2021-08-26 | 23/SEOJK.04/2021Added · Updated
Securities companies acting as underwriters and/or securities trading intermediaries that are stock exchange members must submit a self-assessment report on risk management implementation at least once a year, with a reporting position date of December 31. The report, which must include inherent risk and risk management quality values, must be submitted electronically via the OJK's data communication system or email no later than February 28. If technical failures occur, a hardcopy report signed by the Director overseeing risk management must be submitted by the next business day.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
Directors and Board of Commissioners of Securities Companies conducting business as Underwriters of Securities Issues and/or Securities Trading Intermediaries that are Members of the Stock Exchange,
At your offices.
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 23 /SEOJK.04/2021
REGARDING
THE FORM, STRUCTURE, AND SUBMISSION PROCEDURES FOR SELF-ASSESSMENT REPORTS ON THE IMPLEMENTATION OF RISK MANAGEMENT BY SECURITIES COMPANIES CONDUCTING BUSINESS AS UNDERWRITERS OF SECURITIES ISSUES AND SECURITIES TRADING INTERMEDIARIES THAT ARE MEMBERS OF THE STOCK EXCHANGE
In relation to the provisions of Article 19 paragraph (4) of Financial Services Authority Regulation Number 6/POJK.04/2021 concerning the Implementation of Risk Management for Securities Companies Conducting Business as Underwriters of Securities Issues and Securities Trading Intermediaries that are Members of the Stock Exchange (State Gazette of the Republic of Indonesia Year 2021 Number 80, Supplement to the State Gazette of the Republic of Indonesia Number 6670), it is necessary to regulate provisions regarding the form, structure, and submission procedures for self-assessment reports on the implementation of risk management by securities companies conducting business as underwriters of securities issues and securities trading intermediaries that are members of the stock exchange as follows:
I. GENERAL PROVISIONS
a. Securities Company is a party that conducts business as an underwriter of securities issues, a securities trading intermediary, and/or an investment manager. b. Underwriter of Securities Issues is a party that enters into a contract with an issuer to conduct a public offering for the benefit of the issuer with or without the obligation to purchase unsold securities.
c. Securities Trading Intermediary is a party that conducts business buying and selling securities for its own benefit or for the benefit of other parties.
d. Risk Management is a series of methodologies and procedures used to identify, measure, monitor, and control risks arising from all business activities of Securities Companies. e. Inherent Risk is risk inherent in the activities of Underwriters of Securities Issues and/or Securities Trading Intermediaries that are members of the stock exchange, which has the potential to affect their business activities. f. Board of Directors is the organ of the Securities Company authorized and fully responsible for managing the Securities Company for the benefit of the Securities Company, in accordance with the purpose and objectives of the Securities Company, and representing the Securities Company, both in and out of court, in accordance with the provisions of the Articles of Association. g. Board of Commissioners is the organ of the Securities Company tasked with conducting general and/or specific supervision in accordance with the Articles of Association and providing advice to the Board of Directors.
II. FORM AND STRUCTURE OF SECURITIES COMPANY SELF-ASSESSMENT
The self-assessment report on the implementation of Risk Management contains the following information:
a. The value of each Inherent Risk indicator; b. The value of each Inherent Risk parameter;
c. The Inherent Risk value;
d. The value of each Risk Management indicator; e. The value of each Risk Management parameter; and f. The Risk Management value.
The self-assessment report on the implementation of Risk Management is prepared and signed by the director overseeing the Risk Management function and acknowledged by the Board of Commissioners.
The self-assessment report of the Securities Company is prepared by referring to the format and technical guidelines contained in the Appendix, which is an integral part of this Financial Services Authority Circular Letter.
In the event of changes to the indicators and parameters for the implementation of Risk Management as referred to in paragraph 1, the Financial Services Authority may adjust the format of the self-assessment report.
Changes as referred to in paragraph 4 are established through a letter from the Financial Services Authority.
III. SUBMISSION PROCEDURES FOR SECURITIES COMPANY SELF-ASSESSMENT REPORTS
Securities Companies are required to prepare a self-assessment of the implementation of Risk Management at least once (1) per year for the position as of December 31.
Securities Companies are required to submit the self-assessment report as referred to in paragraph 1 to the Financial Services Authority no later than February 28.
Securities Companies must submit the self-assessment report on the implementation of Risk Management to the Financial Services Authority online through the Financial Services Authority's data communication network system.
In the event that the Financial Services Authority's data communication network system is not yet available, the self-assessment report on the implementation of Risk Management is submitted online via the official email of the Securities Company by attaching a softcopy of the self-assessment report on the implementation of Risk Management to the email address bppe@ojk.go.id.
In the event of technical disruptions in the process of submitting the self-assessment report on the implementation of Risk Management to the Financial Services Authority online through:
a. the Financial Services Authority's data communication network system as referred to in paragraph 2; or b. email as referred to in paragraph 3, the submission of the self-assessment report on the implementation of Risk Management is done in the form of a computer printout (hardcopy) no later than the next business day.
The submission of the self-assessment report on the implementation of Risk Management as referred to in paragraph 4 is done through a letter signed by the Director overseeing the Risk Management function.
In the event that the Director overseeing the Risk Management function as referred to in paragraph 5 is unable to do so, the submission of the self-assessment report on the implementation of Risk Management may be done through a letter signed by another member of the Board of Directors.
Securities Companies are deemed to have submitted the self-assessment report on the implementation of Risk Management with the following conditions:
a. for online submission through the Financial Services Authority's data communication network system, proven by a receipt from the Financial Services Authority; b. for online submission via email, proven by an email receipt from the Financial Services Authority; or
c. for submission via computer printout (hardcopy), proven by a receipt from the Financial Services Authority.
If the deadline for submitting the self-assessment report in the form of a computer printout (hardcopy) as referred to in paragraph 4 falls on a holiday, the submission deadline is the next business day.
IV. CLOSING PROVISIONS
This Financial Services Authority Circular Letter takes effect on the date it is established.
Established in Jakarta on August 26, 2021
EXECUTIVE HEAD OF CAPITAL MARKET SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA,
Signed,
HOSEN
APPENDIX
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 23 /SEOJK.04/2021
REGARDING
THE FORM, STRUCTURE, AND SUBMISSION PROCEDURES FOR SELF-ASSESSMENT REPORTS ON THE IMPLEMENTATION OF RISK MANAGEMENT BY SECURITIES COMPANIES CONDUCTING BUSINESS AS UNDERWRITERS OF SECURITIES ISSUES AND SECURITIES TRADING INTERMEDIARIES THAT ARE MEMBERS OF THE STOCK EXCHANGE
i
OPERATIONAL RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION .......................................................................... 1
CHAPTER II FUNDAMENTAL CONCEPTS OF OPERATIONAL RISK
CHAPTER I
INTRODUCTION
technological developments have led to an increase in the complexity of business activities of Stock Exchange Member Securities Companies, while simultaneously increasing the risks of Stock Exchange Member Securities Companies. This requires Stock Exchange Member Securities Companies to implement Risk Management properly in accordance with the characteristics and complexity of their business. Failure of Stock Exchange Member Securities Companies to conduct Risk Management can cause significant losses and can even disrupt the continuity of the business of Stock Exchange Member Securities Companies.
Operational risk is risk caused by inadequate or non-functional internal processes, human error, system failures, and/or the occurrence of external events that affect the operations of Securities Companies. Operational risk can cause financial losses directly or indirectly (direct or indirect loss) and losses from the loss of opportunity to obtain profits (opportunity cost).
In the context of preparing self-assessment reports, it is necessary to provide guidance for Stock Exchange Member Securities Companies in assessing operational risk. The assessment of operational risk by Stock Exchange Member Securities Companies contains the basic principles for conducting operational risk management assessments, including assessments of Inherent Risk and the quality of operational risk management implementation.
CHAPTER II
FUNDAMENTAL CONCEPTS OF OPERATIONAL RISK
This section outlines the fundamental concepts of operational risk management to facilitate Stock Exchange Member Securities Companies in assessing operational risk. The fundamental concepts of operational risk include: (1) sources, types/types of events, and impacts of operational risk (2) dimensions of assessment of Operational Inherent Risk, and (3) the interrelationship of operational risk with other risks.
The sources, types/types of events, and impacts of operational risk that have a negative impact on Stock Exchange Member Securities Companies are explained in Table 1 below:
Table 1. Sources, Events, and Impacts of Operational Risk
| Source | Event | Impact |
|---|
Business Complexity
Human Resources
Information Technology
External Factors
Complexity of Products and Transactions
Complexity of Trading Service Offerings
Customer Complexity
Unbalanced employee workload due to inefficient work processes
Human Error
Fraud
System failure when forwarding trading orders
Systems unable to support business complexity
Systems can still be intervened manually
Unstable network availability
Possibility of systems accessed by unauthorized parties.
Business Disruption
Regulatory Violations
Loss Compensation
Loss/Damage of Assets
Reputation
Legal
| Source | Event | Impact |
|---|
The following is an explanation of the sources of operational risk, types of operational risk events, and impacts of operational risk events found in Table 1:
a. Sources of Operational Risk
Sources of operational risk can be caused by, among others, business complexity (process), human resources (people), information technology (system), and external factors (external events), which can be explained as follows:
Business complexity (process)
The design and implementation of business processes regarding business complexity in Stock Exchange Member Securities Companies can become a source of operational risk. Weaknesses in complexity processes include ineffective organizational structures, inappropriate workload distribution, overlapping business functions, and other process-related aspects, resulting in inefficient and ineffective business processes that fail to achieve the objectives of Stock Exchange Member Securities Companies.
Human resources (people)
Human Resources (HR) can become a source of operational risk in the form of HR's inability to perform tasks in accordance with established functional tasks and work processes, causing errors that have a negative impact on the business of Stock Exchange Member Securities Companies and can cause losses.
Information technology (system)
Systems can become a source of operational risk considering that Stock Exchange Member Securities Companies use information technology on a large scale (IT-extensive). In addition to information technology, systems in this context also include supporting infrastructure used by Stock Exchange Member Securities Companies in conducting business. Weaknesses in information technology and supporting infrastructure will disrupt the operational continuity of Stock Exchange Member Securities Companies on a large scale and can cause losses to Stock Exchange Member Securities Companies.
External factors (external events)
External events can become sources of operational risk because Stock Exchange Member Securities Companies are exposed to various external factors in conducting their business. Types of external events such as natural disasters, crime, and socio-political conditions can disrupt the operations of Stock Exchange Member Securities Companies and cause losses.
b. Operational Risk Events
The aforementioned sources of risk can cause events that have a negative impact on the operations of Stock Exchange Member Securities Companies (operational risk events), so that the types of operational risk events are a measure of the success or failure of operational risk management, depending on whether the types of operational risk events decrease or increase significantly.
The indicators/types of operational risk events for Stock Exchange Member Securities Companies are as follows:
Complexity of products and transactions
Operational risk can stem from events/actions occurring due to the failure of Stock Exchange Member Securities Companies to provide information on all products and transactions with high complexity according to established standards to customers, failures of marketed products, or transactions that do not comply with procedures. Factors causing this include weaknesses in HR management implementation, ineffective business process design and dysfunctional implementation, and weaknesses in information technology systems and supporting infrastructure.
Complexity of trading service offerings
Operational risk can stem from events/actions occurring due to the failure of Stock Exchange Member Securities Companies to provide all services according to established standards to customers, failures of provided services, or services that do not comply with procedures. Factors causing this include weaknesses in HR management implementation, ineffective business process design and dysfunctional implementation, and weaknesses in information technology systems and supporting infrastructure.
Customer complexity
Operational risk can stem from events/actions occurring due to the failure of Stock Exchange Member Securities Companies to provide services, products, and transactions according to established standards to all types of customers, failures of services provided to certain customer categories, or services that do not comply with customer categories. Factors causing this include weaknesses in HR management implementation, ineffective business process design and dysfunctional implementation, and weaknesses in information technology systems and supporting infrastructure.
Unbalanced employee workload due to inefficient work processes
Operational risk can stem from events/actions occurring because the workload among employees of Stock Exchange Member Securities Companies is unbalanced to operate Stock Exchange Member Securities Companies, disrupting/hindering the effectiveness of business processes. Factors causing this include weaknesses in HR management implementation, ineffective business process design, and inefficient implementation.
Human error
Operational risk can be caused by human error or transaction execution errors in the front and back office units of Stock Exchange Member Securities Companies. Factors causing this include weaknesses in HR management implementation, ineffective business process design and implementation failures, and weaknesses in information technology systems and supporting infrastructure in providing hierarchical control/authorization functions.
Fraud
Fraud can be committed by external and internal parties, such as intentional theft by third parties and employees of Stock Exchange Member Securities Companies. Actions violating laws that cause losses/potential losses to Stock Exchange Member Securities Companies, both financially and non-financially. Forms of fraud include deception, theft, and embezzlement.
Internal and external fraud can also occur due to the personal intentions/goals of employees of Stock Exchange Member Securities Companies and third parties to harm Stock Exchange Member Securities Companies. However, there are several factors that encourage fraud, including weaknesses in management supervision and policies, HR management implementation, IT security, and inadequate supporting infrastructure.
System failure when forwarding trading orders
Operational risk can be caused by system failures in forwarding trading orders or disruptions in executing transactions in the Front Office (FO) function of Stock Exchange Member Securities Companies. Factors causing this include weaknesses in information technology systems and supporting infrastructure in providing hierarchical control/authorization functions, weaknesses in HR management implementation, and ineffective business process design and implementation failures.
Systems unable to support business complexity
Operational risk can be caused by the inability of systems to support the complexity of service offerings, products, and transactions, and hindered data exchange with the back office, both in the front office and back office functions of Stock Exchange Member Securities Companies. Factors causing this include ineffective business process design and implementation failures, weaknesses in information technology systems and supporting infrastructure in providing hierarchical control/authorization functions, and weaknesses in HR management implementation.
Systems can still be intervened manually
Operational risk can be caused by systems that are not integrated in the front office and back office functions of Stock Exchange Member Securities Companies, hindered data exchange with the back office in supporting the complexity of service offerings of Stock Exchange Member Securities Companies. Factors causing this include weaknesses in information technology systems and supporting infrastructure in providing hierarchical control/authorization functions, weaknesses in HR management implementation, and ineffective business process design and implementation failures.
Unstable network availability
Operational risk can be caused by unstable networks in forwarding trading or disruptions in executing transactions in the front office function. Factors causing this include weaknesses in information technology systems and supporting infrastructure in providing hierarchical control/authorization functions, weaknesses in HR management implementation, and ineffective business process design and implementation failures.
Possibility of systems accessed by unauthorized parties
Operational risk can be caused by service, product, and transaction systems being accessed by unauthorized parties. Factors causing this include weaknesses in information technology systems and supporting infrastructure in providing hierarchical control/authorization functions, weaknesses in HR management implementation, and ineffective business process design and implementation failures.
c. Impacts of Operational Risk
Business disruption
a) Inefficiency of work processes, such as rework and work delay. b) Internal reporting errors causing suboptimal decision-making, loss of opportunity to obtain profits, and loss of potential customers.
Regulatory violations
Loss compensation
Loss/Damage of assets
a) Decrease in asset value/business losses b) Resignation of potential employees
Reputation
Legal
Legal impacts on Stock Exchange Member Securities Companies involve dispute resolution efforts or cases between Stock Exchange Member Securities Companies and other parties. Dispute resolution can consist of:
a) Litigation (court); and b) Non-litigation (out of court), including:
(1) Consultation: an action taken between one party and another party that is a consulting party.
(2) Negotiation: settlement out of court with the aim of reaching a mutual agreement based on more harmonious cooperation.
(3) Mediation: settlement through negotiation to reach an agreement among the parties assisted by a mediator.
(4) Conciliation: dispute resolution assisted by a conciliator who functions to mediate the parties to find solutions and reach an agreement among the parties.
(5) Expert Assessment: opinions from experts on matters that are technical and within their field of expertise.
d. Tolerance in Operational Risk Assessment
Operational risk assessment includes the evaluation of the probability of an event and the impact it causes. An event with low probability and impact can still be tolerated, so it does not require intensive attention, although this does not mean that Securities Company members of the Stock Exchange can ignore such risks. Conversely, intensive attention must be given to risks with high probability and impact, which cannot be tolerated and immediately require control measures.
For the same risk event, different levels of probability and impact may arise for each Securities Company member of the Stock Exchange because the tolerance levels or risk appetite (the level of risk that can still be taken) of each Securities Company member differ. Measuring risk appetite is heavily influenced by the level of knowledge the Securities Company member has regarding its own company (Know Your Securities Company).
Figure 1. Linkage Between Operational Risk and Other Risks
Weaknesses in Human Resources of Securities Company Members act as triggers for operational risk and other risks:
CHAPTER III
OPERATIONAL RISK MANAGEMENT PRINCIPLES
Generally, operational risk management aims to manage resources optimally to become more effective and efficient in achieving business objectives while limiting losses caused by the failure of those resources to perform their functions. In addition, good risk management will enhance competitiveness and continuously improve the risk management performed by Securities Company members.
Business strategies and policies are translated into operational control aspects of Securities Company members, making operational management the forefront and strategic pillar in overall risk management. This section outlines the principles of operational risk management, which include:
a. Formulation of Operational Risk Appetite and Risk Tolerance The risk appetite to be taken refers to the level and type of risk that the Securities Company member is willing to take in order to achieve its objectives, while risk tolerance refers to the maximum level and type of risk established by the Securities Company member. Furthermore, in formulating operational management policies, the Board of Directors must provide clear guidance regarding the operational risk appetite and risk tolerance of the Securities Company member and ensure that both are reflected in the risk management policy by considering the business strategy and objectives of the Securities Company member in taking risks.
b. Adequacy of Active Supervision by the Board of Directors and the Board of Commissioners
a. Operational Risk Management Strategy
Securities companies formulate operational risk management strategies in accordance with the operational risk appetite to be taken and the overall business strategy. To ensure the smoothness of this process, the Board of Directors of Securities Company members must provide clear policies regarding the strategy adopted in managing operational risk. Operational Risk Management Strategy is formulated to ensure that the risk exposure of Securities Company members is managed in a controlled manner in accordance with internal policies and procedures of the Securities Company member, as well as applicable laws and regulations and other provisions, considering the following:
b. Operational Risk Management Organization
The implementation of operational risk management requires attention and involvement from all elements of the organization of Securities Company members. All employees in business units and supporting activities of Securities Company members must be part of the implementation of operational risk management. The existence of a centralized operational risk management function can support the Board of Directors and the Board of Commissioners in understanding and managing operational risk. However, all employees in each business line and supporting activity of Securities Company members are responsible for applying operational risk management. Operational risk management organization must consider the following:
c. Operational Policies, Procedures, and Risk Limits
d. Business Continuity Management (BCM)
Business Continuity Management (BCM) is an integrated and comprehensive management process (protocol) to ensure the operational continuity of Securities Company members in conducting business and serving customers. Therefore, BCM is an important component in the operational risk management framework of Securities Company members because Securities Company members may experience significant operational disruptions and losses if they are unable to perform quick and accurate recovery efforts over business disruptions that occur.
a. Identification and Measurement
b. Reporting and Monitoring
c. Control
d. Management Information System
e. Human Resources
Securities Company members are required to ensure that human resources have adequate competence to implement operational risk management.
