2015-11-12 | 13/POJK.03/2015Added
This regulation mandates Rural Banks (BPRs) to implement risk management frameworks tailored to their core capital levels, requiring specific risk coverage, governance structures, and internal controls. BPRs with core capital of at least IDR 50 billion must manage all six risk types, while those with lower capital are required to manage three or four specific risks. The regulation establishes deadlines for submitting action plans and risk profile reports, with full compliance required by June 2018 for larger banks and June 2019 for smaller ones.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
BY THE GRACE OF GOD THE ALMIGHTY,
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that with the increasing complexity of products and activities of Rural Banks, the risks faced by Rural Banks are also increasing; b. that with the increasing risks faced by Rural Banks, the need for the implementation of risk management by Rural Banks is also increasing;
c. that the implementation of risk management is one of the efforts to strengthen institutions and improve the reputation of the Rural Bank industry in accordance with the policy direction for the development of Rural Banks;
d. that the strengthening of institutions and improvement of the reputation of the Rural Bank industry are expected to create a financial sector that grows sustainably and stably and has high competitiveness; e. that based on considerations as referred to in letters a, b, c, and d, it is necessary to establish a Financial Services Authority Regulation on the Implementation of Risk Management for Rural Banks;
Recalling:
DECIDING:
Establishing: FINANCIAL SERVICES AUTHORITY REGULATION ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR RURAL BANKS.
In this Financial Services Authority Regulation, the following terms are defined as:
(1) BPRs are required to implement Risk Management as regulated in this Financial Services Authority Regulation.
(2) The implementation of Risk Management as referred to in paragraph (1) must at least include:
a. Supervision by the Board of Directors and Board of Commissioners. b. Adequacy of policies, procedures, and limits, namely:
(1) Risks that must be managed in the implementation of Risk Management include:
a. Credit Risk; b. Operational Risk;
c. Compliance Risk;
d. Liquidity Risk; e. Reputation Risk; and f. Strategic Risk.
(2) BPRs with core capital of at least IDR 50,000,000,000.00 (fifty billion rupiah) are required to implement Risk Management as referred to in Article 2 for all types of Risks as referred to in paragraph (1). (3) BPRs with core capital of at least IDR 15,000,000,000.00 (fifteen billion rupiah) and less than IDR 50,000,000,000.00 (fifty billion rupiah) are required to implement Risk Management as referred to in Article 2 for at least 4 (four) Risks as referred to in paragraph (1) letters a through d. (4) BPRs with core capital less than IDR 15,000,000,000.00 (fifteen billion rupiah) are required to implement Risk Management as referred to in Article 2 for at least 3 (three) Risks as referred to in paragraph (1) letters a through c. (5) BPRs with core capital of at least IDR 50,000,000,000.00 (fifty billion rupiah) as referred to in paragraph (2) but with total assets less than IDR 300,000,000,000.00 (three hundred billion rupiah) and meeting the conditions:
a. having less than 10 (ten) branch offices; and b. not conducting activities as an issuer of Automated Teller Machine cards or debit cards, are required to implement Risk Management as referred to in Article 2 for at least 4 (four) Risks as referred to in paragraph (1) letters a through d. (6) BPRs with core capital less than IDR 50,000,000,000.00 (fifty billion rupiah) as referred to in paragraph (3) and paragraph (4) but with total assets of at least IDR 300,000,000,000.00 (three hundred billion rupiah) and meeting the conditions:
a. having at least 10 (ten) branch offices; and/or b. conducting activities as an issuer of Automated Teller Machine cards or debit cards, are required to implement Risk Management as referred to in Article 2 for all Risks as referred to in paragraph (1).
In the context of supervising the implementation of Risk Management, BPRs are required to establish clear authorities and responsibilities at every level of position related to the implementation of Risk Management as referred to in Article 2 paragraph (2) letter a.
(1) The authorities and responsibilities of the Board of Directors as referred to in Article 4 must at least include:
a. drafting written policies and guidelines for the implementation of Risk Management; b. evaluating and deciding on transactions requiring Board of Directors approval;
c. developing a Risk Management culture at all levels of the organization;
d. ensuring the improvement of human resources competence related to Risk Management; e. ensuring that the Risk Management function has operated independently; and f. being responsible for:
The authorities and responsibilities of the Board of Commissioners as referred to in Article 4 must at least include:
a. approving and evaluating Risk Management policies; b. ensuring the implementation of Risk Management by the Board of Directors;
c. evaluating the Board of Directors' accountability for the implementation of Risk Management policies as referred to in Article 5 paragraph (1) letter f number 1); and
d. evaluating and deciding on Board of Directors' requests related to transactions requiring Board of Commissioners' approval.
Risk Management policies as referred to in Article 2 paragraph (2) letter b number 1) must at least include:
a. Determination of Risks related to BPR business activities, products, and services; b. Determination of Risk Management information systems;
c. Determination of limits and setting of Risk tolerance;
d. Determination of Risk rating assessments; e. Preparation of contingency plans in worst-case conditions; and f. Determination of internal control systems in the implementation of Risk Management.
(1) Risk Management procedures as referred to in Article 2 paragraph (2) letter b number 2) must at least include:
a. clear levels of delegation of authority and accountability; and b. adequate documentation of procedures and determination of Risk limits.
(2) The determination of Risk limits as referred to in Article 2 paragraph (2) letter b number 3) includes:
a. overall limits; b. limits per type of Risk; and
c. limits per specific functional activities that have Risk exposure.
