2016-03-22 | 18/POJK.03/2016Added
This regulation mandates commercial banks to implement effective risk management covering credit, market, liquidity, operational, legal, reputation, strategic, and compliance risks at both individual and consolidated levels. It establishes specific governance responsibilities for the Board of Directors and Board of Commissioners, requires the formation of a Risk Management Committee and an independent Risk Management Unit, and imposes strict reporting obligations including quarterly risk profile reports and new product/activity notifications to the Financial Services Authority.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
BY THE GRACE OF GOD ALMIGHTY,
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering: a. that the external and internal banking environment situation is experiencing rapid development which will be followed by increasing complexity of risks for banking business activities; b. that the increasing complexity of risks for banking business activities will increase the need for good governance practices as well as the functions of identification, measurement, monitoring, and control of bank risks;
c. that the enhancement of the functions of identification, measurement, monitoring, and control of risks mentioned above is intended so that business activities carried out by banks do not cause losses exceeding the bank's capacity or which could disrupt the continuity of the bank's business;
d. that the management of each functional activity of the bank should be integrated as much as possible into an accurate and comprehensive risk management system and process; e. that in order to create preconditions and infrastructure for risk management, banks are required to take preparatory steps for the implementation of their risk management; f. that transparency is one of the aspects that need to be considered in the control of risks faced by banks; g. that the improvement of the quality of risk management implementation will support the effectiveness of the risk-based supervision framework of banks; h. that based on considerations as referred to in letters a, b, c, d, e, f, and g, it is necessary to establish a Financial Services Authority Regulation concerning the Implementation of Risk Management for Commercial Banks;
Recalling:
DECIDING:
To Establish: A FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE IMPLEMENTATION OF RISK MANAGEMENT FOR COMMERCIAL BANKS.
In this Financial Services Authority Regulation, the following terms are defined:
(1) Banks are required to implement Risk Management effectively, both for the Bank individually and for the Bank on a consolidated basis with Subsidiary Companies. (2) The implementation of Risk Management as referred to in paragraph (1) must at least cover:
a. active supervision by the Board of Directors and Board of Commissioners; b. adequacy of Risk Management policies and procedures as well as the establishment of Risk limits;
c. adequacy of the risk identification, measurement, monitoring, and control processes, as well as the Risk Management information system; and
d. a comprehensive internal control system.
The implementation of Risk Management as referred to in Article 2 must be adjusted to the objectives, business policies, size and complexity of business, and the Bank's capabilities.
(1) Risks as referred to in Article 2 include:
a. Credit Risk; b. Market Risk;
c. Liquidity Risk;
d. Operational Risk; e. Legal Risk; f. Reputation Risk; g. Strategic Risk; and h. Compliance Risk.
(2) Banks are required to implement Risk Management for all Risks as referred to in paragraph (1).
General
Banks are required to establish clear authority and responsibility at every level of position related to the implementation of Risk Management as referred to in Article 2.
Authority and Responsibility of the Board of Directors
(1) Authority and responsibility as referred to in Article 5 for the Board of Directors must at least:
a. formulate written and comprehensive Risk Management policies and strategies; b. be responsible for the implementation of Risk Management policies and the Risk exposure taken by the Bank as a whole;
c. evaluate and decide on transactions requiring Board of Directors approval;
d. develop a Risk Management culture at all organizational levels; e. ensure the improvement of competence of human resources related to Risk Management; f. ensure that the Risk Management function operates independently; and g. conduct periodic reviews to ensure:
1. accuracy of Risk assessment methodologies;
2. adequacy of Risk Management information system implementation; and
3. appropriateness of Risk Management policies and procedures as well as the establishment of Risk limits.
(2) In order to carry out the authority and responsibility as referred to in paragraph (1), the Board of Directors must have adequate understanding of the Risks inherent in all functional activities of the Bank and be able to take necessary actions according to the Bank's Risk profile.
Authority and Responsibility of the Board of Commissioners
Authority and responsibility as referred to in Article 5 for the Board of Commissioners must at least:
a. approve and evaluate Risk Management policies; b. evaluate the accountability of the Board of Directors regarding the implementation of Risk Management policies as referred to in letter a; and
c. evaluate and decide on requests from the Board of Directors related to transactions requiring Board of Commissioners approval.
Risk Management Policies
Risk Management policies as referred to in Article 2 paragraph (2) letter b must at least contain:
a. determination of Risks related to banking products and transactions; b. determination of the use of measurement methods and Risk Management information systems;
c. determination of limits and establishment of Risk tolerance;
d. determination of Risk rating assessments; e. preparation of contingency plans in worst-case scenarios; and f. determination of the internal control system in the implementation of Risk Management.
