2002-07-26
Added · Updated
COBAC Regulation R-2001/07 mandates that credit institutions establish an internal control system adapted to their size, activities, and risk exposure. The regulation defines the responsibilities of the Executive and Deliberative bodies, requiring the implementation of first-level operational controls and an independent second-level Internal Audit function. It further prescribes specific requirements for internal procedure manuals, accounting organization, information system security, and risk measurement systems covering credit, interest rate, settlement, illiquidity, and market risks.
The Central African Banking Commission,
Having regard to the Convention of 16 October 1990 establishing a Central African Banking Commission;
Having regard to Articles 1, 9 and 10 of the Annex to the Convention of 16 October 1990;
Having regard to the Convention of 17 January 1992 on the harmonization of banking regulation in the States of Central Africa;
Having regard to Articles 32 and 38 of the Annex to the Convention of 17 January 1992;
Having regard to Articles 31, 32 and 34 of the Convention governing the Central African Monetary Union;
Having regard to COBAC Regulation R-93/08,
DECIDES
Article 1 - Credit institutions must establish an internal control system under the conditions provided for by this Regulation.
Article 2 - For the purposes of this Regulation, the following definitions apply:
Members of the Executive Body, the Head of Internal Audit, and the statutory auditors of the institution cannot be members of the Audit Committee.
The establishment of an Audit Committee is mandatory for institutions whose balance sheet total exceeds 50 billion FCFA.
It consists of a permanent first-level control or operational control, subdivided, if necessary, into several tiers, and a second-level control constituted by the Internal Audit function.
Article 3 - The internal control system includes in particular: a) a system for controlling operations and risks; b) written internal procedures; c) an accounting organization; d) an information processing system; e) systems for measuring risks and results; f) systems for monitoring and controlling risks; g) a reporting system.
Institutions must ensure the implementation of an effective internal control system by adapting all the measures provided for by this Regulation to the nature and volume of their activities, their size, their locations, and the various types of risks to which they are exposed.
Article 4 - The Deliberative Body must be responsible for: a) defining and periodically reviewing all commercial strategies and significant policies of the bank; b) identifying the main risks incurred by the bank; c) setting acceptable limits for these risks and ensuring that the Executive Body takes the necessary measures to identify, measure, monitor, and control these risks; d) approving the organizational structure; e) verifying that the Executive Body ensures the effectiveness of the internal control system.
Article 5 - The Executive Body must be responsible for: a) implementing the strategies and policies approved by the Deliberative Body; b) developing processes that allow for the identification, measurement, monitoring, and control of risks incurred by the bank; c) maintaining an organizational structure that clearly assigns reporting, authority, and responsibility relationships; d) ensuring that delegated responsibilities are effectively exercised; e) implementing appropriate internal control policies; f) monitoring the adequacy and effectiveness of the internal control system.
Article 6 - The Executive and Deliberative Bodies must promote within the bank a culture that values internal control at all levels of personnel. Each bank agent must understand their role in the internal control framework and be fully involved in it.
Article 7 - The internal control system is placed under the responsibility of the Deliberative Body and implemented by the Executive Body. It must allow, under optimal conditions of security, reliability, and completeness, in particular, to:
a) verify that operations carried out by the institution, as well as the organization and internal procedures, comply with current legislative and regulatory provisions, professional and ethical standards and practices, and the orientations of the Deliberative and Executive Bodies;
b) verify that decision-making procedures, risk-taking procedures, whatever their nature, and management standards set by the Executive Body in application of the decisions of the Deliberative Body, in particular in the form of limits, are strictly respected;
c) verify the quality, reliability, and sincerity of accounting and financial information, whether intended for the Executive Body and the Deliberative Body, transmitted to supervisory and control authorities, or included in documents intended for publication;
d) verify the conditions for the evaluation, recording, retention, and availability of this information, in particular by guaranteeing the existence of the audit trail as defined in Article 22 of this Regulation;
e) verify the quality of information and reporting systems.
All these efforts aim to ensure that the assets and other resources of the institution are used efficiently to ensure the achievement of its objectives.
Article 8 - Credit institutions must ensure that the control system is integrated into the organization, methods, and procedures of each of the activities.
Article 9 - Credit institutions must ensure that the number and qualification of persons participating in the functioning of the internal control system, as well as the resources made available to them, in particular monitoring tools and risk analysis methods, are adapted to the activities, size, and locations of the institution.
Article 10 - Credit institutions must organize their first-level internal control system to provide devices that allow for regular and permanent control at the operational unit level to guarantee the regularity, security, validation of operations carried out, and compliance with other diligence related to the monitoring of risks of any nature associated with operations.
Article 11 - These devices must be designed to ensure a clear separation of tasks and responsibilities between units responsible for the commitment of operations and units responsible for their validation, in particular accounting, as well as those responsible for their settlement and monitoring of diligence related to risk surveillance.