(1) BPRs are required to carry out processes for identifying, measuring, monitoring, and controlling Risks as referred to in Article 2 paragraph (2) letter c number 1) against all material Risk factors. (2) The implementation of the processes for identifying, measuring, monitoring, and controlling Risks as referred to in paragraph (1) must be supported by:
a. adequate management information systems; and b. accurate and informative reports regarding the financial condition of the BPR, performance of functional activities, and BPR Risk exposure.
(1) The implementation of Risk identification processes must at least be conducted by analyzing:
a. Risk characteristics inherent in the BPR; and b. Risks from BPR business activities, products, and services.
(2) In order to carry out Risk measurement, BPRs must at least:
a. evaluate the suitability of assumptions, data sources, and procedures used to measure Risk; and b. adjust the Risk measurement process if there are material changes in BPR service activities, products, and Risk factors. (3) In order to carry out Risk monitoring, BPRs must at least:
a. evaluate Risk exposure; and b. adjust reporting processes if there are material changes in BPR business activities, products, Risk factors, information technology, and Risk Management information systems. (4) The implementation of Risk control processes is used by BPRs to manage Risks that can endanger the continuity of BPR business.
(1) Risk Management information systems as referred to in Article 2 paragraph (2) letter c number 2) must at least include reports or information regarding:
a. Risk exposure; b. compliance with Risk Management policies as referred to in Article 7;
c. compliance with Risk Management procedures and determination of Risk limits as referred to in Article 8; and
d. the realization of Risk Management implementation compared to established targets.
(2) Reports or information generated from Risk Management information systems as referred to in paragraph (1) must be submitted periodically to the Board of Directors.
BPRs are required to implement a comprehensive internal control system effectively regarding the implementation of business activities and operations at all levels of the BPR organization.
The implementation of a comprehensive internal control system as referred to in Article 12 must at least be able to detect weaknesses and deviations that occur, in a timely manner.
(1) The comprehensive internal control system as referred to in Article 2 paragraph (2) letter d in the context of Risk Management implementation must at least include:
a. the suitability of the internal control system with the type and level of Risks inherent in BPR business activities and service types; b. the determination of authorities and responsibilities for monitoring compliance with Risk Management policies as referred to in Article 7;
c. the determination of authorities and responsibilities for monitoring compliance with Risk Management procedures and determination of Risk limits as referred to in Article 8;
d. clear reporting lines and separation of functions; e. an organizational structure that clearly depicts BPR business activities; f. accurate and timely financial and operational reporting; g. adequate procedures to ensure BPR compliance with laws and regulations; h. complete and adequate documentation; and
i. verification and review of the internal control system.
(2) The assessment of the internal control system in the implementation of Risk Management as referred to in paragraph (1) is conducted by the internal audit work unit or Executive Officers handling the internal audit function.
In order to carry out Risk Management processes and systems as referred to in Article 2:
(1) BPRs with core capital of at least IDR 80,000,000,000.00 (eighty billion rupiah) are required to form:
a. a Risk Management Committee; and b. a Risk Management work unit.
(2) BPRs with core capital of at least IDR 50,000,000,000.00 (fifty billion rupiah) and less than IDR 80,000,000,000.00 (eighty billion rupiah) are required to form a Risk Management work unit. (3) BPRs with core capital less than IDR 50,000,000,000.00 (fifty billion rupiah) are at least required to appoint one Executive Officer responsible for the implementation of the Risk Management function. (4) If necessary, BPRs with core capital less than IDR 80,000,000,000.00 (eighty billion rupiah) may form a Risk Management Committee.
(1) The Risk Management Committee as referred to in Article 15 paragraph (1) letter a and paragraph (4) must at least consist of:
a. a majority of the Board of Directors; and b. relevant Executive Officers.
(2) The authorities and responsibilities of the Risk Management Committee as referred to in paragraph (1) provide recommendations to the President Director, which must at least include:
a. drafting policies and guidelines for the implementation of Risk Management; b. improvement and/or refinement of Risk Management implementation based on the results of Risk Management implementation evaluations; and
c. considerations and/or determination of matters related to operational decisions that deviate from normal procedures.
(1) The Risk Management work unit as referred to in Article 15 paragraph (1) letter b and paragraph (2) and the Executive Officer as referred to in Article 15 paragraph (3) must be independent. (2) The Risk Management work unit as referred to in Article 15 paragraph (1) letter b and paragraph (2) and the Executive Officer as referred to in Article 15 paragraph (3) are directly responsible to the Board of Directors member who oversees the Risk Management function. (3) The authorities and responsibilities of the Risk Management work unit or the appointed Executive Officer responsible for implementing the Risk Management function include:
a. monitoring the implementation of Risk Management policies and guidelines approved by the Board of Directors; b. monitoring overall Risk positions, per type of Risk, and per type of functional activity;
c. reviewing proposals for the issuance of products and/or implementation of new activities;
d. submitting recommendations to work units or employees handling operational functions and the Risk Management Committee, according to their respective authorities; and e. drafting and submitting Risk profile reports periodically to the Board of Directors member who oversees the Risk Management function and the Risk Management Committee.
(1) In order to manage Risks inherent in the issuance of products and/or implementation of new activities, BPRs are required to have written policies and procedures.
