To:
- Sharia Commercial Banks; and
- Conventional Commercial Banks having Sharia Business Units
At the place
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10/SEOJK.03/2014
REGARDING
ASSESSMENT OF THE HEALTH LEVEL OF SHARIA COMMERCIAL BANKS AND SHARIA BUSINESS UNITS
In view of the implementation of Financial Services Authority Regulation Number 8/POJK.03/2014 regarding the Assessment of the Health Level of Sharia Commercial Banks and Sharia Business Units (State Gazette of the Republic of Indonesia Year 2014 Number 134, Supplement to the State Gazette of the Republic of Indonesia Number 5544), Bank Indonesia Regulation Number 13/23/PBI/2011 regarding the Implementation of Risk Management for Sharia Commercial Banks and Sharia Business Units (State Gazette of the Republic of Indonesia Year 2011 Number 103, Supplement to the State Gazette of the Republic of Indonesia Number 5247), and Bank Indonesia Regulation Number 8/6/PBI/2006 regarding the Implementation of Consolidated Risk Management for Banks Conducting Control over Subsidiary Companies (State Gazette of the Republic of Indonesia Year 2006 Number 8, Supplement to the State Gazette of the Republic of Indonesia Number 4602), it is necessary to regulate provisions regarding the Assessment of the Health Level of Sharia Commercial Banks and Sharia Business Units in a Circular Letter of the Financial Services Authority as follows:
I. GENERAL
-
The increase in innovation in Sharia banking products, services, and activities affects the increase in business complexity and the Bank's Risk Profile, which if not balanced with the implementation of adequate Risk Management can cause various fundamental problems for the Bank and for the financial system as a whole.
-
In order for Banks to be able to identify problems earlier, take appropriate and faster corrective actions, and implement ... implement the principles of Good Corporate Governance and better Risk Management, the Financial Services Authority has refined the Bank Health Level assessment system.
-
In principle, the health level, Bank management, and Bank business continuity are the full responsibility of the Bank's management. Therefore, Banks are required to maintain, improve, and increase their health level by implementing prudence principles and Risk Management in carrying out their business activities, including conducting periodic self-assessments of their health level and taking effective corrective measures. On the other hand, the Financial Services Authority evaluates, assesses the Bank's Health Level, and takes necessary supervisory actions in order to maintain the stability of the banking and financial system.
II. GENERAL PRINCIPLES OF ASSESSMENT OF THE HEALTH LEVEL OF SHARIA COMMERCIAL BANKS AND SHARIA BUSINESS UNITS
Bank Management needs to pay attention to the following general principles as a basis for assessing the Bank's Health Level.
-
Risk-Oriented
The health level assessment is based on the Bank's Risks and the impact on the Bank's overall performance. This is done by identifying internal and external factors that can increase Risk or affect the Bank's financial performance currently and in the future. Thus, Banks are expected to be able to detect the root causes of Bank problems earlier and take effective and efficient preventive and corrective measures.
-
Proportionality
The use of parameters/indicators in each factor of the Bank's Health Level assessment is done by considering the Bank's business characteristics and complexity. The Bank's Health Level assessment parameters/indicators in this Circular Letter are minimum standards that must be used in assessing the Bank's Health Level. However, Banks may use additional parameters/indicators that are appropriate to their business characteristics and complexity in assessing ... assessing the Bank's Health Level so that it can reflect the Bank's condition better.
-
Materiality and Significance
Banks need to pay attention to the materiality and significance of the Bank's Health Level assessment factors, namely Risk Profile, Good Corporate Governance, Rentability, and Capitalization, as well as the significance of assessment parameters/indicators in each factor in concluding assessment results and determining factor ratings. The determination of materiality and significance is based on analysis supported by adequate data and information regarding Risk and the Bank's financial performance.
-
Comprehensive and Structured
The assessment process is carried out thoroughly and systematically and is focused on the Bank's main problems. The analysis is conducted in an integrated manner considering the interrelationship between Risks and between assessment factors of the Bank's Health Level and Subsidiary Companies that must be consolidated. The analysis must be supported by key facts and relevant ratios to show the level, trend, and level of problems faced by the Bank.
III. PROCEDURES FOR ASSESSING THE HEALTH LEVEL OF BANKS
In accordance with Financial Services Authority Regulation Number ....../POJK.03/2014 regarding the Assessment of the Health Level of Sharia Commercial Banks and Sharia Business Units, Banks are required to conduct self-assessments of the Bank's Health Level using the Risk-based Bank Rating (RBBR) approach. The assessment of the Health Level of Sharia Commercial Banks is conducted individually and consolidated, while the assessment of the Health Level of Sharia Business Units is conducted individually, with the following procedures:
- Procedures for Assessing the Health Level of Sharia Commercial Banks and Sharia Business Units Individually
The individual Health Level assessment for Sharia Commercial Banks includes assessments of the factors: Risk Profile, Good Corporate Governance, Rentability, and Capitalization, while for Sharia Business Units it only covers the Risk Profile factor.
a. Assessment of the Risk Profile Factor
The Risk Profile factor assessment is an assessment of inherent Risk and the quality of Risk Management implementation in the Bank's operational activities. Risks that must be assessed consist of 10 (ten) types of Risk, namely Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Strategic Risk, Compliance Risk, Reputation Risk, Rate of Return Risk, and Investment Risk.
In assessing the Risk Profile, Banks are also required to pay attention to the scope of Risk Management implementation as regulated in applicable provisions regarding the implementation of Risk Management for Sharia Commercial Banks and Sharia Business Units.
- Inherent Risk Assessment
Inherent Risk assessment is an assessment of Risk inherent in the Bank's business activities, both quantifiable and non-quantifiable, which has the potential to affect the Bank's financial position. The Bank's inherent Risk characteristics are determined by internal and external factors, including business strategy, business characteristics, complexity of Bank products and activities, the industry in which the Bank conducts business activities, and macroeconomic conditions.
The assessment of inherent Risk is done by considering quantitative and qualitative parameters/indicators.
The determination of the inherent Risk level for each type of Risk refers to the general principles of assessing the Health Level of Sharia Commercial Banks and Sharia Business Units.
The determination of the inherent Risk level for each type of Risk is categorized into 5 (five) ratings, namely rating 1 (low), rating 2 (low to moderate), rating 3 (moderate), rating 4 (moderate to high), and rating 5 (high).
The following are some minimum parameters/indicators that must serve as the Bank's reference in assessing inherent Risk. Banks may add other relevant parameters/indicators ... with the Bank's business characteristics and complexity by considering the principle of proportionality.
a) Credit Risk
Credit Risk is Risk arising from the failure of customers or other parties to fulfill their obligations to the Bank according to the agreed contract.
Credit Risk generally attaches to all fund investment activities conducted by the Bank whose performance depends on the performance of the counterparty, issuer, or borrower's performance. Credit Risk can also be caused by the concentration of fund provision to debtors, geographical regions, products, types of financing, or specific business fields. This risk is commonly referred to as financing concentration Risk and must also be taken into account in the assessment of inherent Risk.
In assessing inherent Risk regarding Credit Risk, the parameters/indicators used are: (i) asset portfolio composition and concentration level; (ii) fund provision quality and reserve adequacy; (iii) fund provision strategy and sources of fund provision; and (iv) external factors.
Banks in assessing inherent Risk regarding Credit Risk use inherent Risk parameters/indicators based on Appendix I.1.a.
b) Market Risk
Market Risk is Risk on the balance sheet and administrative accounts due to changes in market prices, including Risk in the form of changes in the value of tradable or leaseable assets.
Market Risk includes among others benchmark interest rate Risk, exchange rate Risk, equity Risk, and commodity Risk. The implementation of Risk Management for equity Risk and commodity Risk must be implemented by Banks conducting consolidation with Subsidiary Companies.
In ... In assessing inherent Risk regarding Market Risk, the parameters/indicators used are: (i) volume and portfolio composition; (ii) potential loss from benchmark interest rate Risk in the banking book; and (iii) business strategy and policies.
Banks in assessing inherent Risk regarding Market Risk use inherent Risk parameters/indicators based on Appendix I.1.b.
c) Liquidity Risk
Liquidity Risk is Risk arising from the Bank's inability to meet due obligations from cash flow funding sources and/or high-quality liquid assets that can be pledged, without disrupting the Bank's activities and financial condition.
This risk is also called funding liquidity Risk. Liquidity Risk can also be caused by the Bank's inability to liquidate assets without incurring material discounts due to the absence of active markets or severe market disruption. This risk is called market liquidity Risk.
In assessing inherent Risk regarding Liquidity Risk, the parameters used are: (i) composition of assets, liabilities, and administrative account transactions; (ii) concentration of assets and liabilities; (iii) vulnerability to funding needs; and (iv) access to funding sources.
Banks in assessing inherent Risk regarding Liquidity Risk use inherent Risk parameters/indicators based on Appendix I.1.c.
d) Operational Risk
Operational Risk is Risk of loss caused by inadequate internal processes, internal process failures, human error, system failures, and/or external events affecting Bank operations.
Sources of Operational Risk can be caused among others by human resources, processes, systems, and external events.
In assessing inherent Risk regarding Operational Risk, the parameters/indicators used are: (i) business characteristics and complexity; (ii) human resources; (iii) information technology and supporting infrastructure; (iv) fraud, both internal and external; and (v) external events.
Banks in assessing inherent Risk regarding Operational Risk use inherent Risk parameters/indicators based on Appendix I.1.d.
e) Legal Risk
Legal Risk is Risk arising from legal lawsuits and/or weaknesses in legal aspects.
This risk can also arise among others due to the absence of underlying legislation or weaknesses in agreements, such as the non-fulfillment of contract validity requirements or inadequate collateral.
In assessing inherent Risk regarding Legal Risk, the parameters/indicators used are: (i) litigation factors; (ii) agreement weakness factors; and (iii) absence/change of legislation factors.
Banks in assessing inherent Risk regarding Legal Risk use inherent Risk parameters/indicators based on Appendix I.1.e.
f) Strategic Risk
Strategic Risk is Risk due to inaccuracies in making and/or implementing strategic decisions and failures in anticipating changes in the business environment.
Sources of Strategic Risk can originate from weaknesses in the strategy formulation process and inaccuracies in strategy formulation, inaccuracies in strategy implementation, and failures to anticipate changes in the business environment.
In ... In assessing inherent Risk regarding Strategic Risk, the parameters/indicators used are: (i) strategy alignment with business environment conditions; (ii) high-risk strategies and low-risk strategies; (iii) Bank's business position; and (iv) Bank's business plan achievement.
Banks in assessing inherent Risk regarding Strategic Risk use inherent Risk parameters/indicators based on Appendix I.1.f.
g) Compliance Risk
Compliance Risk is Risk arising from the Bank's failure to comply with and/or implement applicable legislation and provisions, as well as Sharia principles.
Sources of Compliance Risk can be caused by a lack of understanding or legal awareness regarding applicable provisions, Sharia principles, or general business standards.
In assessing inherent Risk regarding Compliance Risk, the parameters/indicators used are: (i) type and significance of violations committed; (ii) frequency of violations committed or Bank's non-compliance track record; and (iii) violations of applicable provisions or business standards for specific financial transactions.
Banks in assessing inherent Risk regarding Compliance Risk use inherent Risk parameters/indicators based on Appendix I.1.g.
h) Reputation Risk
Reputation Risk is Risk arising from a decrease in stakeholder trust stemming from negative perceptions of the Bank.
One approach used in categorizing sources of Reputation Risk is indirect (below the line) and direct (above the line).
In ... In assessing inherent Risk regarding Reputation Risk, the parameters/indicators used are: (i) influence of negative reputation from Bank owners and related companies; (ii) violations of business ethics including Sharia business ethics; (iii) complexity of Bank products and business cooperation; (iv) frequency, materiality, and exposure of negative Bank news; and (v) frequency and materiality of customer complaints.
Banks in assessing inherent Risk regarding Reputation Risk use inherent Risk parameters/indicators based on Appendix I.1.h.
i) Rate of Return Risk
Rate of Return Risk is Risk arising from changes in the rate of return paid by the Bank to customers, due to changes in the rate of return received by the Bank from fund distribution, which can affect the behavior of third-party fund customers of the Bank.
In assessing inherent Risk regarding Rate of Return Risk, the parameters/indicators used are: (i) third-party fund composition; (ii) Bank's strategy and performance in generating profit/income; and (iii) third-party fund customer behavior.
Banks in assessing inherent Risk regarding Rate of Return Risk use inherent Risk parameters/indicators based on Appendix I.1.i.
j) Investment Risk
Investment Risk (Equity Investment Risk) is Risk arising from the Bank sharing in customer losses financed through profit-sharing-based financing, whether using the net revenue sharing method or the profit and loss sharing method.
In assessing inherent Risk regarding Investment Risk, the parameters/indicators used are: (i) composition and concentration level of profit-sharing-based financing; (ii) quality of profit-sharing-based financing; and ... and (iii) external factors.
Banks in assessing inherent Risk regarding Investment Risk use inherent Risk parameters/indicators based on Appendix I.1.j.
- Assessment of Risk Management Implementation Quality
The assessment of Risk Management implementation quality reflects an assessment of the adequacy of the Risk control system, covering all pillars of Risk Management implementation, and aims to evaluate the effectiveness of the Bank's Risk Management implementation according to principles as regulated in provisions regarding the implementation of Risk Management for Sharia Commercial Banks and Sharia Business Units.
The Bank's Risk Management implementation varies significantly according to scale, complexity, and the level of Risk tolerable by the Bank. Thus, in assessing the quality of Risk Management implementation, it is necessary to consider the Bank's business characteristics and complexity.
The assessment of Risk Management implementation quality is an assessment of 4 (four) interrelated aspects, namely: (i) Risk governance; (ii) Risk Management framework; (iii) Risk Management process, adequacy of human resources, and adequacy of management information systems; and (iv) adequacy of Risk control systems, considering the Bank's business characteristics and complexity.
The assessment of Risk Management implementation quality is conducted in an integrated manner as follows:
a) Risk Governance
Risk governance includes evaluations of: (i) formulation of the level of Risk to be taken (risk appetite) and Risk tolerance; and (ii) adequacy of active supervision by the Board of Commissioners, Board of Directors, and Sharia Supervisory Board, including the implementation of authorities and responsibilities of the Board of Commissioners, Board of Directors, and Sharia Supervisory Board.
b) Risk Management Framework
Risk Management Framework includes evaluations of: (i) Risk Management strategies aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management, including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting.
c) Risk Management Process, Human Resource Adequacy, and Management Information System Adequacy
Risk Management Process, Human Resource Adequacy, and Management Information System Adequacy include evaluations of: (i) Risk identification, measurement, monitoring, and control processes; (ii) adequacy of Risk Management information systems; and (iii) adequacy of the quantity and quality of human resources supporting the effectiveness of the Risk Management process.
d) Adequacy of Risk Control Systems
The adequacy of Risk control systems includes evaluations of: (i) adequacy of internal control systems and (ii) adequacy of independent review within the Bank, both by the Risk Management Work Unit and by the Internal Audit Work Unit. Reviews by the Risk Management Work Unit include among others methods, assumptions, and variables used to measure and set Risk limits, while reviews by the Internal Audit Work Unit include among others the reliability of the Risk Management framework and the implementation of Risk Management by business units and/or support units.
The assessment of Risk Management implementation quality is conducted on 10 (ten) types of Risk, namely Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Strategic Risk, ... Compliance Risk, Reputation Risk, Rate of Return Risk, and Investment Risk.
The level of Risk Management implementation quality for each Risk is categorized into 5 (five) ratings, namely rating 1 (strong), rating 2 (satisfactory), rating 3 (fair), rating 4 (marginal), and rating 5 (unsatisfactory).
- Determination of Risk Ratings
Risk ratings are determined based on assessments of the inherent Risk rating and the Risk Management implementation quality rating for each Risk. The determination of inherent Risk ratings for each Risk refers to Appendix III.2.2.a, III.2.3.a, III.2.4.a, III.2.5.a, III.2.6.a, III.2.7.a, III.2.8.a, and III.2.9.a, III.2.10.a, and III.2.11.a. The determination of Risk Management implementation quality ratings for each Risk refers to Appendix III.2.2.b, III.2.3.b, III.2.4.b, III.2.5.b, III.2.6.b, III.2.7.b, III.2.8.b, III.2.9.b, III.2.10.b, and III.2.11.b.
- Determination of the Risk Profile Factor Rating
The determination of the Risk Profile factor rating is carried out in the following steps:
a) Determination of the Risk rating for each Risk, referring to number 3);
b) Determination of composite inherent Risk rating and composite Risk Management implementation quality rating, considering the significance of each Risk to the overall Risk Profile;
c) Determination of the Risk Profile factor rating based on the results of the Risk rating determination as referred to in letter a) and the composite inherent Risk rating and composite Risk Management implementation quality rating as referred to in letter b) based on comprehensive and structured analysis results, considering the significance of each Risk to the overall Risk Profile.
The determination of ... The determination of the Risk Profile factor rating consists of 5 (five) ratings, namely rating 1, rating 2, rating 3, rating 4, and rating 5. A smaller Risk Profile factor rating order reflects a lower level of Risk faced by the Bank. The determination of the Risk Profile factor rating is conducted based on Appendix III.2.
b. Assessment of the Good Corporate Governance (GCG) Factor
-
The Good Corporate Governance factor assessment for Sharia Commercial Banks is an assessment of the quality of bank management in implementing 5 (five) Good Corporate Governance principles, namely transparency, accountability, responsibility, professionalism, and fairness. Good Corporate Governance principles and assessment focus on the implementation of these Good Corporate Governance principles refer to applicable Good Corporate Governance provisions for Sharia Commercial Banks, considering the characteristics and complexity of the bank's business.
-
Sharia Commercial Banks in assessing the Good Corporate Governance factor rating use parameters/indicators based on Appendix I.2.
-
In order to ensure the implementation of 5 (five) Good Corporate Governance principles as referred to in number 1), Sharia Commercial Banks must conduct periodic self-assessments that at least cover 11 (eleven) assessment factors for the implementation of Good Corporate Governance as regulated in applicable Good Corporate Governance provisions for Sharia Commercial Banks as follows:
a) Implementation of duties and responsibilities of the Board of Commissioners;
b) Implementation of duties and responsibilities of the Board of Directors;
c) Completeness and implementation of Committee duties;
d) Implementation of duties and responsibilities of the Sharia Supervisory Board;
e) Implementation of Sharia principles in fund collection activities...
fundraising and lending as well as service provision; f) Handling conflicts of interest; g) Implementation of the compliance function; h) Implementation of the internal audit function; i) Implementation of the external audit function; j) Maximum Lending Limit (BMPD); and k) Transparency of the financial and non-financial conditions of Sharia Commercial Banks, reports on the implementation of Good Corporate Governance, and internal reporting.
4) The determination of the Good Corporate Governance factor rank
is based on an analysis of: (i) the implementation of Good Corporate Governance principles as referred to in item 1); (ii) the adequacy of governance over the structure, process, and results of Good Corporate Governance implementation at the bank; and (iii) other information related to Good Corporate Governance based on relevant data and information.
5) The determination of the Good Corporate Governance factor rank
categorizes into 5 (five) ranks, namely rank 1, rank 2, rank 3, rank 4, and rank 5. A smaller Good Corporate Governance factor rank reflects better implementation of Good Corporate Governance. The determination of the Good Corporate Governance factor rank is conducted with reference to Appendix III.3.
6) Sharia Commercial Banks conduct periodic self-assessments of the implementation of Good Corporate Governance in accordance with the assessment period for the Bank's Health Level and, when necessary, Sharia Commercial Banks are required to update their self-assessments of the implementation of Good Corporate Governance as regulated in the Financial Services Authority Regulation regarding the Assessment of the Health Level of Sharia Commercial Banks and Sharia Business Units. The self-assessment of the implementation of Good Corporate Governance is conducted by
compiling an analysis of the adequacy and effectiveness of the implementation of Good Corporate Governance principles, documented in the Self-Assessment Worksheet for the Implementation of Good Corporate Governance as referred to in Appendix II, with the following steps:
a) collecting relevant data and information to assess the adequacy and effectiveness of the implementation of Good Corporate Governance principles, such as management data, ownership, business group structure, minutes of meetings of the Board of Commissioners, Board of Directors, Sharia Supervisory Board and Committees, and reports including annual reports, special reports from the Director overseeing the Compliance Function, reports related to the duties of the Internal Audit Supervisory Board (SKAI), public accountant reports specifically comments regarding the reliability of the bank's internal control system, reports on the self-assessment of the Bank's Health Level, business plan and realization reports, Board of Commissioners reports, Sharia Supervisory Board supervision results reports, and other reports related to the implementation of other Good Corporate Governance principles; b) assessing the adequacy and effectiveness of the implementation of Good Corporate Governance principles comprehensively and structured across the three governance aspects, namely governance structure, governance process, and governance outcome, while considering the principle of significance or materiality; and c) concluding positive and negative factors from each governance aspect.
6) In concluding the positive and negative factors of the three governance aspects, the following must be considered among others:
a) The assessment must focus on the substance of Good Corporate Governance implementation and not merely on the fulfillment of formal procedural requirements (normative). In this Good Corporate Governance assessment, it is also necessary to...
necessary to consider among others whether policies and procedures have been implemented well. Thus, in conducting the assessment of Good Corporate Governance implementation, Sharia Commercial Banks must not only answer questions with yes/no but must disclose the substance of those answers. As an example, in assessing the fulfillment of organizational organ completeness in the Sharia Commercial Bank's organizational structure, it is also necessary to assess whether those organs function as intended. b) Assessments of governance structure, governance process, and governance outcome must be an integrated, comprehensive, and structured series of assessments so that the conclusion of the governance outcome assessment reflects the extent of governance process implementation and adequate support from governance structure, which needs to be tested and proven further. Example, there is a problem in governance structure, namely the absence of a Director overseeing the compliance function. The absence of a Director overseeing the compliance function results in a weakness in the governance process in implementing the bank's compliance function, namely the absence of preventive measures against policies and/or decisions of the Bank's Board of Directors in the financing field that deviate from applicable regulations. Furthermore, the weakness in the governance process impacts the governance outcome in the form of violations of the Maximum Lending Limit (BMPD) regulations. c) Assessments of governance outcome include both qualitative and quantitative aspects, among others:
(1) bank performance such as profitability, efficiency, and capital adequacy...
capital adequacy;
(2) increase/decrease in compliance with applicable regulations and resolution of problems faced by the bank such as fraud, violations of the Maximum Lending Limit (BMPD), violations of regulations related to bank reporting to the Financial Services Authority. In this regard, Sharia Commercial Banks must consider whether such violations occur repeatedly and/or the materiality/significance of the problems to the bank's performance both currently and in the future. Furthermore, Sharia Commercial Banks must also consider that the assessment covers the follow-up actions that the bank needs to take to address current problems and anticipate the emergence of problems in the future. d) In determining the Good Corporate Governance Factor Rank, Sharia Commercial Banks must consider its alignment with the significance level of the problems faced as obtained from the conclusion of the assessment of the implementation of Good Corporate Governance at the Sharia Commercial Bank. e) Assessments of governance structure, governance process, and governance outcome must be supported by adequate data/information and documents.
7) Based on the Self-Assessment Worksheet for the Implementation of Good Corporate Governance above, the Sharia Commercial Bank formulates the conclusion of the self-assessment of the implementation of Good Corporate Governance and determines the Good Corporate Governance Factor Rank with reference to the Good Corporate Governance Factor Rank Matrix as referred to in Appendix III.3.
In conducting the assessment of the implementation of Good Corporate Governance...
Governance, the Sharia Commercial Bank must consider the assessment of the Quality of Risk Management Implementation in the context of the Risk Profile assessment, given that the Good Corporate Governance factor generally has a connection with the Quality of Risk Management Implementation. Generally, good implementation of Good Corporate Governance ensures good risk management as reflected in the assessment of the Quality of Risk Management Implementation.
8) Subsequently, the Sharia Commercial Bank creates the Good Corporate Governance Factor Assessment as referred to in Appendix IV.4, which at least includes:
a) Good Corporate Governance Factor Rank and Rank Definition; and b) Analysis of the Good Corporate Governance factor, including:
(1) identification of problems in the form of weaknesses and their root causes; and (2) strengths of Good Corporate Governance implementation.
If the result of the self-assessment of the implementation of Good Corporate Governance yields a Good Corporate Governance Factor Rank of 3, 4, or 5, the Sharia Commercial Bank is required to compile and submit an action plan containing comprehensive and systematic improvement steps along with implementation time targets to the Financial Services Authority.
9) The Good Corporate Governance Factor Assessment as referred to in Appendix IV.4 must be signed by the Board of Directors of the Sharia Commercial Bank.
10) The Sharia Commercial Bank submits the Good Corporate Governance Factor Assessment both individually and on a consolidated basis as per Appendix IV.4 to the Financial Services Authority, accompanied by the Self-Assessment Worksheet for the Implementation of Good Corporate Governance as per Appendix II, as part of the self-assessment results of the Bank's Health Level...
Sharia Commercial Bank.
11) The Financial Services Authority conducts an assessment or evaluation of the self-assessment results of the implementation of Good Corporate Governance submitted by the Sharia Commercial Bank. If there is a material difference in the self-assessment results of the implementation of Good Corporate Governance by the Sharia Commercial Bank, namely resulting in a Good Corporate Governance Factor Rank different from the assessment or evaluation results conducted by the Financial Services Authority, the Sharia Commercial Bank must revise the self-assessment results of the implementation of Good Corporate Governance in accordance with the agreement reached in the prudential meeting. If there are still differences in the assessment results of the implementation of Good Corporate Governance, the result of the assessment conducted by the Financial Services Authority shall prevail.
12) Furthermore, if the result of the Good Corporate Governance Factor Rank assessment by the Financial Services Authority is classified as Rank 3, 4, or 5, the Financial Services Authority may request the Sharia Commercial Bank to submit an action plan containing comprehensive and systematic improvement steps along with implementation time targets.
13) If necessary, the Financial Services Authority may request the Sharia Commercial Bank to adjust the action plan already submitted by the Sharia Commercial Bank.
14) The action plan is submitted in accordance with the submission procedures as regulated in the provisions regarding the assessment of the Health Level of Sharia Commercial Banks and Sharia Business Units. However, the Sharia Commercial Bank may submit the action plan earlier, simultaneously with the submission of the Good Corporate Governance Factor Assessment Report.
15) The report on the implementation of the Good Corporate Governance action plan along with the completion time and obstacles...
obstacles/difficulties in resolution (if any) are submitted to the Financial Services Authority with reference to the submission procedures for the action plan implementation report as referred to in the provisions regarding the assessment of the Health Level of Sharia Commercial Banks and Sharia Business Units.
16) Documents related to the self-assessment of the implementation of Good Corporate Governance, including the Self-Assessment Worksheet for the Implementation of Good Corporate Governance and the Good Corporate Governance Factor Assessment Report, must be properly documented.
c. Assessment of the Profitability Factor
-
The assessment of the Profitability factor includes evaluation of Profitability performance, sources of Profitability, Profitability sustainability, Profitability management, and social function implementation. The assessment is conducted by considering the level, trend, structure, and stability of the Sharia Commercial Bank's Profitability, and comparing the Sharia Commercial Bank's performance with the peer group's performance, both through quantitative and qualitative aspect analysis.
In determining the peer group, the Sharia Commercial Bank needs to consider the business scale, characteristics, and/or complexity of the Sharia Commercial Bank's business as well as the availability of data and information held. The Sharia Commercial Bank assesses the Profitability factor using parameters/indicators with reference to Appendix I.3.
-
The determination of the Profitability factor rank is based on a comprehensive and structured analysis of the Profitability parameters/indicators as referred to in item 1) while considering the significance of each parameter/indicator and considering other problems affecting the Sharia Commercial Bank's Profitability.
-
The determination...
-
The determination of the Profitability factor rank categorizes into 5 (five) ranks, namely rank 1, rank 2, rank 3,
rank 4, and rank 5. A smaller Profitability factor rank reflects a better condition of the Sharia Commercial Bank's Profitability. The determination of the Profitability factor rank is conducted with reference to Appendix III.4. d. Assessment of the Capital Adequacy Factor
-
The assessment of the Capital Adequacy factor includes evaluation of capital adequacy and capital management adequacy. In calculating Capital Adequacy, the Sharia Commercial Bank refers to the applicable regulations regarding minimum capital adequacy requirements for Sharia Commercial Banks. Furthermore, in assessing capital adequacy, the Sharia Commercial Bank must also link capital adequacy with the Risk Profile. The higher the Risk, the greater the capital that must be provided to anticipate that Risk.
-
In conducting the assessment, the Sharia Commercial Bank needs to consider the level, trend, structure, and stability of Capital Adequacy while considering peer group performance and the adequacy of the Sharia Commercial Bank's Capital Management. The assessment is conducted using quantitative and qualitative parameters/indicators. In determining the peer group, the Sharia Commercial Bank needs to consider the business scale, characteristics, and/or complexity of the Sharia Commercial Bank's business as well as the availability of data and information held.
-
Parameters/indicators in assessing Capital Adequacy include:
a) Capital Adequacy
The assessment of the Sharia Commercial Bank's capital adequacy needs to be conducted comprehensively, at minimum covering:
(1) Level, trend, and composition of capital;
(2) Minimum Capital Adequacy Ratio considering Credit Risk, Market Risk, and Operational Risk with reference to...
to applicable regulations regarding minimum capital adequacy requirements for Sharia Commercial Banks; and (3) Capital adequacy linked to the Risk Profile. b) Capital Management Analysis of the Sharia Commercial Bank's capital management includes Capital Management and capital access capability. The Sharia Commercial Bank assesses the Capital Adequacy factor using parameters/indicators with reference to Appendix I.4.
4) The Capital Adequacy factor is determined based on a comprehensive and structured analysis of the Capital Adequacy parameters/indicators as referred to in item 3) while considering the significance of each parameter/
indicator and considering other problems affecting the Sharia Commercial Bank's Capital Adequacy.
5) The determination of the Capital Adequacy factor rank categorizes into 5 (five) ranks, namely rank 1, rank 2, rank 3,
rank 4, and rank 5. A smaller Capital Adequacy factor rank reflects a better capital condition. The determination of the Capital Adequacy factor rank is conducted with reference to Appendix III.5. e. Assessment of the Composite Health Level Rank
- The Composite Health Level Rank is determined based on a comprehensive and structured analysis of each factor's rank and considering the general principles of the Health Level Assessment of Commercial Banks. In conducting comprehensive analysis, the Bank also needs to consider the Bank's ability to face significant changes in external conditions.
- The determination of the Composite Rank categorizes into 5 (five) Composite Ranks, namely Composite Rank 1 (CR-1),
Composite Rank 2 (CR-2), Composite Rank 3 (CR-3), Composite Rank 4 (CR-4), and Composite Rank 5 (CR-5).
Order...
Order of Composite Ranks with smaller numbers reflects a healthier Bank condition. The Composite Rank is determined with reference to Appendix III.1.
3) The Financial Services Authority has the authority to downgrade the Composite Health Level Rank of the Bank if problems or violations are found that will significantly affect the Bank's operations and/or business continuity. Examples of problems or violations that have a significant influence include manipulation including window dressing and internal management disputes, which affect the Bank's operations and/or business continuity.