Article 12 - Credit institutions must establish a second-level control system or Internal Audit. The organization of the internal audit function must allow for the verification, at appropriate intervals, of the regularity and compliance of operations and the effectiveness of first-level devices, in particular their adequacy to the nature of all risks associated with operations.
Internal Audit must operate independently from all structures with respect to which it exercises its missions.
Article 13 - The resources allocated to Internal Audit must be sufficient to conduct a complete cycle of investigations of all activities at the shortest possible periodicity. A program of control missions, discussed with the Executive Body and then validated by it and, if it exists, by the Audit Committee, must be established at least once a year, integrating the annual objectives of the Executive Body and the Deliberative Body regarding control.
Article 14 - The Deliberative Body and the Executive Body must ensure that the missions of Internal Audit apply to all activities of the institution's entities, including its subsidiaries and branches.
Article 15 - The Deliberative Body appoints and dismisses, upon proposal of the Executive Body, the Head of Internal Audit. Under the authority of the Executive Body, he/she is responsible for ensuring the consistency and effectiveness of internal control. He/she reports, at least once a year and in complete independence, to the Executive and Deliberative Bodies on the exercise of his/her mission and to the Audit Committee, if one exists.
Article 16 - An Internal Audit Charter approved by the Executive and Deliberative Bodies defines the role, powers, and responsibilities assigned to the Internal Audit function.
This Charter is communicated to the General Secretariat of the Banking Commission.
Article 17 - Credit institutions must regularly review risk measurement systems and limit determination systems to verify their relevance in light of the evolution of activity, market environment, or analysis techniques.
Article 18 - Credit institutions develop and maintain manuals of procedures relating to their different activities. These documents must, in particular, describe the methods for recording, processing, and reporting information, accounting schemes, and operation commitment procedures.
Article 19 - Credit institutions establish under the same conditions a documentation that specifies the means intended to ensure the proper functioning of internal control, in particular: a) the different levels of responsibility; b) the attributions assigned and the resources allocated to the functioning of internal control devices; c) the rules that ensure the independence of these devices; d) procedures related to the security of information and reporting systems; e) a description of risk measurement systems; f) a description of risk monitoring and control systems.
The documentation is organized in such a way as to be made available, upon request, to the Executive Body, the Deliberative Body, the statutory auditors, and the General Secretariat of the Banking Commission.
Article 20 - Accounting procedures and organization must be recorded in a document updated regularly to facilitate the understanding of the accounting system and the conduct of controls.
Article 21 - The information system of the regulated entities must allow for the preparation of summary documents in the form and according to the periodicity fixed by the supervisory and control authorities.
Article 22 - Each amount appearing in summary documents and resulting from the use of general account balances must be controllable by a set of procedures, called an audit trail, allowing: a) to reconstruct operations in chronological order;
b) to justify any information by an original document from which it must be possible to trace, through an uninterrupted path, back to the summary document and vice versa;
c) to explain the evolution of general account balances, from one closing to another, by retaining the movements that affected these accounts.
Each amount appearing on summary documents and resulting from the use of attributes must be controllable from the detail of the elements composing this amount.
Article 23 - When the Banking Commission authorizes that information be provided by a statistical method, these must be verifiable without necessarily falling under the audit trail.
Article 24 - Credit institutions must ensure the completeness, quality, and reliability of information and evaluation and accounting methods, in particular by exercising periodic control: a) on the adequacy of the methods and parameters selected for the evaluation of operations in management systems; b) to ensure the relevance of accounting schemes in light of general security and prudence objectives, as well as their compliance with current accounting rules.
Article 25 - Credit institutions determine the level of computer security deemed desirable in relation to the requirements of their business. They ensure respect for the selected security level and that their information systems are adapted.
Article 26 - Procedures for the computerized processing of data must be recorded in a written document. These procedures must allow for obtaining, on paper or any other support, summary states listing in chronological order all data entered therein, in a form prohibiting any subsequent insertions, deletions, or additions. The reconstruction of account elements, statements, and accounting information, from the data entered, must be possible and vice versa.
Article 27 - Information systems must be subject to regular control allowing, in particular, to ensure that:
a) the security level of computer systems is periodically assessed and, if necessary, corrective actions are undertaken;
b) computer backup procedures are available to ensure the continuity of operations in the event of serious difficulties in the functioning of computer systems.
The control of information systems extends to the retention of information and documentation related to analyses, programming, and execution of treatments.
Article 28 - Credit institutions are required to retain, until the date of the next closing, all files necessary to justify the documents of the last closing submitted to the Banking Commission.
