2026-09-07

Added

Form and Structure of the Good Governance Implementation Report for Financial Sector Technology Innovation Providers

This regulation, issued by the Financial Services Authority (OJK) on August 24, 2026, stipulates the form and structure for good governance implementation reports by Financial Sector Technology Innovation (ITSK) Providers. It requires ITSK Providers to submit an annual report that includes transparency of good governance implementation, a self-assessment, and an action plan for any deficiencies. The regulation also revokes Appendix II part E of OJK Circular Letter Number 4/SEOJK.07/2025 concerning reporting by ITSK Providers, Digital Financial Assets, and Crypto Assets. ITSK Providers must conduct periodic self-assessments covering 11 factors, with specific formulas and weighting for calculating a governance rating from 1 (Very Good) to 5 (Very Poor).

Otoritas Jasa Keuangan (Financial Services Authority) logo

Indonesia

Otoritas Jasa Keuangan (Financial Services Authority)

Scan of the document's first page
Share

OJK published 2 documents in the last 30 days — get each new one by email the day it lands.

COPY OF REGULATION OF THE BOARD OF COMMISSIONERS MEMBER OF THE FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA NUMBER 9 OF 2026 CONCERNING THE FORM AND STRUCTURE OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION PROVIDERS

BY THE GRACE OF ALMIGHTY GOD,
THE MEMBER OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,

Considering:
a. that to support the needs of Financial Sector Technology Innovation Providers in implementing good governance, a mechanism and format are required for filling out the good governance implementation report for Financial Sector Technology Innovation Providers; b. that to implement the mandate of Article 47 paragraph (8) of Financial Services Authority Regulation Number 30 of 2025 concerning the Implementation of Governance and Risk Management for Financial Sector Technology Innovation Providers, it is necessary to further regulate the form and structure of the good governance implementation report for financial sector technology innovation providers;
c. that based on the considerations referred to in letters a and b, it is necessary to stipulate the Regulation of the Board of Commissioners Member of the Financial Services Authority concerning the Form and Structure of the Good Governance Implementation Report for Financial Sector Technology Innovation Providers;

Referring to:

  1. Law Number 21 of 2011 concerning the Financial Services Authority (State Gazette of the Republic of Indonesia Year 2011 Number 111, Supplement to the State Gazette of the Republic of Indonesia Number 5253) as has been amended several times, most recently by Law Number 4 of 2026 concerning Amendments to Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2026 Number 62, Supplement to the State Gazette of the Republic of Indonesia Number 7180);
  2. Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2023 Number 4, Supplement to the State Gazette of the Republic of Indonesia Number 6845) as has been amended by Law Number 4 of 2026 concerning Amendments to Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector (State Gazette of the Republic of Indonesia Year 2026 Number 62, Supplement to the State Gazette of the Republic Indonesia Number 7180);
  3. Financial Services Authority Regulation Number 30 of 2025 concerning the Implementation of Governance and Risk Management for Financial Sector Technology Innovation Providers (State Gazette of the Republic of Indonesia Year 2025 Number 42/OJK, Supplement to the State Gazette of the Republic of Indonesia Number 171/OJK);

DECIDES:
Stipulates: THE REGULATION OF THE BOARD OF COMMISSIONERS MEMBER OF THE FINANCIAL SERVICES AUTHORITY CONCERNING THE FORM AND STRUCTURE OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION PROVIDERS.

Article 1
Provisions regarding the form and structure of the good governance implementation report for financial sector technology innovation providers as contained in:
a. Appendix I which contains guidelines for reporting the implementation of good governance for financial sector technology innovation providers; b. Appendix II which contains the format for good governance implementation transparency;
c. Appendix III which contains the self-assessment format for good governance implementation for financial sector technology innovation providers; and
d. Appendix IV which contains the format for action plans for financial sector technology innovation providers, which are an inseparable part of this Regulation of the Board of Commissioners Member of the Financial Services Authority.

Article 2
(1) When this Regulation of the Board of Commissioners Member of the Financial Services Authority comes into effect, Appendix II part E of Financial Services Authority Circular Letter Number 4/SEOJK.07/2025 concerning Reporting by Financial Sector Technology Innovation Providers, Digital Financial Assets, and Crypto Assets, is revoked and declared invalid.

This copy conforms to the original
Head of Legal Development Directorate
Legal Department signed
Aat Windradi

(2) This Regulation of the Board of Commissioners Member of the Financial Services Authority comes into effect on the date of its stipulation.

Stipulated in Jakarta on August 24, 2026
CHIEF EXECUTIVE
SUPERVISOR OF FINANCIAL
SECTOR TECHNOLOGY
INNOVATION, DIGITAL
FINANCIAL ASSETS AND
CRYPTO ASSETS
FINANCIAL SERVICES AUTHORITY
OF THE REPUBLIC OF INDONESIA, signed
ADI BUDIARSO

APPENDIX I
REGULATION OF THE BOARD OF COMMISSIONERS MEMBER OF THE FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA NUMBER 9 OF 2026 CONCERNING THE FORM AND STRUCTURE OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION PROVIDERS

I. GENERAL PROVISIONS

  1. Financial Sector Technology Innovation, hereinafter abbreviated as ITSK, is technology-based innovation that impacts products, activities, services, and business models in the digital financial ecosystem.
  2. ITSK Provider is any party that provides ITSK and holds a business license from the Financial Services Authority.
  3. Good Governance for ITSK Providers, hereinafter referred to as Good Governance, is the structure and process used and implemented by ITSK Providers to enhance the achievement of business objectives and optimize company value for all stakeholders in an accountable manner and based on legal provisions and ethical values.
  4. Stakeholders are all parties who have a direct or indirect interest in the business activities of ITSK Providers.
  5. Controlling Shareholder, hereinafter abbreviated as PSP, is a legal entity, individual, and/or business group that owns 25% (twenty-five percent) or more of the issued shares of an ITSK Provider and has voting rights, or owns less than 25% (twenty-five percent) of the issued shares of an ITSK Provider and has voting rights but can be proven to have exercised control over the ITSK Provider, either directly or indirectly.
  6. General Meeting of Shareholders, hereinafter abbreviated as RUPS, is a corporate body that has authority not granted to the board of directors or board of commissioners within the limits specified in the law concerning limited liability companies and/or the articles of association for ITSK Providers that are limited liability companies.
  7. Board of Directors is the organ of the ITSK Provider that is authorized and fully responsible for the management of the ITSK Provider for the benefit of the ITSK Provider, in accordance with the aims and objectives of the ITSK Provider and represents the ITSK Provider, both in and out of court in accordance with the provisions of the articles of association.
  8. Board of Commissioners is the organ of the ITSK Provider tasked with conducting general and/or specific supervision in accordance with the articles of association and providing advice to the Board of Directors.
  9. Conflict of Interest is a situation where there is a conflict between the interests of the ITSK Provider and the personal, family, and shareholder group interests of members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider.

II. IMPLEMENTATION OF GOOD GOVERNANCE
The implementation of Good Governance is based on the principles of Good Governance, which include:

  1. Transparency includes openness in decision-making processes and openness in disclosing and providing relevant information that is easily accessible to Stakeholders. In implementing the principle of transparency in decision-making processes and openness in disclosing and providing relevant information for Stakeholders, it must be supported by adequate guidelines and information systems.
  2. Accountability includes clarity of functions and the implementation of accountability of ITSK Provider organs. In implementing the principle of accountability, members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider must have guidelines and work procedures so that tasks are carried out optimally and can be fully accounted for.
  3. Responsibility for the conformity of management with legal provisions and ethical values, as well as standards, principles, and practices at the ITSK Provider. In implementing the principle of responsibility, members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider carry out their duties in accordance with legal provisions and ethical values, as well as applicable standards, principles, and practices.
  4. Independence includes a state managed independently and professionally, free from Conflicts of Interest and influence or pressure from any party that is not in accordance with legal provisions and ethical values, as well as standards, principles, and practices at the ITSK Provider. In implementing the principle of independence, members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider carry out their respective roles and responsibilities in accordance with their duties, functions, and authorities without mutual domination and without being subject to intervention. Members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider must also avoid Conflicts of Interest and influence or pressure from any party. In the event of a Conflict of Interest, members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider must disclose such Conflict of Interest in accordance with the Conflict of Interest policy already held by the ITSK Provider.
  5. Fairness includes equality, balance, and justice in fulfilling the rights of Stakeholders arising from agreements, legal provisions, and ethical values, as well as standards, principles, and practices. In implementing the principle of fairness, ITSK Providers need to consider, among other things: a. the interests of shareholders, including the protection of minority shareholders, fund owners, fund providers, and other Stakeholders; and b. the fulfillment of rights for all human resources of the ITSK Provider, in accordance with legal provisions.

III. FORM AND STRUCTURE OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT

  1. ITSK Providers submit the Good Governance implementation report as part of their annual report.
  2. The form and structure of the Good Governance implementation report as referred to in point 1 must at least contain:
    a. transparency of Good Governance implementation which discloses all aspects of the implementation of Good Governance principles as referred to in Roman II; b. self-assessment of Good Governance implementation; and
    c. action plans covering weaknesses, corrective actions, target completion times, and obstacles to completion, if there are still deficiencies in the implementation of Good Governance.
  3. The transparency of Good Governance implementation as referred to in point 2 letter a and the self-assessment of Good Governance implementation as referred to in point 2 letter b include:
    a. execution of duties and authorities of shareholders and RUPS; b. active supervision by the Board of Directors and Board of Commissioners;
    c. implementation of risk management;
    d. implementation of internal audit function; e. implementation of external audit function; f. handling of Conflicts of Interest; g. information disclosure; h. business ethics;
    i. feasibility of annual business plans;
    j. transparency of financial and non-financial conditions; and k. implementation of control functions for personal data protection and information system security.

IV. TRANSPARENCY OF GOOD GOVERNANCE IMPLEMENTATION

  1. The transparency of Good Governance implementation as referred to in Roman III point 2 letter a is prepared by the ITSK Provider based on the format contained in Appendix II, which is an inseparable part of this Regulation of the Board of Commissioners Member of the Financial Services Authority.
  2. The transparency of Good Governance implementation related to risk management implementation as referred to in Roman III point 3 letter c also includes the implementation of anti-money laundering, prevention of terrorism financing, and prevention of proliferation financing of weapons of mass destruction (AML, CTF, and CPF) programs in carrying out the business activities of ITSK Providers.
  3. The transparency of Good Governance implementation related to handling Conflicts of Interest as referred to in Roman III point 3 letter f includes the handling of ongoing and/or potential Conflicts of Interest for members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider.
  4. The transparency of Good Governance implementation related to information disclosure as referred to in Roman III point 3 letter g, includes:
    a. share ownership of members of the Board of Directors and members of the Board of Commissioners reaching 5% (five percent) or more in the ITSK Provider where the members of the Board of Directors and members of the Board of Commissioners serve and/or in other companies located domestically and abroad; b. financial relationships of members of the Board of Directors and members of the Board of Commissioners with other members of the Board of Directors, other members of the Board of Commissioners, shareholders of the ITSK Provider, and/or employees of the ITSK Provider where the members of the Board of Directors and members of the Board of Commissioners serve;
    c. family relationships of members of the Board of Directors and members of the Board of Commissioners with other members of the Board of Directors, other members of the Board of Commissioners, shareholders of the ITSK Provider, and/or employees of the ITSK Provider where the members of the Board of Directors and members of the Board of Commissioners serve up to the second degree, both horizontal and vertical; and
    d. remuneration and facilities received by members of the Board of Directors and members of the Board of Commissioners.
  5. In addition to the information disclosure as referred to in point 4, ITSK Providers disclose important matters to the Financial Services Authority, including:
    a. resignation or dismissal of external auditors; b. material transactions with affiliated parties; ITSK Providers need to define limits for material transactions adjusted to the size, characteristics, and complexity of the ITSK Provider;
    c. ongoing and/or potential Conflicts of Interest; and
    d. other material information regarding the ITSK Provider, including:
  1. appointment, dismissal, replacement, and/or resignation of members of the Board of Directors, members of the Board of Commissioners, including those permanently unable to serve due to death, mental disability, or other conditions that prevent them from performing their duties properly;
  2. training of members of the Board of Directors and members of the Board of Commissioners;
  3. dual positions of members of the Board of Directors and members of the Board of Commissioners;
  4. frequency of meetings held within 1 (one) year;
  5. foreign workers, including:
    a) Board of Directors; b) Board of Commissioners; c) experts; or d) consultants;
  6. legal issues, both civil and criminal, faced by the ITSK Provider during the reporting year and submitted through legal processes and resolution efforts;
  7. transparency of financial and non-financial conditions of the ITSK Provider not yet disclosed in other reports;
  8. work plans; and
  9. annual budget plans.
  1. ITSK Providers must also follow industry dynamics to encourage the implementation of Good Governance at ITSK Providers so that they can fulfill their function to support the financial sector industry in conducting healthy business practices. One way ITSK Providers follow industry dynamics is by implementing ITSK Provider management in line with the development of legal provisions and current policies, as well as in accordance with the needs of the ITSK Provider industry.
  2. ITSK Providers must have, evaluate, and update internal procedures regarding the implementation of Good Governance in conducting business activities for each governance implementation assessment factor in accordance with legal provisions, including business processes and approval mechanisms at the ITSK Provider.

