2024-01-25 | Resolução BCB 368Added · Updated
BCB Resolution No. 368 amends Resolutions BCB Nos. 28, 65, 85, 93, 155, and 260 to extend their scopes of application to include securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized by the Central Bank of Brazil. The amendments require these entities to establish organizational components for ombudsmen, implement compliance policies, and adopt cybersecurity policies, including specific requirements for incident response, data protection, and the designation of responsible directors. These obligations apply to the newly included financial institutions alongside existing payment institutions, consortium administrators, and other regulated entities.
BCB published 18 documents in the last 30 days — get each new one by email the day it lands.
BCB RESOLUTION NO. 368, OF JANUARY 25, 2024
Amends Resolutions BCB Nos. 28, of October 23, 2020; 65, of January 26, 2021; 85, of April 8, 2021; 93, of May 6, 2021; 155, of October 14, 2021; and 260, of November 22, 2022, to include in their scope of application securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized to operate by the Central Bank of Brazil.
The Collegiate Board of the Central Bank of Brazil, in a session held on January 23, 2024, based on art. 9º-A, items I and II, of Law No. 4.728, of July 14, 1965, 6º and 7º, item III, of Law No. 11.795, of October 8, 2008, 9º, items II and IX, item "b", and 15 of Law No. 12.865, of October 9, 2013,
RESOLVES:
Art. 1º The summary of Resolution BCB No. 28, of October 23, 2020, shall be effective with the following alteration:
"Provides for the constitution and operation of an organizational component of an ombudsman by payment institutions, consortium administrators, securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
Art. 2º Resolution BCB No. 28, of 2020, shall be effective with the following alterations:
"Art. 2º The organizational component of an ombudsman must be constituted by the following institutions:
I - payment institutions, securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized to operate by the Central Bank of Brazil that have natural person clients, including individual entrepreneurs, or legal entities classified as micro-enterprises and small-sized enterprises, in accordance with Complementary Law No. 123, of December 14, 2006; and
................................................................................................................"
(NR)
"Art. 3º For the purposes of this Resolution, a client is also considered:
................................................................................................................"
(NR)
"Art. 4º
............................................................................................................
.........................................................................................................................
II - to act as a communication channel between the institution mentioned in art. 2º and its clients, including in conflict mediation.
................................................................................................................"
(NR)
"Art. 5º
............................................................................................................
I - in the case of the institution mentioned in item I of the caput of art. 2º, with the nature and complexity of the products, services, activities, processes, and systems of each institution; and
................................................................................................................"
(NR)
"Art. 6º The sharing of an ombudsman by the institutions mentioned in art. 2º is admitted, observing the following situations and rules:
.........................................................................................................................
II - the institution not framed in the provision of item I may share the constituted ombudsman:
.........................................................................................................................
§ 2º The provision of item II, item "b", of the caput only applies to a class association that has an effectively implemented code of ethics or self-regulation, to which the institution has adhered." (NR)
"Art. 8º The institutions mentioned in art. 2º must:
................................................................................................................"
(NR)
"Art. 9º
............................................................................................................
.........................................................................................................................
§ 2º The statutory or contractual alterations required by this Resolution relative to the institutions mentioned in art. 2º that opt for the faculty provided in art. 6º, item I, may be promoted only by the institution that constitutes the ombudsman.
§ 3º The institution that does not constitute its own ombudsman as a result of the faculty provided in art. 6º, item II, must ratify the decision at the first general assembly or at the first board of directors meeting held after such decision." (NR)
"Art. 10. The institutions mentioned in art. 2º must designate, before the Central Bank of Brazil, the names of the ombudsman and the director or administrator responsible for the ombudsman, observing the following conditions:
I - the director or administrator responsible for the ombudsman may perform other functions, including that of ombudsman, except that of director of administration of third-party resources;
II - in the case of payment institutions and consortium administrators, the ombudsman may not perform another function, except that of director or administrator responsible for the ombudsman;
III - in situations where the ombudsman performs another activity in the institution, this activity may not constitute a conflict of interest or of attributions; and
IV - in the event that the designation of director or administrator responsible for the ombudsman and of ombudsman in payment institutions and consortium administrators falls on the same person, this person may not perform another function." (NR)
"Art. 12. For compliance with the provision in the caput of art. 10, in the hypotheses provided in art. 6º, item II, the institutions mentioned in art. 2º must:
................................................................................................................"