CHAPTER IV
OPERATIONAL RISK ASSESSMENT
The procedures for operational risk assessment serve as general guidelines for Securities Company members, which can be further developed and adjusted according to the complexity, business scale, and conditions of the Securities Company member.
b. Know Your Securities Company (KYSC) in Operational Risk Assessment
Figure 2. Operational Risk Indicators
Explanation of Figure 2. Operational Risk Indicators:
Business Plan
Strategies and business plans are the basis for the operational activities of Securities Company members for a certain period. Such plans certainly have the potential to change the operational risk profile because Securities Company members need to provide sufficient human resources, supporting infrastructure, and capital.
Risk Governance
Risk governance is one of the considerations in assessing the effectiveness of operational risk management, consisting of awareness and active supervision by the Board of Directors and the Board of Commissioners over all risks, as well as the establishment of strategies to realize a risk-aware culture (risk awareness) among all employees.
Business Activities and Other Activities
From business activities and other activities, Securities Company members can assess the achievement of objectives and also sources of risk that significantly affect the company.
Risk Management
Given the many linkages between operational risk and other risks, when assessing operational risk management, Securities Company members should also understand risk management for other risks, so that a comprehensive picture of operational risk management can be obtained.
Human Resource Management and Performance Evaluation Systems
Human Resource Management and performance evaluation systems provide information for analyzing Inherent Risk arising from human factors. HR analysis results can be used by Securities Company members to assess the adequacy of the company's policies and organizational structure.
Compliance
In practice, applicable regulations will be implemented into regulations in operational functions. Even for Securities Company members fully committed to risk management, provisions in internal regulations formulated by Securities Company members can be more conservative than those regulated by regulators. The tendency of Securities Company members to become increasingly committed to compliance with regulations will make them more conservative in creating internal procedures and regulations to manage operational risk.
c. Thought Process Flow of Operational Risk Assessment
Figure 3. Thought Process Flow of Operational Risk Assessment
No Operational Risk Parameter
Other Risk Measurement Indicators and/or for portfolios of Securities Companies that are Stock Exchange Members.
Securities Companies that are Stock Exchange Members as Participants in debt securities transactions and/or as Issuers of Securities.
Securities Companies that are Stock Exchange Members conduct Repo, Reverse Repo, money lending, and securities lending transactions.
2. Complexity of trading services
Securities Companies have PPE/PEE or PPE/PEE licenses Securities Companies that are Stock Exchange Members have Online Trading Securities Companies that are Stock Exchange Members have Margin and Short Selling transaction licenses Securities Companies that are Stock Exchange Members have Algorithm Trading and Direct Market Access (DMA) licenses
3. Client complexity Number of Retail Account Holders (NPR) and Institutional Clients (NK) in Domestic (DN) and Foreign (LN) markets
Number of active NPR and NK in DN and LN
NPR includes employees of Securities Companies that are Stock Exchange Members
4. Unbalanced employee workload due to inefficient work processes
Number of core employee turnover
Number of licensed employee turnover
Number of individual APPE compared to marketing personnel Number of remote trading users > number of Securities Company Representatives (WPE) Main functions of Securities Companies required to be filled by licensed employees,
No Operational Risk Parameter
Other Risk Measurement Indicators but filled by employees who do not have WPE licenses
5. Human error Frequency of human error incidents
Material impact of human error
6. Fraud Number of fraud incidents
Significance of loss value such that if a Securities Company that is a Stock Exchange Member suffers losses resulting in the average MKBD Value of the Securities Company that is a Stock Exchange Member not meeting regulations (Loss value/(average MKBD after deducting the minimum required value over 6 months))
7. System failure in forwarding trading orders (FO)
Level of product and transaction complexity
Level of trading service complexity
8. System unable to support business complexity
Back Office (BO) to Front Office (FO) data exchange conditions Storage capacity of FO and BO systems Impact of system issues on the operations of Securities Companies that are Stock Exchange Members (order forwarding, database, reports) Level of product and transaction complexity Level of trading service complexity
9. System still subject to manual intervention
System integration with business complexity
BO to FO data exchange conditions
No Operational Risk Parameter
Other Risk Measurement Indicators
Level of trading service complexity
Ownership and placement of automated ordering service systems Number of Algorithm Trading services
10. Unavailability of stable network
Level of product and transaction complexity
Level of trading service complexity
11. Possibility of system access by unauthorized parties.
Level of product and transaction complexity
Level of trading service complexity
3. Assessment of the Quality of Operational Risk Management Implementation
The quality of risk management implementation varies significantly between one Securities Company and another depending on the complexity of their business. However, in general, Securities Companies that are Stock Exchange Members must have risk management that includes:
a. Operational Risk Management Framework
Considering the scope of Risk Management above, the indicators used by Securities Companies that are Stock Exchange Members to conduct operational risk management assessments are as follows:
Table 3. Operational Risk Management Parameters and Indicators
No
Operational Risk Parameter
Risk Management Measurement Indicators
No
Operational Risk Parameter
Risk Management Measurement Indicators
SOPs and/or written policies regarding anti-fraud/fraud handling have been implemented, supervised, and audited SOPs and/or written policies regarding anti-fraud/fraud handling are reviewed periodically and updated Quick and comprehensive corrective actions due to fraud Insider trading mitigation policies Compensation policies due to fraud Strict, consistent, and progressive sanctions Block leave policies
7. System failure when forwarding trading orders
Frequency of FO capacity testing (Mock Trading at PT BEI) Having backup connections Maintenance is performed periodically Having a Business Continuity Plan (BCP) for front office and back office systems Speed of IT HR in resolving IT issues Documentation of technology and information issues
8. System unable to support business complexity
Securities Companies that are Stock Exchange Members develop support systems and ensure they support main systems and are integrated Back office systems meet PT BEI standards Periodic system capacity updates (storage) with alerts Frequency of FO capacity testing (Mock Trading at PT BEI)
No
Operational Risk Parameter
Risk Management Measurement Indicators
Frequency of backups and having colocation servers System updates are performed automatically
9. System still subject to manual intervention
Access rights have been allocated
Having SOPs for trading services
SOPs are implemented, supervised, and audited
SOPs are reviewed periodically and updated
Having policies for handling automated trading errors
10. Unavailability of stable network
Having backup connections
Maintenance is performed periodically
Having a Business Continuity Plan (BCP) for front office and back office systems Speed of IT HR in resolving IT issues
11. Possibility of system access by unauthorized parties
Having SOPs related to company information security SOPs are implemented, supervised, and audited Periodic review of SOPs related to company information security and updates The company has a comprehensive transaction instruction validation mechanism The company has a network infrastructure equipped with firewalls, Intrusion Prevention Systems (IPS), or Intrusion Detection Systems (IDS) Antivirus updates are performed routinely
No
Operational Risk Parameter
Risk Management Measurement Indicators
The company has a policy for creating password combinations The company performs routine password changes for front office and back office system administrators Appropriate ratio between IT HR and the number of systems Policies do not allow information exchange via flash drives, personal email, and other data storage media The company records every user activity for each information system (system logs) Clean desk policy Restriction of physical access rights to server rooms Conducting system security socialization Having a development area for development Having data confidentiality agreements with vendors
4. Assessment of Operational Risk Ratings
Based on the assessment results of Inherent Risk and the quality of operational risk management implementation, the operational risk rating is determined based on comprehensive and structured analysis that provides a holistic view of the operational risks of Securities Companies that are Stock Exchange Members. Assessment of Inherent Risk indicators and operational risk management is conducted using worksheets. In the worksheets, conditions indicating the risk rating for each operational risk indicator and the level of quality of operational risk management implementation have been determined, namely Rating 1 (strong), Rating 2 (satisfactory),
Rating 3 (fair), Rating 4 (marginal), and Rating 5 (unsatisfactory).
A smaller order of magnitude indicates lower risk and better quality of operational risk management implementation, as illustrated in Table 4 below:
Table 4. Operational Risk Assessment Matrix
Inherent Risk
Risk Management
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Inadequate)
Unsatisfactory
(Not Adequate)
Low
(Low)
1 2 3 4 5
Low to Moderate
(Low to Moderate)
2 4 6 8 10
Moderate
(Moderate)
3 6 9 12 15
Moderate to High
(Moderate to High)
4 8 12 16 20
High
(High)
5 10 15 20 25
Based on Table 4, the ranges and operational risk ratings are obtained as follows:
Table 5. Operational Risk Range and Ratings
Range Rating
1.00 - 2.99 I
3.00 - 4.99 II
5.00 - 9.99 III
10.00 - 16.00 IV
16.01 - 25.00 V
In certain conditions where the conditions in the worksheet are less relevant for determining the operational risk rating according to actual conditions, Securities Companies that are Stock Exchange Members can
exercise judgment using comprehensive and structured analysis to set a higher or lower rating as long as it is considered more appropriate to describe the operational risk rating of the Securities Company that is a Stock Exchange Member and recorded in the conclusion of each operational risk indicator as documentation.
Table A. Definition of Operational Inherent Risk Ratings
No Operational Risk Parameter
Low
(Low)
Low to Moderate
(Low to Moderate)
Moderate
(Moderate)
Moderate to High
(Moderate to High)
High
(High)
No Operational Risk Parameter
Low
(Low)
Low to Moderate
(Low to Moderate)
Moderate
(Moderate)
Moderate to High
(Moderate to High)
High
(High) participants in debt securities transactions in debt securities transactions in debt securities transactions in debt securities transactions and/or as securities issuers Securities Companies conduct repo, reverse repo, money lending, and securities lending transactions Securities Companies conduct repo, reverse repo, money lending, and securities lending transactions
2. Complexity of Trading Services
Securities Companies have PPE licenses
Securities Companies have PPE, PEE licenses
Securities Companies have PPE/PEE licenses
Securities Companies have PPE/PEE or PPE/PEE licenses Securities Companies have PPE/PEE or PPE/PEE licenses Securities Companies have online trading Securities Companies have online trading Securities Companies have online trading Securities Companies have online trading Securities Companies have margin and short selling licenses Securities Companies have margin and short selling licenses Securities Companies have margin and short selling licenses Securities Companies have algorithm trading and DMA licenses
3. Client Complexity
Securities Companies have domestic NPR and/or domestic institutional clients Securities Companies have domestic NPR and/or domestic institutional clients Securities Companies have domestic NPR and/or domestic institutional clients and/or foreign clients Securities Companies have domestic NPR and/or domestic institutional clients and/or foreign clients Securities Companies have domestic NPR and/or domestic institutional clients and/or foreign clients Active NPR up to 500 and institutional clients up to Active NPR 501 to 1000 and institutional clients 6 to Active NPR 5001 to 10000 and institutional clients up to 10 Active NPR > 10000 and institutional clients > 10
No Operational Risk Parameter
Low
(Low)
Low to Moderate
(Low to Moderate)
Moderate
(Moderate)
Moderate to High
(Moderate to High)
High
(High)
NPR of Securities Companies includes Employees of Securities Companies NPR of Securities Companies includes Employees of Securities Companies NPR of Securities Companies includes Employees of Securities Companies
4. Unbalanced employee workload due to inefficient work processes
Human resources are very adequate in terms of quantity sufficiency and workload distribution Human resources are adequate in terms of quantity sufficiency and workload distribution Human resources are fairly adequate in terms of quantity sufficiency and workload distribution Human resources are less adequate in terms of quantity sufficiency and workload distribution Human resources are very inadequate in terms of quantity sufficiency and workload distribution. Employee composition is stable and in accordance with regulations, no employee turnover, WPE. Employee composition is relatively stable and in accordance with regulations, employee turnover (no core employees) and WPE < 5 Employee composition is fairly stable and in accordance with regulations, employee turnover (<50% of core employees) <5% and WPE up to 10%. Employee composition is less stable and in accordance with regulations, employee turnover (>50% of core employees) up to 5% and WPE up to 50%. Employee composition is unstable and not in accordance with regulations, employee turnover (>50% of core employees) >10% and WPE > 50. Number of remote trading matches WPE Number of remote trading matches WPE Number of remote trading > WPE Number of remote trading > WPE Number of remote trading > WPE No functions and/or outsourcing employees No outsourcing employees Outsourcing employees 25% (remisiers) Outsourcing employees >50% (remisiers) Outsourcing employees >50%. Main PE functions filled by WPE Main PE functions mostly filled by WPE Main PE functions required to be filled by WPE have been filled by WPE Main PE functions required to be filled by WPE have been filled by WPE Main PE functions required to be filled by WPE are not filled by WPE
5. Human Error Human resources are very adequate in terms of quality
Human resources are adequate in terms of quality Human resources are fairly adequate in terms of HR quality. Historical loss data due to human error is not significant Human resources are less adequate in terms of HR quality. Historical loss data due to human error is less significant Human resources are very inadequate in terms of HR quality. Historical loss data due to human error is very significant
No Operational Risk Parameter
Low
(Low)
Low to Moderate
(Low to Moderate)
Moderate
(Moderate)
Moderate to High
(Moderate to High)
High
(High)
HR quality. Historical loss data due to human error is not significant HR quality. Historical loss data due to human error is less significant Historical loss data due to human error is fairly significant Historical loss data due to human error is significant
6. Fraud Frequency and materiality of internal and external fraud are very low and losses caused are not significant compared to PE MKBD value
Frequency and materiality of internal and external fraud are low and losses caused are less significant compared to PE MKBD value Frequency and materiality of internal and external fraud are fairly low and losses caused are fairly significant compared to PE MKBD value Frequency and materiality of internal and external fraud are high and losses caused are significant compared to PE MKBD value Frequency and materiality of internal and external fraud are very high and losses caused are very significant compared to PE MKBD value
7. System failure when forwarding trading orders (FO)
Impact of information technology failure in forwarding customer orders is very low in terms of product, transaction, and PE service complexity Impact of information technology failure in forwarding customer orders is low in terms of product, transaction, and PE service complexity Impact of information technology failure in forwarding customer orders is fairly low in terms of product, transaction, and PE service complexity Impact of information technology failure in forwarding customer orders is high in terms of product, transaction, and PE service complexity Complex Impact of information technology failure in forwarding customer orders is very high in terms of product, transaction, and PE service complexity
8. System unable to support business complexity
Information technology is very reliable in supporting the complexity of products, transactions, and PE services Information technology is reliable in supporting the complexity of products, transactions, and PE services Information technology is fairly reliable in supporting the complexity of products, transactions, and PE services Information technology is less reliable in supporting the complexity of products, transactions, and PE services Information technology is very unreliable in supporting the complexity of products, transactions, and PE services
No Operational Risk Parameter
Low
(Low)
Low to Moderate
(Low to Moderate)
Moderate
(Moderate)
Moderate to High
(Moderate to High)
High
(High)
9. System still subject to manual intervention
Information technology is very mature, back office and front office systems have very few that require manual intervention Information technology is mature, back office and front office systems have few that require manual intervention Information technology is fairly mature, back office and front office systems have fairly few that require manual intervention Information technology is less mature, back office and front office systems have many that require manual intervention Information technology is very immature, back office and front office systems have very many that require manual intervention
10. Unavailability of stable network
Impact of unstable network is very low on the complexity of products, transactions, and PE services Impact of unstable network is low on the complexity of products, transactions, and PE services Impact of unstable network is fairly low on the complexity of products, transactions, and PE services Impact of unstable network is high on the complexity of products, transactions, and PE services Impact of unstable network is very high on the complexity of products, transactions, and PE services
No Operational Risk Parameter
Low
(Low)
Low to Moderate
(Low to Moderate)
Moderate
(Moderate)
Moderate to High
(Moderate to High)
High
(High)
11. Possibility of system access by unauthorized parties.
System access by unauthorized parties has a very low impact in terms of product, transaction, and PE service complexity System access by unauthorized parties has a low impact in terms of product, transaction, and PE service complexity System access by unauthorized parties has a fairly low impact in terms of product, transaction, and PE service complexity System access by unauthorized parties has a high impact in terms of product, transaction, and PE service complexity System access by unauthorized parties has a very high impact in terms of product, transaction, and PE service complexity
Table B. Definition of Operational Risk Management Implementation Quality Levels
No Operational Risk Parameter
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Inadequate)
Unsatisfactory
(Not Adequate)
pembagian beban kerja SDM pembagian beban kerja SDM pembagian beban kerja SDM pembagian beban kerja SDM pembagian beban kerja SDM
No
Parameter
Operational Risk
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Inadequate)
Unsatisfactory
(Very Inadequate)
Workload distribution
Workload distribution
Workload distribution
Workload distribution
5. Human Error The risk management process is very adequate in identifying, measuring, monitoring, and controlling the quality of human resources and losses due to human error.
The risk management process is adequate in identifying, measuring, monitoring, and controlling the quality of human resources and losses due to human error.
The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling the quality of human resources and losses due to human error.
The risk management process is inadequate in identifying, measuring, monitoring, and controlling the quality of human resources and losses due to human error.
The risk management process is very inadequate in identifying, measuring, monitoring, and controlling the quality of human resources and losses due to human error.
6. Fraud The risk management process is very adequate in identifying, measuring, monitoring, and controlling the frequency and materiality of internal and external fraud as well as losses caused.
The risk management process is adequate in identifying, measuring, monitoring, and controlling the frequency and materiality of internal and external fraud as well as losses caused.
The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling the frequency and materiality of internal and external fraud as well as losses caused. The risk management process is inadequate in identifying, measuring, monitoring, and controlling the frequency and materiality of internal and external fraud as well as losses caused. The risk management process is very inadequate in identifying, measuring, monitoring, and controlling the frequency and materiality of internal and external fraud as well as losses caused.
7. System failure when forwarding trade orders (FO)
The risk management process is very adequate in identifying, measuring, monitoring, and controlling the system in forwarding customer orders.
The risk management process is adequate in identifying, measuring, monitoring, and controlling the system in forwarding customer orders.
The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling the system in forwarding customer orders.
The risk management process is inadequate in identifying, measuring, monitoring, and controlling the system in forwarding customer orders.
The risk management process is very inadequate in identifying, measuring, monitoring, and controlling the system in forwarding customer orders so that it does not impact the complexity of products, transactions, and PE product services.
8. System unable to support business complexity
The risk management process is very adequate in identifying, measuring, monitoring, and controlling the system in supporting the complexity of products, transactions, and PE services.
The risk management process is adequate in identifying, measuring, monitoring, and controlling the system in supporting the complexity of products, transactions, and PE services.
The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling the system in supporting the complexity of products, transactions, and PE services.
The risk management process is inadequate in identifying, measuring, monitoring, and controlling the system in supporting the complexity of products, transactions, and PE services.
The risk management process is very inadequate in identifying, measuring, monitoring, and controlling the system in supporting the complexity of products, transactions, and PE services.
9. System still subject to manual intervention
The risk management process is very adequate in identifying, measuring, monitoring, and controlling manual intervention in back office and front office systems.
The risk management process is adequate in identifying, measuring, monitoring, and controlling manual intervention in back office and front office systems.
The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling manual intervention in back office and front office systems.
The risk management process is inadequate in identifying, measuring, monitoring, and controlling manual intervention in back office and front office systems.
The risk management process is very inadequate in identifying, measuring, monitoring, and controlling manual intervention in back office and front office systems.
10. Unavailability of stable network
The risk management process is very adequate in identifying, measuring, monitoring, and controlling stable networks so that they do not impact the complexity of products, transactions, and PE product services. The risk management process is adequate in identifying, measuring, monitoring, and controlling stable networks so that they do not impact the complexity of products, transactions, and PE product services. The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling stable networks so that they do not impact the complexity of products, transactions, and PE product services. The risk management process is inadequate in identifying, measuring, monitoring, and controlling stable networks so that they do not impact the complexity of products, transactions, and PE product services. The risk management process is very inadequate in identifying, measuring, monitoring, and controlling stable networks so that they do not impact the complexity of products, transactions, and PE product services.
