2024-09-16
Added · Updated
The Banco de Portugal establishes supervisory expectations for credit institutions regarding the suitability of board members and key ICT, security, and risk management personnel. It mandates that executive members responsible for ICT and risk management possess at least three years of relevant professional experience and appropriate academic qualifications. Institutions must ensure collective board competence in ICT risks, maintain independent second-line defense functions, and implement continuous training programs, with performance indicators potentially linked to variable remuneration. These requirements apply to credit institutions, excluding specific agricultural credit entities, and are enforced through ongoing supervisory assessments.
Circular Letter No. CC/2024/00000027 Sent to: Credit Institutions. Mod. 99999975/T – 01/14 Subject: Supervisory expectations regarding the suitability of members of the administrative and supervisory bodies and those responsible for information and communication technology (ICT), security, and associated risk management structural units
Framework In accordance with Articles 115-A and 115-K of the General Regime of Credit Institutions and Financial Companies (RGICSF), institutions must have robust governance systems that allow them to adequately manage the risks to which they are or may become exposed.
In this context, and without prejudice to the management of other risks, emerging risks, particularly those associated with information and communication technologies (ICT) and security, justify special attention from institutions and supervisory authorities.
Indeed, the complexity and risks associated with ICT, as well as the frequency and impact of ICT and security incidents (including cybersecurity incidents) have been increasing in the financial sector. Due to the interdependence among institutions within this sector, such incidents can generate systemic impacts.
Simultaneously, the growing digitalization of financial services, as well as the current geopolitical and macroeconomic context, potentiate an increased risk of threats to the national and European financial sector at the cybersecurity level, potentially affecting financial institutions and national financial market infrastructure directly or indirectly, with special relevance in situations involving the outsourcing of essential or important functions.
In this context, the European Banking Authority (EBA) Guidelines on ICT and security risk management (EBA/GL/2019/04)1 were published on November 28, 2019, which address, among other entities, credit institutions and competent authorities.
More recently, Regulation (EU) 2022/2554 of the European Parliament and of the Council of December 14, 2022, on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (DORA), directly applicable in all Member States from January 17, 2025, has reinforced the importance of operational resilience management by institutions, particularly regarding the knowledge and skills of board members, as provided for in Article 5(4) of said Regulation.
1 https://www.eba.europa.eu/sites/default/documents/files/document_library/Publications/Guidelines/2020/GLs%20on%20ICT%20and%20secu rity%20risk%20management/Updated%20Translations/880824/Final%20draft%20Guidelines%20on%20ICT%20and%20security%20risk%20man agement_COR_PT.pdf
Mod. 99999924/T – 01/14 Banco de Portugal Expectations In this framework, the Banco de Portugal reinforces the importance of financial institutions ensuring adequate management of operational risks to which they are or may become exposed, particularly those associated with ICT and security, with a view to protecting solvency, stability, and strengthening the operational resilience of the financial sector, as well as ensuring their sound and prudent management and safeguarding the national banking system and the funds entrusted to them.
To this end, there is a need for continuous reinforcement of the updating of knowledge and skills of members of the administrative and supervisory bodies2, senior management, and other employees, in risk management matters, especially emerging risks, particularly those associated with ICT and security.
It is thus the expectation of the Banco de Portugal that, in alignment with the European Central Bank (ECB)3, institutions strengthen the composition of their corporate bodies and internal structures and ensure the continuous training of members of their administrative and supervisory bodies, senior management, and other employees4, including in matters related to ICT and security risks and other emerging risks. Thus, it is incumbent upon institutions to develop adequate training programs in these areas, aimed at strengthening knowledge, skills, and decision-making capacity, promoting their attendance by the aforementioned employees and members of the administrative and supervisory bodies. It is considered good practice that, whenever possible, key performance indicators (KPIs) are defined that allow weighing the frequency of training programs within the framework of individual performance evaluation processes and the allocation of variable remuneration, when this is legally and regulationally permitted.
In accordance with Article 30(6) of the RGICSF, the selection and appointment policy must promote the diversity of qualifications and skills necessary for the exercise of the function, and in accordance with Article 5 of Banco de Portugal Notice No. 3/2020, the administrative and supervisory bodies of institutions must identify and evaluate their respective needs regarding their composition and must have succession policies that identify and describe in detail, for each function, the qualifications, skills, and professional experience that subsequent appointments must ensure.