V. SELF-ASSESSMENT OF GOOD GOVERNANCE IMPLEMENTATION

  1. The self-assessment of Good Governance implementation as referred to in Roman III point 2 letter b is carried out by the ITSK Provider based on Good Governance guidelines.
  2. To ensure the implementation of the 5 (five) basic principles of Good Governance as referred to in Roman II, ITSK Providers must conduct a periodic self-assessment covering at least 11 (eleven) governance implementation assessment factors, namely:
    a. execution of duties and authorities of shareholders and RUPS; b. active supervision by the Board of Directors and Board of Commissioners;
    c. implementation of risk management;
    d. implementation of internal audit function; e. implementation of external audit function; f. handling of Conflicts of Interest; g. information disclosure; h. business ethics;
    i. feasibility of annual business plans;
    j. transparency of financial and non-financial conditions; and k. implementation of control functions for personal data protection and information system security.
  3. The self-assessment as referred to in point 1 is documented in the self-assessment worksheet as contained in Appendix III, which is an inseparable part of this Regulation of the Board of Commissioners Member of the Financial Services Authority.
  4. The self-assessment of Good Governance implementation for the factors referred to in point 2 is assessed based on the measurement of:
    a. governance structure and infrastructure, which aims to assess the adequacy of the ITSK Provider's governance structure and infrastructure so that the process of implementing Good Governance principles produces outcomes that meet Stakeholder expectations. Included in the ITSK governance structure are shareholders, members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider. The ITSK Provider's governance infrastructure includes, among others, ITSK Provider policies and procedures, information technology systems, risk management, internal controls, and the main duties and functions of each organizational structure. b. governance implementation process, which aims to assess the effectiveness of the process of implementing governance principles supported by the adequacy of the ITSK Provider's governance structure and infrastructure to produce outcomes that meet Stakeholder expectations.
    c. governance implementation results (governance outcome), which aims to assess the quality of outcomes that meet Stakeholder expectations, resulting from the process of implementing Good Governance principles and supported by the adequacy of the ITSK Provider's governance structure and infrastructure. Governance outcomes include qualitative and quantitative aspects, such as:
  1. adequacy of report transparency;
  2. compliance with legal provisions;
  3. improvement in human resource quality;
  4. consumer protection;
  5. objectivity in conducting assessments or audits;
  6. ITSK Provider performance such as capital; and/or
  7. increase or decrease in compliance with provisions and resolution of issues faced by ITSK Providers such as fraud and violations of provisions related to ITSK Provider reports to the Financial Services Authority.
  1. ITSK Providers may add other parameters or indicators in accordance with the characteristics and business complexity of the ITSK Provider without reducing the substance and scope of the assessment in the self-assessment worksheet as referred to in point 2.
  2. Assessment of quantitative parameters or indicators is carried out based on the position and trend over the last 12 (twelve) months.
  3. In assessing the implementation of Good Governance on a consolidated basis, ITSK Providers may use individual Good Governance implementation assessment parameters or indicators, adjusted to the scale, characteristics, and business complexity of the subsidiary.
  4. The determination of the Good Governance rating and the value of each indicator is carried out based on an analysis of:
    a. the implementation of Good Governance principles; b. governance measurement of the structure, process, and results of governance implementation as in point 4; and
    c. other information related to Good Governance based on relevant data and information.
  5. Filling out the self-assessment worksheet is carried out in the following stages:
    a. ITSK Providers prepare a self-assessment analysis by comparing the fulfillment of each indicator with the condition of the ITSK Provider based on relevant data and information for each statement/question in each factor as referred to in Roman III point 3. b. Based on the results of this analysis, the value of each indicator is determined. For each statement/question in the self-assessment, an indicator value is given as per the following table:

Indicator Value Definition
Meets the condition where the structure and/or infrastructure are fully compliant with provisions, the governance implementation process is carried out very adequately, and is indicated by very good governance implementation results.
Meets the condition where the structure and/or infrastructure are compliant with provisions, the governance implementation process is carried out adequately, and is indicated by good governance implementation results.
Meets the condition where the structure and/or infrastructure are sufficiently compliant with provisions, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Meets the condition where the structure and/or infrastructure are not fully compliant with provisions, the governance implementation process is carried out inadequately, and is indicated by poor governance implementation results. Meets the condition where the structure and/or infrastructure are not compliant with provisions, the governance implementation process is carried out inadequately, and is indicated by very poor governance implementation results.

c. To obtain the value of each factor, ITSK Providers use the following formula:
Factor Value = (∑ indicator value / (5 × number of statements/questions)) × factor weight

The weight of each factor is determined as per the following table:

No. Factor Weight (%)

  1. Execution of duties and authorities of shareholders and RUPS 5.00
  2. a. Active supervision by the Board of Directors 15.00
    b. Active supervision by the Board of Commissioners 15.00
  3. Implementation of risk management 9.00
  4. Implementation of internal audit function 5.00
  5. Implementation of external audit function 5.00
  6. Ongoing and/or potential Conflicts of Interest 10.00
  7. Information disclosure 5.00
  8. Business ethics 9.00
  9. Feasibility of annual business plans 2.00
  10. Transparency of financial and non-financial conditions 5.00
  11. Implementation of control functions for personal data protection and information system security 15.00
    Total 100.00

d. To obtain the total governance factor value, ITSK Providers sum the values of all factors. Based on this value, ITSK Providers determine the rating for the implementation of Good Governance as per the following table:

Governance Value Rating Predicate
84 -100 Very Good 1
68 - 83 Good 2
52 - 67 Sufficiently Good 3
36 - 51 Poor 4
20 - 35 Very Poor 5

e. ITSK Providers determine the governance rating, accompanied by a general conclusion of the self-assessment results, by referring to the definition of governance ratings as follows:

Rating Definition
1 Reflects that the management of the ITSK Provider has

implementing Good Governance which is generally very good. This is reflected in a very adequate fulfillment of the principles of Good Governance. In the event of weaknesses in the implementation of Good Governance principles, such weaknesses are generally not significant and can be immediately rectified by the management of the ITSK Provider. Reflecting that the management of the ITSK Provider has implemented Good Governance which is generally good. This is reflected in an adequate fulfillment of the principles of Good Governance. In the event of weaknesses in the implementation of Good Governance principles, such weaknesses are generally less significant and can be resolved with normal actions by the management of the ITSK Provider. Reflecting that the management of the ITSK Provider has implemented Good Governance which is generally quite good. This is reflected in a sufficiently adequate fulfillment of the principles of Good Governance. In the event of weaknesses in the implementation of Good Governance principles, such weaknesses are generally quite significant and require sufficient attention from the management of the ITSK Provider. Reflecting that the management of the ITSK Provider has implemented Good Governance which is generally less good. This is reflected in a less adequate fulfillment of the principles of Good Governance. There are weaknesses in the implementation of Good Governance principles, and such weaknesses are generally significant and require comprehensive improvement by the management of the ITSK Provider. Reflecting that the management of the ITSK Provider has implemented Good Governance which is generally not good. This is reflected in an inadequate fulfillment of the principles of Good Governance. There are weaknesses in the implementation of Good Governance principles, and such weaknesses are generally very significant and difficult to rectify by the management of the ITSK Provider. f. Based on the self-assessment working paper, the ITSK Provider makes a general conclusion of the self-assessment results on a separate sheet as stated in Appendix III, which is an inseparable part of this Regulation of the Board of Commissioners Member of the Financial Services Authority, describing the adequacy fulfillment of all governance assessment factors, at least covering:

  1. total value of governance factors and governance rating;
  2. weaknesses (negative factors) and root causes of problems;
  3. strengths (positive factors) of governance implementation; and
  4. final conclusion of the governance implementation assessment linked to the definition of the governance rating value.
  1. The self-assessment working paper and supporting documents (if any) of the self-assessment must be well documented in accordance with the provisions of laws and regulations regarding archival retention to facilitate tracing by interested parties.
  2. The Financial Services Authority conducts an assessment of the implementation of Good Governance, including conducting an assessment or evaluation of the self-assessment results by the ITSK Provider on governance implementation.
  3. In the event that based on the results of the assessment or evaluation by the Financial Services Authority as referred to in number 11, there are factors deemed to significantly affect the governance of the ITSK Provider and potentially have an impact on the condition and/or business continuity of the ITSK Provider, the Financial Services Authority may adjust the governance rating of the ITSK Provider.
    VI. ACTION PLAN
  4. The action plan is prepared to improve or perfect the implementation of Good Governance as a follow-up to the self-assessment results. The action plan includes:
    a. weaknesses; b. corrective actions;
    c. target completion time; and
    d. completion constraints, if there are still shortcomings in the implementation of Good Governance.
  5. In the event that based on the self-assessment results of governance implementation, the governance factor rating is rating 4 or rating 5, the ITSK Provider prepares and submits an action plan containing comprehensive and systematic improvement steps and the target time for implementing the action plan to the Financial Services Authority.
  6. If necessary, the Financial Services Authority may request the ITSK Provider to submit an action plan containing comprehensive and systematic improvement steps and the target time for implementing the action plan, with a timeframe as requested by the Financial Services Authority.
  7. In the event that the ITSK Provider has submitted an action plan as referred to in numbers 2 and 3, but based on the consideration of the Financial Services Authority, an adjustment to the action plan is required, the Financial Services Authority may request the ITSK Provider to adjust the action plan that has been submitted by the ITSK Provider and resubmit the adjusted action plan with a timeframe as requested by the Financial Services Authority.
  8. The action plan as referred to in Roman III number 2 letter c is prepared by the ITSK Provider according to the format as stated in Appendix IV, which is an inseparable part of this Regulation of the Board of Commissioners Member of the Financial Services Authority.
    VII. TIME OF SUBMISSION OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT
  9. The ITSK Provider has the obligation to submit the Good Governance implementation report at the end of each financial year to the Financial Services Authority no later than April 30 of the following year.
  10. If April 30 falls on a Saturday, Sunday, or public holiday, the Good Governance implementation report as referred to in number 1 shall be submitted on the next first working day.
  11. Under certain conditions, the Financial Services Authority is authorized to set a different deadline for submitting reports from the provisions as referred to in number 1.
    VIII. REPORTING MECHANISM
  12. The ITSK Provider must submit a cover letter and the Good Governance implementation report online through the Financial Services Authority Reporting System.
  13. In the event that the Financial Services Authority Reporting System as referred to in number 1 is not yet available or experiences technical disruption, the ITSK Provider submits a cover letter and the Good Governance implementation report in the form of an electronic document via email to the address:
    a. mailingroomsumitro@ojk.go.id, if the Financial Services Authority Reporting System is not yet available; b. mailingroommrp@ojk.go.id, if the Financial Services Authority Reporting System experiences technical disruption; or
    c. other addresses determined by the Financial Services Authority.
  14. The submission of the Good Governance implementation report in the form of an electronic document via email as referred to in number 2 is addressed to:
    a. Head of the Department of Supervision of Financial Sector Technology Innovation, Digital Financial Assets and Crypto Assets, if the Financial Services Authority Reporting System is not yet available; or b. Head of the Data and Statistics Management Department with a copy to the Head of the Department of Supervision of Financial Sector Technology Innovation, Digital Financial Assets and Crypto Assets, if the Financial Services Authority Reporting System experiences technical disruption.
  15. In the event that the Financial Services Authority's email as referred to in number 2 experiences technical disruption, the submission of the Good Governance implementation report is submitted to the Financial Services Authority offline by:
    a. direct submission; or b. sending through a courier service company.
  16. The offline submission of reports as referred to in number 4 is addressed to:
    a. Head of the Department of Supervision of Financial Sector Technology Innovation, Digital Financial Assets and Crypto Assets Soemitro Djojohadikusumo Building, Jalan Lapangan Banteng Timur 2-4, Jakarta 10710, Indonesia, in the event that the Financial Services Authority Reporting System is not yet available and the Financial Services Authority's email experiences technical disruption; or b. Head of the Data and Statistics Management Department Menara Radius Prawiro Building, 14th Floor Bank Indonesia Office Complex Jalan MH. Thamrin Number 2, Central Jakarta, 10350, with a copy to:
    Head of the Department of Supervision of Financial Sector Technology Innovation, Digital Financial Assets and Crypto Assets Soemitro Djojohadikusumo Building Jalan Lapangan Banteng Timur 2-4 Jakarta 10710, Indonesia, in the event that the Financial Services Authority System is already available and the Financial Services Authority's email experiences technical disruption.
  17. The ITSK Provider is deemed to have submitted the report with the following provisions:
    a. submission through the Financial Services Authority Reporting System is evidenced by a receipt from the Financial Services Authority Reporting System; b. submission via email is evidenced by an acknowledgment of receipt from the Financial Services Authority's email; or
    c. offline submission is evidenced by a receipt from the Financial Services Authority.
    CHIEF EXECUTIVE OF SUPERVISION
    FINANCIAL SECTOR TECHNOLOGY
    INNOVATION, DIGITAL FINANCIAL
    ASSETS AND CRYPTO ASSETS
    FINANCIAL SERVICES AUTHORITY
    REPUBLIC OF INDONESIA, signed.
    ADI BUDIARSO
    This copy is in accordance with the original
    Head of Legal Development Directorate
    Legal Department signed.
    Aat Windradi

APPENDIX II
REGULATION OF THE BOARD OF COMMISSIONERS MEMBER FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 9 YEAR 2026 CONCERNING FORM AND STRUCTURE OF THE REPORT ON THE IMPLEMENTATION OF GOOD GOVERNANCE FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION PROVIDERS

CHAPTER I
GENERAL EXPLANATION
The preparation of the transparency report on the implementation of Good Governance as referred to in Article 47 paragraph (2) letter a of Financial Services Authority Regulation Number 30 Year 2025 concerning the Implementation of Governance and Risk Management for Financial Sector Technology Innovation Providers, Digital Financial Assets and Crypto Assets, is carried out in the context of implementing the principle of transparency. The ITSK Provider discloses all aspects of Good Governance transparency in the format as stated in this Appendix. The ITSK Provider may provide a general explanation of the implementation of Good Governance or other matters deemed significant in accordance with the conditions and policies of each ITSK Provider.

CHAPTER II
FORMAT OF THE TRANSPARENCY REPORT ON THE IMPLEMENTATION OF GOOD GOVERNANCE FOR ITSK PROVIDERS A. Summary of Assessment Results on the Implementation of Good Governance Address:
Telephone Number:
General Explanation:
Good Governance Self-Assessment Rating:
Explanation of Good Governance Self-Assessment Rating:
B. Disclosure of Governance Implementation