(2) The criteria for the issuance of products and/or implementation of new activities by BPRs are the issuance of products and/or implementation of activities that:
a. have never been issued or implemented previously by the BPR; or b. have been issued or implemented previously by the BPR but undergo development that changes or increases all Risks or specific Risks of the BPR. (3) Written policies and procedures as referred to in paragraph (1) must at least include:
a. determination of risks for new products and activities; b. identification of all Risks related to new products and activities;
c. legal aspect analysis for each new product and activity;
d. operational systems and procedures and authorities in the management of new products and activities; e. accounting information systems for new products and activities; and f. trial period for risk measurement and monitoring methods for new products and activities. (4) The issuance of products and/or implementation of new activities as referred to in paragraph (2) is conducted in accordance with laws and regulations.
BPRs are required to submit written information regarding Risks related to new products and activities as referred to in Article 18 paragraph (3) letter b to customers or prospective customers before the transaction is conducted.
Risk Management Implementation Action Plan
(1) In order to implement Risk Management as referred to in Article 2, BPRs are required to draft and submit an action plan report to the Financial Services Authority.
(2) The action plan report as referred to in paragraph (1) must be submitted no later than June 30, 2016.
(3) The Financial Services Authority may request BPRs to adjust the action plan report as referred to in paragraph (1) if the action plan is deemed to not fully meet the requirements established by the Financial Services Authority. (4) The deadline for completing the action plan as referred to in paragraph (2) and/or completing the adjusted action plan as referred to in paragraph (3) for BPRs with core capital:
a. at least IDR 50,000,000,000.00 (fifty billion rupiah) no later than June 30, 2018; or b. less than IDR 50,000,000,000.00 (fifty billion rupiah) no later than June 30, 2019. (5) The deadline for completing the action plan as referred to in paragraph (4) must take into account the deadline for forming the Risk Management Committee, Risk Management work unit, and/or appointing Executive Officers responsible for the implementation of the Risk Management function as referred to in Article 38.
(1) BPRs are required to submit reports on the realization of the Risk Management implementation action plan as referred to in Article 20 to the Financial Services Authority every semester. (2) The report on the realization of the Risk Management implementation action plan as referred to in paragraph (1) must be submitted no later than July 31 for the first semester report and January 31 of the following year for the second semester report. (3) The report on the realization of the Risk Management implementation action plan as referred to in paragraph (1) is first submitted for the first semester of 2017. (4) In the event that a BPR has realized all Risk Management implementation action plans as referred to in Article 20 paragraph (1) before the deadline as referred to in Article 20 paragraph (4) and has reported it to the Financial Services Authority, the BPR is not required to submit reports on the realization of the Risk Management implementation action plan for the following semester.
Risk Profile Report
(1) BPRs are required to submit Risk profile reports to the Financial Services Authority every semester.
(2) The Risk profile report as referred to in paragraph (1) submitted by BPRs must contain the same material as the Risk profile report submitted by the Risk Management work unit or the Executive Officer appointed to be responsible for implementing the Risk Management function to the Board of Directors member who oversees the Risk Management function and to the Risk Management Committee. (3) The Risk profile report as referred to in paragraph (1) must be submitted no later than July 31 for the first semester report and January 31 of the following year for the second semester report. (4) BPRs with core capital as referred to in Article 3 paragraph (2) and BPRs with core capital, assets, and meeting the conditions as referred to in Article 3 paragraph (6) submit their first Risk profile report as referred to in paragraph (1) including:
a. 3 (three) Risks, namely Credit Risk, Operational Risk, and Compliance Risk for the second semester of 2018; and b. 6 (six) Risks, namely Credit Risk, Operational Risk, Liquidity Risk, Compliance Risk,
Reputational risk, and Strategic risk for the second semester of 2020.
(5) BPRs having core capital as referred to in Article 3 paragraph (3) and BPRs having core capital as well as assets and meeting the conditions as referred to in Article 3 paragraph (5) submit for the first time the Risk Profile Report as referred to in paragraph (1) comprising:
a. 2 (two) Risks, namely Credit Risk and Operational Risk for the second semester of 2019; and b. 4 (four) Risks, namely Credit Risk, Operational Risk, Liquidity Risk, and Compliance Risk for the second semester of 2021. (6) BPRs having core capital as referred to in Article 3 paragraph (4) submit for the first time the Risk Profile Report as referred to in paragraph (1) comprising:
a. 1 (one) Risk, namely Credit Risk for the second semester of 2019; and b. 3 (three) Risks, namely Credit Risk, Operational Risk, and Compliance Risk for the second semester of 2021.
Part Three
New Product and Activity Reports
Article 23
(1) BPRs are required to submit reports on new products and activities to the Financial Services Authority (Otoritas Jasa Keuangan), consisting of:
a. reports on the plan for issuing products and implementing new activities; and b. reports on the realization of issuing products and implementing new activities.
(2) Reports on the plan for issuing products and implementing new activities as referred to in paragraph (1) letter a must be submitted at the latest 30 (thirty) working days before the issuance of products and/or implementation of new activities. (3) Reports on the realization of issuing products and implementing new activities as referred to in paragraph (1) letter b must be submitted at the latest 10 (ten) working days after the issuance of products and/or implementation of new activities. (4) In addition to fulfilling the reporting provisions as referred to in paragraph (1), the issuance of products and/or implementation of new activities meeting the criteria as referred to in Article 18 paragraph (2) must be included in the BPR's business plan. (5) Based on the evaluation results of reports on the plan for issuing products and implementing new activities as referred to in paragraph (1) letter a, the Financial Services Authority may determine that BPRs do not issue products and/or implement new activities as planned. (6) The Financial Services Authority may order BPRs to stop the issuance of products and/or implementation of new activities as referred to in paragraph (1), if subsequently based on the Financial Services Authority's evaluation, the issued products and/or implemented activities meet the conditions:
a. inconsistent with the plan for issuing products and new activities reported to the Financial Services Authority; b. potentially causing significant losses to the financial condition of the BPR; and
c. inconsistent with applicable laws and regulations.