(NR)
"Art. 14. The institutions mentioned in art. 2º must disseminate semi-annually, on their respective electronic sites on the internet, information relative to the activities developed by the ombudsman." (NR)
"Art. 16. The institutions mentioned in art. 2º must adopt measures so that the members of the ombudsman who perform the activities mentioned in art. 7º are considered apt in a certification exam organized by an entity of recognized technical capacity.
.........................................................................................................................
§ 3º The institutions mentioned in art. 2º must ensure the permanent training of the members of their respective ombudsmen regarding the themes mentioned in § 1º.
................................................................................................................"
(NR)
"Art. 18.
...........................................................................................................
Sole Paragraph. The provision in the caput must be observed, including, by the institution mentioned in art. 2º that does not constitute its own ombudsman component as a result of the faculty provided in art. 6º." (NR)
Art. 3º The summary of Resolution BCB No. 65, of January 26, 2021, shall be effective with the following alteration:
"Provides for the compliance policy of consortium administrators, payment institutions, securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
Art. 4º Resolution BCB No. 65, of 2021, shall be effective with the following alterations:
"Art. 1º This Resolution regulates the compliance policy applicable to the following institutions authorized to operate by the Central Bank of Brazil:
I - consortium administrators;
II - payment institutions;
III - securities brokerage companies;
IV - securities distribution companies; and
V - foreign exchange brokerage companies." (NR)
"Art. 2º The institutions mentioned in art. 1º must implement and maintain a compliance policy compatible with the nature, size, complexity, structure, risk profile, and business model, in order to ensure the effective management of their compliance risk.
§ 1º For the purposes of this Resolution, compliance risk is considered the possibility of the institution suffering legal or administrative sanctions, financial losses, reputational damage, and other damages, resulting from non-compliance or failures in observing the legal framework, sub-legal regulation, recommendations of regulatory bodies, and applicable self-regulation codes.
§ 2º The compliance risk must be managed by securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies, in an integrated manner with the other risks incurred by the institution, in accordance with specific regulation." (NR)
"Art. 7º
............................................................................................................
I - test and evaluate the adherence of the institution mentioned in art. 1º to the legal framework, sub-legal regulation, recommendations of supervisory bodies, and, when applicable, to codes of ethics, conduct, and other regulations that they are obliged to observe;
.........................................................................................................................
V - prepare a report, with a minimum annual periodicity, containing the summary of the results of activities related to the compliance function, its main conclusions, recommendations, and measures taken by the administration of the institution mentioned in art. 1º; and
.........................................................................................................................
Sole Paragraph. The institutions mentioned in art. 1º may hire specialists for the execution of activities related to the compliance policy, maintaining integral the attributions and responsibilities of the board of directors." (NR)
"Art. 9º
............................................................................................................
I - ......................................................................................................................
.........................................................................................................................
d) the dissemination of integrity and ethical conduct standards as part of the institution's culture;
................................................................................................................"
(NR)
"Art. 10. For the institutions mentioned in art. 1º that do not have a board of directors, the attributions and responsibilities provided in this Resolution must be imputed to their board of directors or to their administrators." (NR)
"Art. 11. The institutions mentioned in art. 1º must keep at the disposal of the Central Bank of Brazil:
................................................................................................................"