11. Possibility of system access by unauthorized parties.
The risk management process is very adequate in identifying, measuring, monitoring, and controlling system security from access by unauthorized parties so that it does not impact the complexity of products, transactions, and PE product services. The risk management process is adequate in identifying, measuring, monitoring, and controlling system security from access by unauthorized parties so that it does not impact the complexity of products, transactions, and PE product services. The risk management process is fairly adequate in identifying, measuring, monitoring, and controlling system security from access by unauthorized parties so that it does not impact the complexity of products, transactions, and PE product services. The risk management process is inadequate in identifying, measuring, monitoring, and controlling system security from access by unauthorized parties so that it does not impact the complexity of products, transactions, and PE product services. The risk management process is very inadequate in identifying, measuring, monitoring, and controlling system security from access by unauthorized parties so that it does not impact the complexity of products, transactions, and PE product services.
Table C. Recommended Documents
Stock Exchange Members Securities Companies Members of the Stock Exchange in conducting the assessment of Inherent Risk and the quality of operational risk management implementation.
No
Operational Risk Parameter
Documents/Information
i
CREDIT RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION ........................................................................... 1
CHAPTER II BASIC CONCEPTS OF CREDIT RISK
CHAPTER I
INTRODUCTION
Technological developments have led to an increase in the complexity of business activities of Securities Company Stock Exchange Members, while simultaneously increasing the risks faced by Securities Company Stock Exchange Members. This requires Securities Company Stock Exchange Members to implement Risk Management properly in accordance with their business characteristics and complexity. Failure of Securities Company Stock Exchange Members to conduct Risk Management can cause significant losses and can even disrupt the continuity of the business of Securities Company Stock Exchange Members. Credit risk is the risk caused by the failure of customers and/or other parties to fulfill their obligations to the Securities Company. Credit risk is related to the potential failure of customers and/or other parties, transactions where the settlement of securities transactions is not guaranteed by the Clearing and Guarantee Institution, for example, Over The Counter (OTC) transactions and negotiation transactions. Other coverage includes margin financing transactions, non-margin financing transactions, and reverse repo transactions. In the context of preparing self-assessment reports, a guide is needed for Securities Company Stock Exchange Members in assessing credit risk. The credit risk assessment of Securities Company Stock Exchange Members contains basic principles in conducting credit risk management assessment, which includes assessment of Inherent Risk and the quality of credit risk management implementation.
CHAPTER II
BASIC CONCEPTS OF CREDIT RISK
This section outlines the basic concepts of credit risk management to facilitate Securities Company Stock Exchange Members in assessing credit risk. The basic concepts of credit risk include: (1) sources, types/types of events, and impacts of credit risk, (2) dimensions of Inherent Credit Risk assessment, and (3) the interconnection of credit risk with other risks.
CHAPTER III
CREDIT RISK MANAGEMENT PRINCIPLES
Generally, credit risk management aims to manage resources optimally so as to be more effective and efficient in achieving business goals while limiting losses caused by the failure of those resources to perform their functions. In addition to this, good risk management will enhance competitiveness and continuously improve the risk management conducted by Securities Company Stock Exchange Members. This section outlines credit risk management principles, which include among others:
CHAPTER IV
CREDIT RISK ASSESSMENT
This section will outline the procedures for conducting credit risk management assessment. The assessment procedures serve as a general guide for Securities Company Stock Exchange Members, which can still be developed and adjusted to the complexity, business scale, and conditions of Securities Company Stock Exchange Members.
Credit Risk
Institutional Customer Transactions
Securities Transactions Not Guaranteed by LKP
Margin Financing
Reverse Repo Transactions
Non-Margin Financing
c) Obtain approval from the Stock Exchange to conduct margin transactions; and
A Reverse Repurchase Agreement (reverse repo), hereinafter referred to as reverse repo, based on the POJK regarding guidelines for Repurchase Agreement transactions for Financial Service Institutions, is a contract to sell or buy Securities with an agreement to buy back or sell back at a predetermined time and price. Securities Companies that are members of the Stock Exchange conducting reverse repo transactions must:
a) Designate Directors and/or company employees authorized to conduct the transactions.
b) Ensure that every transaction has received authorization from the relevant party within the company.
c) Have adequate policies, procedures, and internal controls, as well as appropriate Risk Management to address risks arising from the transactions.
d) Have adequate documentation to record transactions conducted by the company.
e) Accurately record the legal identity of the other party.
f) Every repo and reverse repo transaction must be accompanied by a change in ownership of the Securities.
g) In the event of a failure to fulfill obligations (default) in repo and reverse repo transactions, such transactions are considered outright sales and purchases without reducing the obligations of the defaulting party to fulfill their respective obligations.
Non-margin financing, also known as T-Plus financing, is financing provided by Securities Companies that are members of the Stock Exchange to clients resulting from client delivery failures, leading to a negative balance. This refers to a position where the client's obligation to transfer funds on the settlement date is greater than the pledged fund balance and the fund balance in the client's fund account.
The duration of T-Plus financing is at most on the 5th (five) trading day since the stock exchange transaction was conducted, or two days after the settlement date agreed upon for off-exchange transactions. If within this period the client has still not fulfilled their obligations, the Securities Company that is a member of the Stock Exchange is required to forcibly sell the client's Securities in the regular market.
In practice, applicable regulations will be implemented into internal regulations of Securities Companies that are members of the Stock Exchange. Even for Securities Companies that are fully committed to risk management, the provisions in the internal regulations formulated by the Securities Company may be more conservative than those regulated by the regulator. The tendency of Securities Companies that are members of the Stock Exchange to be increasingly committed to regulatory compliance will result in increasingly conservative procedures and internal regulations to manage credit risk.
c. Thought Process for Credit Risk Assessment
Figure 3. Credit Risk Assessment Thought Process
Inherent Credit Risk Assessment is grouped into 6 indicators of credit risk parameters as follows:
Table 2. Credit Risk Parameters and Indicators
| No | Credit Risk Parameter | Risk Measurement Indicators |
|---|---|---|
| 1. Institutional Client Delivery Failure | Average value of institutional client sales transactions.<br>Value of institutional client delivery failures.<br>Frequency of institutional client delivery failures.<br>Frequency of lingering institutional client delivery failures. | |
| 2. Securities Company Delivery Failure | Value of sales transactions to other Securities Companies.<br>Value of delivery failures by other Securities Companies.<br>Frequency of delivery failures by other Securities Companies.<br>Frequency of lingering delivery failures by other Securities Companies. | |
| 3. Potential Uncollectability of Securities Transactions Not Guaranteed by LKP | Value of Securities transactions by Securities Companies with counterparts other than LKP conducted off-exchange (OTC). | |
| 4. Aggressive Margin Financing | Ratio of margin transaction value to margin collateral.<br>This ratio is used to measure the potential risk of financing and/or hedging client transactions conducted by the Securities Company. This ratio is calculated by comparing the Securities collateral received from clients with the total margin transaction value.<br>Ratio of margin financing compared to the Securities Company's equity value. | |
| 5. Inadequate Quality of Reverse Repo Transactions | Ratio of the total value of reverse repo transactions to the value of reverse repo collateral.<br>This ratio is used to measure the potential risk of reverse repo receivables by the Securities Company compared to the collateral received. This ratio is calculated by comparing the Securities collateral received with the total reverse repo transaction value.<br>Ratio of reverse repo transactions compared to the Securities Company's equity value. | |
| 6. Non-Margin Financing Not in Accordance with Regulations | Average total value of T-plus transactions.<br>Ratio of T-plus transactions compared to the Securities Company's equity value.<br>Ratio of purchase transactions to T-plus transactions. |
The quality of risk management implementation varies significantly between one Securities Company and another depending on the complexity of their business. However, in general, Securities Companies that are members of the Stock Exchange must have Risk Management with the scope as mentioned in Chapter III of these guidelines.
Considering the scope of risk management mentioned above, the indicators used by Securities Companies that are members of the Stock Exchange to conduct credit risk management assessment are as follows:
Table 3. Credit Risk Management Parameters and Indicators
| No | Credit Risk Parameter | Risk Management Measurement Indicators |
|---|---|---|
| 1. Institutional Client Delivery Failure | Have Standard Operating Procedures (SOP) or policies related to institutional client delivery failure mechanisms containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | |
| 2. Securities Company Delivery Failure | Have SOP or policies related to Securities Company delivery failure mechanisms containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | |
| 3. Potential Uncollectability of Securities Transactions Not Guaranteed by LKP | Have SOP or policies related to Securities Company transactions with counterparts other than LKP conducted off-exchange containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | |
| 4. Aggressive Margin Financing | Have adequate SOP or policies related to margin financing covering the process of opening margin securities accounts which has contained the rights and obligations of each party, client criteria, margin call mechanisms, forced sell execution mechanisms, authority segregation for financing provision, application of haircuts, haircut methods, decision-making flows, portfolio criteria, and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | |
| 5. Inadequate Quality of Reverse Repo Transactions | Have adequate SOP or policies related to reverse repo transactions containing stock criteria, counterparty criteria, criteria for determining non-performing reverse repo receivables, mechanisms for settling non-performing reverse repo receivables, ranking liabilities calculation methods, haircut calculation methods, criteria and mechanisms for adding and reducing collateral, standard agreement standards, decision-making flows, and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | |
| 6. Non-Margin Financing Not in Accordance with Regulations | Have adequate SOP or policies related to non-margin financing provision covering forced sell mechanisms, client criteria, collateral stock haircuts, haircut methods, decision-making flows, and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. |
Based on the assessment results of Inherent Risk and the quality of credit risk management implementation, a credit risk rating is determined based on comprehensive and structured analysis that provides a complete picture of the credit risk of Securities Companies that are members of the Stock Exchange.
The assessment of Inherent Risk indicators and credit risk management quality is conducted using worksheets. In the worksheets, conditions indicating the risk rating for each credit risk indicator and the level of quality of credit risk management implementation are determined, namely Rating 1 (strong), Rating 2 (satisfactory), Rating 3 (fair), Rating 4 (marginal), and Rating 5 (unsatisfactory). A smaller order level indicates lower risk and better quality of credit risk management implementation. For further details, see Table 4 below:
Table 4. Credit Risk Assessment Matrix
| Inherent Risk | Management Risk: Strong (Very Adequate) | Management Risk: Satisfactory (Adequate) | Management Risk: Fair (Fairly Adequate) | Management Risk: Marginal (Inadequate) | Management Risk: Unsatisfactory (Inadequate) |
|---|---|---|---|---|---|
| Low (Low) | 1 | 2 | 3 | 4 | 5 |
| Low to Moderate (Low-Medium) | 2 | 4 | 6 | 8 | 10 |
| Moderate (Medium) | 3 | 6 | 9 | 12 | 15 |
| Moderate to High (Medium-High) | 4 | 8 | 12 | 16 | 20 |
| High (High) | 5 | 10 | 15 | 20 | 25 |
Based on Table 4, the range and credit risk ratings are obtained as follows:
Table 5. Credit Risk Rating Range and Rating
| Range | Rating |
|---|---|
| 1.00 - 2.99 | I |
| 3.00 - 4.99 | II |
| 5.00 - 9.99 | III |
| 10.00 - 16.00 | IV |
| 16.01 - 25.00 | V |
In certain conditions where the worksheets are deemed less relevant for determining credit risk ratings according to actual conditions, Securities Companies that are members of the Stock Exchange may exercise judgment using comprehensive and structured analysis to establish higher or lower ratings, provided it is considered more appropriate to represent the credit risk rating of the Securities Company that is a member of the Stock Exchange, and this must be recorded in the conclusion of each credit risk indicator as documentation.
Table A. Definitions of Inherent Credit Risk Ratings
| No | Credit Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) |
|---|---|---|---|---|---|---|
| 1. Institutional Client Delivery Failure | Average value of institutional client purchase transactions is very small.<br>Never experienced institutional client delivery failures. | Average value of institutional client sales transactions is small.<br>Value of institutional client delivery failures is small.<br>Frequency of institutional client delivery failures is small.<br>Frequency of lingering institutional client delivery failures is small. | Average value of institutional client sales transactions is moderate.<br>Value of institutional client delivery failures is moderate.<br>Frequency of institutional client delivery failures is moderate.<br>Frequency of lingering institutional client delivery failures is moderate. | Average value of institutional client sales transactions is large.<br>Value of institutional client delivery failures is large.<br>Frequency of institutional client delivery failures is high.<br>Frequency of lingering institutional client delivery failures is high. | Average value of institutional client sales transactions is very large.<br>Value of institutional client delivery failures is very large.<br>Frequency of institutional client delivery failures is very high.<br>Frequency of lingering institutional client delivery failures is very high. | |
| 2. Securities Company Delivery Failure | Value of sales transactions to other Securities Companies in the last six months is very small.<br>Never experienced delivery failures by other Securities Companies. | Value of sales transactions to other Securities Companies in the last six months is small.<br>Value of delivery failures by other Securities Companies is small.<br>Frequency of delivery failures by other Securities Companies is low.<br>Frequency of lingering delivery failures by other Securities Companies is low. | Value of sales transactions to other Securities Companies in the last six months is moderate.<br>Value of delivery failures by other Securities Companies is moderate.<br>Frequency of delivery failures by other Securities Companies is moderate.<br>Frequency of lingering delivery failures by other Securities Companies is moderate. | Value of sales transactions to other Securities Companies in the last six months is large.<br>Value of delivery failures by other Securities Companies is large.<br>Frequency of delivery failures by other Securities Companies is high.<br>Frequency of lingering delivery failures by other Securities Companies is high. | Value of sales transactions to other Securities Companies in the last six months is very large.<br>Value of delivery failures by other Securities Companies is very large.<br>Frequency of delivery failures by other Securities Companies is very high.<br>Frequency of lingering delivery failures by other Securities Companies is very high. | |
| 3. Potential Uncollectability of Securities Transactions Not Guaranteed by LKP | Value of Securities transactions by Securities Companies with counterparts other than LKP conducted off-exchange (OTC) is very small. | Value of Securities transactions by Securities Companies with counterparts other than LKP conducted off-exchange (OTC) is small. | Value of Securities transactions by Securities Companies with counterparts other than LKP conducted off-exchange (OTC) is moderate. | Value of Securities transactions by Securities Companies with counterparts other than LKP conducted off-exchange (OTC) is large. | Value of Securities transactions by Securities Companies with counterparts other than LKP conducted off-exchange (OTC) is very large. | |
| 4. Aggressive Margin Financing | No margin transactions or have margin transactions where the ratio of margin transaction value to margin collateral is very small.<br>Ratio of margin financing compared to Securities Company equity value is very small. | Ratio of margin transaction value to margin collateral is small.<br>Ratio of margin financing compared to Securities Company equity value is small. | Ratio of margin transaction value to margin collateral is moderate.<br>Ratio of margin financing compared to Securities Company equity value is moderate. | Ratio of margin transaction value to margin collateral is large.<br>Ratio of margin financing compared to Securities Company equity value is large. | Ratio of margin transaction value to margin collateral is very large.<br>Ratio of margin financing compared to Securities Company equity value is very large. | |
| 5. Inadequate Quality of Reverse Repo Transactions | No reverse repo transactions or have reverse repo transactions where the ratio of reverse repo transaction value to reverse repo collateral value is very small.<br>Ratio of reverse repo transactions compared to Securities Company equity value is very small. | Ratio of reverse repo transaction value to reverse repo collateral value is small.<br>Ratio of reverse repo transactions compared to Securities Company equity value is small. | Ratio of reverse repo transaction value to reverse repo collateral value is moderate.<br>Ratio of reverse repo transactions compared to Securities Company equity value is moderate. | Ratio of reverse repo transaction value to reverse repo collateral value is large.<br>Ratio of reverse repo transactions compared to Securities Company equity value is large. | Ratio of reverse repo transaction value to reverse repo collateral value is very large.<br>Ratio of reverse repo transactions compared to Securities Company equity value is very large. | |
| 6. Non-Margin Financing Not in Accordance with Regulations | No transactions with T-Plus financing.<br>Ratio of T-Plus transactions compared to Securities Company equity value is very large.<br>Ratio of purchase transactions to T-Plus transactions is small. | Average total value of T-Plus transactions is small.<br>Ratio of T-Plus transactions compared to Securities Company equity value is small.<br>Ratio of purchase transactions to T-Plus transactions is moderate. | Average total value of T-Plus transactions is moderate.<br>Ratio of T-Plus transactions compared to Securities Company equity value is moderate.<br>Ratio of purchase transactions to T-Plus transactions is large. | Average total value of T-Plus transactions is large.<br>Ratio of T-Plus transactions compared to Securities Company equity value is large.<br>Ratio of purchase transactions to T-Plus transactions is very large. | Average total value of T-Plus transactions is very large.<br>Ratio of T-Plus transactions compared to Securities Company equity value is very large.<br>Ratio of purchase transactions to T-Plus transactions is very large. |
Table B. Definitions of Credit Risk Management Implementation Quality Levels
| No | Credit Risk Parameter | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Inadequate) |
|---|---|---|---|---|---|---|
| 1. Institutional Client Delivery Failure | Have SOP for institutional client delivery failure containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | Have SOP for institutional client delivery failure containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have written policies containing institutional client delivery failure decision-making flows and adequate authority segregation but not in the form of SOP, where policies are implemented, supervised, and examined, not reviewed periodically and not updated, and no significant violations of policies. | Have policies regarding institutional client delivery failure in the form of decision-making flows, portfolio criteria, and authority segregation but not written. | Have no policies regarding institutional client delivery failure. | |
| 2. Securities Company Delivery Failure | Have SOP for Securities Company delivery failure containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | Have SOP for Securities Company delivery failure containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have written policies containing Securities Company delivery failure decision-making flows and adequate authority segregation but not in the form of SOP, where policies are implemented, supervised, and examined, not reviewed periodically and not updated, and no significant violations of policies. | Have policies regarding Securities Company delivery failure in the form of decision-making flows, portfolio criteria, and authority segregation but not written. | Have no policies regarding Securities Company delivery failure. | |
| 3. Potential Uncollectability of Securities Transactions Not Guaranteed by LKP | Have SOP for mechanisms of Securities transactions not guaranteed by LKP containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | Have SOP for mechanisms of Securities transactions not guaranteed by LKP containing decision-making flows and adequate authority segregation, implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have written policies containing mechanisms of Securities transactions not guaranteed by LKP decision-making flows and adequate authority segregation but not in the form of SOP, where policies are implemented, supervised, and examined, not reviewed periodically and not updated, and no significant violations of policies. | Have policies regarding mechanisms of Securities transactions not guaranteed by LKP in the form of decision-making flows, portfolio criteria, and authority segregation but not written. | Have no policies regarding mechanisms of Securities transactions not guaranteed by LKP. | |
| 4. Aggressive Margin Financing | Have adequate SOP or policies related to margin financing covering the process of opening margin securities accounts which has contained the rights and obligations of each party, client criteria, margin call mechanisms, forced sell execution mechanisms, authority segregation for financing provision, application of haircuts, haircut methods, decision-making flows, portfolio criteria, and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | Have SOP related to margin financing but not covering authority segregation for financing provision and haircut calculation methods. SOP implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have SOP related to margin financing but not covering margin account opening mechanisms, client criteria, and forced sell mechanisms and haircut calculation methods. SOP implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have adequate SOP related to margin financing covering the process of opening margin securities accounts which has contained the rights and obligations of each party, client criteria, margin call mechanisms, forced sell execution mechanisms, authority segregation for financing provision, application of haircuts, haircut methods, authority of each party. SOP not implemented, not supervised, and not examined, not reviewed periodically and not updated, and having significant violations of the SOP. | Have no policies regarding margin financing. | |
| 5. Inadequate Quality of Reverse Repo Transactions | Have adequate SOP or policies related to reverse repo transactions containing stock criteria, counterparty criteria, criteria for determining non-performing reverse repo receivables, mechanisms for settling non-performing reverse repo receivables, ranking liabilities calculation methods, haircut calculation methods, criteria and mechanisms for adding and reducing collateral, standard agreement standards, decision-making flows, and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | Have SOP related to reverse repo transactions but not covering criteria for determining non-performing reverse repo receivables and mechanisms for settling non-performing reverse repo receivables. SOP implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have SOP related to reverse repo transactions but not covering criteria for determining non-performing reverse repo receivables, mechanisms for settling non-performing reverse repo receivables, and ranking liabilities calculation methods. SOP implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have adequate SOP related to reverse repo transactions containing stock criteria, counterparty criteria, criteria for determining non-performing reverse repo receivables, mechanisms for settling non-performing reverse repo receivables, ranking liabilities calculation methods, haircut calculation methods, criteria and mechanisms for adding and reducing collateral, standard agreement standards, decision-making flows, and adequate authority segregation. SOP not implemented, not supervised, and not examined, not reviewed periodically and not updated, and having significant violations of the SOP. | Have no policies regarding reverse repo transactions. | |
| 6. Non-Margin Financing Not in Accordance with Regulations | Have adequate SOP or policies related to non-margin financing provision covering forced sell mechanisms, client criteria, collateral stock haircuts, haircut methods, decision-making flows, and adequate authority segregation, implemented, supervised, and examined, reviewed periodically and updated, and never having violations of the SOP. | Have SOP related to non-margin financing provision but not covering forced sell mechanisms and client criteria. SOP implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have SOP related to non-margin financing provision but not covering forced sell mechanisms, client criteria, and collateral stock haircuts. SOP implemented, supervised, and examined, reviewed incidentally and updated, and never having violations of the SOP. | Have adequate SOP related to non-margin financing provision covering forced sell mechanisms, client criteria, collateral stock haircuts, haircut methods, decision-making flows, and adequate authority segregation. SOP not implemented, not supervised, and not examined, not reviewed periodically and not updated, and having significant violations of the SOP. | Have no policies regarding non-margin financing provision. |
No
Parameter
Credit Risk
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) there is violation of
SOP reviewed and not updated
5. Quality of
reverse repo transactions is not adequate
Has adequate SOP or policy related to reverse repo transactions covering stock criteria, counterparty criteria, criteria for determining non-performing reverse repo receivables, mechanism for settling non-performing reverse repo receivables, ranking calculation Has SOP related to margin financing but does not cover criteria and mechanism for adding/reducing collateral, haircut method and liability ranking. SOP is implemented, monitored, and audited, reviewed incidentally and Has SOP related to margin financing but does not cover criteria and mechanism for settling non-performing reverse repo, standard agreement criteria and stock and counterparty criteria. SOP is implemented, monitored, and audited, reviewed incidentally and updated, and never Has SOP related to reverse repo transactions that is adequate covering stock criteria, counterparty criteria, criteria for determining non-performing reverse repo receivables, mechanism for settling non-performing reverse repo liabilities. Does not have policy regarding reverse repo transactions
No
Parameter
Credit Risk
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) liabilities, haircut calculation method, criteria and mechanism for adding and reducing collateral, standard agreement criteria, decision-making flow, adequate segregation of authority, is implemented, monitored, and audited, reviewed periodically and updated, and never updated, and never has violation of SOP violation of SOP performed, liability ranking, haircut calculation method, criteria and mechanism for adding and reducing collateral, standard agreement criteria. SOP is not implemented, not monitored, and not audited, not reviewed and not updated
No
Parameter
Credit Risk
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) violation of SOP
6. Provision of
non-margin financing that does not comply with regulations Has SOP or policy related to provision of non-margin financing that is adequate covering forced sell mechanism, customer criteria, collateral stock haircut, haircut method, decision-making flow, and adequate segregation of authority, Has SOP related to non-margin financing but does not cover segregation of authority and haircut method. SOP is implemented, monitored, and audited, reviewed incidentally and updated, and never has violation of SOP Has SOP related to non-margin financing but does not cover customer criteria and forced sell mechanism. SOP is implemented, monitored, and audited, reviewed incidentally and updated Has SOP related to the provision of non-margin financing that is adequate covering forced sell mechanism, customer criteria, collateral stock haircut, haircut method and segregation of authority. SOP is not implemented Does not have policy related to provision of non-margin financing
No
Parameter
Credit Risk
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) is implemented, monitored, and audited, reviewed periodically and updated, and never has violation of SOP an, not monitored, and not audited, not reviewed and not updated
Table C. Recommended Documents
for the implementation of credit risk management.