Part Four
Other Risk Profile Reports
Article 24
(1) BPRs are required to submit other Risk Profile Reports to the Financial Services Authority in the event of conditions that have the potential to cause significant losses to the financial condition of the BPR. (2) Other Risk Profile Reports as referred to in paragraph (1) are Risk Profile Reports other than those referred to in Article 22. (3) Other Risk Profile Reports as referred to in paragraph (1) must be submitted at the latest 1 (one) month after the condition with the potential to cause significant losses to the financial condition of the BPR is known. (4) The obligation to submit other Risk Profile Reports as referred to in paragraph (1) may also be based on a request from the Financial Services Authority.
Part Five
Submission Time Limits
Article 25
(1) BPRs are considered to have submitted reports late:
a. action plan reports as referred to in Article 20 paragraph (2); b. action plan realization reports as referred to in Article 21 paragraph (2);
c. Risk Profile Reports as referred to in Article 22 paragraph (3);
d. reports on the realization of issuing products and implementing new activities as referred to in Article 23 paragraph (3); and e. other Risk Profile Reports as referred to in Article 24 paragraph (3), if BPRs submit reports to the Financial Services Authority beyond the final submission deadline by up to 1 (one) month after the final submission deadline. (2) BPRs are considered to have submitted reports on the plan for issuing products and implementing new activities as referred to in Article 23 paragraph (2) late if the reports are submitted less than 30 (thirty) working days before the issuance of products and/or implementation of new activities. (3) BPRs are considered to have not submitted reports:
a. action plan reports as referred to in Article 20 paragraph (2); b. action plan realization reports as referred to in Article 21 paragraph (2);
c. Risk Profile Reports as referred to in Article 22 paragraph (3);
d. reports on the realization of issuing products and implementing new activities as referred to in Article 23 paragraph (3); and e. other Risk Profile Reports as referred to in Article 24 paragraph (3), if BPRs have not submitted the aforementioned reports within the late submission time limit as referred to in paragraph (1). (4) BPRs are considered to have not submitted reports on the plan for issuing products and implementing new activities as referred to in Article 23 paragraph (2) if the reports are submitted at the time of or after the issuance of products and/or implementation of new activities.
Part Six
Format and Method of Report Submission
Article 26
The format, instructions for compilation, and method of submission of reports as referred to in Article 20 paragraph (1), Article 21 paragraph (1), Article 22 paragraph (1), Article 23 paragraph (1), and Article 24 paragraph (1) are regulated by a Circular Letter of the Financial Services Authority.
CHAPTER X
ASSESSMENT OF RISK MANAGEMENT IMPLEMENTATION
Article 27
(1) The Financial Services Authority conducts assessments of the implementation of Risk Management in BPRs.
(2) In addition to conducting assessments as referred to in paragraph (1), the Financial Services Authority may adjust the assessment of Risk Management implementation by considering the development of conditions and potential problems faced by BPRs. (3) In the context of assessing the implementation of Risk Management as referred to in paragraph (1), BPRs are required to submit data and information related to the implementation of Risk Management to the Financial Services Authority. (4) The method and assessment methods for the implementation of Risk Management are further regulated by a Circular Letter of the Financial Services Authority.
CHAPTER XI
ADJUSTMENT OF RISK MANAGEMENT IMPLEMENTATION
Article 28
(1) BPRs that based on monthly reports experience an increase in core capital to at least Rp50,000,000,000.00 (fifty billion rupiah) during 6 (six) consecutive monthly report positions until December 31, 2018, and:
a. have total assets of at least Rp300,000,000,000.00 (three hundred billion rupiah); or b. have total assets of less than Rp300,000,000,000.00 (three hundred billion rupiah) and meet the conditions:
Article 29
(1) BPRs that based on monthly reports experience an increase in core capital to at least Rp80,000,000,000.00 (eighty billion rupiah) during 6 (six) consecutive monthly report positions, must fulfill the organizational structure as referred to in Article 15 paragraph (1) at the latest one year after the BPR meets core capital of at least Rp80,000,000,000.00 (eighty billion rupiah) during 6 (six) consecutive monthly report positions. (2) BPRs that based on monthly reports experience an increase in core capital to at least Rp50,000,000,000.00 (fifty billion rupiah) and less than Rp80,000,000,000.00 (eighty billion rupiah) during 6 (six) consecutive monthly report positions, must fulfill the organizational structure as referred to in Article 15 paragraph (2) at the latest one year after the BPR meets core capital of at least Rp50,000,000,000.00 (fifty billion rupiah) and less than Rp80,000,000,000.00 (eighty billion rupiah) during 6 (six) consecutive monthly report positions.