(NR)
Art. 5º The summary of Resolution BCB No. 85, of April 8, 2021, shall be effective with the following alteration:
"Provides for the cybersecurity policy and on the requirements for the contracting of data processing and storage services and cloud computing to be observed by payment institutions, securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
Art. 6º Resolution BCB No. 85, of 2021, shall be effective with the following alterations:
"Art. 1º This Resolution provides for the cybersecurity policy and on the requirements for the contracting of data processing and storage services and cloud computing to be observed by payment institutions, securities brokerage companies, securities distribution companies, and foreign exchange brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
"Art. 2º The institutions mentioned in art. 1º must implement and maintain a cybersecurity policy formulated based on principles and guidelines that seek to ensure the confidentiality, integrity, and availability of data and information systems used.
.........................................................................................................................
§ 2º Institutions that are part of a prudential conglomerate may adopt a single cybersecurity policy for the prudential conglomerate, in accordance with current regulation, provided it is compatible with the provision in this Chapter.
§ 3º Institutions that do not constitute their own cybersecurity policy as a result of the provision in § 2º must formalize the option for this faculty in a meeting of the board of directors or, in its absence, of the institution's board of directors." (NR)
"Art. 3º ............................................................................................................
I – the cybersecurity objectives of the institution;
II – the procedures and controls adopted to reduce the institution's vulnerability to incidents and to meet the other cybersecurity objectives;
.........................................................................................................................
IV – the recording, analysis of cause and impact, as well as the control of the effects of incidents relevant to the institution's activities;
V - ....................................................................................................................
a) the preparation of incident scenarios considered in business continuity tests;
b) the definition of procedures and controls aimed at the prevention and treatment of incidents to be adopted by third-party service providers that handle sensitive data or information or that are relevant for the conduct of the institution's operational activities;
.........................................................................................................................
VI – the mechanisms for disseminating the cybersecurity culture in the institution, including:
.........................................................................................................................
b) the provision of information to clients and end-users regarding precautions in the use of products and services offered; and
.........................................................................................................................
VII – the initiatives for sharing information on relevant incidents, mentioned in item IV, with the institutions mentioned in art. 1º and with the other institutions authorized to operate by the Central Bank of Brazil.
§ 1º In defining the cybersecurity objectives referred to in item I of the caput, the institution's capacity to prevent, detect, and reduce vulnerability to incidents related to the cyber environment must be contemplated.
.........................................................................................................................
§ 3º The procedures and controls cited in item II of the caput must be applied, including, in the development of secure information systems and in the adoption of new technologies employed in the institution's activities.
.........................................................................................................................
§ 5º The guidelines referred to in item "b" of item V of the caput must contemplate procedures and controls at levels of complexity, scope, and precision compatible with those used by the institution itself." (NR)
"Art. 4º The cybersecurity policy must be disseminated to the employees of the institution mentioned in art. 1º and to third-party service providers, through clear, accessible language, and at a level of detail compatible with the functions performed and with the sensitivity of the information." (NR)
"Art. 5º The institutions mentioned in art. 1º must disseminate to the public a summary containing the general lines of the cybersecurity policy." (NR)
"Art. 6º The institutions mentioned in art. 1º must establish an action and incident response plan aimed at the implementation of the cybersecurity policy.
................................................................................................................"
(NR)
"Art. 7º The institutions mentioned in art. 1º must designate a director responsible for the cybersecurity policy and for the execution of the action and incident response plan.
................................................................................................................"
(NR)
"Art. 8º The institutions mentioned in art. 1º must prepare an annual report on the implementation of the action and incident response plan, mentioned in art. 6º, with a base date of December 31.
§ 1º
.................................................................................................................
.........................................................................................................................
IV – the results of business continuity tests, considering scenarios of unavailability caused by incidents.
§ 2º The report mentioned in the caput must be:
I - submitted to the risk committee, when it exists; and
II - presented to the board of directors or, in its absence, to the institution's board of directors by March 31 of the year following the base date." (NR)
"Art. 9º The cybersecurity policy referred to in art. 2º and the action and incident response plan mentioned in art. 6º must be approved by the board of directors or, in its absence, by the board of directors of the institution mentioned in art. 1º." (NR)
"Art. 11. The institutions mentioned in art. 1º must ensure that their policies, strategies, and structures for risk management provided in current regulation, specifically regarding decision criteria concerning the outsourcing of services, contemplate the contracting of relevant data processing and storage services and cloud computing, in the country or abroad." (NR)
"Art. 12. The institutions mentioned in art. 1º, prior to the contracting of relevant data processing and storage services and cloud computing, must adopt procedures that contemplate:
.........................................................................................................................