Credit Risk Parameter Document/Information
i
MARKET RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION............................................................................ 1
CHAPTER II FUNDAMENTAL CONCEPTS OF MARKET RISK
CHAPTER I
INTRODUCTION technological development has led to an increase in the complexity of business activities of Stock Exchange Member Securities Companies and simultaneously increased the risk for Stock Exchange Member Securities Companies. This requires Stock Exchange Member Securities Companies to implement Risk Management properly in accordance with their business characteristics and complexity. Failure of Stock Exchange Member Securities Companies in conducting Risk Management can cause significant losses and can even disrupt the continuity of the business of Stock Exchange Member Securities Companies. Market risk is the risk caused by adverse movement of market variables (adverse movement) of the portfolio owned by the Securities Company. This market risk is caused by errors in decision-making by Stock Exchange Member Securities Companies in investment decisions in the form of Securities portfolios, which can lower the investment performance of Securities portfolios (both realized and unrealized), which ultimately affects the performance of Stock Exchange Member Securities Companies in generating operating profit. In addition to investment activities, Securities Companies receive portfolios from underwriting activities when the guaranteed Securities in the public offering are not absorbed, so the Securities Company is obligated to absorb those Securities into its own portfolio (full commitment). In the preparation of self-assessment reports, a guide is needed for Stock Exchange Member Securities Companies in assessing market risk. The market risk assessment of Stock Exchange Member Securities Companies contains basic principles in conducting market risk management assessment, including assessment of Inherent Risk and the quality of market risk management implementation.
CHAPTER II
FUNDAMENTAL CONCEPTS OF MARKET RISK
This section outlines the basic concepts of market risk management to facilitate Stock Exchange Member Securities Companies in assessing market risk. The basic concepts of market risk include: (1) sources, types/types of events, and impact of market risk, (2) dimensions of Inherent Market Risk assessment, and (3) interconnection of market risk with other risks.
b. Market Risk Events
The Company incurs losses on portfolio ownership.
c. Impact of Market Risk
Based on the identification of activities of Stock Exchange Member Securities Companies, market risk is interconnected with other risks. For example, errors in decision-making by Stock Exchange Member Securities Companies in investment decisions in the form of Securities portfolios. This results in a decline in the investment performance of Securities portfolios (both realized and unrealized), which ultimately affects the performance of Stock Exchange Member Securities Companies in generating operating profit (Figure 1).
CHAPTER III
PRINCIPLES OF MARKET RISK MANAGEMENT
Generally, market risk management aims to manage resources optimally so as to be more effective and efficient in achieving business goals while limiting losses caused by the failure of those resources to perform their functions. In addition to this, good Risk Management will increase competitiveness and continuously improve the Risk Management conducted by Stock Exchange Member Securities Companies. This section outlines the principles of market risk management, which include among others:
CHAPTER IV
MARKET RISK ASSESSMENT
This section will outline the procedures for conducting market risk assessment. The assessment procedures are general guidelines for Stock Exchange Member Securities Companies that can still be developed and adjusted to the complexity, business scale, and conditions of Stock Exchange Member Securities Companies.
(2) Short Position is the Securities balance in a specific account in the Auxiliary Securities Book which shows a number of Securities sold by the Stock Exchange Member Securities Company for its own interests and/or customer interests, but at the time of sale, such Securities are not yet owned by the Stock Exchange Member Securities Company and/or not yet delivered by customers to the Stock Exchange Member Securities Company. b) Recording of Own Transactions The auxiliary transaction book is maintained by the work unit performing the custodian function at the Stock Exchange Member Securities Company. This book is to record matters related to transactions conducted by the Stock Exchange Member Securities Company, including for own portfolio interests. When conducting Securities transactions for own interests, the Stock Exchange Member Securities Company will make the following recordings:
(1) In the General Ledger. Recording receivables and payables arising from transactions and settlement of transactions and recognition of owned Securities.
(2) In the Auxiliary Funds Book. Recording fund transfers for settlement of rights and obligations arising from Securities transactions.
(3) In the Auxiliary Securities Book. Recording transfers of Securities occurring as a result of conducting Securities transactions. c) Adjustment to Fair Value for Own Portfolio Stocks In recording in financial statements, on each financial statement date, the Stock Exchange Member Securities Company must adjust the value of its portfolio to fair value. Adjustment to fair value is done for stocks classified in the Fair Value Through Profit or Loss (FVTPL) – Trading and Available For Sell (AFS) groups.
In recording in the calculation of Adjusted Net Working Capital (MKBD), adjustments consist of:
(1) Ranking Liabilities are a number of contingent liabilities and off-balance sheet liabilities that will be added to liabilities as a risk factor in the calculation of MKBD, the value of which is determined based on specific calculations. Ranking Liabilities value is applied to concentrated portfolios on:
(a) one type of Security at one Issuer.
(b) one Issuer but in several types of Securities.
(c) several Issuers in one group.
(d) Government Securities.
(2) Market risk adjustment, is an adjustment to the risk of Securities owned by the Stock Exchange Member Securities Company calculated based on a specific haircut from the fair market value. The size of the haircut for each type of Security is regulated in Financial Services Authority Regulations regarding the maintenance and reporting of adjusted net working capital. (3) Business activity risk adjustment, is a reduction factor due to the Stock Exchange Member Securities Company not separating customer funds and/or Securities from the funds and/or Securities of the Stock Exchange Member Securities Company and the consequence that the Stock Exchange Member Securities Company does not set aside funds equal to the fair market value of Securities that are not yet under the direct control of the Stock Exchange Member Securities Company for a period of 5 (five) trading days after the settlement date. (4) Return of haircut on Securities closed with hedging.
c. Thought Process for Market Risk Assessment
Figure 3. Market Risk Assessment Thought Process
2. Inherent Market Risk Assessment
Inherent Market Risk assessment is grouped into market risk parameter indicators as follows:
Table 2. Market Risk Parameters and Indicators
Market Risk Parameter Risk Measurement Indicator The Company incurs losses on portfolio ownership Ratio of average haircut value compared to average fair market value.
Calculation of this ratio becomes an indicator to assess the magnitude of risk over ownership of a Security by the Company. The larger the ratio, the more risky the Securities portfolio owned by the Company is considered. Ratio of unrealized loss value compared to total assets. Calculation of this ratio becomes an indicator to assess the ability of Stock Exchange Member Securities Companies to bear portfolio losses of Securities if sold and become realized/realized loss. Ratio of Ranking Liabilities compared to paid-up capital. Calculation of this ratio becomes an indicator to assess the concentration of Securities portfolios owned by Stock Exchange Member Securities Companies and how large the use of paid-up capital is to obtain such portfolios.
Portfolio complexity, to assess the risk of portfolio management by Securities Companies that are Stock Exchange Members.
Assessing the risk rating of Securities Company portfolios based on their sources, namely from the absorption of underwriting from the Securities Company's function as an underwriter, and/or guarantees on financing and/or reverse repo receivables that have defaulted.
Considering the scope of Risk Management mentioned above, the indicators used by Securities Companies that are Stock Exchange Members to conduct an assessment of the market risk management of Securities Companies that are Stock Exchange Members are as follows:
Table 3. Market Risk Management Parameters and Indicators
Risk Parameter | Market Risk Management Measurement Indicator --- | --- The Company incurs losses on portfolio ownership | The Company has a dedicated Risk Management function that regulates portfolio Securities transaction activities. | Has Standard Operating Procedures (SOPs) or policies containing decision-making flows, portfolio criteria, and adequate segregation of authority, which are implemented, supervised, and examined, reviewed periodically and updated, and there have never been violations of the SOPs.
The assessment of Inherent Risk indicators and market risk management is conducted using a worksheet.
In the worksheet, conditions have been determined that indicate the risk rating for each market risk indicator and the level of quality of market risk management implementation, namely Rating 1 (Strong), Rating 2 (Satisfactory), Rating 3 (Fair), Rating 4 (Marginal), and Rating 5 (Unsatisfactory). A smaller order of magnitude indicates lower risk and better quality of market risk management implementation. For further clarity, this is illustrated in Table 4 as follows:
Table 4. Market Risk Assessment Matrix
Inherent Risk | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Inadequate) --- | --- | --- | --- | --- | --- Low (Low) | 1 | 2 | 3 | 4 | 5 Low to Moderate (Low-Medium) | 2 | 4 | 6 | 8 | 10 Moderate (Medium) | 3 | 6 | 9 | 12 | 15 Moderate to High (Medium-High) | 4 | 8 | 12 | 16 | 20 High (High) | 5 | 10 | 15 | 20 | 25
Based on Table 4, the range and market risk rating are obtained as follows:
Table 5. Market Risk Range and Rating
| Range | Rating |
|---|---|
| 1.00 - 2.99 | I |
| 3.00 - 4.99 | II |
| 5.00 - 9.99 | III |
| 10.00 - 16.00 | IV |
| 16.01 - 25.00 | V |
In certain conditions, the worksheet may be deemed less relevant for determining the market risk rating according to actual conditions. Securities Companies that are Stock Exchange Members may exercise judgment using comprehensive and structured analysis to set a higher or lower rating, provided it is considered more accurate in representing the market risk rating of the Securities Company that is a Stock Exchange Member, and this must be recorded in the conclusion of each market risk indicator as documentation.
In assessing the level of market risk, there are several documents recommended for use by Securities Companies that are Stock Exchange Members. The list of recommended documents is contained in Table C.
Table A. Definition of Market Inherent Risk Ratings
Market Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) --- | --- | --- | --- | --- | --- The Company incurs losses on portfolio ownership | The Securities Company has no market risk. (very small) Example criteria as follows: | The Securities Company has small market risk. Example criteria as follows: | The Securities Company has medium market risk. Example criteria as follows: | The Securities Company has high market risk. Example criteria as follows: | The Securities Company has very high market risk. Example criteria as follows:
The Securities Company does not have its own portfolio | The average haircut value ratio compared to the average fair market value is assessed as small | The average haircut value ratio compared to the average fair market value is assessed as medium | The average haircut value ratio compared to the average fair market value is assessed as high | The average haircut value ratio compared to the average fair market value is assessed as very high
Market Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) --- | --- | --- | --- | --- | ---
Market Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) --- | --- | --- | --- | --- | ---
Table B. Definition of Market Risk Management Implementation Quality Levels
Market Risk Parameter | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Inadequate) --- | --- | --- | --- | --- | --- The Company incurs losses on portfolio ownership | The Risk Management process is very adequate in identifying, measuring, monitoring, and controlling market risk over portfolio ownership. Example criteria as follows: | The Risk Management process is adequate in identifying, measuring, monitoring, and controlling market risk over portfolio ownership. Example criteria as follows: | The Risk Management process is fairly adequate in identifying, measuring, monitoring, and controlling market risk over portfolio ownership. Example criteria as follows: | The Risk Management process is inadequate in identifying, measuring, monitoring, and controlling market risk over portfolio ownership. Example criteria as follows: | The Risk Management process is inadequate in identifying, measuring, monitoring, and controlling market risk over portfolio ownership. Example criteria as follows:
Has Standard Operating Procedures containing decision-making flows, portfolio criteria, and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and there have never been violations of the SOP | Has Standard Operating Procedures containing decision-making flows, portfolio criteria, and adequate segregation of authority, implemented, supervised, and examined, reviewed incidentally and updated, and there have never been violations of the SOP | Has written policies containing decision-making flows, portfolio criteria, and adequate segregation of authority, but not in the form of Standard Operating Procedures, where the policy is implemented, supervised, and examined, not reviewed periodically and not updated, and there are no significant violations of the policy | There are policies regarding decision-making flows, portfolio criteria, and segregation of authority but not in writing | There are no policies regarding decision-making flows, portfolio criteria, and segregation of authority The Company has a dedicated Risk Management function that regulates portfolio Securities transaction activities | The Company does not have a dedicated Risk Management function that regulates portfolio Securities transaction activities | The Company does not have a dedicated Risk Management function that regulates portfolio Securities transaction activities | The Company does not have a dedicated Risk Management function that regulates portfolio Securities transaction activities | The Company does not have a dedicated Risk Management function that regulates portfolio Securities transaction activities
Table C. Recommended Documents
| Market Risk Parameter | Document/Information |
|---|---|
| The Company incurs losses on portfolio ownership | Securities Brokerage Activity Report (LKPPE) according to Appendix 1 of Bapepam and LK Regulation No. X.E.1 MKBD Report Securities Company Financial Statements Business plan, especially related to dealer activities SOPs related to dealer activities Policies related to dealer activities Securities Company allocation results report |
i
LIQUIDITY RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION............................................................................... 1
CHAPTER II FUNDAMENTAL CONCEPTS OF LIQUIDITY RISK
CHAPTER I
INTRODUCTION
Industry competition in the capital market, product and service innovation, and technological development have resulted in an increase in the complexity of business activities of Securities Companies that are Stock Exchange Members, while simultaneously increasing the risk for these Securities Companies. This requires Securities Companies that are Stock Exchange Members to implement Risk Management properly in accordance with their business characteristics and complexity. Failure of Securities Companies that are Stock Exchange Members to conduct Risk Management can cause significant losses and can even disrupt the continuity of the Securities Company's business.
Liquidity risk is the risk arising from the inability of a Securities Company to meet obligations arising from debt transactions of Securities, whether conducted by clients or the Securities Company itself, and/or other debts.
Liquidity risk is related to the ability of Securities Companies that are Stock Exchange Members to meet the required Minimum Adjusted Working Capital (MKBD) value and to settle regular transactions.
In the context of preparing the self-assessment report, a guide is needed for Securities Companies that are Stock Exchange Members to assess liquidity risk. This assessment of liquidity risk for Securities Companies that are Stock Exchange Members contains basic principles for conducting liquidity risk management assessment, which includes assessment of Inherent Risk and the quality of liquidity risk management implementation.
CHAPTER II
FUNDAMENTAL CONCEPTS OF LIQUIDITY RISK
This section outlines the fundamental concepts of liquidity risk management to facilitate Securities Companies that are Stock Exchange Members in assessing liquidity risk. The fundamental concepts of liquidity risk include: (1) sources, types/types of events, and impact of liquidity risk, (2) dimensions of Inherent Liquidity Risk assessment, and (3) the interconnection of liquidity risk with other risks.
