2016-09-07

Added · Updated

COBAC Regulation R-2016/04 on Internal Control in Credit Institutions and Financial Holdings

COBAC Regulation R-2016/04 establishes minimum internal control requirements for credit institutions and financial holdings in the Central African Economic and Monetary Community. It mandates a two-tier control structure comprising permanent control and periodic internal audit, defines specific roles for deliberative and executive bodies, and requires the implementation of risk identification, measurement, and monitoring systems tailored to the institution's size and activities. The regulation further outlines obligations for consolidated supervision, organizational independence, and the promotion of an internal control culture.

Banque des Etats de l'Afrique Centrale logo

Cameroon

Banque des Etats de l'Afrique Centrale

Click to view thumbnail

CENTRAL AFRICAN BANKING COMMISSION

COBAC REGULATION R-2016/04 ON INTERNAL CONTROL IN CREDIT INSTITUTIONS AND FINANCIAL HOLDINGS

The Central African Banking Commission,

Having regard to Article 31 of the Convention governing the Monetary Union of Central Africa of June 25, 2008, revising that of July 5, 1996;

Having regard to the Convention of October 16, 1990 establishing a Central African Banking Commission;

Having regard to the Convention of January 17, 1992 on the harmonization of banking regulation in the States of Central Africa;

Having regard to Regulation No. 04/03/CEMAC/UMAC/COBAC of May 14, 2003 on the duties of statutory auditors in credit institutions;

Having regard to Regulation No. 04/08/CEMAC/UMAC/COBAC of October 6, 2008 on corporate governance in credit institutions of the Economic and Monetary Community of Central Africa;

Having regard to Regulation No. 02/14/CEMAC/UMAC/COBAC/CM of April 25, 2014 on the treatment of credit institutions in difficulty in the Economic and Monetary Community of Central Africa;

Having regard to Regulation No. 01/15/CEMAC/UMAC/COBAC of March 27, 2015 on the supervision of financial holdings and cross-border surveillance;

Having regard to Regulation No. 02/15/CEMAC/UMAC/COBAC/CM of March 27, 2015 amending and supplementing certain conditions relating to the exercise of the banking profession in the Economic and Monetary Community of Central Africa;

Having regard to COBAC Regulation R-93/13 of May 7, 2001 on the commitments of credit institutions in favor of their shareholders or partners, directors, managers, and staff, modified by COBAC Regulation R-2001/05;

Having regard to COBAC Regulation R-2001/07 of December 5, 2001 on internal control in credit institutions;

Having regard to COBAC Regulation R-2003/01 of February 27, 2003 on the organization of accounting in credit institutions;

Having regard to COBAC Regulation R-2005/01 of April 1, 2005 on the duties of subject entities in the fight against money laundering and terrorist financing in Central Africa;

Having regard to COBAC Regulation R-2008/01 of September 29, 2008 requiring credit institutions to develop a business continuity plan;

Having regard to COBAC Regulation R-2014/01 of March 21, 2014 on the classification, accounting, and provisioning of credit institutions' claims;

Having regard to COBAC Instruction I-2004/01 on the compatibility of certain activities with the mandate of statutory auditor of a credit institution;

Met in ordinary session on March 8, 2016 in Libreville;

DECIDES:

Article 1 This Regulation sets the minimum requirements relating to the internal control system that subject entities must implement.

TITLE I: GENERAL PROVISIONS

CHAPTER 1: DEFINITIONS

Article 2 For the purposes of this Regulation, the following terms are understood as:

  • internal audit: an activity, independent of operational units and objective, which provides an institution with assurance on the degree of mastery of its operations, provides advice to improve them, and contributes to creating added value. It helps the institution achieve its objectives by evaluating, through a systematic and methodical approach, its risk management, control, and corporate governance processes and by making proposals to strengthen their effectiveness.

  • audit committee: a body emanating from the deliberative organ charged with assisting it in the exercise of its missions, notably the evaluation of the quality of internal control, the verification of the reliability of information provided by the executive body and external auditors and the relevance of accounting methods, as well as the assessment of the consistency of systems for identifying, measuring, monitoring, and controlling risks and proposing, where appropriate, avenues for improvement.

  • risk committee: a specialized committee of the deliberative organ charged with advising the latter on the overall strategy of the subject institution regarding risk management.

  • permanent control: a device that allows for regular verification of the activity of operational units to guarantee the regularity and security of operations carried out as well as compliance with other duties related to the surveillance of risks of any nature associated with operations.

  • consolidating entity: an entity that ensures the consolidation of the accounts of the group to which a subsidiary established in the CEMAC belongs. It may be a credit institution or not.

  • subject entities: credit institutions and financial holdings.

  • financial holding: an entity defined in Article 1 of Regulation No. 01/15/CEMAC/UMAC/COBAC on the supervision of financial holdings and cross-border surveillance.

  • deliberative organ: a structure that defines the strategic direction of the institution and ensures effective supervision of the management of activities on behalf of shareholders. It is the board of directors as defined in Article 2 of Regulation No. 04/08/CEMAC/UMAC/COBAC mentioned above.

  • executive organ: the set of persons who ensure the day-to-day management of the institution's activities and the effective steering of the process of achieving the strategic objectives set by the deliberative organ. It consists of all persons who ensure the general management of the institution in accordance with Article 15 of Regulation No. 02/15/CEMAC/UMAC/COBAC/CM of March 27, 2015, amending and supplementing certain conditions relating to the exercise of the banking profession in the Economic and Monetary Community of Central Africa.

  • business continuity plan: a written and detailed action plan describing the procedures and systems necessary to continue or restore an organization's operations in the event of a disaster or interruption.

  • emergency funding plan: a set of policies, procedures, and action plans designed to respond, in a timely manner and at a reasonable cost, to serious disruptions in a subject institution's ability to finance part or all of its activities.

  • Risk: a circumstance or event that can produce adverse consequences on the institution's situation and, in particular, threatens the achievement of objectives established by the deliberative and executive organs.

  • intermediation risk: the risk of default by a client or counterparty in a transaction on financial instruments in which the subject company provides its guarantee of good performance.