II - .....................................................................................................................
.........................................................................................................................
g) the identification and segregation of client and end-user data through physical or logical controls; and
h) the quality of access controls aimed at protecting the data and information of the institution's clients and end-users.
................................................................................................................"
(NR)
"Art. 13. For the purposes of the provision in this Resolution, cloud computing services encompass the availability to the contracting institution, on demand and in a virtual manner, of at least one of the following services:
................................................................................................................"
(NR)
"Art. 14. The institution contracting the services mentioned in art. 12 is responsible for the reliability, integrity, availability, security, and confidentiality regarding the contracted services, as well as for compliance with the legislation and current regulation." (NR)
"Art. 15. The contracting of relevant data processing, storage, and cloud computing services must be communicated by the institutions mentioned in art. 1º to the Central Bank of Brazil.
................................................................................................................"
(NR)
"Art. 16.
...........................................................................................................
.........................................................................................................................
II - the contracting institution must ensure that the provision of the services referred to in the caput does not cause prejudice to its regular functioning nor hinder the action of the Central Bank of Brazil;
III - the contracting institution must define, prior to contracting, the countries and regions in each country where the services may be provided and the data may be stored, processed, and managed; and
IV - the contracting institution must provide alternatives for business continuity, in the event of impossibility of maintaining or extinguishing the service provision contract.
§ 1º In the event of the absence of an agreement in the terms of item I of the caput, the contracting institution must request authorization from the Central Bank of Brazil for:
.........................................................................................................................
§ 2º For compliance with items II and III of the caput, institutions must ensure that the legislation and regulation in the countries and regions in each country where the services may be provided do not restrict or impede access by the contracting institutions and the Central Bank of Brazil to the data and information.
................................................................................................................"
(NR)
"Art. 17.
...........................................................................................................
.........................................................................................................................
III - the maintenance, while the contract is in effect, of the segregation of data and access controls for the protection of client and end-user information;
IV -
...................................................................................................................
a) transfer of the data cited in item I to the new service provider or to the contracting institution; and
.........................................................................................................................
V - the access of the contracting institution to:
.........................................................................................................................
---"
VI - the obligation of the contracted company to notify the contracting institution regarding the subcontracting of services relevant to the institution;
.........................................................................................................................
VIII - the adoption of measures by the contracting institution, as a result of determination by the Central Bank of Brazil; and
IX - the obligation of the contracted company to keep the contracting institution permanently informed about any limitations that may affect the provision of services or compliance with legislation and regulations in force.
Sole paragraph. The contracts mentioned in the caput must provide, in the event of the declaration of a resolution regime for the contracting institution by the Central Bank of Brazil:
.........................................................................................................................
II - .....................................................................................................................
.........................................................................................................................
b) the prior notification must also occur in the situation where the interruption is motivated by the default of the contracting institution." (NR)
"Art. 19. The institutions mentioned in art. 1 must ensure that their policies provided for in the risk management structure, in accordance with regulations in force, provide, with regard to business continuity, on:
.........................................................................................................................
III - the incident scenarios considered in the business continuity tests referred to in art. 3, item V, letter "a"." (NR)
"Art. 20. The procedures adopted by the institutions mentioned in art. 1 for risk management provided for in regulations in force must specify, with regard to business continuity:
.........................................................................................................................
III - the timely communication to the Central Bank of Brazil of relevant incident occurrences and interruptions of relevant services, cited in item I, which constitute a crisis situation for the institution mentioned in art. 1, as well as the measures taken to resume their activities.