The sources, types/types of events, and impact of liquidity risk that have a negative impact on Securities Companies are explained in Table 1 below:
Table 1. Sources, Events, and Impact of Liquidity Risk
| Source | Event | Impact |
|---|
The following is an explanation regarding the sources of liquidity risk, types of liquidity risk events, and the impact of liquidity risk events:
a. Sources of Liquidity Risk
Liquidity risk can be caused by the inability of the Securities Company to meet obligations arising from debts and transactions, whether conducted by clients or the Securities Company itself.
b. Liquidity Risk Events
c. Impact of Liquidity Risk
There is an interconnection between liquidity risk and other risks. For example, the inability to pay LKP claims for regular client transactions causes the Securities Company that is a Stock Exchange Member to be subject to trading suspension, which affects operational activities, reputation, and the compliance of the Securities Company that is a Stock Exchange Member in conducting Risk Management over transactions conducted (Figure 1).
Figure 1. Interconnection of Liquidity Risk with Other Risks
PE cannot pay LKP claims for regular client transactions Operational Risk Reputational Risk Compliance Risk
CHAPTER III
LIQUIDITY RISK MANAGEMENT PRINCIPLES
In general, liquidity risk management aims to manage resources optimally so as to be more effective and efficient in achieving business goals while limiting losses caused by the failure of those resources to perform their functions. In addition to this, good Risk Management will increase competitiveness and continuously improve the Risk Management conducted by Securities Companies that are Stock Exchange Members.
Liquidity Risk Management Framework
a. Liquidity Risk Management Strategy. b. Liquidity Risk Management Organizational Structure.
c. Liquidity Risk Policies, Procedures, and Limits.
Liquidity Risk Management Process
a. Identification and Measurement. b. Monitoring.
c. Control.
Liquidity Risk Control
The existence of risk control mechanisms and systems that can ensure the reliability of the liquidity risk management framework, which includes policies and organizational structure for the implementation of liquidity risk management.
CHAPTER IV
LIQUIDITY RISK ASSESSMENT
This section will outline the procedures for conducting liquidity risk management assessment.
Figure 2. Liquidity Risk Indicators
Explanation of Figure 2. KYSC Liquidity Risk Indicators:
and ranking liabilities, plus subordinated debt, and other adjustments.
Securities Companies conducting business as Underwriters of Securities must have an MKBD of at least Rp25,000,000,000.00 (twenty-five billion rupiah) or 6.25% (six point two five percent) of total liabilities without subordinated debt and debt for public/limited offerings plus ranking liabilities, whichever is higher. Securities Companies conducting business as Securities Brokerage Intermediaries that administer client Securities accounts must have an MKBD of at least Rp25,000,000,000.00 (twenty-five billion rupiah) or 6.25% (six point two five percent) of total liabilities without subordinated debt and debt for public/limited offerings plus ranking liabilities, whichever is higher. Securities Companies conducting business as Securities Brokerage Intermediaries that do not administer client Securities accounts must have an MKBD of at least Rp200,000,000.00 (two hundred million rupiah) or 6.25% (six point two five percent) of total liabilities without subordinated debt and debt for public/limited offerings plus ranking liabilities, whichever is higher.
Current Ratio
Current ratio is a ratio used to measure the company's ability to repay its short-term obligations, where it can be determined to what extent the company's current assets can actually guarantee its current liabilities.
Cash Ratio
This is a ratio used to measure the company's ability to pay short-term obligations with available cash and cash stored in banks.
LKP Debt
Liabilities of Securities Companies that are Stock Exchange Members as clearing members arising from Securities transactions conducted on the stock exchange.
Liabilities that arise can be in the form of Securities or money that must be settled on the transaction settlement date.
LKP uses a netting approach with novation (debt renewal) in clearing exchange transactions for equity products. Netting clearing with novation is applied to all exchange transactions occurring in every market segment, namely the regular market (RG), immediate market (SG), and cash market (TN).
Repo Debt Transactions
Repurchase Agreement (Repo) is a transaction involving the sale of a Securities instrument between two parties, accompanied by an agreement that at a later agreed time, the same Securities will be repurchased at a specific agreed price.
Client Fund Borrowing/Lending
The borrowing/lending of Securities and/or funds referred to is the borrowing of Securities and/or funds belonging to clients by Securities Companies that are Stock Exchange Members. The implementation of borrowing/lending of Securities and/or funds belonging to clients can only be conducted if there is a written agreement made separately between the Securities Company that is a Stock Exchange Member and each respective client. The implementation of the borrowing/lending agreement of Securities and/or funds by Securities Companies that are Stock Exchange Members with clients must contain:
a) benefits and risks for clients regarding status changes:
(1) the client becomes the lender and the Securities Company that is a Stock Exchange Member becomes the borrower in the case of Securities borrowing/lending; and (2) the client becomes the creditor and the Securities Company that is a Stock Exchange Member becomes the debtor in the case of fund borrowing/lending, so that the client's assets are no longer client assets, but become assets of the Securities Company that is a Stock Exchange Member; b) credit risks held by the client; c) the amount and value of Securities and/or the amount of funds borrowed;
d) rights and obligations of each party; e) in the event of changes to clauses in the agreement, the parties are required to amend the agreement (addendum); and f) the purpose of the use of Securities and/or borrowed funds. Member Securities Companies are required to convey to the relevant clients the content of the borrowing and lending agreement, especially changes in client status, so that clients truly understand the content of the agreement and the consequences they will receive.
Underwriting Activities
Securities Companies conducting business activities as Underwriters of Securities Issuance are parties that make contracts with issuers to conduct public offerings for the benefit of the issuer with or without the obligation to purchase remaining unsold Securities.
Policies and Procedures
In practice, applicable regulations will be implemented into internal regulations of Member Securities Companies. Even for Member Securities Companies fully committed to risk management, the provisions in the internal regulations drafted by Member Securities Companies can be more conservative than those regulated by the regulator. The tendency of Member Securities Companies to become increasingly committed to compliance with regulations will result in more conservative procedures and internal regulations in managing liquidity risk.
c. Thought Process of Liquidity Risk Assessment
Figure 3. Thought Process of Liquidity Risk Assessment
Table 2. Liquidity Risk Parameters and Indicators
| No | Liquidity Risk Parameter | Risk Measurement Indicators |
|---|---|---|
| 1. | Current assets cannot settle liabilities | Ratio of MKBD value to the minimum required MKBD value; the larger the ratio, the smaller the risk owned by the Member Securities Company.<br>Current Ratio; the larger the current ratio, the smaller the risk owned by the Member Securities Company.<br>Cash Ratio; the larger the cash ratio, the smaller the risk owned by the Member Securities Company. |
| 2. | Unable to settle LKP bills for regular client transactions | Ratio between the value of cash & cash equivalents plus collateral in LKP compared to the value of LKP liabilities; the larger the ratio, the smaller the risk owned by the Member Securities Company. |
| 3. | Repo debt transactions | Ratio between cash & cash equivalents and the value of repo liabilities; the larger the ratio, the smaller the risk owned by the Member Securities Company. |
| 4. | Company unable to settle client fund loans | Ratio between cash & cash equivalents and the value of client fund borrowing/lending; the larger the ratio, the smaller the risk owned by the Member Securities Company.<br>Ratio between the value of current assets and the value of client fund borrowing/lending; the larger the ratio, the smaller the risk owned by the Member Securities Company. |
| 5. | Company lacks liquidity capability when conducting underwriting activities (cash basis) | Activity of Securities Companies conducting business as Underwriters of Securities Issuance in conducting underwriting activities.<br>In the event that a Securities Company conducting business as an Underwriter of Securities Issuance has an obligation to purchase remaining unsold Securities (full commitment), the underwriting capability needs to be assessed by calculating 4 (four) times the difference between the MKBD value and the minimum required MKBD value, then compared with the value of the underwriting portion taken by the Securities Company conducting business as an Underwriter of Securities Issuance.<br>Business activities of Securities Companies conducting business as Underwriters of Securities Issuance in underwriting Securities listed abroad. |
| 6. | Company unable to settle transactions for institutional clients regarding failed receipts | Frequency of occurrence of failed receipts for institutional client transactions.<br>Value of failed receipts for institutional client transactions.<br>Frequency of lingering failed receipts for institutional clients.<br>Ratio between cash & cash equivalents and the value of failed receipts for institutional clients; the larger the ratio, the smaller the risk owned by the Member Securities Company.<br>Frequency of settlement obstacles for institutional client transactions, for example, if settlement of institutional client transactions cannot be done on the same day, it will increase the risk of the Member Securities Company. |
| 7. | Company unable to settle transactions regarding failed receipts from other Securities Companies | Ratio between cash & cash equivalents and the value of failed receipts from other Securities Companies; the larger the ratio, the smaller the risk owned by the Member Securities Company.<br>Frequency of occurrence of failed receipts from other Securities Companies.<br>Value of failed receipts from other Securities Companies.<br>Frequency of lingering failed receipts from other Securities Companies. |
Table 3. Liquidity Risk Parameters and Risk Management Measurement Indicators
| No | Liquidity Risk Parameter | Risk Management Measurement Indicators |
|---|---|---|
| 1. | Current assets cannot settle liabilities | Having written Asset and Liability policies implemented consistently. |
| 2. | Unable to settle LKP bills for regular client transactions | Having Standard Operating Procedures (SOP) or policies related to non-Margin financing (T-Plus) containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP.<br>Ease of requesting additional funds from shareholders. |
| 3. | Repo debt transactions | Having SOP or policies related to the mechanism for determining repo debt transactions containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP. |
| 4. | Company unable to settle client fund loans | Having SOP or policies related to client fund borrowing/lending containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP.<br>Appropriateness of client fund borrowing/lending agreements in accordance with regulations. |
| 5. | Company lacks liquidity capability when conducting underwriting activities (cash basis) | Having a policy considering MKBD in conducting underwriting.<br>Having a policy related to reserve funds while conducting underwriting.<br>Having risk management policies related to the company's capability in guaranteeing Securities listed abroad. |
| 6. | Company unable to settle transactions for institutional clients regarding failed receipts | There is a difference in policy between settlement for regular transactions and negotiation (OTC) transactions for institutional clients.<br>Having a policy to avoid potential failed delivery of institutional client transactions.<br>Having settlement policies for foreign clients. |
| 7. | Company unable to settle transactions regarding failed receipts from other Securities Companies | Having SOP or policies related to the mechanism for failed receipts from Member Securities Companies containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP. |
Table 4. Liquidity Risk Assessment Matrix
| Inherent Risk | Risk Management: Strong (Very Adequate) | Risk Management: Satisfactory (Adequate) | Risk Management: Fair (Fairly Adequate) | Risk Management: Marginal (Inadequate) | Risk Management: Unsatisfactory (Not Adequate) |
|---|---|---|---|---|---|
| Low (Low) | 1 | 2 | 3 | 4 | 5 |
| Low to Moderate (Low-Medium) | 2 | 4 | 6 | 8 | 10 |
| Moderate (Medium) | 3 | 6 | 9 | 12 | 15 |
| Moderate to High (Medium-High) | 4 | 8 | 12 | 16 | 20 |
| High (High) | 5 | 10 | 15 | 20 | 25 |
Based on Table 4, the range and liquidity risk ratings are obtained as follows:
Table 5. Liquidity Risk Range and Ratings
| Range | Rating |
|---|---|
| 1.00 - 2.99 | I |
| 3.00 - 4.99 | II |
| 5.00 - 9.99 | III |
| 10.00 - 16.00 | IV |
| 16.01 - 25.00 | V |
In certain conditions where the conditions in the worksheet are less relevant to determine the liquidity risk rating according to the actual conditions, Member Securities Companies can perform judgment using comprehensive and structured analysis to establish a higher or lower rating as long as it is considered more appropriate to describe the liquidity risk rating of the Member Securities Company and recorded in the conclusion of each liquidity risk indicator as documentation.
Table A. Definition of Inherent Liquidity Risk Ratings
| No | Liquidity Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) |
|---|---|---|---|---|---|---|
| 1. | Current assets cannot settle liabilities | Ratio of MKBD value to minimum required MKBD value is very large.<br>Current Ratio is very large.<br>Cash Ratio is very large. | Ratio of MKBD value to minimum required MKBD value is large.<br>Current Ratio is large.<br>Cash Ratio is large. | Ratio of MKBD value to minimum required MKBD value is medium.<br>Current Ratio is medium.<br>Cash Ratio is medium. | Ratio of MKBD value to minimum required MKBD value is small.<br>Current Ratio is small.<br>Cash Ratio is small. | Ratio of MKBD value to minimum required MKBD value is very small.<br>Current Ratio is very small.<br>Cash Ratio is very small. |
| 2. | Unable to settle LKP bills for regular client transactions | Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is very large.<br>Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is very large. | Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is large.<br>Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is large. | Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is medium.<br>Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is medium. | Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is small.<br>Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is small. | Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is very small.<br>Ratio between cash & cash equivalents plus collateral in LKP compared to LKP liabilities is very small. |
| 3. | Repo debt transactions | Ratio between cash & cash equivalents and repo liability value is very large. | Ratio between cash & cash equivalents and repo liability value is large. | Ratio between cash & cash equivalents and repo liability value is medium. | Ratio between cash & cash equivalents and repo liability value is small. | Ratio between cash & cash equivalents and repo liability value is very small. |
| 4. | Company unable to settle client fund loans | Ratio between cash & cash equivalents and client fund borrowing/lending value is very large.<br>Ratio between current assets value and client fund borrowing/lending value is very large. | Ratio between cash & cash equivalents and client fund borrowing/lending value is large.<br>Ratio between current assets value and client fund borrowing/lending value is large. | Ratio between cash & cash equivalents and client fund borrowing/lending value is medium.<br>Ratio between current assets value and client fund borrowing/lending value is medium. | Ratio between cash & cash equivalents and client fund borrowing/lending value is small.<br>Ratio between current assets value and client fund borrowing/lending value is small. | Ratio between cash & cash equivalents and client fund borrowing/lending value is very small.<br>Ratio between current assets value and client fund borrowing/lending value is very small. |
| 5. | Company lacks liquidity capability when conducting underwriting activities (cash basis) | Ratio of Difference in MKBD value x 4 / underwriting portion is very large.<br>Does not conduct underwriting of Securities listed abroad. | Ratio of Difference in MKBD value x 4 / underwriting portion is large.<br>- | Ratio of Difference in MKBD value x 4 / underwriting portion is medium.<br>- | Ratio of Difference in MKBD value x 4 / underwriting portion is small.<br>- | Ratio of Difference in MKBD value x 4 / underwriting portion is very small.<br>There is business activity of the Securities Company in underwriting Securities listed abroad. |
| 6. | Company unable to settle transactions for institutional clients regarding failed receipts | Never occurred failed receipts for institutional clients.<br>Never had issues related to settlement of institutional client transactions.<br>Frequency of failed receipts for institutional clients is low.<br>Frequency of lingering failed receipts for institutional clients is low.<br>Does not have institutional clients located abroad. | Average Value of failed receipts for institutional clients is small.<br>Ratio of average cash & cash equivalents / average failed receipts for institutional clients is large.<br>Settlement of institutional client transactions can be done on the same day.<br>Frequency of failed receipts for institutional clients is medium.<br>Frequency of lingering failed receipts for institutional clients is medium.<br>- | Average Value of failed receipts for institutional clients is medium.<br>Ratio of average cash & cash equivalents / average failed receipts for institutional clients is medium.<br>Settlement of institutional client transactions can be done on the same day.<br>Frequency of failed receipts for institutional clients is high.<br>Frequency of lingering failed receipts for institutional clients is high.<br>- | Average Value of failed receipts for institutional clients is large.<br>Ratio of average cash & cash equivalents / average failed receipts for institutional clients is small.<br>Settlement of institutional client transactions can be done on the same day.<br>Frequency of failed receipts for institutional clients is very high.<br>Frequency of lingering failed receipts for institutional clients is very high.<br>- | Average Value of failed receipts for institutional clients is very large.<br>Ratio of average cash & cash equivalents / average failed receipts for institutional clients is very small.<br>Settlement of institutional client transactions cannot be done on the same day.<br>-<br>-<br>-<br>Has institutional clients located abroad. |
| 7. | Company unable to settle transactions regarding failed receipts from other Securities Companies | Never occurred failed receipts.<br>Frequency of occurrence of failed receipts from other Securities Companies is low.<br>Value of failed receipts from other Securities Companies is small.<br>Frequency of lingering failed receipts from other Securities Companies is low. | Ratio between cash & cash equivalents and value of failed receipts from other Securities Companies is large.<br>Frequency of occurrence of failed receipts from other Securities Companies is medium.<br>Value of failed receipts from other Securities Companies is medium.<br>Frequency of lingering failed receipts from other Securities Companies is medium. | Ratio between cash & cash equivalents and value of failed receipts from other Securities Companies is medium.<br>Frequency of occurrence of failed receipts from other Securities Companies is high.<br>Value of failed receipts from other Securities Companies is large.<br>Frequency of lingering failed receipts from other Securities Companies is high. | Ratio between cash & cash equivalents and value of failed receipts from other Securities Companies is small.<br>Frequency of occurrence of failed receipts from other Securities Companies is very high.<br>Value of failed receipts from other Securities Companies is very large.<br>Frequency of lingering failed receipts from other Securities Companies is very high. | Ratio between cash & cash equivalents and value of failed receipts from other Securities Companies is very small.<br>-<br>-<br>- |
Table B. Definition of Liquidity Risk Management Implementation Quality Levels
| No | Liquidity Risk Parameter | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Not Adequate) |
|---|---|---|---|---|---|---|
| 1. | Current assets cannot settle liabilities | Having written asset and liability policies implemented consistently. | - Having unwritten asset and liability policies done consistently | - Not having asset and liability policies. | ||
| 2. | Unable to settle LKP bills for regular client transactions | Having SOP or policies related to non-Margin financing (T-Plus) containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP.<br>Very easy to request additional funds from shareholders. | Having SOP related to non-Margin financing (T-Plus) containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed incidentally and updated, and never having violations against the SOP.<br>Easy to request additional funds from shareholders. | Having written policies related to non-Margin financing (T-Plus) containing decision-making flows and adequate segregation of authority but not in the form of SOP, where the policy is implemented, supervised, and examined, not reviewed periodically and not updated, and no significant violations against the policy.<br>Quite easy to request additional funds from shareholders. | There are policies related to non-Margin financing (T-Plus) in the form of decision-making flows, portfolio criteria, and segregation of authority but unwritten.<br>Difficult to request additional funds from shareholders. | Not having policies related to non-Margin financing (T-Plus).<br>Very difficult to request additional funds from shareholders. |
| 3. | Repo debt transactions | Having SOP or policies related to the mechanism for determining repo debt transactions containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP. | Having SOP related to the mechanism for determining repo debt transactions containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed incidentally and updated, and never having violations against the SOP. | Having written policies related to the mechanism for determining repo debt transactions containing decision-making flows and adequate segregation of authority but not in the form of SOP, where the policy is implemented, supervised, and examined, not reviewed periodically and not updated, and no significant violations against the policy. | There are policies related to the mechanism for determining repo debt transactions but unwritten. | Not having policies related to the mechanism for determining repo debt transactions. |
| 4. | Company unable to settle client fund loans | Having SOP or policies related to client fund borrowing/lending containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed periodically and updated, and never having violations against the SOP.<br>Client fund borrowing/lending agreements are in accordance with regulations. | Having SOP related to client fund borrowing/lending containing decision-making flows and adequate segregation of authority, implemented, supervised, and examined, reviewed incidentally and updated, and never having violations against the SOP. | Having written policies related to client fund borrowing/lending containing decision-making flows and adequate segregation of authority but not in the form of SOP, where the policy is implemented, supervised, and examined, not reviewed periodically and not updated, and no significant violations against the policy. | There are policies related to client fund borrowing/lending but unwritten. | Not having policies related to client fund borrowing/lending.<br>Client fund borrowing/lending agreements are not in accordance with regulations. |
| 5. | Company lacks liquidity capability when conducting underwriting activities (cash basis) | Having SOP or policies related to underwriting activities containing decision-making flows and adequate segregation of authority, implemented, supervised, and | Having SOP related to underwriting activities containing decision-making flows and adequate segregation of authority, implemented, supervised, and reviewed | Having written policies related to underwriting activities containing decision-making flows and adequate segregation of authority but not in the form of SOP, where the policy is | There are policies related to underwriting activities but unwritten. | Not having policies related to underwriting activities. |
No Parameter
Risk
Liquidity
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) checked, reviewed periodically and updated, and never violations against SOPs. incidentally and updated, and never violations against SOPs. implemented, monitored, and checked, not periodically reviewed and not updated, and no violations against policies significantly. Has policies considering Net Tangible Assets (NTA) when performing underwriting.