  • basis risk: risk existing between the evolution of an underlying price and the evolution of the hedge.

  • exchange rate risk: risk incurred due to the evolution of currency exchange rates on balance sheet and off-balance sheet operations.

  • concentration risk: risk resulting from the accumulation of very high exposures on: i) single counterparties and groups of interconnected counterparties, both directly and indirectly; ii) counterparties operating in the same industry, same economic sector, or same geographic region; iii) counterparties whose financial results depend on the same activity or same underlying product, or the same off-balance sheet exposures (including guarantees and other commitments). This also includes concentrations of market risks and other risks, when a subject institution is excessively exposed to categories of assets, products, collateral, or currencies.

  • credit risk: risk incurred in the event of default by a counterparty or counterparties considered to be related parties within the meaning of Article 28 of COBAC Regulation R-2014/01 of March 21, 2014.

  • excessive leverage risk: the risk of vulnerability of a subject institution resulting from leverage or potential leverage that may require corrective measures not foreseen by the institution, including an emergency sale of assets that could result in losses or a revaluation of remaining assets.

  • liquidity risk: the risk for the institution not being able to meet its commitments or not being able to unwind or offset a position.

  • market risk: the risk of price variation of any instrument quoted on a market.

  • compliance risk: the risk of judicial, administrative, or disciplinary sanction, significant financial loss, or damage to reputation, arising from non-compliance with provisions specific to banking and financial activities, whether of a legislative or regulatory nature, or professional and ethical standards, or instructions from the executive organ taken notably in application of the orientations of the deliberative organ or not.

  • settlement-delivery risk: risk incurred, notably in foreign exchange operations, during the period separating the moment when the payment instruction for a sold financial instrument can no longer be unilaterally cancelled and the definitive receipt of the purchased instrument.

  • interest rate risk: risk incurred in the event of variation of interest rates on all balance sheet and off-balance sheet operations.

  • legal risk: risk of dispute with a counterparty resulting, notably, from any imprecision, gap, or insufficiency of any nature that can be attributed to the institution regarding its operations.

  • model risk: loss likely to be suffered due to decisions that may be based mainly on the results of internal models, due to errors in their development, implementation, or use.

  • operational risk: risk of losses resulting from the inadequacy or failure of internal processes, people, and systems, or external events. Operational risk includes legal risk, but excludes strategic and reputation risks.

  • residual risk: risk that remains after all prevention and protection measures have been taken into account, notably after eliminating a large part of the controllable risk by internal control.

  • systemic risk: risk of disturbance to the financial system likely to have serious negative repercussions on the financial system and the real economy.

  • internal control system: a set of provisions approved by the deliberative organ and implemented by the executive organ and all personnel of a subject institution to ensure that its activities are properly controlled at all levels to allow it to achieve the objectives set by the deliberative organ.

CHAPTER 2: GENERAL PRINCIPLES AND REQUIREMENTS

Article 3 The internal control system includes provisions to ensure:

  • the verification of operations and internal procedures, the measurement, control, and surveillance of risks;

  • the reliability of the conditions for the collection, processing, dissemination, and retention of accounting and financial data;

  • the effectiveness of internal channels for the circulation of documentation and information as well as their dissemination to third parties.

It consists of two levels:

a) permanent control which includes two tiers:

  • the first tier is ensured by operational staff, team management, and hierarchical managers;

  • the second tier is composed of: i) operational internal control proper, ii) the compliance function, and iii) risk management. This second tier must ensure the proper execution of the controls of the first tier. It is ensured a posteriori by teams dedicated to compliance control missions, who do not exercise operational functions. These teams must be autonomous, directly attached to the executive organ, and have a remuneration method whose variable part cannot have as a calculation base the operations they are charged to control. The appointment of the three heads of these entities must be brought to the knowledge of the Central African Banking Commission under the conditions provided by this Regulation.

b) periodic control or Internal Audit is carried out, under the responsibility of the deliberative organ and the Audit Committee, by independent personnel intervening on documents or on-site within the framework of spot audits.

Article 4 The permanent control of the compliance, security, and validation of operations carried out and the respect of other duties related to the surveillance of risks is ensured by agents dedicated to this activity or by other agents in charge of operational activities.

Article 5 The periodic control of the compliance of operations, the level of risk incurred, the respect of procedures, as well as the effectiveness and appropriateness of surveillance and risk management devices, is ensured by the means of investigations conducted by internal audit.

Article 6 Subject entities must equip themselves with an adequate internal control device by adapting all the devices referred to in this Regulation to the nature and volume of their activities, their size, their locations, and the different types of risks to which they are exposed. They must notably:

  • ensure that the control device is permanently integrated into the organization, methods, and procedures of each of the activities;

  • ensure that the number and qualification of the persons participating in the functioning of the internal control system as well as the means made available to them, in particular monitoring tools and risk analysis methods, are adapted to the activities, size, and locations of the institution;

  • have personnel carrying out permanent or periodic controls.

Article 7 Subject entities supervised on a consolidated or combined basis must:

  • implement the necessary means to ensure compliance with the provisions applicable regarding internal control within entities controlled exclusively or jointly within the meaning of Regulation No. 01/15/CEMAC/UMAC/COBAC on the supervision of financial holdings and cross-border surveillance;

  • ensure that the means put in place within these entities allow for the measurement, surveillance, and control of risks incurred at the consolidated or combined level;

  • verify the establishment of an organization, a control system, as well as the adoption within these entities of adequate procedures for the production of information and data for reporting on a consolidated or combined basis.

Article 8 The levels of authority and responsibility as well as the areas of intervention of the different operational units must be clearly specified and delimited.

Strict independence must be established between the units charged, each in its own regard, with the initiation, execution, validation, accounting, and control of each operation.

This independence can be ensured by a different hierarchical attachment of these units up to a sufficiently high level, as well as by procedures, possibly computerized, which guarantee a strict separation of functions.

Areas that present potential conflicts of interest, risks of collusion, or overlap of competencies or responsibilities must be identified, circumscribed, subjected to continuous surveillance, and the subject of regular evaluation with a view to mitigating or controlling conflict risks.

