2021-10-07
Added · Updated
The National Council of Financial Supervisors (CNSF) adopts revised Recommendations on Business Continuity Management (BCM) for credit institutions, investment companies, financial companies, payment institutions, and electronic money institutions supervised by the Bank of Portugal. These recommendations replace the 2010 guidelines and establish minimum requirements for BCM policies, governance structures, and business continuity plans, adapted to the size, complexity, and risk profile of each institution. The document mandates the integration of BCM into risk management frameworks, emphasizes operational resilience against cyber threats and pandemics, and requires regular testing, maintenance, and reporting of continuity procedures.
BDP published 1 document in the last 30 days — get each new one by email the day it lands.
Circular Letter No. CC/2021/00000047
Sent to:
Credit Institutions, Investment Companies, Financial Companies, Payment Institutions and Electronic Money Institutions.
Mod. 99999975/T – 01/14
Subject: Recommendations on Business Continuity Management (revised)
The National Council of Financial Supervisors (CNSF) approved, on September 20, 2021, the Recommendations on Business Continuity Management (revised), which were elaborated jointly by the Bank of Portugal, the Insurance and Pension Funds Supervisory Authority and the Securities Market Commission, within the framework of the CNSF's Better Regulation initiative for the financial sector.
The Recommendations embody a set of minimum requirements that must be implemented and deepened by institutions according to the nature of their activities, size and complexity, organizational model and risk profile, taking into account the principle of proportionality. Their publication aims to reinforce the content of the guidelines previously issued on this matter and seeks to reflect the evolution that has taken place in the business continuity management of national financial institutions.
The Recommendations reflect the current harmonized legislative and regulatory framework at the European level and the most relevant international principles on this matter, namely the principles of the Basel Committee on Banking Supervision on operational risk management and operational resilience.
In this context, the Recommendations – available in the Annex - must be observed by credit institutions, financial companies, payment institutions and electronic money institutions subject to the direct prudential supervision of the Bank of Portugal.
In particular, the observance of the provisions contained in the Recommendations may be adapted to the specificities of each institution, taking into account the principle of proportionality. In any case, the Recommendations may be implemented flexibly. However, in cases where policies or procedures are adopted that do not appear consistent with the framework of guidelines now established, institutions must demonstrate to the supervisory authorities the adequacy of their options and that the solutions adopted are appropriate and offer, at least, the same degree of resilience as that set out in that document.
With the publication of these Recommendations, the previous Recommendations on BCM, of 2010, published by "Circular Letter No. 75/2010/DSB" of the Bank of Portugal, of December 3, 2010, cease to be in force.
1 https://www.bportugal.pt/cartacircular/0752010dsb
Annex to the Circular Letter of the Bank of Portugal No. CC/2021/00000047
………………………………………………………………………………………………………………………………………………………………………………………………………….
Annex I to Circular Letter No. CC/2021/00000047
RECOMMENDATIONS ON
BUSINESS CONTINUITY MANAGEMENT
(revised)
A. INTRODUCTION 2
B. RECOMMENDATIONS 5_book mark1
Annex to the Circular Letter of the Bank of Portugal No. CC/2021/00000047
………………………………………………………………………………………………………………………………………………………………………………………………..
Mod. 99999975/T – 01/14
A. Introduction
Business Continuity Management (BCM) is a key requirement for organizations in all sectors of activity and, in particular, in sectors of essential activities, such as the financial sector. Thus, it is up to the competent supervisory authorities to ensure that financial institutions have contingency and business continuity plans that ensure their ability to operate on a continuous basis and minimize losses in the event of a serious disruption to their activity.
In the face of strong technological innovation and the progressive automation and digitalization of operational, commercial and management processes of financial institutions, BCM assumes increased preponderance, especially with regard to the technological component. As demonstrated by the Covid-19 pandemic, which forced institutions to quickly adapt their mode of interaction, both with clients and with workers, BCM capabilities, in the operational, human and technological aspects, are absolutely critical to avoid disruptions in the activity developed. Finally, BCM also assumes an essential character, in the current economic framework, where the resilience and stability of the institutions that make up the financial system are of special relevance to support the recovery of economic activity.
In this context, the National Council of Financial Supervisors (CNSF) decided to review its Recommendations to financial institutions on BCM, issued in 2010, in order to promote their update in light of the current legislative and regulatory references and current best practices.
