2019-10-31
Added · Updated
The Swiss Financial Market Supervisory Authority issued Circular 2017/1 to establish comprehensive requirements for corporate governance, risk management, internal controls, and internal audit at banks and financial groups. The regulation mandates that boards of directors define strategy and risk policy while ensuring at least one-third independence, and requires executive boards to implement robust operational risk management and internal control systems. It further specifies the establishment of independent risk control and compliance functions, as well as autonomous internal audit units, with requirements scaled according to the institution's size, complexity, and systemic importance.
Get FINMA alerts — same-day email on every new publication.
Laupenstrasse 27, 3003 Bern
Tel. +41 (0)31 327 91 00, fax +41 (0)31 327 91 01 www.finma.ch Circular 2017/1 Corporate governance – banks Corporate governance, risk management and internal controls at banks Reference: FINMA Circ. 17/1 "Corporate governance – banks" Date: 22 September 2016 Entry into force: 1 July 2017 Last amendment:
Concordance:
4 November 2020 [Modifications are indicated by an asterisk (*) and are listed at the end of the document.] former FINMA Circ. 08/24 "Monitoring and internal control - banks", dated 20 November Legal framework: FINMASA Article 7 para. 1 let. b BA Articles 3 para. 2 lets. a and c, 3b–3f, 4quinquies and 6 BO Articles 11 para. 2 and 12 FinIA Articles 7, 9, 49 FinIO Articles 9, 12, 68 CAO Articles 7–12 Adressees BankA ISA FinIA FMIA CISA AMLA Other Banks Financial groups and congl. Other intermediaries Insurers Insurance groups and congl. Intermediaries Portfolio managers Trustees Managers of collective assets Fund management companies Investment firms (proprietarian trading) Investment firms (non propriet. trading) Trading venues Central counterparties Central securities depositories Trade repositories Payment systems Participants SICAVs Limited partnerships for CISs SICAFs Custodian banks Representatives of foreign CISs Other intermediaries SRO SRO-supervised institutions Audit firms Rating agencies X
Index
2/14
I. Subject matter
II. Terms
III. Scope of application (the principle
of proportionality)
IV. Board of directors
A. Duties and responsibilities
B. Members of top management
C. Basic principles governing a directorship
D. Committees and the division of responsibilities
V. Executive board
A. Duties and responsibilities
B. Requirements to be met by members of the executive board
VI. Risk policy and basic features of institution-wide risk management
VII. Internal control system
A. Revenue-generating units
B. Independent control bodies
VIII. Internal audit
A. Establishment
B. Supervision and organisation
C. Duties and responsibilities
IX. Group structures
X. Transitional provisions
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
Margin no.
2-7
9-46
9-15
16-25
26-29
30-46
47-51
47-50
52-59
60-81
62-81
82-97
82-86
87-90
91-97
98-99
100-105
3/14
Subject matter
This circular sets out the requirements to be met by the corporate governance, risk management, internal control system and internal audit at banks, securities firms, financial groups (Art. 3c para. 1 BA) and financial conglomerates dominated by banking or securities trading (Art. 3c para. 2 BA). These are referred to below as "institutions". Terms Corporate governance is understood to mean the principles and structures on the basis of which an institution is directed and controlled by its governing bodies. Risk management comprises the methods, processes and organisational structures used to define risk strategies and risk management measures in addition to the identification, analysis, assessment, management, monitoring and reporting of risks. Risk tolerance comprises quantitative and qualitative considerations regarding the key risks which an institution is prepared to take to achieve its strategic business objectives in the context of its capital and liquidity planning. Where relevant, risk tolerance is defined per risk category as well as per institution. The risk profile provides an overall picture of the risk positions entered into by an institution at institution level and per risk category at a particular point in time. The internal control system (ICS) comprises the totality of the control structures and processes which at all levels of an institution form the basis for achieving its business objectives and ensuring orderly business operations. The ICS comprises retrospective controls and planning and management elements. An effective ICS consists of control activities which are integrated into work processes, appropriate risk management and compliance processes, and monitoring bodies – particularly an independent risk control and compliance function – which adequately reflect the size, complexity and risk profile of an institution. Compliance is understood to mean abiding by the relevant statutory, regulatory and internal rules and observing generally accepted market standards and codes of conduct. Scope of application (the principle of proportionality) This circular applies to all institutions as defined in margin no. 1. The requirements are to be implemented on a case-by-case basis, giving due consideration to the size, complexity, structure and risk profile of each institution. FINMA can relax or tighten the rules in individual cases.
