COPY
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 13/POJK.03/2020
ON
AMENDMENT TO FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 38/POJK.03/2016 ON RISK MANAGEMENT IMPLEMENTATION IN INFORMATION TECHNOLOGY USAGE BY COMMERCIAL BANKS BY THE GRACE OF GOD ALMIGHTY THE COMMISSIONERS COUNCIL OF THE FINANCIAL SERVICES AUTHORITY, Considering:
a. that adequate utilization of information technology is necessary to enhance the effectiveness and efficiency of bank operations through the use of integrated electronic systems; b. that to support the use of integrated electronic systems, it is necessary to adjust the policy on risk management implementation in information technology usage by commercial banks;
c. that the use of integrated electronic systems as regulated in Financial Services Authority Regulation Number 38/POJK.03/2016 on Risk Management Implementation in Information Technology Usage by Commercial Banks needs to be adjusted to current developments and needs;
d. that based on the considerations referred to in letters a, b, and c, it is necessary to establish a Financial Services Authority Regulation on the Amendment to Financial Services Authority Regulation Number 38/POJK.03/2016 on Risk Management Implementation in Information Technology Usage by Commercial Banks; Recalling:
- Law Number 7 of 1992 on Banking (State Gazette of the Republic of Indonesia Year 1992 Number 31, Supplement to the State Gazette of the Republic of Indonesia Number 3472) as amended by Law Number 10 of 1998 on Amendment to Law Number 7 of 1992 on Banking (State Gazette of the Republic of Indonesia Year 1998 Number 182, Supplement to the State Gazette of the Republic of Indonesia Number 3790);
- Law Number 21 of 2008 on Sharia Banking (State Gazette of the Republic of Indonesia Year 2008 Number 94, Supplement to the State Gazette of the Republic of Indonesia Number 4867);
- Law Number 21 of 2011 on the Financial Services Authority (State Gazette of the Republic of Indonesia Year 2011 Number 111, Supplement to the State Gazette of the Republic of Indonesia Number 5253);
- Financial Services Authority Regulation Number 38/POJK.03/2016 on Risk Management Implementation in Information Technology Usage by Commercial Banks (State Gazette of the Republic of Indonesia Year 2016 Number 267, Supplement to the State Gazette of the Republic of Indonesia Number 5963);
DECIDES:
Establish: FINANCIAL SERVICES AUTHORITY REGULATION ON AMENDMENT TO FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 38/POJK.03/2016 ON RISK MANAGEMENT IMPLEMENTATION IN INFORMATION TECHNOLOGY USAGE BY COMMERCIAL BANKS.
Article I
Several provisions in Financial Services Authority Regulation Number 38/POJK.03/2016 on Risk Management Implementation in Information Technology Usage by Commercial Banks (State Gazette of the Republic of Indonesia Year 2016 Number 267 and Supplement to the State Gazette of the Republic of Indonesia Number 5963) are amended as follows:
- Article 21 provisions are amended to read as follows:
Article 21
(1) Banks must locate Electronic Systems in Data Centers and Disaster Recovery Centers within the territory of Indonesia.
(2) Banks may only locate Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia provided they obtain approval from the Financial Services Authority. (3) Electronic Systems that may be located in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in paragraph (2):
a. Electronic Systems used to support integrated analysis in order to fulfill regulations issued by the home country authority of the Bank that are global in nature, including cross-border; b. Electronic Systems used for integrated risk management with the Bank's headquarters or parent company/main entity office outside the territory of Indonesia;
c. Electronic Systems used for integrated implementation of anti-money laundering and counter-terrorist financing with the Bank's headquarters or parent company outside the territory of Indonesia;
d. Electronic Systems used for global customer service, which requires integration with the Bank Group's Electronic Systems outside the territory of Indonesia; e. Electronic Systems used for communication management between the Bank's headquarters and branches, or between subsidiaries and parent companies; and/or f. Electronic Systems used for the Bank's internal management. (4) Financial Services Authority approval as referred to in paragraph (2) may be granted with the condition that the Bank:
a. meets the requirements as referred to in Article 20 paragraph (3), paragraph (4), and paragraph (5); b. submits the results of country risk analysis;
c. ensures that the operation of Electronic Systems outside the territory of Indonesia does not reduce the effectiveness of Financial Services Authority supervision, proven by a letter of statement;
d. ensures that information regarding bank secrets is only disclosed in accordance with Indonesian statutory regulations, proven by a cooperation agreement between the Bank and the Information Technology service provider; e. ensures that written agreements with Information Technology service providers contain jurisdiction clauses; f. submits a letter of statement of non-objection from the supervisory authority of the Information Technology service provider outside the territory of Indonesia that the Financial Services Authority may conduct examinations of the Information Technology service provider; g. submits a letter of statement that the Bank periodically submits the results of assessments conducted by the Bank's offices outside the territory of Indonesia regarding the implementation of risk management on the Information Technology service provider; h. ensures that the benefits of the planned location of Electronic Systems outside the territory of Indonesia for the Bank are greater than the burdens borne by the Bank; and
i. submits the Bank's plan to enhance the Bank's human resource capabilities, both regarding Information Technology operations and business transactions or products offered.
