2024-09-24
Added · Updated
The Central Bank of Egypt issues updated instructions on corporate governance and internal control for all banks operating in Egypt, replacing previous regulations from 2011 and 2014. The document mandates specific board composition requirements, including a maximum of three executive directors, at least two independent non-executive directors, and representation for minority shareholders holding 5% or more. It establishes detailed obligations for board committees, internal audit functions, risk management, and the use of technology for remote board meetings, requiring banks to adopt comprehensive internal policies and submit annual self-assessment results to the regulator.
Cairo on: September 19, 2024 Mr. / Chairman of the Board Bank Greetings,
With reference to the supervisory instructions on "Bank Governance" issued on August 23, 2011, and its subsequent amendments regarding the formation and periodic meetings of bank boards of directors, which were issued through several circulars, the latest of which was issued on July 2, 2024, and also with reference to the supervisory instructions on "Internal Control of Banks" issued on September 2, 2014.
Furthermore, in implementation of the provisions of the Central Bank and Banking System Law issued by Law No. 194 of 2020, and working to update the aforementioned instructions in line with relevant international practices, which ensures the efficient and effective execution of banks' operations and activities and the monitoring of associated risks, and supports maintaining the integrity and stability of the banking sector, the Board of Directors of the Central Bank, in its meeting held on September 17, 2024, approved the issuance of the attached instructions regarding "Governance and Internal Control of Banks".
Please be kind enough to emphasize strict compliance with the attached instructions.
Accept our highest regards,
Hassan Abdallah
1
Instructions for Governance and Internal Control of Banks
2
Introduction These instructions were prepared in accordance with the provisions of the Central Bank and Banking System Law issued by Law No. 194 of 2020 (hereinafter referred to as the Central Bank Law), with the aim of enhancing and developing the concept of governance and internal control systems in the banking sector, given their importance in maintaining financial stability and addressing various challenges.
The instructions are divided into two parts. The first part relates to governance, which regulates the relationship between the bank's board of directors, senior management, shareholders, and other stakeholders. It defines the duties and responsibilities of each, as well as the approach followed by the board and senior management to direct the bank's affairs and activities, and the principles followed in supervising performance, leading to the optimal use of the bank's resources and maintaining its stability. As for the second part, it stipulates the establishment of a system in each bank through which all bank activities and operations are monitored and reviewed on a continuous and comprehensive basis, ensuring the availability of internal control through all levels of the board of directors and its committees, senior management, and all bank employees, while taking into account the nature of the system for continuous evaluation and development.
Scope of Application These instructions apply to all banks operating in the Arab Republic of Egypt. Branches of foreign banks must comply with these instructions to the extent applicable to them, or with those applied at the bank's headquarters, whichever is more stringent in the event of a conflict between them. Necessary justifications must be submitted and approval obtained from the Central Bank of Egypt.
Each bank must ensure that all its foreign branches comply with these instructions to the extent that does not conflict with the laws and instructions governing them in the country where they operate. In the event of any conflict, approval from the Central Bank of Egypt must be obtained on how to address the matter, as well as notifying the bank's headquarters.
3
Table of Contents
First: Governance -1 Concept of Governance 5......................................................................................................................... -2 Bank Board of Directors 5...................................................................................................................... -3 Board of Directors Committees 14.................................................................................................................. -4 Senior Management 20........................................................................................................................... -5 Disclosure and Transparency 20................................................................................................................... -6 Relationship between the Bank Board of Directors and Shareholders 21............................................................................................ -7 Control over Complex Structures and Processes 21................................................................................... -8 Group Structure 22...................................................................................................................... -9 Control over Foreign Branches 23......................................................................................................