2. Procedures for Assessing the Health Level of Sharia Commercial Banks on a Consolidated Basis
a. Sharia Commercial Banks that exercise Control over Subsidiary Companies must conduct the Bank's Health Level assessment on a consolidated basis. The consolidated Bank Health Level assessment includes assessment of the factors: Risk Profile, Good Corporate Governance, Profitability, and Capital Adequacy. b. The determination of Subsidiary Companies that must be consolidated refers to the applicable regulations regarding the implementation of Risk Management on a consolidated basis for Banks exercising Control over Subsidiary Companies. In conducting consolidated assessment, the Bank must consider: (i) the materiality or significance of the Subsidiary Company's share to the consolidated Bank's share or performance; and/or (ii) the significance of the Subsidiary Company's problems to the Risk Profile, Good Corporate Governance, Profitability, and Capital Adequacy of the consolidated Bank.
c. The determination of the materiality or significance of the Subsidiary Company's share can be determined through the comparison of the Subsidiary Company's total assets to the consolidated Bank's total assets, or the significance of specific items in the Subsidiary Company's financial statements that affect the consolidated Bank's performance such as Risk-Weighted Assets (RWA), profitability, and capital. The determination of the significance of the Subsidiary Company's problems among others considers problems present in the Subsidiary Company...
Company and its impact on the performance or condition of the Bank on a consolidated basis. Example: problems related to the Subsidiary Company's business that can impact the consolidated Bank's Reputational Risk, Credit Risk, or Liquidity Risk, problems in governance, or weaknesses in the implementation of the Subsidiary Company's Risk Management. d. Parameters/indicators used in the individual assessment of the Bank's Health Level can be used by the Bank when assessing the Bank's Health Level on a consolidated basis. These parameters/indicators can be supplemented with other parameters/indicators as long as they are relevant to the business scale, characteristics, and complexity of the Bank on a consolidated basis. e. The consolidated health level assessment for Sharia Commercial Banks controlling Subsidiary Companies in the form of insurance companies is conducted by considering relevant qualitative and quantitative factors, among others the fulfillment of the insurance company's capital adequacy according to the requirements of the competent authority and the impact of Risks considered significant or material that affect the Risk Profile and the consolidated Bank's financial performance. f. In assessing the Bank's Health Level on a consolidated basis, the mechanism for determining ranks and categorizing each assessment factor's rank and determining the consolidated Bank's Composite Health Level Rank refers to the procedures for assessing the Bank's Health Level individually as referred to in item III.1. g. The assessment and determination of the Risk Profile factor on a consolidated basis is conducted by considering the following:
-
Analysis is conducted on the Risks of the Subsidiary Company considered significant or material in affecting the consolidated Bank's Risk Profile.
-
The significance or materiality of the Subsidiary Company's Risk among others can be assessed from the business scale, characteristics, and complexity of the Subsidiary Company's business, the Risk generated by the Subsidiary Company's business activities, and the impact generated on the consolidated Bank's Risk Profile...
consolidated.
-
The determination of the inherent Risk rank, the quality of Risk Management implementation, and the level of Risk of the Sharia Commercial Bank on a consolidated basis is conducted by considering the impact generated by the Subsidiary Company's Risk.
-
The determination of the Risk Profile factor rank for the Bank on a consolidated basis is conducted by considering the impact of all Subsidiary Company Risks on the consolidated Sharia Commercial Bank's Risk Profile.
h. The assessment and determination of the Good Corporate Governance factor rank on a consolidated basis is conducted by considering the following:
-
Assessment is conducted on the implementation problems of Good Corporate Governance at the Subsidiary Company considered to have a significant impact on the consolidated Bank's Good Corporate Governance.
-
The Good Corporate Governance assessment factors of the Subsidiary Company used for the assessment of the implementation of Good Corporate Governance principles on a consolidated basis are determined by considering the business characteristics of the Subsidiary Company and supported by adequate data and information.
-
The determination of the Good Corporate Governance factor rank for the Sharia Commercial Bank on a consolidated basis is conducted by considering the impact of the Subsidiary Company's Good Corporate Governance implementation.
i. The assessment and determination of the Profitability and Capital Adequacy factor ranks on a consolidated basis is conducted based on a comprehensive and structured analysis of specific Profitability and Capital Adequacy parameters/indicators resulting from consolidated financial statements and other financial information, considering the following:
-
Assessment is conducted on the Profitability and Capital Adequacy performance of the Subsidiary Company considered to have a significant impact on the consolidated Sharia Commercial Bank's Profitability and Capital Adequacy.
-
Assessment...
-
The assessment is conducted with reference to specific parameters/indicators applicable to the Bank on an individual basis, provided they are supported by adequate data or information. In conducting the assessment, Islamic Commercial Banks may add relevant parameters/indicators that correspond to the scale, characteristics, and complexity of the Subsidiary Company.
-
The determination of the rating for the Profitability factor and the Capital factor of the Islamic Commercial Bank on a consolidated basis is conducted by considering the impact of the Profitability and Capital performance of the Subsidiary Company.
IV. FOLLOW-UP ON HEALTH LEVEL ASSESSMENT
- The Board of Directors, Board of Commissioners, and/or controlling shareholders of the Bank are required to submit an action plan to the Financial Services Authority containing improvement steps that the Bank must implement to address significant problems faced, along with the target completion time, if the Health Level assessment results of the Bank show:
a. one or more Health Level factor ratings are determined as 4 or 5; b. the composite Health Level rating of the Bank is determined as 4 or 5; and/or
c. the composite Health Level rating of the Bank is determined as 3, but there are significant problems that need to be addressed so as not to disrupt the Bank's business continuity.
- The action plan as referred to in item 1 includes, among others, actions to:
a. improve the implementation of the Bank's Risk Management with concrete improvement steps and target completion times. For example, in a Bank with a high Credit Risk level, the Bank can lower the Credit Risk level by improving weaknesses in the implementation of Credit Risk Management and/or lowering the inherent Credit Risk exposure; b. improve the implementation of Good Corporate Governance with concrete improvement steps and target completion times;
c. improve the Bank's financial performance, including increasing efficiency if the Bank experiences Profitability problems; and/or
d. add cash capital from the Bank's shareholders and/or other parties if the Bank experiences Capital insufficiency problems.
The Bank is required to report the follow-up results of the implementation of the action plan to the Financial Services Authority no later than 10 (ten) working days after the target completion time of the action plan and/or 10 (ten) working days after the end of the month and conducted monthly if there are significant problems so that the completion of the action plan cannot be done on time. The Financial Services Authority may request the Bank to improve the action plan if necessary. In the event that the deadline for submitting the action plan based on the self-assessment results falls on a holiday, the action plan based on the Bank's Health Level self-assessment results is submitted on the next working day.
V. REPORTING
-
The Bank is required to submit the results of its self-assessment of the Bank's Health Level on an individual basis to the Financial Services Authority no later than July 31 for the Health Level assessment of the Bank at the end of June and January 31 for the Health Level assessment of the Bank at the end of December.
-
Islamic Commercial Banks that control a Subsidiary Company are required to submit the results of their self-assessment of the Bank's Health Level on a consolidated basis to the Financial Services Authority no later than August 15 for the Health Level assessment of the Bank at the end of June and no later than February 15 for the Health Level assessment of the Bank at the end of December.
-
In the event that the deadline for submitting the Bank's Health Level self-assessment results falls on a holiday, the Bank's Health Level self-assessment results are submitted on the next working day.
-
The Bank is required to immediately update the self-assessment of the Bank's Health Level and submit it to the Financial Services Authority, among others, in the event that the Bank's financial condition deteriorates, the Bank faces problems such as Liquidity Risk or Capital Risk, or other conditions that the Financial Services Authority deems necessary to update the Bank's Health Level assessment.
-
The self-assessment report on the Bank's Health Level and/or the update of the self-assessment report on the Bank's Health Level is submitted to the Financial Services Authority, at the address:
a. Sharia Banking Department, Radius Prawiro Tower, Jl. M.H. Thamrin No. 2, Jakarta 10350, for Banks with their headquarters in the working area of the Financial Services Authority Headquarters; or b. Local Financial Services Authority Office, for Banks with their headquarters outside the working area of the Financial Services Authority Headquarters.
- The self-assessment report on the Bank's Health Level is submitted using the report format as referred to in Appendix IV.
VI. OTHERS
Appendix I, Appendix II, Appendix III, and Appendix IV constitute a unity and an inseparable part of this Financial Services Authority Circular.
VII. CLOSING
With the implementation of this Financial Services Authority Circular, then:
a. Bank Indonesia Circular No. 9/24/DPbS dated October 30, 2007 regarding the Health Level Assessment System of Islamic Commercial Banks Based on Sharia Principles is declared invalid. b. Letter F regarding Self-Assessment of GCG Implementation item 3, item 4, item 5, item 6, item 7, item 8, item 9, item 10, and item 11 in Bank Indonesia Circular No. 12/13/DPbS dated April 30, 2010 regarding the Implementation of Good Corporate Governance for Islamic Commercial Banks and Islamic Business Units is declared invalid for Islamic Commercial Banks.
The Health Level Assessment of the Bank in these regulations is effectively implemented since July 1, 2014, namely for the Health Level assessment of the Bank at the end of June 2014.
The provisions in this Financial Services Authority Circular take effect on the date of determination.
To ensure that everyone knows, order the announcement of this Financial Services Authority Circular by placing it in the State Gazette of the Republic of Indonesia.
Determined in Jakarta on June 11, 2014
EXECUTIVE HEAD
BANKING SUPERVISOR,
Signed,
NELSON TAMPUBOLON
STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 51 DATED JUNE 27 YEAR Copy in accordance with the original Legal Director 1 Legal Department, Signed, Tini Kustini
APPENDIX I
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 10 /SEOJK.03/2014
REGARDING
THE ASSESSMENT OF THE HEALTH LEVEL OF ISLAMIC COMMERCIAL BANKS AND ISLAMIC BUSINESS UNITS
MATRIX OF PARAMETERS/INDICATORS FOR ASSESSING THE HEALTH LEVEL OF THE BANK
APPENDIX I.1: Risk Profile Factor Assessment
APPENDIX I.1.a: Credit Risk Assessment
APPENDIX I.1.b: Market Risk Assessment
APPENDIX I.1.c: Liquidity Risk Assessment
APPENDIX I.1.d: Operational Risk Assessment
APPENDIX I.1.e: Legal Risk Assessment
APPENDIX I.1.f: Strategic Risk Assessment
APPENDIX I.1.g: Compliance Risk Assessment
APPENDIX I.1.h: Reputational Risk Assessment
APPENDIX I.1.i: Yield Risk Assessment
APPENDIX I.1.j: Investment Risk Assessment
APPENDIX I.2: Good Corporate Governance Factor Assessment
APPENDIX I.3: Profitability Factor Assessment
APPENDIX I.4: Capital Factor Assessment
APPENDIX I.1
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 10/SEOJK.03/2014
REGARDING
THE ASSESSMENT OF THE HEALTH LEVEL OF ISLAMIC COMMERCIAL BANKS AND ISLAMIC BUSINESS UNITS RISK PROFILE FACTOR ASSESSMENT
APPENDIX I.1.a
Matrix of Parameters/Indicators for Credit Risk Assessment
- Composition
Asset Portfolio Composition including the type of contract used and Concentration Level
a. Financing to Core Debtors
Total Financing
- Financing to Core Debtors includes financing to third parties other than Banks, whether individual debtors or groups, outside related parties, with the following criteria:
a) for Banks with total assets less than or equal to Rp1 trillion, includes financing to 10 largest debtors b) for Banks with total assets greater than Rp1 trillion but less than or equal to Rp10 trillion, includes financing to 15 largest debtors/groups c) for Banks with total assets greater than Rp10 trillion, includes financing to 25 largest debtors/groups
- Total Financing is financing to third parties other than Banks.
b. Financing per Economic Sector
Total Financing
-
Financing per Economic Sector is financing to Banks and third parties other than Banks per economic sector category as regulated in the applicable provisions regarding the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units.
-
Total Financing is financing to Banks and third parties other than Banks.
A. Risk...
c. Financing per Portfolio Category
Total Financing
-
Financing per Portfolio Category is Financing to Banks and third parties other than Banks based on portfolio categories as regulated in the applicable provisions regarding the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units.
-
Total Financing is financing to Banks and third parties other than Banks.
d. Financing per Contract Category
(Debt and Profit Sharing)
Total Financing
-
Financing per Debt Contract Category is Financing to third parties other than Banks using Buy-Sell contracts (murabahah, istishna, and salam), Loans (qardh), and Leasing (ijarah).
-
Financing per Profit Sharing Contract Category is Financing to third parties other than Banks using profit sharing contracts (mudharabah and musyarakah including mudharabah mutanaqisah)
-
Total Financing is financing to third parties other than Banks.
- Quality
Fund Provisioning and
Reserve Adequacy
a. Low Quality Assets and TRA
Total Gross Assets and TRA
- Low Quality Assets are all Bank assets, both productive and non-productive, that have a quality of special attention, doubtful, and bad according to applicable provisions regarding Asset Quality, including restructured financing of good quality, AYDA of good quality, abandoned property of good quality, and temporary equity participation of good quality.
A. Risk...
-
Administrative Account Transactions (TRA) consist of irrevocable LCs, guarantees provided, and withdrawal allowances (commitments).
-
Low Quality TRA is TRA that has a quality of special attention, doubtful, and bad according to applicable provisions regarding the Assessment of Asset Quality for Islamic Commercial Banks and Islamic Business Units.
-
Total Gross Assets is total assets gross, consisting of total assets, total CKPN, and non-productive PPA.
-
Calculation of CKPN and PPA refers to applicable provisions and accounting standards.
b. Problematic Assets and TRA
(Total Gross Assets and TRA)
Low Quality
-
Problematic Assets are all Bank assets, both productive and non-productive, that have a quality of doubtful and bad according to applicable provisions regarding Asset Quality.
-
Problematic TRA is TRA that has a quality of doubtful and bad according to applicable provisions regarding the Assessment of Asset Quality for Islamic Commercial Banks and Islamic Business Units.
-
Low Quality Total Gross Assets is total assets gross, consisting of total assets, total CKPN, and non-productive PPA that have a quality of special attention, doubtful, and bad, including restructured financing of good quality, AYDA of good quality,
A. Risk...
abandoned property of good quality, and temporary equity participation of good quality.
- Low Quality TRA is TRA that has a quality of special attention, doubtful, and bad according to applicable provisions regarding the Assessment of Asset Quality for Islamic Commercial Banks and Islamic Business Units.
c. Low Quality Financing
Total Financing
-
Low Quality Financing is all financing to third parties other than Banks that has a quality of special attention, doubtful, and bad, including restructured financing of good quality.
-
Total Financing is financing to third parties other than Banks.
d. Problematic Financing
Total Financing
-
Problematic Financing is financing to third parties other than Banks classified as doubtful and bad.
-
Total Financing is financing to third parties other than Banks.
e. Problematic Financing minus
Problematic Financing CKPN
Total Financing after minus CKPN
-
Problematic Financing is financing to third parties other than Banks classified as doubtful and bad.
-
Problematic Financing CKPN is Impairment Loss Reserve for financing classified as doubtful and bad.
-
Calculation of CKPN refers to applicable provisions and accounting standards.
-
Total Financing is financing to third parties other than Banks.
A. Risk...
f. Problematic Financing per Economic Sector
Total Problematic Financing
-
Problematic Financing per Economic Sector is financing to third parties other than Banks per economic sector category as regulated in the applicable provisions regarding the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units that are classified as doubtful and bad per economic sector.
-
Total Problematic Financing is financing to third parties other than Banks that are classified as doubtful and bad per economic sector.
g. Total Restructured Financing
Total Financing
-
Total Restructured Financing is total financing to third parties other than Banks that is restructured, including financing with good and special attention quality as regulated in the applicable provisions regarding restructuring.
-
Total financing is financing to third parties other than Banks
A. Risk...
h. Restructured Financing with Good and Special Attention Quality Total Restructured Financing
-
Total Restructured Financing with Good and Special Attention Quality is total financing to third parties other than Banks that is restructured with good and special attention quality as regulated in the applicable provisions regarding restructuring.
-
Total Restructured Financing is financing to third parties other than Banks that is restructured.
i. Acquired Assets
Total Assets
-
Acquired Assets according to applicable provisions regarding Asset Quality.
-
Total Assets is total assets in the Balance Sheet as stated in the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units.
j. CKPN on Balance Sheet Productive Assets +
PPA on Productive Assets TRA
PPA Mandatory Formed on
Balance Sheet Productive Assets and TRA
-
Calculation of CKPN refers to applicable provisions and accounting standards.
-
Calculation of mandatory PPA formation on balance sheet productive assets and TRA refers to applicable provisions regarding Asset Quality.
k. All CKPN and PPA that have been formed
Assets and TRA with
Low Quality
-
Calculation of CKPN refers to applicable provisions and accounting standards.
-
Calculation of mandatory PPA formation refers to applicable provisions regarding Asset Quality.
-
Low Quality Assets are all Bank assets, both productive and non-productive, that have a quality of special attention, doubtful, and bad according to applicable provisions regarding Asset Quality, including restructured financing of good quality, AYDA of good quality, abandoned property of good quality, and temporary equity participation of good quality.
-
Low Quality TRA is TRA that has a quality of special attention, doubtful, and bad according to applicable provisions regarding the Assessment of Asset Quality for Islamic Commercial Banks and Islamic Business Units.
A. Risk...
l. All CKPN and PPA
that have been formed
Balance Sheet Productive Assets, TRA Productive Assets and Non-Productive Assets with Low Quality
-
Calculation of CKPN refers to applicable provisions and accounting standards.
-
Calculation of mandatory PPA formation refers to applicable provisions regarding Asset Quality.
-
Balance Sheet Productive Assets, TRA Productive Assets and Non-Productive Assets with Low Quality are balance sheet productive assets, TRA productive assets and non-productive assets that have a quality of special attention, doubtful, and bad according to applicable provisions regarding Asset Quality.
A. Risk...
m. CKPN on Financing
Total Financing
-
CKPN on financing is CKPN formed on financing given to third parties other than Banks.
-
Total Financing is financing to third parties other than Banks.
n. Low Quality Productive Assets
(Earning Asset at Risk)
Productive Assets (Earning Assets)
-
Low Quality Productive Assets are productive assets that are grouped based on their quality and weighted with a certain percentage value (Multiplication Weight: DPK = 5%; KL = 15%; D = 50% and M = 100%).
-
Productive Assets are as referred to in the applicable provisions regarding the Assessment of Asset Quality for Islamic Commercial Banks and Islamic Business Units.
- Strategy
Fund Provisioning and
Source of
Fund Provisioning
a. Fund provisioning process, level of competition, and level of asset growth -
b. New strategies and products In this case, what is meant by new strategies and products is a change in the Bank's fund provisioning strategy or new product marketing that has the potential to increase Credit Risk exposure in the Bank.
c. Significance of fund provisioning
conducted indirectly by the Bank
Fund provisioning conducted indirectly by the Bank includes, among others, fund provisioning in cooperation with third parties or purchasing financing from other Banks/financial institutions.
A. Risk...
- External Factors Changes in economic conditions, changes in technology, or regulations that affect the level of yield, exchange rates, debtor business cycles, and impact on the debtor's ability to repay its obligations. Quite clear.
authority and responsibility of the Board of Commissioners and the Board of Directors.
2 The Risk Management Framework includes evaluation against: (i) Risk Management strategy that is aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting.
3 Risk Management Process, Information Systems, and Human Resources includes evaluation against: (i) process of identification, measurement, monitoring, and control of Risk; (ii) adequacy of Risk Management information systems; and (iii) adequacy of quantity and quality of human resources in supporting the effectiveness of the Risk management process.
4 Risk Control System includes evaluation against: (i) adequacy of the Internal Control System and (ii) adequacy of review by independent parties (independent review) in the Bank both by the Risk Management Work Unit (SKMR) and by the Internal Audit Work Unit (SKAI).
*) It is a minimum parameter/indicator and the Bank can add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 months for quantitative parameters/indicators.
APPENDIX...
APPENDIX I.1.b
Matrix of Parameters/Indicators for Market Risk Assessment
- Assessment of Volume
and Portfolio Composition
a. Trading Assets and Forward Claims
Total Assets
-
Trading Assets are securities owned with the measurement category of traded (trading).
-
Forward Claims are claims obtained from Mark to Market (MTM) profits from forward transactions.
-
Total Assets is total assets in the Balance Sheet as stated in the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units.
b. Trading Liabilities and
Forward Liabilities
Total Liabilities and Equity
-
Trading Liabilities are securities issued with the measurement category of traded (trading).
-
Forward Liabilities are liabilities caused by losses (MTM) from forward transactions.
-
Total Liabilities and Equity are bank liabilities and equity in the Balance Sheet as stated in the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units.
c. Potential profit/loss from
Trading Assets and Forward Claims
Operational Income
- Potential Profit/Loss from financial assets is the total profit/loss (net) from:
a) increase/decrease in fair value (MTM) of securities; b) increase/decrease in fair value (MTM) of other financial assets;
A. Risk...
c) financial liabilities decrease/increase in fair value (MTM); and d) change in fair value (MTM) on forwards and others.
- Operational Income is all income obtained by the Bank from its operational activities.
d. Potential profit/loss from Forward Assets
Operational Income
- Potential Profit/Loss from financial assets is the total profit/loss (net) from:
a) increase/decrease in fair value (MTM) of securities; b) increase/decrease in fair value (MTM) of other financial assets; c) financial liabilities decrease/increase in fair value (MTM); and d) change in fair value (MTM) on forwards and others.
- Operational Income is all income obtained by the Bank from its operational activities.
e. Total Forward
Total Assets
-
Total Forward is all forward transactions owned by the Bank.
-
Total Assets is total assets in the Balance Sheet as stated in the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Business Units.
f. PDN
Total Capital
- Net Foreign Exchange Position (PDN) is a number that is the sum of the absolute values for the sum of:
A. Risk...
a) net difference of assets and liabilities in the balance sheet for each foreign currency; and b) net difference of claims and liabilities, both of which are commitments or contingencies in administrative accounts for each foreign currency which are all expressed in rupiah and in accordance with applicable provisions regarding Net Foreign Exchange Position.
- Total Capital is total capital according to applicable provisions regarding Net Foreign Exchange Position.
g. PDN in Major Currency (USD)
Total Capital
- Net Foreign Exchange Position (PDN) in major currency is a number that is the sum of the absolute values for the sum of:
a) net difference of assets and liabilities in the balance sheet for each foreign currency; and b) net difference of claims and liabilities, both of which are commitments or contingencies in administrative accounts for each foreign currency which are all expressed in major currency (USD) in accordance with applicable provisions regarding Net Foreign Exchange Position.
- Total Capital is total capital according to applicable provisions regarding Net Foreign Exchange Position.
h. Equity Category AFS
Total Capital
- Available for Sale (AFS) Category Equity is participation with the criteria of the participation method measured at fair value
A. Risk...
through equity, the purpose of participation in the context of restructuring and others, groups of issuers other than insurance companies, and participation shares of less than 50%.
2) Total Capital is the total capital in accordance with the applicable regulations regarding Net Foreign Exchange Position.
i. Equity in the Context of
Financing Restructuring
Total Capital
- Equity in the Context of Financing Restructuring is participation where the purpose of participation is in the context of financing restructuring.
- Total Capital is the total capital in accordance with the applicable regulations regarding Net Foreign Exchange Position.
j. Long-Term Financial Liabilities with Fixed Yield Long-Term Financial Assets with Fixed Yield
- Long-Term Financial Liabilities with Fixed Yield are financial liabilities with a fixed yield for the long term (remaining maturity of one year or more).
- Long-Term Financial Assets with Fixed Yield are financial assets with a fixed yield for the long term (remaining maturity of one year or more).
- Potential Loss
(Potential Loss) from
Benchmark Interest Rate Risk in the Banking Book (BRBB) BRBB Exposure Based on Gap Report (Income Perspective and Economic Value Perspective) A gap report is a report that presents asset, liability, and administrative account items that are sensitive to changes in benchmark interest rates to be mapped into a specific time scale. Mapping is done based on the remaining time to maturity for instruments with fixed yield agreements and A. Risk...
based on the remaining time until the next yield adjustment for instruments with floating yield agreements (volatile). Furthermore, the gap report format is prepared by the Bank either contractually or by considering behavioral aspects of the adjustment of the Bank's assets or liabilities. The gap report can be used by the Bank to measure BRBB exposure from both the income (earnings perspective) and economic value (economic value perspective) perspectives. Next, the Bank must ensure that its yield income and capital are able to absorb potential losses due to BRBB exposure. Potential Loss (Unrealized Loss) Securities in the AFS Category Total Capital
- Potential Loss (Unrealized Loss) Securities with portfolio category (AFS/Available for Sale);
- Total Capital is the total capital in accordance with the applicable regulations regarding Net Foreign Exchange Position.
- Business Strategy and Policy
3.1 Trading Strategy a. Characteristics of Trading Bank trading activities generally can be distinguished into activities for own interest (proprietary trading), in the context of market formation (market making), or at the request of customers or brokerage activities (brokering) which have different levels of Inherent Risk.
b. Bank's Market Position in the Industry The Bank's position in the market can be distinguished into major players A. Risk...
or active (market player/market maker), or small players (niche player).
c. Complexity of Trading Products/Instruments
Analysis of the complexity of products owned by the Bank currently or planned to be issued, whether they are classified as complex instruments or simple (plain vanilla) instruments such as fixed income instruments. d. Customer Characteristics Analysis of whether the Bank's main customers are large companies, Banks, or individual customers in relation to their sensitivity to changes in market factors.
3.2 Business Strategy
regarding benchmark interest rate risk in the banking book a. Characteristics of business activities that impact benchmark interest rate risk in the banking book and the Bank's main customer characteristics. Analysis of main business, products with option features, funding structure, and the significance of profit-sharing income that is sensitive to changes in interest rates. b. Bank's market position in the industry Analysis of the Bank's market position, particularly in the competition for cheap funds (savings and checking accounts).
c. Customer Characteristics
Analysis of the Bank's main customer characteristics and their sensitivity to changes in interest rates.
authority and responsibility of the Board of Commissioners and Directors.
2 The Risk Management Framework includes an evaluation of: (i) Risk Management strategy that is in line with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management including clear authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include an evaluation of: (i) the process of identification, measurement, monitoring, and control of Risk; (ii) the adequacy of the Risk Management information system; and (iii) the adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk management process. 4 Risk Control System includes an evaluation of: (i) the adequacy of the Internal Control System and (ii) the adequacy of review by independent parties (independent review) in the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank can add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is done per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX I.1.c
Matrix of Parameters/Indicators for Liquidity Risk Assessment
- Composition
of Assets,
Liabilities, and
Administrative
Account
Transactions a. Total Liquid Assets
Total Assets
-
Total Liquid Assets are Primary Liquid Assets and Secondary Liquid Assets.
-
Primary Liquid Assets are very liquid assets to meet liquidity needs for third-party fund withdrawals and maturing liabilities, consisting of:
a) Cash; b) Placements at Bank Indonesia; c) Placements at other banks; d) Securities categorized as available for sale (Available for Sale/AFS) or trading; and e) All government sukuk securities (government sukuk) categorized as trading and AFS that have high quality, are traded in active markets, and have a remaining maturity of 1 year or less.
-
Secondary Liquid Assets are a number of liquid assets with lower quality
to meet liquidity needs for third-party fund withdrawals and maturing liabilities, consisting of:
a) government sukuk securities (government sukuk) categorized as trading and AFS with good quality, traded in active markets, and having a remaining maturity of more than 1 year but less than 5 years; b) government sukuk securities (government sukuk) categorized as HTM and having a remaining maturity of up to 1 year; and c) government sukuk securities (government sukuk) categorized as trading and AFS and having a remaining maturity of more than 5 years, with a 25% haircut value. A. Risk...
-
Total Assets are total assets in the Financial Position Report as stated in
the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Banking Units. b. Total Liquid Assets Short-Term Funding
-
Total Liquid Assets are Primary Liquid Assets and Secondary Liquid Assets.
-
Short-Term Funding is all third-party funds that do not have a maturity and/or third-party funds that have a maturity of 1 year or
less.
c. Short-Term Assets
Short-Term
Liabilities
-
Short-Term Assets are liquid assets of less than 3 months other than cash,
placements at BI (SBIS) and SBSN in the maturity profile report as referred to in the Islamic Commercial Bank Periodic Report.
-
Short-Term Liabilities are liquid liabilities of less than 3 months other than cash,
placements at BI (SBIS) and SBSN in the maturity profile report as referred to in the Islamic Commercial Bank Periodic Report. d. Total Liquid Assets Non-Core Funding
-
Total Liquid Assets are Primary Liquid Assets and Secondary Liquid Assets.
-
Non-Core Funding is funding that according to the Bank is relatively unstable or tends not to remain in the Bank in both normal and crisis situations, including:
a) third-party funds with amounts above Rp 2 billion; b) all inter-bank transactions; and c) all borrowing (borrowing) but not including subordinated loans that are part of capital components. e. Primary Liquid Assets Short-Term Non-Core Funding
-
Primary Liquid Assets are very liquid assets to meet liquidity needs for third-party fund withdrawals and maturing liabilities, consisting of:
A. Risk...
a) Cash; b) Placements at Bank Indonesia; c) Placements at other banks; d) Securities categorized as available for sale (Available for Sale/AFS) or trading; and
2) All government sukuk securities (government sukuk) categorized as trading and AFS
that have high quality, are traded in active markets, and have a remaining maturity of 1 year or less.
3) Short-Term Non-Core Funding (Non Core Funding) is funding that according to the Bank is relatively unstable or tends not to remain in the Bank in both normal and crisis situations, including:
a) third-party funds with amounts above Rp 2 billion; b) all inter-bank transactions; and c) all borrowing (borrowing) but not including subordinated loans that are part of capital components with a maturity of less than 1 year. f. Non-Core Funding Total Funding
- Non-Core Funding (Non Core Funding) is funding that according to the Bank is relatively unstable or tends not to remain in the Bank in both normal and crisis situations, including:
a) third-party funds with amounts above Rp 2 billion; b) all inter-bank transactions; and c) all borrowing (borrowing) but not including subordinated loans that are part of capital components.
- Total Funding is all sources of funds obtained by the Bank, whether in the form of third-party funds or loans received.
A. Risk...
g. Non-Core Funding –
Total Liquid Assets
Total Assets – Liquid
Assets
- Non-Core Funding (Non Core Funding) is funding that according to the Bank is relatively unstable or tends not to remain in the Bank in both normal and crisis situations, including:
a) third-party funds with amounts above Rp 2 billion; b) all inter-bank transactions; and c) all borrowing (borrowing) but not including subordinated loans that are part of capital components.
- Total Liquid Assets are Primary Liquid Assets and Secondary Liquid Assets.
- Total Assets are total assets in the Financial Position Report as stated in
the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Banking Units.
The ratio is used to assess the Bank's dependence on Non-Core Funding. h. DPK insured by LPS DPK
- DPK insured by LPS is third-party funds with a nominal value of less than Rp 2 billion and insured by LPS.
- DPK is all third-party funds.
i. Significance of
Administrative Account
Transactions
(commitment and contingent liabilities)
Commitment and contingent liabilities are commitment and contingent liabilities contained in Administrative Account Transactions as regulated in regulations regarding the Monthly Monetary Stability and Financial System Report of Islamic Commercial Banks and Islamic Banking Units.
