2021-01-04

Added · Updated

Circular dated January 4, 2021 regarding operational risk management instructions

The Central Bank of Egypt mandates that all banks operating in Egypt replace the Basic Indicator Approach with the Standardized Approach (SA) for calculating operational risk capital requirements under Pillar 1 of Basel III. Banks are granted a transition period until the end of December 2021 to align their operations, during which they may continue using the Basic Indicator Approach. Banks must submit completed loss data collection forms quarterly to the Supervision Department starting from the end of December 2020.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Operational Risk Management Instructions

"In accordance with the Basel III reforms issued in December 2017"

Part One: General Framework

First: Introduction

In the context of the Central Bank of Egypt's continued efforts to study and apply the latest and best international practices regarding banking supervision, with the aim of enhancing the performance of the Egyptian banking system, strengthening the financial positions of banks operating in Egypt, and improving their risk management methods to enhance their competitiveness at the local, regional, and international levels, and to help them withstand potential financial crises, it has been decided to apply the new Standardized Approach (SA) to measure operational risk to replace the Basic Indicator Approach currently in use. The issuance of these instructions comes within the framework of applying the final set of Basel III reforms related to the post-financial crisis phase issued on December 7, 2017. All banks are required to use this unified approach to calculate capital requirements under Pillar 1. The Standardized Approach addresses several weaknesses in the four approaches previously stipulated by the Basel Committee as follows:

  • Simplifying the supervisory framework, as this unified approach will replace the four approaches previously allowed by the Basel Committee for calculating capital requirements to cover operational risk.

  • Combining both a bank's financial statement-based indicator, namely the "Business Indicator (BI)," and the bank's historical operational losses to calculate the capital required to cover operational risk, resulting in a framework that is more sensitive to risk.

  • Reducing the complexities of the Advanced Measurement Approach and enhancing the comparability of results across different banks and countries.

Second: Scope of Application

These instructions apply to all banks operating in the Arab Republic of Egypt and subject to the supervision of the Central Bank of Egypt as follows:

  • Reporting is done as a banking group, which is the entity dominated by banking activity considered as a single economic entity, without regard to legal boundaries between the bank and its subsidiaries, on a consolidated basis. The banking group includes the bank and all its branches inside and outside the country, and all other financial companies (excluding insurance companies) in which the bank (or the bank and its related parties) owns more than 50% of shareholders' equity or any percentage that enables it to control that entity according to the previously mentioned concept. As for banks that do not have subsidiaries (including all their branches inside and outside the country) and banks that are subsidiaries of foreign banks, reporting is done on an individual basis.

Part Two: Definitions

  • Operational Risk is the loss that a bank may suffer as a result of deficiencies in its internal control system or internal operating system, or the failure and incompetence of employees and human resources in performing their duties, or malfunctions in electronic operating systems, or as a result of external factors and events, including fraud and forgery. This definition includes legal risk, excluding strategic risk and reputational risk.

  • Legal/Compliance Risk is the loss resulting from fines, penalties, and sanctions imposed on banks in case of failure to fulfill their contractual and legal obligations or non-compliance with supervisory instructions, or as a result of their application in violation of contract provisions or because those provisions do not clearly and correctly reflect the rights and contractual obligations of the bank and/or the counterparty.