Article 29 - Credit institutions put in place systems for analyzing and measuring risks by adapting them to the nature and volume of their operations to apprehend the risks of different nature to which these operations expose them and in particular credit risk, interest rate risk, settlement risk, illiquidity risk, and market risk, including foreign exchange risk.
Article 30 - Credit institutions must have systems allowing them to evaluate the value variations of quoted instruments held for own account.
They must have, in particular, systems for monitoring their foreign exchange operations carried out for their own account allowing them to determine daily their positions in each currency and to calculate their foreign exchange results.
A reconciliation must be performed, at least monthly, between the results calculated for operational management and the results accounted for. Institutions must be able to identify and analyze the discrepancies observed.
Article 31 - Credit institutions must have an interest rate risk evaluation system allowing them to permanently apprehend the different interest rate risk factors to which balance sheet and off-balance sheet operations expose them and to periodically evaluate the impact of these different factors on their results.
Article 32 - Credit institutions must at all times be able to evaluate their settlement risk by listing all operations for which they are or could be exposed to this risk, identifying the different phases of the settlement process and in particular those that would confront them with a potential loss. Appropriate measures must be provided to address this risk.
Article 33 - Credit institutions must establish a device allowing them at all times to evaluate their illiquidity risk. This device must allow for permanent monitoring of the maturity schedules of the institution's commitments or exigibilities in relation to the market situation and available resources at each maturity. Institutions must ensure that their liquidity permanently covers their exigibilities.
Article 34 - Credit institutions must have a credit risk selection procedure and a system for measuring these risks allowing them in particular: a) to centrally identify their balance sheet and off-balance sheet risks vis-à-vis a counterparty or counterparties considered as a single beneficiary within the meaning of Article 3 of COBAC Regulation R-2001/03; b) to appreciate different categories of risk levels based on qualitative and quantitative information, in particular through internal rating; c) to proceed, if significant, to global allocations of their commitments by groups of counterparties receiving an identical assessment of their risk level, as appreciated by the institution, as well as by economic sector and geography; d) to evaluate the potential profitability of the operation by ensuring, for institutions for which the establishment of the audit committee is mandatory pursuant to the provisions of Article 2 of this Regulation, that the forecast analysis of direct and indirect charges and revenues is as exhaustive as possible and covers in particular operational and financing costs, the charge corresponding to an estimate of the borrower's default risk, and the cost of remuneration of equity.
Institutions set specific rules for the selection and monitoring of the most significant risks, assessed based on the level of equity and the degree of concentration of the credit portfolio.
Article 35 - The assessment of credit risk must in particular take into account elements regarding the financial situation of the beneficiary, in particular his/her repayment capacity and, if applicable, the guarantees received, evaluated under the conditions specified in the second paragraph of Article 38 below.
For risks on companies, it must also take into account the analysis of their environment, the characteristics of partners or shareholders and directors, as well as the most recent accounting documents.
For risks on correspondents, it must also take into account their rating by a rating agency or at least their supervision by an organism recognized by the Basel Committee.
Article 36 - Credit institutions create credit files intended to collect all this qualitative and quantitative information and group in the same file the information concerning counterparties considered as a single beneficiary.
Credit institutions complete these files, at least quarterly, for counterparties whose claims are unpaid or doubtful or who present significant risks or volumes.
Article 37 - Loan decision procedures or commitment procedures, in particular when organized by the fixing of delegations, must be clearly formalized and adapted to the characteristics of the institution, in particular its size, organization, nature of activity, and level of equity.
When the nature and importance of operations make it necessary, credit institutions ensure, within the framework of compliance with any defined delegation procedures, that loan or commitment decisions are taken by at least two people, placed at different and sufficiently high hierarchical levels, and that credit files are also subject to analysis by a specialized unit independent of operational units.
When granting loans or commitments to their shareholders or partners, directors, managers, and staff within the meaning of COBAC Regulation R-93/13, credit institutions examine the nature of the operations and the conditions under which they are concluded compared to operations of the same nature usually concluded with persons other than those mentioned above.
Article 38 - Credit institutions must, at least quarterly, analyze the evolution of the quality of their commitments. This review must in particular make it possible to determine, for operations of significant importance, any necessary reclassifications within the internal categories of credit risk assessment, as well as, as necessary, allocations to doubtful debt accounting headings and appropriate provisioning levels.
The determination of the appropriate provisioning level takes into account guarantees for which institutions must ensure effective implementation possibilities and the existence of a recent evaluation made on a prudent basis, unless special derogation by the Banking Commission in favor of specialized institutions for the application of specific modalities. In all cases, the minimum provisioning standards set by COBAC Regulation R-98/03 must be respected.
In institutions where the establishment of the audit committee is mandatory under the provisions of Article 2 of this regulation, the executive body carries out, at least semi-annually, a post-facto analysis of the profitability of credit operations.