In light of the above, the Banco de Portugal considers, in particular, that credit institutions supervised by the Banco de Portugal, regarding the treatment of ICT and security matters:
2 Communication regarding the "Main results, concerns, and supervisory expectations related to training actions for members of the administrative and supervisory bodies of credit institutions", sent to institutions on September 4, 2023. 3 New policy for more bank board expertise on ICT and security risks (https://www.bankingsupervision.europa.eu/press/publications/newsletter/2024/html/ssm.nl240221_2.en.html) 4 The EBA Guidelines on the assessment of the suitability of members of the administrative body and holders of essential functions (EBA/GL/2021/06) establish the obligation for institutions to have training policies. As previously disclosed (Circular Letter No. CC/2021/00000058 of November 29, 2021 and published in the Official Bulletin No. 11/2021 5th Supplement), institutions must comply with the provisions of said Guidelines.
Mod. 99999924/T – 01/14 I. Regarding Administrative and Supervisory Bodies
Institutions must ensure that all members of the administrative and supervisory bodies possess updated essential minimum knowledge necessary for the adequate performance of their functions in terms of ICT, including regarding risks associated with ICT and security, and the impact of these risks on their strategy and business models, thereby ensuring that their administrative and supervisory bodies collectively possess adequate levels of knowledge in this area, in addition to complying with the other suitability requirements established in the RGICSF.
In particular, regarding executive members of the administrative body, based on the current market average determined by the Banco de Portugal, it is expected that the person responsible for: a. The ICT portfolio possesses adequate academic qualifications and relevant professional experience, of at least 3 years, in the ICT area, preferably acquired in entities of the banking or financial sector. b. The risk management function, which includes the management of risks associated with ICT and security, or another structural unit performing an equivalent function, possesses adequate academic qualifications and, at least, 3 years of relevant professional experience related to the area of management of risks associated with ICT and security.
In the distribution of responsibilities at the level of the administrative body, institutions must ensure the independence of the function responsible for the assessment, monitoring, management, and control of risks associated with ICT and security (2nd line of defense) vis-à-vis business-generating units and related areas (1st line of defense).
Whenever the thresholds referred to in paragraph 2 above are not met regarding persons selected by institutions for positions, they must indicate the grounds for their choices, as well as the mitigation measures adopted, in line with the provisions of EBA/GL/2021/06 and point 3.1 of the ECB Guide to fit and proper assessments5.
In this sense, a candidate for a member of the administrative body may still be considered suitable if the institution can appropriately justify it, namely if: i) the candidate possesses relevant professional experience or specialized knowledge that meets the specific needs of the institution; ii) the candidate commits, and the institution also, to attending necessary training actions to strengthen the professional qualification necessary for the exercise of the position; iii) adequate mitigants are presented and iv) the candidate complies with the other suitability requirements for the exercise of the position.
The assessment of the persons in question must include and weigh the mitigants implemented or to be implemented by the institution that allow ensuring good decision-making in ICT and security matters, and in the management of associated risks, by the administrative body, whenever its members do not meet the established thresholds.
5 Guide to fit and proper assessments (https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.fit_and_proper_guide_update202112~d66f230eca.pt.pdf)
Mod. 99999924/T – 01/14 II. Regarding Other Structural Units 6. When the management of risks associated with ICT and security is ensured by a structural unit different or complementary to the risk management function, the respective responsible person must be qualified by the institutions to which this Circular Letter is addressed as a holder of an essential function, as established in Article 33-A of the RGICSF, and evaluated according to the legal regime established for holders of essential functions. It must be ensured, in particular, that they possess adequate academic qualifications and relevant professional experience in ICT and security, preferably acquired in entities of the banking or financial sector, and that they meet the conditions to exercise their functions in a framework that ensures the organizational independence of this structural unit.
For practical purposes of the assessments in question, institutions must keep in mind the recommendations and examples of mitigants to be weighed published in the Frequently Asked Questions (FAQ) published on this date and available as an attachment.