Second: Internal Control -1 Concept of Internal Control 25............................................................................................................. -2 Objectives of Internal Control 25.............................................................................................................. -3 Elements of Internal Control 25............................................................................................................ -4 Responsibilities of the Board of Directors 25.......................................................................................................... -5 Responsibilities of Senior Management 27.............................................................................................................. -6 Sectors of Internal Control 27............................................................................................................ -7 Role of Legal Management within Internal Control 34................................................................................. -8 Information Systems and Reports 35............................................................................................................
Appendix 1: Key requirements of internal policies related to governance to be available at banks as a minimum 37.......................... Appendix 2: Evaluation of the Board of Directors' performance 39...........................................................................................................
4
First: Governance
-1 Concept of Governance Governance is the framework that regulates the relationship between the bank's board of directors, senior management, shareholders, and other stakeholders. Governance covers the principles followed by the bank to determine its objectives and the resources required to achieve them, as well as supervising performance. Governance also defines the responsibilities and duties of all parties involved in the bank, as well as the approach followed by the board of directors and senior management to conduct the bank's affairs and supervise its daily activities. It covers the following: 1-1 Setting strategies and determining objectives. 2-1 Achieving a balance between commitment to accountability towards shareholders and protecting depositors' interests, taking into account other stakeholders' interests. 3-1 Ensuring that the bank's activities are conducted within a safe and sound framework, in compliance with applicable laws and regulations. 4-1 Establishing effective internal policies regarding governance principles and ensuring their implementation. 5-1 Conducting the bank's daily operations and activities. 6-1 Determining the acceptable risk level for the bank.
-2 Bank Board of Directors 1-2 General Provisions 1-1-2 Each bank must be managed by a competent board of directors that is primarily responsible for setting the bank's strategy, including its main objectives and how to achieve them, as well as supervising the performance of senior management to ensure the achievement of these objectives in accordance with a sound strategy and clear risk policy that includes objectives, while ensuring that the bank's management is committed to all legal and supervisory requirements, and ensuring the effectiveness of the bank's internal control system, which includes the bank's stability and maintaining its reputation. 2-1-2 An organizational structure must be established for the bank that organizes the responsibilities and authorities of all levels of the board of directors, its committees, and senior management, with the bank's structure reflecting the principles of transparency, fairness, and separation of duties through an effective framework that includes continuous supervision and effective control at various functional levels. The Central Bank must be notified of the aforementioned structure after its approval by the Board, as well as any amendments made to it. 3-1-2 At least four managerial levels must be available in the organizational structure of the bank, with the authorities and responsibilities of each defined, as follows: 1-3-1-2 The Supervisory Level, represented by the Board of Directors and its committees. 2-3-1-2 The Management Level, represented by senior management. 3-3-1-2 The Executive Level, represented by those responsible for direct supervision of the bank's various operations. 4-3-1-2 The Control Level, represented by the independent internal audit functions of the bank (Risk, Compliance, and Internal Audit sectors). 4-1-2 Each bank must have written procedures that clarify the authorities and responsibilities at the bank level, including the main duties of the Board and senior management. 5-1-2 The Board of Directors adopts the professional standards to be followed by board members, senior management, and all bank employees, with the necessity of enhancing individual and collective accountability as follows: 1-5-1-2 Employees must promote a governance culture among senior management levels in the bank, which reflects on the performance of all other management levels. 2-5-1-2 Establishing a code of conduct for banking employees for all bank employees, including clear standards, acceptable and unacceptable behaviors, and values to be committed to. A copy must be made available to all employees, who must sign to confirm they have read and committed to it.