TermDefinition
Business Indicator (BI)Is a proxy indicator that reflects the bank's output based on its financial statements (Income Statement) and consists of three components: Net Interest Income (NII), Net Fees and Commissions Income (FC), and Investment Income (ILDC).
Business Indicator ComponentIs the result of the Business Indicator (BI) (i.e., regulatory transactions) (∝) and is determined according to the bank's activity that reflects its business output.
Business Indicator ComponentIs the net value of other operating income resulting from operational risks that are not covered by the previous components.
Historical Losses (LC)Is the average net value of other losses resulting from operational risks over the last 10 years or a minimum of 5 years (LC), previously multiplied by 15 times (the one that represents a constant transaction determined by the Basel Committee).
Internal Loss Multiplier (ILM)Is a general multiplier used to estimate the expected loss based on the average net historical losses of the bank and the Business Indicator component. It relies on a supervisory multiplier for historical operational losses specific to the bank for a specified period.
Pending LossesAre losses arising from operational risk events with a confirmed financial impact, recorded for a specific period in temporary accounts, and their impact has not yet been reflected in the profit and loss account.
Time LossesAre losses or negative economic impacts recorded in financial statements in a specific accounting period due to events related to operational risk that affect cash flows or financial statements of previous financial periods.
Gross LossesIs the value of actual losses before any type of recovery.
Recovered AmountsIs an independent event related to the original loss event but separated from it in time when any incoming cash flows from a third party are received. Recovered amounts may include amounts recovered from insurance companies, perpetrators of fraud, and amounts recovered from erroneous transfers.
Net LossesIs the value of actual losses after taking into account the impact of recoveries.

Part Three: Qualitative Requirements for Operational Risk Management

Banks must follow the qualitative requirements contained in this section for operational risk management to develop and improve policies and procedures for managing these risks, which include the basic principles that banks must apply (as a minimum) to achieve more effective and comprehensive management of operational risk, as follows:

1. Establishment of an Independent Management or Unit for Operational Risk Management

  • The bank must establish a sub-management or independent unit for operational risk management operating under the bank's risk management department. Its main tasks are to identify, measure, monitor, limit, and mitigate the impact of operational risks.

2. Responsibilities of the Board of Directors

  • The Board of Directors must be fully aware and cognizant of the main aspects of operational risk as a type of risk with a special nature, different from other types of risks that should be managed.

  • Approving the general framework for operational risk management and reviewing it periodically, and ensuring that the general operational risk framework is clear, defined, and covers all aspects related to operational risk.

  • Approving policies and procedures for operational risk that define all aspects related to operational risk management.

  • Promoting a culture of effective operational risk management.

  • Ensuring that the general framework for operational risk management is subject to a comprehensive and effective internal audit by the bank's internal audit management, which must be completely independent of the operational risk management department.

  • Maintaining the independence of the internal audit management and ensuring that it provides accurate information about the performance of the operational risk unit to the bank's Board of Directors or its committees.

3. Responsibilities of the Bank's Senior Management

  • Senior management is responsible for implementing the general framework for operational risk management approved by the Board of Directors.

  • Developing policies and procedures for operational risk management related to all products, activities, operations, and banking systems.

  • Defining and distributing authorities and responsibilities across different business lines and taking necessary measures to hold wrongdoers and violators accountable.

  • Ensuring that policies and procedures for operational risk management have been explained and clarified to all employees in the work units concerned with managing these risks.

  • Ensuring that all bank employees have the necessary expertise and technical capabilities to perform the tasks and activities assigned to them.

  • Ensuring coordination between those responsible for operational risk management and those responsible for managing other major risks (credit risk, market risk, liquidity risk, etc.).

  • Ensuring that all procedures and policies related to operational risk, and regulatory rules related to information technology system management, are documented.

  • Developing an emergency plan to face the possibility of the bank being exposed to difficult conditions or severe disruptions leading to the cessation of activity according to item (8) which will be mentioned later.

4. Responsibilities of the Operational Risk Management Unit/Department

  • Establishing an effective general framework for operational risk in terms of identifying, assessing, monitoring, controlling, and mitigating operational risk as part of the bank's comprehensive risk management approach, and approving it with the Board of Directors and notifying supervisory authorities thereof.

  • Identifying and assessing operational risks related to all current or new banking products, activities, and operations (before launching or issuing them).

  • Implementing a specific system to monitor and track actual operational risks and operational losses.

  • Providing policies and procedures for mitigating and limiting significant operational risks, with these policies and procedures being reviewed periodically.

  • Providing periodic reports on information related to operational risk to senior management and the bank's Board of Directors to assist them in managing operational risk, including suggestions for corrective actions to be taken.

  • Identifying early warning indicators that enable the identification of potential sources of operational risk and predicting the probability of exposure to losses.