No Parameter
Risk
Liquidity
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) while performing underwriting. while performing underwriting.
Has risk management policies regarding the company's ability to underwrite securities listed abroad.
No Parameter
Risk
Liquidity
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) for failed delivery.
Has policies to avoid potential failed delivery of transactions for institutional customers
No Parameter
Risk
Liquidity
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate) of other Securities
Companies. that is adequate, implemented, monitored, and checked, reviewed periodically and updated, and never violations against SOPs. implemented, monitored, and checked, reviewed incidentally and updated, and never violations against SOPs. that is adequate but not in the form of SOPs, where the policy is implemented, monitored, and checked, not periodically reviewed and not updated, and no violations against policies significantly.
Table C. Recommended Documents
implementation of liquidity risk management.
No
Risk Parameter
Liquidity
Documents/Information
No
Risk Parameter
Liquidity
Documents/Information
7. The Company
cannot perform settlement of transactions for failed delivery of other Securities Companies.
i
COMPLIANCE RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION............................................................................ 1
CHAPTER II FUNDAMENTAL CONCEPTS OF COMPLIANCE RISK
CHAPTER I
INTRODUCTION
Technological developments have led to an increase in the complexity of business activities of Securities Company Exchange Members, while simultaneously increasing the risk for Securities Company Exchange Members. This requires Securities Company Exchange Members to implement Risk Management properly in accordance with their business characteristics and complexity. Failure of Securities Company Exchange Members to perform Risk Management can cause significant losses and can even disrupt the continuity of the business of Securities Company Exchange Members. Compliance risk is the risk caused by a Securities Company not complying with and/or not implementing applicable laws and regulations and provisions applicable to Securities Companies. Compliance Risk can cause negative impacts from the behavior of Securities Company Exchange Members who do not comply with and/or do not implement applicable laws and regulations and provisions applicable to Securities Companies, in the form of operational disruptions, reputation, and assessment of requirements as Securities Company Exchange Members. In the context of preparing self-assessment reports, a guide is needed for Securities Company Exchange Members in assessing compliance risk. The compliance risk assessment of Securities Company Exchange Members contains basic principles in conducting compliance risk management assessment, which includes assessment of inherent risk and the quality of compliance risk management implementation.
CHAPTER II
FUNDAMENTAL CONCEPTS OF COMPLIANCE RISK
This section outlines the basic concepts of compliance risk management to facilitate Securities Company Exchange Members in assessing compliance risk. The basic concepts of compliance risk include: (1) sources, types/Types of events, and impacts of compliance risk (2) dimensions of Inherent Compliance Risk assessment, and (3) the interconnection of compliance risk with other risks.
CHAPTER III
PRINCIPLES OF COMPLIANCE RISK MANAGEMENT
Generally, compliance risk management aims to manage resources optimally so that they become more effective and efficient in achieving business goals while limiting losses caused by the failure of those resources to perform their functions. In addition, good Risk Management will increase competitiveness and continuously improve the Risk Management performed by Securities Company Exchange Members. This section outlines the principles of compliance risk management, which include:
CHAPTER IV
COMPLIANCE RISK ASSESSMENT
The operational risk assessment procedure is a general guide for Securities Company Exchange Members that can still be developed and adjusted to the complexity, business scale, and conditions of Securities Company Exchange Members.
Inherent Compliance Risk Assessment
The Inherent Compliance Risk Assessment has the following compliance risk parameter indicators:
Table 2. Parameters and Indicators of Compliance Risk
Compliance Risk
Parameter
Risk Measurement Indicator
Number of Sanctions The number of written reprimands, fines, activity restrictions, and suspension of business activities from OJK and SRO in the last 3 years, for each sanction can be weighted by Securities Company Exchange Members, for example, if a Securities Company Exchange Member receives a suspension of business activities sanction once, then the risk assessment is considered moderate, then a large weight can be given to the suspension of business activities sanction. Significance of fine value in the last 3 years compared to the difference in NTA, for example, the fine value is considered significant if it causes the average NTA value (last 3 years) to enter the Early Warning System or does not meet the minimum NTA value requirements. Repetition of violations, whether partial or complete, is considered an additional factor for compliance risk.
Assessment of the Quality of Compliance Risk Management Implementation
The quality of risk management implementation varies significantly between one Securities Company and another, depending on the complexity of its business. Nevertheless, generally, Securities Company Members of the Exchange must have Risk Management that includes a Compliance Risk Management Framework as mentioned in Chapter III.
Considering the scope of the aforementioned Risk Management framework, the indicators used by Securities Company Members of the Exchange to conduct an assessment of the compliance risk management of Securities Company Members of the Exchange are as follows:
Table 3. Compliance Risk Management Parameters and Indicators
Compliance Risk Parameter | Risk Management Measurement Indicator --- | --- Number of Sanctions | Has adequate Standard Operating Procedures (SOPs) or follow-up policies on findings from OJK and SRO inspections, which are implemented, supervised, and audited, reviewed periodically and updated, and where there have never been violations of the SOP.
There are functions within the company that still need improvement and have not implemented regulations due to inadequate infrastructure.
Based on the assessment results of Inherent Risk and the quality of compliance risk management implementation, the compliance risk rating is determined through a comprehensive and structured analysis that provides a holistic view of the compliance risk of Securities Company Members of the Exchange.
The assessment of Inherent Risk indicators and compliance risk management quality is conducted using a worksheet.
In the worksheet, conditions indicating the risk rating for each compliance risk indicator and the quality level of compliance risk management implementation have been defined, namely: Rating 1 (Strong), Rating 2 (Satisfactory), Rating 3 (Fair), Rating 4 (Marginal), and Rating 5 (Unsatisfactory).
A smaller order of magnitude indicates lower risk and better quality of compliance risk management implementation. For further clarity, this is illustrated in Table 4 as follows:
Table 4. Compliance Risk Assessment Matrix
| Inherent Risk | Risk Management | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Not Adequate) |
|---|---|---|---|---|---|---|
| Low (Low) | 1 | 2 | 3 | 4 | 5 | |
| Low to Moderate (Low-Medium) | 2 | 4 | 6 | 8 | 10 | |
| Moderate (Medium) | 3 | 6 | 9 | 12 | 15 | |
| Moderate to High (Medium-High) | 4 | 8 | 12 | 16 | 20 | |
| High (High) | 5 | 10 | 15 | 20 | 25 |
Based on Table 4, the range and compliance risk ratings are obtained as follows:
Table 5. Compliance Risk Range and Rating
| Range | Rating |
|---|---|
| 1.00 - 2.99 | I |
| 3.00 - 4.99 | II |
| 5.00 - 9.99 | III |
| 10.00 - 16.00 | IV |
| 16.01 - 25.00 | V |
In certain conditions where the conditions in the worksheet are less relevant for determining the compliance risk rating of Securities Company Members of the Exchange according to actual conditions, Securities Company Members of the Exchange may exercise judgment using comprehensive and structured analysis to establish a higher or lower rating, provided it is considered more accurate to describe the compliance risk rating of the Securities Company Member of the Exchange, and this must be recorded in the conclusion of each compliance risk indicator as documentation.
Table A. Definition of Compliance Inherent Risk Ratings
| Compliance Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) |
|---|---|---|---|---|---|
| Potential loss caused by compliance risk | Almost no potential loss caused by compliance risk during a certain period. Example of assessment characteristics below: | Small potential loss caused by compliance risk during a certain period. Example of assessment characteristics below: | Moderate potential loss caused by compliance risk during a certain period. Example of assessment characteristics below: | Quite high potential loss caused by compliance risk during a certain period. Example of assessment characteristics below: | High potential loss caused by compliance risk during a certain period. Example of assessment characteristics below: |
| Number of Sanctions | The Securities Company has never received sanctions from OJK and SRO. | Sanctions received by the Securities Company are not significant. | Sanctions received by the Securities Company are quite significant. | Sanctions received by the Securities Company are significant. | Sanctions received by the Securities Company are very significant. |
| - No repetition of violations. | There is repetition of a small portion of violations. | There is repetition of most of the violations. | There is repetition of all violations previously found. | - | |
| - The amount of fines is not significant against the difference between the MKBD value and the minimum required value. | The amount of fines is quite significant against the difference between the MKBD value and the minimum required value. | The amount of fines is significant against the difference between the MKBD value and the minimum required value. | The amount of fines is very significant against the difference between the MKBD value and the minimum required value. | - |
Table B. Definition of Compliance Risk Management Implementation Quality Levels
| Compliance Risk Parameter | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Not Adequate) |
|---|---|---|---|---|---|
| Quality of compliance risk management implementation viewed from the adequacy of the risk control system | The quality of compliance risk management implementation viewed from the adequacy of the risk control system is very adequate. Example of assessment characteristics below: | The quality of compliance risk management implementation viewed from the adequacy of the risk control system is adequate. Example of assessment characteristics below: | The quality of compliance risk management implementation viewed from the adequacy of the risk control system is fairly adequate. Example of assessment characteristics below: | The quality of compliance risk management implementation viewed from the adequacy of the risk control system is inadequate. Example of assessment characteristics below: | The quality of compliance risk management implementation viewed from the adequacy of the risk control system is not adequate. Example of assessment characteristics below: |
| Number of Sanctions | Has adequate SOPs for follow-up on violation findings, implemented, supervised, and audited, reviewed periodically and updated, and where there have never been violations of the SOP. | Has adequate SOPs for follow-up on violation findings, implemented, supervised, and audited, reviewed incidentally and updated, and where there have never been violations of the SOP. | Has written policies for follow-up on violation findings that are adequate but not in the form of SOPs, where the policy is implemented, supervised, and audited, not reviewed periodically and not updated, and where there are no significant violations of the policy. | There are follow-up policies for violation findings but they are not written. | No follow-up policy for violation findings. |
| - No functions within the company that still need improvement and have not implemented regulations due to inadequate infrastructure. | - | - | - | There are functions within the company that still need improvement and have not implemented regulations due to inadequate infrastructure. |
Table C. Recommended Documents
Securities Company Members of the Exchange in conducting the assessment of Inherent Risk and the quality of compliance risk management implementation.
| Compliance Risk Parameter | Document/Information |
|---|---|
| Number of Sanctions | 1. List of OJK sanctions containing the type of violation and fine amount in the last 3 years.<br>2. List of SRO sanctions containing the type of violation and fine amount in the last 3 years.<br>3. Recap of the Securities Company Member of the Exchange's response to follow-up on inspection findings (on-site examination).<br>4. Organizational structure of the Securities Company Member of the Exchange to view the adequacy of functions possessed by the Securities Company Member of the Exchange. |
i
LEGAL RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION............................................................................ 1
CHAPTER II BASIC CONCEPTS OF LEGAL RISK
CHAPTER I
INTRODUCTION
Technological development has led to an increase in the complexity of business activities of Securities Company Members of the Exchange, simultaneously increasing the risk of Securities Company Members of the Exchange. This requires Securities Company Members of the Exchange to implement Risk Management properly in accordance with the characteristics and complexity of their business. Failure of Securities Company Members of the Exchange to conduct Risk Management can cause significant losses and can even disrupt the continuity of the business of Securities Company Members of the Exchange.
Legal risk is the risk caused by legal claims, weaknesses in the legal aspects of agreements made by the Securities Company, and/or activities and products that are not yet regulated in legislation. This risk arises, among others, due to the absence of supporting legislation or weaknesses in obligations, such as the non-fulfillment of the validity requirements of an agreement.
In the preparation of self-assessment reports, a guide is needed for Securities Company Members of the Exchange in assessing legal risk. The legal risk assessment of Securities Company Members of the Exchange contains basic principles in conducting legal risk management assessment, which includes assessment of Inherent Risk and the quality of legal risk management implementation.
CHAPTER II
BASIC CONCEPTS OF LEGAL RISK
This section outlines the basic concepts of legal risk management to facilitate Securities Company Members of the Exchange in assessing legal risk. The basic concepts of legal risk include: (1) sources, types/types of events, and impact of legal risk (2) dimensions of Legal Inherent Risk assessment, and (3) the interconnection of legal risk with other risks.
The sources, types/types of events, and impact of legal risk that negatively affect Securities Company Members of the Exchange are explained in Table 1 below:
Table 1. Sources, Events, and Impact of Legal Risk
| Source | Event | Impact |
|---|---|---|
| 1. Lawsuit<br>2. Agreement/Obligation<br>3. Legislation | 1. The Company receives a lawsuit<br>2. The Company has an agreement with obligation weaknesses<br>3. Activities and products that have no regulations in applicable legislation | 1. Assessment of requirements as a Securities Company<br>2. Operational disruption<br>3. Violation of regulations<br>4. Compensation for damages<br>5. Uncollected receivables<br>6. Reputation |
The following is an explanation regarding Table 1, the sources of legal risk, types of legal risk events, and the impact of legal risk events:
a. Sources of Legal Risk
In conducting business activities, Securities Company Members of the Exchange can be sued civilly by other parties who feel harmed by the Securities Company Member of the Exchange, so that the lawsuit becomes a source of legal risk that must be faced by the Securities Company Member of the Exchange.
The lawsuits referred to in this case include lawsuits filed by parties who feel harmed by the Securities Company Member of the Exchange. Lawsuits can be filed through litigation channels and can also be filed through non-litigation channels; both channels are processes in an effort to resolve issues between two parties with a legal relationship. The lawsuit gives rise to a legal process for the Securities Company Member of the Exchange to undergo a litigation process through a judicial body or undergo a non-litigation process, among others, through an alternative dispute resolution body; the legal process aims to enforce the legal aspects of the legal relationship held by the Securities Company Member of the Exchange with the plaintiff party.
In civil law concepts, a civil lawsuit is generally based on 2 (two) main things, namely if there is a breach of contract or a tort committed by one party so as to harm the other party.
a) Breach of Contract
A lawsuit filed on the basis of breach of contract is a lawsuit that arises from an obligation between two parties; in this case, it generally occurs because there is an obligation between the parties but one party breaches the contract, thereby harming the other party.
Breach of contract means not doing what was promised to be done, doing what was promised but not as promised, doing what was promised but late, and doing something that according to the agreement should not be done. The consequences of breach of contract (negligence or fault) are: (i) compensation for both material and immaterial damages, (ii) cancellation of the agreement, (iii) transfer of risk, and (iv) paying court costs if the matter is taken to court.
Compensation is often detailed into three elements, namely costs, losses, and interest. Costs in this case are all expenses or expenditures that have clearly been incurred by one party. Loss is damage due to the non-implementation of the agreement because one party is negligent or at fault, thereby harming the other party. Interest is damage in the form of lost profits that have been imagined or calculated by the creditor.
In the concept of breach of contract, the party feeling harmed can file a lawsuit, among others, for fulfillment of the agreement, fulfillment of the agreement accompanied by compensation, compensation only, cancellation of the agreement, and/or cancellation of the agreement accompanied by compensation.
b) Tort
A lawsuit filed on the basis of a tort is a lawsuit that arises because of an act that is not in accordance with and contradicts regulations and/or norms applicable in society, so that there is a party who feels harmed.
Article 1365 of Book III of the Civil Code (BW) contains provisions that "Every tortious act that causes damage to another person obligates the person who, through their fault, caused the damage to compensate for the damage."
In litigation efforts, this certainly requires a long and very long time, starting from the stage of filing a lawsuit at the District Court to the cassation process at the Supreme Court, and must follow the applicable civil procedural law. This certainly requires mitigation from the management of Securities Company Members of the Exchange regarding the case and often results in considerable costs and gives rise to other risks such as reputational risk.
The legal aspect issues or legal aspect weaknesses are more directed at weaknesses in agreements made by Securities Company Members of the Exchange. This is related to the validity requirements of agreements and clauses, both regarding structure and the content of articles in agreements entered into by Securities Company Members of the Exchange with customers or third parties, taking into account applicable regulations such as OJK Regulations on standard agreements and the mechanism for using alternative dispute resolution institutions.
To understand the general principles regarding the validity requirements of agreements, it is necessary to master the obligation provisions regulated in Book III of the Civil Code.
An agreement is an event where one person promises to another person or where more than one party promises each other to carry out something. From this event, an obligation arises, which is a legal relationship between more than one party or two parties, where one party has the right to demand something from the other party, and the other party is obligated to fulfill that demand, guaranteed by law or legislation.
Article 1338 of the BW states that:
"All agreements made legally are binding as legislation for those who make them."
Article 1320 of the BW regulates that:
"For the validity of an agreement, four requirements are needed: (i) Agreement of those who bind themselves; (ii) Capacity to make an agreement; (iii) A specific object; and (iv) A lawful cause."
The first two requirements above are subjective requirements because they concern the persons or subjects, while the following two requirements are objective requirements because they concern the agreement itself. In the event that subjective requirements are not met, one party can request the cancellation of the agreement. In the event that objective requirements are not met, the agreement is void ab initio, meaning that from the beginning the agreement is considered never to have existed.
In addition to the obligation to comply with the validity requirements of agreements, a good agreement must certainly go through good planning, organization, processing, and internal control processes so as to mitigate risks that may arise, especially legal risks. This can be seen from the form, format, and clauses of the agreement. Generally, the structure of a good agreement contains matters such as:
a) The parties to the agreement and the date and place of the agreement
In this case, it generally mentions the names of the persons from the parties signing the agreement and the capacity of such persons, as well as the legal basis and authority of such persons, including address/domicile. In addition, the date and place of the agreement are also mentioned.
b) Consideration (recital/background)
This section explains the purpose of the parties entering into the agreement and matters supporting such purpose, as well as important facts of the contract.
c) Definitions
Definitions are intended to classify terminology used in the agreement so that there is no diverse interpretation and to minimize potential conflicts from terminology.
d) Pre-Conditions (Condition Precedent)
In this case, matters that must be fulfilled first before the agreement or contract becomes effective are agreed upon, such as documents that must be submitted or payments that must be made first.
e) Rights and Obligations
In this case, the parties set forth matters that are agreed upon, which are highly determined by the object of the agreement and require material explanation presented in the definition section, and clearly describe the rights and obligations of each party, such as amount and duration, purpose of use, interest and provisions, costs, fines, repayment, taxes, insurance, collateral, powers of attorney, and others.
f) Representations and Warranties
Representations in this case concern the existence of the parties, statements regarding the validity of such parties in entering into the contract, statements regarding the status of the company represented, statements regarding the validity of necessary documents, and others. Warranties can include warranties that all rights and obligations agreed upon are legal, warranties regarding no potential claims from other parties now or in the future, warranties regarding no errors in all provided documents, warranties regarding no legal issues in ownership rights involved in the contract, and others.
g) Covenants
A covenant can be a positive/affirmative covenant or a negative covenant. Positive/affirmative covenants are matters that must be done by the parties to ensure that the agreement can be executed during the specified duration and that the required conditions can be executed/maintained. Conversely, negative covenants are matters that must not be done by the parties regarding the execution of the agreement.
h) Events of Default
In this case, the parties determine matters categorized as events of default and the consequences of such events of default occurring, including whether notice or warning is necessary, and procedures for accelerating the maturity date of the entire agreement and the right to terminate the agreement.
i) Force Majeure
In this case, it regulates conditions if force majeure occurs, both generally and specifically, such as earthquakes and others.