Risk Management Procedures and Establishment of Risk Limits
(1) Risk Management procedures and the establishment of Risk limits as referred to in Article 2 paragraph (2) letter b must be adjusted to the level of Risk to be taken (risk appetite) against the Bank's Risks. (2) Risk Management procedures and the establishment of Risk limits as referred to in paragraph (1) must at least contain:
a. clear accountability and levels of delegation of authority; b. periodic review of Risk Management procedures and the establishment of Risk limits; and
c. adequate documentation of Risk Management procedures and the establishment of Risk limits.
(3) The establishment of Risk limits as referred to in paragraph (2) must cover:
a. aggregate limits; b. limits per type of Risk; and
c. limits per specific functional activities having Risk exposure.
General
(1) Banks are required to carry out the risk identification, measurement, monitoring, and control processes as referred to in Article 2 paragraph (2) letter c regarding material risk factors. (2) The implementation of the risk identification, measurement, monitoring, and control processes as referred to in paragraph (1) must be supported by:
a. timely management information systems; and b. accurate and informative reports regarding financial conditions, performance of functional activities, and the Bank's Risk exposure.
Risk Identification, Measurement, Monitoring, and Control Processes
(1) In order to carry out the Risk identification process, Banks are required to conduct analysis at least on:
a. characteristics of Risks inherent in the Bank; and b. Risks from the Bank's products and business activities.
(2) In order to carry out the Risk measurement process, Banks are required to at least:
a. periodically evaluate the suitability of assumptions, data sources, and procedures used to measure Risk; and b. improve the Risk measurement system in case of changes in the Bank's business activities, products, transactions, and material Risk factors. (3) In order to carry out the Risk monitoring process, Banks are required to at least:
a. evaluate Risk exposure; and b. improve the reporting process in case of changes in business activities, products, transactions, Risk factors, information technology, and the Bank's Risk Management information systems that are material. (4) Banks are required to carry out Risk control processes to manage specific Risks that may endanger the continuity of the Bank's business. (5) In carrying out the functions of interest rate Risk, exchange rate Risk, and Liquidity Risk control as referred to in Article 4 paragraph (1) letters b and c, Banks must at least apply Assets and Liabilities Management (ALMA).
Risk Management Information Systems
(1) Risk Management information systems as referred to in Article 2 paragraph (2) letter c must cover reports or information at least regarding:
a. Risk exposure; b. compliance with Risk Management policies and procedures as well as the establishment of Risk limits as referred to in Article 8 and Article 9; and
c. realization of Risk Management implementation compared to established targets.
(2) Reports or information generated from Risk Management information systems as referred to in paragraph (1) must be submitted regularly to the Board of Directors.
General
Banks are required to implement an internal control system effectively regarding the implementation of business activities and operations at all levels of the Bank's organization.
(1) The implementation of the internal control system as referred to in Article 13 must at least be able to detect weaknesses and deviations that occur in a timely manner. (2) The internal control system as referred to in paragraph (1) must ensure:
a. compliance with laws and regulations as well as Bank policies or internal provisions; b. the availability of complete, accurate, useful, and timely financial and management information;
c. effectiveness and efficiency in operational activities; and
d. the effectiveness of Risk culture within the entire Bank organization.
Internal Control System in the Implementation of Risk Management
(1) The internal control system in the implementation of Risk Management as referred to in Article 2 paragraph (2) letter d must at least cover:
a. the suitability of the internal control system with the type and level of Risks inherent in the Bank's business activities; b. the establishment of authority and responsibility for monitoring compliance with Risk Management policies and procedures as well as the establishment of Risk limits as referred to in Article 8 and Article 9;
c. the establishment of clear reporting lines and separation of functions from operational work units to work units carrying out control functions;
d. an organizational structure that clearly depicts the Bank's business activities; e. accurate and timely financial and operational activity reporting; f. adequacy of procedures to ensure the Bank's compliance with provisions and laws; g. effective, independent, and objective review of procedures for assessing the Bank's operational activities; h. adequate testing and review of Risk Management information systems;
i. complete and adequate documentation of operational procedures, scope, audit findings, and responses from the Bank's management based on audit results; and
j. periodic and continuous verification and review of the handling of material Bank weaknesses and management actions to correct deviations that occurred. (2) Assessment of the internal control system in the implementation of Risk Management as referred to in paragraph (1) must be conducted by the internal audit work unit.
General
In order to carry out effective Risk Management processes and systems as referred to in Article 2, Banks are required to form:
a. a Risk Management Committee; and b. a Risk Management Work Unit.
Risk Management Committee
(1) The Risk Management Committee as referred to in Article 16 letter a must consist at least of:
a. a majority of the Board of Directors; and b. relevant executive officials.