4/14
1 The head of internal audit can also be selected by the audit committee.
Board of directors
A. Duties and responsibilities
The duties of an institution's board of directors, i.e. the governing body for guidance, supervision and control, comprise in particular:
a) Business strategy and risk policy
The board of directors sets out the business strategy and defines guiding principles for the institution's corporate culture. It signs off the risk policy and the basic features of institution-wide risk management and is responsible for issuing regulations, establishing and monitoring an effective risk management function, and managing overall risks. b) Organisation The board of directors is responsible for establishing an appropriate business organisation and issues the rules and regulations required to achieve this. c) Finances The board of directors bears ultimate responsibility for the financial situation and development of the institution. It approves/signs off the capital and liquidity plans, the annual report, the annual budget, the interim financial statements and the financial objectives for the year. d) Personnel and other resources The board of directors is responsible for ensuring that an institution has appropriate levels of personnel and other resources (e.g. infrastructure, IT) and for the personnel and remuneration policies. It appoints and dismisses the members of its committees, the members of the executive board, the chair of the executive board, the chief risk officer (CRO) and the head of internal audit.1 e) Monitoring and control The board of directors oversees the work of the executive board. It is responsible for ensuring that there is both an appropriate risk and control environment within the institution and an effective ICS. It appoints and monitors the internal audit, commissions the regulatory audit firm and assesses its reports.
5/14 f) Major structural changes and investments The board of directors takes decisions on major changes to the company and group structure, major changes in significant subsidiaries, and other strategically important projects. B. Members of the board of directors a) General prerequisites The board of directors in its totality has adequate management expertise and the prerequisite specialist knowledge and experience of the banking and financial services sector. It is diversified to the extent that all key aspects of the business, including finance, accounting and risk management, are adequately represented. b) Independence At least one third of the board of directors consists of independent members. FINMA may approve exceptions (e.g. for domestic financial groups) where there is good reason for doing so. Members of the board of directors are deemed to be independent if they: 18
6/14
C. Basic principles governing a directorship
All members of the board of directors devote sufficient time to their roles and play an active part in strategic corporate governance. Members must perform their function in person and be permanently prepared to intervene in crisis situations and emergencies besides the normal pattern of meetings. The board of directors defines the requirements profile for its members, its chair, any members of committees, and the chair of the executive board. It approves and periodically assesses the requirements profile for the other members of the executive board, as well as for the CRO and the head of internal audit. It is responsible for succession planning. At least once a year the board of directors, where necessary with the assistance of a third party, critically assesses its own performance (meeting of targets and method of operating) and records the results in writing. The board of directors defines how conflicts of interest are to be handled. All current and previous conflicting interests must be disclosed. If a conflict of interest cannot be avoided, the institution takes appropriate steps to ensure that it is effectively limited or removed. D. Committees and the division of responsibilities a) Role of the chair The chair presides over the board of directors as a whole and represents it internally and externally. That person has a key role in shaping the strategy, communications and culture of the company. b) Committees Institutions in supervisory categories 1 to 3 must establish an audit committee and a risk committee. Institutions in supervisory category 3 may combine these into a single committee. Systemically important institutions must establish, at least at group level, a compensation and nomination committee. The committees are responsible for ensuring appropriate reporting to the board of directors. The personnel composition of the audit committee must differ sufficiently from that of other committees. A majority of the members of the audit and risk committees must be substantially independent (see margin no. 18 ff.). As a matter of principle, the chair of the board of directors must be neither a member of the audit committee nor chair of the risk committee. Each committee as a whole must have sufficient knowledge and experience of the areas for which it is responsible.