Article 30
(1) BPRs that based on monthly reports experience an increase in core capital to at least Rp15,000,000,000.00 (fifteen billion rupiah) and less than Rp50,000,000,000.00 (fifty billion rupiah) during 6 (six) consecutive monthly report positions until December 31, 2019, and have total assets of less than Rp300,000,000,000.00 (three hundred billion rupiah), must report Risks as referred to in Article 3 paragraph (1) letters a through d according to the phasing as referred to in Article 22 paragraph (5). (2) BPRs that based on monthly reports experience an increase in core capital to at least Rp15,000,000,000.00 (fifteen billion rupiah) and less than Rp50,000,000,000.00 (fifty billion rupiah) during 6 (six) consecutive monthly report positions after December 31, 2019 until December 31, 2021 and have total assets of less than Rp300,000,000,000.00 (three hundred billion rupiah), must report Risk Profiles as referred to in Article 3 paragraph (1) letters a through d for the first time for the Risk Profile Report of the second semester of 2021. (3) BPRs that based on monthly reports experience an increase in core capital to at least Rp15,000,000,000.00 (fifteen billion rupiah) and less than Rp50,000,000,000.00 (fifty billion rupiah) during 6 (six) consecutive monthly report positions after December 31, 2021 and have total assets of less than Rp300,000,000,000.00 (three hundred billion rupiah), must report Risk Profiles as referred to in Article 3 paragraph (1) letters a through d for the first time in the Risk Profile Report of the semester following one year after the BPR meets core capital of at least Rp15,000,000,000.00 (fifteen billion rupiah) and less than Rp50,000,000,000.00 (fifty billion rupiah) during 6 (six) consecutive monthly report positions.
Article 31
(1) BPRs that experience an increase in assets to at least Rp300,000,000,000.00 (three hundred billion rupiah) during 6 (six) consecutive monthly report positions and meet the conditions as referred to in Article 3 paragraph (6) until December 31, 2018, must report all Risks as referred to in Article 3 paragraph (1) according to the phasing as referred to in Article 22 paragraph (4). (2) BPRs that experience an increase in assets to at least Rp300,000,000,000.00 (three hundred billion rupiah) during 6 (six) consecutive monthly report positions and meet the conditions as referred to in Article 3 paragraph (6) after December 31, 2018 until December 31, 2020, must report all Risks as referred to in Article 3 paragraph (1) at the latest by December 31, 2020. (3) BPRs that experience an increase in assets to at least Rp300,000,000,000.00 (three hundred billion rupiah) during 6 (six) consecutive monthly report positions and meet the conditions as referred to in Article 3 paragraph (6) after December 31, 2020, must report all Risks as referred to in Article 3 paragraph (1) for the first time in the Risk Profile Report of the semester following one year after the BPR meets total assets of at least Rp300,000,000,000.00 (three hundred billion rupiah) during 6 (six) consecutive monthly report positions.
Article 32
BPRs that based on monthly reports experience a decrease in core capital or total assets resulting in a reduction of the obligation to implement the number of Risks from the original number, must continue to apply the types of Risks and completeness of the organizational structure that were in effect before the decrease in core capital or total assets occurred.
CHAPTER XII
SANCTIONS
Article 33
(1) BPRs that submit reports late as referred to in Article 25 paragraph (1) and paragraph (2) are subject to sanctions in the form of a fine of Rp100,000.00 (one hundred thousand rupiah) per day of delay per report, with a maximum fine of Rp3,000,000.00 (three million rupiah) per report. (2) BPRs that do not submit reports as referred to in Article 25 paragraph (3) and paragraph (4) are subject to sanctions in the form of a fine of Rp5,000,000.00 (five million rupiah) per report. (3) BPRs that submit Risk Profile Reports as regulated in Article 22 paragraph (1) which, based on the Financial Services Authority's assessment, are declared significantly incorrect and/or incomplete are subject to administrative sanctions in the form of written warnings and sanctions in the form of a fine of Rp10,000,000.00 (ten million rupiah). (4) In addition to administrative sanctions in the form of written warnings and sanctions in the form of fines as referred to in paragraph (3), BPRs are also subject to administrative sanctions in the form of:
a. downgrade of the BPR's health level; and/or b. inclusion of management in the list of parties receiving a "failed" designation.
(5) The imposition of sanctions in the form of fines as referred to in paragraph (3) is carried out after BPRs have been given 2 (two) written warning letters by the Financial Services Authority with a grace period of 10 (ten) working days for each warning, and the BPR does not submit or correct the Risk Profile Report within 10 (ten) working days after the final warning letter.
Article 34
BPRs that do not implement the provisions as regulated in Article 2 paragraph (1), Article 3 paragraph (2), paragraph (3), paragraph (4), paragraph (5), and paragraph (6), Article 4, Article 9, Article 12, Article 15 paragraph (1), paragraph (2) and paragraph (3), Article 18 paragraph (1), Article 19, Article 20 paragraph (1), Article 27 paragraph (3), Article 29, and Article 38, are subject to administrative sanctions in the form of written warnings and/or:
a. downgrade of the health assessment level; and/or b. temporary suspension of part of the BPR's operational activities.
Article 35
BPRs that violate the determination of the Financial Services Authority not to issue products and/or implement new activities as planned as referred to in Article 23 paragraph (5) or do not comply with the order of the Financial Services Authority to stop the issuance of products and/or implementation of new activities as referred to in Article 23 paragraph (6) are subject to administrative sanctions in the form of written warnings and:
a. downgrade of the health assessment level; b. temporary suspension of part of the BPR's operational activities; and/or
c. inclusion of BPR management in the list of parties receiving a "failed" designation.
Article 36
(1) BPRs that violate the provisions of Article 28, Article 30, and Article 31 are subject to administrative sanctions in the form of written warnings and sanctions in the form of a fine of Rp10,000,000.00 (ten million rupiah). (2) In addition to administrative sanctions in the form of written warnings and sanctions in the form of fines as referred to in paragraph (1), BPRs are also subject to administrative sanctions in the form of:
a. downgrade of the health level; and/or b. inclusion of management in the list of parties receiving a "failed" designation.
