2017-04-12

Added · Updated

Central Bank of Jordan Internal Control and Supervision Regulations No. 25/2007

The Central Bank of Jordan issues Regulations No. 25/2007 to establish minimum internal control and supervision standards for banks. The document mandates specific responsibilities for the Board of Directors and Executive Management, requiring the establishment of independent internal audit and risk management functions. It further imposes detailed obligations regarding organizational structure, financial and accounting systems, information technology management, and physical security measures. Additionally, banks are required to submit specific reports and notifications to the Central Bank, including changes in executive management, debt write-offs, and shareholder information.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

In the Name of Allah, the Most Gracious, the Most Merciful

Central Bank of Jordan Ref: 10/1/766 Date: 4/5/1428 AH Corresponding to: 10/6/2007 AD

Internal Control and Supervision Regulations No. (25/2007) Issued by the Central Bank of Jordan pursuant to the provisions of Article (45/A) of the Central Bank Law and Article (99/B) of the Banks Law

The minimum controls necessary to ensure that the Bank's management exercises appropriate supervision over the Bank's operations are listed below:

First: The terms used in these Regulations have the meanings assigned to them below: 1- Executive Management: General Managers, their deputies and assistants, and administrative and banking consultants, and those in their rank in the Bank. 2- Quality of Information: Refers to the aggregate of factors that provide the following conditions: a- Effectiveness: The availability of information related to the administrative process and decision-making at the required and appropriate time, such that this information is correct, coherent (consistent), and usable. b- Efficiency: The management of information using various resources in the most optimal economic ways. c- Confidentiality: Concerns the protection of information from unauthorized access, publication, disclosure, and use. d- Integrity: Concerns the accuracy and completeness of information and its validity (Accurate, Complete, and Valid). e- Availability: The information is available when needed at the current time and at any future time. f- Reliability: The information is appropriate and reliable for use in the administrative process and decision-making. g- Compliance: The management of information aligns with prevailing laws, regulations, and instructions, as well as the Bank's strategies, policies, and procedures regarding them. 3- Information and associated technology resources: All resources related to the production process, including human elements, data, software, hardware, and equipment, as well as the time element.

Second: Responsibilities of the Board of Directors In addition to what is stipulated in relevant legislation, the Bank's Board of Directors must ensure the existence of appropriate and effective internal control and supervision systems, and continuously monitor them by following and adhering to the following controls as a minimum: 1- Understanding the main risks facing the Bank and adopting acceptable limits for these risks, and supervising the Executive Management to ensure the necessary measures are taken to identify, measure, control, and monitor these risks. 2- Adopting the Bank's organizational structure, forming committees, and delegating authorities and powers. 3- Adopting the Bank's strategies, policies, annual budget, and Code of Conduct, and reviewing them periodically. 4- Ensuring that the Executive Management achieves the effectiveness of internal control and supervision systems. 5- Informing the Board or its subordinate committees of reports from regulatory authorities and external and internal audit, following up on violations and observations contained therein, and ensuring that the Executive Management corrects them and takes necessary measures to prevent recurrence, in addition to any other reports related to compliance and risk management and any other related matters. 6- Exercising authorities that fall outside the Executive Management's powers. 7- Evaluating the performance of the Executive Management and its adherence to the Board's policies, its success in achieving planned results and objectives, and addressing deviations.

Third: Responsibilities of the Executive Management In addition to what is stipulated in relevant legislation, the Bank's Executive Management must adhere, as a minimum, to the following: 1- Preparing, developing, and implementing strategies and policies after their adoption by the Board of Directors. 2- Preparing and developing work procedures that ensure the identification, measurement, control, and monitoring of risks facing the Bank and the implementation of those procedures. 3- Preparing financial statements and final accounts. 4- Preparing an organizational structure as specified in Item (Fourth), and ensuring actual compliance with it after its adoption by the Board of Directors. 5- Preparing an annual budget, obtaining its approval from the Board of Directors, and submitting periodic performance reports to the Board of Directors showing deviations of actual performance from the estimated. 6- Establishing appropriate internal control and supervision policies and implementing them after their adoption by the Board of Directors. 7- Executing responsibilities according to delegated authorities. 8- Achieving the effectiveness of internal control and supervision systems, and submitting an annual report at least to the Board of Directors regarding the application and effectiveness of the systems. 9- Establishing procedures to assess capital adequacy and submitting periodic reports to the Board of Directors on this matter. 10- Providing external and internal regulatory bodies, such as regulatory authorities, internal audit, external audit, and any other relevant parties, with the required information and statements at the times specified by those bodies to enable them to perform their duties optimally. 11- Including in the annual report a statement regarding the Executive Management's responsibility to provide internal control and supervision systems that ensure the quality and transparency of information and published financial data. 12- Drafting the Bank's Code of Conduct, obtaining its approval from the Board of Directors, and disseminating it to all administrative levels in the Bank. 13- Developing the skills and professional behavior of Bank employees to align with the latest developments and technologies.