-
Concentration
of assets and
Liabilities a. Asset Concentration
Concentration on specific assets or providing funds to sectors not dominated by the Bank can disrupt liquidity positions if a default occurs. b. Liability Concentration Concentration on funding sources that tend to be sensitive to changes in yield so that it can cause problems in the Bank's liquidity position if a large amount of funds are withdrawn. A. Risk...
-
Vulnerability to
Funding Needs
The Bank's Vulnerability to funding needs and the Bank's ability to meet funding needs.
Indicators for assessing the Bank's funding needs in normal and crisis situations and the Bank's ability to meet funding needs, including through analysis of the maturity profile report, cash flow projections, and stress tests.
-
Access to
Sources of Funding
The Bank's Ability to obtain sources of funding under normal and crisis conditions.
Assessment is focused on the Bank's reputation for maintaining sources of funding, the condition of financing lines, the performance of access to sources of funding, and the support of the parent company or intra-group.
authority and responsibility of the Board of Commissioners and Directors.
2 The Risk Management Framework includes an evaluation of: (i) Risk Management strategy that is in line with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management including clear authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include an evaluation of: (i) the process of identification, measurement, monitoring, and control of Risk; (ii) the adequacy of the Risk Management information system; and (iii) the adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk management process. 4 Risk Control System includes an evaluation of: (i) the adequacy of the Internal Control System and (ii) the adequacy of review by independent parties (independent review) in the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank can add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is done per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX I.1.d
Matrix of Parameters/Indicators for Operational Risk Assessment
- Characteristics
and
Complexity of Business a. Business scale and Bank's organizational structure b. Complexity of business processes and diversity of products/services
c. Corporate action and new business development
d. Outsourcing
High business complexity and the level of product diversity of the Bank will cause complexity and variation of work processes both manually and automatically, so there is a potential for operational disruption/loss.
- Human Resources
a. Implementation of Human Resource
Management b. Failure due to Human Factors (Human Error) Ineffective human resource management can result in the potential for operational disruption/loss of the Bank.
- Information Technology
and Supporting
Infrastructure a. Complexity of Information Technology b. IT System Changes
c. IT System Vulnerability to threats
and IT attacks d. IT System Maturity e. IT System Failure f. Reliability of Supporting Infrastructure Information technology that is no longer adequate or insufficient supports the Bank's operational activities and/or management that is not effective and efficient can cause losses to the Bank.
- Fraud a. Internal Fraud
b. External Fraud
Fraud assessment is done against the frequency/materiality of fraud that has occurred in the previous assessment period, including potential fraud that can arise from weaknesses in A. Risk...
business aspects, HR, information technology, and external events.
5. External
Events
Frequency and materiality of external events that impact the Bank's operational activities External events such as terrorism, crime, pandemics, and natural disasters. The Bank's location and geographical conditions.
authority and responsibility of the Board of Commissioners and Directors.
2 The Risk Management Framework includes an evaluation of: (i) Risk Management strategy that is in line with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management including clear authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include an evaluation of: (i) the process of identification, measurement, monitoring, and control of Risk; (ii) the adequacy of the Risk Management information system; and (iii) the adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk management process. 4 Risk Control System includes an evaluation of: (i) the adequacy of the Internal Control System and (ii) the adequacy of review by independent parties (independent review) in the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank can add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is done per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX I.1.e
Matrix of Parameters/Indicators for Legal Risk Assessment
- Litigation Factors a. The nominal amount of claims or lawsuits
filed or the estimated losses that may be experienced by the Bank due to lawsuits compared to the Bank's capital. b. The amount of losses experienced by the Bank from a court decision that has obtained permanent legal force compared to the Bank's capital.
c. The basis of the lawsuits that occurred and the parties
sued/suing the Bank in a lawsuit filed as well as management's actions regarding a lawsuit filed. d. The possibility of similar lawsuits arising due to the existence of the same contract standards and the estimated total losses that may arise compared to the Bank's capital. Litigation can occur due to lawsuits or claims from third parties to the Bank or lawsuits or claims filed against third parties both through courts and outside courts. Lawsuits or claims on the basis generally cause costs that can harm the Bank's condition.
- Weakness Factors
of Agreements a. Failure to meet the validity requirements of the agreement. b. There are weaknesses in agreement clauses and/or failure to meet the requirements that have been agreed upon. Weaknesses in agreements made by the Bank are a source of problems or disputes at a later time that can cause potential Legal Risk for the Bank. A. Risk...
c. Understanding of the parties regarding
agreements, especially regarding Risks that exist in complex transactions and using terms that are difficult to understand or unusual for the general public. d. Failure to execute an agreement, either in whole or in part. e. Insufficient supporting documents related to agreements made by the Bank with third parties. f. Updating and review of the use of standard agreements by the Bank and/or independent parties. g. The choice of law for agreements made by the Bank and also the use of dispute resolution forums.
3. Factors
of Absence/Changes in Legislation a. The number and nominal value of the total products of the Bank that are not clearly regulated by legislation and such products tend to have a high level of complexity, compared to the capital owned by the Bank. The absence of legislation especially over products owned by the Bank or transactions made by the Bank will result in such products becoming disputes at a later time, so there is a potential for Legal Risk. A. Risk...
b. The use of standard agreements that have not been updated even though there have been changes in best practices or legislation.
authority and responsibility of the Board of Commissioners and Directors.
2 The Risk Management Framework includes an evaluation of: (i) Risk Management strategy that is in line with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management including clear authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include an evaluation of: (i) the process of identification, measurement, monitoring, and control of Risk; (ii) the adequacy of the Risk Management information system; and (iii) the adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk management process. 4 Risk Control System includes an evaluation of: (i) the adequacy of the Internal Control System and (ii) the adequacy of review by independent parties (independent review) in the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank can add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is done per position and trend over the last 12 months for parameters/indicators that are quantitative. In...
APPENDIX...
APPENDIX I.1.f
Matrix of Parameters/Indicators for Strategic Risk Assessment
- Alignment
of Strategy with
Business Environment
Conditions
Strategic goal setting considers internal and external factors of the Bank's business:
a. Internal factors, including:
- Vision, mission, and direction of business that the
Bank wants to achieve;
- Organizational culture, especially if
strategic goal setting requires organizational structure changes and adjustment of business processes;
- Organizational capability factors
including among others human resources, infrastructure, and information management systems; and
- Level of Risk tolerance, which is the level
of the Bank's financial ability to absorb
Risk. b. External factors, including:
- Macroeconomic conditions;
- Technological developments; and
- Level of business competition.
Parameter assessment is used to measure whether strategic goal setting by the Directors is supported by internal and external conditions of the Bank's business environment.
- High-Risk Strategy and
Low-Risk Strategy a. Low-risk strategy is a strategy where the Bank conducts business activities in market segments and customers that are known previously or provides products that are traditional so that the level of business growth tends to be stable and can be predicted. b. High-risk strategy is a strategy where the Bank plans to enter new business areas, whether market segments, products or services, or new customers.
- Bank's Business Position
Assessment is based on:
a. The market where the Bank conducts business activities; b. Competitors and competitive advantages;
c. Efficiency in conducting business activities;
d. Diversification of business activities and coverage of operational areas; and e. Macroeconomic conditions and their impact on the Bank's condition.
The level of success/failure of the Bank in achieving goals can be assessed based on the Bank's position in the market and competitive advantages owned, both against peer groups and the banking industry as a whole.
- Achievement of
Bank Business Plan (RBB)
Realization of RBB compared to RBB. The purpose of assessment is to measure how large the deviation of RBB realization is compared to the Bank's strategic plan.
authority and responsibilities of the Board of Commissioners and the Board of Directors.
2 The Risk Management Framework includes evaluation of: (i) Risk Management strategy aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices in supporting the effective implementation of Risk Management including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) adequacy of Risk Management information systems; and (iii) adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk Management process. 4 Risk Control System includes evaluation of: (i) adequacy of the Internal Control System and (ii) adequacy of independent review within the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank may add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX I.1.g
Matrix of Parameters/Indicators for Compliance Risk Assessment
- Type and
Significance of Violations
Committed a. Type of violation or non-compliance committed by the Bank. b. Type of violation or non-compliance regarding the implementation of Sharia principles committed by the Bank based on findings from the Sharia Supervisory Board (DPS) or the authority.
c. Amount of fine sanctions imposed on the Bank by the authority.
- The scope of violations includes violations of applicable regulations and commitments to the Financial Services Authority (OJK), including sanctions imposed for violations committed by the Bank.
- Violations or non-compliance regarding the implementation of Sharia principles include, among others, violations of fatwas issued by the National Sharia Board (DSN) or other standards generally applicable in the Sharia financial sector.
- Frequency
of Violations
Committed or
Track Record of Bank Non-compliance a. Type and frequency of the same violations found annually in the last 3 years. b. Significance of the Bank's follow-up on those findings. Frequency is more historical, looking at the Bank's compliance trend over the last 3 years to determine whether the type of violation committed is recurring or if significant improvements were not made to the error.
- Violations
of
Applicable
Business
Regulations or
Standards
Frequency of violations of regulations on certain financial transactions because they do not comply with generally applicable standards.
An example is violations of, among others, UCP, ICC, or other standards generally applicable in the financial sector.
A. Risk...
Certain Financial
Transactions and Risk tolerance (risk tolerance) and (ii) adequacy of active supervision by the Board of Commissioners, Board of Directors, and Sharia Supervisory Board including the implementation of authority and responsibilities of the Board of Commissioners, Board of Directors, and Sharia Supervisory Board. 2 The Risk Management Framework includes evaluation of: (i) Risk Management strategy aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices in supporting the effective implementation of Risk Management including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) adequacy of Risk Management information systems; and (iii) adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk Management process. 4 Risk Control System includes evaluation of: (i) adequacy of the Internal Control System and (ii) adequacy of independent review within the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank may add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX I.1.h
Matrix of Parameters/Indicators for Reputation Risk Assessment
-
Negative Reputation
Impact from
Bank Owners and
Related Companies a. Credibility of owners and related companies. b. Reputational events on owners and related companies.
Negative reputation/news impact from the Bank's owner and/or related companies with the Bank is one of the factors that can cause an increase in Reputation Risk at the Bank.
-
Business
Ethics
Violations
Ethics violations are visible, among others, through:
a. financial information transparency; and b. business cooperation with other stakeholders.
c. implementation of Sharia principles
In this case, what needs to be considered is if the Bank violates generally applicable business ethics/norms.
-
Complexity
of Products and
Business
Cooperation
Bank a. Number and level of customer usage of complex Bank products. b. Number and materiality of Bank's cooperation with business partners.
Complex products and cooperation with business partners can be exposed to Reputation Risk if there is misunderstanding of product/service usage or negative reporting on business partners, among others, in bancassurance and mutual fund products.
-
Frequency,
Materiality, and
Exposure of Negative
Bank Reporting a. Frequency and materiality of reporting. b. Type of media and scope of reporting.
Frequency, type of media, and materiality of negative reporting on the Bank, including Bank officials, are measured during the assessment period.
A. Risk...
-
Frequency and
Materiality of Customer
Complaints a. Frequency of customer complaints. b. Materiality of customer complaints.
Customer complaints are measured during the assessment period. authority and responsibilities of the Board of Commissioners and the Board of Directors.
2 The Risk Management Framework includes evaluation of: (i) Risk Management strategy aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices in supporting the effective implementation of Risk Management including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) adequacy of Risk Management information systems; and (iii) adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk Management process. 4 Risk Control System includes evaluation of: (i) adequacy of the Internal Control System and (ii) adequacy of independent review within the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). *) It is a minimum parameter/indicator and the Bank may add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX I.1.i
Matrix of Parameters/Indicators for Return Risk Assessment
- Composition of
Third-Party Funds
Non Core Deposit
Total Third-Party Funds
- Non Core Deposit are demand deposits, savings, and deposits that are not insured by the Deposit Insurance Corporation (nominal greater than Rp 2 billion).
- Total Third-Party Funds are all third-party funds other than bank funds in the form of demand deposits, savings, and deposits.
- Strategy and
Bank Performance in Generating
Profit/Income a. Debt-Based
Financing
Profit-Sharing-Based Financing
-
Debt-Based Financing is financing to the Bank and third parties other than Banks that have fixed returns, among others, murabahah, istishna, and ijarah (including musyarakah mutanaqisah).
-
Profit-Sharing-Based Financing is financing to the Bank and third parties other than Banks that have volatile returns, among others, mudharabah and musyarakah.
b. Problematic Financing
Total Financing
-
Problematic Financing is financing to third parties other than Banks that has poor, doubtful, and loss quality.
-
Total Financing is financing to third parties other than Banks.
c. Pre-Tax Profit
Average Total Assets
-
Pre-Tax Profit is profit as recorded in the Bank's current year income statement annualized.
Example: For the June position, accumulated profit per June position is calculated by dividing by 6 and multiplying by 12.
A. Risk...
-
Average Total Assets is the average total assets in the Financial Position Report as stated in the Monthly Monetary and Financial System Stability Report of Sharia Commercial Banks and Sharia Business Units.
Example: For the June position, it is calculated by summing the total assets position from January to June and dividing by 6.
- Customer Behavior
Third-Party
Funds a. Correlation between Mudharabah Deposit Return Rate and Deposit Interest Rate To understand the relationship between the interest rate of Conventional Banks and the return given by Sharia Banks to customers for 1-month deposits. b. Realization of Bank Deposit Profit According to Time Period versus Deposit Profit/Interest from Other Sharia Banks/Conventional Banks Comparing the profit given by the Bank over deposits for each time period against the profit given by other Sharia Banks or Conventional Banks for the same instrument.
c. Realization of Bank Deposit Profit
versus Other Instruments
Comparing the profit given by the Bank over deposits for each time period against the profit given by other instruments (sukuk, mutual funds, and bonds).
authority and responsibilities of the Board of Commissioners and the Board of Directors.
2 The Risk Management Framework includes evaluation of: (i) Risk Management strategy aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices in supporting the effective implementation of Risk Management including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting. 3 Risk Management Process, Information Systems, and Human Resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) adequacy of Risk Management information systems; and (iii) adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk Management process. 4 Risk Control System includes evaluation of: (i) adequacy of the Internal Control System and (ii) adequacy of independent review A. Risk...
by independent parties within the Bank either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI).
*) It is a minimum parameter/indicator and the Bank may add other parameters/indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 months for parameters/indicators that are quantitative.
APPENDIX...
APPENDIX 1.2
Matrix of Parameters/Indicators for Good Corporate Governance Factor Assessment Assessment of the Good Corporate Governance factor based on 5 (five) basic principles as regulated in the Good Corporate Governance regulations applicable to Sharia Commercial Banks and Sharia Business Units. In the TKS-RBBR Syariah assessment, it is evaluated within a governance system consisting of 3 (three) governance aspects, namely governance structure, governance process, and governance outcome. Parameter/Indicator assessment of the Good Corporate Governance factor regarding the implementation of Good Corporate Governance principles refers to the Good Corporate Governance regulations applicable to Sharia Commercial Banks and Sharia Business Units, considering the characteristics and complexity of the Bank's business. The implementation results of Good Corporate Governance principles of the Bank as regulated in the applicable regulations regarding Good Corporate Governance for Sharia Commercial Banks and Sharia Business Units is only one source of assessment for the Bank's Good Corporate Governance factor rating in the Bank Health Level assessment.
APPENDIX...
APPENDIX 1.3
Matrix of Parameters/Indicators for Rentability Factor Assessment
- Bank Performance
in Generating
Profit
(Rentability) a. Return on Asset (ROA)
Pre-Tax Profit
Average Total Assets
-
Pre-Tax Profit is profit as recorded in the Bank's current year income statement as regulated in the applicable regulations regarding the Monthly Monetary and Financial System Stability Report of Sharia Commercial Banks and Sharia Business Units, annualized.
Example: For the June position, accumulated profit per June position is calculated by dividing by 6 and multiplying by 12.
-
Average Total Assets is the average total assets in the Financial Position Report as stated in the Monthly Monetary and Financial System Stability Report of Sharia Commercial Banks and Sharia Business Units.
Example: For the June position, it is calculated by summing the total assets position from January to June and dividing by 6. b. Net Operation Margin (NOM) Income from Fund Disbursement After Profit Sharing – Operating Expenses Average Productive Assets
-
Income from Fund Disbursement After Profit Sharing is income from fund disbursement after deducting profit sharing expenses and operating expenses (annualized).
Income from fund disbursement includes all income from fund disbursement, while profit sharing expenses include all profit sharing expenses from fund gathering.
-
Operating Expenses are operating expenses including profit sharing expenses and bonuses (annualized).
-
Productive Assets...
-
Productive assets considered are assets that generate profit sharing, returns, and bonuses both in the balance sheet and in the TRA.
Average productive assets.
Example: For the June position, it is calculated by summing the total productive assets position from January to June and dividing by 6.
c. Net Return (NI)
Income from Fund Disbursement
After Profit Sharing –
(Returns and Bonuses)
Average Total Productive Assets
-
Income from Fund Disbursement After Profit Sharing – (Returns and Bonuses) is income from fund disbursement after deducting return expenses, returns, and bonuses (annualized).
Income from fund disbursement includes all income from fund disbursement, while return expenses include all profit sharing expenses, returns, and bonuses from fund gathering.
-
Productive assets considered are assets that generate profit sharing, returns, and bonuses both in the balance sheet and in the TRA.
Average productive assets.
Example: For the June position, it is calculated by summing the total productive assets position from January to June and dividing by 6. d. Profit Component Performance (Rentability) Actual vs. Bank Business Plan (RBB) Performance on profit components (rentability) including, among others, operating income, operating expenses, non-operating income, non-operating expenses, and net profit compared to the Bank's business plan. e. Profit Component Ability (Rentability) in Increasing Capital Capital is the Bank's ability to increase capital both internally and externally.
- Sources
Supporting
Rentability a. Income from Fund Disbursement
After Profit Sharing –
(Returns and Bonuses)
Average Total Assets
- Income from Fund Disbursement After Profit Sharing, Returns and Bonuses is income from fund disbursement after deducting return expenses, returns, and bonuses (annualized).
Income from fund disbursement includes all income from fund disbursement, while return expenses include all profit sharing expenses, returns, and bonuses from fund gathering.
- Average Total Assets is the average total assets in the Financial Position Report as stated in the Monthly Monetary and Financial System Stability Report of Sharia Commercial Banks and Sharia Business Units.
Example: For the June position, it is calculated by summing the total assets position from January to June and dividing by 6. b. Other Operating Income Average Total Assets
- Other Operating Income is other operating income annualized.
- Average Total Assets is the average total assets in the Financial Position Report as stated in the Monthly Monetary and Financial System Stability Report of Sharia Commercial Banks and Sharia Business Units.
Example: For the June position, it is calculated by summing the total assets position from January to June and dividing by 6.
c. Overhead
Expenses
Average Total Assets
- Overhead expenses are all operational costs that are not profit sharing expenses (annualized) including costs:
a) Asset depreciation/amortization; b) Labor costs; c) Education and training; d) Insurance premiums; e) Losses due to Operational Risk; f) Research and development; g) Rent; h) Promotion; i) Taxes (excluding income tax); j) Maintenance and repair; k) Goods and services; and l) Others.
- Average Total Assets is the average total assets in the Financial Position Report as stated in the Monthly Monetary and Financial System Stability Report of Sharia Commercial Banks and Sharia Business Units.
Example: For the June position, it is calculated by summing the total assets position from January to June and dividing by 6. d. Provisioning Expenses Average Total Assets
- Provisioning expenses are all costs incurred for provisioning in the form of Financial Asset Impairment Losses & Non-Productive NPLs (annualized).
- Average Total Assets is the average total assets in the...
Financial Position as stated in the Monthly Monetary Stability and Financial System Report of Sharia Public Banks and Sharia Business Units.
Example: For the position of June, it is calculated by summing the total asset positions from January to June divided by 6. e. Operating Expenses Operating Income
- Operating Expenses are operating expenses including profit-sharing and bonuses (annualized).
- Operating Income is income from fund disbursement.
- Stability
components that support
Profitability a. Core ROA =
Primary Core Net Income - Operating
Discretionary Items
Average Total Assets
- Primary Core Net Income is primary core Income minus primary core expense (annualized).
- Primary Core Income is income from fund disbursement after profit-sharing, remuneration, and bonuses plus fee-based income (annualized).
- Primary Core Expense is overhead expenses, namely operating expenses other than profit-sharing, remuneration, and bonuses, and impairment losses (annualized).
- Operating Discretionary Items are impairment losses (annualized).
- Average Total Assets is the average total assets in the Financial Position Statement as stated in the Monthly Monetary Stability and Financial System Report of Sharia Public Banks and Sharia Business Units.
Example: For the position of June, it is calculated by summing the total asset positions from January to June divided by 6. b. Profitability Prospects...
b. Future profitability prospects are quite clear.
4. Management
of Profitability
Bank's ability to manage profitability
Quite clear.
5. Implementation
of Social Functions by the Bank
Bank's role in implementing social functions
To assess the Bank's role in implementing its social function through the receipt and disbursement of zakat funds and the receipt and disbursement of charity funds. *) Represents a minimum parameter/indicator and the Bank may add other parameters/indicators according to the Bank's business characteristics and complexity. Assessment is performed per position and trend over the last 12 months for quantitative parameters/indicators.
APPENDIX...
APPENDIX 1.4
Matrix of Parameters/Indicators for Assessing Capital Factors
- Adequacy
of Bank's capital a. Capital Adequacy Ratio:
- Capital
ATMR a) Calculation of capital and Risk-Weighted Assets (RWA) refers to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles. b) The ratio is calculated per assessment position, including considering the trend of MCR.
- Core Capital (Tier 1)
ATMR
Calculation of core capital refers to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles.
- Core Capital
Total Capital a) Calculation of core capital refers to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles. b) Total Capital is capital according to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles.
- Criticized Assets (Low Quality) –
CKPN (Low Quality)
Core Capital + General Reserve a) Criticized Assets are balance sheet productive assets with low quality, namely productive assets with special attention, less active, doubtful, and non-performing qualities according to the applicable regulations regarding Asset Quality, including restructured financing with active quality, AYDA with active quality, abandoned property with active quality, and temporary equity participation with active quality. b) CKPN Low Quality is Provision for Impairment Losses for financing classified as special attention, less active, doubtful, and non-performing, including CKPN for restructured financing with active quality, AYDA with active quality, abandoned property with active quality, and temporary equity participation with active quality. c) Calculation of Core Capital and General Reserve refers to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles.
- Problematic Productive Assets –
CKPN Problematic Productive Assets
Core Capital + General Reserve a) Productive Assets are as referred to in the applicable regulations regarding Asset Quality Assessment for Sharia Public Banks and Sharia Business Units. b) Problematic Productive Assets are productive assets with less active, doubtful, and non-performing quality. c) CKPN calculation refers to applicable regulations and accounting standards. d) CKPN Problematic Productive Assets is CKPN formed over productive assets with less active, doubtful, and non-performing quality. e) Calculation of Core Capital and General Reserve refers to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles.
- Low Quality Assets – CKPN for
Low Quality Assets
Core Capital + General Reserve a) Low Quality Assets are all Bank assets, both productive and non-productive, having special attention, less active, doubtful, and non-performing quality according to the applicable regulations regarding Asset Quality, including restructured financing with active quality, AYDA with active quality, abandoned property with active quality, and temporary equity participation with active quality. b) CKPN calculation refers to applicable regulations and accounting standards. c) CKPN for Low Quality Assets is CKPN formed over assets with special attention, less active, doubtful, and non-performing quality, including CKPN for restructured financing with active quality, AYDA with active quality, abandoned property with active quality, and temporary equity participation with active quality. d) Calculation of Core Capital and General Reserve refers to the applicable regulations regarding Minimum Capital Requirements for Public Banks based on Sharia principles. b. Adequacy of Bank's capital to anticipate potential losses according to Risk profile. The assessment of Bank's capital adequacy to anticipate potential losses according to Risk profile is conducted by considering among others: (i) Inherent Risk; (ii) quality of Risk Management implementation; (iii) Risk level; and (iv) Bank's Risk profile rating, both individually and consolidated.
- Capital
Management a. Bank's capital management. This includes understanding by the Board of Commissioners and Board of Directors; capital management policies and procedures; capital planning; capital adequacy assessment; and independent review. b. Ability to access capital, viewed from internal sources and external sources.
- Access to capital from internal sources comes, for example, from profitability performance supporting capital.
- Access to capital from external sources comes, for example, from the capital market...
capital market (primary market) and parent companies.
*) Represents a minimum parameter/indicator and the Bank may add other parameters/indicators according to the Bank's business characteristics and complexity. Assessment is performed per position and trend over the last 12 months for quantitative parameters/indicators. Established in Jakarta On the date of 11 June 2014 CHIEF EXECUTIVE BANKING SUPERVISOR, Signed. NELSON TAMPUBOLON Copy consistent with the original Director of Law 1 Legal Department, Signed. Tini Kustini
APPENDIX II
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10/SEOJK.03/2014 ABOUT ASSESSMENT OF HEALTH LEVEL OF SHARIA PUBLIC BANKS AND SHARIA BUSINESS UNITS
SELF-ASSESSMENT WORK SHEET
IMPLEMENTATION OF GOOD CORPORATE GOVERNANCE
Purpose
- The governance structure assessment aims to evaluate the adequacy of the Bank's governance structure and infrastructure so that the implementation process of Good Corporate Governance principles yields outcomes in line with Bank stakeholders' expectations. Included in the Bank's governance structure are Commissioners, Directors, Committees, Sharia Supervisory Board, and operational units within the Bank. Included in the Bank's governance infrastructure are Bank policies and procedures, management information systems, and the main duties and functions (tupoksi) of each organizational structure component.
- The governance process assessment aims to evaluate the effectiveness of the implementation process of Good Corporate Governance principles supported by adequate governance structure and infrastructure, thereby yielding outcomes in line with Bank stakeholders' expectations.
- The governance outcome assessment aims to evaluate the quality of outcomes meeting Bank stakeholders' expectations, which are the results of the implementation process of Good Corporate Governance principles supported by adequate governance structure and infrastructure.
Outcomes include qualitative and quantitative aspects, such as:
- adequacy of report transparency;
- compliance with legislation;
- compliance with Sharia principles;
- consumer protection;
- objectivity in conducting assessments/audits;
- Bank performance such as profitability, efficiency, and capitalization; and/or
- improvement/decrease in compliance with applicable regulations and resolution of problems faced by the Bank such as fraud, violations of Maximum Fund Limitation (BMPD), violations of regulations related to Bank reports to the Financial Services Authority.
-
Implementation...
-
Implementation of Duties and Responsibilities of the Board of Commissioners
A. Governance Structure
- The number of Board of Commissioners members is at least 3 (three) persons and at most equal to the number of Board of Directors members.
- At least 1 (one) member of the Board of Commissioners resides in Indonesia.
- At least 50% (fifty percent) of the number of Board of Commissioners members are Independent Commissioners.
- The Board of Commissioners does not hold concurrent positions except for matters established in applicable regulations regarding the Implementation of Good Corporate Governance for Sharia Public Banks and Sharia Business Units, namely only holding concurrent positions as:
a) member of the Board of Commissioners, Board of Directors, or Executive Officer at 1 (one) institution/company that is not a financial institution; b) member of the Board of Commissioners or Board of Directors who performs supervisory functions at 1 (one) subsidiary company of a non-Bank financial institution owned by the Bank; c) member of the Board of Commissioners, Board of Directors, or Executive Officer at 1 (one) company that is a shareholder of the Bank; or d) officer at at most 3 (three) non-profit institutions.
- Independent Commissioners may hold concurrent positions as Chairman of Committees at most at 2 (two) Committees within the same Bank.
- A majority of Board of Commissioners members do not have family relationships up to the second degree with fellow Board of Commissioners members and/or Board of Directors members.
- The Board of Commissioners has established working guidelines and house rules that include, among others, provisions on work ethics, working hours, and meetings.
- All Board of Commissioners members possess adequate integrity, competence, and financial reputation.
- Independent Commissioners originating from former Board of Directors members from the same Bank who do not perform supervisory functions that could affect their ability to act independently must have served a waiting period (cooling off) of at least 6 (six) months.
- All Independent Commissioners do not have financial, managerial, shareholding, and/or family relationships with Controlling Shareholders, other Board of Commissioners members, and/or Board of Directors members, or financial and/or shareholding relationships with the Bank, that could influence their ability to act independently.
- All Board of Commissioners members have passed the fit and proper test and have obtained approval letters from the Financial Services Authority.
- Board of Commissioners members possess adequate and relevant competence for their positions to carry out their duties and responsibilities...
responsibilities and are able to implement their competencies in carrying out their duties and responsibilities.
13) Board of Commissioners members have the willingness and ability to engage in continuous learning to enhance knowledge about banking and recent developments in finance/other fields supporting the implementation of their duties and responsibilities.
14) The composition of the Board of Commissioners fails to meet requirements due to owner intervention.
B. Governance Process
-
Appointment and/or replacement of Board of Commissioners members has considered recommendations from the Nomination Committee or Remuneration and Nomination Committee and obtained approval from the General Meeting of Shareholders (GMS).
-
The Board of Commissioners has carried out its duties to ensure the implementation of Good Corporate Governance principles in every business activity of the Bank at all levels or tiers of the organization.
-
The Board of Commissioners has carried out supervision over the implementation of duties and responsibilities of the Board of Directors periodically and ad hoc, and provided advice to the Board of Directors.
-
In carrying out supervisory duties, Commissioners have directed, monitored, and evaluated the implementation of the Bank's strategic policies.
-
The Board of Commissioners has approved, evaluated Risk Management policies and strategies at least 1 (one) time in 1 (one) year or more frequently if there are significant changes in factors affecting the Bank's business activities.
-
The Board of Commissioners evaluates the Board of Directors' accountability and provides guidance for improvements in Risk Management implementation periodically. Evaluation is conducted to ensure that the Board of Directors manages Bank activities and Risks effectively.
-
The Board of Commissioners approves and oversees the Bank's Business Plan and corporate plan.
-
The Board of Commissioners is not involved in operational decision-making of the Bank, except for decisions regarding financing grants to the Board of Directors as long as established in the Bank's Articles of Association and/or GMS.
-
The Board of Commissioners has ensured that the Board of Directors has followed up on audit findings and recommendations from the Internal Audit Unit (SKAI) of the Bank, external auditors, results of Financial Services Authority supervision, results of Sharia Supervisory Board supervision, and/or results of other authorities' supervision.
-
The Board of Commissioners notifies the Financial Services Authority in writing within at most 7 (seven) working days since the discovery of violations of legislation in the field of finance and banking, and conditions or estimated conditions that may endanger the continuity of the Bank's business.
-
The Board of Commissioners has carried out its duties and responsibilities independently.
-
The...
-
The Board of Commissioners has formed the Audit Committee, Risk Monitoring Committee, and Remuneration and Nomination Committee.
-
Appointment of Committee members was conducted by the Board of Directors based on the decision of the Board of Commissioners meeting.
-
The Board of Commissioners has ensured that the formed Committees have executed their duties effectively.
-
The Board of Commissioners has provided sufficient time to execute their duties and responsibilities optimally.
-
Board of Commissioners meetings discuss issues according to the meeting agenda and are held periodically, at least 1 (one) time in 2 (two) months.