(3) The imposition of sanctions in the form of fines as referred to in paragraph (1) is carried out after BPRs have been given 2 (two) written warning letters by the Financial Services Authority with a grace period of 10 (ten) working days for each warning, and the BPR does not submit or correct the Risk Profile Report within 10 (ten) working days after the final warning letter.
Article 37
(1) The imposition of sanctions for the submission of Risk Profile Reports as referred to in Article 22 paragraph (4) starts to be applied to the submission of reports for the position of December 31, 2019. (2) The imposition of sanctions for the submission of Risk Profile Reports as referred to in Article 22 paragraph (5) and paragraph (6) starts to be applied to the submission of reports for the position of December 31, 2020.
CHAPTER XIII
TRANSITIONAL PROVISIONS
Article 38
The formation of the Risk Management Committee, Risk Management work units, and/or the appointment of one Executive Officer responsible for the implementation of Risk Management functions as referred to in Article 15 by BPRs that have obtained business permits before these provisions take effect, must be carried out at the latest by December 31, 2017.
CHAPTER XIV
CLOSING PROVISIONS
Article 39
Further provisions of this Financial Services Authority Regulation are regulated by a Circular Letter of the Financial Services Authority.
Article 40
This Financial Services Authority Regulation takes effect on the date of its enactment.
To ensure that everyone knows it, the enactment of this Financial Services Authority Regulation is ordered by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta
On December 3, 2015
CHAIRMAN OF THE COMMISSIONERS
FINANCIAL SERVICES AUTHORITY signed
MULIAMAN D. HADAD
Enacted in Jakarta
On November 12, 2015
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H.LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2015 NUMBER 272 Copy consistent with the original Legal Director 1 Legal Department signed Sudarmaji
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 13/POJK.03/2015
ON
THE IMPLEMENTATION OF RISK MANAGEMENT FOR RURAL BANKS
I. GENERAL
Rural Banks (BPR) as one type of bank providing financial intermediation services, especially to micro and small businesses and rural communities, constantly face Risks in the execution of their business activities. The increasing development of the banking industry, the public's need for more varied, easy, and fast financial service offerings, accompanied by very rapid information technology development, encourages BPRs to further improve their products and services, which in turn will increase BPR Risks. This increase in Risk must be balanced by an increase in Risk control. Therefore, BPRs are required to implement Risk Management. The implementation of Risk Management is not only aimed at BPRs but also to protect BPR stakeholders. Risk Management principles, including the types of Risks that BPRs must implement, are adjusted to the characteristics of BPR business activities and aligned with regulations regarding the implementation of Risk Management for conventional banks and Islamic banking. Risk Management principles are essentially banking standards to operate more cautiously in the scope of very rapid business development and banking operations today. Considering the existing gaps in the BPR industry, the implementation of Risk Management is differentiated according to business activities, products, and services, as well as BPR capabilities in terms of finances, supporting infrastructure, and human resources. The Financial Services Authority establishes these provisions as minimum standards that BPRs must meet in implementing Risk Management. With these provisions, BPRs are expected to be able to carry out all activities in an integrated manner within an accurate and comprehensive Risk management framework.
II. ARTICLE BY ARTICLE
Article 1
Sufficiently clear.
Article 2
Sufficiently clear.
Article 3
Paragraph (1)
Letter a
What is meant by Credit Risk is the Risk due to the failure of debtors and/or other parties to fulfill their obligations to the BPR.
Letter b
What is meant by Operational Risk is the Risk caused by, among other things, the insufficiency and/or malfunction of internal processes, human resource errors, system failures, and/or external issues affecting BPR operations. Letter c What is meant by Compliance Risk is the Risk due to BPRs not complying with and/or not implementing applicable laws and regulations and other provisions, including Risks due to legal aspect weaknesses. Legal aspect weaknesses are caused by, among other things, legal claims, the absence of supporting laws and regulations, or weaknesses in agreements such as the failure to meet contract validity requirements and imperfect collateral binding. Letter d What is meant by Liquidity Risk is the Risk due to the BPR's inability to fulfill obligations due from cash flow funding sources and/or high-quality liquid assets that can be pledged, without disrupting activities and/or the financial condition of the BPR. Letter e What is meant by Reputational Risk is the Risk due to the decline in the level of trust of stakeholders stemming from negative perceptions regarding the BPR. Letter f What is meant by Strategic Risk is the Risk due to the BPR's inappropriateness in making and/or implementing strategic decisions and the BPR's failure to anticipate changes in the business environment. Paragraph (2) Sufficiently clear. Paragraph (3) Sufficiently clear. Paragraph (4) Sufficiently clear. Paragraph (5) Sufficiently clear. Paragraph (6) Sufficiently clear.
Article 4
Clear enough.
Article 5
Paragraph (1)
Letter a
Risk Management Policy includes among others the strategy and Risk framework established in accordance with the level of Risk to be taken (risk appetite) and risk tolerance (risk tolerance).
Letter b
Transactions requiring Board of Directors approval include among others transactions that have exceeded the authority of the BPR executive one level below the Board of Directors, in accordance with applicable internal policies and procedures.
Letter c
Development of Risk Management culture includes among others the dissemination of information to all employees and adequate communication regarding Risk Management principles including developing a Risk-conscious culture and the importance of effective internal controls.