The Banco de Portugal will continue to intensify its supervisory actions in this matter, within the framework of the guidelines emanating from the Single Supervisory Mechanism and in collaboration with other relevant National Competent Authorities, namely the Insurance and Pension Funds Supervisory Authority (ASF) and the Securities Market Commission (CMVM), and will take into account, in its actions and supervisory processes, the expectations transmitted through this Circular Letter.
Annex to Circular Letter of Banco de Portugal No. CC/2024/00000027 ……………………………………………………………………………………………………………………………………………………………………………………………….. Mod. 99999975/T – 01/14 Annex to Circular Letter No. CC/2024/00000027 These FAQs constitute a list of relevant aspects for the assessment of the suitability of members of the administrative bodies and members with responsibility for the institution's information and communication technology (ICT), security, and associated risk management structural units6, regarding the requirement of professional qualification and experience and in relation to conflicts of interest, which institutions must weigh within the framework of assessment processes and, where applicable, subsequent authorization by the Banco de Portugal for the exercise of functions.
A. Scope of institutions covered by Circular Letter No. CC/2024/00000027 a. Which institutions are the object of this Circular Letter? These supervisory expectations apply to credit institutions, excluding Caixas de Crédito Agrícola Mútuo integrated into the Integrated System of Mutual Agricultural Credit (SICAM).
However, and always from a risk-based assessment perspective, the Banco de Portugal may extend its supervisory expectations on this matter, concretized in the aforementioned Circular Letter, to other types of financial institutions, whenever prudential reasons justify it, considering, among other aspects, the nature, size, complexity, and risk profile of these institutions.
B. Individual assessment of the executive member (ME) of the administrative body with the ICT portfolio a. How to assess if the qualification and experience of the ME with the ICT portfolio is adequate? In this assessment, it is necessary to weigh the candidate's academic qualifications, whether they are in an adequate academic or training area, and if their professional experience in the ICT area is relevant, meeting the 3-year threshold recommended by the Banco de Portugal. It must also be assessed if their relevant professional experience in the ICT area was acquired in entities of the banking or financial sector.
The candidate, based on their professional qualification and experience, must be able to identify, prevent, manage, and adequately mitigate the main internal and external threats and vulnerabilities to which the institution is or may become exposed arising from ICT and security, at the 1st line of defense level.
The candidate must possess knowledge and experience in the management and monitoring of outsourced essential or important functions, in order to ensure adequate service provision, namely by effectively preventing risks associated with ICT and security,
6 Cfr. EBA Guidelines on the management of risks associated with ICT and security (EBA/GL/2019/04 of November 28) available at https://www.eba.europa.eu/sites/default/documents/files/document_library/Publications/Guidelines/2020/GLs%20on%20ICT%20and% security%20risk%20management/Updated%20Translations/880824/Final%20draft%20Guidelines%20on%20ICT%20and%20security%20risk %20management_COR_PT.pdf.
Annex to Circular Letter of Banco de Portugal No. CC/2024/00000027 ……………………………………………………………………………………………………………………………………………………………………………………………….. Mod. 99999975/T – 01/14 which the institution is or may become exposed.
b. How is it expected that the ME with the ICT portfolio assesses the risks inherent to ICT (as 1st line of defense)? Within the scope of the institution's activity and the markets where it operates, the ME must be able to identify, manage, prevent, monitor, and mitigate, at the 1st line of defense level, the risks associated with ICT and security to which the institution is and will be exposed in the long term, as well as contribute to decision-making in conformity.
c. What specific internal knowledge of the institution and its functioning must be guaranteed by the ME with the ICT portfolio? The ME in question must: i) Know who the employees with relevant knowledge and experience in ICT and security are, and the internal procedures necessary in case of operational and security incidents, including cyberattacks; ii) Be able to, within the scope of the institution's activity and the markets where it operates, identify, manage, prevent, monitor, and mitigate, at the 1st line of defense level, the risks associated with ICT and security to which the institution is and will be exposed in the long term, and contribute to decision-making in conformity; iii) Have knowledge in the management of risks associated with ICT and security, at the 1st line of defense level, including within the scope of outsourcing functions; iv) Understand all domains and concepts of ICT (availability and continuity, security, outsourcing, change management, and data integrity), adequately assessing the potential or effective associated risks and their functioning, at the 1st line of defense level, being able to challenge the information provided by the person responsible for the ICT structural unit; and v) Be able to analyze and monitor the assessments, reports, and recommendations issued by the internal audit function or by independent external entities to the institution in matters of ICT and security.
