2018-01-01
Added · Updated
The Registrar of Financial Institutions issued this directive to establish comprehensive information management requirements for banks, mandating the adoption of written policies and the identification, protection, and electronic storage of records with business value. Banks must implement supporting methodologies, including classification structures and back-up procedures, while maintaining all relevant information for a minimum of seven years. The directive revokes the 2012 Record Keeping Directive, grants the Registrar unannounced inspection rights, and enforces compliance through monetary penalties of up to K50 million for institutions and K10 million for senior management.
(CAP. 44:05)
| PARAGRAPH | PART I—PRELIMINARY |
|---|---|
| 1. Citation | |
| 2. Interpretation | |
| PART II—OBJECTIVE | |
| 3. Objectives | |
| PART III—RESPONSIBILITY OF THE BOARD AND SENIOR MANAGEMENT | |
| 4. Board and management responsibility | |
| PART IV—OBLIGATIONS OF A BANK | |
| 5. Identification of information resources of business value | |
| 6. Protection of information resources of business value | |
| 7. Record keeping | |
| 8. Supporting methodologies | |
| 9. Back-up |
This Directive may be cited as the Financial Services (Information Management Requirements for Banks) Directive, 2018.
In this Directive unless the context otherwise requires:
The objectives of this Directive are to ensure:
(1) The Board of Directors of a bank shall adopt and ensure implementation by management, of a written policy on information management.
(2) The written policy shall at a minimum:
(3) Senior management of a bank shall ensure that record keeping is an integral part of the bank’s overall information management program.
A bank shall identify and protect its information resources of business value based on an analysis of its departmental functions and activities.
A bank shall protect its information resources of business value.
The records shall be:
A bank shall establish key methodologies, mechanisms and tools to support the bank’s record keeping and these shall include:
A bank shall ensure that appropriate back-up and recovery procedures are in place for all information of business value.
The records referred to in paragraph 7 (a) shall be subject to inspection from time to time and without notice, by the Registrar.
A bank shall preserve the records and information required to be kept under this Directive for a period of at least seven (7) years.
A bank shall develop and implement a documented disposal process for all information resources, and ensure that the disposal process is performed after the retention period.
(1) A bank account shall be classified as a dormant account where there has been no transaction on the bank account for twelve (12) months after the last transaction.
(2) A bank shall, as soon as practicable, transfer a dormant account to a separate register of dormant accounts maintained in the books of the bank and a notice of the transfer shall be given to the depositor at his last known address or through a newspaper of wide circulation.
(3) A bank shall cease to charge service fees or any other form of fees or charges on the dormant account transferred in sub-paragraph (2) immediately from the date of transfer.
The Registrar shall impose the following monetary penalties for violations of this Directive:
In addition to the monetary penalties imposed in paragraph revocation of the Financial Services (Record Keeping Requirements for Banks) Directive, 2012.
The Financial Services (Record Keeping Requirements for Banks) Directive, 2012 is hereby revoked.
**Made this 3rd day of April, 371
FILE NO. FIN/FPSPD/03/04
D. KABAMBE, PhD
Registrar of Financial Institutions
More like this from RBM
We email you every new RBM publication the day it's published.