Sole paragraph. The institutions mentioned in art. 1 must establish and document the criteria that constitute the crisis situation referred to in item III of the caput." (NR)
"Art. 21. The institutions mentioned in art. 1 must institute monitoring and control mechanisms with a view to ensuring the implementation and effectiveness of the cybersecurity policy, the action plan and incident response, and the requirements for contracting data processing and storage services and cloud computing, including:
..................................................................................................................."
(NR)
"Art. 22. Without prejudice to the duty of confidentiality and free competition, the institutions mentioned in art. 1 must develop initiatives for sharing information on the relevant incidents referred to in art. 3, item IV.
..................................................................................................................."
(NR)
Art. 7 The summary of BCB Resolution No. 93, of May 6, 2021, shall be amended as follows:
"Provides for the internal audit activity in consortium administrators, payment institutions, securities brokerage companies, securities distribution companies, and currency brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
Art. 8 BCB Resolution No. 93, of 2021, shall be amended as follows:
"Art. 1 This Resolution regulates the internal audit activity in the following institutions authorized to operate by the Central Bank of Brazil:
I - consortium administrators;
II - payment institutions;
III - securities brokerage companies;
IV - securities distribution companies; and
V - currency brokerage companies." (NR)
"Art. 2 The institutions mentioned in art. 1 must implement and maintain an internal audit activity compatible with the nature, size, complexity, structure, risk profile, and business model of the institution.
..................................................................................................................."
(NR)
"Art. 3 The internal audit activity must be carried out by a specific unit of the institution mentioned in art. 1 or of another institution authorized to operate by the Central Bank of Brazil that is part of the same prudential conglomerate, directly subordinate to the board of directors.
§ 1º .................................................................................................................
I - by an independent auditor duly qualified, in accordance with regulations in force, to provide independent audit services for institutions authorized to operate by the Central Bank of Brazil, provided that this auditor is not responsible for the audit of the financial statements of the institution mentioned in art. 1 or for any other activity with a potential conflict of interest;
II - by the audit of the class entity to which the institution mentioned in art. 1 is affiliated; or
III - by the audit of a class entity of other institutions authorized to operate by the Central Bank of Brazil, through an agreement, previously approved by this authority, entered into between the entity to which the institution mentioned in art. 1 is affiliated and the entity providing the service.
§ 2º The provisions of § 1 do not apply to the institutions mentioned in art. 1 that, in accordance with regulations in force, are required to constitute an audit committee." (NR)
"Art. 7 The institutions mentioned in art. 1 must guarantee to the members of the audit team, in the performance of their activities:
..................................................................................................................."
(NR)
"Art. 10. The scope of the internal audit activity must consider all functions of the institution mentioned in art. 1, including outsourced ones.
..................................................................................................................."
(NR)
"Art. 13. The institutions mentioned in art. 1 must prepare and maintain a specific regulation for the internal audit activity, approved by the board of directors and the audit committee, when constituted." (NR)
"Art. 17. Those responsible for the internal audit activity of the institutions mentioned in art. 1 must prepare the following documents:
..................................................................................................................."
(NR)
"Art. 19. The board of directors is the body responsible for ensuring compliance, by the institution mentioned in art. 1, with the norms and procedures applicable to the internal audit activity." (NR)
"Art. 21. For the institutions mentioned in art. 1 that do not have a board of directors, the duties, competencies, and requirements provided for in this Resolution must be attributed to their executive board or administrators." (NR)
"Art. 23. The institutions mentioned in art. 1 must keep at the disposal of the Central Bank of Brazil:
..................................................................................................................."
(NR)
Art. 9 The summary of BCB Resolution No. 155, of October 14, 2021, shall be amended as follows:
"Provides for principles and procedures to be adopted in the relationship with customers and users of products and services by consortium administrators, payment institutions, securities brokerage companies, securities distribution companies, and currency brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
Art. 10 BCB Resolution No. 155, of 2021, shall be amended as follows:
"Art. 1 This Resolution provides for principles and procedures to be adopted in the relationship with customers and users of products and services by the following institutions authorized to operate by the Central Bank of Brazil:
I - consortium administrators;
II - payment institutions;
III - securities brokerage companies;
IV - securities distribution companies; and
V - currency brokerage companies.