(5) Banks must ensure that data used in Electronic Systems located in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia is not used for purposes other than those referred to in paragraph (3). (6) In the event that, based on the Financial Services Authority's assessment, the location of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia:
a. does not match the planned location of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia submitted to the Financial Services Authority; b. has the potential to reduce the effectiveness of Financial Services Authority supervision;
c. has the potential to negatively impact the Bank's performance; and/or
d. does not comply with statutory regulations, the Financial Services Authority has the authority to request the Bank to locate Electronic Systems in Data Centers and/or Disaster Recovery Centers within the territory of Indonesia. (7) Banks that do not implement the provisions as referred to in paragraph (5) are subject to administrative sanctions in the form of written warnings. (8) In the event that Banks do not comply with the provisions after being subject to administrative sanctions as referred to in paragraph (7), Banks may be subject to administrative sanctions in the form of:
a. reduction of health level, namely the reduction of the governance factor rating in the Bank's health assessment; b. prohibition on issuing products or conducting new activities;
c. suspension of certain business activities; and/or
d. prohibition from acting as the principal party of a financial service institution in accordance with Financial Services Authority Regulations regarding the re-evaluation of principal parties of financial service institutions.
- Between Article 42 and Article 43, 1 (one) Article is inserted, namely Article 42A, so that it reads as follows:
Article 42A
(1) Banks must implement the action plan submitted to the Financial Services Authority as referred to in Article 41 paragraph (2).
(2) Banks that do not implement the action plan as referred to in paragraph (1) are declared to have violated obligations as referred to in Article 21 paragraph (1).
- Between Article 43 and Article 44, 1 (one) Article is inserted, namely Article 43A, so that it reads as follows:
Article 43A
At the time this Financial Services Authority Regulation takes effect, the Bank Indonesia Circular Letter Number 9/30/DPNP dated December 12, 2007 on Risk Management Implementation in Information Technology Usage by Commercial Banks is repealed and declared invalid.
Article II
This Financial Services Authority Regulation takes effect on the date of enactment.
This copy is consistent with the original
Deputy Director of Legal Consultancy and
Banking Regulation Harmonization 1
Legal Directorate 1
Legal Department signed
Wiwit Puspasari
To be known by everyone, ordering the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on March 24, 2020
CHAIRMAN OF THE COMMISSIONERS COUNCIL
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
Enacted in Jakarta on March 31, 2020
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2020 NUMBER 88
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
REPUBLIC OF INDONESIA
NUMBER 13/POJK.03/2020
ON
AMENDMENT TO FINANCIAL SERVICES AUTHORITY REGULATION NUMBER 38/POJK.03/2016 ON RISK MANAGEMENT IMPLEMENTATION IN INFORMATION TECHNOLOGY USAGE BY COMMERCIAL BANKS
I. GENERAL
To enhance the effectiveness and efficiency of Bank operations and provide better banking services to customers, adequate utilization of information technology is required. This can be achieved through the use of Electronic Systems integrated with the Bank Group, including those located outside the territory of Indonesia. To support the use of integrated Electronic Systems, it is necessary to adjust provisions with greater emphasis on the effectiveness and efficiency of Bank operations and strengthening supervision aspects regarding data usage in Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia. In light of these matters, it is necessary to adjust Financial Services Authority Regulation Number 38/POJK.03/2016 on Risk Management Implementation in Information Technology Usage by Commercial Banks.
II. ARTICLE BY ARTICLE
Article I
Number 1
Article 21
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Letter a
Regulations issued by the home regulatory authority of the Bank (home regulatory) for branches are consistent with the location of the Bank's headquarters outside the territory of Indonesia, while for subsidiaries, it is consistent with the location of the parent company/main entity office, namely banks outside the territory of Indonesia. Letter b Sufficiently clear. Letter c Sufficiently clear. Letter d Global customer service refers to front-end electronic systems used by the Bank or by customers to obtain Bank services provided globally to all customers, both within Indonesia and outside the territory of Indonesia, for example, a global cash management system. Meanwhile, Electronic Systems used to process reports to authorities and back-end systems that finally process individual customer data, accounts, and/or transactions, must remain located within the territory of Indonesia. Back-end systems include, among others, core banking systems used to process customer data, current accounts, savings, time deposits, and loans or financing; as well as other back-end systems such as those used to process credit cards, Sharia cards, treasury, trade financing, and general ledgers. Letter e Sufficiently clear. Letter f Electronic Systems used for internal management are systems used by the Bank for internal purposes, not related to customer service and/or Bank operations. Electronic Systems used for internal management include, among others:
- personnel systems;
- remuneration systems; and/or
- internal audit systems.
Paragraph (4)
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
The phrase "does not reduce the effectiveness of Financial Services Authority supervision" means not causing difficulties for the Financial Services Authority in obtaining necessary data and information, such as having access to Databases and possessing the Database structure of each application used. Letter d Indonesian statutory regulations include regulations regarding requirements and procedures for issuing written orders or permits to open bank secrets. Letter e Sufficiently clear. Letter f Letters of statement are only submitted for Information Technology service providers that have supervisory authority. Letter g Bank offices outside the territory of Indonesia:
- for branches of banks located outside the territory of Indonesia, namely headquarters or other offices; or
- for Banks owned by foreign financial institutions, namely the parent bank office.
Letters of statement are also submitted if the Bank has bank offices in the same region as the location of the Information Technology service provider.
Letter h
Expected benefits include improved service quality for customers and the implementation of anti-money laundering and counter-terrorist financing programs.
Letter i
Sufficiently clear.
Paragraph (5)
Sufficiently clear.
Paragraph (6)
Sufficiently clear.
Paragraph (7)
Sufficiently clear.
Paragraph (8)
Sufficiently clear.
Number 2
Article 42A
Sufficiently clear.
Article 43A
Sufficiently clear.
Article II
Sufficiently clear.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 6486