(2) The authority and responsibility of the Risk Management Committee as referred to in paragraph (1) is to provide recommendations to the Chief Director, which must at least cover:
a. formulation of policies, strategies, and guidelines for the implementation of Risk Management; b. improvement or refinement of Risk Management implementation based on evaluation results of Risk Management implementation; and
c. determination of matters related to business decisions that deviate from normal procedures.
Risk Management Work Unit
(1) The organizational structure of the Bank's Risk Management Work Unit as referred to in Article 16 letter b must be adjusted to the size and complexity of the Bank's business and the Risks inherent in the Bank. (2) The Risk Management Work Unit as referred to in paragraph (1) must be independent from operational work units (risk-taking units) and from work units carrying out internal control functions. (3) The Risk Management Work Unit as referred to in paragraph (2) is directly responsible to the Chief Director or to a Director assigned specifically for this purpose. (4) The authority and responsibility of the Risk Management Work Unit includes:
a. monitoring the implementation of Risk Management strategies approved by the Board of Directors; b. monitoring composite Risk positions, per type of Risk, and per type of functional activity, and conducting stress testing;
c. periodic review of Risk Management processes;
d. assessment of proposals for new activities and/or products; e. evaluation of model accuracy and data validity used to measure Risk, for Banks using models for internal purposes (internal model); f. providing recommendations to operational work units (risk-taking units) and/or to the Risk Management Committee, according to the authority held; and g. preparing and submitting Risk profile reports to the Chief Director or Director assigned specifically for this purpose and the Risk Management Committee on a periodic basis.
Relationship Between Operational Work Units and Risk Management Work Units
Operational work units (risk-taking units) as referred to in Article 18 paragraph (2) are required to inform the Risk Management Work Unit periodically about the Risks inherent in the respective work units.
(1) Banks are required to have written policies and procedures to manage Risks inherent in new Bank products or activities.
(2) Policies and procedures as referred to in paragraph (1) must at least cover:
a. systems and procedures (standard operating procedures) and authority in the management of new products and activities; b. identification of all Risks inherent in new products or activities, both those related to the Bank and customers;
c. trial period for Risk measurement and monitoring methods for new products and activities;
d. accounting information systems for new products and activities; e. legal aspect analysis for new products and activities; and f. transparency of information to customers. (3) A Bank product or activity is considered a new product or new activity if it meets the criteria:
a. has never been issued or conducted previously by the Bank; or b. has been issued or implemented previously by the Bank but undergoes development that changes or increases specific Risk exposures to the Bank.
Banks are prohibited from assigning or approving Bank management and/or employees to market products or carry out activities that are not Bank products or activities using Bank facilities or instruments.
Banks are required to apply transparency of Bank product or activity information to customers as referred to in Article 20 paragraph (2) letter f, both in writing and orally.
Risk Profile Reports and New Product and Activity Reports
(1) Banks are required to submit Risk profile reports to the Financial Services Authority.
(2) The Risk profile report as referred to in paragraph (1) submitted by the Risk Management Work Unit must contain the same substance as the Risk profile report submitted by the Risk Management Work Unit to the Chief Director and the Risk Management Committee. (3) The Risk profile report as referred to in paragraph (1) is submitted quarterly for the positions in March, June, September, and December. (4) The Risk profile report as referred to in paragraph (1) is submitted no later than 15 (fifteen) working days after the end of the reporting month. (5) If necessary, the Financial Services Authority may request Banks to submit Risk profile reports as referred to in paragraph (1) outside the timeframes established as referred to in paragraph (3).
(1) Banks are required to submit reports on new products or activities to the Financial Services Authority, consisting of:
a. Reports on the plan to issue new products or carry out new activities; and b. Reports on the realization of issuing new products or carrying out new activities.
(2) The plan report referred to in paragraph (1) letter a must be submitted at the latest 60 (sixty) days before the issuance or implementation of new products or activities. (3) The realization report referred to in paragraph (1) letter b must be submitted at the latest 7 (seven) working days after the new product or activity is carried out. (4) In addition to fulfilling the reporting provisions referred to in paragraph (1), the plan to issue products or carry out new activities that meet the criteria in Article 20 paragraph (3) letter a must be included in the Bank's business plan. (5) Based on the evaluation results of the report referred to in paragraph (1) letter a, the Financial Services Authority may prohibit the Bank from issuing products or carrying out new activities as planned. (6) In the event that subsequently, based on the Financial Services Authority's evaluation, the issued product or carried out activity meets the conditions:
a. does not match the plan for issuing products or new activities reported to the Financial Services Authority; b. has the potential to cause significant losses to the Bank's financial condition; and/or
c. does not comply with regulations,
the Financial Services Authority may order the Bank to stop the issued product or carried out activity.