Periodic reviews of the responsibilities and functions of persons holding key positions must also be carried out to ensure that these managers are not able to conceal inappropriate conduct.

Article 9 The executive and deliberative organs must promote within the subject institution a culture of internal control at all levels of personnel. Each member of the institution's staff must understand their role in the internal control device and be fully involved in it.

Article 10 Subject entities must implement for each risk a system of identification, analysis, measurement, surveillance, mitigation or control, as well as risk control comprising notably:

  • the risk map which identifies and evaluates all risks incurred with regard to internal factors (notably the complexity of the organization, the nature of activities, the professionalism of personnel, and the quality of systems) and external factors (notably economic conditions and regulatory developments);

  • the definition of the institution's policy regarding each risk, formulated by the executive organ and approved by the deliberative organ;

  • the organization of activities generating this risk, with procedures relating to specific limits;

  • the operational conditions for managing activities generating this risk;

  • the procedures for measuring the risk;

  • the procedures for monitoring the risk;

  • the procedures for permanent and periodic control of the risk;

  • the procedures for mitigating or controlling the risk;

  • information on the risk provided to the deliberative and executive organs and to the General Secretariat of the Banking Commission.

Article 11 Subject entities put in place systems and procedures ensuring both upstream and prospective analysis of risks incurred when they decide:

  • to carry out operations involving new products;

  • to make significant modifications to an existing product, for this institution or for the market;

  • to carry out internal and external growth operations;

  • to carry out exceptional transactions.

Article 12 Each subject institution must equip itself with an internal control device comprising notably:

  • a system for controlling operations and risks;

  • written internal procedures;

  • an accounting organization;

  • an information processing system;

  • systems for measuring risks and results;

  • systems for monitoring and controlling risks;

  • a reporting and documentation system.

TITLE II: ORGANIZATION OF THE INTERNAL CONTROL SYSTEM

Article 13 The internal control system is designed by the executive organ and approved by the deliberative organ.

CHAPTER 3: THE DELIBERATIVE ORGAN

Article 14 The deliberative organ ensures the implementation and follow-up by the executive organ of the internal control system.

To this end, it proceeds, at least once a year, to the examination of the activity and results of internal control based on the information sent to it by the executive organ in the forms provided by this Regulation.

Article 15 The deliberative organ is in charge of:

  • defining and reviewing at least once a year all the commercial strategies and significant policies of the subject institution;

  • apprehending the main risks incurred by the subject institution;

  • approving the overall risk management policy as well as the strategic orientations for the management of each risk taken individually;

  • setting limits for these risks and ensuring that the executive organ takes the necessary measures to identify, measure, follow, and control these risks with a view to mitigating or controlling them;

  • approving the organizational structure;

  • verifying that the executive organ ensures the effectiveness of the internal control system.

Article 16 Within the framework of the internal control system, the deliberative organ has in particular the following attributions:

  • supervise the implementation of the internal control system;

  • approve the internal audit charter referred to in this Regulation as well as the annual audit program, after opinion of the audit committee;

  • ensure complete coverage of the subject institution's activities by internal controls and external audits;

  • ensure the adequacy of the internal control system to the subject institution's activities;

  • assess the adequacy of the human and material means allocated to the two levels of control;

  • ensure that internal controllers possess the necessary skills and propose, if necessary, measures to be taken at this level;

  • provide an assessment of the quality of the internal control system, notably the consistency of the devices for measuring, monitoring, and controlling risks and propose, where appropriate, complementary actions in this regard;

  • define the minimum risk areas that internal controllers and statutory auditors must cover;

  • verify the reliability and accuracy of financial information intended for the deliberative organ and third parties, and provide an assessment of the relevance of the accounting methods adopted for the preparation of individual and consolidated accounts;

  • evaluate the relevance of corrective measures taken or proposed to fill gaps or deficiencies detected in the internal control system;

  • recommend the choice of statutory auditors and external auditors of the subject institution, and supervise their relations with this institution;

  • take note of the activity reports and recommendations of the internal control function, statutory auditors, external auditors, and the supervisory authority as well as the corrective measures taken;

  • approve emergency funding plans, the business continuity plan transmitted annually, and the scenarios put in place for this purpose, including all substantial modifications that have occurred;

  • approve or evaluate any outsourced activity.

Article 17 The deliberative organ clearly delimits the responsibilities of the members of the executive organ and defines the terms of delegation of powers.

Article 18 The deliberative organ ensures the promotion, within their institution, of a control culture that particularly emphasizes the necessity, for each member of staff, to perform their tasks in compliance with current legal and regulatory provisions and internal directives and procedures.

It approves, to this end, a training and information policy that highlights the institution's objectives and explains the means of achieving them.

CHAPTER 4: THE EXECUTIVE ORGAN

Article 19 The executive organ must have the responsibility to:

a) implement the strategies and policies approved by the deliberative organ;

b) put in place appropriate internal control policies;

c) develop processes that allow identifying, measuring, following, and controlling the risks incurred by the subject institution;

d) maintain an organizational structure that clearly assigns reporting, authority, and responsibility relationships;

e) ensure that delegated responsibilities are effectively exercised;

f) monitor the adequacy and effectiveness of the internal control system.

Article 20 The design and implementation of the internal control system is the responsibility of the executive body, which, for this purpose:

  • establishes the structure of the internal control system;

  • provides the necessary human and material resources for the implementation of the internal control system;

  • identifies all internal and external risk sources;

  • defines adequate internal control procedures.

Article 21 The executive body ensures the overall proper functioning of the internal control system at all times and takes the necessary measures to remedy, in a timely manner, any deficiency or insufficiency identified.

Article 22 The executive body develops an internal control charter that specifies in particular:

  • the constituent elements of each device and the means of their implementation (internal control procedures, tools, etc.);

  • the rules ensuring the independence of control devices from operational units;

  • the different levels of responsibility for control.

This charter, approved by the deliberative body, is subject to an annual review and an update at least once every three (03) years, in order to adapt its provisions to legal and regulatory requirements as well as to the evolution of the establishment's activity, the economic and financial environment, and analysis techniques.