2-2 Formation of the Board of Directors 1-2-2 Without prejudice to the provisions of international agreements and laws concerning the establishment of certain banks and Article 134 of the Central Bank Law, the bank's management is entrusted to a board of directors consisting of a number of members elected by the General Assembly for a term of three years. The Board elects from among its members a non-executive Chairman, as well as an Executive Member / Managing Director. 2-2-2 Board members must possess diverse qualifications and expertise, including banking, financial, economic, accounting, legal, information technology, and risk management, to support the Board's adequacy and reflect on its performance and decisions, enabling it to evaluate the bank's and senior management's performance, in accordance with conditions of independence and technical suitability. 3-2-2 The presence of a board member representing minority shareholders must be considered if their total shareholding represents 5% or more of total shareholdings. It must also be ensured that the representation of women on the bank's board of directors does not exceed two members at minimum. 4-2-2 A board member of any bank may not, in their personal capacity or as a representative, hold membership on the board of directors of another bank or entity, nor engage in any management or advisory activities in any of them. 5-2-2 The Chairman of the Board of Directors must be a non-executive member. There must be a complete separation between the responsibilities and duties of the Chairman of the Board and the Chief Executive Officer / Managing Director. The same person may not hold the position of Chairman of the Board and the duties of the Chief Executive Officer / Managing Director. The competencies and responsibilities of each must be determined according to the following instructions, documented in writing, and approved by the Board of Directors. 6-2-2 The Chairman of the Board (non-executive) is primarily responsible for the proper performance of the Board and its committees and ensuring their effectiveness. He must possess the experience and competence necessary to fulfill his responsibilities, which include at least: 1-6-2-2 Ensuring that Board decisions are based on sound and comprehensive grounds regarding the subjects under discussion, with the necessity of ensuring the existence of an appropriate mechanism to ensure the timely implementation and follow-up of these decisions. 2-6-2-2 Encouraging discussion and effective participation by all members, especially non-executive members, and allowing the expression of opposing views and discussing them within the decision-making process. 3-6-2-2 Ensuring the Board fulfills its duties in the best possible manner to achieve the bank's and its employees' interests, and working to manage conflicts of interest. 4-6-2-2 Providing sufficient opportunity for non-executive members to follow up on the performance of senior management. 5-6-2-2 Strengthening the relationship between the Board as a whole and senior management by inviting them to attend Board and committee meetings when necessary. 6-6-2-2 Ensuring that necessary information is made available in a sufficient and accurate manner at the appropriate time to Board members and shareholders. 7-6-2-2 Ensuring the effectiveness of the Board's and its committees' performance in applying the established governance systems. 8-6-2-2 Ensuring that all Board members conduct self-evaluation annually. 9-6-2-2 Convening the Board of Directors regularly and periodically, ensuring that Board meetings are consistent with the Bank's Articles of Association and relevant laws and instructions. 10-6-2-2 Coordinating with senior management and the Board Secretary regarding the Board's agenda. 11-6-2-2 Ensuring the provision of an induction program for new Board members, including informing them of their duties and performing their responsibilities effectively. 12-6-2-2 Ensuring the availability of an annual training plan to develop the technical skills of Board members, especially those from outside the banking sector.
3-2 Balance and Independence in Forming the Bank Board of Directors 1-3-2 The balance and independence of the bank's board of directors must be considered, ensuring that the number of executive and non-executive members is balanced, with a maximum of three executive members, and that there are at least two independent non-executive members among the non-executive members. 2-3-2 The non-executive member must be among those with competence and expertise, and must not be an employee, manager, or annual consultant of the bank, nor receive any paid consultations. His term of membership must not exceed six years, continuous or separate; it may be extended for 3 years for strong reasons and with the approval of the Central Bank. 3-3-2 The following conditions must be met by the independent non-executive board member: 1-3-3-2 He must not be an employee, manager, or annual consultant of the bank or one of its related parties during the previous three years. 2-3-3-2 He must not be a member of the board of directors of any of the parties related to the bank. 3-3-3-2 He must not have any kinship with any of the Board members, senior management, or the bank's consultant or any of their related parties up to the second degree. 4-3-3-2 He must not have any interests that conflict with his duties or could affect his neutrality in making decisions. 5-3-3-2 He must not have any shared interests with the bank's board of directors and senior management through participation in other companies or institutions. 6-3-3-2 He must not receive any salary or monetary amount from the bank except what he receives in exchange for his membership on the Board or its committees. 7-3-3-2 He must not be (or represent) a shareholder of the bank directly or indirectly. 8-3-3-2 He must not be a partner in the bank's external audit firm or an employee thereof during the previous three years. 9-3-3-2 His term of membership must not exceed six years, continuous or separate. 4-3-2 The Board must disclose in its annual report and governance forms all independent non-executive members. Proposals for their nomination must be submitted through the Governance and Nominations Committee and presented to the Board to be submitted to the General Assembly for approval, and after obtaining approval from the Central Bank.