(7) Reports on plans and realization regarding the issuance of products or implementation of certain activities are regulated separately in a Circular Letter of the Financial Services Authority.
Part Two
Other Reports
Article 25
(1) Banks are required to submit other reports to the Financial Services Authority besides those referred to in Article 23, in the event of conditions that have the potential to cause significant losses to the Bank's financial condition. (2) Banks are required to submit to the Financial Services Authority other reports related to the implementation of Risk Management and/or related to the issuance of products or implementation of certain activities periodically or at any time when necessary. (3) The format and reporting procedures referred to in paragraph (2) are regulated separately in a Circular Letter of the Financial Services Authority.
Part Three
Reporting Deadlines
Article 26
A Bank is considered late in submitting reports referred to in Article 23 and Article 24 if the reports are submitted beyond the submission deadline.
Part Four
Submission Address
Article 27
Reports referred to in Article 23, Article 24, and Article 25 are submitted to the Financial Services Authority at the following addresses:
a. The Department of Supervision of the relevant Bank, for Banks with headquarters or branches of banks located outside the country situated in the Special Capital Region of Jakarta; or
b. The Regional Office of the Financial Services Authority or the Local Office of the Financial Services Authority according to the area where the Bank's headquarters is located.
CHAPTER X
OTHER PROVISIONS
Part One
Assessment of Risk Management Implementation
Article 28
The Financial Services Authority may conduct assessments regarding the implementation of Risk Management at Banks.
Article 29
Banks are required to provide data and information related to the implementation of Risk Management to the Financial Services Authority.
Part Two
Aspects of Performance Disclosure and Risk Management Policy
Article 30
(1) Banks are required to disclose Risk Management in the Bank's annual publication report.
(2) The disclosure referred to in paragraph (1) must at least cover Risk Management performance and the direction of Risk Management policy.
CHAPTER XI
SANCTIONS
Article 31
(1) Banks that are late in submitting reports referred to in Article 23 paragraph (1), Article 24 paragraph (1) letter b, Article 24 paragraph (3), Article 24 paragraph (7), or Article 25 paragraph (2) shall be subject to administrative sanctions in the form of a fine of Rp1,000,000.00 (one million rupiah) per day of delay per report. (2) Banks that have not submitted reports referred to in Article 23 paragraph (1), Article 24 paragraph (1) letter b, Article 24 paragraph (3), Article 24 paragraph (7), or Article 25 paragraph (2) after 1 (one) month from the final deadline for report submission shall be subject to administrative sanctions in the form of a fine of Rp50,000,000.00 (fifty million rupiah) per report. (3) Banks that have not submitted reports referred to in Article 23 paragraph (1), Article 24 paragraph (1) letter b, Article 24 paragraph (3), Article 24 paragraph (7), or Article 25 paragraph (2) and have been subject to administrative sanctions in the form of a fine as referred to in paragraph (2) remain obligated to submit reports to the Financial Services Authority. (4) Banks that do not submit plan reports referred to in Article 24 paragraph (1) letter a shall be subject to administrative sanctions in the form of a fine of Rp100,000,000.00 (one hundred million rupiah). (5) Banks that submit reports referred to in Article 23 paragraph (1), Article 24 paragraph (1) letter b, Article 24 paragraph (3), Article 24 paragraph (7), or Article 25 paragraph (2), but:
a. are assessed as significantly incomplete; and/or b. are not accompanied by material documents and information, according to the determined format, shall be subject to administrative sanctions in the form of a fine of Rp50,000,000.00 (fifty million rupiah).
(6) Banks are subject to sanctions as referred to in paragraph (5) after:
a. The Bank is given 2 (two) warning letters by the Financial Services Authority with a grace period of 7 (seven) working days for each warning letter; and b. The Bank does not correct the report within a period of at the latest 7 (seven) working days after the last warning letter.
Article 32
Banks that do not implement the provisions as stipulated in Article 2 paragraph (1), Article 3, Article 4 paragraph (2), Article 5, Article 9 paragraph (1), Article 9 paragraph (3), Article 10, Article 11 paragraph (1), Article 11 paragraph (2), Article 11 paragraph (3), Article 11 paragraph (4), Article 12 paragraph (2), Article 13, Article 14 paragraph (2), Article 15 paragraph (2), Article 16, Article 19, Article 20 paragraph (1), Article 21, Article 22, Article 29, or Article 30 paragraph (1) of this Financial Services Authority Regulation and other related implementation provisions may be subject to administrative sanctions in the form of:
a. written reprimand; b. downgrade of the Bank's health level;
c. suspension of certain business activities;
d. inclusion of board members, Bank employees, and/or shareholders in the list of parties receiving the "Unfit" designation in the assessment of competence and propriety or in the administrative records of the Financial Services Authority as regulated in Financial Services Authority provisions; and/or e. dismissal of Bank board members.