  1. Execution of duties and authorities of shareholders and General Meeting of Shareholders (GMS)
    a. Controlling Shareholders (PSP)
    No. Execution of duties and authorities of PSP
  2. National Identity Number (NIK)*):
    Name:
    Date of Approval of Fit and Proper Test Results:
    Number of Fit and Proper Test Results:
    Country of Origin
    Citizenship ):
    Domicile:
    Duties and Authorities:
    2 National Identity Number (NIK)
    ):
    Name:
    Date of Approval of Fit and Proper Test Results:
    Number of Fit and Proper Test Results:
    Country of Origin:
    Citizenship *):
    Domicile:
    Duties and Authorities:
    etc.
    *) NIK and Citizenship are only submitted in reports to the Financial Services Authority and are filled in only for individual PSPs. b. Shareholders No. Execution of duties and authorities of Shareholders
  3. National Identity Number (NIK)*):
    Name:
    Country of Origin
    Citizenship ):
    Domicile:
    Duties and Authorities:
    National Identity Number (NIK)
    ):
    No. Execution of duties and authorities of Shareholders 2 Name:
    Country of Origin:
    Citizenship *):
    Domicile:
    Duties and Authorities:
    etc.
    *) NIK and Citizenship are only submitted in reports to the Financial Services Authority and are filled in only for individual shareholders.
    c. Execution of GMS
    No. Execution of GMS
  4. Date:
    Number of Participants:
    Topic/Discussion Material:
    2 Date:
    Number of Participants:
    Topic/Discussion Material:
    etc.
  5. A. Active Supervision by the Board of Directors
    No. Execution of Duties, Responsibilities, and Authorities of the Board of Directors
  6. National Identity Number (NIK)):
    Name:
    Position:
    Date of Approval of Fit and Proper Test Results:
    Number of Fit and Proper Test Results:
    Date of GMS Appointment:
    Term of Office:
    Citizenship:
    Domicile:
    Work History in the Last Five Years:
    Education:
    Professional Title:
    Work Permit):
    Temporary Stay Permit/Permanent Stay Permit (KITAS/KITAP)
    ) Validity Period of KITAS/KITAP *):
    Duties, Responsibilities, and Authorities)
    :
  7. National Identity Number (NIK)):
    Name:
    Position:
    Date of Approval of Fit and Proper Test Results:
    Number of Fit and Proper Test Results:
    No. Execution of Duties, Responsibilities, and Authorities of the Board of Directors Date of GMS Appointment:
    Term of Office:
    Citizenship:
    Domicile:
    Work History in the Last Five Years:
    Education:
    Professional Title:
    Work Permit):
    Temporary Stay Permit/Permanent Stay Permit (KITAS/KITAP)
    ) Validity Period of KITAS/KITAP *):
    Duties, Responsibilities, and Authorities)
    :
    etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) Filled in if the Board of Directors member is a foreign citizen.
    *) Filled in if the Board of Directors member is a foreign citizen and domiciled in Indonesia.
    ) Filled in with a description of the duties, responsibilities, and authorities of the Board of Directors.
    *) Follow-up on recommendations from the Board of Commissioners that have not been reported in the previous year's Good Governance implementation report.
    B. Active Supervision by the Board of Commissioners No. Execution of Duties, Responsibilities, and Authorities of the Board of Commissioners
  8. National Identity Number (NIK)*):
    Name:
    Position:
    Date of Approval of Fit and Proper Test Results:
    Number of Fit and Proper Test Results:
    Date of Appointment by GMS:
    Term of Office:
    Citizenship:
    Domicile:
    Work History in the Last Five Years:
    Education:
    Professional Title:
    Work Permit):
  • Follow-up on Board of Commissioners Recommendations*) -
    Temporary Stay Permit/Permanent Stay Permit (KITAS/KITAP)*) Validity Period of KITAS/KITAP *):
    Duties, Responsibilities, and Authorities)
    :
    etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) Filled in if the Board of Commissioners member is a foreign citizen.
    *) Filled in if the Board of Commissioners member is a foreign citizen and domiciled in Indonesia.
    ) Filled in with a description of the duties, responsibilities, and authorities of the Board of Commissioners and reports on the results of the Board of Commissioners' supervision of financial reporting integrity.
  1. Implementation of Risk Management
    a. Implementation of Risk Management
  1. Ownership of Risk Management Function
    No. Responsible Head of Work Unit
  2. Active supervision by the Board of Commissioners and Board of Directors
  3. Adequacy of policies, procedures, and risk limit setting
    -Brief description of examples to ensure that the ITSK Provider implements Good Governance-
  • Recommendation to the Board of Directors –
    -Brief description-
  1. Adequacy of risk identification, measurement, monitoring, and control processes
  2. Risk management information system
  3. Comprehensive internal control system
    b. Implementation of Anti-Money Laundering, Counter-Terrorism Financing, and Prevention of Proliferation Financing of Weapons of Mass Destruction Program No. Responsible Head of Work Unit/Function Implementer
  1. Implementation of Internal Audit Function
    Effectiveness and scope of internal auditor's duties in assessing all aspects and elements of activities a. Scope of audit work -Brief description- -Brief description- -Brief description- -Brief description- b. Structure or position of the internal audit function
    c. Independence of the internal auditor
    d. Description of internal audit function duties e. Profile of the head of the internal audit function f. Number of employees in the internal audit function g. Internal audit task implementation report.
    -Brief description-
    -Brief description-
    -Brief description-
    -Brief description-
    -Brief description-
    -Brief description, for example: office audit and information system technology audit -
  2. Implementation of External Audit Function
    Effectiveness of external auditor's duties and company's compliance with provisions, among others, regarding the provision of all accounting records and supporting data required by the external auditor, enabling the external auditor to provide an opinion on the fairness, compliance, and conformity of the company's financial statements with applicable audit standards. Public Accounting Firms that Audited the Company's Financial Statements During the Last 5 (Five) Years Year Public Accounting Firm Accountant's Name (Individual) and Registration Number at the Financial Services Authority External Auditor Fee -Brief description-
  3. Handling Conflicts of Interest
    Examples of ongoing and/or potential Conflicts of Interest are the purchase of company assets by members of the Board of Directors, members of the Board of Commissioners, and/or employees of the ITSK Provider.
    No.
    Party with Conflict of Interest Decision Maker Type of Transaction Transaction Value (Millions of Rupiah) Remarks) NIK*) Name Position NIK*) Name Position 1.
  4. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) Remarks are filled with:
  • conformity and/or non-conformity of the transaction with internal provisions;
  • explaining the relationship between the party with a Conflict of Interest and the decision maker; and
  • form of follow-up action for identified Conflicts of Interest.
  1. Information Disclosure
    a. Share Ownership of Members of the Board of Directors and Board of Commissioners in ITSK Providers
  1. Share Ownership of Members of the Board of Directors in ITSK Providers
    No. NIK*) Name of Board of Directors Member Nominal (Rp) Percentage of Ownership (%) Nominal (Rp) Previous Year Percentage of Ownership (%) Previous Year 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
  1. Share Ownership of Members of the Board of Commissioners in ITSK Providers
    No. NIK*) Name of Board of Commissioners Member Nominal (Rp) Percentage of Ownership (%) Nominal (Rp) Previous Year Percentage of Ownership (%) Previous Year 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority. b. Share Ownership of Members of the Board of Directors and Board of Commissioners in Other Companies
  1. Share Ownership of Members of the Board of Directors in Other Companies
    No. NIK*) Name of Board of Directors Member Name of Other Company Nominal (Rp) Percentage of Ownership (%) Nominal (Rp) Previous Year Percentage of Ownership (%) Previous Year 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
  1. Share Ownership of Members of the Board of Commissioners in Other Companies
    No. NIK*) Name of Board of Commissioners Member Name of Other Company Nominal (Rp) Percentage of Ownership (%) Nominal (Rp) Previous Year Percentage of Ownership (%) Previous Year 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    c. Financial Relationships of Members of the Board of Directors and Board of Commissioners in ITSK Providers
  1. Financial Relationships of Members of the Board of Directors in ITSK Providers
    No. NIK*) Name of Board of Directors Member Financial Relationship) Board of Directors Member Board of Commissioners Member Shareholder Employee 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) - If there is a financial relationship, fill in with “Name – Financial Relationship”. Financial relationships may include, among others, receiving and/or providing income, financial assistance, loans, and/or acting as guarantor or receiving guarantees, e.g., “Mr. A – Loan”.
  • If a Board of Directors member has a financial relationship with more than one party in each column, it can be added separated by a comma (,).
  • If there is no financial relationship, fill in with “None”.
  1. Financial Relationships of Members of the Board of Commissioners in ITSK Providers
    No. NIK*) Name of Board of Commissioners Member Financial Relationship) Board of Directors Member Board of Commissioners Member Shareholder Employee 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) - If there is a financial relationship, fill in with “Name – Financial Relationship”. Financial relationships may include, among others, receiving and/or providing income, financial assistance, loans, and/or acting as guarantor or receiving guarantees, e.g., “Mr. A – Loan”.
  • If a Board of Commissioners member has a financial relationship with more than one party in each column, it can be added separated by a comma (,).
  • If there is no financial relationship, fill in with “None”.
    d. Family Relationships of Members of the Board of Directors and Board of Commissioners in ITSK Providers
  1. Family Relationships of Members of the Board of Directors in ITSK Providers
    No. NIK*) Name of Board of Directors Member Family Relationship) Board of Directors Member Board of Commissioners Member Shareholder Employee 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) - If there is a family relationship, fill in with “Name – Family Relationship”, e.g., “Mr. A – Cousin”.
  • If a Board of Directors member has a family relationship with more than one party in each column, it can be added separated by a comma (,).
  • If there is no family relationship, fill in with “None”.
  1. Family Relationships of Members of the Board of Commissioners in ITSK Providers
    No. NIK*) Name of Board of Commissioners Member Family Relationship) Board of Directors Member Board of Commissioners Member Shareholder Employee 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) - If there is a family relationship, fill in with “Name – Family Relationship”, e.g., “Mr. A – Cousin”.
  • If a Board of Commissioners member has a family relationship with more than one party in each column, it can be added separated by a comma (,).
  • If there is no family relationship, fill in with “None”.
    e. Remuneration and Other Facilities Received by Members of the Board of Directors and Board of Commissioners No. Type of Remuneration (Within 1 Year) Board of Directors Board of Commissioners Number of People Total Amount (Rp) Number of People Total Amount (Rp)
  1. Salary*)
  2. Allowances
  3. Tantiem
  4. Share-based compensation
  5. Other remuneration)
    Total Remuneration
    Type of Other Facilities
  6. Housing
    No. Type of Remuneration (Within 1 Year) Board of Directors Board of Commissioners Number of People Total Amount (Rp) Number of People Total Amount (Rp)
  7. Transportation
  8. Health insurance
  9. Other facilities*)
    Total Other Facilities
    Total Remuneration and Other Facilities
    *) Salary is basic salary, not including allowances received by members of the Board of Directors and Board of Commissioners and their families.
    ) Other remuneration for ITSK Provider management and determined based on GMS with due regard to the duties, authorities, responsibilities, and risks of each member of the Board of Directors and Board of Commissioners. f. Disclosure of Other Important Matters
  1. Resignation or Dismissal of External Auditor
    No. Resignation or Dismissal of External Auditor
  1. Name:
    Position:
    Date of Appointment:
    Date of Resignation or Dismissal:
    Reason for Resignation or Dismissal etc.
  1. Material Transactions with Affiliated Parties
    No.
    Affiliated Party Decision Maker Type of Transaction Transaction Value (Millions of Rupiah) Remarks) NIK*) Name Position NIK*) Name Position 1.
  1. etc.
    *) NIK is only submitted in reports to the Financial Services Authority.
    ) Remarks are filled with:
  • Conformity and/or non-conformity of the transaction with internal provisions; and
  • Explaining the relationship between the affiliated party and the decision maker.

g. Other Material Information regarding ITSK Providers Related to Good Governance

  1. Changes in the Composition of the Board of Directors, Members of the Board of Commissioners
    Changes in the Composition of the Board of Directors, Members of the Board of Commissioners, include the appointment, dismissal, replacement, and/or resignation of members of the Board of Directors and members of the Board of Commissioners. If during the reporting year there are changes in the composition of the Board of Directors and members of the Board of Commissioners, the previous composition of the Board of Directors and Board of Commissioners must be included with a table as follows:
    a) Members of the Board of Directors
    | No. | Changes in the Composition of the Board of Directors |
    |-----|------------------------------------------------------|
    | 1. | Name: |
    | | Position: |
    | | Date of Appointment by GMS: |
    | | Date of Dismissal, Replacement, and/or Resignation by GMS: |
    | | Reason for Dismissal, Replacement, and/or Resignation by GMS: |
    | | etc. |
    b) Members of the Board of Commissioners
    | No. | Changes in the Composition of the Board of Commissioners |
    |-----|----------------------------------------------------------|
    | 1. | Name: |
    | | Position: |
    | | Date of Appointment by GMS: |
    | | Date of Dismissal, Replacement, and/or Resignation by GMS: |
    | | Reason for Dismissal, Replacement, and/or Resignation by GMS: |
    | | etc. |
  2. Training for Members of the Board of Directors and Members of the Board of Commissioners
    Training related to improving the capabilities of members of the Board of Directors and members of the Board of Commissioners in achieving the vision and mission of the ITSK Provider. a) Members of the Board of Directors
    | No. | Training for Members of the Board of Directors |
    |-----|------------------------------------------------|
    | 1. | Name: |
    | | Workshop/Training/Seminar: |
    | | Date: |
    | | Organizer - Venue: |
    | 2. | Name: |
    | | Workshop/Training/Seminar: |
    | | Date: |
    | | Organizer - Venue: |
    | | etc. |
    b) Members of the Board of Commissioners
    | No. | Training for Members of the Board of Commissioners |
    |-----|----------------------------------------------------|
    | 1. | Name: |
    | | Workshop/Training/Seminar: |
    | | Date: |
    | | Organizer - Venue: |
    | 2. | Name: |
    | | Workshop/Training/Seminar: |
    | | Date: |
    | | Organizer - Venue: |
    | | etc. |
  3. Concurrent Positions of Members of the Board of Directors and Members of the Board of Commissioners,
    a) Members of the Board of Directors
    | No. | Concurrent Positions of Members of the Board of Directors |
    |-----|-----------------------------------------------------------|
    | 1. | Name: |
    | | Position at ITSK Provider: |
    | | Position at Other Company: |
    | | Name of Other Company: |
    | | Business Field: |
    | | etc. |
    b) Members of the Board of Commissioners
    | No. | Concurrent Positions of Members of the Board of Commissioners |
    |-----|---------------------------------------------------------------|
    | 1. | Name: |
    | | Position at ITSK Provider: |
    | | Position at Other Company: |
    | | Name of Other Company: |
    | | Business Field: |
    | | etc. |
  4. Frequency of Meetings Held in 1 (One) Year
    a) Board of Directors Meeting
    | No. | Implementation of Board of Directors Meeting |
    |-----|----------------------------------------------|
    | 1. | Date: |
    | | Number of Participants: |
    | | Topic/Material of Discussion: |
    | | etc. |
    Attendance at Board of Directors Meeting
    | No. | Attendance at Board of Directors Meeting |
    |-----|------------------------------------------|
    | 1. | Name: |
    | | Number of Physical Attendances: |
    | | Number of Electronic Media Attendances: |
    | | Attendance Rate (%)*): |
    | | Reason for Absence: |
    | | etc. |
    ) Attendance Rate = (Number of Physical Attendances + Number of Electronic Media Attendances) / Number of Meetings * 100% b) Joint Meeting of Board of Directors and Board of Commissioners
    | No. | Implementation of Joint Meeting of Board of Directors and Board of Commissioners |
    |-----|----------------------------------------------------------------------------------|
    | 1. | Date: |
    | | Number of Participants: |
    | | Topic/Material of Discussion: |
    | | etc. |
    Attendance at Joint Meeting of Board of Directors and Board of Commissioners
    | No. | Attendance at Joint Meeting of Board of Directors and Board of Commissioners |
    |-----|------------------------------------------------------------------------------|
    | 1. | Name: |
    | | Number of Physical Attendances: |
    | | Number of Electronic Media Attendances: |
    | | Attendance Rate (%)
    ): |
    | | Reason for Absence: |
    | | etc. |
    ) Attendance Rate = (Number of Physical Attendances + Number of Electronic Media Attendances) / Number of Meetings * 100% c) Board of Commissioners Meeting
    | No. | Implementation of Board of Commissioners Meeting |
    |-----|--------------------------------------------------|
    | 1. | Date: |
    | | Number of Participants: |
    | | Topic/Material of Discussion: |
    | | etc. |
    Attendance at Board of Commissioners Meeting
    | No. | Attendance at Board of Commissioners Meeting |
    |-----|----------------------------------------------|
    | 1. | Name: |
    | | Number of Physical Attendances: |
    | | Number of Electronic Media Attendances: |
    | | Attendance Rate (%)
    ): |
    | | Reason for Absence: |
    | | etc. |
  5. Foreign Workers
    | No. | Name | Position | KITAS | IMTA | Work Permit | Validity Period | Permit Number | Validity Period |
    |-----|------|----------|-------|------|-------------|-----------------|---------------|-----------------|
    | 1. | | | | | | | | |
    | 2. | | | | | | | | |
    | Dst.| | | | | | | | |
  6. Legal Issues
    | Legal Issues | Amount (Unit) |
    |--------------|---------------|
    | Civil | |
    | Criminal | |
    | Completed (has permanent legal force) | |
    | In Process of Resolution | |
    | Total | |
    ITSK Providers must further explain the efforts to resolve legal issues by the ITSK Provider.
  7. Work Plan
  8. Annual Budget Plan
  1. Business Ethics
  2. Feasibility of Annual Business Plan
  3. Transparency of Financial and Non-Financial Conditions (adjusted to each ITSK Provider).
    -Brief description-
    -Brief description-
    -Brief description-
    -Brief description related to the business ethics values of the ITSK Provider that serve as a guide for the ITSK Provider's organs and all employees -

This copy conforms to the original
Head of Legal Development Directorate
Legal Department signed.
Aat Windradi
11. Implementation of control functions for personal data protection and information system security
Approved,
BOARD OF DIRECTORS
CHIEF EXECUTIVE SUPERVISOR OF FINANCIAL SECTOR TECHNOLOGY INNOVATION, DIGITAL FINANCIAL ASSETS AND CRYPTO ASSETS FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA, signed.
ADI BUDIARSO
-Brief description of the control function for personal data protection and information system security. Furthermore, ITSK Providers are requested to submit a brief description of the implementation of cybersecurity, which at least includes the responsibility structure, cybersecurity policies and procedures, results of periodic evaluations, material cyber incidents and their follow-up, access management, incident resilience and recovery, and data and information protection- -Brief description, for example: announcing annual reports (financial profiles) on the website, informing ITSK products and/or services, guided by the provisions of laws and regulations regarding consumer protection, and personal data protection, informing the implementation of Good Governance, at least disclosing all aspects of the implementation of Good Governance principles, and disclosure and form of accountability of ITSK Providers for the use of Consumer data in accordance with laws and regulations regarding personal data protection-

APPENDIX III
REGULATION OF THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA NUMBER 9 YEAR 2026 CONCERNING THE FORM AND STRUCTURE OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION PROVIDERS

SELF-ASSESSMENT OF GOOD GOVERNANCE IMPLEMENTATION FOR ITSK PROVIDERS The good governance implementation worksheet is filled out by the respective ITSK Provider. This worksheet is filled out by providing answers to the questions/statements in the said worksheet.