Fourth: Organizational Structure and Job Descriptions The Bank's management must prepare a detailed, clear, flexible, and applicable organizational structure and a comprehensive job description, which must include, as a minimum, the following: 1- All organizational units and activities for all functional levels, in addition to subordinate organizational structures for those units. 2- Committees emanating from the Board of Directors and other committees formed in the Bank. 3- A detailed work procedures manual for implementing and controlling operations. 4- A detailed description of tasks and responsibilities for each job, activity, and organizational unit, to be reviewed by all Bank employees according to their specialization. 5- Achieving dual control for at least each activity or process. 6- Separation and definition of duties to avoid conflicts of interest and reduce risks. 7- Administrative and operational separation of activities and procedures between approval, execution, and recording tasks. 8- Separation of risk management tasks from internal audit management. 9- Involvement of risk and compliance management in the planning and approval of any new products or procedures, with a consultative role for internal audit units. 10- Compliance with regulatory authority requirements and the Bank's internal policies. 11- Regular supervision confirming the application of the organizational structure and adherence to it, and following up on its development to achieve the Bank's objectives.

Fifth: Internal Audit Management The Bank must commit to establishing an independent internal audit management that reports directly to the Audit Committee (formed pursuant to the provisions of Article (32) of the Banks Law) (or its equivalent for branches of foreign banks), with periodic reports submitted to it. The duties of the audit management must include, as a minimum, the following: 1- Establishing an Internal Audit Charter, approved by the Board of Directors, which must include the duties, responsibilities, authorities, and work methodology of the audit management. 2- Establishing internal audit procedures consistent with best practices and international standards. 3- Preparing an annual audit plan approved by the Audit Committee, derived from the Bank's strategic plan, covering most of the Bank's activities and organizational units, including risk management, according to the risk level of those activities. 4- Preparing an annual report on the adequacy of internal control and supervision systems to mitigate risks facing the Bank and working to provide appropriate recommendations to correct weaknesses. 5- Staffing the internal audit management with employees having appropriate scientific qualifications and sufficient practical experience to audit all activities and processes, including having qualified personnel to assess information and associated technology risks. 6- Following up on violations and observations in reports from regulatory authorities and external auditors, ensuring they are addressed, and verifying the existence of appropriate controls by the Executive Management to prevent recurrence. 7- Ensuring the availability of procedures for receiving, processing, and retaining customer complaints and observations related to the accounting system, internal control and supervision, and audit processes, and submitting periodic reports on them. 8- Retaining audit reports and working papers for a period consistent with prevailing legislation in this regard, in an organized and secure manner, and making them available for review by regulatory authorities and external auditors.