Since this is a matter of transversal importance for the resilience of the financial sector, these Recommendations, like the previous ones, were prepared jointly by the Bank of Portugal (BdP), the Insurance and Pension Funds Supervisory Authority (ASF) and the Securities Market Commission (CMVM) – hereinafter, "competent authorities" – under the aegis of the CNSF, and within the framework of the "Better Regulation" project for the financial sector.
Indeed, the previous Recommendations already provided for the possibility of the CNSF "proceeding to their update or adaptation, taking into account, both the experience collected from institutions in the meantime, as well as changes in the level of risk conditions to which institutions may be subject, and other developments that may occur in relation to this matter.".
Thus, the main changes in these revised Recommendations compared to the 2010 Recommendations are indicated below:
i. The introduction and clarification of requirements and supervisory expectations in compliance with the changes verified in the reference regulation in this matter, at the European and international level in general, compared to the regulatory framework in force in 2010, at the time of the preparation of the previous recommendations. In concrete terms, requirements and supervisory expectations are introduced regarding the internal governance of institutions, the outsourcing of critical business services, processes or functions, and the supervision of risk associated with information and communication technologies (ICT) and security;
ii. A revised and adapted approach to the main risks for the continuity of activity and security of institutions resulting from the increasing digitalization of the financial system, which has resulted in the greater
Annex to the Circular Letter of the Bank of Portugal No. CC/2021/00000047
………………………………………………………………………………………………………………………………………………………………………………………………..
Mod. 99999975/T – 01/14 use and dependence of institutions on ICT and other innovative technologies, alerting to procedures that guarantee cybersecurity and operational resilience of institutions against external attacks, from the perspective of detection and prevention of disruptive events as a complement to the capacity for recovery and response;
iii. The provision of best practices learned in the context of the Covid-19 pandemic, including the reinforcement of the relevance of recovery and response procedures considering different recovery strategies adapted to multiple scenarios (for example, the use of the remote work system - "teleworking"), and the need to contemplate with adequate criticality and for multiple scenarios, also, internal reporting procedures to the management body and external to the supervisor, with adequate accuracy and timeliness;
iv. The clarification of some requirements, based on lessons learned in the context of the supervisory process, namely with regard to the business continuity planning of institutions included in a group, the incorporation of business continuity into the risk management framework of institutions and the adequate consideration of risks associated with the outsourcing of critical processes and functions.
The Recommendations reflect the relevant international principles on this matter, especially within the framework of the European harmonization of financial regulation.
Transversally to the entire financial sector, the proposal for a Regulation of the European Parliament and of the Council on digital operational resilience for the financial sector ("DORA"1) is relevant.
With regard to the insurance, reinsurance and pension funds sector, the following Guidelines2 and Opinion of the European Insurance and Occupational Pensions Authority (EIOPA) are also relevant: Guidelines on governance system ("EIOPA-BoS-14/253"); Guidelines on ICT security and governance ("EIOPA-BoS-20/600"); Guidelines on outsourcing of cloud computing service providers ("EIOPA-BoS-20-002"); and "Opinion on the supervision of the management of operational risks faced by IORP ("EIOPA-BoS-19-247"). Also relevant are Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the business of Insurance and Reinsurance ("Solvency II") and Delegated Regulation (EU) 2015/35 of the Commission of 10 October 2014, as well as Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision (IORP).
In the banking sector, the following Guidelines of the European Banking Authority2 (EBA) are additionally relevant: Guidelines on internal governance ("EBA/GL/2017/11"); Guidelines on outsourcing ("EBA/GL/2019/02"); and Guidelines on ICT risk management and security ("EBA/GL/2019/04"). Also relevant are Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 ("CRD-IV") and Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 ("PSD2"), as well as the "Principles for the Sound Management of Operational Risk" ("BCBS195") and the "Principles for Operational Resilience" ("BCBSd509"), both from the Basel Committee on Banking Supervision.
In the sector of markets and financial instruments, the "High-level Principles for Business Continuity" of the International Organization of Securities Commissions ("IOSCO FR32/2015")2 are also relevant.