4-2 Responsibilities and Obligations of the Board of Directors 1-4-2 The bank's Board of Directors is responsible for supervising the bank's management in general, as well as following up on the implementation of the bank's objectives by senior management. The following must be done at a minimum to strengthen the governance system in the bank and ensure its effectiveness: 1-1-4-2 Adopting the bank's strategy, policies, and main objectives, supervising their implementation, and ensuring their dissemination among bank employees. An action plan must be established containing at least: 1-1-1-4-2 The scope of the bank's activities and the risks it is exposed to. 2-1-1-4-2 The bank's current and future objectives, which must be specific and measurable. 3-1-1-4-2 An independent budget estimate for each activity in the bank, as well as expected financial results. 2-1-4-2 Adopting the bank's financial statements after approval by the Audit Committee. 3-1-4-2 Adopting the organizational structure and determining the structure of authorities and responsibilities in the bank, as well as selecting senior management. 4-1-4-2 Holding regular meetings with senior management and the Internal Audit sector to review and discuss established policies and follow up on the achievement of the bank's strategic objectives. Non-executive Board members must meet with the Chairman of the Board at least once a year without the executive members. 5-1-4-2 Holding a meeting between non-executive Board members at least once a year with the external auditor, without executive members, in the presence of the Head of Internal Audit and Compliance sectors. 6-1-4-2 Holding a meeting between non-executive Board members and the Head of the Risk sector at least once a year, without executive members. 7-1-4-2 Ensuring that the Central Bank is provided with copies of the minutes of the aforementioned meetings (items 4-1-4-2, 5-1-4-2, and 6-1-4-2) within one month from the date of their holding. 8-1-4-2 Supervising and overseeing the bank's operations, without including tasks that involve executive work. 9-1-4-2 Establishing a general framework for managing any potential conflict of interest in the interests of the bank and all its board members, senior management, employees, shareholders, consultants, and other interested parties. 10-1-4-2 Avoiding any conflict of interest in the Board's duties and obligations. In the event that any suspicion of a conflict of interest arises in the duties or obligations of a Board member, he must disclose this and not participate in decision-making or voting. 11-1-4-2 Working to achieve the interests of shareholders, depositors, employees, and other stakeholders, with priority given to depositors' interests. 12-1-4-2 Adequate knowledge and understanding of the legal and regulatory environment in which the bank operates, and ensuring compliance with laws and supervisory controls. 13-1-4-2 Allocating sufficient time and appropriate efforts from all members to ensure the Board fulfills its duties. 2-4-2 One of the Board's most important responsibilities is to adopt the governance policy and related policies, and determine the optimal approach for the size, complexity, and risk level of the bank's activities and its business model, as well as continuous and periodic evaluation of the adequacy and effectiveness of the bank's governance and internal control policies and procedures. The Board must do the following: 1-3-4-2 Establish a policy for reporting violations and irregularities, including a mechanism to protect whistleblowers and ensure complete confidentiality; to encourage employees to initiate the disclosure of violations and report them, based on specific documents or information. 2-3-4-2 Ensure the adoption of an internal policy by the bank regarding the management of any potential conflict of interest, including the requirements set out in Appendix 1 as a minimum, to ensure that transactions with all parties related to the bank are conducted independently, while considering not harming the interests of shareholders, depositors, and the bank in general. The Board must make the necessary disclosure, including disclosure to the Central Bank of transactions that may involve a conflict of interest. 3-3-4-2 Establish a policy for the bank's social responsibility, clarifying the bank's participation in community development through economic, social, and informational channels. 4-3-4-2 Adopt and periodically review the disclosure policy and supervise its implementation within the framework of the Central Bank Law and related instructions. 5-3-4-2 Adopt the internal recruitment policy, including standards and controls to ensure that employees' expertise and qualifications match their job requirements. It must include a mechanism for nominating and appointing senior management, as well as supervising and following up on their performance and compensation, with the adoption of a succession plan. 6-3-4-2 The Board of Directors must adopt all the bank's internal policies, including but not limited to: risk management policy, information technology and IT governance policy, information security and confidentiality policy, anti-money laundering and counter-terrorism financing policy, and salaries and bonuses. 7-3-4-2 Ensure that the bank reviews its internal policies every 3 years at the maximum and updates them if necessary, with the necessity of obtaining Board approval for the review or update, and ensuring that operational procedures are updated – in cases requiring it – to reflect any amendments made to the relevant policies.