Sixth: Risk Management The assessment and management of risks is the responsibility of every unit in the Bank according to its position and duties. The Bank must commit, as a minimum, to the following: 1- Establishing a risk management system compatible with the Bank's size and nature of operations, which must include, as a minimum, the following: a- The existence of risk policy/policies approved by the Board of Directors covering all Bank operations and setting clear measures and limits for each type of risk, and ensuring that all employees, according to their administrative level, are fully aware of them, with periodic review. These policies must include procedures ensuring the following: 1- Periodic definition of major and sudden changes in risks reflected in financial data, market developments, and the legal environment, etc., in addition to evaluating these changes and reporting to relevant units. 2- Ensuring the Bank hedges against potential losses (Risk Mitigation) through avoidance, transfer, reduction, and acceptance (AVOID, TRANSFER, REDUCTION, ACCEPTANCE) and disclosing them in financial statements. b- The existence of a specialized and independent administrative body responsible for analyzing and studying risks arising from Bank operations and developing necessary methodologies for managing and monitoring these risks. c- Monitoring compliance with risk control procedures and policies, as well as risk limits of all types. d- Procedures ensuring that high-quality information reaches decision-makers regarding any material breaches, and the necessary steps to address those breaches and follow up on the implementation of those procedures. e- Regular evaluation of risk procedures, policies, and limits in light of the severity of problems that have emerged, the Bank's strategy, and market developments. 2- Adopting means that help in risk management, including but not limited to: a- Self-assessment of risks and setting risk indicators. b- Preparing a historical database of losses, identifying sources of those losses, and categorizing them according to risk type. c- Availability of necessary equipment and suitable automated systems for risk management at the Bank. d- Use of quantitative means for risk control. 3- Ensuring, before commencing any new (product/process/system), that it is consistent with the overall strategic development policy, and that all resulting risks, including operational risks, have been identified, and that new control procedures and amendments have been implemented in proportion to the Bank's acceptable risk limits. 4- Forming an independent risk management committee emanating from the Board of Directors, which may include some senior Executive Management members, and which must have, as a minimum, the following duties: a- Reviewing the risk management strategy before its adoption by the Board of Directors and continuously evaluating its effectiveness to ensure alignment with changes. b- Ensuring the availability of risk management policies and framework, programs, and tools necessary for that, reviewing them at least annually to ensure effectiveness and amending them if necessary. c- Submitting periodic reports to the Board of Directors showing the extent to which existing risks align with adopted policies and acceptable risk levels defined therein, enabling the Board to make appropriate decisions. d- Supervising the development of the database necessary for risk management. e- Discussing risk management reports. f- Ensuring the existence of a business continuity plan and examining it periodically. 5- The necessity of using modern information systems for risk management that ensure the availability of high-quality information about the risks the Bank faces.

Seventh: Bank's Relationship with the External Auditor In addition to the provisions of the Banks Law and any other relevant legislation, the Bank must commit, as a minimum, to the following: 1- Signing an "Engagement letter" with the external auditor to audit the Bank's operations, covering all matters falling on their responsibility and consistent with international auditing standards requirements. The agreement must include the external auditor undertaking the following: a- Providing the Board of Directors with a detailed report including all weaknesses in accounting and internal control systems and any other matters with negative impact discovered during the audit process. b- Verifying the accuracy and integrity of data provided to them during the audit process. c- Providing the Central Bank with copies of any reports the external auditor submits to the Bank within the scope of the audit assignment for which they were appointed. 2- Obtaining prior approval from the Audit Committee before agreeing with the external auditor to provide any other services outside the scope of the audit assignment, in accordance with the prevailing Law on the Practice of Auditing Profession and instructions issued thereunder, with disclosure of these services.

Eighth: Financial and Accounting Systems Requirements The Bank must have, as a minimum, the following: 1- Financial and accounting systems that help show the Bank's true financial position and provide necessary information for decision-making, enabling the preparation of periodic and annual financial statements consistent with International Financial Reporting Standards (IFRS), or their equivalent for Islamic banks. 2- Sound and written financial, accounting, and documentary systems ensuring the recording of financial operations immediately upon occurrence. 3- Written procedures to ensure the regular and secure preservation of books and records for a period not less than that stipulated in prevailing legislation, in a manner that facilitates audit and inspection. 4- Periodic audit procedures, specifically on accounting entries, to ensure their proper recording. 5- A mechanism to verify the quality of information and financial data provided to regulatory authorities. 6- Written procedures for selecting suitable automated and accounting systems, in addition to sufficient qualified personnel to ensure the effectiveness of financial and accounting systems. 7- All necessary technical means and backups to ensure operational continuity. 8- Appropriate control systems covering all Bank systems to ensure that each Bank operation is conducted properly, such that: a- They are consistent with legislation and characterized by accuracy. b- They are implemented under the work manual of the concerned unit. c- They are implemented by the authorized person. d- They are documented and retained in appropriate records according to prevailing legislation.