Article 23 The executive body develops procedures to guarantee the separation of duties and to prevent conflicts of interest in accordance with the guidelines of the deliberative body.

Article 24 The executive body ensures the promotion, within their establishment, of a control culture that particularly emphasizes the necessity for each agent to perform their tasks in compliance with applicable legal and regulatory provisions and internal directives and procedures.

To this end, it implements, in accordance with the guidelines of the deliberative body, a training and information policy that highlights the establishment's objectives and clarifies the means of achieving them.

CHAPTER 5: THE AUDIT COMMITTEE

Article 25 The establishment of an audit committee is mandatory for all regulated establishments.

Article 26 The audit committee assists the deliberative body in supervising the internal control system. It reports regularly to it on the exercise of its duties and informs it without delay of any difficulties encountered.

The audit committee must in particular ensure:

  • the reliability and clarity of financial information prepared by the executive body and external auditors, and provide an assessment of the relevance and permanence of the accounting methods adopted for the preparation of accounts;

  • the quality and effectiveness of internal control devices, in particular the consistency of risk measurement, monitoring, and control systems, and propose, as necessary, complementary actions in this regard;

  • the monitoring of the statutory audit of annual accounts, and where applicable, consolidated accounts by statutory auditors;

  • the independence of statutory auditors. To this end, the audit committee gives its opinion to the deliberative body on the statutory auditors proposed for appointment by the general meeting;

  • the prior validation of any other mission entrusted to statutory auditors, with regard to the aforementioned COBAC Instruction I-2004/01.

However, the existence of an audit committee does not relieve the deliberative body of its responsibilities defined in this regulation.

Article 27 The audit committee must analyze the main areas of risk or uncertainty in annual or consolidated accounts (including semi-annual accounts) identified by statutory auditors, assess their audit approach, and the difficulties possibly encountered in the execution of their mission. In this regard, statutory auditors bring to the knowledge of the audit committee:

  • their general work program implemented as well as the various sampling procedures conducted;

  • the modifications they deem necessary to be made to the accounts to be finalized or to other accounting documents, making all useful observations on the valuation methods used for their preparation;

  • the irregularities and inaccuracies they may have discovered;

  • the conclusions resulting from the above observations and corrections on the results of the period compared to those of the previous period.

The audit committee must examine the main elements having an impact on the audit approach (consolidation scope, acquisition or disposal operations, accounting options, new standards applied, significant operations, etc.) and the significant risks related to the preparation and processing of accounting and financial information, identified by the statutory auditor.

Article 28 The audit committee meets directly with statutory auditors on the occasion of each semi-annual and annual accounting finalization, and as often as it deems necessary, outside the presence of the executive body.

Article 29 In the exercise of its duties, the audit committee relies primarily on information provided by the establishment's services and on the interviews it conducts. In this context, the audit committee is the recipient, within a timeframe it sets, of relevant documents and analyses whose content and formats must ensure the comparability of information over time and allow members of the audit committee to have the necessary comfort regarding the expected information.

The audit committee may also request access to any other information it deems relevant in the exercise of its functions.

Subject to the agreement of the deliberative body, the audit committee may engage external experts when the situation requires it.

Article 30 The audit committee must be chaired by a member of the deliberative body and be composed of at least three members, including one independent administrator of the regulated establishment.

No person exercising executive responsibilities in the establishment may be a member of the audit committee, in particular members of the executive body, the head of Internal Audit, the head of Permanent Control, the head of Risk Management, and the head of Compliance. Similarly, the establishment's statutory auditors cannot be members of the audit committee.

Article 31 Persons designated as members of the audit committee must have the required experience and skills in financial and accounting fields as well as in audit activities.

The General Secretariat of COBAC is notified of the appointment of audit committee members before it takes effect. The regulated establishment must attach to the notification the minutes of the deliberative body session that carried out this appointment, the curriculum vitae of each designated member, and any other information allowing in particular to attest to the skills referred to in the previous paragraph.

In the absence of a reasoned objection from the General Secretary of COBAC, within a period of forty-five (45) days after notification, this appointment takes effect.

In the event of an objection by the General Secretary of COBAC, the regulated establishment is required to designate, in the forms prescribed by this article, one or more persons to replace the person(s) concerned.

Article 32 The audit committee performs preparatory work for the deliberative body. Its work is subject to regular reporting to the deliberative body, at least on the occasion of each semi-annual and annual accounting finalization.

The deliberative body evaluates the audit committee each year. On this occasion, it assesses the duties effectively carried out by the audit committee with regard to the objectives set for it and formulates suggestions for improving the committee's functioning.

Article 33 The audit committee reports exclusively to the deliberative body, which determines its operating procedures and to which it reports. Its role can in no case substitute for that of internal audit.

Article 34 The audit committee meets at least three (03) times per year.

Members of the executive body, the head of internal audit, and the establishment's statutory auditors may be heard by the audit committee during its work. They can in no case participate continuously nor take part in deliberations.

The audit committee organizes its work autonomously, in compliance with the provisions of this regulation.

The detailed minutes of each audit committee session are communicated to the General Secretariat of COBAC.

CHAPTER 6: PERMANENT CONTROL

Article 35 Regulated establishments must organize their permanent control system to provide devices that allow regular and permanent control at the operational unit level to guarantee the regularity, security, validation of operations carried out, and compliance with other diligence related to the monitoring of risks of any nature associated with operations.

Article 36 The permanent control device must ensure:

  • that the specific risk analysis has been conducted rigorously;

  • that the procedures for measuring, setting limits, and controlling incurred risks are adequate;

  • that, where applicable, necessary adaptations of existing procedures have been initiated;

  • that a risk monitoring accompanied by sufficient means for its implementation is put in place.

Article 37 The permanent control of the regularity, security, and validation of operations carried out and the compliance with other diligence related to the missions of the risk management function is ensured, with an adequate set of resources, by:

a) certain agents, at the central and local service levels, exclusively dedicated to this function;

b) other agents performing operational activities.

