDR through certain products or services they provide. The
SFDR came into effect on 10 March 2021, with certain disclosure
requirements being in effect at a later stage.
In 2025, the European Commission launched a review of the SFDR aimed at
simplifying the framework and improving legal clarity. The initiative seeks
to reduce complexity, address overlaps with other EU sustainable finance
regulations, and introduce clearer product categories to enhance
comparability and mitigate greenwashing risks. A legislative proposal for
these revisions is published in November 2025, which will be followed by
the standard EU legislative process.
California Climate Disclosure Bills
California has enacted climate disclosure laws (SB 253 & SB 261) which
require companies that has business activities in California and meet
certain revenue thresholds to provide; (1) annual greenhouse gas (GHG)
emissions reporting in accordance with the GHG Protocol in 2026 for fiscal
year 2025; and (2) biennial climate-related financial risk reporting in line
with the recommendations of the Task Force on Climate-Related
Disclosures (TCFD) or with another framework that is consistent with the
recommendations by the beginning of 2026. There are phased in
requirements in relation to GHG emissions reporting where scope 3
emissions are only to be disclosed in 2027. In addition, scope 1 and scope
2 emissions are subject to limited assurance in 2026 and to reasonable
assurance in 2030; whereas scope 3 emissions are subject to limited
assurance only in 2030. Authorities issued further guidance in relation to
implementation of disclosure laws during the second half of 2025.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 57
Subsequently, on 18 November 2025, the U.S. Court of Appeals for the
Ninth Circuit temporarily suspended enforcement of SB 261 pending
appeal, while SB 253 remains in effect for the time being. This suspension
introduces a degree of regulatory uncertainty and ING will continue to
monitor legal developments closely.
Additional information regarding regulatory developments
For additional information regarding regulatory developments, see also
this Form 20-F 2025, under “Additional Information – ING Group Risk
Management - Environmental, social and governance Risk”.
For a description of our segments including a breakdown of total revenues
by category for the last three financial years, refer to "Item 5. Operating
and financial review and prospects - Segment reporting”.
C. Organisational structure
ING Groep N.V., a publicly listed company, is the parent of one main legal
entity: ING Bank N.V. (ING Bank). ING Bank is the parent company of
various Dutch and foreign banking and other subsidiaries.
Reference is made to Exhibit 8 “List of subsidiaries of ING Groep N.V.” for a
list of principal subsidiaries of ING Groep. N.V. For the majority of ING’s
principal subsidiaries, ING Groep N.V. has control because it either directly
or indirectly owns more than half of the voting power. For subsidiaries in
which the interest held is below 50%, control exists based on the
combination of ING’s financial interest and its rights from other contractual
arrangements which result in control over the operating and financial
policies of the entity.
D.Property, plants and equipment
ING predominantly leases the land and buildings used in the normal
course of its business. In addition, ING has invested in land and buildings.
Management believes that ING’s facilities are adequate for its present
needs in all material respects.
For information on property, plants and equipment, reference is made to
Note 9 'Property and equipment', for information on lease liabilities
reference is made to Note 16 'Other liabilities' and for information on
investment properties reference is made to Note 11 'Other assets' in the
consolidated financial statements.
ING Group Annual Report on Form 20-F Contents Part I Part II Part III Additional information Financial statements 58