Ninth: Information and Associated Technology Management Internal control and supervision systems must ensure the effectiveness and integrity of information and associated technology management at the Bank, including, as a minimum, the following matters: 1- Establishing a strategic plan concerning the management of information and associated technology resources, aligned with the Bank's strategic plan and approved by the Board of Directors. 2- Establishing policies and procedures emanating from the Bank's strategy capable of achieving its objectives, to be continuously reviewed by all concerned parties to ensure alignment with the Bank's strategy and plans. 3- The Executive Management must establish appropriate organizational structures necessary to achieve the Bank's objectives, ensuring alignment between IT resource management plans and Bank plans, including forming a senior steering committee for IT resource management and information security, among others. 4- The administrative organization for information and associated technology management must achieve high information quality, managed by persons with competence in knowledge and experience, in addition to a specialized professional cadre performing duties under a defined, documented, and Board-approved job description. Task separation must be used to maintain precautionary controls preventing any single person from executing a sensitive process completely. 5- Identifying owners of different systems based on information ownership and the associated banking process, especially sensitive systems, with clear responsibilities toward ownership to ensure information quality objectives are met. 6- Issuing necessary principles and standards, including the "Code of Conduct for Information Security and Protection," and continuously working to educate and raise awareness of Bank personnel within this framework. 7- Establishing appropriate administrative organization and mechanisms to identify, measure, control, and monitor information and associated technology risks within the framework of strategic planning and medium and short-term risk planning. 8- Establishing appropriate mechanisms to enable continuous monitoring and measurement of information and associated technology management performance to ensure the quality of services provided (whether by internal units or external parties) to various Bank units, and ensuring these services meet the required level to achieve the Bank's objectives efficiently and effectively. 9- Obtaining assessment reports (risk - controls) for information and associated technology from independent regulatory bodies such as internal audit, external audit, and the Central Bank, and committing to addressing weaknesses and taking feedback for improvement and development, including regulatory authority inspection reports on this matter. 10- Establishing appropriate controls to ensure, as a minimum, the following: a- The development/purchase of application software is done efficiently and effectively so that these programs meet the objectives and requirements of Bank units. b- The purchase and operation of IT infrastructure is done efficiently and effectively so that this infrastructure supports and meets the objectives and requirements of Bank units. c- Examination of software and infrastructure before operation to ensure their adequacy, reliability, and integrity, fulfilling their intended purpose which achieves the Bank's objectives. d- Integrity (validity) of software and infrastructure when any changes are made to them, such that change processes are approved by their owners based on documented formal approvals. e- Quality of services provided by external parties and the mechanism of their provision in terms of maintaining confidentiality, accuracy, availability, and integrity (validity), with these conditions controlled through documented formal agreements. f- Security conditions for different systems and related data in terms of protecting them from any unauthorized (unapproved) change. g- Processing problems and events affecting information and associated technology negatively by establishing mechanisms capable of detecting, recording, and making appropriate decisions to confront such events. h- Adequacy, accuracy, and validity of data entered, processed, and extracted from different programs and systems, and ensuring the continuous process of data updating, taking backups, checking their reliability, and storing them in a manner that reduces risks that may negatively affect them.

Tenth: Bank Security and Safety Requirements The Bank must commit to necessary security and safety requirements, including, as a minimum, the following: 1- Selecting the Bank's location and its organizational units in a suitable manner, so that buildings do not lack appropriate protection means or are in an area where adequate security means are difficult to provide. 2- Selecting vault/safe locations away from customer areas, using dual control for entering and opening vault locations, recording entry operations in organized registers for this purpose, fortifying walls, and selecting safes and doors in a manner difficult to tamper with or breach, and working to double fortification means for those sites whenever necessary. 3- Closing Bank branch doors securely, fortifying Bank building windows, and imposing security and protection systems for all Bank work locations. 4- Using alarm devices and cameras, linking the Bank's communication network with the police operations room network or early warning stations licensed by security agencies, imposing necessary guard duties after working hours in cases and locations requiring it, including ATMs, and retaining camera films for a suitable period not less than one year. 5- Using necessary protection means in entry and exit operations to and from various Bank locations. 6- Training all employees on security and protection measures adopted by the Bank, including the emergency plan. 7- Determining ceilings for holding cash in various Bank units and committing to those ceilings, and following necessary security procedures during the transfer of cash to and from the Bank and its organizational units or any other entity within the Kingdom. 8- Insuring all Bank assets against all possible risks that those assets may be exposed to.