-
Decision-making in Board of Commissioners meetings is conducted based on consensus or majority vote in case consensus cannot be reached.
-
Board of Commissioners members do not utilize the Bank for personal, family, and/or third-party interests that can reduce Bank assets or reduce Bank profits.
-
Board of Commissioners members do not take and/or receive personal benefits from the Bank other than remuneration and other facilities established by the GMS.
-
Owners intervene in the execution of the Board of Commissioners' duties, causing disruption to the Bank's operational activities, thereby impacting the reduction of Bank assets and/or reduction of Bank profits.
C. Governance...
C. Governance Outcome
- Results of Board of Commissioners meetings have been recorded in minutes and documented well, including clear disclosure of dissenting opinions.
- Results of Board of Commissioners meetings have been distributed to all Board of Commissioners members and related parties.
- Results of Board of Commissioners meetings are recommendations and/or directives that can be implemented by the GMS and/or Board of Directors.
- In the Good Corporate Governance implementation report, all Board of Commissioners members have disclosed at least:
a) their share ownership reaching 5% (five percent) or more in the respective Bank or in other banks and companies located domestically and internationally; b) financial and family relationships with Controlling Shareholders, other Board of Commissioners members, and/or Board of Directors members of the Bank; c) concurrent positions in other companies or institutions; and d) remuneration and other facilities.
- Active supervision over the implementation of Risk Management policies and strategies has been effectively carried out by the Board of Commissioners.
- Enhancement of knowledge, expertise, and abilities of Board of Commissioners members in Bank supervision is demonstrated, among others, by improved Bank performance, resolution of problems faced by the Bank, and achievement of results according to stakeholder expectations.
Continuous learning culture enhancement to improve knowledge about banking and recent developments in finance/other fields supporting the implementation of duties and responsibilities of Board of Commissioners members.
- Bank operational activities are disrupted and/or provide unfair benefits to owners, impacting the reduction of Bank assets and/or reduction of Bank profits, due to owner intervention in the composition and/or execution of duties of the Board of Commissioners.
- The Bank has implemented Risk Management effectively, adjusted to the Bank's objectives, business policies, size, and capabilities.
- Implementation of Duties and Responsibilities of the Board of Directors
A. Governance Structure
-
The number of Board of Directors members is at least 3 (three) persons.
-
All Board of Directors members reside in Indonesia.
-
A majority of Board of Directors members must have experience of at least 4 (four) years with the lowest position as an Executive Officer in the banking industry and at least 1 (one) year thereof serving as an Executive Officer at a Bank.
-
The Board of...
-
The Board of Directors does not hold concurrent positions as Commissioner, Director, or Executive Officer at other banks, companies, and/or institutions except for matters established in applicable regulations regarding the Implementation of Good Corporate Governance for Sharia Public Banks and Sharia Business Units, namely becoming a Board of Commissioner to carry out supervisory duties over participations in non-Bank subsidiary companies controlled by the Bank and/or holding positions at 2 (two) non-profit institutions.
-
Board of Directors members, individually or jointly, do not hold shares exceeding 25% (twenty-five percent) of paid-up capital in other companies.
-
A majority of Board of Directors members do not have family relationships up to the second degree with fellow Board of Directors members, and/or with Board of Commissioners members.
-
The Board of Directors has established working guidelines and house rules that include, among others, provisions on work ethics, working hours, and meetings.
-
The Board of Directors does not use individual advisors and/or professional services as consultants except for projects of a special nature, which are based on clear contracts covering scope of work, responsibilities, duration of work, and costs, and the consultant is an Independent Party qualified to handle special projects.
-
All Board of Directors members possess adequate integrity, competence, and financial reputation...
reputation.
10) The President Director or Main Director originates from a party independent from the Controlling Shareholder, meaning they do not have financial, managerial, shareholding, and family relationships.
11) All Board of Directors members have passed the fit and proper test and have obtained approval letters from the Financial Services Authority.
12) Board of Directors members possess adequate and relevant competence for their positions to carry out their duties and responsibilities and are able to implement their competencies in carrying out their duties and responsibilities.
13) Board of Directors members have the willingness and ability to engage in continuous learning to enhance knowledge about banking and recent developments in finance/other fields supporting the implementation of their duties and responsibilities.
14) Board of Directors members cultivate continuous learning to enhance knowledge about banking and recent developments in finance/other fields supporting the implementation of their duties and responsibilities at all levels or tiers of the organization.
15) The composition of the Board of Directors fails to meet requirements due to owner intervention.
B. Governance Process
- Appointment and/or replacement of Board of Directors members has considered recommendations from the Nomination Committee or Remuneration and Nomination...
Nomination Committee and obtained approval from the GMS.
2) The Board of Directors has appointed Committee members, based on the decision of the Board of Commissioners meeting.
3) Board of Directors members do not grant general power of attorney to other parties resulting in the transfer of duties and functions of the Board of Directors.
4) The Board of Directors is fully responsible for the management of the Bank based on prudence principles and Sharia principles.
5) The Board of Directors manages the Bank within its authority and responsibilities as regulated in the Articles of Association and applicable legislation.
6) The Board of Directors has carried out its duties and responsibilities independently from shareholders.
7) The Board of Directors has implemented Good Corporate Governance principles in every business activity of the Bank at all levels or tiers of the organization.
8) The Board of Directors has followed up on audit findings and recommendations from SKAI, external auditors, and results of Financial Services Authority supervision, Sharia Supervisory Board supervision, and/or results of other authorities' supervision.
9) The Board of Directors has provided accurate, relevant, and timely data and information to the Board of Commissioners and Sharia Supervisory Board.
10) Decision-making in Board of Directors meetings is conducted based on consensus or majority vote in case consensus cannot be reached.
11) Every...
- Every decision taken by the Board of Directors during meetings can be implemented in accordance with applicable policies, guidelines, and work regulations.
- The Board of Directors has established policies and strategic decisions through Board of Directors meetings mechanisms.
- The Board of Directors does not utilize the Bank for personal, family, and/or third-party interests that could reduce the Bank's assets or profits.
- The Board of Directors does not take and/or receive personal benefits from the Bank other than remuneration and other facilities determined by the General Meeting of Shareholders (GMS).
- Owners intervene in the implementation of the Board of Directors' duties, causing the Bank's operational activities to be disrupted, thereby impacting a reduction in the Bank's assets and/or profits.
- The Board of Directors has prepared written and comprehensive Risk Management policies and strategy frameworks, considering the level of Risk taken and Risk tolerance regarding capital adequacy. After obtaining approval from the Board of Commissioners, the Board of Directors establishes policies, strategies, and Risk Management frameworks at least once (1) within one (1) year, or at more frequent intervals if there are significant changes in factors affecting the Bank's business activities.
- The Board of Directors has prepared, established, and updated procedures and tools to identify, measure, monitor, and control Risk.
- The Board of Directors has evaluated and/or updated Risk strategy policies and frameworks at least once (1) within one (1) year, or at more frequent intervals if there are significant changes in factors affecting the Bank's business activities, Risk exposure, and/or Risk profile.
- The Board of Directors is responsible for the implementation of Risk Management policies and the overall Risk exposure taken by the Bank.
- The Board of Directors has prepared and established approval mechanisms for transactions, including those exceeding limits and authority for each job level.
- The Board of Directors has evaluated and decided on transactions requiring Board of Directors' approval.
- The Board of Directors has developed a Risk Management culture at all organizational levels.
- The Board of Directors has ensured that the Risk Management function operates independently.
- The Bank's Business Plan has been prepared realistically, comprehensively, and measurably (achievable), considering prudential principles and responsiveness to internal and external changes.
- The Board of Directors has communicated the Bank's Business Plan to the Bank's shareholders and all organizational levels within the Bank.
C. Governance Outcome
- The Board of Directors has accounted for the implementation of their duties to shareholders through the General Meeting of Shareholders (GMS).
- The Board of Directors' accountability regarding the implementation of their duties is accepted by shareholders through the GMS.
- The Board of Directors has disclosed the Bank's strategic policies in the field of human resources to employees through media easily accessible to employees.
- The Board of Directors has communicated to employees regarding the bank's business direction in achieving the bank's mission and vision.
- Board of Directors meeting results have been recorded in meeting minutes and documented well, including clear disclosure of dissenting opinions.
- In the Good Corporate Governance implementation report, all Board of Directors members have disclosed at least:
a) share ownership reaching 5% (five percent) or more in the relevant Bank or in other Banks and companies located domestically and abroad; b) financial relationships and family relationships with Controlling Shareholders, members of the Board of Commissioners, and/or other members of the Board of Directors of the Bank; and c) remuneration and other facilities.
- Enhancement of knowledge, skills, and abilities of Board of Directors members in managing the Bank, demonstrated among others by improved Bank performance, resolution of problems faced by the Bank, and achievement of results according to stakeholder expectations.
- Enhancement of knowledge, skills, and abilities of all Bank employees at all levels or organizational hierarchies, demonstrated among others by improved individual performance according to their duties and responsibilities.
- Enhancement of a continuous learning culture to increase knowledge about banking and current developments in the financial/other fields supporting the implementation of duties and responsibilities at all levels or organizational hierarchies, demonstrated among others by increased employee participation in banking certification and/or education/training to develop individual quality.
- Active supervision of the implementation of Risk Management policies and strategies has been effectively carried out by the Board of Directors.
- Bank operational activities are disrupted and/or provide unfair benefits to owners, impacting a reduction in the Bank's assets and/or profits, due to owner intervention in the composition and/or implementation of the Board of Directors' duties.
- The Bank has effectively implemented Risk Management, adjusted to the Bank's objectives, business policies, size, and capabilities.
- The Bank's Business Plan has been prepared based on comprehensive studies considering business opportunities and the Bank's strengths, while identifying weaknesses and threats (SWOT analysis).
- The Bank's Business Plan has depicted the Bank's sustainable growth.
- Completeness and Implementation of Committee Duties
A. Governance Structure
- Audit Committee
a) Audit Committee members consist of at least one Independent Commissioner, one Independent Party expert in financial accounting, and one Independent Party expert in Sharia banking. b) The Audit Committee is chaired by an Independent Commissioner. c) The majority of Commissioners who are members of the Audit Committee are Independent Commissioners. d) Audit Committee members have good integrity and financial reputation.
- Risk Monitoring Committee
a) Risk Monitoring Committee members consist of at least one Independent Commissioner, one Independent Party expert in Sharia banking, and one Independent Party expert in Risk Management. b) The Risk Monitoring Committee is chaired by an Independent Commissioner. c) The majority of Board of Commissioners members who are members of the Risk Monitoring Committee are Independent Commissioners. d) Risk Monitoring Committee members have good integrity and financial reputation.
- Remuneration and Nomination Committee
a) Remuneration and Nomination Committee members consist of at least 2 (two) Independent Commissioners and one Executive Officer overseeing human resources. b) The Executive Officer must have knowledge and understand the Bank's remuneration and/or nomination systems and/or succession plan. c) The Remuneration and Nomination Committee is chaired by an Independent Commissioner. d) The majority of Commissioners who are members of the Remuneration and Nomination Committee are Independent Commissioners. e) If the Bank forms these Committees separately, then:
(1) The Executive Officer member of the Remuneration Committee must have knowledge of the Bank's remuneration system; and (2) The Executive Officer member of the Nomination Committee must have knowledge of the nomination system and the Bank's succession plan.
- Members of the Audit Committee, Risk Monitoring Committee, and Remuneration and Nomination Committee are not members of the same Bank's Board of Directors or other Banks.
- Concurrent positions of Independent Parties in the same Bank, other Banks, and/or other companies have considered independence criteria, expertise criteria, ability to maintain Bank confidentiality, code of ethics, and the implementation of duties and responsibilities as committee members.
- All Independent Party members of the Committee have no financial, managerial, share ownership, and/or family relationships with Controlling Shareholders, members of the Board of Commissioners, and/or members of the Board of Directors, or financial and/or share ownership relationships with the Bank, which could influence their ability to act independently.
- All Independent Parties who are former members of the Board of Directors from the relevant Bank and do not perform supervisory functions that could influence their ability to act independently have undergone a waiting period (cooling off) of at least 6 (six) months.
- Meetings of the Audit Committee and Risk Monitoring Committee are attended by at least 51% (fifty-one percent) of the members, including Independent Commissioners and Independent Parties.
- Meetings of the Remuneration and Nomination Committee are attended by at least 51% (fifty-one percent) of the members, including one Independent Commissioner and an Executive Officer.
- Committee composition does not meet requirements due to owner intervention.
B. Governance Process
- Audit Committee
To provide recommendations to the Board of Commissioners:
a) The Audit Committee has monitored and evaluated the planning and implementation of audits, as well as monitored the follow-up of audit results to assess the adequacy of internal controls, including the adequacy of the financial reporting process. b) The Audit Committee has reviewed:
(1) the implementation of duties of the Internal Audit Unit (SKAI); (2) the compliance of audit implementation by the Public Accounting Firm (KAP) with applicable audit standards; (3) the compliance of financial reports with applicable accounting standards; and (4) the follow-up implementation by the Board of Directors regarding findings from SKAI, Public Accountants, results of Financial Services Authority (OJK) supervision, and/or results of Sharia Supervisory Board supervision. c) The Audit Committee has provided recommendations for the appointment of Public Accountants and KAP to the Board of Commissioners.
- Risk Monitoring Committee
To provide recommendations to the Board of Commissioners:
a) The Risk Monitoring Committee evaluates Risk Management policies and implementation; b) The Risk Monitoring Committee monitors and evaluates the implementation of duties of the Risk Management Committee and Risk Management Work Unit (SKMR).
- Remuneration and Nomination Committee
To provide recommendations to the Board of Commissioners:
a) The Remuneration Committee has evaluated remuneration policies for:
(1) the Board of Commissioners, Board of Directors, and Sharia Supervisory Board, which have been submitted to the GMS; (2) Executive Officers and employees, which have been submitted to the Board of Directors. b) Regarding nomination policies, the Committee has prepared systems and procedures for the selection and/or replacement of members of the Board of Commissioners, Board of Directors, and Sharia Supervisory Board to be submitted to the GMS. c) The Nomination Committee has provided recommendations for candidates for members of the Board of Commissioners, Board of Directors, and/or Sharia Supervisory Board to be submitted to the GMS. d) The Nomination Committee has provided recommendations for candidate Independent Parties who can become committee members to the Board of Commissioners.
- Committee meetings are held as needed by the Bank.
- Meeting decisions are taken based on consensus or majority vote if consensus is not reached.
- Committee meeting results are recommendations that can be utilized optimally by the Board of Commissioners.
- Owners intervene in the implementation of Committee duties, such as regarding recommendations for unfair remuneration to related parties of owners, or recommendations for Board of Commissioners/Board of Directors candidates that do not comply with established selection and/or replacement procedures.
C. Governance Outcome
- Committee meeting results have been recorded in meeting minutes and documented well, including clear disclosure of dissenting opinions.
- Each Committee has performed its functions according to applicable regulations, such as providing recommendations according to its duties to the Board of Commissioners.
- Implementation of Duties and Responsibilities of the Sharia Supervisory Board
A. Governance Structure
- The number of Sharia Supervisory Board members is at least 2 (two) persons or at most 50% (fifty percent) of the number of Board of Directors members.
- Sharia Supervisory Board members do not hold concurrent positions as members of the Sharia Supervisory Board, except as determined in applicable regulations regarding the Implementation of Good Corporate Governance for Sharia Commercial Banks and Sharia Business Units, namely at most 4 (four) other Sharia financial institutions.
- The Sharia Supervisory Board has received adequate facilities, including workspace, telephone, and filing cabinets.
- The Sharia Supervisory Board has at least 1 (one) employee to support the implementation of their duties and responsibilities.
- The Bank must submit candidates for Sharia Supervisory Board members to obtain approval from the Financial Services Authority (OJK) before assuming their positions.
- The appointment of Sharia Supervisory Board members by the GMS becomes effective after obtaining approval from the Financial Services Authority (OJK).
- The submission of Sharia Supervisory Board member candidates to the Financial Services Authority (OJK) is done after receiving a recommendation from the Indonesian Ulema Council (Majelis Ulama Indonesia).
- All members of the Sharia Supervisory Board have adequate integrity, competence, and financial reputation.
B. Governance Process
- The appointment and/or replacement of Sharia Supervisory Board members has considered recommendations from the Nomination Committee or Remuneration and Nomination Committee and obtained approval from the GMS.
- The Sharia Supervisory Board has performed its duties and responsibilities in accordance with Good Corporate Governance principles.
- In performing their duties and responsibilities, the Sharia Supervisory Board has provided advice and suggestions to the Board of Directors and supervised Bank activities to ensure compliance with Sharia principles.
- The Sharia Supervisory Board has performed duties and responsibilities including:
a) assessing and ensuring compliance with Sharia principles for operational guidelines and products issued by the Bank; b) supervising the Bank's new product development process to ensure compliance with fatwas from the National Sharia Council – Indonesian Ulema Council; c) requesting fatwas from the National Sharia Council – Indonesian Ulema Council for new Bank products that do not yet have fatwas; d) conducting periodic reviews of Sharia principle compliance regarding fund collection and distribution mechanisms and Bank service provision; and e) requesting data and information related to Sharia aspects from Bank work units in the implementation of their duties.
- Sharia Supervisory Board members have provided sufficient time to perform their duties and responsibilities optimally.
- Sharia Supervisory Board meetings have been held at least once (1) within one (1) month.
- Decision-making in Sharia Supervisory Board meetings has been based on consensus.
- All decisions of the Sharia Supervisory Board recorded in meeting minutes are joint decisions of all Sharia Supervisory Board members.
- Sharia Supervisory Board members do not utilize the Bank for personal, family, and/or third-party interests that could reduce the Bank's assets or profits.
- Sharia Supervisory Board members do not take and/or receive personal benefits from the Bank other than remuneration and other facilities determined by the GMS.
- Sharia Supervisory Board members do not hold concurrent positions as consultants in all Banks.
C. Governance Outcome
- Sharia Supervisory Board meeting results are recorded in meeting minutes and documented well, including clear disclosure of dissenting opinions.
- The Sharia Supervisory Board has submitted the Sharia Supervisory Board Supervision Results Report semi-annually.
- The Sharia Supervisory Board Supervision Results Report has been submitted to the Financial Services Authority (OJK) at the latest 2 (two) months after the end of the relevant semester period.
- In the Good Corporate Governance implementation report, all members of the Sharia Supervisory Board have disclosed at least:
a) concurrent positions as Sharia Supervisory Board members at other Sharia financial institutions; b) remuneration and other facilities.
- Enhancement of knowledge, skills, and abilities of Sharia Supervisory Board members in supervising the compliance of Bank activities with Sharia principles, demonstrated among others by improved Bank performance through the reduction of violations of Sharia principles and the resolution of problems related to violations of Sharia principles.
- Implementation of Sharia Principles in Fund Collection and Distribution Activities and Service Provision
A. Governance Structure
- The Bank has a sufficient number of Sharia Supervisory Board members with adequate competence.
- The Bank has at least 1 (one) person in the compliance function with knowledge and/or understanding of Sharia banking operations.
- The Bank has at least 1 (one) person in the internal audit function with knowledge and/or understanding of Sharia banking operations.
- The Bank has an independent product development function separate from business units (fund collection, fund distribution, and service provision functions).
- Human resources in the product development function have knowledge and/or understanding of Sharia principles and banking products in general.
- Human resources in business units (fund collection, fund distribution, and service provision) have knowledge and/or understanding of the Sharia banking products they sell.
B. Governance Process
- The new product development process has considered fatwas from the National Sharia Council and has obtained Sharia opinions from the Sharia Supervisory Board.
- The implementation of the Bank's fund collection, distribution, and service provision activities has complied with fatwas from the National Sharia Council – Indonesian Ulema Council and Sharia opinions from the Sharia Supervisory Board.
C. Governance Outcome
- Products owned by the Bank have complied with Fatwas issued by the National Sharia Council – Indonesian Ulema Council and have been completed with Sharia opinions from the Sharia Supervisory Board.
- Implementation procedures (Standard Operating Procedures/SOP) in fund collection, distribution, and service provision have complied with Sharia principles.
- Sharia Supervisory Board Supervision Results Reports have been submitted semi-annually.
- Internal audit reports related to the implementation of Sharia principle compliance have been submitted to the Sharia Supervisory Board.
- Handling Conflicts of Interest
A. Governance Structure
The Bank has policies, systems, and procedures for resolving:
- conflicts of interest binding every Bank manager and employee;
- administration, documentation, and disclosure of the conflicts of interest mentioned in Meeting Minutes.
B. Governance Process
In the event of a conflict of interest, members of the Board of Commissioners, members of the Board of Directors, and Executive Officers do not take actions that could reduce the Bank's assets or profits.
C. Governance Outcome
- Conflicts of interest that could reduce the Bank's assets or profits have been disclosed in every decision and have been well documented.
- Bank operational activities are free from intervention by owners/related parties/other parties that could cause conflicts of interest that could harm the Bank or reduce the Bank's profits.
- The Bank successfully resolves conflicts of interest that occur.
- Implementation of the Bank's Compliance Function
A. Governance Structure
- An independent compliance work unit separate from operational work units.
- The appointment, dismissal, and/or resignation of the Director overseeing the Compliance Function is in accordance with applicable regulations.
- The Bank has provided quality human resources in the Compliance work unit to perform duties effectively.
B. Governance Process
- The Director overseeing the Compliance Function is responsible for:
a) ensuring the Bank's compliance with applicable laws and regulations, by:
(1) establishing necessary steps considering prudential principles; (2) monitoring and ensuring that the Bank's business activities do not deviate from regulations; (3) monitoring and ensuring the Bank's compliance with all agreements and commitments made by the Bank to the Financial Services Authority (OJK) and competent authority agencies; b) submitting reports on the implementation of duties and responsibilities at least quarterly to the President Director, with copies to the Board of Commissioners or competent parties according to the Bank's organizational structure; c) formulating strategies to encourage the creation of the Bank's Compliance Culture; d) proposing compliance policies or compliance principles to be established by the Board of Directors; e) establishing compliance systems and procedures to be used to formulate the Bank's internal regulations and guidelines; f) ensuring that all policies, regulations, systems, procedures, and business activities conducted by the Bank comply with applicable laws and regulations; g) minimizing the Bank's Compliance Risk; h) taking preventive actions so that policies and/or decisions taken by the Bank's Board of Directors do not deviate from applicable laws and regulations; i) performing other tasks related to the Compliance Function.
- The appointment of the Director overseeing the Compliance Function has been in accordance with applicable regulations.
- The Board of Directors has:
a) approved the Bank's compliance policies in the form of formal documents regarding the effective compliance function; b) is responsible for communicating all policies, guidelines, systems, and procedures to all relevant organizational levels; c) is responsible for creating an effective and permanent compliance function as part of the Bank's overall compliance policies.
- The compliance work unit is responsible for:
a) establishing steps to support the creation of Compliance Culture in all business activities of the Bank at all organizational levels; b) identifying, measuring, monitoring, and controlling Compliance Risk by referring to applicable regulations regarding the Implementation of Risk Management for Sharia Commercial Banks and Sharia Business Units; c) assessing and evaluating the effectiveness, adequacy, and compliance of the Bank's policies, regulations, systems, and procedures with applicable laws and regulations; d) reviewing and/or recommending the updating and refinement of the Bank's policies, regulations, systems, and procedures to comply with applicable laws and regulations; e) taking efforts to ensure that...
that the policies, regulations, systems and procedures, as well as business activities of the Bank are in accordance with the applicable laws and regulations; f) carrying out other tasks related to the Compliance Function.
C. Governance Outcome
- The Bank has submitted the main report on the implementation of the duties of the Director overseeing the Compliance Function and special reports to the Financial Services Authority and related parties.
- The scope of the report on the implementation of the duties of the Director overseeing the Compliance Function has been in accordance with the applicable regulations.
- The Bank has succeeded in reducing the level of violations of the applicable regulations.
- The Bank has succeeded in building a compliance culture in decision-making and in the Bank's operational activities.
- Implementation of the Internal Audit Function
A. Governance Structure
-
The organizational structure of the Internal Audit Unit (SKAI) of the Bank is in accordance with the applicable regulations.
-
The Bank has Standards for the Implementation of the Bank's Internal Audit Function (Control System and Internal Audit Function), with:
a) drafting the Internal Audit Charter; b) establishing the SKAI; c) drafting internal audit guidelines.
-
The institutionalization of SKAI is independent of operational work units.
-
The Bank...
-
The Bank provides quality resources to SKAI to complete tasks effectively.
B. Governance Process
-
The Board of Directors is responsible for:
a) creating an internal control structure, and ensuring the implementation of the Bank's internal audit function at every level of management; b) follow-up of the Bank's internal audit findings in accordance with the policies and directives of the Board of Commissioners.
-
The Bank implements the internal audit function effectively on all aspects and elements of activities that are directly estimated to affect the interests of the Bank and the public.
-
The Bank periodically reviews the effectiveness of the implementation of SKAI work and its compliance with the Control System and Internal Audit Function by external parties every three years.
-
The Bank's SKAI examination plan, adequacy of the examination scope, and depth of examination are adequate.
-
There are no deviations in the realization of the Bank's SKAI examination plan.
-
The Bank plans and realizes the continuous and periodic improvement of human resource skills.
-
SKAI has performed supervisory functions independently with adequate task coverage in accordance with the plan, implementation, and monitoring of audit results.
-
SKAI has performed its duties at least including the assessment of:
a) the adequacy of the Bank's Internal Control System; b) the effectiveness of the Bank's Internal Control System; c) performance quality.
-
SKAI has reported all audit findings in accordance with the applicable regulations.
-
SKAI has monitored, analyzed, and reported the progress of follow-up improvements made by the auditee.
-
SKAI has compiled and updated work guidelines and systems and procedures to perform tasks for internal auditors periodically in accordance with applicable regulations and legislation.
C. Governance Outcome
-
The Board of Directors is responsible for the availability of reports on the implementation of the Bank's internal audit function to the General Meeting of Shareholders (GMS).
-
SKAI examination findings have been followed up and no recurring findings have occurred.
-
SKAI acts objectively in conducting audits.
-
The internal audit function has been implemented adequately by considering among others:
a) Audit programs cover all work units, with implementation considering the risk level of each work unit. b) Audit programs and audit scope are adequate in accordance with the principles of the Control System and Internal Audit Function, including the fulfillment of independence, objectivity, and no restrictions in the scope and coverage of internal audit. c) The fulfillment of the number and quality of internal auditors.
- Implementation of External Audit Function
A. Governance Structure
The assignment of audits to Public Accountants and Public Accounting Firms (KAP) must at least meet the following aspects:
- the capacity of the appointed KAP;
- the legality of the employment agreement;
- the scope of the audit;
- public accountant professional standards; and
- communication between the Financial Services Authority and the aforementioned KAP.
B. Governance Process
- In the implementation of the Bank's financial statement audit, the Bank appoints Public Accountants and KAP registered with the Financial Services Authority.
- The appointment of the same Public Accountant and KAP by the Bank is in accordance with the applicable laws and regulations.
- The appointment of Public Accountants and KAP must first obtain approval from the GMS based on recommendations from the Audit Committee through the Board of Commissioners.
- The appointed Public Accountants and KAP are able to work independently, meet public accountant professional standards, employment agreements, and the established scope of the audit.
- Public Accountants have communicated with the Financial Services Authority regarding the conditions of the audited Bank in the preparation and implementation of the audit.
- Public Accountants have implemented the audit independently and professionally.
- Public Accountants have reported audit results and Management Letters to the Financial Services Authority.
C. Governance Outcome
- Audit results and management letters have described significant bank problems and were submitted accurately and on time to the Financial Services Authority by the appointed KAP.
- The scope of audit results is at least in accordance with the scope of the audit as regulated in the applicable regulations.
- Auditors act objectively in conducting audits.
- Maximum Limit on Fund Disbursement
A. Governance Structure
The Bank has adequate written policies, systems, and procedures for providing funds to related parties and providing large funds, including monitoring and resolving issues. B. Governance Process
- The Bank has periodically evaluated and updated the aforementioned policies, systems, and procedures to align with applicable regulations and legislation.
- There are adequate processes to ensure that providing funds to related parties and providing large funds are in accordance with prudential principles.
- Decision-making in fund provision is decided by management independently without intervention from related parties and/or other parties.
C. Governance Outcome
- The implementation of fund provision by the Bank to related parties and/or large fund provision has:
a) met the applicable regulations regarding the Maximum Limit on Fund Disbursement (BMPD) and considered prudential principles and applicable legislation; b) considered capital adequacy and the distribution/diversification of fund provision portfolios.
- Reports as referred to in number 1) have been submitted periodically to the Financial Services Authority accurately and on time.
- Transparency of Financial and Non-Financial Conditions, Implementation of Good Corporate Governance Reports, and Internal Reporting
A. Governance Structure
- The Bank has policies and procedures regarding the implementation of transparency of financial and non-financial conditions.
- The Bank is required to compile Implementation Reports of Good Corporate Governance at the end of each fiscal year with coverage in accordance with applicable regulations.
- The availability of complete, accurate, and timely internal reporting supported by adequate Management Information Systems (SIM).
- There are reliable information systems supported by competent human resources and adequate Information Technology (IT) security systems.
B. Governance Process
- The Bank has transparently disclosed financial and non-financial conditions to stakeholders, including announcing Quarterly Public Financial Reports and reporting them to the Financial Services Authority or stakeholders in accordance with applicable regulations.
- The Bank transparently discloses Bank product information in accordance with applicable regulations regarding Transparency of Bank Product Information and Use of Customer Personal Data, including:
a) written information regarding Bank products that meet the minimum requirements as determined; b) Bank staff (Customer Service and Marketing) have explained product information to customers; c) product information provided is consistent with actual conditions; d) The Bank has informed customers if there are changes to product information; e) product information is clearly readable and understandable; f) The Bank has product information services that are easily accessible to the public; g) The Bank has explained the purpose and consequences of disseminating personal data to customers; h) customers whose personal data is disseminated have given consent for the provision of their personal data.
- The Bank transparently discloses customer complaint procedures and dispute resolution to customers in accordance with applicable regulations regarding Customer Complaints and Banking Mediation.
- The Bank compiles and presents reports with procedures, types, and coverage as regulated in the applicable regulations regarding Financial Condition Transparency.
- The Bank has compiled Implementation Reports of Good Corporate Governance with content and coverage at least in accordance with applicable regulations.
- In the event that the Implementation Report of Good Corporate Governance does not reflect the actual conditions of the Bank, the Bank immediately submits a complete revision to the Financial Services Authority, and for Banks that have a homepage, are required to publish it on the Bank's homepage as well.
- In the event of differences in the Good Corporate Governance Factor Rating in the assessment results (self-assessment) in the Implementation Report of Good Corporate Governance of the Bank with the assessment results of the implementation of Good Corporate Governance by the Financial Services Authority, the Bank:
a) At least revises the Good Corporate Governance Factor Rating and the Definition of Rating results (self-assessment) to the public through Quarterly Public Financial Reports in the nearest period; b) Immediately submits a complete revision of the Bank's Good Corporate Governance assessment results (self-assessment) to the Financial Services Authority, and for Banks that have a homepage, are required to publish it on the Bank's homepage as well.