5-2 Board of Directors Meetings 1-5-2 The Board must meet regularly and periodically, not less than six times during the year, upon the call of the Chairman of the Board, or a majority of its members. The Chief Executive Officer / Managing Director of the bank may request the Chairman to convene a meeting, accompanied by the agenda he wishes to present. 2-5-2 No member of the Board may be absent from more than one-third of the Board's meetings during the year; otherwise, the Chairman of the Board must notify the Bank's General Assembly, which will take whatever it deems appropriate. 3-5-2 Board members may delegate each other to attend Board and committee meetings, up to a maximum of twice during the year. Attendance through delegation is not considered actual attendance. 4-5-2 Members may participate in bank board meetings via telephone or video conference, according to the following conditions: 1-4-5-2 The Bank's Articles of Association must allow participation in meetings via telephone or video conference, in addition to clear procedures adopted by the Board of Directors to hold meetings via these means. 2-4-5-2 The principle is actual attendance. If this is not possible, participation via video or telephone is allowed after notifying the Chairman of the Board and informing the Board Secretary, provided it does not exceed twice during the year for a single member, while ensuring that a majority of the Board members attend in person. 3-4-5-2 Participation of a Board member via video or telephone is considered actual participation in the Board of Directors meeting, and he has the right to vote. He is counted in the legal quorum for the Board's meetings and the validity of decisions issued regarding him. 5-5-2 Banks must comply with the following technical controls regarding member participation in meetings via telephone or video conference: 1-5-5-2 Ensuring an appropriate level of security for applications used for participation in meetings via telephone or video conference, with the Internal Audit sector evaluating the procedures and irregularities applied to mitigate risks resulting from the use of these technologies and reporting them to the Audit Committee. Necessary corrective actions must be followed up in case of any deficiencies, considering the following as a minimum and obtaining Central Bank approval: a) Applying all procedures and controls that include verifying the identity of participants in meetings. b) Ensuring that service users' devices are effectively secured, whether connected to the bank's network or outside the bank's secured network. c) Availability of access control mechanisms in the management and monitoring of access to prevent unauthorized entry to meetings, whether at the service user level or system administrators. d) Using necessary technology to ensure the confidentiality, integrity, and availability of data and information stored on devices or any other storage media when transmitted. e) Scanning files on service users' devices before saving them to ensure the absence of any viruses. f) Protecting virtual meeting rooms with a password and preventing their dissemination except through secured channels. g) Providing a meeting recording feature in the service, accompanied by consent from all participants before starting the recording, with the bank committed to ensuring that the application used provides adequate technologies to protect any recordings from unauthorized intrusion. h) Applying multi-factor authentication – if possible – at the service user level, not just system administrators. i) Allowing file sharing with authorized parties at the service user level. j) Conducting penetration tests to conduct a detailed assessment of the system's security status before starting its use and after making any fundamental changes to the system. 6-2 Evaluation of the Bank Board of Directors' Performance 1-6-2 The Bank Board of Directors must follow a specific system to conduct an annual self-evaluation – either alone or with the assistance of an independent entity after obtaining its approval from the Central Bank – through which each member evaluates his performance, as well as the Board's performance as a single unit, and its committees, in addition to conducting mutual evaluations among all Board members, including the Chairman of the Board. The evaluation must include the degree of commitment to duties and identifying necessary actions to improve the competence of Board members. The Central Bank must be notified of the results of this evaluation and the proposed actions in this regard, taking into account the following: 1-1-6-2 The necessity of designing a self-evaluation model that fits the size and nature of its activities according to the standards and determinants set out in Appendix 2, which must be approved by the Board of Directors. 