Letter d
Improvement of human resource competence includes among others through continuous education and training programs regarding the implementation of Risk Management.
Letter e
The meaning of the term independent includes among others the separation of functions between the work unit or Executive Official responsible for handling the Risk Management function and the work unit or employee who carries out the operational functions of the BPR. The meaning of operational function is the function related to the collection and disbursement of funds.
Letter f
Number 1)
Including responsibility for the implementation of Risk Management policy is:
Number 2)
Clear enough.
Paragraph (2)
Clear enough.
Article 6
Letter a
Evaluation of Risk Management policy is conducted by the Board of Commissioners at least once a year or at any time in the event of changes that significantly affect the business activities of the BPR.
Letter b
Clear enough.
Letter c
Evaluation of the Board of Directors' accountability for the implementation of Risk Management policy is conducted by the Board of Commissioners at least every semester.
Letter d
Transactions requiring Board of Commissioners approval are transactions that according to legislation require Board of Commissioners approval, including among others the provision of credit to related parties.
Article 7
The establishment of Risk Management policy considers financial conditions, organizational structure and complexity, and Risks arising as a result of changes in internal and external factors.
Letter a
Clear enough.
Letter b
Included in the Risk Management information system is the information flow to the BPR Board of Directors utilizing information technology or data processing results in order to support decision making.
Letter c
Risk Tolerance is the potential loss that can be absorbed by the BPR's capital.
Letter d
Risk rating assessment is the basis for the BPR to establish the BPR Risk rating which is categorized into 5 (five) Risk ratings, namely very low, low, medium, high, and very high.
Letter e
The meaning of emergency plan is the development of scenario plans to anticipate the occurrence of internal disruptions including system failures and external disruptions that cause emergency conditions that can cause operational disruptions to the BPR.
Letter f
Clear enough.
Article 8
Risk Management procedures and Risk limit establishment are adjusted to the level of Risk to be taken (risk appetite) against the BPR's Risk.
The level of Risk to be taken takes into account the experience held by the BPR regarding the Risk of BPR business transactions in the past.
Paragraph (1)
Letter a
Clear enough.
Letter b
The meaning of adequate documentation is written, complete, accurate, current, and intact documentation so as to facilitate audit trails for the purpose of BPR internal control.
Paragraph (2)
Letter a
The meaning of overall limit is the Risk limit that can be tolerated by the BPR for all Risks implemented.
Letter b
The meaning of limit per type of Risk is the Risk limit that can be tolerated by the BPR for each type of Risk.
Letter c
The meaning of limit per specific functional activity is the Risk limit that can be tolerated by the BPR for each functional activity.
Article 9
Paragraph (1)
The meaning of material Risk factors are quantitative and qualitative Risk factors that significantly affect the financial condition of the BPR.
Paragraph (2)
Letter a
The meaning of adequate management information system is a management information system capable of providing complete, accurate, current, and intact data and information for decision making related to Risk Management.
Letter b
Clear enough.
Article 10
Paragraph (1)
Risk identification is conducted based on past experience related to transactions that caused losses, reduced profits or caused problems for the BPR.
Paragraph (2)
Letter a
Evaluation is conducted by an independent work unit or official not related to the preparation and/or establishment in the context of Risk measurement.
Evaluation is conducted in accordance with business development, internal and external conditions of the BPR that can directly affect the BPR's condition.
Letter b
Included in material changes is the existence of changes in products, BPR service activities, organizational structure, information systems, and quantitative and qualitative Risk factors that significantly affect the BPR's condition.
Paragraph (3)
Letter a
Evaluation of Risk exposure is conducted by an independent work unit or official not related to the preparation and/or establishment of Risk exposure by monitoring and reporting significant Risks or those that impact the BPR's capital condition, which among others is conducted using historical data analysis.
Letter b
Clear enough.
Paragraph (4)
Included in the Risk control process is the addition of capital to absorb potential losses.
Article 11
Paragraph (1)
Letter a
Risk exposure reports or information cover overall quantitative and/or qualitative Risk exposure, details per type of Risk and per type of functional activity.
Letter b
Clear enough.
Letter c
Clear enough.
Letter d
Clear enough.
Paragraph (2)
The meaning of periodically is at least every semester and can be done more frequently if there are operational changes, issuance of new products and/or implementation of new activities.
Article 12
Clear enough.
Article 13
The purpose of a comprehensive internal control system is to ensure:
a. compliance with legislation, policies, and internal BPR regulations; b. the availability of complete, accurate, current, and intact financial and management information;
c. effectiveness and efficiency in operational activities; and
d. the effectiveness of Risk culture in the BPR organization comprehensively.
Article 14
Paragraph (1)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
Clear enough.
Letter d
The meaning of the establishment of reporting lines and clear separation of functions is:
Letter e
Clear enough.
Letter f
Clear enough.
Letter g
Clear enough.
Letter h
The meaning of complete and adequate documentation is documentation of operational procedures, scope and audit findings and the response of BPR managers to audit results.
Letter i
Verification and review of the internal control system including handling of significant BPR weaknesses and actions by BPR managers to correct deviations that occur.
Paragraph (2)
Clear enough.
Article 15
Paragraph (1)
Letter a
The Risk Management Committee is a non-structural unit with membership that can be permanent or non-permanent in accordance with BPR policy.
Letter b
The Risk Management work unit is a structural work unit.
Paragraph (2)
The Risk Management work unit and compliance work unit can be combined into one, namely a work unit handling Risk Management and Compliance.