C. Governance Outcome
- Annual Reports have been submitted by the Bank completely and on time to shareholders and at least to:
a) Financial Services Authority; b) Indonesian Consumer Foundation (YLKI); c) Rating Agencies in Indonesia; d) National Association of General Banks (Perbanas); e) 1 (one) research institution in the field of economics and finance; f) 1 (one) economics and finance magazine.
- Transparent reporting has been done accurately and on time with coverage in accordance with regulations on the Bank's homepage, including:
a) Annual Reports (financial and non-financial); b) Quarterly Public Financial Reports at least in 1 (one) newspaper with wide circulation in the location of the Bank's head office.
- Implementation Reports of Good Corporate Governance reflect the actual conditions of the Bank or the results of the Bank's most recent self-assessment, at least covering:
a) General Conclusions from the self-assessment results of the implementation of Good Corporate Governance of the Bank; b) share ownership, financial relationships, family relationships, and concurrent positions of Board of Commissioners members; c) share ownership, financial relationships, and family relationships of Board of Directors members; d) concurrent positions as members of the Sharia Supervisory Board at other Islamic financial institutions; e) committee structure, committee membership, and committee member expertise; f) list of consultants, advisors, or equivalents used by the Bank; g) remuneration policies and other facilities for Board of Commissioners, Board of Directors, and Sharia Supervisory Board members; h) ratio of highest to lowest salaries; i) frequency of Board of Commissioners meetings; j) frequency of Sharia Supervisory Board meetings; k) number of deviations (internal fraud) that occurred and the Bank's resolution efforts; l) number of legal issues and the Bank's resolution; m) transactions containing conflicts of interest; n) buy back shares and/or buy back bonds of the Bank; o) fund disbursement for social activities, both the amount and the recipients of the funds; and p) non-halal income and its usage.
- Implementation Reports of Good Corporate Governance have been submitted completely and on time to shareholders and to:
a) Financial Services Authority; b) Indonesian Consumer Foundation (YLKI); c) Rating Agencies in Indonesia; d) National Association of General Banks (Perbanas); e) 1 (one) research institution in the field of economics and finance; f) 1 (one) economics and finance magazine.
- Implementation Reports of Good Corporate Governance have been presented on the homepage accurately and on time.
- Mediation in the context of resolving Bank customer complaints has been implemented well.
- The Bank applies transparency of information regarding products and the use of customer personal data.
Conclusion:
Based on the analysis of all the above assessment criteria/indicators, it is concluded that:
A. Governance Structure
- Positive factors of the Bank's governance structure aspect are ....
- Negative factors of the Bank's governance structure aspect are ....
B. Governance Process
- Positive factors of the Bank's governance process aspect are ....
- Negative factors of the Bank's governance process aspect are ....
C. Governance Outcome
- Positive factors of the Bank's governance outcome aspect are ....
- Negative factors of the Bank's governance outcome aspect are ....
Established in Jakarta
On June 11, 2014
EXECUTIVE HEAD
BANKING SUPERVISOR,
Signed,
NELSON TAMPUBOLON
Legal Director 1
Legal Department,
Signed,
Tini Kustini
APPENDIX III
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.03/2014 REGARDING THE ASSESSMENT OF THE HEALTH LEVEL OF GENERAL ISLAMIC BANKS AND ISLAMIC BUSINESS UNITS
HEALTH LEVEL ASSESSMENT OF THE BANK
APPENDIX III.1 : Composite Health Rating Matrix of the Bank
APPENDIX III.2 : Risk Profile Factor Rating Matrix
APPENDIX III.2.1 : Risk Rating Determination Matrix
APPENDIX III.2.2.a : Inherent Risk Rating Determination Matrix for Credit Risk
APPENDIX III.2.2.b : Risk Management Implementation Quality Rating Matrix for Credit Risk
APPENDIX III.2.3.a : Inherent Risk Rating Determination Matrix for Market Risk
APPENDIX III.2.3.b : Risk Management Implementation Quality Rating Matrix for Market Risk
APPENDIX III.2.4.a : Inherent Risk Rating Determination Matrix for Liquidity Risk
APPENDIX III.2.4.b : Risk Management Implementation Quality Rating Matrix for Liquidity Risk
APPENDIX III.2.5.a : Inherent Risk Rating Determination Matrix for Operational Risk
APPENDIX III.2.5.b : Risk Management Implementation Quality Rating Matrix for Operational Risk
APPENDIX III.2.6.a : Inherent Risk Rating Determination Matrix for Legal Risk
APPENDIX III.2.6.b : Risk Management Implementation Quality Rating Matrix for Legal Risk
APPENDIX III.2.7.a : Inherent Risk Rating Determination Matrix for Strategic Risk
APPENDIX III.2.7.b : Risk Management Implementation Quality Rating Matrix for Strategic Risk
APPENDIX III.2.8.a : Inherent Risk Rating Determination Matrix for Compliance Risk
APPENDIX III.2.8.b : Risk Management Implementation Quality Rating Matrix for Compliance Risk
APPENDIX III.2.9.a : Inherent Risk Rating Determination Matrix for Reputational Risk
APPENDIX III.2.9.b : Risk Management Implementation Quality Rating Matrix for Reputational Risk
APPENDIX III.2.10.a : Inherent Risk Rating Determination Matrix for Yield Risk
APPENDIX III.2.10.b : Risk Management Implementation Quality Rating Matrix for Yield Risk
APPENDIX III.2.11.a : Inherent Risk Rating Determination Matrix for Investment Risk
APPENDIX III.2.11.b : Risk Management Implementation Quality Rating Matrix for Investment Risk
APPENDIX III.3 : Good Corporate Governance Factor Rating Matrix
APPENDIX III.4 : Profitability Factor Rating Matrix
APPENDIX III.5 : Capital Adequacy Factor Rating Matrix
APPENDIX III...
APPENDIX III.1
Composite Health Rating Matrix of the Bank
Rating Explanation
PK 1 Reflects the condition of the Bank which is generally very healthy, so it is assessed as being very capable of facing significant negative influences from changes in business conditions and other external factors, reflected in the rating of assessment factors, including Risk Profile, implementation of Good Corporate Governance principles, profitability, and capital adequacy which are generally very good. If there are weaknesses, they are generally not significant. PK 2 Reflects the condition of the Bank which is generally healthy, so it is assessed as being capable of facing significant negative influences from changes in business conditions and other external factors, reflected in the rating of assessment factors, including Risk Profile, implementation of Good Corporate Governance, profitability, and capital adequacy which are generally good. If there are weaknesses, they are generally less significant. PK 3 Reflects the condition of the Bank which is generally fairly healthy, so it is assessed as being fairly capable of facing significant negative influences from changes in business conditions and other external factors, reflected in the rating of assessment factors, including Risk Profile, implementation of Good Corporate Governance, profitability, and capital adequacy which are generally fairly good. If there are weaknesses, they are generally fairly significant and if not successfully addressed well by management, they can disrupt the Bank's business continuity. PK 4 Reflects the condition of the Bank which is generally less healthy, so it is assessed as being less capable of facing significant negative influences from changes in business conditions and other external factors, reflected in the rating of assessment factors, including Risk Profile, implementation of Good Corporate Governance, profitability, and capital adequacy which are generally less good. There are...
*) Applicable for individual and consolidated Bank health assessments significant weaknesses that are not well addressed by management and disrupt the Bank's business continuity. PK 5 Reflects the condition of the Bank which is generally unhealthy, so it is assessed as being unable to face significant negative influences from changes in business conditions and other external factors, reflected in the rating of assessment factors, including Risk Profile, implementation of Good Corporate Governance, profitability, and capital adequacy which are generally less good. There are weaknesses that are generally very significant, so to address them, support funds from shareholders or funds from other parties are needed to strengthen the Bank's financial condition.
APPENDIX...
APPENDIX III.2
Risk Profile Factor Rating Matrix
Rating Definition
1 Risk Profile of Banks included in this rating generally have characteristics as follows:
- Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Composite Inherent Risk are classified as very low during a certain period in the future.
- The quality of Composite Risk Management implementation is very adequate. Although there are minor weaknesses, these weaknesses can be ignored.
2 Risk Profile of Banks included in this rating generally have characteristics as follows:
- Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Composite Inherent Risk are classified as low during a certain period in the future.
- The quality of Composite Risk Management implementation is adequate. Although there are minor weaknesses, these weaknesses require management attention.
3 Risk Profile of Banks included in this rating generally have characteristics as follows:
- Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Composite Inherent Risk are classified as fairly high during a certain period in the future.
- The quality of Composite Risk Management implementation is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention and improvement.
4 Risk Profile of Banks included in this rating generally have characteristics as follows:
- Considering the business activities conducted by the Bank...
Bank, the potential losses faced by the Bank from Composite Inherent Risk are classified as high during a certain period in the future.
- The quality of Composite Risk Management implementation is less adequate. There are significant weaknesses in various aspects of Risk Management that require immediate corrective action.
5 Risk Profile of Banks included in this rating generally have characteristics as follows:
- Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Composite Inherent Risk are classified as very high during a certain period in the future.
- The quality of Composite Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Risk Management where resolution actions are beyond the capacity of management.
APPENDIX...
APPENDIX III.2.1
Risk Rating Determination Matrix
Risk Rating is the final conclusion on the Bank's Risk after considering mitigation through Risk Management implementation. To determine the Risk Rating, the Bank can refer to the following Risk Rating matrix. This matrix basically maps the Risk Rating resulting from the combination of Inherent Risk and the quality of Risk Management implementation.
APPENDIX...
APPENDIX III.2.2.a
Matrix for Setting Inherent Risk Ratings for Credit Risk
| Rating | Definition | Rating |
|---|
| Low (1) | Considering the business activities conducted by the bank, the potential losses faced by the bank from Credit Risk are classified as very low over a certain period in the future.<br><br>Examples of characteristics of banks included in this rating include the following:<br>• The funding portfolio is dominated by very low credit/financing exposure.<br>• Funding exposure is very well diversified.<br>• Funding has very good quality.<br>• The bank's funding strategy or business model is classified as stable.<br>• The funding portfolio is relatively unaffected by changes in external factors. | Low (1) |
| Low to Moderate (2) | Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Credit Risk are classified as low over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The funding portfolio is dominated by low credit/financing exposure.<br>• Funding exposure is well diversified.<br>• Funding has good quality.<br>• The funding strategy or business model is relatively stable.<br>• The funding portfolio is less affected by changes in external factors. | Low to Moderate (2) |
| Moderate (3) | Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Credit Risk are classified as moderately high over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The funding portfolio is dominated by moderate credit/financing exposure.<br>• There is a fairly significant concentration of funding.<br>• Funding has fairly good quality.<br>• The funding strategy or business model is generally fairly stable.<br>• The funding portfolio is fairly affected by changes in external factors. | Moderate (3) |
| Moderate to High (4) | Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Credit Risk are classified as high over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The funding portfolio is dominated by high credit/financing exposure.<br>• There is a significant concentration of funding.<br>• Funding has poor quality.<br>• There are significant changes in the funding strategy or business model.<br>• The funding portfolio is affected by changes in external factors. | Moderate to High (4) |
| High (5) | Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Credit Risk are classified as very high over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The funding portfolio is dominated by very high credit/financing exposure.<br>• There is a very significant concentration of funding.<br>• Funding has poor quality.<br>• There are very significant changes in the funding strategy or business model.<br>• The funding portfolio is very affected by changes in external factors. | High (5) |
APPENDIX III.2.2.b
For Credit Risk
| Rating | Definition | Rating |
|---|
| Strong (1) | The quality of Credit Risk management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for credit is very adequate and has aligned with the Bank's overall strategic objectives and business strategy.<br>• The Board of Commissioners and Board of Directors have very good awareness and understanding regarding Credit Risk management.<br>• Credit Risk management culture is very strong and has been internalized very well at all levels of the organization.<br>• The execution of duties by Commissioners and Directors is overall very adequate.<br>• The Credit Risk management function is independent, has clear duties and responsibilities, and has operated very well.<br>• Delegation of authority is controlled and monitored periodically, and has operated very well.<br>• The lending strategy is very good and very aligned with the level of Risk to be taken and Credit Risk tolerance.<br>• Credit Risk policies, procedures, and limits are very adequate and available for all Credit Risk management areas, aligned with implementation, and well understood by employees.<br>• The Credit Risk management process is very adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>• The funding process in general is very adequate from the underwriting process to non-performing asset handling.<br>• The Credit Risk grading system is very good, applied consistently, and well understood by employees. There is an independent financing review function that operates well.<br>• The Credit Risk Management Information System (MIS) is very good, producing comprehensive and integrated Credit Risk reporting to the Board of Commissioners and Board of Directors.<br>• Human resources are generally very adequate in terms of both quantity and competence in the Credit Risk management function.<br>• The internal control system is very effective in supporting the implementation of Credit Risk management.<br>• The implementation of independent review by the internal audit work unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.<br>• Generally, there are no significant weaknesses based on independent review results.<br>• Follow-up on independent review has been implemented very adequately. | Strong (1) |
| Satisfactory (2) | The quality of Credit Risk management implementation is adequate. Although there are some minor weaknesses, these weaknesses can be resolved in normal business activities.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with the Bank's overall strategic objectives and business strategy.<br>• The Board of Commissioners and Board of Directors have good awareness and understanding regarding Credit Risk management.<br>• Credit Risk management culture is strong and has been internalized very well at all levels of the organization.<br>• The execution of duties by Commissioners and Directors is overall adequate. There are some weaknesses but they are not significant and can be repaired immediately.<br>• The Credit Risk management function is independent, has clear duties and responsibilities, and has operated well. There are minor weaknesses, but they can be resolved in normal business activities.<br>• Delegation of authority is controlled and monitored periodically, and has operated well.<br>• The lending strategy is good and aligned with the level of Risk to be taken and Credit Risk tolerance.<br>• Credit Risk policies, procedures, and limits are adequate and available for all Credit Risk management areas, aligned with implementation, and well understood by employees.<br>• The Credit Risk management process is adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>• The funding process is good. There are minor weaknesses in one or more aspects of funding but can be easily repaired.<br>• The Credit Risk grading system is good, applied consistently, and understood by employees. The independent financing review function exists. There are minor weaknesses that do not disrupt the overall process.<br>• The Credit Risk Management Information System (MIS) is good, including Credit Risk reporting to the Board of Commissioners and Board of Directors. There are minor weaknesses but can be easily repaired.<br>• Human resources are adequate in terms of both quantity and competence in the Credit Risk management function.<br>• The internal control system is effective in supporting the implementation of Credit Risk management.<br>• The implementation of independent review by the internal audit work unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.<br>• There are weaknesses but not significant based on independent review results.<br>• Follow-up on independent review has been implemented adequately. | Satisfactory (2) |
| Fair (3) | The quality of Credit Risk management implementation is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is fairly adequate but not always aligned with the Bank's overall strategic objectives and business strategy.<br>• The Board of Commissioners and Board of Directors have fairly good awareness and understanding regarding Credit Risk management.<br>• Credit Risk management culture is fairly strong and has been internalized fairly well but not always implemented consistently.<br>• The execution of duties by Commissioners and Directors is overall fairly adequate. There are some weaknesses in some assessment aspects that need management attention.<br>• The Credit Risk management function has operated fairly well, but there are some fairly significant weaknesses that need to be resolved immediately by management.<br>• Delegation of authority is fairly good, but control and monitoring are not always implemented well.<br>• The lending strategy is fairly aligned with the level of Risk to be taken and Credit Risk tolerance.<br>• Credit Risk policies, procedures, and limits are fairly adequate but not always consistent with implementation and/or not well understood by employees.<br>• The Credit Risk management process is fairly adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>• The funding process is fairly good. There are weaknesses in one or more aspects of funding that need management attention.<br>• The Credit Risk grading system and financing review function are fairly good, but there are some weaknesses that need management attention.<br>• The Credit Risk Management Information System (MIS) meets minimum expectations but there are some weaknesses, including Credit Risk reporting to the Board of Commissioners and Board of Directors, that require management attention.<br>• Human resources are fairly adequate in terms of both quantity and competence in the Credit Risk management function.<br>• The internal control system is fairly effective in supporting the implementation of Credit Risk management.<br>• The implementation of independent review by the internal audit work unit and functions conducting independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that require management attention.<br>• There are fairly significant weaknesses based on independent review results.<br>• Follow-up on independent review has been implemented fairly adequately. | Fair (3) |
| Marginal (4) | The quality of Credit Risk management implementation is less than adequate. There are significant weaknesses in various aspects of Credit Risk management that require immediate corrective action.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less than adequate and not aligned with the Bank's overall strategic objectives and business strategy.<br>• Significant weaknesses in the awareness and understanding of the Board of Commissioners and Board of Directors regarding Credit Risk management.<br>• Credit Risk management culture is less than strong and has not been internalized at every level of the work unit.<br>• The execution of duties by Commissioners and Directors is overall less than adequate. There are weaknesses in some assessment aspects that require immediate repair.<br>• Significant weaknesses in the Credit Risk management function that require immediate repair.<br>• Delegation of authority is weak and not controlled and monitored well.<br>• The lending strategy is less than aligned with the level of Risk to be taken and Credit Risk tolerance.<br>• Significant weaknesses in Credit Risk policies, procedures, and limits.<br>• The Credit Risk management process is less than adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>• The funding process is less than good. There are weaknesses in one or more aspects of funding that need immediate repair.<br>• The Credit Risk grading system and financing review are less than good. There are some weaknesses that need immediate repair.<br>• Significant weaknesses in the Credit Risk Management Information System (MIS), including Risk reporting to the Board of Commissioners and Board of Directors, that require immediate repair.<br>• Human resources are less than adequate in terms of both quantity and competence in the Credit Risk management function.<br>• The internal control system is less than effective in supporting the implementation of Credit Risk management.<br>• The implementation of independent review by the internal audit work unit and functions conducting independent review is less than adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that require immediate repair.<br>• There are significant weaknesses based on independent review results that require immediate repair.<br>• Follow-up on independent review is less than adequate. | Marginal (4) |
| Unacceptable (5) | The quality of Credit Risk management implementation is inadequate. There are significant weaknesses in various aspects of Credit Risk management where the resolution is beyond the capability of management.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less than adequate and not aligned with the Bank's overall strategic objectives and business strategy.<br>• Awareness and understanding of the Board of Commissioners and Board of Directors are very weak regarding Credit Risk management.<br>• Significant weaknesses in the awareness and understanding of the Board of Commissioners and Board of Directors regarding Credit Risk management.<br>• Credit Risk management culture is less than strong and has not been internalized at every level of the work unit.<br>• The execution of duties by Commissioners and Directors is overall less than adequate. There are weaknesses in some assessment aspects that require immediate repair.<br>• Significant weaknesses in the Credit Risk management function that require immediate repair.<br>• Delegation of authority is weak and not controlled and monitored well.<br>• The lending strategy is less than aligned with the level of Risk to be taken and Credit Risk tolerance.<br>• Significant weaknesses in Credit Risk policies, procedures, and limits.<br>• The Credit Risk management process is less than adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>• The funding process is less than good. There are weaknesses in one or more aspects of funding that need immediate repair.<br>• The Credit Risk grading system and financing review function are less than good. There are some weaknesses that need immediate repair.<br>• Significant weaknesses in the Credit Risk Management Information System (MIS), including Risk reporting to the Board of Commissioners and Board of Directors, that require immediate repair.<br>• Human resources are less than adequate in terms of both quantity and competence in the Credit Risk management function.<br>• The internal control system is less than effective in supporting the implementation of Credit Risk management.<br>• The implementation of independent review by the internal audit work unit and functions conducting independent review is less than adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that require immediate repair.<br>• There are significant weaknesses based on independent review results that require immediate repair.<br>• Follow-up on independent review is less than adequate. | Unacceptable (5) |
APPENDIX III.2.3.a
Matrix for Setting Inherent Risk Ratings for Market Risk
| Rating | Definition | Rating |
|---|
| Low (1) | Considering the business activities conducted by the bank, the potential losses faced by the bank from Market Risk are classified as very low over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• Market Risk exposure from trading is not significant.<br>• Most trading book positions offset each other with minimal repricing risk.<br>• Exchange rate positions are completely matched/hedged.<br>• The bank's asset and liability structure is not sensitive to changes in benchmark interest rates, reflected in the repricing gap of assets and liabilities having very minimal impact on the bank's financing distribution income and capital.<br>• The bank's portfolio is dominated by less complex financial instruments.<br>• Trading activities are generally to meet customer needs (customer accommodation). | Low (1) |
| Low to Moderate (2) | Considering the business activities conducted by the bank, the potential losses faced by the bank from Market Risk are classified as low over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• Market Risk exposure from trading is less than significant.<br>• There is a mismatch in trading book positions but less than significant.<br>• Most exchange rate positions can offset each other or be hedged.<br>• The bank's asset and liability structure is less than sensitive to changes in benchmark interest rates, reflected in the repricing gap of assets and liabilities having minimal impact on the bank's financing distribution income and capital.<br>• The bank's portfolio is dominated by fairly complex financial instruments.<br>• Trading activities are generally to meet customer needs (customer accommodation). | Low to Moderate (2) |
| Moderate (3) | Considering the business activities conducted by the bank, the potential losses faced by the bank from Market Risk are classified as fairly high over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• Market Risk exposure from trading is fairly significant.<br>• There is a fairly significant mismatch in trading book positions.<br>• There is a fairly significant exchange rate exposure.<br>• The bank's asset and liability structure is fairly sensitive to changes in benchmark interest rates, reflected in the repricing gap of assets and liabilities having a fairly significant impact on the bank's financing distribution income and capital.<br>• The bank's portfolio is dominated by fairly complex financial instruments.<br>• There are proprietary trading activities or market making activities but not significant. | Moderate (3) |
| Moderate to High (4) | Considering the business activities conducted by the bank, the potential losses faced by the bank from Market Risk are classified as high over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• Market Risk exposure from trading is significant.<br>• There is a significant mismatch in trading book positions.<br>• Exchange rate exposure is significant.<br>• The bank's asset and liability structure is sensitive to changes in benchmark interest rates, reflected in the repricing gap of assets and liabilities having a significant impact on the bank's financing distribution income and capital.<br>• The bank's portfolio is dominated by complex financial instruments.<br>• There are proprietary trading or market making activities that are fairly significant. | Moderate to High (4) |
| High (5) | Considering the business activities conducted by the bank, the potential losses faced by the bank from Market Risk are classified as very high over a certain period in the future.<br><br>Examples of characteristics of Banks included in this rating include the following:<br>• Market Risk exposure from trading is very significant.<br>• Mismatch in trading book positions is very significant.<br>• Exchange rate exposure is very significant.<br>• The bank's asset and liability structure is sensitive to changes in benchmark interest rates, reflected in the repricing gap of assets and liabilities being very significant when compared to the bank's financing distribution income and capital capacity to absorb potential losses.<br>• The bank's portfolio is dominated by very complex financial instruments.<br>• The bank's trading activities are dominated by proprietary trading and market making. | High (5) |
APPENDIX III.2.3.b
Matrix for Setting the Risk Management Quality Rating for Market Risk
Rating Definition
Strong (1)
The quality of Market Risk management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of Bank characteristics included in this rating are as follows:
- The Board of Commissioners and Board of Directors have a very good awareness and understanding of Market Risk management.
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is very adequate and aligned with the overall strategic and business objectives of the Bank.
- The Market Risk management culture is very strong and has been internalized very well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is very adequate.
- The Market Risk management function, including related committees, is independent, has clear tasks and responsibilities, and operates very well.
- Delegation of authority is controlled and monitored periodically, and operates very well.
- Market Risk strategies, including trading strategies and banking book position management, are very adequate.
- Market Risk policies, procedures, and limits are very adequate and available for all areas of Market Risk management, aligned with implementation, and well understood by staff.
- The Market Risk management process is very adequate in identifying, measuring, monitoring, and controlling Market Risk.
- The Market Risk Management Information System (SIM) is very good, producing comprehensive and integrated Market Risk reports to the Board of Commissioners and Board of Directors.
- Generally, human resources are very adequate in terms of quantity and competence in the Market Risk management function.
- The internal control system is very effective in supporting the implementation of Market Risk management.
- The implementation of independent review by the internal audit work unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- Generally, there are no significant weaknesses based on the results of independent reviews.
Satisfactory (2)
The quality of Liquidity Risk management implementation is adequate, although there are some minor weaknesses, but these weaknesses can be resolved in normal business activities. (Note: The text below describes Market Risk characteristics despite the definition header mentioning Liquidity Risk, consistent with source structure) Examples of Bank characteristics included in this rating are as follows:
- The Board of Commissioners and Board of Directors have a good awareness and understanding of Market Risk management.
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is adequate and aligned with the overall strategic and business objectives of the Bank.
- The Market Risk management culture is strong and has been internalized well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is adequate. There are some weaknesses but they are not significant and can be repaired immediately.
- The Market Risk management function, including related committees, is independent, has clear tasks and responsibilities, and operates well. There are minor weaknesses but can be resolved in normal business activities.
- Delegation of authority is controlled and monitored periodically, and operates well.
- Market Risk strategies, including trading strategies and banking book position management, are adequate.
- Market Risk policies, procedures, and limits are adequate and available for all areas of Market Risk management, aligned with implementation, and well understood by staff.
- The Market Risk management process is adequate in identifying, measuring, monitoring, and controlling Market Risk.
- The Market Risk Management Information System (SIM) is good, producing comprehensive and integrated Market Risk reports to the Board of Commissioners and Board of Directors.
- Generally, human resources are adequate in terms of quantity and competence in the Market Risk management function.
- The internal control system is effective in supporting the implementation of Market Risk management.
- The implementation of independent review by the internal audit work unit and functions performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- There are weaknesses but they are not significant based on the results of independent reviews.
- Follow-up on independent reviews has been carried out adequately.
Fair (3)
The quality of Liquidity Risk management implementation is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention. (Note: The text below describes Market Risk characteristics despite the definition header mentioning Liquidity Risk, consistent with source structure) Examples of Bank characteristics included in this rating are as follows:
- The Board of Commissioners and Board of Directors have a fairly good awareness and understanding of Market Risk management.
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is fairly adequate and aligned with the overall strategic and business objectives of the Bank.
- The Market Risk management culture is fairly strong and has been internalized fairly well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is fairly adequate. There are weaknesses in some assessment aspects that need management attention.
- The Market Risk management function, including related committees, is independent, has clear tasks and responsibilities, and operates fairly well, but there are some weaknesses that need management attention.
- Delegation of authority is fairly good, but control and monitoring are not always implemented well.
- Market Risk management strategies, including trading strategies and banking book position management, are fairly adequate.
- Market Risk policies, procedures, and limits are fairly adequate and available for all areas of Market Risk management, aligned with implementation, and well understood by staff.
- The Market Risk management process is fairly adequate in identifying, measuring, monitoring, and controlling Market Risk.
- The Market Risk Management Information System (SIM) meets minimum expectations but has some weaknesses, including reporting to the Board of Commissioners and Board of Directors, which requires management attention.
- Generally, human resources are fairly adequate in terms of quantity and competence in the Market Risk management function.
- The internal control system is fairly effective in supporting the implementation of Market Risk management.
- The implementation of independent review by the internal audit work unit and functions performing independent review is fairly adequate. There are some weaknesses in methodology, frequency, or reporting to the Board of Commissioners and Board of Directors that require management attention.
- There are fairly significant weaknesses based on the results of independent reviews.
- Follow-up on independent reviews has been carried out fairly adequately.
Marginal (4)
The quality of Liquidity Risk management implementation is inadequate. There are significant weaknesses in various aspects of Liquidity Risk management that require immediate corrective action. (Note: The text below describes Market Risk characteristics despite the definition header mentioning Liquidity Risk, consistent with source structure) Examples of Bank characteristics included in this rating are as follows:
- Significant weakness in the awareness and understanding of the Board of Commissioners and Board of Directors regarding Market Risk management.
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and not aligned with the overall strategic and business objectives of the Bank.
- The Market Risk management culture is weak and has not been internalized well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is inadequate. There are some weaknesses in some assessment aspects that need management attention.
- Significant weakness in the Market Risk management function requiring immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Market Risk management strategy is inadequate. There are weaknesses in liquidity management aspects that require immediate improvement.
- Significant weakness in Market Risk policies, procedures, and limits.
- The Market Risk management process is inadequate in identifying, measuring, monitoring, and controlling Market Risk.
- Significant weakness in the Market Risk Management Information System (SIM), including reporting to the Board of Commissioners and Board of Directors, requiring immediate improvement.
- Human resources are inadequate in terms of quantity and competence in the Market Risk management function.
- There are significant weaknesses based on the results of independent reviews that require immediate corrective action.
- Follow-up on independent reviews is inadequate.
Unsatisfactory (5)
The quality of Liquidity Risk management implementation is inadequate. There are significant weaknesses in various aspects of Liquidity Risk management where resolution actions are beyond management's capability. (Note: The text below describes Market Risk characteristics despite the definition header mentioning Liquidity Risk, consistent with source structure) Examples of Bank characteristics included in this rating are as follows:
- Awareness and understanding of the Board of Commissioners and Board of Directors regarding Market Risk management are very weak.
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and has no connection with the overall strategic and business objectives of the Bank.
- The Market Risk management culture is not strong or does not exist at all.
- The execution of duties by Commissioners and Directors is inadequate. There are weaknesses in almost all assessment aspects where resolution actions are beyond the Bank's capability.
- Significant weakness in the Market Risk management function requiring fundamental improvement.
- Delegation of authority is very weak or non-existent.
- Market Risk management strategy is inadequate. There are weaknesses in almost all aspects of Market Risk management requiring immediate improvement.
- Very significant weakness in Market Risk policies, procedures, and limits.
- The Market Risk management process is inadequate in identifying, measuring, monitoring, and controlling Market Risk.
- Fundamental weakness in the Liquidity Risk Management Information System (SIM). Reporting of Liquidity Risk to the Board of Commissioners and Board of Directors is very inadequate.
- Human resources are inadequate in terms of quantity and competence in the Market Risk management function.
- The internal control system is ineffective in supporting the implementation of Market Risk management.
- The implementation of independent review by the internal audit work unit and functions performing independent review is inadequate. There are very significant weaknesses in methodology, frequency, or reporting to the Board of Commissioners and Board of Directors that require fundamental improvement.
- There are very significant weaknesses based on the results of independent reviews where corrective actions are beyond management's capability.
APPENDIX III.2.4.a
Matrix for Setting the Inherent Risk Rating for Liquidity Risk
Rating Definition
Low (1)
Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Liquidity Risk is classified as very low during a certain period in the future. Examples of Bank characteristics included in this rating are as follows:
- The Bank has high-quality liquid assets that are very adequate to cover maturing liabilities.
- Funding sources consisting of unstable (volatile) funding are not significant.
- The volume of administrative account transactions and/or intra-group funding commitments is not significant.
- Concentration on unstable (volatile) funding sources is not significant.
- The Bank is very capable of meeting obligations and cash flow needs under normal conditions and crisis scenarios.
- Cash flows originating from assets and liabilities offset each other very well.
- Access to funding sources is very adequate, evidenced by the Bank's very good reputation, very adequate stand-by financing, and liquidity commitment/support from the parent company/intra-group.
Low to Moderate (2)
Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Liquidity Risk is classified as low during a certain period in the future. Examples of Bank characteristics included in this rating are as follows:
- The Bank has high-quality liquid assets that are adequate to cover maturing liabilities.
- Funding sources consisting of unstable (volatile) funding are less significant.