..................................................................................................................."
(NR)
"Art. 2 The institutions mentioned in art. 1, in their relationship with customers and users of products and services, must conduct their activities with observance of principles of ethics, responsibility, transparency, and diligence, promoting the convergence of interests and the consolidation of an institutional image of credibility, security, and competence." (NR)
"Art. 4 The institutions mentioned in art. 1, in the contracting of operations and the provision of services, must ensure:
.........................................................................................................................
V - identification of the end-users beneficiaries of payments or transfers in statements and account extracts of registration and payment accounts, including in situations where the payment service involves institutions participating in different payment arrangements; and
..................................................................................................................."
(NR)
"Art. 6 The institutions mentioned in art. 1 must prepare and implement an institutional policy for relationship with customers and users that consolidates guidelines, strategic objectives, and organizational values, in order to guide the conduct of their activities in accordance with the provisions of art. 2.
.........................................................................................................................
§ 3º The institutions mentioned in art. 1 that do not establish their own policy as a result of the option provided for in § 2 must formalize the decision in a meeting of the board of directors or executive board.
..................................................................................................................."
(NR)
"Art. 7 The institutions mentioned in art. 1 must ensure the consistency of routines and operational procedures related to the relationship with customers and users, as well as their adequacy to the institutional relationship policy referred to in art. 6, including with regard to the following aspects:
.........................................................................................................................
§ 1º With respect to the provisions of items II and III of the caput, and in observance of the provisions of art. 4, item I, the institutions mentioned in art. 1 must establish the profile of the customers that make up the target audience for the products and services made available, considering their characteristics and complexity.
.........................................................................................................................
§ 3º For the purposes of the provisions of the caput, the institutions mentioned in art. 1 must, additionally:
..................................................................................................................."
(NR)
"Art. 8 With regard to the institutional policy for relationship with customers and users, the institutions mentioned in art. 1 must institute monitoring, control, and risk mitigation mechanisms with a view to ensuring:
..................................................................................................................."
(NR)
"Art. 9 The institutions mentioned in art. 1 must indicate to the Central Bank of Brazil a director responsible for compliance with the obligations provided for in this Resolution." (NR)
Art. 11 The summary of BCB Resolution No. 260, of November 22, 2022, shall be amended as follows:
"Provides for the internal control systems of consortium administrators, payment institutions, securities brokerage companies, securities distribution companies, and currency brokerage companies authorized to operate by the Central Bank of Brazil." (NR)
Art. 12 BCB Resolution No. 260, of 2022, shall be amended as follows:
"Art. 1 This Resolution provides for the internal control systems of the following institutions authorized to operate by the Central Bank of Brazil:
I - consortium administrators;
II - payment institutions;
III - securities brokerage companies;
IV - securities distribution companies; and
V - currency brokerage companies." (NR)
"Art. 2 The institutions mentioned in art. 1 must implement and maintain internal control systems compatible with their nature, size, complexity, structure, risk profile, and business model." (NR)
"Art. 4 ............................................................................................................
I - be continuous and effective, covering control activities for all levels of business and for all risks to which the institution is exposed;
II - integrate the routine activities of the relevant areas of the institution; and
..................................................................................................................."
(NR)
"Art. 5 ............................................................................................................
I - ......................................................................................................................
.........................................................................................................................
b) ..………...........................................................................................................
.........................................................................................................................
situations of non-compliance with the conduct standards defined by the institution mentioned in art. 1; and
violations of the policies of the institution mentioned in art. 1 or of legal and regulatory provisions;
.........................................................................................................................
II - .....................................................................................................................
a) means to identify and continuously assess internal and external factors that may adversely affect the achievement of the objectives of the institution mentioned in art. 1 and, when applicable, the economic group it is part of;
.........................................................................................................................
III - ….................................................................................................................
.........................................................................................................................
g) appropriate segregation of functions assigned to members of the institution mentioned in art. 1, in order to avoid situations of conflict of interest;
.........................................................................................................................
i) controls aimed at preventing the involvement of the institution mentioned in art. 1 in improper or illegal activities, especially those related to social, environmental, and climate risks;
.........................................................................................................................