Article 38 The organization of regulated establishments, adopted in application of Article 8 of this regulation, is designed to ensure strict independence between, on the one hand, the units responsible for committing operations, and on the other hand, the units responsible for their validation, in particular accounting, settlement, and monitoring of diligence related to the missions of the risk management function.

Article 39 The remuneration of personnel in units responsible for the control of operations is fixed independently from that of the businesses whose operations they validate or verify, and in such a way as to have qualified and experienced personnel. It is determined by the establishment's remuneration committee and takes into account the achievement of objectives associated with the function.

Article 40 Regulated establishments designate one or more managers for the permanent control provided for in bullet a) of Article 3.

Managers at the highest level do not perform any commercial, financial, or accounting operations.

Article 41 Each incident must be the subject of a detailed report by the permanent control manager. This report is transmitted to the head of internal audit and to the executive body.

Article 42 When the size of the regulated establishment does not justify entrusting the responsibilities of permanent control to an agent under the conditions provided for in Article 40, said responsibilities may be entrusted, with the agreement of the General Secretary of COBAC, cumulatively to another manager of the establishment, other than the one in charge of internal audit.

CHAPTER 7: INTERNAL AUDIT

Article 43 Regulated establishments must equip themselves with a second-level control system or Internal Audit. The organization of the internal audit function must allow for verifying, at an adapted periodicity, the regularity and compliance of operations and the effectiveness of first-level devices, in particular their adequacy to the nature of all risks associated with operations.

Article 44 Regulated establishments are required to develop an internal audit charter that defines in particular:

  • the position, powers, and objectives of the internal audit function;

  • the responsibilities of this function and the nature of its work;

  • the modalities for communicating the results of its control missions.

This charter is communicated to the General Secretariat of the Banking Commission.

Article 45 Internal audit must operate independently from all structures with respect to which it exercises its missions.

Article 46 Internal audit ensures comprehensive monitoring of the internal control system and ensures its coherence through the evaluation of different control levels within the establishment. It is hierarchically and administratively attached to the executive body. It is directly and functionally attached to the deliberative body and the audit committee, to which it reports independently on its missions. It transmits a copy of its reports to the executive body.

Article 47 Internal audit is responsible for periodically evaluating the effectiveness of risk management and governance processes, internal procedures and policies, and the proper functioning of different control levels. It also evaluates:

  • the financial communication process and examines the reliability and accuracy of information communicated to third parties;

  • internal risk measurement and monitoring models;

  • internal procedures for evaluating the adequacy of the establishment's own funds;

  • the overall approach to business continuity management within the establishment;

  • controls performed by the structure in charge of compliance.

Article 48 Internal audit conducts periodic controls. To this end, it:

  • relies on a methodology allowing the identification of significant risks incurred by the establishment;

  • prepares a multi-year audit plan approved by the audit committee and distributes its resources accordingly; the multi-year plan must cover all activities and functions of the regulated establishment, as well as all its geographical locations including its subsidiaries, within a maximum period of three (03) years. The General Secretariat of the Central African Banking Commission may impose a shorter period if the establishment's situation justifies it;

  • must have sufficient resources and staff with appropriate training and the required experience to understand and evaluate the activities to be audited;

  • has access, for the needs of its mission, to the establishment's archives, files, and data.

Article 49 The deliberative body appoints and dismisses, on the proposal of the executive body and after approval by the audit committee, the head of internal audit.

The head of internal audit is an employee of the regulated establishment who must have the skills and qualities allowing them to properly exercise their missions.

The General Secretariat of COBAC is notified of this appointment before it takes effect. The regulated establishment must attach to the notification the minutes of the deliberative body session that carried out this appointment, the curriculum vitae of the designated person, and any other information allowing in particular to attest to the skills and qualities referred to in the previous paragraph.

In the absence of a reasoned objection from the General Secretary of COBAC, within a period of forty-five (45) days after notification, this appointment takes effect.

In the event of an objection by the General Secretary of COBAC, the regulated establishment is required to proceed with the designation of a new head of internal audit in the forms prescribed by this article.

Article 50 The head of internal audit reports on the exercise of their mission at least once a year, entirely independently, to the deliberative body and the audit committee, and monitors the implementation of corrective measures that are the subject of their recommendations.

They inform the executive body of identified deficiencies, recommendations formulated to strengthen internal control and risk management devices. They report to the deliberative body and the audit committee on their implementation by the executive body and operational services.

They also inform the head of the structure in charge of compliance, covered by this regulation, of any deficiency related to the management of non-compliance risk.

Article 51 The periodic control of the compliance of operations, the level of risk actually incurred, the respect of procedures, the effectiveness, and the appropriateness of the devices mentioned in Article 35 is ensured through investigations by agents at the central level and, where applicable, local level, other than those mentioned in said article.

Agents in charge of the periodic control provided for in the first paragraph of this article exercise their missions independently with respect to all entities and services they control.

Article 52 Regulated establishments ensure that the number and qualification of persons assigned to internal audit, as well as the resources made available to them, in particular monitoring tools and risk analysis methods, are adapted to the size, locations, and nature, scale, and complexity of risks inherent in the business model and their activities.

Article 53 The remuneration of persons assigned to internal audit is fixed independently from that of the businesses whose operations they verify, and in such a way as to have qualified and experienced personnel. It is determined by the establishment's remuneration committee and takes into account the achievement of objectives associated with the function.

CHAPTER 8: COMPLIANCE CONTROL

Article 54 Regulated establishments must equip themselves with a compliance control device. This device is responsible for monitoring non-compliance risk. The organization of the compliance device meets the following conditions:

  • compliance control is a structure independent of operational entities and directly attached to the executive body;

  • it ensures the coordination of non-compliance risk management within the establishment;

  • compliance control must be exclusive of the exercise of any other function within the establishment to avoid any potential conflict of interest;

  • certain tasks related to compliance control responsibilities may be delegated to services, cells, or departments. In this case, compliance control assumes a coordination role between entities responsible for executing tasks resulting from its responsibilities;

  • persons in charge of compliance must possess a high level of competence in the field of banking and financial activities and an in-depth knowledge of applicable rules and standards.