- The volume of administrative account transactions and/or intra-group funding commitments is less significant.
- Concentration on unstable (volatile) funding sources is less significant.
- The Bank is capable of meeting obligations and cash flow needs under normal conditions and crisis scenarios.
- Cash flows originating from assets and liabilities offset each other well.
- Access to funding sources is adequate, evidenced by the Bank's good reputation, adequate stand-by financing, and liquidity commitment/support from the parent company/intra-group.
Moderate (3)
Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Liquidity Risk is classified as fairly high during a certain period in the future. Examples of Bank characteristics included in this rating are as follows:
- The Bank's liquid assets are fairly adequate to cover maturing liabilities.
- Funding sources consisting of unstable (volatile) funding are fairly significant.
- The volume of administrative account transactions and/or intra-group funding commitments is fairly significant.
- Concentration on unstable (volatile) funding sources is fairly significant.
- The Bank is fairly capable of meeting obligations and cash flow needs under normal conditions and crisis scenarios.
- Cash flows originating from assets and liabilities offset each other fairly well.
- Access to funding sources is fairly adequate, evidenced by the Bank's fairly good reputation, fairly adequate stand-by financing, and liquidity commitment/support from the parent company/intra-group.
Moderate to High (4)
Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Liquidity Risk is classified as high during a certain period in the future. Examples of Bank characteristics included in this rating are as follows:
- There are concerns regarding the quality of the Bank's liquid assets and the ability of liquid assets to cover maturing liabilities.
- Funding sources consisting of unstable (volatile) funding are significant.
- Administrative account transactions and/or intra-group funding commitments are significant.
- Concentration on unstable (volatile) funding sources is significant.
- The Bank is less capable of meeting obligations and cash flow needs under normal conditions and crisis scenarios.
- Cash flow mismatches at various time scales are significant.
- Access to funding sources is less adequate due to the Bank's poor reputation, limited stand-by financing, and lack of liquidity commitment/support from the parent company/intra-group.
High (5)
Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Liquidity Risk is classified as very high during a certain period in the future. Examples of Bank characteristics included in this rating are as follows:
- Liquid asset quality is poor, and the volume of liquid assets is very insufficient to meet maturing liabilities.
- Funding sources consisting of unstable (volatile) funding are very significant.
- Administrative account transactions and/or intra-group funding commitments are significant.
- Concentration on unstable (volatile) funding sources is very significant.
- The Bank is unable to meet obligations and cash flow needs under normal conditions and crisis scenarios.
- Cash flows cannot offset each other at almost all significant times.
- Access to funding sources is less adequate due to deteriorating Bank reputation, unavailability of stand-by financing, and lack of liquidity commitment/support from the parent company/intra-group.
APPENDIX III.2.4.b
For Liquidity Risk
Rating Definition
Strong (1)
The quality of Liquidity Risk management is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored.
Examples of Bank characteristics included in this rating are as follows:
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is very adequate and aligned with the overall strategic and business strategy objectives of the Bank.
- The Board of Commissioners and Board of Directors have a very good awareness and understanding of Liquidity Risk management.
- The Liquidity Risk management culture is very strong and has been internalized very well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is very adequate.
- The Liquidity Risk management function, including ALCO and other related committees, is independent, has clear tasks and responsibilities, and operates very well.
- Delegation of authority is controlled and monitored periodically, and operates very well.
- Liquidity management strategy is very adequate, covering among others funding strategy, intraday position and Liquidity Risk management strategy, intra-group position and Liquidity Risk management, high-quality liquid asset management as collateral, and emergency funding plan (Contingency Funding Plan/CFP).
- Liquidity Risk policies, procedures, and limits are very adequate and available for all areas of Liquidity Risk management, aligned with implementation, and well understood by employees.
- The Liquidity Risk management process is very adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
- The Liquidity Risk Management Information System (SIM) is very good, producing comprehensive and integrated Liquidity Risk reports to the Board of Commissioners and Board of Directors.
- Generally, human resources are very adequate in terms of quantity and competence in the Liquidity Risk management function.
- The internal control system is very effective in supporting the implementation of Liquidity Risk management.
- The implementation of independent review by the internal audit work unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- Generally, there are no significant weaknesses based on the results of independent reviews.
- Follow-up on independent reviews has been carried out very adequately.
Satisfactory (2)
The quality of Liquidity Risk management is adequate. There are some minor weaknesses, but these weaknesses can be resolved in normal business activities.
Examples of Bank characteristics included in this rating are as follows:
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is adequate and aligned with the overall strategic and business strategy objectives of the Bank.
- The Board of Commissioners and Board of Directors have a good awareness and understanding of Liquidity Risk management.
- The Liquidity Risk management culture is strong and has been internalized well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is adequate. There are some weaknesses but they are not significant and can be repaired immediately.
- The Liquidity Risk management function, including ALCO and other related committees, is independent, has clear tasks and responsibilities, and operates well. There are minor weaknesses but can be resolved in normal business activities.
- Delegation of authority is controlled and monitored periodically, and operates well.
- Liquidity management strategy is adequate, covering among others funding strategy, intraday position and Liquidity Risk management strategy, intra-group position and Liquidity Risk management, high-quality liquid asset management as collateral, and emergency funding plan (Contingency Funding Plan/CFP).
- Liquidity Risk policies, procedures, and limits are adequate and available for all areas of Liquidity Risk management, aligned with implementation, and well understood by employees.
- The Liquidity Risk management process is adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
- The Liquidity Risk Management Information System (SIM) is good, producing comprehensive and integrated Liquidity Risk reports to the Board of Commissioners and Board of Directors.
- Generally, human resources are adequate in terms of quantity and competence in the Liquidity Risk management function.
- The internal control system is effective in supporting the implementation of Liquidity Risk management.
- The implementation of independent review by the internal audit work unit and functions performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- There are weaknesses but they are not significant based on the results of independent reviews.
- Follow-up on independent reviews has been carried out adequately.
Fair (3)
The quality of Liquidity Risk management is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Bank characteristics included in this rating are as follows:
- The formulation of the level of risk to be taken (risk appetite) and risk tolerance is fairly adequate and aligned with the overall strategic and business strategy objectives of the Bank.
- The Board of Commissioners and Board of Directors have a fairly good awareness and understanding of Liquidity Risk management.
- The Liquidity Risk management culture is fairly strong and has been internalized fairly well at all levels of the organization.
- The execution of duties by Commissioners and Directors as a whole is fairly adequate. There are weaknesses in some assessment aspects that need management attention.
- The Liquidity Risk management function, including ALCO and other related committees...
Rating Definition Rating
Other related committees are independent, have clear tasks and responsibilities, and have been running quite well, but there are some weaknesses that need management attention.
- Delegation of authority is quite good, but control and monitoring are not always implemented well.
- Liquidity management strategy is quite adequate. There are some weaknesses in one or more aspects of liquidity management that need management attention.
- Policies, procedures, and limits for Liquidity Risk are quite adequate but not always consistent with implementation.
- The Liquidity Risk management process is quite adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
- The Management Information System (MIS) for Liquidity Risk meets minimum expectations but there are some weaknesses including reporting to the Board of Commissioners and Directors that requires management attention.
- Generally, human resources are quite adequate in terms of quantity and competence in the Liquidity Risk management function.
- The internal control system is quite effective in supporting the implementation of Liquidity Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is quite adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require management attention.
- There are significant weaknesses based on the results of independent review.
- Follow-up on independent review has been carried out quite adequately.
Marginal
(4)
The quality of Liquidity Risk management is inadequate. There are significant weaknesses in various aspects of Credit Risk management that require immediate corrective action. Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and not aligned with strategic objectives and the Bank's overall business strategy.
- Significant weakness in awareness and understanding of the Board...
Rating Definition Rating
Board of Commissioners and Directors regarding Liquidity Risk management.
- Liquidity Risk management culture is weak and has not been well internalized at every level of work units.
- Execution of duties by Commissioners and Directors as a whole is inadequate. There are some weaknesses in several aspects of assessment that need to be improved immediately.
- Significant weakness in the Liquidity Risk management function that requires immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Liquidity management strategy is inadequate. There are weaknesses in aspects of liquidity management that require immediate improvement.
- Significant weakness in policies, procedures, and limits for Liquidity Risk.
- The Liquidity Risk management process is inadequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
- Significant weakness in the Management Information System (MIS) for Liquidity Risk including reporting to the Board of Commissioners and Directors that requires immediate improvement.
- Human resources are inadequate in terms of quantity and competence in the Liquidity Risk management function.
- The internal control system is less effective in supporting the implementation of Liquidity Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require immediate improvement.
- There are significant weaknesses based on the results of independent review that require immediate corrective action.
- Follow-up on independent review is inadequate.
Unstatisfactory
(5)
The quality of Credit Risk management is inadequate. There are significant weaknesses in various aspects of Credit Risk management where resolution actions are beyond management's capability. Example...
Rating Definition Rating
Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with strategic objectives and the Bank's overall business strategy.
- Awareness and understanding of the Board of Commissioners and Directors regarding Liquidity Risk management is very weak.
- Liquidity Risk management culture is not strong or does not exist at all.
- Execution of duties by Commissioners and Directors is inadequate. There are significant weaknesses in almost all aspects of assessment where resolution actions are beyond the Bank's capability.
- Significant weakness in the Liquidity Risk management function that requires fundamental improvement.
- Delegation of authority is very weak or non-existent.
- Liquidity management strategy is inadequate. There are weaknesses in almost all aspects of liquidity management that require immediate improvement.
- Very significant weakness in policies, procedures, and limits for Liquidity Risk.
- The Liquidity Risk management process is inadequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
- Fundamental weakness in the Management Information System (MIS) for Liquidity Risk. Reporting of Liquidity Risk to the Board of Commissioners and Directors is very inadequate.
- Human resources are inadequate in terms of quantity and competence in the Liquidity Risk management function.
- The internal control system is ineffective in supporting the implementation of Liquidity Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require fundamental improvement.
- There are very significant weaknesses based on the results of independent review where corrective actions are beyond management's capability.
or...
Rating Definition Rating
APPENDIX...
APPENDIX III.2.5.a
Matrix for Setting Inherent Risk Ratings for Operational Risk Rating Definition Rating Low (1) Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Operational Risk is classified as very low during a certain period in the future. Examples of characteristics of Banks included in this ranking include the following:
- The Bank's business has very simple characteristics. Products and services are not varied, business mechanisms are very simple, transaction volume is low, organizational structure is not complex, there are no significant corporate actions, and use of outsourcing services is very minimal.
- Human resources are very adequate, both in terms of sufficiency of quantity and quality of HR. Historical data on losses due to human error is not significant.
- Information Technology (IT) is very mature and there are no significant changes in IT systems. IT vulnerability to disruption/attacks is very low. Supporting infrastructure is very reliable in supporting the Bank's business.
- Frequency and materiality of internal and external fraud are very low and losses caused are not significant compared to the Bank's transaction volume/revenue.
- Threats of business disruption as a result of external events are very low.
Low to
Moderate (2)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Operational Risk is low during a certain period in the future. Examples of characteristics of Banks included in this ranking include the following:
- The Bank's business has very simple characteristics. Products and services are relatively less varied, business mechanisms are simple, transaction volume is relatively low, organizational structure is less complex, corporate actions are less significant, and use of outsourcing services is minimal.
- Human resources are adequate, both in terms of sufficiency of quantity and quality of HR. Historical data on losses due to human error is less significant.
- Information Technology (IT) is relatively mature and there are no significant changes in IT systems.
Vulnerability...
Rating Definition Rating
IT vulnerability to disruption/attacks is low.
Supporting infrastructure is reliable in supporting the Bank's business.
- Frequency and materiality of internal and external fraud are low and losses caused are less significant compared to the Bank's transaction volume/revenue.
- Threats of business disruption as a result of external events are low.
Moderate (3) Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Operational Risk is classified as quite high during a certain period in the future. Examples of characteristics of Banks included in this ranking include the following:
- The Bank's business has quite complex characteristics. Products and services are quite varied, business mechanisms are quite complex, transaction volume is quite high, organizational structure is quite complex, corporate actions are quite significant, and use of outsourcing services is quite significant.
- Human resources are quite adequate, both in terms of sufficiency of quantity and quality of HR. Historical data on losses due to human error is quite significant.
- Information technology is moving towards maturity and there may be significant changes in IT systems. IT is quite vulnerable to disruption/attacks. Supporting infrastructure is quite reliable in supporting the Bank's business.
- Frequency and materiality of internal and external fraud are quite high and losses caused are quite significant compared to the Bank's transaction volume/revenue.
- Threats of business disruption as a result of external events are quite high.
Moderate to
High (4)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Operational Risk is classified as high during a certain period in the future. Examples of characteristics of Banks included in this ranking include the following:
- The Bank's business has complex characteristics. Products and services are varied, business mechanisms are complex, transaction volume is high, organizational structure is complex, corporate actions are significant, and use of outsourcing services is significant.
- Human resources are adequate, both in terms of sufficiency of...
Rating Definition Rating quantity and quality of HR. Historical data on losses due to human error is significant.
- Information technology is not yet mature and there are significant changes in IT systems. IT is vulnerable to disruption/attacks. Supporting infrastructure is less reliable in supporting the Bank's business.
- Frequency and materiality of internal and external fraud are high and losses caused are significant compared to the Bank's transaction volume/revenue.
- Threats of business disruption as a result of external events are high.
High (5) Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Operational Risk is classified as very high during a certain period in the future. Examples of characteristics of Banks included in this ranking include the following:
- The Bank's business has very complex characteristics. Products and services are very varied, business mechanisms are very complex, transaction volume is very high, organizational structure is very complex, corporate actions are significant, and use of outsourcing services is very high.
- Human resources are inadequate, both in terms of sufficiency of quantity and quality of HR. Historical data on losses due to human error is very significant.
- Information technology is not yet mature and there are significant changes in IT systems. IT is very vulnerable to disruption/attacks. Supporting infrastructure is unreliable in supporting the Bank's business.
- Frequency and materiality of internal and external fraud are very high and losses caused are very significant compared to the Bank's transaction volume/revenue.
- Threats of business disruption as a result of external events are very high.
APPENDIX...
APPENDIX III.2.5.b
For Operational Risk
Rating Definition Rating
Strong
(1)
The quality of Operational Risk management is very adequate.
Although there are minor weaknesses, these weaknesses are not significant so they can be ignored.
Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has been aligned with strategic objectives and the Bank's overall business strategy.
- The Board of Commissioners and Directors have very good awareness and understanding regarding Operational Risk management.
- Operational Risk management culture is very strong and has been very well internalized at all levels of the organization.
- Execution of duties by Commissioners and Directors as a whole is very adequate.
- Operational Risk management function is independent, has clear tasks and responsibilities, and has been running very well.
- Delegation of authority has been running very well.
- Operational Risk strategy is very aligned with the level of Risk to be taken and Operational Risk tolerance.
- Policies, procedures, and limits for Operational Risk are very adequate and available for all areas of Operational Risk management, aligned with implementation, and well understood by employees.
- The Operational Risk management process is very adequate in identifying, measuring, monitoring, and controlling Operational Risk.
- Business Continuity Management is very reliable and very tested.
- The Management Information System (MIS) for Operational Risk is very good, resulting in comprehensive and integrated Operational Risk Reports to the Board of Commissioners and Directors.
- Generally, human resources are very adequate in terms of quantity and competence in the Operational Risk management function.
- The internal control system is very effective in supporting...
Rating Definition Rating supporting the implementation of Operational Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is very adequate both in terms of methodology, frequency, and reporting to the Board of Commissioners and Directors.
- Generally, there are no significant weaknesses based on the results of independent review.
- Follow-up on independent review has been carried out very adequately.
Satisfactory
(2)
The quality of Operational Risk management is adequate.
Although there are some minor weaknesses, these weaknesses can be resolved in normal business activities.
Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has been aligned with strategic objectives and the Bank's overall business strategy.
- The Board of Commissioners and Directors have good awareness and understanding regarding Operational Risk management.
- Operational Risk management culture is strong and has been well internalized at all levels of the organization.
- Execution of duties by Commissioners and Directors is generally adequate. There are some weaknesses but they are not significant and can be improved immediately.
- Operational Risk management function is independent, has clear tasks and responsibilities, and has been running well. There are minor weaknesses, but they can be resolved in normal business activities.
- Delegation of authority has been running well.
- Operational Risk strategy is aligned with the level of Risk to be taken and Operational Risk tolerance.
- Policies, procedures, and limits for Operational Risk are adequate and available for all areas of Operational Risk management, aligned with implementation, and well understood by employees although there are minor weaknesses.
- The Operational Risk management process is adequate in identifying, measuring, monitoring, and controlling Operational Risk.
- Business Continuity Management is reliable and tested.
System...
Rating Definition Rating
- The Management Information System (MIS) for Operational Risk is good including reporting of Operational Risk to the Board of Commissioners and Directors. There are minor weaknesses but they can be easily repaired.
- Human resources are adequate, both in terms of quantity and competence in the Operational Risk management function.
- The internal control system is effective in supporting the implementation of Operational Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is adequate both in terms of methodology, frequency, and reporting to the Board of Commissioners and Directors.
- There are weaknesses but they are not significant based on the results of independent review.
- Follow-up on independent review has been carried out adequately.
Fair
(3)
The quality of Operational Risk management is quite adequate.
Although minimum requirements are met, there are some weaknesses that require management attention.
Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is quite adequate but not always aligned with strategic objectives and the Bank's overall business strategy.
- The Board of Commissioners and Directors have quite good awareness and understanding regarding Operational Risk management.
- Operational Risk management culture is quite strong and has been internalized quite well but not always implemented consistently.
- Execution of duties by Commissioners and Directors is generally quite adequate.
- Operational Risk management function is quite good, but there are some weaknesses that need management attention.
- Delegation of authority has been running quite well.
- Operational Risk strategy is quite aligned with the level of Risk to be taken and Operational Risk tolerance.
- Policies, procedures, and limits for Operational Risk are quite adequate but not always consistent with implementation.
Process...
Rating Definition Rating
- The Operational Risk management process is quite adequate in identifying, measuring, monitoring, and controlling Operational Risk.
- Business Continuity Management is quite reliable.
- The Management Information System (MIS) for Risk meets minimum expectations but there are some weaknesses including reporting to the Board of Commissioners and Directors that requires management attention.
- Generally, human resources are quite adequate in terms of quantity and competence in the Operational Risk management function.
- The internal control system is quite effective in supporting the implementation of Operational Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is quite adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require management attention.
- There are quite significant weaknesses based on the results of independent review that require management attention.
- Follow-up on independent review has been carried out quite adequately.
Marginal
(4)
The quality of Operational Risk management is less adequate. There are significant weaknesses in various aspects of Operational Risk management that require immediate corrective action. Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and not aligned with strategic objectives and the Bank's overall business strategy.
- Significant weakness in awareness and understanding of the Board of Commissioners and Directors regarding Operational Risk management.
- Operational Risk management culture is weak and has not been well internalized at every level of work units.
- Execution of duties by Commissioners and Directors is generally inadequate. There are weaknesses in various aspects of assessment that require immediate improvement.
- Significant weakness in the Operational Risk management function that requires immediate improvement.
Delegation...
Rating Definition Rating
- Delegation of authority is weak.
- Operational Risk strategy is less aligned with the level of Risk to be taken and Operational Risk tolerance.
- Significant weakness in policies, procedures, and limits for Operational Risk.
- The Operational Risk management process is inadequate in identifying, measuring, monitoring, and controlling Operational Risk.
- Business Continuity Management is less reliable.
- Significant weakness in the Management Information System (MIS) for Operational Risk including reporting to the Board of Commissioners and Directors that requires immediate improvement.
- Human resources are inadequate in terms of quantity and competence in the Operational Risk management function.
- The internal control system is less effective in supporting the implementation of Operational Risk management.
- Implementation of independent review by the internal audit work unit and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require immediate improvement.
- There are significant weaknesses based on the results of independent review that require immediate corrective action.
- Follow-up on independent review is inadequate.
Unstatisfactory
(5)
The quality of Operational Risk management is inadequate. There are significant weaknesses in various aspects of Operational Risk Management where resolution actions are beyond management's capability. Examples of characteristics of Banks included in this ranking include the following:
- Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with strategic objectives and the Bank's overall business strategy.
- Awareness and understanding of the Board of Commissioners and Directors regarding Operational Risk management is very weak.
- Operational Risk management culture is not strong or does not exist at all.
Rank Definition Rank
- The execution of duties by the Board of Commissioners and Board of Directors is inadequate.
Significant weaknesses exist in almost all aspects of assessment and remedial actions beyond the Bank's capability.
- Significant weakness in the Operational Risk Management function requiring fundamental improvement.
- Delegation of authority is very weak.
- Operational Risk Strategy is not aligned with the level of Risk to be taken and Operational Risk tolerance.
- Very significant weakness in Operational Risk policies, procedures, and limits.
- The Operational Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Operational Risk.
- Business Continuity Management is unreliable.
- Fundamental weakness in the Operational Risk Management Information System (SIM).
- Human resources are inadequate in terms of quantity and competence in the Operational Risk Management function.
- The internal control system is ineffective in supporting the implementation of Operational Risk Management.
- The execution of independent review by the internal audit unit and the function performing independent review is inadequate.
There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors requiring fundamental improvement.
- There are very significant weaknesses based on the results of independent review requiring immediate remedial action.
APPENDIX...
APPENDIX III.2.6.a
Matrix for Determining Inherent Risk Rating for Legal Risk
Rank Definition Rank
Low (1) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Legal Risk is classified as very low during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There is no litigation process occurring at the Bank or there is a litigation process but the frequency and/or financial impact of the lawsuit is not significant enough to disturb the Bank's financial condition and does not have a major impact on the Bank's reputation.
- Agreements made by the Bank are very adequate.
- All of the Bank's activities and products comply with applicable legislation.
Low to Moderate (2) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Legal Risk is classified as low during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There is a litigation process but the frequency and/or financial impact of the lawsuit is less significant enough to disturb the Bank's financial condition and has less major impact on the Bank's reputation.
- Agreements made by the Bank are adequate.
- There are activities and products not regulated in applicable legislation in an insignificant amount.
Moderate (3) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Legal Risk is classified as moderately high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There is a litigation process occurring at the Bank but the frequency and/or financial impact of the lawsuit is quite significant so as to less disturb the Bank's financial condition but has the possibility of emerging Reputational Risk for the Bank;
- Agreements made by the Bank are quite adequate.
- There are activities and products not regulated in applicable legislation in a quite significant amount.
Moderate to High (4) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Legal Risk is classified as high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There is a litigation process occurring at the Bank and the frequency and/or financial impact of the lawsuit is significant so that if the Bank loses, the compensation for the lawsuit can disturb the Bank's financial condition and have a major impact on the Bank's reputation.
- Agreements made by the Bank are less adequate.
- There are activities and products not regulated in applicable legislation in a significant amount.
High (5) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Legal Risk is classified as very high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There is a litigation process against the Bank by Bank customers/debtors in frequency and/or financial impact that is very significant so that if the Bank is defeated in a court decision, that condition can significantly affect the Bank's business condition.
- Agreements made by the Bank are inadequate.
- There are activities and products not regulated in applicable legislation in a very significant amount.
APPENDIX...
APPENDIX III.2.6.b
For Legal Risk
Rank Definition Rank
Strong (1) The quality of Legal Risk Management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and aligned with the Bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have very good awareness and understanding of Legal Risk Management.
- Legal Risk Management culture is very strong and has been internalized very well at all levels of the organization.
- The execution of duties by Commissioners and Directors is overall very adequate.
- The Legal Risk Management function is independent, has clear duties and responsibilities, and has been running very well.
- Delegation of authority is controlled and monitored periodically, and has been running very well.
- Legal Risk Strategy is very aligned with the level of Risk to be taken and Risk tolerance.
- Legal Risk Management policies and procedures are very adequate and available for all areas of Legal Risk Management, aligned with implementation, and well understood by employees.
- The Legal Risk Management process is very adequate in identifying, measuring, monitoring, and controlling Legal Risk.
- The Legal Risk Management Information System (SIM) is very good so as to produce comprehensive Legal Risk Reports integrated to the Board of Commissioners and Board of Directors.
- Generally, human resources are very adequate in terms of quantity and competence in the Legal Risk Management function.
- The internal control system is very effective in supporting the implementation of Risk Management.
- The execution of independent review by the internal audit unit and the function performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- Generally, there are no significant weaknesses based on independent review results.
- Follow-up on independent review has been executed very adequately.
Satisfactory (2) The quality of Legal Risk Management implementation is adequate although there are some minor weaknesses, but these weaknesses can be resolved in normal business activities. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and aligned with the Bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have good awareness and understanding of Legal Risk Management.
- Legal Risk Management culture is strong and has been internalized well at all levels of the organization.
- The execution of duties by Commissioners and Directors is generally adequate. There are some weaknesses but not significant and can be repaired immediately.
- The Legal Risk Management function has clear duties and responsibilities and has been running well. There are minor weaknesses, but can be resolved in normal business activities.
- Delegation of authority is controlled and monitored periodically, and has been running well.
- Legal Risk Strategy is aligned with the level of Risk to be taken and Risk tolerance.
- Legal Risk Management policies and procedures are adequate and available for all areas of Legal Risk Management, aligned with implementation, and well understood by employees although there are minor weaknesses.
- The Legal Risk Management process is adequate in identifying, measuring, monitoring, and controlling Legal Risk.
- The Legal Risk Management Information System (SIM) is good including Legal Risk reporting to the Board of Commissioners and Board of Directors. There are minor weaknesses but can be easily repaired.
- Human resources are adequate both in terms of quantity and competence in the Legal Risk Management function.
- The internal control system is effective in supporting the implementation of Risk Management.
- The execution of independent review by the internal audit unit and the function performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- There are weaknesses but not significant based on independent review results.
- Follow-up on independent review has been executed adequately.
Fair (3) The quality of Legal Risk Management implementation is quite adequate. Although minimum requirements are met, there are some weaknesses requiring management attention. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is quite adequate but not always aligned with the Bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have quite good awareness and understanding of Legal Risk Management.
- Legal Risk Management culture is quite strong and has been internalized quite well but not always implemented consistently.
- The execution of duties by Commissioners and Directors is generally quite adequate. There are weaknesses in some assessment aspects that need management attention.
- The Legal Risk Management function is quite good, but there are some weaknesses that need management attention.
- Delegation of authority is quite good, but control and monitoring are not always implemented well.
- Legal Risk Strategy is quite aligned with the level of Risk to be taken and Risk tolerance.
- Legal Risk Management policies and procedures are quite adequate but not always consistent with implementation.
- The Legal Risk Management process is quite adequate in identifying, measuring, monitoring, and controlling Legal Risk.
- The Legal Risk Management Information System (SIM) meets minimum expectations but there are some weaknesses including reporting to the Board of Commissioners and Board of Directors requiring management attention.
- Generally, human resources are quite adequate both in terms of quantity and competence in the Legal Risk Management function.
- The internal control system is quite effective in supporting the implementation of Risk Management.
- The execution of independent review by the internal audit unit and the function performing independent review is quite adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors requiring management attention.
- There are quite significant weaknesses based on independent review results requiring management attention.
- Follow-up on independent review has been executed quite adequately.
Marginal (4) The quality of Legal Risk Management implementation is less adequate. There are significant weaknesses in various aspects of Legal Risk Management requiring immediate corrective action. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with the Bank's overall strategic objectives and business strategy.
- Significant weakness in the awareness and understanding of the Board of Commissioners and Board of Directors regarding Legal Risk Management.
- Legal Risk Management culture is less strong and has not been internalized well at every level of work unit.
- The execution of duties by Commissioners and Directors is generally less adequate. There are weaknesses in various assessment aspects requiring immediate improvement.
- Significant weakness in the Legal Risk Management function requiring immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Legal Risk Strategy is less aligned with the level of Risk to be taken and Risk tolerance.
- Significant weakness in Legal Risk policies, procedures, and limits.
- The Legal Risk Management process is less adequate in identifying, measuring, monitoring, and controlling Legal Risk.
- Significant weakness in the Legal Risk Management Information System (SIM) including reporting to the Board of Commissioners and Board of Directors requiring immediate improvement.
- Human resources are less adequate in terms of quantity and competence in the Legal Risk Management function.
- The internal control system is less effective in supporting the implementation of Risk Management.
- The execution of independent review by the internal audit unit and the function performing independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors requiring immediate improvement.
- There are significant weaknesses based on independent review results requiring immediate remedial action.
- Follow-up on independent review is less adequate.
Unsatisfactory (5) The quality of Legal Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Legal Risk Management where remedial actions are beyond management's capability. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with the Bank's overall strategic objectives and business strategy.
- Awareness and understanding of the Board of Commissioners and Board of Directors is very weak regarding Legal Risk Management.
- Legal Risk Management culture is not strong or does not exist at all.
- Significant weakness in the Legal Risk Management function requiring fundamental improvement.
- Delegation of authority is very weak or non-existent.
- Legal Risk Strategy is not aligned with the level of Risk to be taken and Risk tolerance.
- The Legal Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Legal Risk.
- Fundamental weakness in the Legal Risk Management Information System (SIM). Legal Risk reporting to the Board of Commissioners and Board of Directors is very inadequate.
- Human resources are inadequate in terms of quantity and competence in the Legal Risk Management function.
- The internal control system is ineffective in supporting the implementation of Risk Management.
- The execution of independent review by the internal audit unit and the function performing independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors requiring fundamental improvement.
- There are very significant weaknesses based on independent review results where remedial actions are beyond management's capability.
- Follow-up on independent review is inadequate.
APPENDIX...
APPENDIX III.2.7.a
Matrix for Determining Inherent Risk Level for Strategic Risk
Rank Definition Rank
Low (1) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Strategic Risk is classified as very low during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- The Bank's strategy is classified as conservative or low risk.
- The Bank's products/business activities are classified as stable, not complex, and diversified.
- The Bank continues existing strategies with a high level of strategic success.
- The Bank has stable competitive advantages, and there are no threats from competitors.
- The Bank's business plan achievement is very adequate.
Low to Moderate (2) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Strategic Risk is classified as low during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- The Bank's strategy is low risk but with an increasing trend.
- The Bank's products/business activities are classified as not complex and diversified.
- The Bank continues the same strategy or has some new strategies but still within the Bank's core business and competence.
- The Bank has competitive advantages and competitor threats are classified as minor.
- The Bank's business plan achievement is adequate.
Moderate (3) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Strategic Risk is classified as moderately high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- The Bank's strategy is classified as moderately risky.
- The Bank's products/business activities are generally diversified, but some are classified as complex.
- The Bank's strategic success level is classified as moderate due to threats from competitors.
- The Bank has moderate competitive advantages and there are threats from competitors.
- The Bank's business plan achievement is quite adequate.
Moderate to High (4) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Strategic Risk is classified as high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- The Bank's strategy is classified as moderately risky but with an increasing trend.
- Some of the Bank's products/business activities are concentrated and classified as complex.
- The Bank applies strategies to enter new business/markets with an uncertain level of success.
- The Bank lacks competitive advantages, or there are significant threats from competitors.
- The Bank's business plan achievement is less adequate.
High (5) Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Strategic Risk is classified as very high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- The Bank's strategy is classified as high risk.
- Products/business activities are highly concentrated and classified as complex.
- The majority of the Bank's strategies shift to areas that are different from the main business lines and the Bank's competence.