CHAPTER XII
CLOSING PROVISIONS
Article 33
Further provisions regarding the implementation of Risk Management for Commercial Banks are regulated in a Circular Letter of the Financial Services Authority.
Article 34
(1) At the time this Financial Services Authority Regulation comes into force:
a. Bank Indonesia Regulation Number 5/8/PBI/2003 dated 19 May 2003 concerning the Implementation of Risk Management for Commercial Banks (State Gazette of the Republic of Indonesia Year 2003 Number 56, Supplement to the State Gazette of the Republic of Indonesia Number 4292); and b. Bank Indonesia Regulation Number 11/25/PBI/2009 dated 1 July 2009 concerning Amendments to Bank Indonesia Regulation Number 5/8/PBI/2003 concerning the Implementation of Risk Management for Commercial Banks (State Gazette of the Republic of Indonesia Year 2009 Number 103, Supplement to the State Gazette of the Republic of Indonesia Number 5029), are revoked and declared invalid. (2) Implementation regulations of Bank Indonesia Regulation Number 5/8/PBI/2003 dated 19 May 2003 concerning the Implementation of Risk Management for Commercial Banks and Bank Indonesia Regulation Number 11/25/PBI/2009 dated 1 July 2009 concerning Amendments to Bank Indonesia Regulation Number 5/8/PBI/2003 concerning the Implementation of Risk Management for Commercial Banks are declared to remain in force insofar as they do not conflict with this Financial Services Authority Regulation.
(3) With the coming into force of this Financial Services Authority Regulation, regulations that previously referred to Bank Indonesia provisions regarding the implementation of Risk Management for commercial banks become referred to this Financial Services Authority Regulation.
Article 35
This Financial Services Authority Regulation comes into force on the date of its promulgation.
To ensure that everyone knows it, it is ordered to promulgate this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia. Determined in Jakarta on 16 March 2016 CHAIRMAN OF THE COMMISSIONERS BOARD FINANCIAL SERVICES AUTHORITY, ttd MULIAMAN D. HADAD Promulgated in Jakarta on 22 March 2016 MINISTER OF LAW AND HUMAN RIGHTS REPUBLIC OF INDONESIA, ttd YASONNA H. LAOLY STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2016 NUMBER 53 Copy in accordance with the original Legal Director 1 Department of Law ttd Yuliana
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 18 /POJK.03/2016
CONCERNING
THE IMPLEMENTATION OF RISK MANAGEMENT FOR COMMERCIAL BANKS
I. GENERAL
Bank business activities are constantly faced with risks closely related to their function as financial intermediation institutions. The rapid development of the external and internal banking environment also causes the risks of banking business activities to become increasingly complex. Therefore, to be able to adapt in the banking business environment, Banks are required to implement Risk Management. In this regard, the principles of Risk Management to be adopted and applied in Indonesian banking are directed in line with recommendations issued by the Bank for International Settlements through the Basel Committee on Banking Supervision. These principles are essentially standards for the banking world to be able to operate more cautiously in the scope of the very rapid development of business activities and banking operations today. Through the implementation of Risk Management, Banks are expected to be able to measure and control the Risks faced in conducting their business activities better. Furthermore, the implementation of Risk Management by banks will support the effectiveness of the Risk-based supervision framework conducted by the Financial Services Authority. The effort to implement Risk Management is not only directed for the benefit of Banks but also for the benefit of customers. One important aspect in protecting customer interests and in the context of Risk control is the transparency of information related to Bank products or activities. The implementation of Risk Management can vary between one Bank and another Bank according to the purpose, business policy, size and complexity of business, financial capacity, supporting infrastructure, and human resource capabilities. The Financial Services Authority establishes these provisions as minimum standards that must be met by Indonesian banks in implementing Risk Management. With these provisions, Banks are expected to be able to carry out all their activities in an integrated manner within an accurate and comprehensive Risk management system.
II. ARTICLE BY ARTICLE
Article 1
It is clear enough.
Article 2
Paragraph (1)
Included in the scope of Risk Management implementation is the implementation of the Anti-Money Laundering and Counter-Terrorism Financing program. Paragraph (2) It is clear enough.
Article 3
Business complexity includes, among others, diversity in the types of transactions, products or services, and business networks.
Bank capabilities include, among others, financial capacity, supporting infrastructure, and human resource capabilities.
Article 4
Paragraph (1)
Letter a
Included in the Credit Risk group are Credit concentration risk, counterparty credit risk, and settlement risk.