7/14 c) Responsibilities of the audit committee These include in particular: 34
8/14
The risk committee receives regular reports from the CRO and other relevant office holders on the respective aspects of the risk policy and the basic features of institution-wide risk management (see margin no. 52 ff.) and compliance with it. Executive board A. Duties and responsibilities The executive board is responsible for operational business activities which reflect the business strategy and the targets and resolutions of the board of directors and is also responsible in particular for:
9/14
2 By class, type and level and in line with the definitions set out in the Capital Adequacy Ordinance (CAO).
10/14
In the context of their duties, the independent control bodies have unlimited information, access and inspection rights and are to be integrated independently from the revenuegenerating units into the overall organisation or the ICS. They must be provided with the necessary resources and powers. The institution defines one or more persons on the executive board to be responsible for the independent control bodies. It ensures that the independent control bodies have direct access to the board of directors. Institutions in supervisory categories 1 to 3 have an autonomous risk control and compliance function as independent control bodies. They appoint a CRO who, in addition to risk control, can also be responsible for other independent control bodies. Systemically important institutions appoint a CRO who is a member of the executive board. b) Duties and responsibilities of risk control Risk control ensures systematic monitoring of and reporting on individual and aggregated risk positions. This includes conducting stress tests and scenario analysis under unfavourable operating conditions as part of the quantitative and qualitative analysis. Institutions participating in the small banks regime in accordance with Articles 47a–47e CAO must conduct scenario analysis as a minimum. In the case of institutions in supervisory categories 1 to 3, risk control also ensures the appropriate implementation of provisions relating to risk data aggregation and reporting as set out in margin no. 59. Risk control also monitors the institution's risk profile in line with the risk tolerance and risk limits defined in the risk policy and the basic features of institution-wide risk management. Risk control is also responsible for developing and operating adequate risk monitoring systems, defining and applying principles and methods for risk analysis and assessment (e.g. assessment and aggregation methods, validation of models), and monitoring systems to ensure compliance with supervisory regulations (especially regulations relating to capital adequacy, risk diversification and liquidity). Risk control is to be appropriately consulted during the development of new or expanded product categories, services or business/market areas and for major or complex transactions. Risk control is actively involved in the process of defining risk limits and ensures that risk limits are consistent with the defined risk tolerance and reconciled to the results of the
11/14 stress tests and that they are defined in such a way as to constitute an operationally effective management tool for the executive board. Risk control reports to the executive board at least every six months and to the board of directors at least annually on the institution's risk profile and its activities as defined in margin no. 69 ff. A copy of these reports must be provided to internal audit and the regulatory audit firm. In the event of special developments, risk control promptly informs the executive board and internal audit. If matters with far-reaching implications are involved, it also informs the board of directors. c) Duties and responsibilities of the compliance function The duties and responsibilities of the compliance function include at least the following activities:
12/14
13/14
Internal audit reports in writing in a timely manner on all material findings both to the board of directors or its audit committee and to the executive board. Internal audit publishes a report setting out the key audit findings and important activities in the audit period at least annually and submits this report with any corresponding conclusions to the board of directors or its audit committee, the executive board and the regulatory audit firm for their information. Furthermore, internal audit or another independent unit within the institution (e.g. the compliance function or risk control) informs the board of directors or its audit committee at least every six months about progress made in eliminating major shortcomings and/or implementing the recommendations of internal audit or the regulatory audit firm. Group structures This circular applies by extension to financial groups and conglomerates ("groups"). 98 Groups must regulate the duties and responsibilities of the units with overall responsibility for group management. While giving due consideration to the business activities and material risks at group and individual institution level, the defined standards must ensure the efficient and consistent management of the group, permit necessary information exchange, take account of legal and organisational structures and define the duties, responsibilities and necessary independence of the respective management levels. Particular attention must be paid to risks which arise specifically from combining a number of companies into a single business entity. Transitional provisions Abrogated 100*-104* The relevant later date applies to meeting the more far-reaching provisions on risk data aggregation and reporting, as set out in margin no. 59 for systemically important banks:
List of modifications
14/14
This Circular has been modified as follows:
These modifications were adopted on 31 October 2019 and will enter into force on 1 January 2020. modified margin nos. 10, 41, 43, 45, 46, 52, 53, 54, 69, 71, 92 abrogated margin nos. 100, 101, 102, 103, 104 other modifications change in title before margin no. 52 The references and terms were adjusted upon the entry into force of FinIA and FinSA on 1 January 2020.
Note from RegAlert. AI assistants can read this document in full, and search 70,000+ more, through the RegAlert MCP connector (https://mcp.regalert.today/mcp). Free with an account. How to connect ChatGPT, Claude or Cursor.
Read the rest free
Source: Swiss Financial Market Supervisory Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from FINMA
We email you every new FINMA publication the day it's published.