Article 39 - Credit institutions equip themselves with means adapted to the control of operational and legal risks. They put in place risk surveillance and control systems, notably for credit, exchange rate, interest rate, settlement, illiquidity, and market risks, showing internal limits as well as the conditions under which these limits are respected.
Article 40 - The risk surveillance and control systems for credit, exchange rate, interest rate, settlement, illiquidity, and market risks must include a global limit device.
Global risk limits are set and reviewed, as necessary and at least once a year, by the Deliberative Body taking into account the institution's own funds.
Operational limits set by the Executive Body at the level of different internal organizational entities must be established in a manner consistent with global limits.
The determination of global and operational limits must be carried out in a homogeneous manner relative to the risk measurement system.
Article 41 - Credit institutions equip themselves with devices allowing, according to formalized procedures: a) to ensure, permanently, compliance with procedures and limits set;
b) to analyze the causes of any non-compliance with procedures and limits;
c) to inform the entities or persons designated for this purpose of the extent of these breaches and the corrective actions proposed or undertaken;
d) to ensure business continuity in case of serious difficulties affecting the institution's operations.
When the monitoring of limit compliance is controlled by a risk committee, it must be composed not only of heads of operational units and representatives of the Executive Body but also of persons chosen for their competence in the field of risk control and independent of operational units.
Article 42 - Credit institutions define information procedures for the Executive and Deliberative Bodies, at a rhythm adapted to each body, and, if it exists, the Risk Committee, regarding compliance with risk limits, notably when global limits are likely to be reached.
Article 43 - For the monitoring of their operations and notably for information intended for the Executive Body, the Risk Committee, the Deliberative Body, and, if it exists, the Audit Committee, credit institutions must prepare adapted summary statements.
Article 44 - Reports established following Internal Audit missions are communicated to the Executive Body and the Deliberative Body and, if it exists, the Audit Committee. These reports are kept available to the statutory auditors and the General Secretariat of the Banking Commission.
Article 45 - At least once a year, the Deliberative Body and, if it exists, the Audit Committee, examine the activity and results of internal control based on the information transmitted to them for this purpose by the Head of Internal Audit. The minutes of the deliberations are transmitted to the General Secretariat of the Banking Commission and to the statutory auditors.
These minutes must mention the most significant findings noted during Internal Audit missions as well as the corresponding recommendations.
Article 46 - The Executive Body regularly informs, at least once a year, the Deliberative Body and, if it exists, the Audit Committee, of the essential elements and main lessons that can be drawn from the measures of all risks to which the institution is exposed, notably the distributions (division, sector, quality) in terms of credit risk.
Article 47 - At least once a year, credit institutions prepare a report on the execution of internal control, risk measurement, and surveillance. This report includes, in particular: a) an inventory of missions carried out highlighting the main lessons and, in particular, the main deficiencies noted as well as a follow-up of corrective measures taken; b) a description of significant changes occurring in the field of internal control during the period under review, in particular to take into account the evolution of activity and risks; c) a description of the conditions for applying procedures put in place for new activities; d) a development regarding the internal control system of branches and subsidiaries abroad; e) the presentation of the main projected actions in the internal control system; f) a description regarding the measurement and surveillance of risks to which they are exposed, notably credit risk, specifying the conditions under which COBAC Regulation R-98/03 is respected; g) the distributions of commitments provided for in Article 34 as well as the analysis of the profitability of operations referred to in Articles 34 and 38 above; h) the status of implementation of recommendations from the General Secretariat of the Banking Commission following an on-site control.
This report is communicated to the Deliberative Body. It is also sent each year to the General Secretariat of the Banking Commission and to the statutory auditors as well as, if it exists, to the Audit Committee.
Article 48 - The Deliberative Body examines during a special deliberation the results of a COBAC verification mission. The Head of Mission who conducted the investigation attends this deliberation in the presence, if applicable, of the Secretary General of the Banking Commission or their Deputy.
Article 49 - In the event of non-compliance with the provisions of this regulation, the Banking Commission may issue an injunction to the effect, in particular, to take within a determined deadline all corrective measures likely to bring the institution into compliance with these provisions.
If a credit institution has not complied with an injunction or has not taken into account a warning or has seriously violated the regulations, the Banking Commission may impose one or more disciplinary sanctions provided for in Article 13 of the Annex to the Convention of October 16, 1990.
Article 50 - Regulation R-93/08 is repealed.
Article 51 - These provisions, which enter into force on January 1, 2003, apply to the institutions covered by the Convention of October 16, 1990 establishing a Central African Banking Commission.
Article 52 - The Secretary General of the Banking Commission is responsible for the execution of this regulation.
Done in Yaoundé, on DEC 5, 2001
For the Banking Commission, The President,
Jean-Félix MAMALEPOT
More like this from BEAC
We email you every new BEAC publication the day it's published.