Credit concentration risk is a Risk that arises due to the concentration of fund provision to 1 (one) party or a group of parties, industries, sectors, and/or specific geographic areas that has the potential to cause considerable losses that can threaten the continuity of the Bank's business. Counterparty credit risk is a Risk that arises due to the failure of the counterparty to fulfill its obligations and arises from transaction types that have certain characteristics, for example, transactions influenced by fair value or market value movements. Settlement risk is a Risk that arises due to the failure to deliver cash and/or financial instruments on the agreed settlement date from the sale and/or purchase transactions of financial instruments. Letter b Market Risk includes, among others, Interest Rate Risk, Exchange Rate Risk, Commodity Risk, and Equity Risk. What is meant by "Interest Rate Risk" is Risk due to changes in the price of financial instruments from the trading book position or due to changes in the economic value of the banking book position, caused by interest rate changes. In the Interest Rate Risk category, it also includes Interest Rate Risk from the banking book position which among others includes repricing risk, yield curve risk, basis risk, and optionality risk. What is meant by "Exchange Rate Risk" is Risk due to changes in the value of the trading book and banking book positions caused by changes in foreign currency exchange rates or changes in gold prices. What is meant by "Commodity Risk" is Risk due to changes in the price of financial instruments from the trading book and banking book positions caused by changes in commodity prices. What is meant by "Equity Risk" is Risk due to changes in the price of financial instruments from the trading book position caused by changes in stock prices. Letter c It is clear enough. Letter d It is clear enough. Letter e Legal Risk arises, among others, due to the absence of supporting legislation or weaknesses in agreements such as the non-fulfillment of contract validity requirements or imperfect collateral binding. Letter f Reputational Risk arises, among others, due to negative media coverage and/or rumors regarding the Bank, and the Bank's ineffective communication strategy. Letter g Strategic Risk arises, among others, because the Bank sets strategies that are not in line with the Bank's vision and mission, conducts non-comprehensive strategic environment analysis, and/or there is a mismatch of strategic plans (strategic plan) between strategic levels. In addition, Strategic Risk also arises due to failures in anticipating changes in the business environment, including failures in anticipating changes in technology, changes in macroeconomic conditions, dynamics of competition in the market, and changes in relevant authority policies.
Letter h
It is clear enough.
Paragraph (2)
It is clear enough.
Article 5
It is clear enough.
Article 6
Paragraph (1)
Letter a
Included in Risk Management policy and strategy is the establishment and approval of Risk limits, both overall Risk (composite), per type of Risk, and per functional activity. Risk Management policy and strategy are prepared at least 1 (one) time in 1 (one) year or at a higher frequency in the event of changes in factors significantly affecting the Bank's business activities. Letter b Included in the responsibility for the implementation of Risk Management policy are:
Letter e
Increasing human resource competence includes, among others, through continuous education and training programs regarding the implementation of Risk Management. Letter f What is meant by independent includes, among others, the separation of functions between the Risk Management work unit that identifies, measures, and monitors Risk and the work unit that conducts and completes transactions. Letter g Periodic review is intended, among others, to anticipate if there are changes in external and internal factors. Paragraph (2) It is clear enough.
Article 7
Letter a
Evaluation of Risk Management policy is conducted by the Board of Commissioners at least 1 (one) time in 1 (one) year or at a higher frequency in the event of changes in factors significantly affecting the Bank's business activities. Letter b Evaluation of the Board of Directors' accountability for the implementation of Risk Management policy is conducted by the Board of Commissioners at least quarterly. Letter c What is meant by "transactions requiring Board of Commissioners approval" are transactions that have exceeded the Board of Directors' authority to decide on transactions, in accordance with the Bank's internal policies and procedures in force.
Article 8
Risk Management policy is established, among others, by formulating Risk Management strategy to ensure that:
a. The Bank continues to maintain Risk exposure in accordance with internal Bank policies and procedures and legislation and other provisions; and b. The Bank is managed by human resources who have knowledge, experience, and expertise in Risk Management according to the complexity of the Bank's business. The formulation of Risk Management strategy is done by considering the Bank's financial condition, Bank organization, and Risks arising as a result of changes in external and internal factors. Letter a It is clear enough. Letter b It is clear enough. Letter c Risk Tolerance is the potential loss that can be absorbed by the Bank's capital. Letter d The establishment of Risk rating assessment is the basis for the Bank to categorize the Bank's Risk rating. Risk ratings for Banks are categorized into 5 (five) ratings, namely:
Article 9
Paragraph (1)
The level of Risk to be taken (risk appetite) takes into account the experience owned by the Bank in managing Risk.
Paragraph (2)
Letter a
It is clear enough.