Paragraph (3)
The Executive Official appointed to carry out the Risk Management function can concurrently serve as the Executive Official handling the compliance function.
Paragraph (4)
BPR may consider forming a Risk Management Committee if necessary.
Article 16
Paragraph (1)
Letter a
The meaning of majority of the Board of Directors is more than 50% (fifty percent) of the total number of Board of Directors members.
Board of Directors members in the Risk Management Committee do not include the President Director and consist of at least Board of Directors members who oversee the compliance function.
Letter b
The relevant Executive Official is a BPR official one level below the Board of Directors who leads the operational work unit and the Risk Management work unit. The membership of Executive Officials in the Risk Management Committee is adjusted to the problems and needs of the BPR.
Paragraph (2)
Clear enough.
Article 17
Paragraph (1)
The meaning of independent is the Risk Management work unit or Executive Official appointed responsible for implementing the Risk Management function does not handle the function of collecting and disbursing funds and does not carry out the internal audit function.
Paragraph (2)
Clear enough.
Paragraph (3)
The authority and responsibility of the work unit or Executive Official handling the Risk Management function is adjusted to the complexity of the BPR's business activities.
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
The study of proposals for new products and/or activities aims to assess the BPR's ability to issue new products and/or activities including the study of system and procedure changes due to the issuance of new products and/or activities.
Letter d
The meaning of operational work unit is the work unit or employee handling credit provision, fund collection, and other operational activities.
Recommendations include the size or maximum Risk exposure that the BPR must maintain.
Recommendations are submitted to the Risk Management Committee if in accordance with BPR regulations it is required to have a Risk Management Committee or a BPR that has a Risk Management Committee.
Letter e
Risk Profile is a comprehensive overview of the magnitude of potential Risk inherent in the entire portfolio or BPR exposure.
Periodic submission of reports is adjusted to the BPR's condition and is conducted at least every semester.
Risk profile reports are submitted to the Risk Management Committee if in accordance with BPR regulations it is required to have a Risk Management Committee or a BPR that has a Risk Management Committee.
Article 18
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
Policies and procedures related to legal aspect analysis including the ability to provide information regarding compliance with legislation and legal weaknesses caused by new products and activities.
Letter d
Clear enough.
Letter e
Policies and procedures regarding accounting information systems including the system's ability to provide information regarding profit or loss levels for new products and activities.
Letter f
The trial period is intended to ensure that Risk measurement and monitoring methods have been tested from a prudence aspect and other aspects.
Paragraph (4)
Clear enough.
Article 19
Clear enough.
Article 20
Clear enough.
Article 21
Paragraph (1)
The first semester is January 1 to June 30 and the second semester is July 1 to December 31.
Paragraph (2)
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Clear enough.
Article 22
Paragraph (1)
The first semester is January 1 to June 30 and the second semester is July 1 to December 31.
Paragraph (2)
Risk profile reports are submitted by the Risk Management work unit or Executive Official appointed responsible for implementing the Risk Management function to the Risk Management Committee if in accordance with BPR regulations it is required to have a Risk Management Committee or a BPR that has a Risk Management Committee.
Risk profile reports submitted by the BPR to the Financial Services Authority are based on complete, accurate, current, and intact data and information.
Paragraph (3)
Clear enough.
Paragraph (4)
Clear enough.
Paragraph (5)
Clear enough.
Paragraph (6)
Clear enough.
Article 23
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Clear enough.
Paragraph (5)
Clear enough.
Paragraph (6)
Letter a
Clear enough.
Letter b
The meaning of potentially causing significant losses to the BPR's financial condition, among others, having significant risk exposure differences.
Letter c
Clear enough.
Article 24
Paragraph (1)
The meaning of conditions potentially causing significant losses to the BPR's financial condition is conditions that have the potential to reduce profits, cause losses, or reduce the BPR's capital ratio.
Paragraph (2)
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Clear enough.
Article 25
Clear enough.
Article 26
Clear enough.
Article 27
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
The submission of data and information related to the implementation of Risk Management is conducted by the BPR upon request of the Financial Services Authority.
Paragraph (4)
Clear enough.
Article 28
Monthly reports are monthly reports submitted by the BPR including monthly reports after correction of the results of the Financial Services Authority examination.
Article 29
Monthly reports are monthly reports submitted by the BPR including monthly reports after correction of the results of the Financial Services Authority examination.
Article 30
Monthly reports are monthly reports submitted by the BPR including monthly reports after correction of the results of the Financial Services Authority examination.
Article 31
Monthly reports are monthly reports submitted by the BPR including monthly reports after correction of the results of the Financial Services Authority examination.
Article 32
Monthly reports are monthly reports submitted by the BPR including monthly reports after correction of the results of the Financial Services Authority examination.
Article 33
Clear enough.
Article 34
Clear enough.
Article 35
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
The listing of BPR managers in the list of parties receiving the failed predicate is implemented through a competence and suitability test process in accordance with Financial Services Authority regulations regarding competence and suitability tests.
Article 36
Paragraph (1)
Clear enough.
Paragraph (2)
Letter a
Clear enough.
Letter b
The listing of BPR managers in the list of parties receiving the failed predicate is implemented through a competence and suitability test process in accordance with Financial Services Authority regulations regarding competence and suitability tests.
Paragraph (3)
Clear enough.
Article 37
Clear enough.
Article 38
Clear enough.
Article 39
Clear enough.
Article 40
Clear enough.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 5761
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.