For each of the identified aspects, if the candidate's knowledge is not the most adequate, the institution must, in its assessment, always indicate the mitigants it weighed and that justify its choice.
d. If the thresholds recommended by the Banco de Portugal are not met, what additional aspects/mitigants should be evaluated? The institution must evaluate the measures it has already taken or intends to take towards the professional development of administrative body members and its organizational structure, such as: a. Frequency of training actions aimed at providing members with portfolios related to a deep knowledge of the risks associated with ICT and security to which the institution is or may become exposed; b. Frequency of training actions aimed at strengthening the theoretical knowledge of members in these matters relevant to the institution's activity and/or the functions to be exercised by the members in question. c. Assessment of its internal organization and the qualification of resources assigned to functions, including at the Senior Management level, which supports that these allow弥补 any weaknesses in the qualification and experience of the ME.
C. Individual assessment of the executive member of the administrative body with the portfolio of the function of management of risks associated with ICT and security a. How to assess if the qualification and experience of the ME with the portfolio of the function of management of risks associated with ICT and security is adequate? In this assessment, it is necessary to weigh the candidate's academic qualifications, whether they are in an adequate academic or training area, and their professional experience in the area of ICT and security risk management, meeting the 3-year threshold recommended by the Banco de Portugal. The candidate's academic qualifications and professional experience must guarantee that they are able to analyze information related to the risks associated with ICT and security of the institution, identify key issues arising from that information, and propose appropriate controls and measures to mitigate these risks.
b. What specific internal knowledge of the institution and its functioning must be guaranteed by the ME with the portfolio of the function of management of risks associated with ICT and security? In terms of internal knowledge of the institution, the candidate must: i) Identify which are the relevant risks in terms of ICT and security, considering the institution's business model; and ii) Possess a transversal knowledge of the most relevant risks associated with ICT and security inherent to the institution's activities, in the short, medium, and long term.
For each of the identified aspects, if the candidate's knowledge is not the most adequate, the institution must, in its assessment, always indicate the mitigants it weighed and that justify its choice.
c. What measures must the ME with the portfolio of the function of management of risks associated with ICT and security guarantee regarding action in the prevention and occurrence of operational and security incidents? One of the essential roles of the ME with the portfolio of the function of management of risks associated with ICT and security is to prevent and ensure effective action in the event of operational and security incidents.
In a preventive perspective of operational and security incidents, the candidate must be able to adopt innovative solutions in the assessment of risks associated with ICT and security. In the event of an actual occurrence of operational and security incidents, including cyberattacks, the candidate must be able to swiftly and effectively activate the business continuity plan and assess and manage the impacts and risks on the institution's activities resulting from these occurrences, ensuring the sound and prudent management of the institution.
For each of the identified aspects, if the candidate's knowledge is not the most adequate, the institution must, in its assessment, always indicate the mitigants it weighed and that justify its choice.
D. Collective assessment of the administrative body relevant in ICT matters a. How to assess if the knowledge at the collective level of the administrative body is sufficient and adequate regarding ICT matters? Collectively, it is expected that a collegiate body brings together members with different characteristics, namely various levels of knowledge in the referred matters and different professional experience, inside or outside the institution.
Thus, in addition to a specific analysis of the executive members of the administrative body with the ICT portfolio and with the portfolio of the function of management of risks associated with ICT and security, the administrative body must also be assessed as a whole.
Thus, it must be ensured that all members of the administrative body: i) Possess essential minimum knowledge for the performance of their functions in terms of ICT, including regarding risks associated with ICT and security; ii) Are able to identify the impact of risks associated with ICT and security on the institution's strategy and business model; iii) Possess adequate levels of knowledge in ICT and security, to verify if the decisions taken by the body are in consonance with EBA/GL/2019/047.
Specifically regarding non-executive members of the administrative body, if any, they must possess knowledge that allows them to supervise and audit the decisions of the administrative body in terms of ICT and security, including regarding the risks associated with these.
For each of the identified aspects, if the candidate's knowledge is not the most adequate, the institution must, in its assessment, always indicate the mitigants it weighed and that