Eleventh: The Bank must provide the Central Bank of Jordan with the following: 1- Any change the Bank wishes to make to the position of General Manager or any member of the Executive Management in the Bank, before taking the decision. 2- Detailed reports on cases filed between the Bank and other parties, including the legal opinion and rulings issued regarding them. 3- Debts written off by the Bank, including the customer's name, debt value, guarantees, reasons for writing off these debts, and any information the Bank deems necessary to include, with a decision from the Board of Directors or Audit Committee (or its equivalent for foreign bank branches) on this matter. 4- Information related to Board of Directors and Executive Management members and committees including Board members, according to attached forms, annually or upon any modifications. 5- Shareholder statements as follows, semi-annually: a- Contributions of Jordanians, Arabs, and foreigners and their percentage of total capital. b- Contributions of Board of Directors members, their representatives, and Executive Management, showing name, number of shares, contribution percentage, and nationality. c- Contributions of the ten largest shareholders in the Bank, showing name, number of shares, contribution percentage, and nationality. d- Shareholders whose contribution value is (10,000) shares or more, showing name, number of shares, contribution percentage, and nationality. e- Contributions of banks, showing bank name, number of shares, contribution percentage, and bank nationality. f- Contributions less than (10,000) shares, showing the number of shareholders and their contribution value and percentage in total. 6- Name of the liaison officer responsible for providing all Central Bank requirements in various fields and the name of a substitute, annually or upon any modifications. 7- Annual budget and the assumptions it is based on, and the objectives desired to be achieved, no later than the end of January of each year. 8- Detailed report explaining all circumstances of any embezzlement, forgery, theft, fraud, or significant shortage of assets incident, with a statement of measures the Bank takes to recover its rights and ensure non-recurrence in the future.

Twelfth: The following instructions are considered an integral part of these Regulations: 1- Instructions on Banks Practicing Their Operations by Electronic Means No. (2001/8) dated 26/7/2001. 2- Instructions on Electronic Money Transfer Operations No. (2004/20) dated 13/4/2004. 3- Principles of E-Banking Risk Management issued pursuant to Circular No. (3344/1/10) dated 21/3/2005. 4- Instructions on Business Continuity Plan No. (2006/27) dated 30/3/2006. 5- Instructions on Combating Money Laundering and Terrorist Financing No. (2006/29) dated 28/5/2006. 6- Instructions on Compliance Monitoring No. (2006/33) dated 26/12/2006. 7- Any other related instructions.

Thirteenth: The provisions of these Regulations apply to banks licensed within the Kingdom and foreign branches of Jordanian banks only.

Fourteenth: These Regulations shall be effective as of their date, and the following memoranda and circulars are repealed:

No.Memo/Circular No.DateSubject
1Memo (75/22)13/2/1975Reporting embezzlement incidents
2Memo (79/100)3/5/1979Writing off debts
3Memo (80/88)21/6/1980Internal auditors at branches
4Memo (81/30)4/2/1981Security procedures (night guards, alarm devices, ...)
5Memo (82/200)7/11/1982Judicial disputes
6Circular (7474/70/3)26/3/1988Internal audit departments and staff
7Circular (6591/70/3)18/3/1989Presenting inspection reports to the Board of Directors
8Circular (3293/70/3)10/2/1991Strengthening internal control means
9Circular (14883/70/3)29/7/1991Providing the Central Bank with Board of Directors meeting minutes
10Circular (17769/70/3)19/8/1991Budgets
11Circular (23890/7136)17/11/1991Shareholder data
12Memo (92/3)4/1/1992Consulting the Central Bank when appointing a General Manager or Deputy General Manager
13Circular (11146/70/3)9/5/1993Providing the Central Bank with information on employees in the Inspection/Internal Audit Department
14Circular (17828/7136)27/7/1994Shareholder data
15Circular (22563/70/3)22/9/1994Reporting embezzlement incidents
16Circular (22387/70/3)12/9/1995Correcting violations and observations in inspection reports
17Circular (14151/2/4/10)18/6/1996Providing the Central Bank with information on Treasury Department employees
18Circular (12617/10)20/7/1998Security procedures (cameras, ...)
19Circular (1990/6/3/2/1/10)15/11/1999Security procedures (cameras, alarm devices, ...)
20Circular (1751/10)7/2/2000Budgets
21Circular (5939/3/3/2/1/10)13/4/2000Security procedures (money transfer)
22Circular (1912/10)29/1/2001Naming a liaison officer
23Circular (3940/10)27/1/2001Audit Committee names
24Circular (4794/10)27/3/2002Guidelines on control and supervision systems
25Circular (13556/10)25/5/2002Information on Board of Directors and Executive Management
26Circular (2935/4/2/10)21/3/2006Security procedures (cameras, ...)
27Memo (2006/36)18/6/2006Security procedures (cash transfer)
28Circular (6393/4/2/10)2/7/2006Security procedures (cameras, ...)
29Circular (1106/4/2/10)31/1/2007Reporting embezzlement incidents

Attachments: Forms No. (3)

Governor Dr. Amieh Touqan