Article 55 Regulated establishments designate a manager responsible for ensuring the coherence and effectiveness of non-compliance risk control, whose identity they communicate to the General Secretariat of COBAC. They report their mission directly to the executive body and the risk committee.

When the size of the regulated establishment does not justify entrusting this responsibility to a person other than the permanent control manager, the latter ensures the coordination of all devices contributing to the exercise of the compliance control function.

CHAPTER 9: RISK MANAGEMENT DEVICE

Article 56 Risk management concerns all agents and units responsible for the measurement, control, and monitoring of risks. It is carried out under the authority of the executive body and the supervision of a risk committee established by the deliberative body.

The risk committee assists the deliberative body in steering the risk management device within the establishment. This committee has in particular the following attributions:

  • to advise the deliberative body on the definition of a risk management policy;

  • to propose limits for each type of risk and to periodically ensure compliance with these limits by the executive body;

  • to periodically evaluate the quality of the risk measurement, control, and monitoring device at the establishment or group level;

  • to ensure the adequacy of information systems with regard to the nature of the establishment's activities;

  • to ensure the allocation of human and material resources to the risk management function and to guarantee the independence of this function.

Article 57 Regulated establishments designate a risk management manager. Their appointment is notified to the General Secretariat of the Banking Commission. They report their mission to the risk committee and the executive body. They must not perform any commercial, financial, or accounting operations.

The risk management manager is appointed and dismissed from their functions by the deliberative body, on the proposal of the executive body.

Article 58 The risk management manager ensures the implementation of risk measurement systems and results mentioned in Title IV and risk monitoring and control systems mentioned in Title V.

They ensure that the level of risks incurred by the regulated establishment is compatible with the orientations and policies set by the supervisory body and the limits provided for in Title V of this regulation.

Article 59 The risk management manager must alert the risk committee and the executive body of any situation likely to have significant repercussions on risk control. If necessary, in case of risk evolution, they may report directly to the deliberative body.

The risk management manager communicates to the deliberative body any information necessary for the exercise of its missions or requested by it.

When the size, scale, nature, and complexity of a regulated establishment's activity or circumstances justify it, the permanent control manager may, with the agreement of the General Secretariat of COBAC, ensure the coordination of all devices participating in the risk management function.

Article 60 Regulated establishments equip the risk management activity with sufficient resources in terms of personnel, information systems, and access to internal and external information necessary for the exercise of its functions.

They ensure that the risk management function personnel have sufficient experience, qualifications, and appropriate positioning to perform their duties within the institution.

Article 61 The head of risk management shall conduct a crisis simulation on the most significant risks at least once a year.

The report of this simulation is communicated to the General Secretariat of COBAC.

CHAPTER 10: SPECIFIC CONDITIONS APPLICABLE TO OUTSOURCING

Article 62 Outsourced activities are those for which the covered institution entrusts to a third party, a natural person not part of its staff or a legal entity different from said institution, on a durable and habitual basis, the provision of services related to its essential or operational activities through subcontracting, mandate, or delegation.

Article 63 Covered institutions must ensure that any service that substantially contributes to the decision engaging the institution vis-à-vis its clients to conclude an operation is outsourced only to persons approved or authorized according to the standards required to perform such activities.

The decisions engaging the institution vis-à-vis the clients referred to in the previous paragraph are those relating to:

  • all banking operations and their related operations;

  • services participating in the execution of these operations;

  • operations for which a failure could harm the conditions for exercising the approval granted by the Monetary Authority, after the conform opinion of the Central African Banking Commission, or compliance with legal and regulatory provisions.

Article 64 Covered institutions that outsource activities must:

  • ensure that their internal control system includes their outsourced activities;

  • put in place control mechanisms for their outsourced activities.

Outsourcing activities must not have the effect of reducing or limiting the responsibilities of the deliberative body, the executive body, internal audit, entities and persons in charge of permanent control, risk management, and compliance.

Article 65 Covered institutions that outsource a service to their activity must retain full control of said activity. They must in particular respect the following provisions:

(i) outsourcing must:

  • result in a written contract between the external provider and the covered institution;

  • be part of a formalized policy, external provider control, defined by the covered institution.

(ii) covered institutions must ensure, in their relations with their external providers, that these latter:

  • commit to a quality level ensuring normal service operation and, in case of incident, resorting to backup mechanisms;

  • implement backup mechanisms in case of serious difficulty affecting service continuity or that their own continuity plan takes into account the impossibility for the external provider to perform their service;

  • cannot impose a substantial modification of the service they provide without the prior agreement of the covered institution;

  • comply with procedures defined by the covered institution concerning the organization and implementation of the control of the services they provide;

  • allow them, whenever necessary, access, possibly on-site, to any information on the services made available to them, in compliance with regulations regarding information disclosure;

  • report regularly on how the outsourced activity is exercised as well as their financial situation.

(iii) all data of the covered institution must be available on the territory of the State of its principal seat in CEMAC, notwithstanding any other provisions taken by the institution within the framework of its backup and business continuity plans. To this end, the following must be kept and permanently accessible on the territory of the State of the institution's registered office in CEMAC:

  • computer servers containing all the institution's data;

  • all physical files relating to personnel, assets, banking and related operations as well as all other transactions carried out by the covered institution;

  • all procedures, archives, and miscellaneous documents.

Article 66 The contract between the covered institution and the provider of outsourced activities must provide for the possibility for the Central African Banking Commission to exercise control on documents and on-site regarding the conditions for the performance of outsourced services.

Article 67 The outsourcing of activities must be decided by the deliberative body after a special deliberation based on a study clearly highlighting the strategic and operational advantages of this outsourcing as well as the significant risks associated with it.

Article 68 Activities related to permanent control, internal audit, compliance control, and risk management defined in Title II of this regulation cannot be outsourced.

However, for covered institutions belonging to a banking group, activities related to permanent control, compliance control, and risk management can partially be performed by the parent company or another entity of the group, under the conditions set out in Article 69, with the agreement of the COBAC Secretary-General.