In particular, these Recommendations complement, for the purposes of the national legal and regulatory framework, the provisions of the legal regime for access and exercise of the insurance and reinsurance activity, approved by Law No. 147/2015, of September 9, in the legal regime for the constitution and functioning of pension funds and pension fund management entities, approved by Law No. 27/2020, of July 23, in
1 Proposal of 24/09/2020.
2 Note that, in some cases, there is no direct correspondence with the content of the Guidelines or Principles, which served as a reference point for the revision of the Recommendations.
Annex to the Circular Letter of the Bank of Portugal No. CC/2021/00000047
………………………………………………………………………………………………………………………………………………………………………………………………..
Mod. 99999975/T – 01/14
Regulatory Standards of ASF No. 14/2005-R
3, of November 29, and 8/2009-R, of June 4; in Notice No. 3/2020 of the Bank of Portugal; in the Securities Code and in the General Regime of Collective Investment Undertakings, where the obligation regarding the existence of a business continuity plan is essentially established.
These Recommendations embody a set of minimum requirements that must be implemented and deepened by institutions according to the nature of their activities, size and complexity, organizational model and risk profile, taking into account the principle of proportionality. In any case, the Recommendations may be implemented flexibly. Nevertheless, institutions must be able to demonstrate the adequacy of adopting solutions not consistent with the framework of guidelines now established, in particular, that they offer at least the same degree of resilience as those provided for in this document. Indeed, the competent authorities will monitor the adequacy of the implementation of these Recommendations by their respective supervised institutions with reference to their degree of observance, namely through targeted actions or other supervisory procedures. Additionally, the members of the CNSF may also evaluate the degree of observance of the Recommendations, in order to verify the need and relevance of proceeding to a new update or adaptation of them.
These Recommendations were submitted to public consultation, the response received having been weighed and the comments accepted in the final version, in accordance with the terms set out in the corresponding CNSF Public Consultation Report No. 1/2021.
Thus, the CNSF, in the exercise of its powers under paragraph f) of paragraph 2 of Article 2 of Decree-Law No. 228/2000, of September 23, establishes the following:
i. The Recommendations on business continuity management addressed to financial institutions subject to the supervision of the competent authorities are adopted;
ii. Financial institutions must observe the provisions presented in the Recommendations, which comprise a set of minimum requirements and translate the general supervisory expectations of the competent authorities;
iii. Financial institutions must apply these Recommendations taking into account the nature of their activities, size and complexity, organizational model and risk profile;
iv. With the publication of these Recommendations, the previous Recommendations on BCM, of 2010, published by "Circular Letter No. 75/2010/DSB" of the Bank of Portugal, of December 3, and by "Circular No. 11/2010" of the ASF, of November 115, as well as through communication dated December 1, 2010 on the CMVM website6, cease to be in force.
3 The ASF is currently developing regulatory work aimed at issuing a new regulatory standard regarding the governance system of insurance and reinsurance companies.
4 https://www.bportugal.pt/cartacircular/0752010dsb 5 https://www.asf.com.pt/winlib/cgi/winlib.exe?skey=&cap=&pesq=7&thes0=14924&label=ESTRUTURAS+DE+GOVERNA%C3%87%C3%83O&doc=19711 5 https://www.cmvm.pt/pt/Legislacao/Legislacaonacional/Recomendacoes/Pages/Recomendações-da-CMVM,-do-Banco-de-Portugal-e-do-ISP-sobre-Gestão-daContinuidade-do-Negócio.aspx
Annex to the Circular Letter of the Bank of Portugal No. CC/2021/00000047
………………………………………………………………………………………………………………………………………………………………………………………………..
Mod. 99999975/T – 01/14
B. Recommendations
Business continuity management (BCM) must embody an integrated and structured approach of the institution, or, where applicable, of the financial group, and must integrate the global risk management policies. The need to adopt an integrated approach to BCM does not invalidate that other action plans specifically aimed at certain components (e.g. building evacuation plans, security plans) may be outlined. In these cases, the adequate integration of these plans within the scope of the global business continuity management policy must be ensured.
Institutions must outline a business continuity management policy ("BCM policy") adjusted to their specificities, integrating it into the institution's risk management system, in particular, within the scope of operational risk. Thus, the BCM policy must reflect the main risks to which the institution is exposed and the vulnerabilities inherent to its business, organizational structure, internal governance, characteristics of physical infrastructures, geographical implementation, among others.