Letter b
The definition of periodically is at least 1 (one) time in 1 (one) year or at a higher frequency, according to the type of Risk, needs, and Bank development. Letter c What is meant by "adequate documentation" is written, complete documentation that facilitates the conduct of an audit trail for the Bank's internal control purposes. Paragraph (3) It is clear enough.
Article 10
Paragraph (1)
What is meant by "Risk factors" are various parameters that affect Risk exposure.
What is meant by "material Risk factors (risk factors)" are Risk factors, both quantitative and qualitative, that significantly affect the Bank's financial condition. Paragraph (2) It is clear enough.
Article 11
Paragraph (1)
The Risk identification process can, among others, be based on the Bank's past loss experience.
Paragraph (2)
To estimate Risk, Banks can use various approaches, both qualitative and quantitative, adjusted to business objectives, business complexity, and Bank capabilities. Letter a The definition of periodically is at least quarterly or at a higher frequency, according to Bank business development and external conditions that directly affect the Bank's condition. Letter b What is meant by "material changes" are changes in the Bank's business activities, products, transactions, and/or Risk factors, which can affect the Bank's financial condition. Paragraph (3) Letter a Evaluation of Risk exposure is conducted by monitoring and reporting Material Risks or those impacting the Bank's capital condition, which among others is based on the assessment of potential Risk using historical trends. Letter b It is clear enough. Paragraph (4) Risk control can be conducted, among others, by hedging, Risk mitigation methods, and capital addition to absorb potential losses. Paragraph (5) It is clear enough.
Article 12
Paragraph (1)
Letter a
Risk exposure reports or information include quantitative and qualitative exposure, overall (composite) as well as details per type of Risk and per type of functional activity. Letter b It is clear enough. Letter c It is clear enough. Paragraph (2) Reports or information submitted to the Board of Directors can have their frequency increased according to the Bank's needs.
Article 13
It is clear enough.
Article 14
Paragraph (1)
It is clear enough.
Paragraph (2)
Letter a
It is clear enough.
Letter b
Complete, accurate, useful, and timely financial and management information is needed in order to make appropriate and accountable decisions, and to communicate to interested parties. Letter c Effectiveness and efficiency in operational activities are, among others, needed to protect Bank assets and other resources from related Risks. Letter d The effectiveness of Risk culture (risk culture) is intended to identify weaknesses and deviations earlier and to continuously reassess the fairness of existing Bank policies and procedures.
Article 15
It is clear enough.
Article 16
Letter a
The Risk Management Committee must be non-structural.
Letter b
The Risk Management work unit must be structural.
Article 17
Paragraph (1)
Membership of the Risk Management Committee can be permanent and non-permanent, according to the Bank's needs.
Letter a
One member from the majority of the Board of Directors in the Risk Management Committee is the director who oversees the compliance function.
Letter b
What is meant by "executive officials" are officials who are directly responsible to the Board of Directors or have significant influence on Bank policy or operations. Paragraph (2) Letter a It is clear enough. Letter b It is clear enough. Letter c Included in business decisions that deviate from normal procedures include, among others, significant expansion of business beyond the Bank's business plan and taking positions or Risk exposures that deviate from established limits.
Article 18
Paragraph (1)
This regulation is intended so that Banks can determine the appropriate organizational structure suitable for the Bank's condition, including financial capacity and human resources. Paragraph (2) The definition of independent is reflected, among others, by the existence of:
a. separation of functions and tasks between the Risk Management work unit and the operational work unit (risk-taking unit) and the work unit carrying out internal control functions; and b. a decision-making process that is impartial or does not favor certain operational work units or ignores other operational work units. Paragraph (3) Given the different sizes and complexities of Bank businesses, the Risk Management work unit can report directly to a director specifically assigned by the Bank, such as a director who oversees the compliance function or a Risk Management director. The term Chief Director can be equated with President Director. Paragraph (4) The authority and responsibility of the Risk Management work unit are adjusted to business objectives, business complexity, and Bank capabilities. Letter a It is clear enough. Letter b Stress testing is conducted to determine the impact of the implementation of Risk Management policies and strategies on the performance and income of each operational work unit or functional activity of the Bank. Letter c Review is conducted, among others, based on internal audit findings and/or the development of internationally applicable Risk Management practices.
Letter d
Included in the assessment is the evaluation of the Bank's ability to conduct new activities and/or products and the study of proposed system and procedure changes.
Letter e
Clear enough.
Letter f
Recommendations include, among others, recommendations related to the magnitude or maximum exposure of Risk that must be maintained by the Bank.
Letter g
Risk Profile is a comprehensive picture of the magnitude of potential Risk inherent in the Bank's entire portfolio or exposure.