Article 69 The outsourcing of operations is subject to the prior agreement of the COBAC Secretary-General to whom covered institutions provide all elements and information relating to the contemplated outsourcing decision.

To form its decision, the COBAC Secretary-General assesses within a period of ninety (90) days the conditions for the performance of outsourced activities, examines the implementation modalities of the provisions of this regulation, ensures that the responsibilities of the persons and entities covered by this regulation will continue to be exercised properly in the interest of the covered institution and the banking system, and verifies that all necessary conditions for the business continuity of the covered institution remain met.

Article 70 When a covered institution resorts to the technical assistance of a third party, the services provided in this context must not result in the outsourcing of the concerned activities within the meaning of the provisions of Article 62 of this regulation.

The technical assistance contract must clearly show the precise nature of the services expected by the covered institution and the costs to be borne by it. It must be formally approved by the Board of Directors.

The billing for technical assistance services must correspond to services actually rendered and verifiable. It cannot be performed on a lump-sum basis, nor be fixedly backed by a balance sheet, off-balance sheet, or income statement aggregate.

The technical assistance contract is submitted, before its implementation, to the prior information of the COBAC Secretary-General who may require amendments within a period of ninety (90) days taking into account the provisions of this regulation, the situation of the covered institution, and the banking sector.

Covered institutions transmit to the General Secretariat of COBAC, at the latest three months after the end of the fiscal year, an annual report on the execution of the technical assistance signed by the different stakeholders of the aforementioned contract.

TITLE III: ACCOUNTING ORGANIZATION, INFORMATION PROCESSING, AND INTERNAL PROCEDURES

Article 71 Covered institutions must put in place a system for controlling operations and internal procedures that must allow them to ensure, under optimal conditions of security, reliability, and completeness, in particular:

  • the conformity of operations performed, internal organization, and procedures with current legal and regulatory prescriptions as well as with professional and ethical standards and usages, and internal instructions of the executive body taken in application of the directives of the deliberative body;

  • strict respect of decision-making and risk-taking procedures as well as management standards and limits set by the executive body;

  • the quality of accounting and financial information intended for the deliberative body or the executive body, to be transmitted to the Banking Commission or to be published;

  • the conditions for evaluation, recording, retention, and availability of this information, particularly the existence of an audit trail;

  • the quality of information and communication systems;

  • the execution within reasonable timeframes of corrective measures decided.

CHAPTER 11: INTERNAL PROCEDURES

Article 72 Covered institutions must develop and keep up-to-date procedure manuals related to their various activities. These documents must in particular describe the modalities for recording, processing, and reporting information, accounting schemes, and operation engagement procedures.

Covered institutions must establish, under the same conditions, a procedure manual that specifies the means intended to ensure the proper functioning of internal control, in particular:

  • the different levels of responsibility;

  • the attributions assigned and the means allocated to the functioning of the internal control device;

  • the rules ensuring the independence of these devices under the conditions provided in Article 22 of this regulation;

  • procedures related to the security of information and communication systems and business continuity plans;

  • a description of the systems for measuring, limiting, monitoring, and controlling risks;

  • the organization mode of the compliance control device.

The documentation is organized in such a way as to be made available, upon request, to the deliberative body, the executive body, the audit committee, the statutory auditors, and the General Secretariat of the Banking Commission.

Article 73 Each service or operational unit must be equipped with a manual in which the procedures for performing the operations it is charged to execute are recorded. These manuals are validated by the executive body and approved by the deliberative body.

These procedures fix in particular the modalities for engagement, recording, and processing of the operation, as well as the corresponding accounting schemes, reporting, and archiving.

Article 74 The modalities for executing operations performed daily by operational entities must include appropriate permanent control procedures to ensure the regularity, reliability, and security of these operations as well as compliance with other diligence related to the monitoring of associated risks.

CHAPTER 12: ACCOUNTING CONTROL DEVICE

Article 75 Covered institutions are required to put in place a formal accounting control device, which must in particular include a dedicated function for accounting control. This device must ensure the reliability and completeness of accounting and financial data and ensure the permanent availability of information.

Accounting procedures and organization must be recorded in a document updated regularly to facilitate understanding of the system and the performance of controls. This document must comply with regulatory provisions, in particular those provided by COBAC Regulation R-2003/01 mentioned above.

Article 76 The modalities for accounting recording of operations in balance sheet, off-balance sheet, and income statement accounts must provide for a set of procedures, called an audit trail, which allows:

  • reconstructing operations in chronological order;

  • justifying any information with an original document from which it must be possible to go back through an uninterrupted path to the summary document and vice versa;

  • justifying accounting entry schemes;

  • explaining the evolution of balances from one cutoff to another by retaining movements that affected accounting items.

Article 77 The information contained in accounting statements and that necessary for calculating management standards and prudential ratios intended for the General Secretariat of the Banking Commission must respect the provisions of Article 76 of this regulation.

However, when the Banking Commission authorizes that information be provided via a statistical channel, these must be verifiable without necessarily relying on the audit trail.

Article 78 Securities and other values of the same nature held or managed for the account of third parties must be tracked through a physical inventory accounting that records entries, exits, and holdings and be subject to inventory at least once a year, and reconciliation with social accounting.

A distinction must be made between values received in free deposit and those serving as guarantees in favor of the institution itself or third parties.

Article 79 Covered institutions must ensure the completeness, quality, and reliability of information and evaluation and accounting methods in particular by:

  • periodic control of the adequacy of methods and parameters retained for the evaluation of operations;

  • regular evaluations of the accounting and information processing system regarding general prudential and security objectives as well as the conformity of accounting schemes with current rules;

  • for operations involving market risks, including exchange risk, a reconciliation, at least at the end-of-month cutoff date, between results calculated by operational units and accounting results obtained based on current evaluation rules. Significant discrepancies observed must be justified and brought to the attention of the executive body.

CHAPTER 13: INFORMATION PROCESSING SYSTEM CONTROL DEVICE

Article 80 Covered institutions determine the computer security level deemed acceptable relative to their business requirements. They monitor the retained security level and ensure that their information system is adapted. They also ensure that this security level integrates into the business continuity devices put in place in application of COBAC Regulation R-2008/01 mentioned above.