The BCM policy must, therefore, be aligned with the BCM strategy, which in turn must be an integral part of the institution's global business strategy. Specifically, in addition to providing for the selection of critical business processes and functions, and the definition of priorities, procedures and resources (human and material) to be mobilized, the BCM policy must reflect the conditions under which the business is normally developed. The scope and degree of detail in planning to mitigate disaster situations must therefore be proportional to the nature of the institution's activity, its size and complexity. Consequently, the BCM policy must be subject to continuous adjustment to the development of the business.
This policy must be written, duly approved, and must apply to all relevant collaborators, as well as, where appropriate, to the institution's service providers. Additionally, the BCM policy must be disseminated internally to all collaborators and made available, when appropriate, to service providers.
RECOMMENDATION 1 – Business Continuity Management Policy Institutions must have a business continuity management policy that reflects their risk profile and is proportional to the nature of their activities, their size, complexity and organizational model.
Key references: EBA GL/2017/11 Paragraph 208; EBA GL/2019/04 Paragraphs 79 and 81; EIOPA-BoS-20/600 Guidelines 2, 3, 4, 6, 19 and EIOPA-BoS-14/253 Guideline 8; EIOPA-BoS-19-247 Opinion; BCBS195 Principle 11; BCBSd509 Principles 1 and 7.
The BCM policy must comprise the implementation of a business continuity management process with several stages, which cover, in particular, the definition of a business continuity plan (BCP) that integrates, in turn, a business impact analysis of an eventual unplanned interruption of activity (in English acronym - BIA, "Business Impact Analysis") and the definition of a disaster recovery strategy or plan (in English acronym - DRP, "Disaster Recovery Plan") involving the various affected aspects. These recovery procedures must not be limited to the domains of technology, computing or physical infrastructures, it being essential that the functional recovery methods of the business are also safeguarded, which implies, in particular, that the human resources aspects and their mobility and adaptability are considered. Additionally, the BCM policy should provide for the definition of a communication policy for BCM purposes, the carrying out of tests, maintenance and audit of the BCP and also the training of all collaborators involved and awareness at all levels of the institution.
Finally, in the current context of the digitalization of the financial sector - which induced a growing dependence of institutions on information and communication technologies (ICT), making their business more vulnerable to security incidents, including cyberattacks - it is important that, in addition to continuity and response and recovery capabilities, institutions ensure adequate management of ICT security risks to which they are exposed, in order to prevent and detect potential disruptions of this nature to their activity.
The competence for the implementation of the BCM policy may be delegated to a committee created for this purpose or to another structural unit or responsible person deemed appropriate, which does not exclude, however, the ultimate responsibility of the management body. For this purpose, an interlocutor for matters related to BCM should be designated within the management body. If the creation of a committee or another structural unit, or responsible person, with the specific competence to implement the business continuity policy is justified, there must be an adequate assignment and segregation of responsibilities, and, in particular, a direct reporting line to the management body must be maintained. In the case of larger financial institutions and with a more complex business model, this structural unit must have resources dedicated exclusively to it, and the creation of a business continuity function should be considered. This function must have as its main responsibilities: to support the management body in defining the BCM policy and monitoring its implementation; monitor and review the implementation of business continuity procedures, RECOMMENDATION 2 – Responsibilities of the management body The management bodies of institutions must guarantee the safeguarding of the operational resilience of the institution. Key references: EBA GL/2019/04 Paragraph 80; EIOPA-BoS-20/600 Guidelines 2, 3, 4, 6, 7; IOSCO FR32/2015 Principle 1; BCBS195 Principle 11.
Annex to the Circular Letter of the Bank of Portugal No. CC/2021/00000047
………………………………………………………………………………………………………………………………………………………………………………………………..
Mod. 99999975/T – 01/14 reporting and advising the management body, regularly or, when necessary, about its activation; ensure the adherence of service providers to the BCM policy; and ensure that all collaborators are aware of the BCM policy and other procedures related to BCM.
In case of disaster, the management body must be responsible for activating the business continuity procedures. In this sense, the institution's BCP must provide for institutional communication channels that ensure that the management body is informed continuously and adequately about the
Read the rest free
Source: Banco de Portugal — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BDP
BDP published 1 document in the last 30 days. We email you each new one the day it's published.