2-1-6-2 The evaluation must include the member's performance and his effective participation in Board and committee meetings. 3-1-6-2 A consolidated report of the most important findings in all evaluations, as well as proposals and recommendations, must be presented to the Governance and Nominations Committee, which will present it to the Board of Directors for approval. 4-1-6-2 The Chairman of the Board is responsible for taking whatever he deems appropriate in terms of actions according to the aforementioned evaluation results, including improving the Board's performance. 5-1-6-2 The Board must take whatever it deems appropriate in the event that one of its members does not comply with the minimum acceptable performance level.
7-2 Board Secretary 1-7-2 Each bank must identify a person with competence, experience, and sufficient knowledge of banking operations, entrusted with the responsibility of "Board Secretary". The establishment of a Board Secretariat management is allowed, and the main tasks of this management include, but are not limited to: 1-1-7-2 Preparing Board meetings and preparing the agenda, providing necessary information and documents, and delivering them to Board members in sufficient time before the meeting. 2-1-7-2 Preparing meeting minutes, signing them, and delivering them to Board members for review – either by attendees or participants via communication means – in addition to saving meeting recordings – using a dedicated recording device called "Recording Security" – for the bank's policies and legal requirements and applicable supervisory controls. 3-1-7-2 Presenting Board of Directors and committee meeting minutes at the following sessions for approval. A copy of the meeting minutes must be provided to the Central Bank within one month from the date of the meeting (in Arabic). 4-1-7-2 Ensuring that members receive all documents and the meeting agenda in the event of their participation via telephone or video. 5-1-7-2 Counting the number of Board meetings held during the year, recording attendance in meetings, and documenting whether attendance was actual, via telephone, or via video, and ensuring the application of prevailing rules in this regard. 6-1-7-2 Following up on the implementation of Board decisions within the mechanism established for this purpose, with this item being presented at the beginning of all Board meetings. 7-1-7-2 Preserving and documenting data and documents related to Board decisions and subjects presented to it, and ensuring their availability to the Central Bank. 8-1-7-2 Coordinating with all bank management departments and sectors to present their work results to the Board. 9-1-7-2 Coordinating with all Board of Directors committees to enable effective communication between them and the Board. 10-1-7-2 Providing appropriate channels for effective communication and information exchange in a complete, accurate, and timely manner between Board members and senior management. 11-1-7-2 Working to ensure that Board members are aware of any updates in supervisory or legal responsibilities resulting from changes in the bank's operations or activities or the legal and supervisory framework governing it. 12-1-7-2 Providing necessary information about the bank to new members and assisting in providing the induction program for them. 13-1-7-2 Documenting the discussions and recommendations of each member at Board and its committees' meetings in detail, with the names of attendees (whether Board members or others) recorded in the meeting minutes.
-3 Board of Directors Committees 1-3 General Provisions 1-1-3 The Board's committees play a significant role in supporting the Board of Directors in the decision-making process. 2-1-3 The Bank Board of Directors establishes the rules and procedures necessary for the formation of committees...
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 79,839-character original (30% of the document). The remainder was not translated. The complete original-language text is stored with this document.]