  • Continuously identifying external and internal threats and potential failures in the performance of individuals, operations, and systems, and immediately evaluating factors that may hinder the performance of key operations, and managing the resulting risks in light of expected operational resilience.

  • The bank must disclose its general framework for operational risk management in a manner that allows its counterparties to determine the extent of the bank's ability to identify, assess, monitor, and control its operational risks.

  • The bank must disclose sufficiently the volume of losses resulting from its operational risks to allow all market participants to evaluate the approach followed by the bank in managing operational risk.

  • The volume of data and information disclosed regarding operational risk must be commensurate with the size of the bank, the complexity of its operations and activities, and its general risk framework.

5. Disclosure

6. Aggregation of Data Related to Operational Risk Losses

  • All banks must classify actual losses resulting from operational risk according to the results of the following events, and in light of the guidance table in Attachment No. (3):

1/6 Internal fraud means. 2/6 External fraud means. 3/6 Credit card fraud means. 4/6 Violation of labor laws, occupational safety and health regulations, and violation of supervisory instructions. 5/6 Misconduct towards bank customers. 6/6 Damage to the bank's physical assets. 7/6 Work disruption and system failure. 8/6 Deficiencies in the management and execution of operations.

7. Methods of Measuring Operational Risk

  • Banks should commit to using the new Standardized Approach for measuring operational risk as a supervisory approach when calculating the capital required to cover these risks for the purpose of preparing the capital adequacy standard (Pillar 1).

  • Banks may use other methods to measure operational risk for internal risk management purposes within the bank.

8. Emergency Plan / Business Continuity Plans

  • The bank should have a written, documented, and approved emergency plan, with the aim of ensuring the bank's ability to work continuously and minimize losses in the event of business disruption.

  • Emergency plans must be reviewed periodically by individuals independent of those responsible for formulating and managing these plans, and their inspection reports must be submitted to senior management and the Board of Directors.

  • The plan must include at least the following:

    • Definition of disasters and crises and appropriate methods to mitigate their effects in the event of their occurrence.
    • Identification of key functions and operations that ensure business continuity.
    • Definition of decision-making steps and how to adhere to them.
    • Identification of a manager responsible for the business continuity plan.
    • Determination of work priorities and corrective steps for each main sector, main/alternative emergency communication means, and activity locations.
    • Conducting periodic tests of the business continuity plan in light of a set of accepted acute scenarios to test the bank's ability to perform its basic operations in emergency and unusual conditions, and to ensure the credibility of the established plan and inform all employees about it.

9. Management of Service Providers and Outsourcing Entities - Outsourcing

  • At a minimum, the following must be considered in the policy of outsourcing to external service providers:

    • That it is done under a written contract - legally reviewed - between the external service provider and the bank.
    • Establishing appropriate measures to verify the external service provider's ability to perform its tasks with the required efficiency according to its contractual obligations.
    • Considering what was stated in the governance instructions regarding conflicts of interest.
  • The bank must ensure through its contracts with external service providers the following:

    • Quality of contracted services according to pre-specified standards and the ability to implement them in case of emergencies.
    • Commitment of service providers to ensure complete protection of the confidentiality of information regarding the bank and customers.
    • The ability of contracts concluded with the service provider to be terminated by the bank if necessary, such as breach of obligations without arranging any financial obligation on the bank, with the importance of having alternatives that guarantee the continuity and quality of service provision to customers through a business continuity plan.
    • Service providers not making any changes to the services assigned to them without obtaining the bank's prior approval.
    • Commitment to the procedures specified by the bank regarding auditing the provided services, including presenting periodic reports to the bank's management regarding their performance level.
    • Commitment of service providers through concluded contracts to inform the bank of information related to the services assigned to them according to the provisions of disclosure and information transparency.
    • Commitment of service providers through concluded contracts to notify the bank of any events that may have a significant impact on their ability to undertake assigned tasks.

[RegAlert note: the English text above is a translation of the first 24,000 characters of a 165,068-character original (15% of the document). The remainder was not translated. The complete original-language text is stored with this document.]