  1. Implementation of Duties and Authorities of Shareholders and GMS
    A. Assessment Worksheet
    | No. | Statement/Question | Indicator Value | Description |
    |-----|--------------------|-----------------|-------------|
    A. Governance Structure and Infrastructure (S)
    | 1. | a. Composition and requirements of shareholders comply with laws and regulations. | | |
    | --- | --- | --- | --- |
    | | b. Each PSP has been approved for capability and fitness assessment. | | |
    | 2. | Policies and procedures for decision-making through GMS are stated in the articles of association and are in line with laws and regulations. | | |
    B. Governance Implementation Process (P)
    | 3. | Communication of the vision and mission for the development of the ITSK Provider to the Board of Directors and/or Board of Commissioners. | | |
    | --- | --- | --- | --- |
    | 4. | Monitoring the development of the ITSK Provider through the results of the Board of Commissioners' supervision. | | |
    | 5. | Shareholder commitment in the operational development of the ITSK Provider through capital planning or other development support. | | |
    | 6. | Ensuring the implementation of sound governance, including avoiding Conflicts of Interest, intervention, taking personal gain or the interests of certain groups, and decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners. | | |
    | 7. | Decision-making through GMS considers, among others, input and recommendations from the Board of Commissioners, as well as input or opinions from all shareholders. | | |
    C. Governance Implementation Results (H)
    | 8. | Shareholders receive fair rights and treatment, including in the implementation of corporate actions. | | |
    | --- | --- | --- | --- |
    | 9. | The development of the ITSK Provider's performance is in line with the strategic plan, including through the realization of capital plans or other support plans. | | |
    | 10. | Shareholders do not engage in Conflicts of Interest, intervention, taking personal gain or the interests of certain groups, and decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners. | | |
    | 11. | The use of profit and dividend distribution considers profit utilization and dividend distribution policies that are in line with the articles of association and laws and regulations, and takes into account external and internal conditions. | | |
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring Shareholder Aspect Implementation governance is implemented very adequately, and is demonstrated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The shareholder structure complies with all provisions and governance implementation is very adequate, so there are no Conflicts of Interest, intervention, taking personal gain or the interests of certain groups, and/or decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners in accordance with laws and regulations. b. All corporate action policy decisions through GMS are in line with the articles of association, laws and regulations, and strategic plans, so that the ITSK Provider's development planning is fully realized, reflected in the fulfillment of capital provisions, financial performance, and/or the development of the ITSK Provider's business activities.
c. Profit utilization and dividend distribution policies have been evaluated periodically, so that all profit utilization and dividend distribution implementations are in accordance with the established policies.
Score 4 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the governance implementation process is carried out adequately, and is demonstrated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The shareholder structure complies with all provisions and governance implementation is adequate, so that Conflicts of Interest can be resolved, interventions that arise are not significant, personal gain or the interests of certain groups are not taken, and/or decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners are in accordance with laws and regulations. b. Most corporate action policy decisions through GMS are in line with the articles of association, laws and regulations, and strategic plans, so that most of the ITSK Provider's development planning is realized, reflected in the fulfillment of capital provisions, financial performance, and/or the development of the ITSK Provider's business activities.
c. Profit utilization and dividend distribution policies have been evaluated, so that most of the profit utilization and dividend distribution implementations are in accordance with the established policies.

Score 3 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the governance implementation process is carried out sufficiently adequately, and is demonstrated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The shareholder structure complies with all provisions and governance implementation is sufficiently adequate, so that Conflicts of Interest can be resolved, interventions that arise are not significant, personal gain or the interests of certain groups are not taken, and/or decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners are in accordance with laws and regulations. b. Some corporate action policy decisions through GMS are in line with the articles of association, laws and regulations, and strategic plans, so that the ITSK Provider's development planning has not been fully realized, reflected in the fulfillment of capital provisions, financial performance, and/or the development of the ITSK Provider's business activities.
c. Profit utilization and dividend distribution policies have been evaluated, so that some of the profit utilization and dividend distribution implementations are in accordance with the established policies.
Score 2 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not fully met, the governance implementation process is carried out inadequately, and is demonstrated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The shareholder structure complies with some provisions and governance implementation is inadequate, so that Conflicts of Interest cannot be adequately resolved, interventions that arise are quite significant, personal gain or the interests of certain groups are taken, and/or decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners are not sufficiently in accordance with laws and regulations. b. A small portion of corporate action policy decisions through GMS are in line with the articles of association, laws and regulations, and strategic plans, so that a small portion of the ITSK Provider's development planning is realized, reflected in the fulfillment of capital provisions, financial performance, and/or the development of the ITSK Provider's business activities.
c. Some profit utilization and dividend distribution policies have been evaluated, so that a small portion of the profit utilization and dividend distribution implementations are in accordance with the established policies.

Score 1 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not met, the governance implementation process is carried out inadequately, and is demonstrated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The shareholder structure does not comply with provisions and governance implementation is inadequate, so that Conflicts of Interest cannot be resolved, interventions that arise are significant, personal gain or the interests of certain groups are taken, and/or decisions on the appointment, replacement, or dismissal of members of the Board of Directors and/or Board of Commissioners are not in accordance with laws and regulations. b. Corporate action policy decisions are not made through GMS and are not in line with the articles of association, laws and regulations, and strategic plans, so that the ITSK Provider's development planning is not realized, reflected in the fulfillment of capital provisions, financial performance, and/or the development of the ITSK Provider's business activities.
c. Profit utilization and dividend distribution policies are not evaluated, so that the implementation of profit utilization and dividend distribution is not in accordance with the established policies.

  1. A. Implementation of Duties, Responsibilities, and Authorities of the Board of Directors
  1. Assessment Worksheet
    | No | Statement/Question | Indicator Value | Description |
    |----|--------------------|-----------------|-------------|
    A. Governance Structure and Infrastructure (S)
    | 1. | The number of members of the Board of Directors complies with the provisions of the Financial Services Authority and one member of the Board of Directors acts as the President Director. | | |
    | --- | --- | --- | --- |
    | 2. | The President Director resides in the territory of the Republic of Indonesia and at least 50% (fifty percent) of the members of the Board of Directors reside in Indonesia, in accordance with the provisions of the Financial Services Authority. | | |
    | 3. | Members of the Board of Directors do not hold concurrent positions in accordance with the provisions of the Financial Services Authority. | | |
    | 4. | All members of the Board of Directors meet the requirements related to share ownership, financial relationships, and family relationships as regulated in the provisions of the Financial Services Authority. | | |
    | 5. | The Board of Directors ensures the fulfillment of human resources and organizational structure, including having established functions (business, operational, risk management, AML CFT, legal and compliance, internal audit functions) adjusted to the complexity of ITSK to support the implementation of the duties and functions of the Board of Directors. | | |
    | 6. | The Board of Directors has guidelines and work procedures for members of the Board of Directors as regulated in the provisions of the Financial Services Authority and makes decisions in accordance with the guidelines and work procedures. | | |
    | 7. | Foreign national members of the Board of Directors have: a. limited stay permit card or permanent stay permit card from the authorized agency; b. work permit from the authorized agency; and; and c. other documents stipulated by the authorized authority in accordance with laws and regulations. | | |
    | 8. | The Board of Directors has competence in accordance with the provisions of the Financial Services Authority, and participates in training related to improving human resource capabilities, especially those related to ITSK, developments in the information technology industry, or LJK to be able to carry out the duties and responsibilities of the ITSK Provider. | | |
    B. Governance Implementation Process (P)
    | 9. | The Board of Directors: a. complies with laws and regulations, articles of association, and other internal regulations of the ITSK Provider in carrying out its duties; b. carries out duties with good faith, full responsibility, prudence, and independently; c. is accountable for the implementation of its duties to shareholders through the GMS; d. ensures that the ITSK Provider considers the interests of Consumers with good faith and prudence in accordance with laws and regulations, articles of association, and/or GMS decisions; e. ensures that information regarding the ITSK Provider is provided to the Board of Commissioners accurately, relevantly, and timely; f. implements the principles of governance, risk management, and compliance in an integrated manner; g. follows up on audit or examination findings (including findings of violations of laws and recurring findings) and recommendations from internal audit, external auditors, and the results of supervision by the Board of Commissioners, Financial Services Authority and/or other authorities; h. provides accurate, relevant, and timely data and information to parties entitled to obtain data and information in accordance with laws and regulations, including to the Board of Commissioners; i. manages data and information in accordance with Good Governance; j. assists and provides facilities and/or resources for the smooth implementation of the duties and authorities of the ITSK Provider's organs; k. communicates to all employees regarding the ITSK Provider's strategic policies that may affect the rights and obligations of employees in order to achieve the vision and mission of the ITSK Provider using media (electronic and non-electronic) that are easily accessible to all employees; l. does not grant general power of attorney that may result in the transfer of duties and authorities of the Board of Directors. | | |
    | --- | --- | --- | --- |
    | 10. | The Board of Directors holds Board of Directors meetings in accordance with the provisions of the Financial Services Authority, and strategic policies and decisions made in Board of Directors meetings consider the supervision of the Board of Commissioners and are first carried out through deliberation to reach a consensus. | | |
    | 11. | The Board of Directors: a. acts in the interest of the ITSK Provider and other Stakeholders and prioritizes the interests of the ITSK Provider and/or other Stakeholders over personal interests; b. does not use the ITSK Provider for personal, family, and/or other parties' interests that may harm or reduce the ITSK Provider's profit; c. does not take and/or receive personal gain from the ITSK Provider, other than remuneration and other facilities stipulated by the GMS. | | |
    | 12. | Members of the Board of Directors cultivate continuous learning in order to increase knowledge about ITSK and the latest developments related to finance and other fields that support the implementation of their duties and responsibilities. | | |
    | 13. | The Board of Directors discloses: a. share ownership in the respective ITSK Provider and other companies; and b. financial relationships and/or family relationships up to the second degree with members of the Board of Commissioners, other members of the Board of Directors and/or shareholders of the ITSK Provider. | | |
    | 14. | Members of the Board of Directors are able to maintain financial integrity and reputation and implement their competencies in carrying out their duties and responsibilities. | | |
    | 15. | The Board of Directors implements and evaluates the guidelines and work procedures for members of the Board of Directors consistently. | | |
    C. Governance Implementation Results (H)
    | 16. | The Board of Directors performs its duties well and has accounted for the implementation of its duties to shareholders through the GMS, and the Board of Directors submits reports related to governance implementation to parties as regulated in the provisions of the Financial Services Authority completely, accurately, currently, wholly, and timely. | | |
    | --- | --- | --- | --- |
    | 17. | All employees know and are involved in the implementation of strategic policies to achieve the vision and mission of the ITSK Provider. | | |
    | 18. | Board of Directors' decisions are binding and become the responsibility of all members of the Board of Directors. | | |
    | 19. | The results of Board of Directors meetings and dissenting opinions are recorded in the meeting minutes and well-documented, and distributed to all Board of Directors and followed up according to agreed commitments. | | |
    | 20. | There is an increase in the capabilities, experience, and expertise of members of the Board of Directors in managing the ITSK Provider and an increase in knowledge at all levels or organizational tiers, demonstrated by, among others, an increase in individual performance, an increase in ITSK Provider performance, resolution of issues faced by the ITSK Provider, and achievement of results according to stakeholder expectations. | | |
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

  2. Guidance on Scoring the Performance of Duties, Responsibilities, and Authorities of the Board of Directors

Governance is carried out very adequately, and is demonstrated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Directors fulfills all requirements that must be met during their tenure in accordance with the provisions, so that duties and responsibilities are carried out with good faith, full responsibility, prudence, and independence, and the performance results of the Board of Directors can be fully accounted for to shareholders through the General Meeting of Shareholders (GMS). b. The Board of Directors has fulfilled human resources and organizational structure, including forming functions with quantity and quality in accordance with the provisions, considering the complexity of business activities in order to support the implementation of the Board of Directors' duties and functions, so that the conduct of business activities at all organizational levels has fully implemented governance principles.
c. The Board of Directors has and regularly updates guidelines and a code of conduct for Board of Directors members, so that the execution of duties and strategic decision-making in Board of Directors meetings is carried out with due regard to the guidelines and code of conduct.
d. The Board of Directors has the willingness and ability, as well as efforts to cultivate regular and continuous learning, resulting in increased knowledge, expertise, and capabilities. e. The Board of Directors, in accordance with their duties and responsibilities, follows up on all audit or examination findings, and recommendations from work units or officials responsible for internal audit, external auditors, and the results of supervision by the Board of Commissioners, the Financial Services Authority, and/or other authorities, so that there are no similar findings and/or recurring findings.

Score 4 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out adequately, and is demonstrated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Directors fulfills all requirements that must be met during their tenure in accordance with the provisions, so that duties and responsibilities are carried out well, but there are insignificant weaknesses in duties and responsibilities that can be immediately rectified, and the performance results of the Board of Directors can be accounted for to shareholders through the GMS. b. The Board of Directors has fulfilled human resources and organizational structure, including forming functions with quantity and quality in accordance with the provisions in order to support the implementation of the Board of Directors' duties and functions, so that the conduct of business activities at all organizational levels has implemented governance principles well.
c. The Board of Directors has and updates guidelines and a code of conduct for Board of Directors members, so that the execution of duties and strategic decision-making in Board of Directors meetings is carried out with due regard to the guidelines and code of conduct.
d. The Board of Directors has the willingness and ability, as well as efforts to cultivate regular learning, resulting in increased knowledge, expertise, and capabilities. e. The Board of Directors, in accordance with their duties and responsibilities, has followed up on all audit or examination findings, and recommendations from work units or officials responsible for internal audit, external auditors, and the results of supervision by the Board of Commissioners, the Financial Services Authority, and/or other authorities, but there are administrative findings.