IV - ….................................................................................................................
.........................................................................................................................
c) methodologies for recording and maintaining internal information of the institution mentioned in art. 1, such as financial, operational, and compliance data;
.........................................................................................................................
h) business recovery and contingency plans for situations of interruption of the provision of services by the institution mentioned in art. 1 due to events outside its control, providing for the use of remote physical facilities, including services provided by third parties; and
V - ....................................................................................................................
a) continuous monitoring of the effectiveness of internal control systems and the main risks associated with the activities of the institution mentioned in art. 1;
b) periodic assessments, including by internal audit, regarding the effectiveness of internal control systems and the main risks associated with the activities of the institution mentioned in art. 1;
c) ......................................................................................................................
..................................................................................................................."
(NR)
"Art. 6 ............................................................................................................
Sole paragraph.
..............................................................................................
I - be submitted to the board of directors or, if nonexistent, to the executive board, as well as to the internal and external audits of the institution mentioned in art. 1; and
..................................................................................................................."
(NR)
"Art. 8 ............................................................................................................
I - the executive board of the institution mentioned in art. 1 takes the necessary measures to identify, measure, monitor, and control risks according to the defined risk levels;
.........................................................................................................................
III - the executive board of the institution mentioned in art. 1 monitors the adequacy and effectiveness of the internal control systems; and
.........................................................................................................................
Sole paragraph. For the institutions mentioned in art. 1 that do not have a board of directors, the responsibilities provided for in the caput must be attributed to the executive board of the institution." (NR)
"Art. 9 The executive board of the institution mentioned in art. 1 is responsible for:
..................................................................................................................."
(NR)
"Art. 10. The institutions mentioned in art. 1 must designate to the Central Bank of Brazil a director responsible for compliance with the provisions of this Resolution.
Sole paragraph. The director mentioned in the caput may perform other functions in the institution, provided there is no conflict of interest." (NR)
"Art. 11.
...........................................................................................................
I - determine the adoption of additional controls in cases where inadequacy in the controls implemented by the institutions mentioned in art. 1 is found; and
II - impose more restrictive operational limits on the institutions mentioned in art. 1 that fail to observe the determination in item I within the established deadline." (NR)
Art. 13 The following are repealed:
I - the sole paragraph of art. 2 of BCB Resolution No. 65, of 2021; and
II - art. 24 of BCB Resolution No. 85, of 2021.
Art. 14 This Resolution enters into force on March 1, 2024.
Otávio Ribeiro Damaso
Director of Regulation
Read the rest free
This document amends: Resolution BCB No. 260 — Provides for the internal control systems of consortium administrators, payment institutions, securities brokerage firms, securities distribution firms and foreign exchange brokerage firms, Resolution BCB No. 155 — Sets out principles and procedures to be adopted in the relationship with customers and users of products and services by consortium administrators, payment institutions, securities broker societies, securities distributor societies, foreign‑exchange broker societies and virtual‑asset service providers authorized to operate by the Central Bank of Brazil, Resolution BCB No. 93 — Regulates internal audit activity in consortium administrators, payment institutions, securities broker-dealers, securities distributors, foreign exchange brokers, and virtual asset service providers authorized by the Central Bank of Brazil, Resolution BCB No. 85 — Cybersecurity Policy and Requirements for Data Processing, Storage, and Cloud Computing Services, Resolution BCB No. 65 — Regulates the compliance policy of consortium administrators, payment institutions, securities brokerage firms, securities distribution firms, foreign exchange brokerage firms, and virtual asset service providers, BCB Resolution No. 28 — Establishes the constitution and functioning of an ombudsman organizational component for payment institutions, consortium administrators, securities brokerage and distribution companies, foreign exchange brokerage companies, and virtual asset service providers authorized by the Central Bank of Brazil
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 18 documents in the last 30 days. We email you each new one the day it's published.