In addition to fulfilling Article 1338 of the BW, in drafting an agreement, Securities Company Members of the Exchange are required to fulfill OJK Circular Letter Number 13/SEOJK.07/2014 regarding Standard Agreements. Standard Agreements (SEOJK 13/2014) are written agreements established unilaterally by Financial Service Business Actors (PUJK) and contain standard clauses regarding content, form, and manner of creation, and are used to offer products and/or services to consumers on a mass basis.
The clauses required in SEOJK 13/2014 are as follows:
a) Exoneration/exemption clauses, which contain content that adds rights and/or reduces the obligations of the PUJK, or reduces rights and/or adds the obligations of the Consumer.
b) Abuse of circumstances, which is a condition in a Standard Agreement that has indications of abuse of circumstances. An example of this condition is, for instance, exploiting the consumer's urgent condition due to certain conditions or in an emergency, and the PUJK intentionally or unintentionally does not explain the benefits, costs, and risks of the offered products and/or services.
Standard agreements that are prohibited are agreements that contain the following matters:
a) stating the transfer of responsibility or obligations of the Securities Company (PUJK) to the consumer; b) stating that the PUJK has the right to refuse the return of money already paid by the consumer for products and/or services purchased; c) stating the granting of power of attorney from the consumer to the PUJK, either directly or indirectly, to take any unilateral actions regarding goods pledged by the consumer, except where such unilateral actions are performed based on applicable legislation; d) requiring the consumer to prove the PUJK's claims that the loss of utility of the purchased product and/or service is not the responsibility of the PUJK; e) granting the PUJK the right to reduce the utility of the product and/or service or reduce the consumer's assets that are the object of the product and service agreement; f) stating that the consumer is subject to new, additional, supplementary, and/or changed rules made unilaterally by the PUJK during the period the consumer utilizes the purchased product and/or service; and/or g) stating that the consumer grants power of attorney to the PUJK for the imposition of mortgage rights, pledge rights, or other security rights over products and/or services purchased by the consumer on an installment basis.
The Format of Standard Agreements based on SEOJK 13/2014 includes among others:
a) Standard agreements containing consumer rights and obligations and requirements that legally bind the consumer must use letters, writing, symbols, diagrams, signs, terms, phrases that are readable, and/or sentences that are simple in Indonesian language and easily understood by consumers. b) If the consumer finds ambiguity, the PUJK is required to provide explanations regarding terms, phrases, sentences, and/or symbols, diagrams, and signs that are not yet understood by the consumer, either in writing within the Standard Agreement or orally before the Standard Agreement is signed. c) In the event that the Standard Agreement uses terms, phrases, and/or sentences from languages other than Indonesian, such terms, phrases, and/or sentences from other languages must be juxtaposed with terms, phrases, and/or sentences in Indonesian. d) Standard agreements must contain the following statement:
"THIS AGREEMENT HAS BEEN ADAPTED TO THE PROVISIONS OF APPLICABLE LEGISLATION, INCLUDING THE PROVISIONS OF FINANCIAL SERVICES AUTHORITY REGULATIONS." e) In addition to printed form, Standard Agreements may be in digital or electronic form, referred to as e-contracts, offered by the PUJK through electronic media. f) In the event that the Standard Agreement is in printed form, the following matters apply:
(1) The PUJK is required to ensure written approval from the Consumer by, among other things, affixing a signature in the Standard Agreement or other documents that are an integral part of the Standard Agreement stating consumer approval. (2) The PUJK may duplicate it so that transactions can meet the objectives, namely being fast, effective, efficient, repetitive, and providing legal certainty.
b. Legal Risk Events
c. Impact of Legal Risk
d. Tolerance in Legal Risk Assessment
Legal risk assessment includes assessment of the possibility (probability) of an event and the impact caused. An event with small possibility and impact can still be tolerated and does not need intensive attention, although this does not mean that Securities Company Members of the Exchange can ignore such risks. Conversely, attention needs to be given intensively to risks that have large possibility and impact so that they cannot be tolerated and immediately require control efforts.
For the same risk event, it can provide different levels of possibility and impact for each Securities Company Member of the Exchange because the tolerance level or risk rating that can still be taken (risk appetite) of each Securities Company Member of the Exchange is different. Measuring risk appetite is heavily influenced by the level of knowledge of the Securities Company Member of the Exchange regarding its own company (Know Your Securities Company).
Figure 1. Interconnection of Legal Risk with Other Risks
Legal Risk
In Absensia Decision in
Litigation Process
Profitability
Reputational Risk
Operational Risk
Compensation Obligation
Increasing Burden
Loss of Clients
Potential
CHAPTER III
LEGAL RISK MANAGEMENT PRINCIPLES
This section describes legal risk management principles, which among others consist of:
Legal Risk Management Framework
a. Implementing all applicable national and international legislation and best practices to avoid legal claims from within and abroad. b. Consistency in making agreements in accordance with applicable national and international legislation and best practices to avoid legal claims from within and abroad.
c. Having adequate systems and policies.
d. Having adequate resources. e. Prioritizing the use of alternative dispute resolution institutions in every dispute settlement clause in agreements. f. Service activities and products offered are always accompanied by underlying agreements and adequate guarantees in accordance with the complexity and risk of each service and product offered, and have been regulated by the Financial Services Authority (OJK) or at least obtained approval from the Financial Services Authority (OJK).
Legal Risk Management Process
a. The Board of Directors and Board of Commissioners have thoroughly understood the legal risk management strategy after being able to define and identify legal risks. b. The Board of Directors and Board of Commissioners ensure that the legal risk management strategy has been effectively and transparently formulated in policies and procedures.
c. The Board of Directors and Board of Commissioners are responsible for the implementation of the established legal risk management strategy, policies, and procedures.
Legal Risk Control
The existence of mechanisms and risk control systems that can ensure the reliability of the legal risk management framework, which includes policies, organizational structure, resource allocation, and information systems regarding the implementation of legal risk management.
CHAPTER IV
LEGAL RISK ASSESSMENT
This section will describe the procedures for conducting legal risk management assessment. The assessment procedures are general guidelines for Securities Company Members of the Exchange which can still be developed and adjusted to the complexity, business scale, and conditions of the Securities Company Members of the Exchange.
Figure 2. Legal Risk Indicators
Explanation of Figure 2. Legal Risk Indicators:
c. Thought Process of Legal Risk Assessment
Figure 3. Legal Risk Assessment Thought Process
Table 2. Legal Risk Parameters
No
Legal Risk Parameter
Risk Measurement Indicator
Company receives
claims/litigation
There is a litigation process against
Securities Companies by clients of
Securities Company Members of the Exchange
Significant claim value (causing average MKBD value of Securities Company Members of the Exchange to fail to meet the minimum MKBD value required) Litigation process not handled adequately (not attending court sessions/ in absensia).
Company has
agreements with agreement weaknesses
Agreements made by Securities Company
Members of the Exchange are inadequate and there are several major weaknesses that can cause errors in agreement interpretation by both parties and law enforcement officials. The division overseeing law in Securities Company Members of the Exchange pays less attention to recent developments in order to periodically review the agreements used by Securities Company Members of the Exchange.
Absence of
legislation
Securities Company Members of the Exchange do not have activities and products that have no rules in applicable legislation, namely as parties conducting marketing or as issuers.
Quality of Legal Risk Management Implementation Assessment
The quality of risk management implementation varies between one Securities Company and another depending on the complexity of its business. However, generally, Securities Company Members of the Exchange must have Risk Management that includes the Legal Risk Management Framework as mentioned in Chapter III. Considering the scope of the Risk Management framework, the indicators used by Securities Company Members of the Exchange to conduct legal risk management assessment of Securities Company Members of the Exchange are as follows:
Table 3. Legal Risk Management Implementation Parameters
No
Legal Risk Parameter
Risk Management Measurement Indicator
Company
receives claims/ litigation
Securities Company Members of the Exchange appoint legal counsel/ have competent legal staff Have adequate Standard Operating Procedures (SOP) for handling litigation, implemented, supervised, and examined, periodically reviewed and updated, and there have never been violations against SOP
Company has
agreements with agreement weaknesses
Securities Company Members of the Exchange always use dispute resolution forums Have adequate Standard Operating Procedures (SOP) for drafting agreements, implemented, supervised, and examined, periodically reviewed and updated, and there have never been violations against SOP
Absence of
legislation
Activities and products that have no rules are accompanied by underlying agreements and adequate guarantees.
Obtain approval from the Financial Services Authority (OJK)
Legal Risk Rating Assessment
Based on the assessment results of Inherent Risk and the quality of legal risk management implementation, the legal risk rating is determined based on comprehensive and structured analysis that provides a comprehensive picture of the legal risk of Securities Company Members of the Exchange. Assessment of Inherent Risk Indicators and legal risk management is conducted using a worksheet. In the worksheet, conditions indicating the risk rating of each legal risk indicator and the level of quality of legal risk management implementation have been determined, namely Rating 1 (strong), Rating 2 (satisfactory), Rating 3 (fair), Rating 4 (marginal), and Rating 5 (unsatisfactory). A smaller order level indicates lower risk and better quality of legal risk management implementation, for clarity described through Table 4 as follows:
Table 4. Legal Risk Assessment Matrix
Inherent Risk
Risk Management
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate)
Low
(Low)
1 2 3 4 5
Low to
Moderate
(Low to Medium)
2 4 6 8 10
Moderate
(Medium)
3 6 9 12 15
Moderate to
High
(Medium to High)
4 8 12 16 20
High
(High)
5 10 15 20 25
Based on Table 4, the range and legal risk rating are obtained as follows:
Table 5. Range and Legal Risk Rating
Range Rating
1.00 - 2.99 I
3.00 - 4.99 II
5.00 - 9.99 III
10.00 - 16.00 IV
16.01 - 25.00 V
In certain conditions where the conditions in the worksheet are less relevant to determine the legal risk rating of Securities Companies according to actual conditions, Securities Company Members of the Exchange can perform judgment using comprehensive and structured analysis to set a higher or lower rating as long as it is considered more appropriate to describe the legal risk rating of Securities Company Members of the Exchange and recorded in the conclusion of each legal risk indicator as documentation.
Table A. Definition of Inherent Legal Risk Ratings
No Legal Risk Parameter
Low
(Low)
Low to Moderate
(Low to Medium)
Moderate
(Medium)
Moderate to High
(Medium to High)
High
(High)
Potential losses caused by legal risk almost none during a certain time period.
Example assessment characteristics below:
Potential losses caused by legal risk are small during a certain time period.
Example assessment characteristics below:
Potential losses caused by legal risk are moderate during a certain time period.
Example assessment characteristics below:
Potential losses caused by legal risk are quite high during a certain time period.
Example assessment characteristics below:
Potential losses caused by legal risk are high during a certain time period.
Example assessment characteristics below:
No Legal Risk Parameter
Low
(Low)
Low to Moderate
(Low to Medium)
Moderate
(Medium)
Moderate to High
(Medium to High)
High
(High)
Claim value is not significant
For example, does not cause average MKBD Value of Securities Company Members of the Exchange to be in EWS condition (<120%).
Claim value is not significant
For example, causes average MKBD Value of Securities Company Members of the Exchange to be in EWS condition (110% < MKBD value <120%).
Claim value is not significant
For example, causes average MKBD Value of Securities Company Members of the Exchange to be in EWS condition (100% < MKBD Value <110%).
Claim value is not significant
For example, causes average MKBD Value of Securities Company Members of the Exchange to fail to meet the minimum MKBD value required.
No Legal Risk Parameter
Low
(Low)
Low to Moderate
(Low to Medium)
Moderate
(Medium)
Moderate to High
(Medium to High)
High
(High)
Litigation process handled adequately.
Litigation process handled adequately.
Litigation process handled adequately.
Not handled (not attending court sessions/ in absensia).
2. Company
has agreements with agreement weaknesses
Agreements made by
Securities Company Members of the Exchange are very adequate Agreements made by Securities Company Members of the Exchange are adequate but still have several minor weaknesses.
Agreements have been reviewed by independent legal consultants but not periodically, but Agreements made by Securities Company Members of the Exchange are quite adequate but still have several weaknesses that are less significant and need to be fixed soon. Securities Companies have not fully performed Agreements made by Securities Company Members of the Exchange are inadequate and there are several major weaknesses that can cause errors in agreement interpretation by both parties and law enforcement officials. The division overseeing law in Securities Companies pays less attention to recent developments in order to periodically review the agreements used by Securities Companies. Agreements made by Securities Company Members of the Exchange are completely inadequate and have never been reviewed so that weaknesses are unknown.
No Legal Risk Parameter
Low
(Low)
Low to Moderate
(Low to Medium)
Moderate
(Medium)
Moderate to High
(Medium to High)
High
(High) law division at
Securities Companies has performed periodic review of agreements used by Securities Companies. updating of agreements used.
3. Absence of
legislation
Securities Company Members of the Exchange do not have any activities and products that have no rules in applicable legislation Securities Company Members of the Exchange do not have any activities and products that have no rules in applicable legislation Securities Company Members of the Exchange market certain activities and products that have no rules in applicable legislation Securities Company Members of the Exchange have certain activities and products that have no rules in Securities Company Members of the Exchange issue certain activities and products that have no rules in
No Legal Risk Parameter
Low
(Low)
Low to Moderate
(Low to Medium)
Moderate
(Medium)
Moderate to High
(Medium to High)
High
(High) rules in applicable legislation in applicable legislation in applicable legislation applicable legislation applicable legislation
Table B. Definition of Legal Risk Management Implementation Quality Levels
| No | Parameter | Legal Risk | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Very Inadequate) | ||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Quality of legal risk management implementation viewed from human resources and adequacy of risk control systems | The quality of legal risk management implementation viewed from human resources and adequacy of risk control systems is very adequate. Example assessment characteristics below: | The quality of legal risk management implementation viewed from human resources and adequacy of risk control systems is adequate. Example assessment characteristics below: | The quality of legal risk management implementation viewed from human resources and adequacy of risk control systems is fairly adequate. Example assessment characteristics below: | The quality of legal risk management implementation viewed from human resources and adequacy of risk control systems is inadequate. Example assessment characteristics below: | The quality of legal risk management implementation viewed from human resources and adequacy of risk control systems is very inadequate. Example assessment characteristics below: | ||||||
| 1. | Company receives litigation | Securities Company Member of the Exchange appoints legal counsel/has competent legal staff | Securities Company Member of the Exchange appoints legal counsel/has competent legal staff | Securities Company Member of the Exchange appoints legal counsel/has competent legal staff | Securities Company Member of the Exchange appoints legal counsel/has competent legal staff | Securities Company Member of the Exchange does not appoint legal counsel/does not have legal staff | Has Adequate Standard Operating Procedures (SOP) for handling litigation, implemented, supervised, and reviewed periodically and updated, and there have never been violations of the SOP | Has Adequate Standard Operating Procedures (SOP) for handling litigation, implemented, supervised, and reviewed incidentally and updated, and there have never been violations of the SOP | Has written litigation handling policy that is adequate but not in the form of Standard Operating Procedures (SOP), where the policy is implemented, supervised, and reviewed, not reviewed periodically and not updated, and there are no significant violations of the policy | Has litigation handling policy but it is not written | Does not have a litigation handling policy |
| 2. | Company has agreements with weak obligations | Securities Company Member of the Exchange always uses dispute resolution forum clauses | Securities Company Member of the Exchange always uses dispute resolution forum clauses | Securities Company Member of the Exchange does not always use dispute resolution forum clauses | Securities Company Member of the Exchange does not always use dispute resolution forum clauses | Securities Company Member of the Exchange does not use dispute resolution forum clauses | Has Adequate Standard Operating Procedures (SOP) for drafting agreements, implemented, supervised, and reviewed periodically and updated, and there have never been violations of the SOP | Has Adequate Standard Operating Procedures (SOP) for drafting agreements, implemented, supervised, and reviewed incidentally and updated, and there have never been violations of the SOP | Has written agreement drafting policy that is adequate but not in the form of Standard Operating Procedures (SOP), where the policy is implemented, supervised, and reviewed, not reviewed periodically and not updated, and there are no significant violations of the policy | Has policy regarding agreement drafting but it is not written | Does not have SOP or policy regarding agreement drafting used by the Securities Company Member of the Exchange |
| 3. | Absence of regulations | Activities and products that have no regulations are accompanied by adequate underlying agreements and guarantees. | Activities and products that have no regulations are accompanied by adequate underlying agreements and guarantees. | Activities and products that have no regulations are not accompanied by adequate underlying agreements and guarantees. | Obtains approval from the Financial Services Authority (OJK) | Has not obtained approval from the Financial Services Authority (OJK) | Does not obtain approval from the Financial Services Authority (OJK) |
Table C. Recommended Documents for Legal Risk Management Implementation
| No | Legal Risk Parameter | Documents/Information |
|---|---|---|
| 1. | Company receives litigation | 1. Written policies and procedures of the Securities Company Member of the Exchange regarding litigation handling<br>2. Litigation filed by the Securities Company Member of the Exchange against third parties and/or third parties against the Securities Company<br>3. Financial reports related to costs incurred in connection with the litigation process<br>4. Summons filed against the Securities Company Member of the Exchange by customers/debtors or third parties, or customer complaint reports that cannot be resolved by the Securities Company Member of the Exchange |
| 2. | Company has agreements with weak obligations | 1. Written policies and procedures of the Securities Company conducting business as an Underwriter and/or Stock Exchange Member Broker regarding litigation handling<br>2. Securities Company agreements and Offering Letters from the Securities Company to customers/debtors or third parties, Letters of Intent, Memorandum of Understanding (MoU), or Letters of Commitment (LoC) |
| 3. | Absence of regulations | 1. Written policies and procedures of the Securities Company regarding litigation handling<br>2. List of types of products and services offered by the Securities Company<br>3. OJK approval for other activities in accordance with POJK 20/POJK.04/2016 on Licensing of Securities Companies Conducting Business as Underwriters and Stock Exchange Member Brokers and SEOJK 14/SEOJK.04/2018 on Other Activities for Securities Companies Conducting Business as Underwriters and Stock Exchange Member Brokers |
i
REPUTATION RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION ........................................................................... 1
CHAPTER II BASIC CONCEPTS OF REPUTATION RISK
CHAPTER I
INTRODUCTION
Technological development has led to an increase in the complexity of business activities of Securities Companies that are Members of the Exchange, while simultaneously increasing the risk for Securities Companies that are Members of the Exchange. This requires Securities Companies that are Members of the Exchange to implement Risk Management properly in accordance with their business characteristics and complexity. Failure of Securities Companies that are Members of the Exchange to conduct Risk Management can cause significant losses and can even disrupt the continuity of the business of Securities Companies that are Members of the Exchange.