The frequency of report submission is increased in the event of rapid market changes. For exposures that change relatively slowly, such as Credit Risk, reports are submitted at least 1 (one) time in 1 (one) month.
Article 19
The frequency of submitting Risk exposure information is adjusted according to the characteristics of the type of Risk.
Included in the definition of operational work unit (risk-taking unit) includes, among others, credit units, treasury, and funding.
Article 20
Paragraph (1)
What is meant by "Bank product" is a financial instrument issued by the Bank.
What is meant by "Bank activity" is services provided by the Bank to customers, including, among others, agency and/or custodian services.
Paragraph (2)
Letter a
Clear enough.
Letter b
Clear enough.
Letter c
The trial period is intended to ensure that risk measurement and monitoring methods have been tested.
Letter d
Accounting information systems must at least accurately describe the Risk profile and the level of profit or loss for new products or activities.
Letter e
Legal aspect analysis covers the possibility of Legal Risk arising from new products or activities and compliance with laws and regulations.
Letter f
Aspects in applying information transparency to customers consider at least:
Paragraph (3)
Letter a
Included in the criteria of never having been issued or conducted before are products or activities that have been issued or conducted by other Banks but have never been issued or conducted by the Bank in question.
Letter b
Changes in Risk exposure in this regulation do not include changes in Risk exposure related to conventional products or activities such as checking accounts, savings, deposits, loans, plain vanilla derivative products, and custodian activities.
Article 21
Included in the category of approval actions is knowing but not prohibiting or allowing the marketing of products or activities that are not Bank products or activities using Bank facilities or amenities by directors and/or employees.
Article 22
The scope of information transparency to be disclosed to customers refers to regulations governing Bank product information transparency. In addition, information transparency also covers procedures, schemes, and materials that need to be disclosed, such as product or activity characteristics, Risks, and customer rights and obligations.
Article 23
Paragraph (1)
Risk profile reports include, among others, information about the level and trends of all Risk exposures.
Paragraph (2)
Clear enough.
Paragraph (3)
Risk profile reports are presented comparatively with the previous quarter's position.
Paragraph (4)
Clear enough.
Paragraph (5)
Clear enough.
Article 24
Paragraph (1)
Clear enough.
Paragraph (2)
Products or new activities that must be reported include all products or new activities as referred to in Article 20 paragraph (3).
Reports on plans to issue products or implement new activities must at least contain matters established in Article 20 paragraph (2).
Paragraph (3)
Clear enough.
Paragraph (4)
Plans to issue products or implement new activities are included in the Bank's business plan for the same year as the plan to issue products or implement new activities.
Paragraph (5)
Otoritas Jasa Keuangan's evaluation includes, among others, aspects of Bank readiness, implementation of Risk Management, product information transparency, and customer protection.
Paragraph (6)
Letter a
Inconsistencies include, among others, procedures, schemes, product or activity characteristics, Risks, and customer rights and obligations.
Letter b
Conditions that have the potential to cause significant losses to the Bank's financial condition, among others, can be caused by Reputation Risk and Market Risk from the issuance of products or implementation of Bank activities.
Letter c
Clear enough.
Paragraph (7)
Clear enough.
Article 25
Paragraph (1)
Clear enough.
Paragraph (2)
Reports related to the implementation of Risk Management include, among others, cash flow projection reports and maturity profile reports in the implementation of Risk Management for Liquidity Risk.
Reports related to specific activities include, among others, reports on the implementation of mutual fund agency activities and/or reports on the implementation of bancassurance activities.
Paragraph (3)
Clear enough.
Article 26
Clear enough.
Article 27
Clear enough.
Article 28
Assessment of Bank Risk Management includes assessment of inherent risk and adequacy of the risk control system.
Article 29
Clear enough.
Article 30
Paragraph (1)
Clear enough.
Paragraph (2)
Risk Management performance is the result of implementing Risk Management for the initial period of the year (January) to the end of the year (December), including the Risk profile, while Risk Management policy direction is the direction and strategy of Risk Management for the next 1 (one) year.
Article 31
Paragraph (1)
What is meant by "day" is a working day.
Paragraph (2)
Banks that have been subject to administrative sanctions in the form of fines in this paragraph are not subject to late sanctions as referred to in paragraph (1).
Paragraph (3)
Clear enough.
Paragraph (4)
Clear enough.
Paragraph (5)
Banks that have been subject to administrative sanctions in the form of fines in this paragraph are not subject to late sanctions as referred to in paragraph (1).
Paragraph (6)
Clear enough.
Article 32
Clear enough.
Article 33
Clear enough.
Article 34
Clear enough.
Article 35
Clear enough.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 5861
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.