Score 3 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out sufficiently adequately, and is demonstrated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Directors fulfills all requirements that must be met during their tenure in accordance with the provisions, so that duties and responsibilities are carried out sufficiently well, but there are weaknesses in duties and responsibilities that can be rectified, and the performance results of the Board of Directors can be accounted for to shareholders through the GMS. b. The Board of Directors has fulfilled human resources and organizational structure, including forming work units with quantity and quality in accordance with the provisions in order to support the implementation of the Board of Directors' duties and functions, so that the conduct of business activities at all organizational levels has implemented governance principles sufficiently well.
c. The Board of Directors has guidelines and a code of conduct for Board of Directors members, so that the execution of duties and strategic decision-making in Board of Directors meetings is carried out with due regard to the guidelines and code of conduct.
d. The Board of Directors has the willingness and ability, as well as efforts to cultivate learning, resulting in increased knowledge, expertise, and capabilities. e. The Board of Directors, in accordance with their duties and responsibilities, has followed up on all audit or examination findings, and recommendations from work units or officials responsible for internal audit, external auditors, and the results of supervision by the Board of Commissioners, the Financial Services Authority, and/or other authorities, but there are recurring administrative findings.

Score 2 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not fully met, the governance implementation process is carried out inadequately, and is demonstrated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Directors fulfills only some of the requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities is not carried out well, and the performance results of the Board of Directors cannot be fully accounted for to shareholders through the GMS. b. The Board of Directors does not fulfill human resources and organizational structure, including the formation of functions with quantity and quality that are not in accordance with the provisions, thus inadequately supporting the implementation of the Board of Directors' duties and functions, so that the conduct of business activities at all organizational levels does not fully implement governance principles.
c. The Board of Directors has guidelines and a code of conduct for Board of Directors members, but the scope is not in accordance with the provisions, so that the execution of duties and strategic decision-making in Board of Directors meetings is not carried out well.
d. The Board of Directors lacks the willingness and ability, as well as efforts to cultivate continuous learning, so that there is no increase in knowledge, expertise, and capabilities. e. The Board of Directors has followed up on some audit or examination findings, and recommendations from functions responsible for internal audit, external audit, and the results of supervision by the Board of Commissioners, the Financial Services Authority, and/or other authorities, so that there are substantive findings and/or recurring substantive findings.

Score 1 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not met, the governance implementation process is carried out inadequately, and is demonstrated by very poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Directors does not fulfill all requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities is not carried out well, and the performance results of the Board of Directors cannot be accounted for to shareholders through the GMS. b. The Board of Directors does not fulfill human resources and organizational structure, including not forming functions in accordance with the provisions in order to support the implementation of the Board of Directors' duties and functions, so that governance principles cannot be implemented in the conduct of business activities at all organizational levels.
c. The Board of Directors does not have guidelines and a code of conduct for Board of Directors members, so that the execution of duties and strategic decision-making in Board of Directors meetings cannot be carried out well.
d. The Board of Directors does not have the willingness and ability, as well as efforts to cultivate continuous learning, so that there is no increase in knowledge, expertise, and capabilities. e. The Board of Directors does not follow up on all audit or examination findings, and recommendations from functions responsible for internal audit, external auditors, and the results of supervision by the Board of Commissioners, the Financial Services Authority, and/or other authorities, so that there are substantive findings and/or recurring substantive findings.

B. Performance of Duties, Responsibilities, and Authorities of the Board of Commissioners

  1. Assessment Worksheet
NoStatement/QuestionIndicator ScoreRemarks
A. Governance Structure and Infrastructure (S)
1.The number of Board of Commissioners members is in accordance with the provisions of the Financial Services Authority or at most equal to the number of Board of Directors members.
2.Foreign national Board of Commissioners members domiciled in Indonesia have work permits from the authorized agency.
3.The Board of Commissioners does not hold dual positions, in accordance with the provisions of the Financial Services Authority.
4.All Board of Commissioners members meet the requirements related to share ownership, financial relationships, and family relationships as stipulated in the provisions of the Financial Services Authority.
5.The Board of Commissioners:
a. has guidelines and a code of conduct that are binding on each member of the Board of Commissioners as stipulated in the provisions of the Financial Services Authority;
b. has competencies as stipulated in the provisions of the Financial Services Authority; and
c. participates in training related to improving the human resource capabilities of ITSK Providers in achieving the vision and mission of ITSK Providers.
B. Governance Implementation Process (P)
6.The Board of Commissioners:
a. carries out supervisory duties and provides advice to the Board of Directors;
b. carries out duties, authorities, and responsibilities with good faith and the principle of prudence;
c. supervises the management policy and the general course of management carried out by the Board of Directors for the interests of the ITSK Provider and in accordance with the purpose and objectives of the ITSK Provider;
d. prepares a Board of Commissioners' activity report which is part of the Good Governance implementation report;
e. directs, monitors, and evaluates the effectiveness of the implementation of Good Governance, Risk Management, compliance, and internal audit;
f. ensures that the Board of Directors has followed up on audit or examination findings and recommendations from the ITSK Provider's internal audit, external auditors, the results of supervision by the Financial Services Authority, and/or the results of supervision by other authorities and institutions; and
g. ensures effective, precise, fast decision-making and acts independently in carrying out duties;
h. complies with laws and regulations, articles of association, and other internal regulations of the ITSK Provider in carrying out its duties.
7.The Board of Commissioners holds regular Board of Commissioners meetings, and decision-making in Board of Commissioners meetings has been carried out first through deliberation to reach consensus in accordance with the Board of Commissioners' guidelines and code of conduct. (with the number of meetings included in the governance report)
8.The Board of Commissioners:
a. holds joint meetings with the Board of Directors at least 1 (one) time every 3 (three) months.
b. provides strategic policies and decisions in Board of Commissioners meetings with the Board of Directors, considering the supervision of the Board of Commissioners and carried out first through deliberation to reach consensus.
c. may request the Board of Directors to provide explanations regarding problems, performance, and operational policies of the ITSK Provider.
9.The Board of Commissioners:
a. consistently implements and evaluates the guidelines and code of conduct for Board of Commissioners members;
b. carries out duties and responsibilities optimally in accordance with the guidelines and code of conduct;
c. and makes Board of Commissioners decisions in accordance with the guidelines and code of conduct.
10.The Board of Commissioners:
a. does not use the ITSK Provider for personal interests, family, and/or other parties that could harm or reduce the profits of the ITSK Provider;
b. does not take and/or receive personal profit from the ITSK Provider, other than remuneration and other facilities determined by the GMS;
c. is able to maintain financial integrity and reputation.
11.The Board of Commissioners:
a. cultivates continuous learning in order to increase knowledge about ITSK and the latest developments related to supervision and other fields that support the implementation of their duties and responsibilities;
b. implements their competencies in the execution of duties and responsibilities.
12.The Board of Commissioners discloses:
a. share ownership in the relevant ITSK Provider and/or in other companies located domestically and abroad; and
b. financial relationships of Board of Directors members and Board of Commissioners members with other Board of Directors members, other Board of Commissioners members, shareholders of the ITSK Provider and/or employees of the ITSK Provider where Board of Directors members and Board of Commissioners members serve; and
c. family relationships of Board of Directors members and Board of Commissioners members with other Board of Directors members, other Board of Commissioners members, shareholders of the ITSK Provider, and/or employees of the ITSK Provider where Board of Directors members and Board of Commissioners members serve up to the second degree, both horizontal and vertical.
C. Governance Implementation Results (H)
13.The Board of Commissioners:
a. performs duties well and has accounted for the performance of duties to shareholders through the GMS;
b. submits reports related to the Board of Commissioners' functions to the Financial Services Authority as stipulated in the provisions of the Financial Services Authority completely, accurately, up-to-date, wholly, and on time.
14.The results of Board of Commissioners meetings and dissenting opinions are recorded in meeting minutes and well-documented, and are distributed to all Board of Commissioners members and followed up according to agreed commitments.
15.There is an increase in the capabilities, experience, and expertise of Board of Commissioners members in carrying out their supervisory duties and responsibilities for the ITSK Provider, demonstrated, among others, by improved individual performance, improved ITSK Provider performance, resolution of problems faced by the ITSK Provider, and achievement of results according to stakeholder expectations.

Positive Factors
Contains a summary of positive factors from key factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
c. Results (H)

Negative Factors
Contains a summary of negative factors from key factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
c. Results (H)

  1. Guidance on Scoring the Performance of Duties, Responsibilities, and Authorities of the Board of Commissioners

Governance is carried out very adequately, and is demonstrated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Commissioners fulfills all requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities, including decision-making, is carried out very well, and the performance results of the Board of Commissioners can be fully accounted for to shareholders through the GMS. b. The Board of Commissioners has and regularly updates guidelines and a code of conduct for Board of Commissioners members, so that the execution of duties and decision-making in Board of Commissioners meetings is carried out with due regard to the guidelines and code of conduct.
c. The Board of Commissioners has the willingness and ability, as well as efforts to cultivate regular and continuous learning, resulting in increased knowledge, expertise, and capabilities.

Score 4 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out adequately, and is demonstrated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Commissioners fulfills all requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities, including decision-making, is carried out well, and the performance results of the Board of Commissioners can be accounted for to shareholders through the GMS. b. The Board of Commissioners has and updates guidelines and a code of conduct for Board of Commissioners members, so that the execution of duties and decision-making in Board of Commissioners meetings is carried out with due regard to the guidelines and code of conduct.
c. The Board of Commissioners has the willingness and ability, as well as efforts to cultivate regular learning, resulting in increased knowledge, expertise, and capabilities.

Score 3 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out sufficiently adequately, and is demonstrated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Commissioners fulfills all requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities, including decision-making, is carried out sufficiently well, and the performance results of the Board of Commissioners can be accounted for to shareholders through the GMS. b. The Board of Commissioners has guidelines and a code of conduct for Board of Commissioners members, so that the execution of duties and decision-making in Board of Commissioners meetings is carried out with due regard to the guidelines and code of conduct.
c. The Board of Commissioners has the willingness and ability, as well as efforts to cultivate learning, resulting in increased knowledge, expertise, and capabilities.

Score 2 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not fully met, the governance implementation process is carried out inadequately, and is demonstrated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Commissioners fulfills only some of the requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities, including decision-making, is carried out inadequately, and the performance results of the Board of Commissioners cannot be fully accounted for to shareholders through the GMS. b. The Board of Commissioners has guidelines and a code of conduct for Board of Commissioners members, but the scope is not in accordance with the provisions, so that the execution of duties and decision-making in Board of Commissioners meetings is not carried out well.
c. The Board of Commissioners lacks the willingness and ability, as well as efforts to cultivate regular learning, so that there is no increase in knowledge, expertise, and capabilities.

Score 1 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not met, the governance implementation process is carried out inadequately, and is demonstrated by very poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The Board of Commissioners does not fulfill all requirements that must be met during their tenure in accordance with the provisions, so that the execution of duties and responsibilities, including decision-making, is not carried out well, and the performance results of the Board of Commissioners cannot be accounted for to shareholders through the GMS. b. The Board of Commissioners does not have guidelines and a code of conduct for Board of Commissioners members, so that the execution of duties and decision-making in Board of Commissioners meetings cannot be carried out well.
c. The Board of Commissioners does not have the willingness and ability, as well as efforts to cultivate regular learning, so that there is no increase in knowledge, expertise, and capabilities.

  1. Application of Risk Management

A. Assessment Worksheet

No.Statement/QuestionIndicator ScoreRemarks
A. Governance Structure and Infrastructure (S)
1.The ITSK Provider has a risk management function in accordance with the provisions of the Financial Services Authority.
2.The ITSK Provider has and updates risk management policies, risk management procedures, and risk limit setting.
3.The ITSK Provider has and updates written policies and procedures regarding the management of risks inherent in new products and activities in accordance with applicable regulations.
B. Governance Implementation Process (P)
4.The risk management function is carried out effectively in accordance with the objectives, business policies, type, and capabilities of the ITSK Provider, in accordance with policies and procedures based on the provisions of the Financial Services Authority.
5.The ITSK Provider implements governance, risk management, and compliance in an integrated manner, supported by necessary policies or procedures.
6.The ITSK Provider implements risk management for all required risks in accordance with the provisions of the Financial Services Authority.
7.The ITSK Provider has an adequate information system, namely a management information system capable of providing complete, accurate, up-to-date, and whole data and information.
8.The ITSK Provider implements risk management by:
a. identifying, assessing, monitoring, and managing risks effectively;
b. considering the adequacy of policies in risk management;
c. considering procedures in risk management;
d. considering the setting of risk limits in risk management;
e. considering the adequacy of identification processes in risk management;
f. considering measurement in risk management;
g. considering risk monitoring and control.