- The Bank has no competitive advantages, and there are very significant threats from competitors.
- The Bank's business plan achievement is inadequate.
APPENDIX...
APPENDIX III.2.7.b
For Strategic Risk
Rank Definition Rank
Strong (1) The quality of Strategic Risk Management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and aligned with the Bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have very good awareness and understanding of Strategic Risk Management, Strategic Risk sources, and Strategic Risk levels at the Bank.
- Strategic Risk Management culture is very strong and has been internalized very well at all levels of the organization.
- The execution of duties by Commissioners and Directors is overall very adequate.
- The Strategic Risk Management function is independent, has clear duties and responsibilities, and has been running very well.
- Delegation of authority is controlled and monitored periodically, and has been running very well.
- Strategic Risk Management policies and procedures are very adequate and available for all areas of Strategic Risk Management, aligned with implementation, and well understood by employees.
- The Strategic Risk Management process is very adequate in identifying, measuring, monitoring, and controlling Strategic Risk.
- The Strategic Risk Management Information System (SIM) is very good so as to produce comprehensive Strategic Risk Reports integrated to the Board of Commissioners and Board of Directors.
- Generally, human resources are very adequate in terms of quantity and competence in the Strategic Risk Management function.
- The internal control system is very effective in supporting the implementation of Risk Management.
- The execution of independent review by...
Rank Definition by internal audit work units and functions that perform independent review are very adequate both in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- Generally, there are no significant weaknesses based on independent review results.
- Follow-up on independent review has been carried out very adequately.
Satisfactory (2)
The quality of Strategic Risk Management implementation is adequate although there are some minor weaknesses, but these weaknesses can be resolved in normal business activities. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with the Bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have good awareness and understanding of Strategic Risk Management.
- Strategic Risk Management culture is strong and has been well internalized at all organizational levels.
- The execution of duties by Commissioners and Directors is generally adequate. There are some weaknesses but not significant and can be repaired immediately.
- The Strategic Risk Management function has clear duties and responsibilities and has run well. There are minor weaknesses, but can be resolved in normal business activities.
- Delegation of authority is controlled and monitored periodically, and has run well.
- Strategic Risk Management policies and procedures are adequate and available for all areas of Strategic Risk Management, aligned with implementation, and well understood by employees although there are minor weaknesses.
- Strategic Risk Management process is adequate in identifying, measuring, monitoring, and controlling Strategic Risk.
- Strategic Risk Management Information System (SIM) is good including Strategic Risk reporting to the Board of Commissioners and Board of Directors. There are minor weaknesses but can be easily repaired.
Source...
Rank Definition
- Human resources are adequate both in terms of quantity and competence in the Strategic Risk Management function.
- Internal control system is effective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is adequate both in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- There are weaknesses but not significant based on independent review results.
- Follow-up on independent review has been carried out adequately.
Fair (3)
The quality of Strategic Risk Management implementation is quite adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is quite adequate but not always aligned with the Bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have fairly good awareness and understanding of Strategic Risk Management.
- Strategic Risk Management culture is fairly strong and has been internalized fairly well but not always implemented consistently.
- The execution of duties by Commissioners and Directors is generally fairly adequate. There are weaknesses in some assessment aspects that need management attention.
- The Strategic Risk Management function is fairly good, but there are some weaknesses that need management attention.
- Delegation of authority is fairly good, but control and monitoring are not always implemented well.
- Strategic Risk Management policies and procedures are fairly adequate but not always consistent with implementation.
- The Strategic Risk Management function is fairly good, but there are some weaknesses that need management attention.
Rank Definition
Delegation of authority is fairly good, but control and monitoring are not always implemented well.
- Strategic Risk Management policies and procedures are fairly adequate but not always consistent with implementation.
- Strategic Risk Management process is fairly adequate in identifying, measuring, monitoring, and controlling Legal Risk.
- Strategic Risk Management Information System (SIM) meets minimum expectations but there are some weaknesses including reporting to the Board of Commissioners and Board of Directors that require management attention.
- Generally, human resources are fairly adequate both in terms of quantity and competence in the Strategic Risk Management function.
- Internal control system is fairly effective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that require management attention.
- There are fairly significant weaknesses based on independent review results that require management attention.
- Follow-up on independent review has been carried out fairly adequately.
Marginal (4)
The quality of Strategic Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Strategic Risk Management that require immediate corrective action. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and not aligned with the Bank's overall strategic objectives and business strategy.
- Significant weaknesses in awareness and understanding of the Board of Commissioners and Board of Directors regarding Strategic Risk Management.
- Strategic Risk Management culture is weak and has not been well internalized at every level of work units.
Rank Definition
- The execution of duties by Commissioners and Directors is generally inadequate. There are weaknesses in various assessment aspects that require immediate improvement.
- Significant weaknesses in the Strategic Risk Management function that require immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Significant weaknesses in Strategic Risk policies, procedures, and limits.
- Strategic Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Strategic Risk.
- Significant weaknesses in the Strategic Risk Management Information System (SIM) including reporting to the Board of Commissioners and Board of Directors that require immediate improvement.
- Human resources are inadequate in terms of quantity and competence in the Strategic Risk Management function.
- Internal control system is ineffective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that require immediate improvement.
- There are significant weaknesses based on independent review results that require immediate corrective action.
- Follow-up on independent review is inadequate.
Unsatisfactory (5)
The quality of Strategic Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Strategic Risk Management where the resolution actions are beyond management's capability. Examples of Bank characteristics included in this rank are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with the Bank's overall strategic objectives and business strategy.
Awareness...
Rank Definition
- Awareness and understanding of the Board of Commissioners and Board of Directors are very weak regarding Strategic Risk Management.
- Strategic Risk Management culture is not strong or does not exist at all.
- The execution of duties by Commissioners and Directors is inadequate. There are significant weaknesses in almost all assessment aspects and the actions and resolutions are beyond the Bank's capability.
- Significant weaknesses in the Strategic Risk Management function that require fundamental improvement.
- Delegation of authority is very weak or non-existent.
- Very significant weaknesses in Strategic Risk policies, procedures, and limits.
- Strategic Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Strategic Risk.
- Fundamental weaknesses in the Strategic Risk Management Information System (SIM).
- Human resources are inadequate in terms of quantity and competence in the Strategic Risk Management function.
- Internal control system is ineffective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that require fundamental improvement.
- There are very significant weaknesses based on independent review results where corrective actions are beyond management's capability.
- Follow-up on independent review is inadequate.
APPENDIX III.2.8.a
Matrix for Setting Inherent Risk Rank for Compliance Risk
Rank Definition
Low (1) Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Compliance Risk are classified as very low during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- No regulatory violations.
- No Sharia principle violations in the operationalization of fund gathering and provision as well as service provision.
- The Bank's compliance track record is very good.
- The Bank has implemented almost all applicable financial standards and codes of ethics.
Low to Moderate (2) Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Compliance Risk are classified as low during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There are relatively minor regulatory violations that can be immediately repaired by the Bank.
- There are relatively minor Sharia principle violations in the operationalization of fund gathering and provision as well as service provision.
- The Bank's compliance track record is good.
- The Bank has implemented almost all applicable financial standards and codes of ethics.
Moderate (3) Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Compliance Risk are classified as fairly high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There are fairly significant regulatory violations that require management attention.
- There are fairly significant Sharia principle violations in the operationalization of fund gathering and provision as well as service provision.
- The Bank's compliance track record is fairly good.
- There are minor violations of applicable financial standards and codes of ethics.
Moderate to High (4) Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Compliance Risk are classified as high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There are significant regulatory violations that require immediate corrective action.
- There are significant Sharia principle violations in the operationalization of fund gathering and provision as well as service provision.
- The Bank's compliance track record is poor.
- There are significant violations of applicable financial standards and codes of ethics.
High (5) Considering the business activities conducted by the Bank, the potential losses faced by the Bank from Compliance Risk are classified as very high during a certain period in the future. Examples of Bank characteristics included in this rank are as follows:
- There are very significant regulatory violations that require immediate corrective action.
- There are very significant Sharia principle violations in the operationalization of fund gathering and provision as well as service provision.
- The Bank's compliance track record is not good.
- There are very significant violations of applicable financial standards and codes of ethics.
APPENDIX III.2.8.b
For Compliance Risk
Rank Definition
Strong (1) The quality of Compliance Risk Management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of Bank characteristics included in this rank are as follows:
- The Board of Commissioners, Board of Directors, and Sharia Supervisory Board have very good awareness and understanding regarding Compliance Risk Management.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has aligned with the Bank's overall strategic objectives and business strategy.
- Compliance Risk Management culture is very strong and has been internalized very well at all organizational levels.
- The execution of duties by Commissioners, Directors, and the Sharia Supervisory Board is overall very adequate.
- The Compliance Risk Management function is independent, has clear duties and responsibilities, and has run very well.
- Delegation of authority is controlled and monitored periodically, and has run very well.
- Compliance Risk Strategy is very aligned with the level of Risk to be taken and Risk tolerance.
- Compliance Risk Management policies and procedures are very adequate and available for all areas of Compliance Risk Management, aligned with implementation, and well understood by employees.
- Compliance Risk Management process is very adequate in identifying, measuring, monitoring, and controlling Compliance Risk.
- Compliance Risk Management Information System (SIM) is very good so as to produce comprehensive and integrated Compliance Risk Reports to Commissioners, Directors, and the Sharia Supervisory Board.
- Generally, human resources are very adequate in terms of quantity and competence in the Compliance Risk Management function.
- Internal control system is very effective in supporting Risk Management implementation.
Rank Definition
- Implementation of independent review by internal audit work units and functions that perform independent review is very adequate both in terms of methodology, frequency, and reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board.
- Generally, there are no significant weaknesses based on independent review results.
- Follow-up on independent review has been carried out very adequately.
Satisfactory (2) The quality of Compliance Risk Management implementation is adequate although there are some minor weaknesses, but these weaknesses can be resolved in normal business activities. Examples of Bank characteristics included in this rank are as follows:
- The Board of Commissioners, Board of Directors, and Sharia Supervisory Board have good awareness and understanding regarding Compliance Risk Management.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with the Bank's overall strategic objectives and business strategy.
- Compliance Risk Management culture is strong and has been internalized well at all organizational levels.
- The execution of duties by Commissioners, Directors, and the Sharia Supervisory Board is generally adequate. There are some weaknesses but not significant and can be repaired immediately.
- The Compliance Risk Management function has clear duties and responsibilities and has run well. There are minor weaknesses, but can be resolved in normal business activities.
- Delegation of authority is controlled and monitored periodically, and has run well.
- Compliance Risk Strategy is aligned with the level of Risk to be taken and Risk tolerance.
- Compliance Risk Management policies and procedures are adequate and available for all areas of Compliance Risk Management, aligned with implementation, and well understood by employees although there are minor weaknesses.
- Compliance Risk Management process is adequate in identifying, measuring, monitoring, and controlling Compliance Risk.
Rank Definition
- Compliance Risk Management Information System (SIM) is good including Compliance Risk reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board. There are minor weaknesses but can be easily repaired.
- Human resources are adequate both in terms of quantity and competence in the Compliance Risk Management function.
- Internal control system is effective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is adequate both in terms of methodology, frequency, and reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board.
- There are weaknesses but not significant based on independent review results.
- Follow-up on independent review has been carried out adequately.
Fair (3) The quality of Compliance Risk Management implementation is quite adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Bank characteristics included in this rank are as follows:
- The Board of Commissioners, Board of Directors, and Sharia Supervisory Board have fairly good awareness and understanding regarding Compliance Risk Management.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is fairly adequate but not always aligned with the Bank's overall strategic objectives and business strategy.
- Compliance Risk Management culture is fairly strong and has been internalized fairly well but not always implemented consistently.
- The execution of duties by Commissioners, Directors, and the Sharia Supervisory Board is generally fairly adequate. There are weaknesses in some assessment aspects that need management attention.
- The Compliance Risk Management function is fairly good, but there are some weaknesses that need management attention.
- Delegation of authority is fairly good, but control and monitoring are not always implemented well.
- Compliance Risk Strategy is fairly aligned with the level of Risk to be taken and Risk tolerance.
Rank Definition
- Compliance Risk Management policies and procedures are fairly adequate but not always consistent with implementation.
- Compliance Risk Management process is fairly adequate in identifying, measuring, monitoring, and controlling Legal Risk.
- Compliance Risk Management Information System (SIM) meets minimum expectations but there are some weaknesses including reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board that require management attention.
- Generally, human resources are fairly adequate both in terms of quantity and competence in the Compliance Risk Management function.
- Internal control system is fairly effective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board that require management attention.
- There are fairly significant weaknesses based on independent review results that require management attention.
- Follow-up on independent review has been carried out fairly adequately.
Marginal (4) The quality of Compliance Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Compliance Risk Management that require immediate corrective action. Examples of Bank characteristics included in this rank are as follows:
- Significant weaknesses in awareness and understanding of the Board of Commissioners, Board of Directors, and Sharia Supervisory Board regarding Compliance Risk Management.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and not aligned with the Bank's overall strategic objectives and business strategy.
- Compliance Risk Management culture is weak and has not been well internalized at every level of work units.
Rank Definition
- The execution of duties by Commissioners, Directors, and the Sharia Supervisory Board is generally inadequate. There are weaknesses in various assessment aspects that require immediate improvement.
- Significant weaknesses in the Compliance Risk Management function that require immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Compliance Risk Strategy is not aligned with the level of Risk to be taken and Risk tolerance.
- Significant weaknesses in Compliance Risk policies, procedures, and limits.
- Compliance Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Compliance Risk.
- Significant weaknesses in the Compliance Risk Management Information System (SIM) including reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board that require immediate improvement.
- Human resources are inadequate in terms of quantity and competence in the Compliance Risk Management function.
- Internal control system is ineffective in supporting Risk Management implementation.
- Implementation of independent review by internal audit work units and functions that perform independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners, Board of Directors, and Sharia Supervisory Board that require immediate improvement.
- There are significant weaknesses based on independent review results that require immediate corrective action.
- Follow-up on independent review is inadequate.
Unsatisfactory (5) The quality of Compliance Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Compliance Risk Management where the resolution actions are beyond management's capability. Examples of Bank characteristics included in this rank are as follows:
- Awareness and understanding of the Board of Commissioners, Board of Directors, and Sharia Supervisory Board are very weak regarding Compliance Risk Management.
Formulation...
Risk Rating Definitions
Low (1)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as very low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Generally, there is no negative reputational influence from the bank's owners and related companies; in fact, it is expected that the owners and related companies can provide a very positive influence on the bank's reputation.
- Violations or potential violations of business ethics are very minimal. The bank has a reputation as a company that highly upholds business ethics.
- The bank's products are not complex and are easy for customers to understand.
- Business cooperation with business partners is very minimal in number.
- The frequency of negative news coverage about the bank is very minimal; negative news is very immaterial, and the scope of coverage is limited.
- The frequency of customer complaints is very minimal and very immaterial.
Low to Moderate (2)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies, but the scale of influence is small and can be well mitigated.
- Business ethics violations/potential violations are minimal, and the bank has a reputation as a company that upholds business ethics.
- The bank's products are simple, so they relatively do not require special understanding by customers.
- Business cooperation with business partners is minimal in number.
- The frequency of negative news coverage about the bank is minimal; negative news is immaterial, and the scope of coverage is small relative to the scale of the bank.
- The frequency of complaints is minimal and immaterial.
Moderate (3)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as moderately high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies; although the scale of influence is quite large, it can still be controlled.
- Business ethics violations/potential violations occur, but the scale of influence is quite significant and may require management attention.
- The bank's products are quite complex, so to a certain extent they require special understanding by customers.
- Business cooperation with business partners is quite numerous.
- The frequency of negative news coverage about the bank is quite high; negative news is quite material, and the scope of coverage is quite wide relative to the scale of the bank.
- The frequency of complaints is quite high and quite material.
Moderate to High (4)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies with a material scale of influence requiring special management attention.
- Business ethics violations/potential violations occur with a material scale of influence requiring special attention.
- The bank's products are complex, requiring special understanding by customers.
- Business cooperation with business partners is material in number.
- The frequency of negative news coverage about the bank is high; negative news is material, and the scope of coverage is large relative to the scale of the bank.
- The frequency of complaints is high and material.
High (5)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as very high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies with a very material scale of influence requiring immediate follow-up and management.
- Business ethics violations/potential violations occur with a very material scale of influence requiring immediate follow-up and management.
- The bank's products are very complex, so they very much require special understanding by customers.
- Business cooperation with business partners is material in number.
- The frequency of negative news coverage about the bank is very high; negative news is very material, and the scope of coverage is very large relative to the scale of the bank.
- The frequency of complaints is very high and very material.
APPENDIX III.2.9.a
Matrix for Determining Inherent Risk Ratings for Reputation Risk
Rating Definition
Low (1)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as very low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Generally, there is no negative reputational influence from the bank's owners and related companies; in fact, it is expected that the owners and related companies can provide a very positive influence on the bank's reputation.
- Violations or potential violations of business ethics are very minimal. The bank has a reputation as a company that highly upholds business ethics.
- The bank's products are not complex and are easy for customers to understand.
- Business cooperation with business partners is very minimal in number.
- The frequency of negative news coverage about the bank is very minimal; negative news is very immaterial, and the scope of coverage is limited.
- The frequency of customer complaints is very minimal and very immaterial.
Low to Moderate (2)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies, but the scale of influence is small and can be well mitigated.
- Business ethics violations/potential violations are minimal, and the bank has a reputation as a company that upholds business ethics.
- The bank's products are simple, so they relatively do not require special understanding by customers.
- Business cooperation with business partners is minimal in number.
- The frequency of negative news coverage about the bank is minimal; negative news is immaterial, and the scope of coverage is small relative to the scale of the bank.
- The frequency of complaints is minimal and immaterial.
Moderate (3)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as moderately high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies; although the scale of influence is quite large, it can still be controlled.
- Business ethics violations/potential violations occur, but the scale of influence is quite significant and may require management attention.
- The bank's products are quite complex, so to a certain extent they require special understanding by customers.
- Business cooperation with business partners is quite numerous.
- The frequency of negative news coverage about the bank is quite high; negative news is quite material, and the scope of coverage is quite wide relative to the scale of the bank.
- The frequency of complaints is quite high and quite material.
Moderate to High (4)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies with a material scale of influence requiring special management attention.
- Business ethics violations/potential violations occur with a material scale of influence requiring special attention.
- The bank's products are complex, requiring special understanding by customers.
- Business cooperation with business partners is material in number.
- The frequency of negative news coverage about the bank is high; negative news is material, and the scope of coverage is large relative to the scale of the bank.
- The frequency of complaints is high and material.
High (5)
Considering the bank's business activities, the potential loss the bank faces from Reputation Risk is classified as very high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- There is a negative reputational influence from the bank's owners and related companies with a very material scale of influence requiring immediate follow-up and management.
- Business ethics violations/potential violations occur with a very material scale of influence requiring immediate follow-up and management.
- The bank's products are very complex, so they very much require special understanding by customers.
- Business cooperation with business partners is material in number.
- The frequency of negative news coverage about the bank is very high; negative news is very material, and the scope of coverage is very large relative to the scale of the bank.
- The frequency of complaints is very high and very material.
APPENDIX III.2.9.b
For Reputation Risk
Rating Definition
Strong (1)
The quality of Reputation Risk management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of bank characteristics included in this rating are as follows:
- The Board of Commissioners and Board of Directors have very good awareness and understanding of Reputation Risk management.
- The formulation of risk appetite and risk tolerance is very adequate and has aligned with the bank's strategic objectives and overall business strategy.
- Reputation Risk management culture is very strong and has been internalized very well at all organizational levels.
- The execution of Commissioners' and Directors' duties overall is very adequate.
- The Reputation Risk management function is independent, has clear tasks and responsibilities, and operates very well.
- Authority delegation is controlled and monitored periodically, and operates very well.
- Reputation Risk strategy is very aligned with risk appetite and risk tolerance.
- Reputation Risk management policies and procedures are very adequate and available for all areas of Reputation Risk management, aligned with implementation, and well understood by employees.
- The Reputation Risk management process is very adequate in identifying, measuring, monitoring, and controlling Reputation Risk.
- The Reputation Risk Management Information System (MIS) is very good, producing comprehensive and integrated Reputation Risk Reports for the Board of Commissioners and Board of Directors.
- Generally, human resources are very adequate in terms of quantity and competence in the Reputation Risk management function.
- The internal control system is very effective in supporting Risk Management implementation.
- Independent review implementation by internal audit units and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- Generally, there are no significant weaknesses based on independent review results.
- Follow-up on independent reviews has been implemented very adequately.
Satisfactory (2)
The quality of Reputation Risk management implementation is adequate, although there are some minor weaknesses, but these weaknesses can be resolved in normal business activities. Examples of bank characteristics included in this rating are as follows:
- The Board of Commissioners and Board of Directors have good awareness and understanding of Reputation Risk management.
- The formulation of risk appetite and risk tolerance is adequate and has aligned with the bank's strategic objectives and overall business strategy.
- Reputation Risk management culture is strong and has been internalized well at all organizational levels.
- The execution of Commissioners' and Directors' duties is generally adequate. There are some weaknesses but not significant and can be repaired immediately.
- The Reputation Risk management function has clear tasks and responsibilities and operates well. There are minor weaknesses, but they can be resolved in normal business activities.
- Authority delegation is controlled and monitored periodically, and operates well.
- Reputation Risk strategy is aligned with risk appetite and risk tolerance.
- Reputation Risk management policies and procedures are adequate and available for all areas of Reputation Risk management, aligned with implementation, and well understood by employees, although there are minor weaknesses.
- The Reputation Risk management process is adequate in identifying, measuring, monitoring, and controlling Reputation Risk.
- The Reputation Risk Management Information System (MIS) is good, including Reputation Risk reporting to the Board of Commissioners and Board of Directors. There are minor weaknesses but can be easily repaired.
- Human resources are adequate in terms of quantity and competence in the Reputation Risk management function.
- The internal control system is effective in supporting Risk Management implementation.
- Independent review implementation by internal audit units and functions performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Board of Directors.
- There are weaknesses but not significant based on independent review results.
- Follow-up on independent reviews has been implemented adequately.
Fair (3)
The quality of Reputation Risk management implementation is quite adequate. Although minimum requirements are met, there are some weaknesses requiring management attention. Examples of bank characteristics included in this rating are as follows:
- The Board of Commissioners and Board of Directors have quite good awareness and understanding of Reputation Risk management.
- The formulation of risk appetite and risk tolerance is quite adequate but not always aligned with the bank's strategic objectives and overall business strategy.
- Reputation Risk management culture is quite strong and has been internalized quite well but not always implemented consistently.
- The execution of Commissioners' and Directors' duties is generally quite adequate. There are weaknesses in some assessment aspects that need management attention.
- The Reputation Risk management function is quite good, but there are some weaknesses that need management attention.
- Authority delegation is quite good, but control and monitoring are not always implemented well.
- Reputation Risk strategy is quite aligned with risk appetite and risk tolerance.
- Reputation Risk management policies and procedures are quite adequate but not always consistent with implementation.
- The Reputation Risk management process is quite adequate in identifying, measuring, monitoring, and controlling Reputation Risk.
- The Reputation Management Information System (MIS) meets minimum expectations but has some weaknesses, including reporting to the Board of Commissioners and Board of Directors that needs management attention.
- Generally, human resources are quite adequate in terms of quantity and competence in the Reputation Risk management function.
- The internal control system is quite effective in supporting Risk Management implementation.
- Independent review implementation by internal audit units and functions performing independent review is quite adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that need management attention.
- There are weaknesses that are quite significant based on independent review results, requiring management attention.
- Follow-up on independent reviews has been implemented quite adequately.
Marginal (4)
The quality of Reputation Risk management implementation is inadequate. There are significant weaknesses in various aspects of Reputation Risk management requiring immediate corrective action. Examples of bank characteristics included in this rating are as follows:
- Significant weaknesses in Board of Commissioners' and Directors' awareness and understanding of Reputation Risk management.
- The formulation of risk appetite and risk tolerance is inadequate and not aligned with the bank's strategic objectives and overall business strategy.
- Reputation Risk management culture is weak and has not been internalized well at every unit of work level.
- The execution of Commissioners' and Directors' duties is generally inadequate. There are weaknesses in various assessment aspects requiring immediate repair.
- Significant weaknesses in the Reputation Risk management function requiring immediate repair.
- Authority delegation is weak and not controlled and monitored well.
- Reputation Risk strategy is not aligned with risk appetite and risk tolerance.
- Significant weaknesses in Reputation Risk policies, procedures, and limits.
- The Reputation Risk management process is inadequate in identifying, measuring, monitoring, and controlling Reputation Risk.
- Significant weaknesses in the Reputation Risk Management Information System (MIS), including reporting to the Board of Commissioners and Board of Directors that needs immediate repair.
- Human resources are inadequate in terms of quantity and competence in the Reputation Risk management function.
- The internal control system is ineffective in supporting Risk Management implementation.
- Independent review implementation by internal audit units and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that need immediate repair.
- There are significant weaknesses based on independent review results requiring immediate repair action.
- Follow-up on independent reviews is inadequate.
Unsatisfactory (5)
The quality of Reputation Risk management implementation is inadequate. There are significant weaknesses in various aspects of Reputation Risk management where the resolution actions are beyond management's capability. Examples of bank characteristics included in this rating are as follows:
- Board of Commissioners' and Directors' awareness and understanding of Reputation Risk management is very weak.
- The formulation of risk appetite and risk tolerance is inadequate and not linked to the bank's strategic objectives and overall business strategy.
- Reputation Risk management culture is weak or does not exist at all.
- Significant weaknesses in the Reputation Risk management function requiring fundamental repair.
- Authority delegation is very weak or non-existent.
- Reputation Risk strategy is not aligned with risk appetite and risk tolerance.
- The Reputation Risk management process is inadequate in identifying, measuring, monitoring, and controlling Reputation Risk.
- Fundamental weaknesses in the Reputation Risk Management Information System (MIS). Reputation Risk reporting to the Board of Commissioners and Board of Directors is very inadequate.
- Human resources are inadequate in terms of quantity and competence in the Reputation Risk management function.
- The internal control system is ineffective in supporting Risk Management implementation.
- Independent review implementation by internal audit units and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Board of Directors that need fundamental repair.
- There are very significant weaknesses based on independent review results where repair actions are beyond management's capability.
APPENDIX III.2.10.a
Matrix for Determining Inherent Risk Ratings for Return Risk
Rating Definition
Low (1)
Considering the bank's business activities, the potential loss the bank faces from Return Risk is classified as very low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- The management of funding sources from investors with high return risk has been done very well.
- The funding portfolio is dominated by exposures with high returns and risks that are very well mitigated.
- Funding exposures are very significantly diversified into contracts with certain and fixed returns.
- Funding has very good quality.
- The bank's funding strategy or business model is classified as stable.
- The funding portfolio is relatively unaffected by changes in external factors.
Low to Moderate (2)
Considering the bank's business activities, the potential loss the bank faces from Investment Risk is classified as low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- The management of funding sources from investors with high return risk has been done well.
- The funding portfolio is dominated by exposures with relatively high returns and risks that are well mitigated.
- Funding exposures are relatively significantly diversified into contracts with certain and fixed returns.
- Funding has good quality.
- The bank's funding strategy or business model is classified as relatively stable.
- The funding portfolio is relatively less affected by changes in external factors.
Moderate (3)
Considering the bank's business activities, the potential loss the bank faces from Investment Risk is classified as moderately high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- The management of funding sources from investors with high return risk has been done quite well.
- The funding portfolio is dominated by exposures with quite high returns and risks that are quite well mitigated.
- Funding exposures are quite significantly diversified into contracts with certain and fixed returns.
- Funding has quite good quality.
- The bank's funding strategy or business model is classified as quite stable.
- The funding portfolio is relatively quite affected by changes in external factors.
Moderate to High (4)
Considering the bank's business activities, the potential loss the bank faces from Return Risk is classified as high during a certain period in the future.
Examples of bank characteristics included in this rating are as follows:
- The management of funding sources from investors with high return risk has been done less well.
- The funding portfolio is dominated by exposures with relatively low returns and risks that are less well mitigated.
- Funding exposures are less diversified into contracts with certain and fixed returns.
- Funding has less good quality.
- There are significant changes in the funding strategy or business model.
- The funding portfolio is affected by changes in external factors.
High (5)
Considering the bank's business activities, the potential loss the bank faces from Return Risk is classified as very high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- The management of funding sources from investors with high return risk has been done poorly.
- The funding portfolio is dominated by exposures with low returns and risks that are poorly mitigated.
- Funding exposures are not diversified into contracts with certain and fixed returns.
- Funding has poor quality.
- There are very significant changes in the funding strategy or business model.
- The funding portfolio is very affected by changes in external factors.
APPENDIX III.2.10.b
For Return Risk
Rating Definition Rating
Strong
(1)
The quality of Return Risk management application is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of bank characteristics included in this rating are as follows:
- The strategy for managing funding sources from investors with high return risk has been carried out very well.
- The strategy for providing funds to portfolios containing high returns and diversified, and having very good quality.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for returns is very adequate and has been in line with the bank's overall strategic objectives and business strategy.
- The Board of Commissioners and Board of Directors have very good awareness and understanding of Return Risk management.
- Return Risk management culture is very strong and has been internalized very well at all levels of the organization.
- The implementation of the duties of Commissioners and Directors as a whole is very adequate.
- The Return Risk management function is independent, has clear tasks and responsibilities, and has run very well.
- The delegation of authority is controlled and monitored periodically, and has run very well.
- Financing strategy is very good and very consistent with the level of Risk to be taken and Return Risk tolerance.
- Return Risk policies, procedures, and limits are very adequate and available for all areas of Return Risk management, consistent with implementation, and well understood by employees.
- The Return Risk management process is very adequate in identifying, measuring, monitoring, and controlling Return Risk.
- The Management Information System (MIS) for Return Risk is very good, resulting in comprehensive and integrated Investment Risk reporting to the Board of Commissioners and Directors.
- Generally, Human Resources (HR) are very adequate in terms of both quantity and competence in the Return Risk management function.
- The internal control system is very effective in supporting the implementation of Return Risk management.
- The implementation of independent review by the Internal Audit Unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Directors.
- Generally, there are no significant weaknesses based on the results of independent review.
- Follow-up on independent review has been carried out very adequately.
Satisfactory
(2)
The quality of Return Risk management application is adequate. Although there are several minor weaknesses, these weaknesses can be resolved in normal business activities. Examples of bank characteristics included in this rating are as follows:
- The strategy for managing funding sources from investors with high return risk has been carried out well.
- The strategy for providing funds to portfolios containing relatively high returns and relatively diversified, and having good quality.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for returns is adequate and has been in line with the bank's strategic objectives and overall business strategy.
- The Board of Commissioners and Board of Directors have good awareness and understanding of Return Risk management.
- Return Risk management culture is strong and has been internalized very well at all levels of the organization.
- The implementation of the duties of Commissioners and Directors as a whole is adequate. There are some weaknesses but not significant and can be repaired immediately.
- The Return Risk management function is independent, has clear tasks and responsibilities, and has run well. There are minor weaknesses, but can be resolved in normal business activities.
- The delegation of authority is controlled and monitored periodically, and has run well.
- Financing strategy is good and consistent with the level of Risk to be taken and Return Risk tolerance.