Article 81 Procedures for computerized data processing must be recorded in a written document. These procedures must allow obtaining, on paper or any other support, summary states listing in chronological order all data entered, in a form prohibiting any subsequent insertions, deletions, or additions. The reconstruction of account elements, statements, and accounting information, from entered data, must be possible and vice versa.

Article 82 The control of information systems must in particular ensure that:

  • the security level of computer systems is periodically assessed and, if necessary, corrective actions are taken;

  • computer backup procedures are available to ensure business continuity in case of serious difficulties in the functioning of computer systems;

  • the integrity and confidentiality of operations are preserved under all circumstances.

The control of information systems extends to the retention of information and documentation related to analysis, programming, and execution of treatments.

Article 83 Covered institutions must keep available, until the next cutoff date, all files necessary to justify the documents of the last cutoff submitted to the Banking Commission.

TITLE IV: RISK AND RESULT MEASUREMENT SYSTEM

CHAPTER 14: GENERAL PROVISIONS

Article 84 Covered institutions put in place systems for analyzing, measuring, and controlling risks by adapting them to the nature and volume of their operations to apprehend the various types of risks to which these operations expose them and, in particular, credit and counterparty risks, residual risk, concentration risk, market risk, global interest rate risk, intermediation risk, settlement risk, liquidity risk, excessive leverage, as well as systemic risks, model-related risks, and operational risk.

These systems also allow for a transversal and prospective analysis and measurement of risks.

Article 85 Covered institutions have reliable, effective, and comprehensive systems and procedures to evaluate and permanently maintain the amounts, types, and distribution of internal capital they deem appropriate given the nature and level of risks to which they are or could be exposed.

These systems and procedures are subject to regular internal control to ensure they remain comprehensive and adapted to the size, locations, as well as the nature, scale, and complexity of risks inherent to the business model and activities of covered institutions.

Article 86 The risk analysis and measurement systems provided for in Article 84 include criteria and thresholds to identify as significant incidents revealed by internal control procedures.

These criteria are adapted to the activity of the covered institution and cover loss risks, including when the loss has not materialized.

For this purpose, any fraud resulting in a loss or gain of a gross amount exceeding 0.5% of core own funds, without being less than five million CFA francs, is deemed significant.

Article 87 Covered institutions put in place systems and procedures to globally apprehend all risks associated with the banking and non-banking activities of the covered institution, in particular credit and counterparty risks, residual risk, concentration risk, market risk, global interest rate risk, basis risk, intermediation risk, settlement risk, liquidity risk, securitization risk, excessive leverage, as well as systemic risks, model-related risks, and operational risk.

These systems and procedures allow covered institutions to measure and manage all significant causes and effects of risks and to have a risk map that identifies and evaluates incurred risks regarding internal and external factors.

Internal factors include in particular the complexity of the organization, the nature of activities performed, the professionalism of personnel, and the quality of systems.

External factors include in particular economic conditions and regulatory developments.

Article 88 The risk map mentioned in Article 87 takes into account all incurred risks. It is established by entity or business line, evaluates the adequacy of incurred risks relative to activity developments, and identifies actions to control incurred risks by:

  • strengthening permanent control devices;

  • implementing systems for monitoring and controlling identified risks;

  • defining emergency and business continuity plans provided by COBAC Regulation R-2008/01 mentioned above.

Article 89 Covered institutions must put in place systems for analyzing and measuring all risks of different nature to which their activities expose them and, in particular, ensure that:

  • credit, market, operational, interest rate, exchange, liquidity, settlement risks, as well as risks related to outsourced activities, are correctly evaluated and controlled;

  • processes for evaluating the overall adequacy of regulatory own funds regarding these risks are put in place.

The measurement, control, and monitoring device for each risk must ensure that the risks to which the covered institution may be exposed are correctly evaluated and regularly monitored.

Article 90 The executive body must constitute committees charged with monitoring certain categories of specific risks, in particular credit risk committees, asset-liability management committees, operational risk committees, and market risk committees.

CHAPTER 15: CREDIT RISK

Article 91 Credit risk management is done under the supervision of the credit committee set up by the deliberative body and which must have the following functions:

a) propose to the executive body and the deliberative body macro-economic orientations in terms of credit distribution: sectoral orientations, geographical, policy of requirement and acceptance of different types of guarantee, policy regarding the maturity of distributed credits;

b) propose to the executive body and the deliberative body orientations, in compliance with regulatory provisions, regarding the identification, downgrading, and provisioning of risky claims;

c) examine, on behalf of the deliberative body and in compliance with regulatory and ethical provisions, credit requests from related parties and render an opinion on their acceptance and conditions applied (rate, maturity, guarantees);

d) examine important and/or sensitive credit requests, in particular those exceeding the commitment line powers and those for which the risk line has rendered a negative or reserved opinion.

Article 92 Covered institutions must have a procedure for selecting credit risks and a system for measuring these risks allowing them in particular:

  • to centrally identify their balance sheet and off-balance sheet risks vis-à-vis related parties within the meaning of Article 28 of COBAC Regulation R-2014/01;

  • to apprehend different categories of risk levels from qualitative and quantitative information, in particular through internal rating;


  • to proceed, if significant, with global distributions of their exposures by groups of counterparties subject to an identical assessment of their risk level, as assessed by the institution, as well as by economic sector and geography;

  • to evaluate the potential profitability of the transaction by ensuring that the forecast analysis of direct and indirect charges and revenues is as comprehensive as possible and covers in particular operational and financing costs, the charge corresponding to an estimate of the borrower's default risk, and the cost of remuneration of own funds.

Institutions set specific rules for the selection and monitoring of risks, assessed according to the level of own funds and the degree of concentration of the credit portfolio.

Credit risk decisions may in no case fall under, or be taken by, persons or entities external to the regulated institution. Persons or entities external to the regulated institution are those who are not part of the staff or internal organization of that institution as a legal entity.

Article 93 Regulated institutions must establish an independent credit risk control unit separate from the staff members

More like this from BEAC

We email you every new BEAC publication the day it's published.

Share