No. Statement/Question Indicator Value Description
9. ITSK Providers implement a comprehensive internal control system.
10. The Board of Directors has developed a risk management culture at all organizational levels and enhanced human resource competence, including through training and/or socialization on risk management.
C. Good Governance Implementation Results (H)
11. ITSK Providers prepare risk profile reports and other risk profiles (if any) which are reported to the Financial Services Authority in accordance with the provisions of the Financial Services Authority, and are able to maintain and improve risk profiles in order to support better risk management implementation.
12. The risk management information system presents reports or information covering:
a. Risk exposure; b. compliance with the adequacy of Risk Management policies and Risk Management procedures as well as the setting of Risk limits; and
c. realization of Risk Management implementation compared to established targets.
Positive Factors
Contains a summary of positive factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
c. Results (H)
Negative Factors
Contains a summary of negative factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
c. Results (H)

B. Guidelines for Scoring Risk Management Implementation good governance is implemented very adequately, and is indicated by very good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. ITSK Providers meet all requirements related to functions responsible for risk management implementation, including anti-fraud programs, anti-money laundering, and prevention of terrorism financing functions as regulated in the Financial Services Authority Regulations and statutory provisions, and the implementation of risk management functions is carried out well so that:

  1. risk rating is very low;
  2. no fraud exists; and/or
  3. anti-money laundering and prevention of terrorism financing program rating is very low.
    b. ITSK Providers have and regularly update risk management guidelines, risk management procedures, risk limit setting, and written policy procedures regarding the management of risks inherent in new products and activities with a very adequate scope, and risk management implementation considers these guidelines and policies.
    c. All duties and functions of the Board of Directors and Board of Commissioners regarding risk management implementation are carried out in accordance with statutory provisions and guidelines, including developing a risk management culture at all organizational levels and enhancing human resource competence.
    Score 4 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out adequately, and is indicated by good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
    a. ITSK Providers meet all requirements related to functions responsible for risk management implementation, including anti-fraud programs, anti-money laundering, and prevention of terrorism financing functions as regulated in the Financial Services Authority Regulations and statutory provisions, and the implementation of risk management functions is carried out well so that:
  4. risk rating is low;
  5. no fraud exists; and/or
  6. anti-money laundering and prevention of terrorism financing program rating is low.
    b. ITSK Providers have and update risk management guidelines, risk management procedures, risk limit setting, and written policy procedures regarding the management of risks inherent in new products and activities with an adequate scope, and risk management implementation considers these guidelines and policies.
    c. Most of the duties and functions of the Board of Directors and Board of Commissioners regarding risk management implementation are carried out in accordance with statutory provisions and guidelines, including developing a risk management culture at most organizational levels and enhancing human resource competence.
    Score 3 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
    a. ITSK Providers meet all requirements related to functions responsible for risk management implementation, including anti-fraud programs, anti-money laundering, and prevention of terrorism financing functions as regulated in the Financial Services Authority Regulations and statutory provisions, and the implementation of risk management functions is carried out sufficiently well so that:
  7. risk rating is moderate;
  8. no fraud exists; and/or
  9. anti-money laundering and prevention of terrorism financing program rating is low.
    b. ITSK Providers have risk management guidelines, risk management procedures, risk limit setting, and written policy procedures regarding the management of risks inherent in new products and activities with a sufficiently adequate scope, and risk management implementation considers these guidelines and policies.
    c. Some of the duties and functions of the Board of Directors and Board of Commissioners regarding risk management implementation are carried out in accordance with statutory provisions and guidelines, including developing a risk management culture at some organizational levels and enhancing human resource competence.
    Score 2 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not fully met, the good governance implementation process is carried out inadequately, and is indicated by poor good governance implementation results. Examples/illustrations of conditions that can be indicators include:
    a. ITSK Providers meet some requirements related to functions responsible for risk management implementation, including anti-fraud programs, anti-money laundering, and prevention of terrorism financing functions as regulated in the Financial Services Authority Regulations and statutory provisions, and the implementation of risk management functions is carried out poorly so that:
  10. risk rating is high;
  11. fraud exists; and/or
  12. anti-money laundering and prevention of terrorism financing program rating is high.
    b. ITSK Providers have risk management guidelines, risk management procedures, risk limit setting, and written policy procedures regarding the management of risks inherent in new products and activities with an inadequately adequate scope, and risk management implementation inadequately considers these guidelines and policies.
    c. A small part of the duties and functions of the Board of Directors and Board of Commissioners regarding risk management implementation are carried out in accordance with statutory provisions and guidelines, including developing a risk management culture at a small number of organizational levels and enhancing human resource competence.
    Score 1 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not met, the good governance implementation process is carried out inadequately, and is indicated by poor good governance implementation results. Examples/illustrations of conditions that can be indicators include:
    a. ITSK Providers do not meet the requirements related to functions responsible for risk management implementation, including anti-fraud programs, anti-money laundering, and prevention of terrorism financing functions as regulated in the Financial Services Authority Regulations and statutory provisions, and the implementation of risk management functions is carried out poorly so that:
  13. risk rating is very high;
  14. fraud exists; and/or
  15. anti-money laundering and prevention of terrorism financing program rating is very high.
    b. ITSK Providers do not have risk management guidelines, risk management procedures, risk limit setting, and written policy procedures regarding the management of risks inherent in new products and activities, so risk management implementation does not consider guidelines and policies.
    c. All duties and functions of the Board of Directors and Board of Commissioners regarding risk management implementation are not carried out in accordance with statutory provisions and guidelines, including not developing a risk management culture at all organizational levels and not enhancing human resource competence.
  1. Internal Audit Function Implementation
    A. Assessment Worksheet
    No. Statement/Question Indicator Value Description A. Good Governance Structure and Infrastructure (S)
  2. ITSK Providers have an internal audit function in accordance with Financial Services Authority provisions.
  3. The internal audit function has and updates its guidelines and work procedures in accordance with Financial Services Authority provisions and has been approved by the President Director and Board of Commissioners.
  4. The internal audit function is directly responsible to the Board of Directors.
  5. ITSK Providers have provided human resources with adequate quantity and quality for the internal audit function to effectively complete tasks.
    B. Good Governance Implementation Process (P)
  6. ITSK Providers implement the internal audit function in accordance with the internal audit guidelines prepared by the ITSK Provider and Financial Services Authority provisions across all aspects and elements of activities directly estimated to affect the interests of the ITSK Provider and the public.
  7. ITSK Providers assign external parties to conduct a review containing opinions on the internal audit function's work results and its compliance with internal audit function implementation standards.
  8. The implementation of the internal audit function (audit activities) is carried out independently and adequately, covering audit preparation, audit program development, audit execution, audit results reporting, and follow-up on audit results.
  9. ITSK Providers carry out periodic and continuous improvement of human resource skills related to the implementation of the internal audit function.
  10. The internal audit function prepares and realizes annual audit program plans.
  11. The internal audit function assists the Board of Directors and Board of Commissioners in supervising the operational activities of ITSK Providers, especially in monitoring audit results.
    No. Statement/Question Indicator Value Description
  12. The internal audit function performs analysis and assessment in the areas of finance, accounting, operations, and other activities.
  13. The internal audit function provides improvement suggestions and objective information about audited activities at all management levels.
  14. The internal audit function documents evidence from tests and audits already conducted by the internal audit function, including information systems and technology audits.
    C. Good Governance Implementation Results (H)
  15. ITSK Providers present annual audit program plans and realizations as requested by the Financial Services Authority.
  16. ITSK Providers submit reports related to the implementation of the internal audit function to the Financial Services Authority as regulated in Financial Services Authority provisions, completely, accurately, currently, wholly, and on time.
    Positive Factors
    Contains a summary of positive factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring Internal Audit Function Implementation good governance is implemented very adequately, and is indicated by very good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The internal audit function meets all requirements that must be fulfilled during its tenure in accordance with provisions, so that the execution of duties and responsibilities runs very well and the performance results of the internal audit function can be fully accounted for to the Board of Directors, and reports are submitted completely, accurately, currently, wholly, and on time. b. The internal audit function has and regularly updates its guidelines and work procedures so that the execution of duties is carried out in consideration of these guidelines and work procedures. Score 4 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out adequately, and is indicated by good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The internal audit function meets all requirements that must be fulfilled during its tenure in accordance with provisions, so that the execution of duties and responsibilities runs well and the performance results of the internal audit function can be accounted for to the Board of Directors, and reports are submitted completely, accurately, currently, wholly, and on time. b. The internal audit function has and updates its guidelines and work procedures so that the execution of duties is carried out in consideration of these guidelines and work procedures. Score 3 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The internal audit function meets all requirements that must be fulfilled during its tenure in accordance with provisions, so that the execution of duties and responsibilities runs sufficiently well and the performance results of the internal audit function can be accounted for to the President Director, and reports are submitted completely, accurately, currently, wholly, and on time. b. The internal audit function has guidelines and work procedures so that the execution of duties is carried out in consideration of these guidelines and work procedures. Score 2 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not fully met, the good governance implementation process is carried out inadequately, and is indicated by poor good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The internal audit function meets some requirements that must be fulfilled during its tenure in accordance with provisions, so that the execution of duties and responsibilities runs poorly and the performance results of the internal audit function cannot be fully accounted for to the Board of Directors, and reports are submitted incompletely, inaccurately, not currently, not wholly, and beyond the deadline. b. The internal audit function has guidelines and work procedures, but their scope is not yet in accordance with provisions, so the execution of duties is not carried out well. Score 1 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not met, the good governance implementation process is carried out inadequately, and is indicated by poor good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The internal audit function does not meet the requirements that must be fulfilled during its tenure in accordance with provisions, so that the execution of duties and responsibilities does not run well and the performance results of the internal audit function cannot be accounted for to the President Director, and reports are submitted incompletely, inaccurately, not currently, not wholly, and beyond the deadline. b. The internal audit function does not have guidelines and work procedures, so the execution of duties cannot be carried out well.

  1. External Audit Implementation
    A. Assessment Worksheet
    No. Statement/Question Indicator Value Desc.
    A. Good Governance Structure and Infrastructure (S)
  2. The audit engagement with public accountants and public accounting firms (KAP) has met aspects of work agreement legality, audit scope, public accountant professional standards, audit completion target time, communication between the Financial Services Authority and KAP, and considered the adequate competence of the KAP (including public accountants).
  3. The appointed public accountants and KAP have competence in accordance with the business complexity of the ITSK Provider.
    B. Good Governance Implementation Process (P)
  4. In conducting the audit of the ITSK Provider's financial statements, the ITSK Provider appoints public accountants and KAP registered with the Financial Services Authority and obtains approval from the GMS based on the proposal of the Board of Commissioners.
  5. ITSK Providers provide all accounting records and data required for external audit.
  6. ITSK Providers have reported the KAP audit results and management letter to the Financial Services Authority on time.
  7. External auditors are independent.
    C. Good Governance Implementation Results (H)
  8. Audit results and management letters have described the ITSK Provider's problems and presented transparent and quality financial information.
  9. The scope of audit results is at least in accordance with the audit scope as per Financial Services Authority provisions.
    Positive Factors
    Contains a summary of positive factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring External Audit Function Implementation Score 5 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out very adequately, and is indicated by very good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
The audit engagement with Public Accountants and KAP has met all requirements as regulated in Financial Services Authority provisions and statutory provisions, so that the audit results of Public Accountants and KAP and the management letter are submitted completely, accurately, currently, wholly, and on time, and the audit results describe all problems of the ITSK Provider. Score 4 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out adequately, and is indicated by good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
The audit engagement with Public Accountants and KAP has met all requirements as regulated in Financial Services Authority provisions and statutory provisions, but the audit results of Public Accountants and KAP and the management letter are submitted completely, accurately, currently, wholly, and on time, however, the audit results only describe most of the problems of the ITSK Provider. Score 3 If the conditions for fulfilling the structure and/or infrastructure according to provisions are met, the good governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good good governance implementation results. Examples/illustrations of conditions that can be indicators include:
The audit engagement with Public Accountants and KAP has met all requirements as regulated in Financial Services Authority provisions and statutory provisions, but the audit results of Public Accountants and KAP and the management letter are submitted sufficiently completely, accurately, currently, wholly, and on time, so that the audit results describe some of the problems of the ITSK Provider. Score 2 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not fully met, the good governance implementation process is carried out inadequately, and is indicated by poor good governance implementation results. Examples/illustrations of conditions that can be indicators include:
The audit engagement with Public Accountants and KAP only meets some requirements as regulated in Financial Services Authority provisions and statutory provisions, and the audit results of Public Accountants and KAP and the management letter are submitted incompletely, inaccurately, not currently, not wholly, and beyond the deadline, so that the audit results do not fully describe the problems of the ITSK Provider. Score 1 If the conditions for fulfilling the structure and/or infrastructure according to provisions are not met, the good governance implementation process is carried out inadequately, and is indicated by poor good governance implementation results. Examples/illustrations of conditions that can be indicators include:
The audit engagement with Public Accountants and KAP does not meet the requirements as regulated in Financial Services Authority provisions and statutory provisions, and the audit results of Public Accountants and KAP and the management letter are submitted incompletely, inaccurately, not currently, not wholly, and beyond the deadline, and the audit results do not describe the problems of the ITSK Provider.

  1. Conflict of Interest Handling
    A. Assessment Worksheet
    No. Statement/Question Indicator Value Description A. Good Governance Structure and Infrastructure (S)
  2. ITSK Providers have a Conflict of Interest policy aimed at identifying, reducing, and managing potential Conflicts of Interest that may arise within the ITSK Provider due to the execution of the ITSK Provider's business activities, which is stipulated in regulations.
    B. Good Governance Implementation Process (P)
  3. Members of the Board of Directors, Board of Commissioners, and employees of ITSK Providers avoid all forms of Conflicts of Interest in carrying out their duties of managing and supervising ITSK Providers.
  4. Members of the Board of Directors, Board of Commissioners, and employees of ITSK Providers do not take actions that could potentially harm the ITSK Provider or reduce the ITSK Provider's profits.
    C. Good Governance Implementation Results (H)
  5. Members of the Board of Directors, Board of Commissioners, and employees of ITSK Providers disclose Conflicts of Interest in every decision that meets the conditions of a Conflict of Interest to the Financial Services Authority.
  6. ITSK Providers disclose to the Financial Services Authority transactions of the ITSK Provider that have potential Conflicts of Interest with other ITSK Providers.
    Positive Factors
    Contains a summary of positive factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from key factors that have a significant impact on good governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring Conflict of Interest Handling Governance is carried out very adequately, and is indicated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and regularly updates a Conflict of Interest policy with a very adequate scope. b. There are no transactions that have a Conflict of Interest.
c. The performance of duties, functions, and authorities of the Board of Directors, Board of Commissioners, and employees of the ITSK Provider related to handling Conflicts of Interest is carried out very well.
Score 4 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out adequately, and is indicated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and updates a Conflict of Interest policy with an adequate scope, and has successfully handled Conflicts of Interest well in accordance with the policy. b. There are no transactions that have a Conflict of Interest, and if there is a Conflict of Interest, it is handled well and does not cause losses or reduce the profits of the ITSK Provider, is fully disclosed in every decision, and has been very well documented.
c. The performance of duties, functions, and authorities of the Board of Directors, Board of Commissioners, and employees of the ITSK Provider related to handling Conflicts of Interest is carried out well.
Score 3 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has a Conflict of Interest policy with a sufficiently adequate scope, and the handling of Conflicts of Interest is carried out sufficiently well in accordance with the policy. b. There are Conflicts of Interest that have not been fully handled and cause losses or reduce the profits of the ITSK Provider, are fully disclosed in every decision, and have been well documented.
c. The performance of duties, functions, and authorities of the Board of Directors, Board of Commissioners, and employees of the ITSK Provider related to handling Conflicts of Interest is carried out sufficiently well.
Score 2 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not fully met, the governance implementation process is carried out less adequately, and is indicated by less good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has a Conflict of Interest policy with a less adequate scope, so the handling of Conflicts of Interest is less successful. b. There are Conflicts of Interest that have not been fully handled and cause losses or reduce the profits of the BPR, are partially disclosed in every decision, and are less well documented.
c. The performance of duties, functions, and authorities of the Board of Directors, Board of Commissioners, and employees of the ITSK Provider related to handling Conflicts of Interest is carried out less well.
Score 1 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not met, the governance implementation process is carried out inadequately, and is indicated by not good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider does not have a Conflict of Interest policy, so the handling of Conflicts of Interest is unsuccessful. b. All Conflicts of Interest are not handled and cause losses or reduce the profits of the ITSK Provider, are not disclosed in every decision, and are not documented.
c. The performance of duties, functions, and authorities of the Board of Directors, Board of Commissioners, and employees of the ITSK Provider related to handling Conflicts of Interest is carried out not well.