- Return Risk policies, procedures, and limits are adequate and available for all areas of Return Risk management, consistent with implementation, and well understood by employees.
- The Return Risk management process is adequate in identifying, measuring, monitoring, and controlling Return Risk.
- The Management Information System (MIS) for Return Risk is good, including reporting Return Risk to the Board of Commissioners and Directors. There are minor weaknesses but can be repaired easily.
- Human Resources (HR) are adequate in terms of both quantity and competence in the Return Risk management function.
- The internal control system is effective in supporting the implementation of Return Risk management.
- The implementation of independent review by the Internal Audit Unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Directors.
- There are weaknesses but not significant based on the results of independent review.
- Follow-up on independent review has been carried out adequately.
Fair
(3)
The quality of Return Risk management application is fairly adequate. Although minimum requirements are met, there are several weaknesses that require management attention. Examples of bank characteristics included in this rating are as follows:
- The strategy for managing funding sources from investors with high return risk has been carried out fairly well.
- The strategy for providing funds to portfolios containing fairly high returns and fairly diversified, and having fairly good quality.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for returns is fairly adequate but not always consistent with the bank's strategic objectives and overall business strategy.
- The Board of Commissioners and Board of Directors have fairly good awareness and understanding of Return Risk management.
- Return Risk management culture is fairly strong and has been internalized fairly well but not always implemented consistently.
- The implementation of the duties of Commissioners and Directors as a whole is fairly adequate. There are some weaknesses in some assessment aspects that need management attention.
- The Return Risk management function has run fairly well, but there are several fairly significant weaknesses that need to be resolved immediately by management.
- Delegation of authority is fairly good, but control and monitoring are not always carried out well.
- Financing strategy is fairly consistent with the level of Risk to be taken and Return Risk tolerance.
- Return Risk policies, procedures, and limits are fairly adequate but not always consistent with implementation and/or not well understood by employees.
- The Return Risk management process is fairly adequate in identifying, measuring, monitoring, and controlling Return Risk.
- The Management Information System (MIS) for Return Risk meets minimum expectations but there are several weaknesses including reporting Return Risk to the Board of Commissioners and Directors that require management attention.
- Human Resources (HR) are fairly adequate in terms of both quantity and competence in the Return Risk management function.
- The internal control system is fairly effective in supporting the implementation of Return Risk management.
- The implementation of independent review by the Internal Audit Unit and functions conducting independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require management attention.
- There are fairly significant weaknesses based on the results of independent review.
- Follow-up on independent review has been carried out fairly adequately.
Marginal
(4)
The quality of Return Risk management application is less than adequate. There are significant weaknesses in various aspects of Return Risk management that require immediate corrective action. Examples of bank characteristics included in this rating are as follows:
- The strategy for managing funding sources from investors with high return risk has been carried out less well.
- The strategy for providing funds to portfolios containing low returns and less diversified, and having less good quality.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for returns is less adequate and not consistent with the bank's strategic objectives and overall business strategy.
- Significant weaknesses in the awareness and understanding of the Board of Commissioners and Directors regarding Return Risk management.
- Return Risk management culture is less strong and has not been internalized at every level of work unit.
- The implementation of the duties of Commissioners and Directors as a whole is less adequate. There are weaknesses in some assessment aspects that require immediate improvement.
- Significant weaknesses in the Return Risk management function that require immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Financing strategy is less consistent with the level of Risk to be taken and Return Risk tolerance.
- Significant weaknesses in Return Risk policies, procedures, and limits.
- The Return Risk management process is less adequate in identifying, measuring, monitoring, and controlling Return Risk.
- Significant weaknesses in the Management Information System (MIS) for Return Risk including reporting Risk to the Board of Commissioners and Directors that require immediate improvement.
- Human Resources (HR) are less adequate in terms of quantity and competence in the Return Risk management function.
- The internal control system is less effective in supporting the implementation of Return Risk management.
- The implementation of independent review by the Internal Audit Unit and functions conducting independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require immediate improvement.
- There are significant weaknesses based on the results of independent review that require immediate improvement.
- Follow-up on independent review is less adequate.
Unsatisfactory
(5)
The quality of Return Risk management application is inadequate. There are significant weaknesses in various aspects of Return Risk management where the resolution actions are beyond the capability of management. Examples of bank characteristics included in this rating are as follows:
- The strategy for managing funding sources from investors with high return risk has been carried out not well.
- The strategy for providing funds to portfolios containing low returns and not diversified, and having not good quality.
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for returns is less adequate and not consistent with the bank's strategic objectives and overall business strategy.
- Significant weaknesses in the awareness and understanding of the Board of Commissioners and Directors regarding Return Risk management.
- Return Risk management culture is less strong and has not been internalized at every level of work unit.
- The implementation of the duties of Commissioners and Directors as a whole is less adequate. There are weaknesses in some assessment aspects that require immediate improvement.
- Significant weaknesses in the Return Risk management function that require immediate improvement.
- Delegation of authority is weak and not controlled and monitored well.
- Financing strategy is less consistent with the level of Risk to be taken and Return Risk tolerance.
- Significant weaknesses in Return Risk policies, procedures, and limits.
- The Return Risk management process is less adequate in identifying, measuring, monitoring, and controlling Return Risk.
- Significant weaknesses in the Management Information System (MIS) for Return Risk including reporting Risk to the Board of Commissioners and Directors that require immediate improvement.
- Human Resources (HR) are less adequate in terms of quantity and competence in the Return Risk management function.
- The internal control system is less effective in supporting the implementation of Return Risk management.
- The implementation of independent review by the Internal Audit Unit and functions conducting independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require immediate improvement.
- There are significant weaknesses based on the results of independent review that require immediate improvement.
- Follow-up on independent review is less adequate.
APPENDIX III.2.11.a
Inherent Risk Rating Matrix for Investment Risk
Rating Definition Rating
Low (1) Considering the bank's business activities, the probability of losses faced by the bank from Investment Risk is classified as very low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Funding portfolios based on profit-sharing (mudharabah and musyarakah agreements) are very small.
- Funding based on profit-sharing (mudharabah and musyarakah agreements) has very good quality.
- The bank's funding strategy or business model for profit-sharing agreements is given to customers who have very good track records at the bank and to customer businesses controlled by the bank and have very low risk.
- Funding portfolios based on profit-sharing are relatively unaffected by changes in external factors.
Low to Moderate (2) Considering the bank's business activities, the probability of losses faced by the bank from Investment Risk is classified as low during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Funding portfolios based on profit-sharing (mudharabah and musyarakah agreements) are small.
- Funding based on profit-sharing (mudharabah and musyarakah agreements) has good quality.
- The bank's funding strategy or business model for profit-sharing agreements is given to customers who have good track records at the bank and to customer businesses controlled by the bank and have low risk.
- Funding portfolios based on profit-sharing are less affected by changes in external factors.
Moderate (3) Considering the bank's business activities, the probability of losses faced by the bank from Investment Risk is classified as fairly high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Funding portfolios based on profit-sharing (mudharabah and musyarakah agreements) are fairly significant.
- Funding based on profit-sharing (mudharabah and musyarakah agreements) has fairly good quality.
- The bank's funding strategy or business model for profit-sharing agreements is given to customers who have fairly good track records at the bank and to customer businesses controlled by the bank and have moderate risk.
- Funding portfolios based on profit-sharing are fairly affected by changes in external factors.
Moderate to High (4) Considering the bank's business activities, the probability of losses faced by the bank from Investment Risk is classified as high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Funding portfolios based on profit-sharing (mudharabah and musyarakah agreements) are significant.
- Funding based on profit-sharing (mudharabah and musyarakah agreements) has less good quality.
- The bank's funding strategy or business model for profit-sharing agreements is given to customers who have less good track records at the bank and to customer businesses less controlled by the bank and have fairly high risk.
- Funding portfolios based on profit-sharing are affected by changes in external factors.
High (5) Considering the bank's business activities, the probability of losses faced by the bank from Investment Risk is classified as very high during a certain period in the future. Examples of bank characteristics included in this rating are as follows:
- Funding portfolios based on profit-sharing (mudharabah and musyarakah agreements) are very significant.
- Funding based on profit-sharing (mudharabah and musyarakah agreements) has not good quality.
- The bank's funding strategy or business model for profit-sharing agreements is given to customers who have not good track records at the bank and to customer businesses not controlled by the bank and have very very high risk.
- Funding portfolios based on profit-sharing are very affected by changes in external factors.
APPENDIX III.2.11.b
For Investment Risk
Rating Definition Rating
Strong
(1)
The quality of Investment Risk management application is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Examples of bank characteristics included in this rating are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for investments is very adequate and has been in line with the bank's strategic objectives and overall business strategy.
- The Board of Commissioners and Board of Directors have very good awareness and understanding of Investment Risk management.
- Investment Risk management culture is very strong and has been internalized very well at all levels of the organization.
- The implementation of the duties of Commissioners and Directors as a whole is very adequate.
- The Investment Risk management function is independent, has clear tasks and responsibilities, and has run very well.
- The delegation of authority is controlled and monitored periodically, and has run very well.
- Financing strategy is very good and very consistent with the level of Risk to be taken and Investment Risk tolerance.
- Investment Risk policies, procedures, and limits are very adequate and available for all areas of Investment Risk management, consistent with implementation, and well understood by employees.
- The Investment Risk management process is very adequate in identifying, measuring, monitoring, and controlling Investment Risk.
- The funding provision process in general is very adequate, starting from the underwriting process to handling non-performing assets.
- The Investment Risk grading system (investment risk grading) is very good, applied consistently, and well understood by employees. There is an independent financing review function that runs well.
- The Management Information System (MIS) for Investment Risk is very good, resulting in comprehensive and integrated Investment Risk reporting to the Board of Commissioners and Directors.
- Generally, Human Resources (HR) are very adequate in terms of both quantity and competence in the Investment Risk management function.
- The internal control system is very effective in supporting the implementation of Investment Risk management.
- The implementation of independent review by the Internal Audit Unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Directors.
- Generally, there are no significant weaknesses based on the results of independent review.
- Follow-up on independent review has been carried out very adequately.
Satisfactory
(2)
The quality of Investment Risk management application is adequate. Although there are several minor weaknesses, these weaknesses can be resolved in normal business activities. Examples of bank characteristics included in this rating are as follows:
- The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for investments is adequate and has been in line with the bank's strategic objectives and overall business strategy.
- The Board of Commissioners and Board of Directors have good awareness and understanding of Investment Risk management.
- Investment Risk management culture is strong and has been internalized very well at all levels of the organization.
- The implementation of the duties of Commissioners and Directors as a whole is adequate. There are some weaknesses but not significant and can be repaired immediately.
- The Investment Risk management function is independent, has clear tasks and responsibilities, and has run well. There are minor weaknesses, but can be resolved in normal business activities.
- The delegation of authority is controlled and monitored periodically, and has run well.
- Financing strategy is good and consistent with the level of Risk to be taken and Investment Risk tolerance.
- Investment Risk policies, procedures, and limits are adequate and available for all areas of Investment Risk management, consistent with implementation, and well understood by employees.
- The Investment Risk management process is adequate in identifying, measuring, monitoring, and controlling Investment Risk.
- The funding provision process is good. There are minor weaknesses in one or more aspects of funding provision but can be repaired easily.
- The Investment Risk grading system (investment risk grading) is good, applied consistently and understood by employees. The independent financing review function. There are minor weaknesses that do not disrupt the overall process.
- The Management Information System (MIS) for Investment Risk is good, including reporting Investment Risk to the Board of Commissioners and Directors.
Rank Definition Rank
Commissioners and Directors. There are minor weaknesses but they can be easily repaired.
- Human Resources (HR) are adequate in terms
of quantity and competence in the function of
Investment Risk Management.
- Internal control systems are effective in supporting
the implementation of Investment Risk Management.
- Implementation of independent review by the Internal Audit Unit and functions that
perform independent review is adequate in terms of methodology, frequency, and reporting to the Board of Commissioners and Directors.
- There are weaknesses but not significant based on
the results of independent review.
- Follow-up on independent review has been
implemented adequately.
Fair...
Rank Definition Rank
Fair
(3)
The quality of Investment Risk Management implementation is quite adequate. Although minimum requirements are met, there are several weaknesses that require management attention. Examples of characteristics of banks included in this rank are as follows:
- Formulation of the level of Risk to be taken (risk
appetite) and Risk tolerance (risk tolerance) is quite adequate but not always aligned with strategic objectives and the bank's overall business strategy.
- The Board of Commissioners and Directors has sufficient awareness and
understanding of Investment Risk Management.
- Investment Risk Management culture is quite strong and
has been internalized quite well but not always implemented consistently.
- Implementation of the duties of Commissioners and Directors as a
whole is quite adequate. There are some weaknesses in some aspects of assessment that need to receive management attention.
- The Investment Risk Management function has run quite
well, but there are several weaknesses that are quite significant and need to be resolved immediately by management.
- Delegation of authority is quite good, but control
and monitoring are not always implemented well.
- Financing strategy is quite aligned with the level of Risk
to be taken and Investment Risk tolerance.
- Investment Risk policies, procedures, and limits are quite
adequate but not always consistent with implementation and/or not well understood by employees.
- Investment Risk Management process is quite adequate
in identifying, measuring, monitoring, and controlling Investment Risk.
- Funding provision process is quite good. There are weaknesses
in one or more aspects of funding provision that need to receive management attention.
- Investment Risk grading system (investment risk
grading) and financing review function (financing review) are quite good, but there are several weaknesses that need to receive management attention.
- Investment Risk Management Information System (SIM)
meets minimum expectations but there are several weaknesses including Investment Risk reporting to the Board of Commissioners and Directors that need attention...
Rank Definition Rank management attention.
- Human Resources (HR) are quite adequate in terms of
quantity and competence in the function of
Investment Risk Management.
- Internal control systems are quite effective in
supporting the implementation of Investment Risk Management.
- Implementation of independent review (independent review)
by the Internal Audit Unit and functions that perform independent review is quite adequate.
There are some weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that need management attention.
- There are weaknesses that are quite significant based on
the results of independent review.
- Follow-up on independent review has been
implemented quite adequately.
Quality...
Rank Definition Rank
Marginal
(4)
The quality of Investment Risk Management implementation is less adequate. There are significant weaknesses in various aspects of Investment Risk Management that require corrective action immediately. Examples of characteristics of banks included in this rank are as follows:
- Formulation of the level of Risk to be taken (risk
appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with strategic objectives and the bank's overall business strategy.
- Significant weaknesses in awareness and understanding
of the Board of Commissioners and Directors regarding Investment Risk Management.
- Investment Risk Management culture is weak and
has not been internalized at every level of work unit.
- Implementation of the duties of Commissioners and Directors as a
whole is less adequate. There are weaknesses in some aspects of assessment that require immediate improvement.
- Significant weaknesses in the Investment Risk Management
function that require immediate improvement.
- Delegation of authority is weak and not controlled and
monitored well.
- Financing strategy is less aligned with the level of
Risk to be taken and Investment Risk tolerance.
- Significant weaknesses in Investment Risk policies, procedures, and limits.
- Investment Risk Management process is less adequate
in identifying, measuring, monitoring, and controlling Investment Risk.
- Funding provision process is less good. There
are weaknesses in one or more aspects of funding provision that require immediate improvement.
- Investment Risk grading system (investment risk
grading) and financing review (financing review) are less good. There are several weaknesses that require immediate improvement.
- Significant weaknesses in the Management Information System
(SIM) of Investment Risk including Risk reporting to the Board of Commissioners and Directors that require immediate improvement.
- Human Resources (HR) are less adequate in terms of
quantity and competence in the Investment Risk Management function.
System...
Rank Definition Rank
- Internal control systems are less effective in
supporting the implementation of Investment Risk Management.
- Implementation of independent review (independent review)
by the Internal Audit Unit and functions that perform independent review is less adequate.
There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require immediate improvement.
- There are significant weaknesses based on the results
of independent review that require immediate improvement.
- Follow-up on independent review is less
adequate.
Unsatisfactory...
Rank Definition Rank
(5)
The quality of Investment Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Investment Risk Management where the resolution actions are beyond management's capability. Examples of characteristics of banks included in this rank are as follows:
- Formulation of the level of Risk to be taken (risk
appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with strategic objectives and the bank's overall business strategy.
- Significant weaknesses in awareness and understanding
of the Board of Commissioners and Directors regarding Investment Risk Management.
- Investment Risk Management culture is weak and
has not been internalized at every level of work unit.
- Implementation of the duties of Commissioners and Directors as a
whole is less adequate. There are weaknesses in some aspects of assessment that require immediate improvement.
- Significant weaknesses in the Investment Risk Management
function that require immediate improvement.
- Delegation of authority is weak and not controlled and
monitored well.
- Financing strategy is less aligned with the level of
Risk to be taken and Investment Risk tolerance.
- Significant weaknesses in Investment Risk policies, procedures, and limits.
- Investment Risk Management process is less adequate
in identifying, measuring, monitoring, and controlling Investment Risk.
- Funding provision process is less good. There
are weaknesses in one or more aspects of funding provision that require immediate improvement.
- Investment Risk grading system (investment risk
grading) and financing review function (financing review) are less good. There are several weaknesses that require immediate improvement.
- Significant weaknesses in the Management Information System
(SIM) of Investment Risk including Risk reporting to the Board of Commissioners and Directors that require immediate improvement.
- Human Resources (HR) are less adequate in terms of
quantity and competence in the Investment Risk Management function.
System...
Rank Definition Rank
- Internal control systems are less effective in
supporting the implementation of Investment Risk Management.
- Implementation of independent review (independent review)
by the Internal Audit Unit and functions that perform independent review is less adequate.
There are weaknesses in methodology, frequency, and/or reporting to the Board of Commissioners and Directors that require immediate improvement.
- There are significant weaknesses based on the results
of independent review that require immediate improvement.
- Follow-up on independent review is less
adequate.
APPENDIX...
APPENDIX III.3
Matrix of Good Corporate Governance Factor Rating Rank Definition 1 Reflects that Bank Management has implemented Good Corporate Governance which is generally very good. This is reflected in the implementation of Good Corporate Governance principles which are very adequate. If there are weaknesses in the implementation of Good Corporate Governance principles, then generally the weaknesses are not significant and can be immediately repaired by Bank Management. 2 Reflects that Bank Management has implemented Good Corporate Governance which is generally good. This is reflected in the implementation of Good Corporate Governance principles which are adequate. If there are weaknesses in the implementation of Good Corporate Governance principles, then generally the weaknesses are less significant and can be resolved with normal actions by Bank Management. 3 Reflects that Bank Management has implemented Good Corporate Governance which is generally quite good. This is reflected in the implementation of Good Corporate Governance principles which are quite adequate. If there are weaknesses in the implementation of Good Corporate Governance principles, then generally the weaknesses are quite significant and require quite a lot of attention from Bank Management. 4 Reflects that Bank Management has implemented Good Corporate Governance which is generally less good. This is reflected in the implementation of Good Corporate Governance principles which are less adequate. There are weaknesses in the implementation of Good Corporate Governance principles, then generally the weaknesses are significant and require comprehensive improvement by Bank Management. 5 Reflects that Bank Management has implemented Good Corporate Governance which is generally not good. This is reflected...
reflected in the implementation of Good Corporate Governance principles which are inadequate. Weaknesses in the implementation of Good Corporate Governance principles are generally very significant and difficult to repair by Bank Management.
APPENDIX...
APPENDIX III.4
Matrix of Profitability Factor Rating
Rank Definition
1 Profitability is very adequate, profit exceeds target and supports Bank's capital growth.
Banks included in this rank meet all or most of the following example characteristics:
- Bank's performance in generating profit (profitability) is very
adequate.
- The main source of profitability from core earnings
is very dominant.
- Components supporting core earnings are very
stable.
- The ability of profit to increase capital and
profit prospects in the future is very high.
- Implementation of Bank's social function is carried out very
well and significantly.
2 Profitability is adequate, profit exceeds target and supports Bank's capital growth.
Banks included in this rank meet all or most of the following example characteristics:
- Bank's performance in generating profit (profitability) is adequate.
- The main source of profitability from core earnings
is dominant.
- Components supporting core earnings are stable.
- The ability of profit to increase capital and
profit prospects in the future is high.
- Implementation of Bank's social function is carried out well and
quite significantly.
3 Profitability is quite adequate, profit meets target, but there is pressure on profit performance that can cause profit decline but still quite supports Bank's capital growth. Bank...
Rank Definition
Banks included in this rank meet all or most of the following example characteristics:
- Bank's performance in generating profit (profitability) is quite
adequate.
- The main source of profitability from core earnings is quite
dominant but there is quite a large influence from non core earnings.
- Components supporting core earnings are quite
stable.
- The ability of profit to increase capital and
profit prospects in the future is quite good.
- Implementation of Bank's social function is carried out quite
well.
4 Profitability is less adequate, profit does not meet target, and is estimated to remain in that condition in the future so it is less able to support Bank's capital growth and business continuity. Banks included in this rank meet all or most of the following example characteristics:
- Bank's performance in generating profit (profitability) is not
adequate or Bank incurs losses.
- The main source of profitability comes from non-core earnings.
- Components supporting core earnings are less
stable.
- The ability of profit to increase capital and
profit prospects in the future is less good or even can have a negative impact on Bank's capital.
- Implementation of Bank's social function carried out is less
adequate/less good.
5 Profitability is inadequate, Profit does not meet target and cannot be relied upon and requires immediate improvement in profit performance to ensure Bank's business continuity. Banks included in this rank meet all or most of the following example characteristics:
Bank...
Rank Definition
- Bank incurs significant losses.
- The main source of profitability comes from non-core earnings.
- Components supporting core earnings are not
stable.
- Bank's losses significantly affect capital.
- Implementation of Bank's social function has not been carried out.
APPENDIX...
APPENDIX III.5
Matrix of Capital Factor Rating
Rank Definition
1 Bank has very adequate capital quality and adequacy relative to its Risk profile, accompanied by very strong capital management according to the characteristics, business scale, and business complexity of the Bank. Banks included in this rank meet all or most of the following example characteristics:
- Bank has a very adequate level of capital,
very able to anticipate all Risks faced, and supports Bank's business expansion in the future.
- The quality of capital components is generally very good,
permanent, and able to absorb losses.
- Bank has conducted stress tests with results that can
close all Risks faced very adequately.
- Bank has very good capital management and/or has a capital adequacy assessment process
that is very good according to strategy and business objectives as well as complexity and scale of the Bank.
- Bank has very good access to capital sources and/or has capital support from the
business group or parent company.
2 Bank has adequate capital quality and adequacy relative to its Risk profile, accompanied by strong capital management according to the characteristics, business scale, and business complexity of the Bank. Banks included in this rank meet all or most of the following example characteristics:
- Bank has an adequate level of capital and can
anticipate almost all Risks faced.
- The quality of capital components is generally good,
permanent...
Rank Definition permanent, and able to absorb losses.
- Bank has conducted stress tests with results that can
close all Risks faced adequately.
- Bank has good capital management and/or
has a good capital adequacy assessment process.
- Bank has good access to capital sources and/or
there is capital support from the business group or parent company.
3 Bank has quite adequate capital quality and adequacy relative to its Risk profile, accompanied by quite strong capital management according to the characteristics, business scale, and business complexity of the Bank. Banks included in this rank meet all or most of the following example characteristics:
- Bank has a quite adequate level of capital, and
is quite able to anticipate the Risks faced.
- The quality of capital components is generally quite good,
quite permanent, and quite able to absorb losses.
- Bank has conducted stress tests with results that can
close all Risks faced quite adequately.
- Bank has quite good capital management and/or has a capital adequacy assessment process
that is quite good.
- Bank has quite good access to capital sources,
however, support from the business group or parent company is not done explicitly.
4 Bank has less adequate capital quality and adequacy relative to its Risk profile, accompanied by weak capital management compared to the characteristics, business scale, and business complexity of the Bank. Banks included in this rank meet all or most of the following example characteristics:
- Bank has a less adequate level of capital and does not...
Rank Definition cannot anticipate all Risks faced.
- The quality of capital components is generally less good,
less permanent, and less able to absorb losses.
- Bank has conducted stress tests with results that are less
able to close all Risks faced.
- Bank has less good capital management and/or has a capital adequacy assessment process
that is less good.
- Bank is less able to access capital sources, and there is no support from the business group
or parent company.
5 Bank has inadequate capital quality and adequacy relative to its Risk profile, accompanied by very weak capital management compared to the characteristics, business scale, and business complexity of the Bank. Banks included in this rank meet all or most of the following example characteristics:
- Bank has inadequate capital levels,
so the Bank must add capital to anticipate all Risks faced under normal and crisis conditions.
- The quality of capital instruments is generally not good,
not permanent, and unable to absorb losses.
- Bank has conducted stress tests with results that do not
close all Risks faced.
- Bank has poor capital management and/or has a capital adequacy assessment process
that is poor.
- Bank is unable to access capital sources, and there is no support from the business group
or parent company.
Determined...
Determined in Jakarta on June 11, 2014
CHIEF EXECUTIVE
BANKING SUPERVISOR,
Signed,
NELSON TAMPUBOLON
Legal Director 1
Legal Department,
Signed,
Tini Kustini
APPENDIX IV
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10/SEOJK.03/2014 REGARDING ASSESSMENT OF THE HEALTH LEVEL OF SHARIA COMMERCIAL BANKS AND SHARIA BUSINESS UNITS
ASSESSMENT RESULTS REPORT OF THE HEALTH LEVEL OF THE BANK
Appendix IV.1: Assessment Results Report of the Health Level of the Bank
Appendix IV.2: Risk Profile Factor Assessment
Appendix IV.3: Risk Analysis Assessment
Appendix IV.4: Good Corporate Governance Factor Assessment
Appendix IV.5: Profitability Factor Assessment
Appendix IV.6: Capital Factor Assessment
APPENDIX...
APPENDIX IV.1
REPORT
ASSESSMENT RESULTS OF THE HEALTH LEVEL OF THE BANK (RISK BASED BANK RATING) Bank Name :
Position :
No. Assessment Factors
Individual Rank Consolidated *)
1 Risk Profile
2 Good Corporate Governance
3 Profitability
4 Capital
Risk-Based Health Level Rank
*) In the event that the Bank has subsidiaries that must be consolidated Analysis Analysis of the Bank's overall condition reflected in the four factors of the Risk-Based Health Level Assessment (TKB).
- Risk profile analysis covering Inherent Risk, quality of implementation
of Risk Management, and the level of Risk for each Risk as well as the Risk level rank
- Analysis regarding the implementation of Good Corporate Governance
- Analysis regarding Profitability
- Analysis regarding Capital
In the event that the Bank has subsidiaries that must be consolidated, the Bank must consider the impact of Risk, implementation of Good Corporate Governance, and profitability and capital performance of the subsidiary on the Risk profile and financial performance of the Bank by considering the significance and materiality of the subsidiary and/or the significance of the subsidiary's problems. Date: Date:
Prepared By: Approved By:
APPENDIX...
APPENDIX IV.2
RISK PROFILE FACTOR ASSESSMENT
Bank Name :
Position :
Risk
Profile
INDIVIDUAL CONSOLIDATED
Rank
Inherent Risk
Rank
Quality
Risk Management
Implementation
Rank
Risk
Rank
Inherent Risk
Rank
Quality
Risk Management
Implementation
Rank
Risk
Risk
Credit Risk
Market Risk
Liquidity Risk
Operational Risk
Legal Risk
Strategic Risk
Compliance Risk
Reputation Risk
Yield Risk
Investment Risk
Composite
Rank
Risk Profile
Rank
Risk Profile
Rank
Description...
Analysis
Description regarding the conclusion of the Bank's overall Risk profile including assessment of Inherent Risk and quality of Risk Management implementation, with analysis focus on significant and material Risk exposures at the Bank. For example, Credit Risk is generally the most dominant Risk in Bank activities, thus having higher significance compared to other Risks. Thus, the Bank's Risk profile rank will be more influenced by the Credit Risk rank as the most dominant Risk at the Bank, and subsequently by other Risks considered significant, such as Market Risk, Liquidity Risk, and/or Operational Risk. In the event that the Bank has subsidiaries that must be consolidated, the Bank considers the impact of the subsidiary's Risk on the Bank's Risk profile by considering the significance and materiality of the subsidiary and/or the significance of the subsidiary's problems.
APPENDIX...
APPENDIX IV.3
RISK ANALYSIS ASSESSMENT …………. *)
Bank Name :
Position :
Analysis
Risk Rating:
Final conclusion regarding the Bank's Risk level, encompassing Inherent Risk and the quality of Risk Management implementation, thereby describing the Bank's Risk level. Inherent Risk:
Description regarding the assessment of Inherent Risk based on analysis of assessment factors using both quantitative and qualitative indicators, thereby describing the Bank's Inherent Risk level. Quality of Risk Management Implementation:
Analysis of the Quality of Risk Management Implementation consists of Risk governance; Risk management framework; Risk Management process, HR, and MIS; and Risk control. *) This working paper is used to support the analysis of Risks at the Bank, including Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Strategic Risk, Compliance Risk, Reputational Risk, Yield Risk, and Investment Risk.
APPENDIX...
APPENDIX IV.4
GOOD CORPORATE GOVERNANCE FACTOR ASSESSMENT
Bank Name :
Position :
Rating Definition Rating
Individual
Consolidated
Analysis
Description regarding the conclusion on the assessment of the Bank's implementation of Good Corporate Governance, considering the assessment factors of Good Corporate Governance comprehensively and structurally, covering both governance structure, governance process, and governance outcome. In this description, it must at least explain the identification of issues in the form of weaknesses and their causes (root causes) and the strengths of Good Corporate Governance implementation. In the event the Bank has Subsidiary Companies that are required to be consolidated, then:
- Assessment is conducted on issues regarding the implementation of Good Corporate Governance of the Subsidiary Company considered to have a significant impact on the Good Corporate Governance of the Bank on a consolidated basis.
- The assessment factors of Good Corporate Governance of the Subsidiary Company used for the assessment of the implementation of Good Corporate Governance principles on a consolidated basis are determined by considering the business characteristics of the Subsidiary Company and are supported by adequate data and information.
- The determination of the Good Corporate Governance rating of the Bank on a consolidated basis is conducted by considering the impact of the implementation of Good Corporate Governance of the Subsidiary Company.
APPENDIX...
APPENDIX IV.5
PROFITABILITY FACTOR ASSESSMENT
Bank Name :
Position :
Individual Consolidated Profitability Rating
Analysis
Final conclusion regarding the Bank's profitability performance by considering the profitability assessment factors. In the event the Bank has a subsidiary company that is required to be consolidated, the Bank calculates the impact of the subsidiary company's profitability performance on the Bank's overall profitability by considering the significance and materiality of the subsidiary company.
APPENDIX...
APPENDIX IV.6
CAPITALIZATION FACTOR ASSESSMENT
Bank Name :
Position :
Individual Consolidated Capitalization Rating
Analysis
Final conclusion regarding the Bank's capitalization performance by considering the capitalization assessment factors. In the event the Bank has a subsidiary company that is required to be consolidated, the Bank calculates the impact of the subsidiary company's capitalization performance on the Bank's overall capitalization by considering the significance and materiality of the subsidiary company. Determined in Jakarta on June 11, 2014 EXECUTIVE HEAD BANKING SUPERVISOR, Signed, NELSON TAMPUBOLON Director of Law 1 Legal Department, Signed, Tini Kustini ---