  1. Information Disclosure
    A. Assessment Worksheet
    No. Statement/Question Indicator Score Remarks A. Governance Structure and Infrastructure (S)
  2. The ITSK Provider has procedures and methods for information disclosure and the appointment, dismissal, replacement, and/or resignation of members of the Board of Directors, members of the Board of Commissioners.
    B. Governance Implementation Process (P)
  3. The appointment and/or replacement of members of the Board of Directors and/or members of the Board of Commissioners prioritizes professional composition, independence, competency suitability, and considers diversity, which is appropriately needed in the performance of duties and responsibilities of members of the Board of Directors, and/or members of the Board of Commissioners.
  4. The dismissal or replacement of members of the Board of Directors, and/or members of the Board of Commissioners, prioritizes the primary interests of the ITSK Provider.
  5. The dismissal or replacement of members of the Board of Directors and/or members of the Board of Commissioners carried out before the end of the term of office of members of the Board of Directors, and/or members of the Board of Commissioners, is due to members of the Board of Directors and/or members of the Board of Commissioners:
    a. being deemed unable to carry out duties and responsibilities in the management and implementation of sound ITSK Provider strategies; b. not being based on subjective assessment by shareholders, but based on objective assessment related to the management of the ITSK Provider;
    c. the dismissal or replacement of members of the Board of Directors has gone through planning and applicable mechanisms (which at least consider the assessment from members of the Board of Commissioners for the dismissal or replacement of the Board of Directors) and has been agendaed in the GMS;
    d. due to information that members of the Board of Directors are included in prohibited parties as main parties determined by the authorized authority.
  6. The ITSK Provider appoints a replacement for members of the Board of Directors and/or members of the Board of Commissioners, in the event of:
    a. dismissal of members of the Board of Directors and/or members of the Board of Commissioners; b. permanent incapacitation;
    c. resignation,
    which results in the number of members of the Board of Directors and/or members of the Board of Commissioners being less than the minimum number of members of the Board of Directors and/or members of the Board of Commissioners.
    C. Governance Implementation Results (H)
  7. The ITSK Provider discloses:
    a. share ownership of members of the Board of Directors and members of the Board of Commissioners reaching 5% (five percent) or more in the ITSK Provider where the members of the Board of Directors and members of the Board of Commissioners serve and/or in other companies domiciled domestically and abroad; b. financial relationships of members of the Board of Directors and members of the Board of Commissioners with other members of the Board of Directors, other members of the Board of Commissioners, shareholders of the ITSK Provider, and/or employees of the ITSK Provider where the members of the Board of Directors and members of the Board of Commissioners serve;
    c. family relationships of members of the Board of Directors and members of the Board of Commissioners with other members of the Board of Directors, other members of the Board of Commissioners, shareholders of the ITSK Provider, and/or employees of the ITSK Provider where the members of the Board of Directors and members of the Board of Commissioners serve up to the second degree, both horizontal and vertical; and
    d. remuneration and facilities received by members of the Board of Directors and members of the Board of Commissioners, in the Good Governance implementation report.
  8. Members of the Board of Directors and/or members of the Board of Commissioners who resign from their positions before the end of their term of office submit written notification to the ITSK Provider.
  9. External auditors who resign submit written notification to the ITSK Provider.
  10. The ITSK Provider discloses to the Financial Services Authority (OJK) regarding:
    a. Resignation of the Board of Directors and/or members of the Board of Commissioners. b. dismissal of members of the Board of Directors and/or members of the Board of Commissioners.
    c. resignation of the external auditor.
    d. dismissal of the external auditor.
  11. The ITSK Provider carries out the orders of the Financial Services Authority (OJK) to conduct evaluations and corrective actions regarding decisions on dismissal, replacement, and/or resignation of members of the Board of Directors and/or members of the Board of Commissioners carried out before the end of the term of office of members of the Board of Directors and/or members of the Board of Commissioners.
  12. The ITSK Provider appoints a replacement for members of the Board of Directors, and/or members of the Board of Commissioners, no later than 6 (six) months from the date of dismissal of members of the Board of Directors and/or members of the Board of Commissioners.
  13. The ITSK Provider appoints a replacement for members of the Board of Directors and/or members of the Board of Commissioners, no later than 6 (six) months from when members of the Board of Directors and/or members of the Board of Commissioners become permanently incapacitated.
  14. The ITSK Provider appoints a replacement for members of the Board of Directors and/or members of the Board of Commissioners, no later than 6 (six) months from when members of the Board of Directors and/or members of the Board of Commissioners resign.
  15. The Board of Commissioners reports to the Financial Services Authority (OJK) no later than 10 (ten) working days since the discovery of:
    a. violations of financial sector laws and regulations and related ITSK Providers; and b. conditions or anticipated conditions that could endanger the business continuity of the ITSK Provider.
  16. The ITSK Provider discloses to the Financial Services Authority (OJK) regarding:
    a. resignation or dismissal of the external auditor; b. material transactions with affiliated parties;
    c. ongoing and/or potential Conflicts of Interest; and
    d. other material information regarding the ITSK Provider, in the Good Governance implementation report.
  17. The ITSK Provider provides complete and timely data and information to the Financial Services Authority (OJK).
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring Information Disclosure Governance is carried out very adequately, and is indicated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and regularly updates complete information disclosure procedures and methods in accordance with Financial Services Authority (OJK) regulations and consistently applied to all business activities of the ITSK Provider in accordance with laws and regulations. b. The ITSK Provider submits all material and relevant information to the Financial Services Authority (OJK) completely, accurately, currently, wholly, easily understandable, and on time in accordance with laws and regulations.
c. The ITSK Provider provides and/or opens access to all systems used to the Financial Services Authority (OJK) in accordance with laws and regulations.
Score 4 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out adequately, and is indicated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and updates information disclosure procedures and methods in accordance with Financial Services Authority (OJK) regulations and most of them have been consistently applied to the business activities of the ITSK Provider in accordance with laws and regulations. b. Most material and relevant information has been submitted to the Financial Services Authority (OJK) completely, accurately, currently, wholly, easily understandable, and on time in accordance with laws and regulations, but there are still insignificant administrative weaknesses that can be immediately rectified.
c. The ITSK Provider has provided and/or opened access to most of the systems used to the Financial Services Authority (OJK) in accordance with laws and regulations.
Score 3 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has information disclosure procedures and methods in accordance with Financial Services Authority (OJK) regulations, but not all of them have been updated or consistently applied to the business activities of the ITSK Provider in accordance with laws and regulations. b. Some material and relevant information has been submitted to the Financial Services Authority (OJK) sufficiently completely, accurately, currently, wholly, easily understandable, and on time in accordance with laws and regulations, but there are still shortcomings that require improvement.
c. The ITSK Provider has provided and/or opened access to certain systems used to the Financial Services Authority (OJK), but it has not been done optimally in accordance with laws and regulations.
Score 2 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not fully met, the governance implementation process is carried out less adequately, and is indicated by less good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider only partially fulfills the provisions related to information disclosure procedures and methods, so its implementation is less consistent in the business activities of the ITSK Provider. b. Material and relevant information submitted to the Financial Services Authority (OJK) is less complete, less accurate, not current, not whole, less easily understandable, and/or exceeds the time limit set in accordance with laws and regulations.
c. The ITSK Provider only provides and/or opens access to a small portion of the systems used to the Financial Services Authority (OJK), thereby hindering the effectiveness of supervision implementation in accordance with laws and regulations.
Score 1 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not met, the governance implementation process is carried out inadequately, and is indicated by not good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider does not have information disclosure procedures and methods in accordance with Financial Services Authority (OJK) regulations or does not apply them in the business activities of the ITSK Provider. b. Material and relevant information is not submitted to the Financial Services Authority (OJK) or is submitted incompletely, inaccurately, not currently, not wholly, not easily understandable, and not on time, thus not in accordance with laws and regulations.
c. The ITSK Provider does not provide and/or does not open access to the systems used to the Financial Services Authority (OJK), thereby hindering the implementation of regulatory, supervisory, examination, and/or oversight functions in accordance with laws and regulations.

  1. Business Ethics
    A. Assessment Worksheet
    No. Statement/Question Indicator Score Remarks A. Governance Structure and Infrastructure (S)
  2. The ITSK Provider develops guidelines on ethical behavior, which include business ethics values, as a guide for all employees of the ITSK Provider.
    B. Governance Implementation Process (P)
  3. The ITSK Provider does not take actions aimed at exploiting loopholes in regulations or business ethics that are not in line with the principles of sound ITSK Provider management, which can increase risk for the ITSK Provider, and/or generate unreasonable profits.
  4. Members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider do not offer or give anything, directly or indirectly, to other parties, to influence decision-making related to the business activities of the ITSK Provider, in violation of laws and regulations.
  5. Members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider do not accept anything for personal, family, and/or other parties' interests in violation of laws and regulations, directly or indirectly, from anyone, that could influence decision-making related to the business activities of the ITSK Provider.
    C. Governance Implementation Results (H)
  6. The ITSK Provider does not violate guidelines on ethical behavior, including business ethics values, in carrying out business activities.
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring Business Ethics Implementation Governance is carried out very adequately, and is indicated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and regularly updates complete guidelines on ethical behavior, including business ethics values, in accordance with laws and regulations and consistently applied at all organizational levels. b. The ITSK Provider does not take actions aimed at exploiting loopholes in regulations or business ethics that are not in line with the principles of sound ITSK Provider management, thereby not increasing risk for the ITSK Provider and/or generating unreasonable profits.
c. Members of the Board of Directors, members of the Board of Commissioners, and employees of the ITSK Provider do not offer, give, receive, or obtain anything, directly or indirectly, that could influence decision-making related to the ITSK Provider's business activities in violation of laws and regulations.
d. There are no violations of ethical behavior guidelines and business ethics values in the implementation of the ITSK Provider's business activities.
Score 4 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out adequately, and is indicated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and updates guidelines on ethical behavior, including business ethics values, in accordance with laws and regulations and most of them have been consistently applied at all organizational levels. b. The ITSK Provider generally does not take actions aimed at exploiting loopholes in regulations or business ethics that are not in line with the principles of sound ITSK Provider management.
c. There are no significant violations related to offering or receiving anything that could influence decision-making related to the ITSK Provider's business activities, but there are still administrative weaknesses that can be immediately rectified.
d. There are administrative and insignificant ethical violations that have been properly followed up.
Score 3 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are met, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has guidelines on ethical behavior and business ethics values, but not all of them have been updated or consistently applied at all organizational levels. b. There are still actions that exploit loopholes in certain regulations or business ethics but have not yet caused a significant impact on the ITSK Provider.
c. There are certain violations related to offering or receiving anything that could influence decision-making related to the ITSK Provider's business activities, but they have been disclosed and followed up.
d. There are violations of ethical behavior guidelines and business ethics values that are limited in nature and corrective actions have been taken.
Score 2 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not fully met, the governance implementation process is carried out less adequately, and is indicated by less good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider only partially fulfills the provisions related to ethical behavior guidelines and business ethics values, so its implementation is less effective. b. There are actions that exploit loopholes in regulations or business ethics that are not in line with the principles of sound ITSK Provider management, thereby increasing risk and/or providing unreasonable profits.
c. There are violations related to offering or receiving anything that could influence decision-making related to the ITSK Provider's business activities and its handling has not been adequately performed.
d. There are violations of ethical behavior guidelines and business ethics values that impact the business activities of the ITSK Provider.
Score 1 If the conditions for fulfilling the structure and/or infrastructure in accordance with the provisions are not met, the governance implementation process is carried out inadequately, and is indicated by not good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider does not have guidelines on ethical behavior and business ethics values in accordance with laws and regulations or does not apply them in the business activities of the ITSK Provider. b. The ITSK Provider takes actions aimed at exploiting loopholes in regulations or business ethics that are not in line with the principles of sound ITSK Provider management, thereby increasing risk and/or generating unreasonable profits.
c. Members of the Board of Directors, members of the Board of Commissioners, and/or employees of the ITSK Provider offer, give, receive, or obtain anything, directly or indirectly, that influences decision-making related to the ITSK Provider's business activities in violation of laws and regulations.
d. There are significant violations of ethical behavior guidelines and business ethics values that cause negative impacts on the ITSK Provider, consumers, and/or other Stakeholders.

  1. Annual Business Plan Eligibility
    A. Assessment Worksheet
    No. Statement/Question Indicator Value Description A. Governance Structure and Infrastructure (S)
  2. The ITSK Provider's business plan has been prepared by the Board of Directors and approved by the Board of Commissioners in accordance with the ITSK Provider's vision and mission.
  3. The ITSK Provider's business plan describes the ITSK Provider's business activities plan for a period of 1 (one) year, including plans to improve business performance and strategies to realize these plans according to established targets and timelines, while still considering the fulfillment of risk management and prudence principles.
  4. The ITSK Provider's business plan is fully supported by shareholders in order to strengthen capital and adequate infrastructure, including human resources, information technology, office networks, policies, and procedures.
  5. The ITSK Provider's business plan is prepared based on a comprehensive study, taking into account business opportunities and strengths possessed by the ITSK Provider, and identifying weaknesses and threats (Strength, Weakness, Opportunity, Threat/SWOT Analysis);
  6. The ITSK Provider's business plan must be supported by adequate infrastructure preparation, including human resources, information technology, office networks, and policies and procedures.
    B. Governance Implementation Process (P)
    No. Statement/Question Indicator Value Description
  7. The ITSK Provider's business plan describes the sustainable growth of the ITSK Provider.
    C. Governance Implementation Results (H)
  8. The business plan, including changes to the business plan, is submitted to the Financial Services Authority in accordance with the provisions of the Financial Services Authority.
  9. Financial and non-financial performance indicators in the business plan are achieved according to established targets, including the realization of shareholder commitments.
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on the implementation of governance. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on the implementation of governance. a. Structure (S) b. Process (P)
    c. Results (H)

B. Annual Business Plan Scoring Guidelines governance is carried out very adequately, and is indicated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider's business plan has been prepared realistically, comprehensively, and measurably (achievable) by the Board of Directors and approved by the Board of Commissioners in accordance with the ITSK Provider's vision and mission, and describes long-term strategic plans and annual business plans and is realized in accordance with planning so that financial and non-financial performance indicators in the business plan are achieved beyond the established targets, including the submission of business plan reports completely, accurately, currently, wholly, and on time. b. The ITSK Provider's business plan that has been prepared is supported by shareholders, as indicated by the fulfillment of all commitments in order to strengthen capital and infrastructure. Score 4 If the conditions for fulfilling the structure and/or infrastructure according to regulations are met, the governance implementation process is carried out adequately, and is indicated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider's business plan has been prepared realistically, comprehensively, and measurably (achievable) by the Board of Directors and approved by the Board of Commissioners in accordance with the ITSK Provider's vision and mission, and describes long-term strategic plans and annual business plans and is realized in accordance with planning so that financial and non-financial performance indicators in the business plan are achieved according to established targets, including the submission of business plan reports completely, accurately, currently, wholly, and on time. b. The ITSK Provider's business plan that has been prepared is supported by shareholders, as indicated by the fulfillment of most commitments in order to strengthen capital and infrastructure. Score 3 If the conditions for fulfilling the structure and/or infrastructure according to regulations are met, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider's business plan has been prepared realistically, comprehensively, and measurably (achievable) by the Board of Directors and approved by the Board of Commissioners in accordance with the ITSK Provider's vision and mission, and describes long-term strategic plans and annual business plans and most of it is realized in accordance with planning so that financial and non-financial performance indicators in the business plan are partially achieved according to established targets, including the submission of business plan reports completely, accurately, currently, wholly, and on time. b. The ITSK Provider's business plan that has been prepared is supported by shareholders, but the fulfillment of commitments in order to strengthen capital and infrastructure is only partially carried out. Score 2 If the conditions for fulfilling the structure and/or infrastructure according to regulations are not fully met, the governance implementation process is carried out less adequately, and is indicated by less good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider's business plan has not been fully prepared realistically, comprehensively, and measurably (achievable) by the Board of Directors and approved by the Board of Commissioners, and less describes long-term strategic plans and annual business plans and is realized less in accordance with planning so that financial and non-financial performance indicators in the business plan do not achieve the established targets, including business plan reports not being fully submitted completely, accurately, currently, wholly, and on time. b. The ITSK Provider's business plan that has been prepared is not fully supported by shareholders, as indicated by the fulfillment of only a small portion of commitments in order to strengthen capital and infrastructure. Score 1 If the conditions for fulfilling the structure and/or infrastructure according to regulations are not met, the governance implementation process is carried out inadequately, and is indicated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider's business plan is not prepared realistically, comprehensively, and measurably (achievable) by the Board of Directors and approved by the Board of Commissioners, and does not describe long-term strategic plans and annual business plans and is not realized in accordance with planning so that financial and non-financial performance indicators in the business plan do not achieve the established targets, including the submission of business plan reports incompletely, inaccurately, not currently, not wholly, and exceeding the deadline. b. The ITSK Provider's business plan that has been prepared is not supported by shareholders, as indicated by no fulfillment of commitments in order to strengthen capital and infrastructure.

  1. Transparency of Financial and Non-Financial Conditions
    A. Assessment Worksheet
    No. Statement/Question Indicator Value Description A. Governance Structure and Infrastructure (S)
  2. Announce annual reports openly and easily accessible through the ITSK Provider's official website.
  3. Information regarding ITSK products and/or services is conveyed clearly, accurately, and not misleadingly through the website and/or application, by disclosing the benefits, risks, costs, and terms of use of ITSK Products and/or Services and guided by the provisions of laws and regulations regarding consumer protection, and personal data protection.
  4. Inform the implementation of Good Governance principles, at least covering transparency, accountability, responsibility, independence, and fairness.
  5. Explanation of the purpose, legal basis, and mechanism for utilizing Consumer data.
  6. Disclosure of the types of Consumer data collected and utilized by the ITSK Provider and the submission of the ITSK Provider's form of accountability for the utilization of Consumer data.
  7. Compliance with the provisions of laws and regulations regarding personal data protection, including consent mechanisms and fulfillment of Consumer rights.
    B. Governance Implementation Process (P)
  8. Implementation of internal review and approval mechanisms for ITSK Product and/or Service information materials before publication.
  9. Consumers can easily access complete information regarding ITSK Provider products and/or services.
  10. Establishment of policies for managing and utilizing Consumer data in accordance with the provisions of laws and regulations regarding personal data protection.
    C. Governance Implementation Results (H)
  11. Improved quality of ITSK Provider management oriented towards business sustainability.
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on the implementation of governance. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on the implementation of governance. a. Structure (S) b. Process (P)
    c. Results (H)

B. Transparency of Financial and Non-Financial Conditions Scoring Guidelines governance is carried out very adequately, and is indicated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider announces annual reports and provides financial and/or non-financial condition information completely, accurately, currently, wholly, easily understandable, easily accessible, and on time through its official website and/or other media in accordance with the provisions of laws and regulations. b. Information regarding ITSK products and/or services, including benefits, risks, costs, and terms of use of products and/or services, is conveyed very clearly, accurately, not misleadingly, in accordance with provisions regarding consumer protection and personal data protection.
c. The ITSK Provider discloses the implementation of Good Governance principles, including accountability for the utilization of Consumer data, very transparently in accordance with the provisions of laws and regulations.
d. There are no violations related to misleading information, or significant complaints related to information transparency and Consumer data utilization.
Score 4 If the conditions for fulfilling the structure and/or infrastructure according to regulations are met, the governance implementation process is carried out adequately, and is indicated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. Most annual reports and financial and/or non-financial condition information have been announced and provided completely, accurately, currently, wholly, easily understandable, easily accessible, and on time in accordance with the provisions of laws and regulations, but there are still insignificant administrative weaknesses. b. Information regarding ITSK products and/or services, including benefits, risks, costs, and terms of use of products and/or services, is conveyed clearly enough and not misleadingly in accordance with provisions regarding consumer protection and personal data protection.
c. The ITSK Provider discloses the implementation of Good Governance principles, including accountability for the utilization of Consumer data, transparently enough in accordance with the provisions of laws and regulations.
d. There are no significant violations related to information transparency and Consumer data utilization, but there are still administrative complaints that have been followed up well.
Score 3 If the conditions for fulfilling the structure and/or infrastructure according to regulations are met, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. Annual reports and financial and/or non-financial condition information have been announced and provided, but there are still deficiencies in terms of completeness, currency, ease of access, or timeliness of information submission. b. Information regarding ITSK products and/or services has been conveyed, but there is still information that is less clear or does not fully comply with provisions regarding consumer protection and personal data protection.
c. The ITSK Provider discloses the implementation of Good Governance principles and accountability for the utilization of Consumer data transparently but not optimally and consistently in accordance with the provisions of laws and regulations.
d. There are violations or complaints or certain weaknesses related to information transparency and Consumer data utilization that have been followed up but are not yet fully effective.
Score 2 If the conditions for fulfilling the structure and/or infrastructure according to regulations are not fully met, the governance implementation process is carried out less adequately, and is indicated by less good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. Annual reports and financial and/or non-financial condition information are only partially announced or provided, so the information conveyed is less complete, less accurate, difficult to understand, difficult to access, and/or not on time. b. Information regarding ITSK products and/or services is conveyed less clearly and/or potentially misleading, so it does not fully comply with provisions regarding consumer protection and personal data protection.
c. Disclosure of the implementation of Good Governance principles and accountability for the utilization of Consumer data has not been carried out adequately in accordance with the provisions of laws and regulations.
d. There are significant violations or complaints related to information transparency and Consumer data utilization that have not been adequately followed up.
Score 1 If the conditions for fulfilling the structure and/or infrastructure according to regulations are not met, the governance implementation process is carried out inadequately, and is indicated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider does not announce annual reports and does not provide financial and/or non-financial condition information in accordance with the provisions of laws and regulations or provides information incompletely, inaccurately, misleadingly, and not on time. b. Information regarding ITSK products and/or services is conveyed unclearly and/or potentially misleading or does not comply with provisions regarding consumer protection and personal data protection.
c. The ITSK Provider does not disclose the implementation of Good Governance principles and accountability for the utilization of Consumer data transparently in accordance with the provisions of laws and regulations.
d. There are significant violations, misleading information, and/or material complaints related to information transparency and Consumer data utilization that impact consumers or other Stakeholders.

  1. Implementation of Control Functions for Personal Data Protection and Information System Security
    A. Assessment Worksheet
    No. Statement/Question Indicator Value Ket
    A. Governance Structure and Infrastructure (S)
  2. Availability of written policies and procedures for information systems.
  3. Use of secure and reliable systems, at least:
    a. security and protection of data confidentiality; b. model development;
    c. fulfillment of certification, security standards, and/or system reliability; and
    d. maintenance and improvement of technology security;
  4. Implement cybersecurity standards, data and information security, and conduct regular, comprehensive information system audits, and apply prudence principles.
  5. Implement personal data protection principles in accordance with the provisions of laws and regulations regarding personal data protection.
    B. Governance Implementation Process (P)
  6. Review and periodic updating of written policies and procedures for information systems in accordance with developments in risks, technology, and laws and regulations, and the implementation of monitoring and follow-up on information system audit findings as part of strengthening internal controls.
  7. Implementation of mechanisms for identification, protection, detection, mitigation, and recovery of cyber incidents.
  8. Security of storage, processing, transmission, and destruction of data and information.
    C. Governance Implementation Results (H)
  9. Ensured clarity of roles, responsibilities, and authorities in information system management.
  10. Protection of confidentiality, integrity, and availability of data in the use of information systems and follow-up on audit findings for improvement and strengthening of information system controls.
  11. Effective implementation of identification, protection, detection, mitigation, and recovery of cyber incidents.
    Positive Factors
    Contains a summary of positive factors from the main factors that have a significant impact on the implementation of governance. a. Structure (S) b. Process (P)
    c. Results (H)
    Negative Factors
    Contains a summary of negative factors from the main factors that have a significant impact on the implementation of governance. a. Structure (S) b. Process (P)
    c. Results (H)

B. Guidelines for Scoring the Implementation of Control Functions for Personal Data Protection and Information System Security governance is carried out very adequately, and is indicated by very good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and periodically updates complete, documented written policies and procedures for information systems, in accordance with laws and regulations, and consistently applied to all business activities. b. The ITSK Provider implements data security and protection, as well as maintenance and improvement of technology security effectively and sustainably, so that data confidentiality, integrity, and availability are very well maintained.
c. The ITSK Provider implements cyber protection mechanisms, including identification, protection, detection, mitigation, and recovery of cyber incidents effectively and continuously.
d. The ITSK Provider monitors and follows up on information system audit results periodically and comprehensively, and there are no significant violations, data breaches, material information system disruptions, or non-compliance with personal data protection and information system security provisions. Score 4 If the conditions for fulfilling the structure and/or infrastructure according to regulations are met, the governance implementation process is carried out adequately, and is indicated by good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has and updates written policies and procedures for information systems in accordance with laws and regulations and most of them have been consistently applied. b. The ITSK Provider has implemented data security, cybersecurity standards, and information system management well, so that data confidentiality, integrity, and availability are generally maintained.
c. The ITSK Provider has implemented cyber protection mechanisms, including identification, protection, detection, mitigation, and recovery of cyber incidents well, although there are still insignificant administrative weaknesses that can be immediately corrected.
d. The ITSK Provider has monitored and followed up on information system audit results periodically and there are no significant violations or material disruptions to information system security.
Score 3 If the conditions for fulfilling the structure and/or infrastructure according to regulations are met, the governance implementation process is carried out sufficiently adequately, and is indicated by sufficiently good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider has written policies and procedures for information systems, but not all of them have been updated or consistently applied in accordance with developments in risks, technology, and laws and regulations. b. The ITSK Provider has implemented data security, cybersecurity standards, and information system management, but there are still certain weaknesses that require improvement.
c. The ITSK Provider has implemented cyber protection mechanisms, including identification, protection, detection, mitigation, and recovery of cyber incidents, but not optimally.
d. The ITSK Provider monitors and follows up on information system audit results, but there are still certain system disruptions, complaints, or weaknesses that require further strengthening.
Score 2 If the conditions for fulfilling the structure and/or infrastructure according to regulations are not fully met, the governance implementation process is carried out less adequately, and is indicated by less good governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider only fulfills some provisions related to information system policies and procedures, so their implementation is less effective. b. The ITSK Provider implements data security, cybersecurity standards, and information system controls less adequately, thereby increasing the risk of system disruptions or data breaches.
c. The ITSK Provider has implemented cyber protection mechanisms, including identification, protection, detection, mitigation, and recovery of cyber incidents, but they are not yet effective.
Score 1 If the conditions for fulfilling the structure and/or infrastructure according to regulations are not met, the governance implementation process is carried out inadequately, and is indicated by poor governance implementation results. Examples/illustrations of conditions that can be indicators include:
a. The ITSK Provider does not have written policies and procedures for information systems, or they are not implemented at all, or they are not in accordance with laws and regulations. b. The ITSK Provider does not implement data security, cybersecurity standards, and information system controls, or they are implemented very poorly, thereby causing significant system disruptions or data breaches.
c. The ITSK Provider does not implement cyber protection mechanisms, including identification, protection, detection, mitigation, and recovery of cyber incidents, or they are implemented very poorly, thereby causing significant cyber incidents.
d. The ITSK Provider does not monitor and follow up on information system audit results, or there are significant and recurring system disruptions, data breaches, or non-compliance with personal data protection and information system security provisions that are not followed up.

d. There are violations, information system disruptions, or specific security weaknesses that impact the operations of FSTI Providers or the protection of Consumers' personal data.
Score 1 If the conditions for structure and/or infrastructure are not met according to regulations, the governance implementation process is inadequate, and the results of governance implementation are poor. Examples/illustrations of conditions that can be indicators include:
a. FSTI Providers do not have written information system policies and procedures in accordance with statutory provisions or do not implement them in the business activities of FSTI Providers. b. FSTI Providers do not adequately implement data security, cybersecurity standards, and information system controls, so the confidentiality, integrity, and availability of data are not guaranteed.
c. FSTI Providers do not adequately implement cyber protection mechanisms, including identification, protection, detection, mitigation, and recovery of cyber incidents.
d. There are significant violations, data breaches, material information system disruptions, and/or non-compliance with personal data protection and information system security provisions that impact FSTI Providers, Consumers, or other Stakeholders.

This copy is in accordance with the original
Head of Legal Development Directorate
Legal Department signed
Aat Windradi
RECAPITULATION OF SCORES AND FINAL CONCLUSION OF GOVERNANCE ASSESSMENT

FactorTotal Indicator ScoreNumber of QuestionsWeight (%)Factor Score
1.115.00
2.a2015.00
2.b1515.00
3.129.00
4.155.00
5.85.00
6.510.00
7.165.00
8.59.00
9.82.00
10.105.00
11.1015.00
Total Governance Score
Governance Rating
Final Conclusion
Contains the final conclusion of the governance implementation assessment linked to the definition of the rating score.
Positive Factors
Contains a summary of positive factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
c. Results (H)
Negative Factors
Contains a summary of negative factors from the main factors that have a significant impact on governance implementation. a. Structure (S) b. Process (P)
c. Results (H)
Approved by,
BOARD OF DIRECTORS
CHIEF EXECUTIVE OF SUPERVISION OF FINANCIAL SECTOR TECHNOLOGY INNOVATION, DIGITAL FINANCIAL ASSETS AND CRYPTO ASSETS, FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA, signed ADI BUDIARSO

APPENDIX IV
REGULATION OF THE BOARD OF COMMISSIONERS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
NUMBER 9 YEAR 2026
CONCERNING
FORM AND STRUCTURE OF THE GOOD GOVERNANCE IMPLEMENTATION REPORT FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION PROVIDERS

This copy is in accordance with the original
Head of Legal Development Directorate
Legal Department signed
Aat Windradi
ACTION PLAN

No.WeaknessCorrective ActionTarget Completion TimeCompletion ObstaclesRemarks
1.
2.
3.
Etc.
Approved by,
BOARD OF DIRECTORS
CHIEF EXECUTIVE OF SUPERVISION OF FINANCIAL SECTOR TECHNOLOGY INNOVATION, DIGITAL FINANCIAL ASSETS AND CRYPTO ASSETS, FINANCIAL SERVICES AUTHORITY OF THE REPUBLIC OF INDONESIA, signed ADI BUDIARSO

Sign in to read the rest — it's free

Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document

Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from OJK

OJK published 2 documents in the last 30 days. We email you each new one the day it's published.