Reputation risk is the risk caused by a decrease in the level of trust of stakeholders, which stems from customer complaints and/or negative news reports about the Securities Company. Negative perceptions of Securities Companies that are Members of the Exchange, whether originating from the actions of the Securities Company itself or from external parties, mean that Securities Companies that are Members of the Exchange must take mitigation actions to reduce the impact of such negative perceptions.
In the context of preparing self-assessment reports, a guide is needed for Securities Companies that are Members of the Exchange in assessing reputation risk. The reputation risk assessment of Securities Companies that are Members of the Exchange contains basic principles for conducting reputation risk management assessment, which includes assessment of Inherent Risk and the quality of reputation risk management implementation.
CHAPTER II
BASIC CONCEPTS OF REPUTATION RISK
This section outlines the basic concepts of reputation risk management to facilitate Securities Companies that are Members of the Exchange in assessing reputation risk. The basic concepts of reputation risk include: (1) sources, types/types of events, and impacts of reputation risk; (2) dimensions of Inherent Reputation Risk assessment; and (3) the interconnection of reputation risk with other risks.
Table 1. Sources, Events, and Impacts of Reputation Risk
| Source | Event | Impact |
|---|---|---|
| 1. Customer complaints<br>2. Negative news reports | 1. Frequency of complaints<br>2. Type of complaint<br>3. Frequency of negative news reports<br>4. Type of negative news reports<br>5. Impact of negative news reports<br>6. Media used in negative news reports | 1. Operational disruption<br>2. Regulatory violations<br>3. Compensation for losses<br>4. Loss of potential customers due to decreased reputation<br>5. Assessment of requirements as a Securities Company (PE) |
The following is an explanation regarding the sources of reputation risk, types of reputation risk events, and impacts of reputation risk events:
a) Sources of Reputation Risk
Definition of Complaint is an expression of consumer dissatisfaction, whether oral or written, caused by actual and/or potential material, fair, and direct losses to the Consumer due to the non-fulfillment of financial agreements and/or transaction documents that have been agreed upon.
Definition of complaint handling is the service and resolution of complaints in the financial services sector.
a) Obligations of Securities Companies that are Members of the Exchange regarding customer complaints Securities Companies that are Members of the Exchange are obligated to serve and resolve customer complaints before the complaint is submitted to other parties, with the following provisions:
(1) providing balanced and objective treatment to every complaint; (2) providing adequate opportunity for customers to explain the substance of the complaint; and (3) providing opportunity to other parties who have an interest in the complaint, to provide explanations in the resolution of the complaint (if any).
Securities Companies that are Members of the Exchange must follow up and resolve complaints orally within a maximum of 5 (five) working days from the date the complaint is received, and must follow up and resolve complaints in writing within a maximum of 20 (twenty) working days from the date documents directly related to the complaint are received completely.
In the event of certain conditions, Securities Companies that are Members of the Exchange may extend the time limit by a maximum of 20 (twenty) working days from the end of the initial time limit.
Securities Companies that are Members of the Exchange must establish a function or complaint service unit to receive or resolve complaints submitted by consumers or consumer representatives.
Securities Companies that are Members of the Exchange must have complaint service and resolution procedures that at least cover the following:
(1) Application of principles of accessibility, independence, fairness, efficiency, and effectiveness; (2) Implementation of receiving customer complaints through various means such as face-to-face, email, and mail, but not including complaints made through media reports; (3) Communication procedures with customers at least covering:
(a) complaint service and resolution procedures in a format that is easy to understand and easily accessible by customers; and (b) offering resolution if, based on the analysis and evaluation conducted by the Securities Company that is a Member of the Exchange, the complaint is caused by the fault of the Securities Company that is a Member of the Exchange. (4) Keeping confidential information regarding customers who file complaints from any party.
b) Results of Complaint Resolution
Securities Companies that are Members of the Exchange may resolve complaints by issuing an apology or offering compensation (redress/remedy) to customers, with the following provisions:
(1) Apology
Given that an "apology" is an act between the Securities Company that is a Member of the Exchange and the customer, the procedure for giving an "apology" is made based on mutual agreement.
(2) Compensation
Compensation that can be given is for losses occurring due to financial aspects. Compensation as referred to must meet the following requirements:
(a) there is a complaint containing a claim for compensation related to financial aspects; (b) the customer's complaint submitted is true, after the Securities Company that is a Member of the Exchange conducts an investigation; (c) there is a discrepancy between the product and/or service agreement and the product and/or service received; (d) there is material loss; and (e) the customer has fulfilled their obligations.
The mechanism for submitting a compensation claim must meet the following:
(a) submitting a compensation request accompanied by a chronology of events explaining the product and/or use of services that do not match, accompanied by evidence; (b) the request is made within a maximum of 30 (thirty) days from the date the product and/or service that does not match the agreement is known; (c) the request is submitted with a written request and can be represented by attaching a power of attorney; and (d) compensation is only for losses that directly impact the customer and at most equal to the value of the loss experienced by the customer.
Based on the principle of lex specialis derogat legi generalis (special law overrides general law), Law Number 40 of 1999 concerning the Press ("Press Law") is the lex specialis compared to the Civil Code ("KUHPer") and also compared to the Criminal Code ("KUHP"). Therefore, in the event of a problem related to press reporting, the applicable regulation is the Press Law.
The Right of Reply is the right of a person or group of people to provide a response or rebuttal to news reports containing facts that harm their good name, while the Right of Correction is the right of every person to correct or rectify erroneous information provided by the press, whether about themselves or about others.
The resolution mechanisms that can be taken by Securities Companies that are Members of the Exchange in the event of news reports that harm the Securities Company that is a Member of the Exchange are as follows:
a) The Securities Company that is a Member of the Exchange directly submits its right of reply to the editorial office, which in this case represents the press company, subsequently, as the responsible party, the editorial office is obligated to serve the Right of Reply and Right of Correction perfectly. Securities Companies that feel their good name is harmed by the report must provide the data or facts intended as evidence to refute or rebut that the report is incorrect. Implementation of the Right of Reply can be seen in Article 10 of the Press Council Regulation Number: 6/Regulation-DP/V/2008 concerning the Approval of the Press Council Decision Number 03/SK-DP/III/2006 concerning the Journalistic Code of Ethics as a Press Council Regulation ("Journalistic Code of Ethics") (as the new code of ethics for journalists), which states that "Indonesian journalists immediately withdraw, correct, and improve erroneous and inaccurate news accompanied by an apology to readers, listeners, and/or viewers". b) Furthermore, the implementation of the Right of Reply and Right of Correction can also be done to the Press Council (Article 15 paragraph [2] letter d of the Press Law). It is stated that one of the functions of the Press Council is to provide consideration and strive to resolve public complaints regarding cases related to press reporting. c) Problems arising from press reports can also be filed as a civil lawsuit in court or reported to the police. However, since the mechanism for resolving problems arising from press reports is specifically regulated in the Press Law, the ultimate outcome is the fulfillment of the Right of Reply or Right of Correction, so that the court (in civil cases) or investigators, prosecutors, or judges examining and adjudicating the case still use the Press Law, with the ultimate outcome being the fulfillment of the Right of Reply and/or Right of Correction. Follow-up actions that can be applied by Securities Companies that are Members of the Exchange using the Right of Reply include:
a) Responses from the press regarding the Right of Reply and Right of Correction are a correction obligation as contained in Article 1 letter 13 of the Press Law. The Correction Obligation is the requirement to correct or rectify incorrect information, data, facts, opinions, or images that have been reported by the press in question. This correction obligation is also a form of press responsibility for the news it publishes. In practice, the use of the Right of Reply is considered to function to resolve problems peacefully. b) Furthermore, the Journalistic Code of Ethics also states that the final assessment of violations of the journalistic code of ethics is conducted by the Press Council. Sanctions for violations of the journalistic code of ethics are carried out by journalist organizations and/or press companies. c) On the other hand, the party harmed by press reporting still has the right to submit their problem to court, either civilly or criminally. In criminal cases involving the press, the judge examining the case must refer to the Supreme Court Circular Letter Number 13 of 2008 concerning Requesting Information from Expert Witnesses (SEMA 13/2008). Based on SEMA Number 13 of 2008 in handling/examining cases related to press offenses, the panel of judges should hear/request information from expert witnesses from the Press Council, because the Press Council knows the intricacies of the press better both theoretically and practically.
d) Reputation Risk Events
(1) Frequency and type of complaints
(2) Frequency, type, impact of negative news reports, and media used in negative news reports. e) Impacts of Reputation Risk (1) Operational disruption.
(2) Regulatory violations, which result in:
(a) Fines or other administrative sanctions
(b) License suspension sanctions
(c) License revocation sanctions
(3) Compensation for losses, regarding:
(a) Complaints handled by OJK
(b) Violations of Business Ethics or Agreements/Cooperation Between Parties (4) Loss of potential customers due to decreased reputation.
(5) Assessment of requirements as a Securities Company. f) Tolerance in Reputation Risk Assessment Reputation risk assessment includes assessment of the probability of an event and the impact it causes. An event with small probability and impact can still be tolerated so that it does not need intensive attention. However, Securities Companies that are Members of the Exchange must not ignore such risks. Conversely, Securities Companies that are Members of the Exchange need to pay intensive attention to risks that have large probability and impact beyond the tolerable limit and immediately require control efforts.
For the same risk event, different levels of probability and impact can be given to each Securities Company that is a Member of the Exchange because the level of tolerance or risk appetite (risk rating that can still be taken) of each Securities Company that is a Member of the Exchange is different. The measurement of risk appetite is greatly influenced by the level of knowledge of the Securities Company that is a Member of the Exchange about its own company (Know Your Securities Company).
Figure 1. Interconnection of Reputation Risk with Other Risks
Reputation Risk:
Inadequate Complaint Handling
Compensation Obligation
Regulatory Violation
Operational Risk
Increased Burden
Customer files complaint with OJK
OJK Sanctions
Compliance Risk
CHAPTER III
REPUTATION RISK MANAGEMENT PRINCIPLES
In the reputation risk management assessment process, Stock Exchange Member Securities Companies need to understand the basic principles of reputation risk management. This section outlines the reputation risk management principles, which include among others:
Reputation Risk Management Governance
a. Formulation of risk ratings taken and reputation risk tolerance The formulation of risk ratings is adjusted to actual conditions where risks exist but will be taken or absorbed by the Stock Exchange Member Securities Company, often referred to as risk appetite and risk tolerance. b. Active supervision by the Board of Directors and Board of Commissioners in the exercise of their authority and responsibilities The Board of Directors and Board of Commissioners are responsible for ensuring that the implementation of Risk Management is adequate according to the characteristics, complexity, and reputation risk profile of the Stock Exchange Member Securities Company. The Board of Directors and Board of Commissioners must have a good understanding of the types and reputation risk ratings inherent in the business activities of the Stock Exchange Member Securities Company.
Reputation Risk Management Framework
a. Having adequate procedures and policies regarding complaint handling. b. Having adequate procedures and policies regarding the use of the right of reply.
c. Having adequate resources
The resources referred to include the availability of policies, organizational structure, resource allocation, and supporting information systems to measure and monitor reputation risk. d. Existence of a whistle-blowing system.
Reputation Risk Management Process
a. The Board of Directors and Board of Commissioners have thoroughly understood the reputation risk management strategy after being able to define and identify reputation risks. b. The Board of Directors and Board of Commissioners ensure that the reputation risk management strategy has been effectively and transparently implemented in policies and procedures.
c. The Board of Directors and Board of Commissioners are responsible for the implementation of the reputation risk management strategy, policies, and procedures established.
Reputation Risk Control
The existence of risk control mechanisms and systems that can ensure the reliability of the reputation risk management framework, which includes policies, organizational structure, resource allocation, and information systems regarding the implementation of reputation risk management.
CHAPTER IV
REPUTATION RISK ASSESSMENT
This section will outline the procedures for conducting reputation risk management assessment. These assessment procedures serve as general guidelines for Stock Exchange Member Securities Companies, which can be further developed and adjusted according to the complexity, business scale, and conditions of the Stock Exchange Member Securities Company.
b. Know Your Securities Company (KYSC) in Reputation Risk Assessment
Figure 2. Reputation Risk Indicators
Reputation Risk
Complaints
Complaint Handling at Securities Company
Complaint Handling at OJK
Negative Reporting
Use of Right of Reply for Negative Reporting
Explanation of Figure 2. Reputation Risk Indicators:
Complaints
The type of customer complaints is used to assess whether there are recurring complaints and to assess the significance of complaints that can affect the performance of the Stock Exchange Member Securities Company and the relationship between the Stock Exchange Member Securities Company and customers (e.g., trading system disruptions, inadequate product information, negligence by the Securities Company, customer negligence, etc.).
Complaint Handling at Stock Exchange Member Securities Company
The number of complaints resolved, currently being handled, or not yet handled by the Stock Exchange Member Securities Company within the last 6 (six) months. This information is accompanied by actions taken to resolve complaints such as compensation payments, amicable settlements, and other information reported by the Stock Exchange Member Securities Company through the OJK's complaint reporting system.
Complaint Handling at the Financial Services Authority (OJK)
The number of complaints against the Stock Exchange Member Securities Company that have been resolved, are currently being handled, or are not yet handled by the Financial Services Authority within the last 6 (six) months. This information is accompanied by actions taken to resolve complaints such as compensation payments.
Negative Reporting
The number of negative reports received by the Stock Exchange Member Securities Company within the last 1 (one) year, knowing the type of report, e.g., business ethics violations or cooperation violations, media of reporting, and the negative impact/suffered by the Stock Exchange Member Securities Company.
Use of Right of Reply for Negative Reporting
The comparison of the number of right of replies used with the number of negative reports, and the procedures and policies applied by the Stock Exchange Member Securities Company regarding the use of the right of reply.
c. Thought Process of Reputation Risk Assessment
Figure 3. Reputation Risk Thought Process
Table 2. Reputation Risk Parameters and Indicators
No
Reputation Risk Parameter
Risk Measurement Indicator
No
Reputation Risk Parameter
Risk Measurement Indicator
2. Frequency, type,
negative reporting impact, and media used
The Stock Exchange Member Securities Company has received negative reporting.
In the event that there is no negative reporting for the Stock Exchange Member Securities Company, the risk is still assessed in the very low category.
The type of negative reporting is divided based on the significance of the impact caused by the negative reporting, e.g., viewed from the type of business ethics violation, cooperation violation between parties, or legal violation. The media for negative reporting is divided based on the significance of the impact caused by the negative reporting, e.g., viewed from the reach of local or national scale media, print or electronic media.
Table 3. Reputation Risk Management Parameters and Indicators
No
Reputation Risk Parameter
Risk Management Measurement Indicator
The order of smaller levels indicates lower risk and better quality of reputation risk management implementation. For more details, it is illustrated in Table 4 as follows:
Table 4. Reputation Risk Assessment Matrix
Inherent Risk
Risk Management
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate)
Low
(Low)
1 2 3 4 5
Low to
Moderate
(Low to Medium)
2 4 6 8 10
Moderate
(Medium)
3 6 9 12 15
Moderate to
High
(Medium to High)
4 8 12 16 20
High
(High)
5 10 15 20 25
Based on Table 4, the range and Reputation Risk ratings are obtained as follows:
Table 5. Range and Reputation Risk Ratings
Range Rating
1.00 - 2.99 I
3.00 - 4.99 II
5.00 - 9.99 III
10.00 - 16.00 IV
16.01 - 25.00 V
In certain conditions where the conditions in the worksheet are less relevant to determine the reputation risk rating according to actual conditions, Stock Exchange Member Securities Companies can perform judgment using comprehensive and structured analysis to set a higher or lower rating as long as it is considered more appropriate to describe the reputation risk rating of the Stock Exchange Member Securities Company and recorded in the conclusion of each reputation risk indicator as documentation.
Table A. Definition of Inherent Reputation Risk Ratings
No
Reputation Risk Parameter
Low
(Low)
Low to Moderate
(Low to Medium)
Moderate
(Medium)
Moderate to High
(Medium to High)
High
(High)
Potential losses caused by reputation risk almost none during a certain period of time.
Example assessment characteristics below:
Potential losses caused by reputation risk are small during a certain period of time.
Example assessment characteristics below:
Potential losses caused by reputation risk are moderate during a certain period of time.
Example assessment characteristics below:
Potential losses caused by reputation risk are quite high during a certain period of time.
Example assessment characteristics below:
Potential losses caused by reputation risk are high during a certain period of time.
Example assessment characteristics below:
Table B. Definition of Reputation Risk Management Implementation Quality Levels
No
Reputation Risk Parameter
Strong
(Very Adequate)
Satisfactory
(Adequate)
Fair
(Fairly Adequate)
Marginal
(Less Adequate)
Unsatisfactory
(Inadequate)
The quality of reputation risk management implementation viewed from the adequacy of the risk control system is very adequate.
Example assessment characteristics below:
The quality of reputation risk management implementation viewed from the adequacy of the risk control system is adequate.
Example assessment characteristics below:
The quality of reputation risk management implementation viewed from the adequacy of the risk control system is fairly adequate.
Example assessment characteristics below:
The quality of reputation risk management implementation viewed from the adequacy of the risk control system is less adequate.
Example assessment characteristics below:
The quality of reputation risk management implementation viewed from the adequacy of the risk control system is inadequate.
Example assessment characteristics below:
Table C. Recommended Documents for the Implementation of Reputation Risk Management.
No
Reputation Risk Parameter
Documents/Information
i
STRATEGIC RISK ASSESSMENT
ii
TABLE OF CONTENTS
CHAPTER I INTRODUCTION............................................................................ 1
CHAPTER II BASIC CONCEPTS OF STRATEGIC MANAGEMENT
CHAPTER I
INTRODUCTION
Technological development has led to an increase in the complexity of business activities of Stock Exchange Member Securities Companies, simultaneously increasing the risk of Stock Exchange Member Securities Companies. This requires Stock Exchange Member Securities Companies to implement Risk Management well in accordance with their characteristics and business complexity. Failure of Stock Exchange Member Securities Companies in conducting Risk Management can cause significant losses and can even disrupt the continuity of the business of Stock Exchange Member Securities Companies. Strategic risk is the risk caused by the inappropriateness of the Securities Company in making and/or implementing a strategic decision as well as failure to anticipate changes in the business environment. This risk arises among others due to the establishment of strategies that are not aligned with the vision and mission of the Stock Exchange Member Securities Company, non-comprehensive strategic environment analysis, and/or inconsistencies in strategic plans (strategic plan) between strategic levels. In addition, strategic risk can also arise due to failure to anticipate changes in the business environment, including changes in technology, changes in macroeconomic conditions, market competition dynamics, and changes in relevant authority policies. In the context of preparing the self-assessment report, a guide is needed for Stock Exchange Member Securities Companies in assessing strategic risk. This assessment of strategic risk by Stock Exchange Member Securities Companies contains the basic principles in conducting strategic risk management assessment, which includes assessment of Inherent Risk and the quality of strategic risk management implementation.
CHAPTER II
BASIC CONCEPTS OF STRATEGIC MANAGEMENT
This section outlines the basic concepts of strategic risk to facilitate the assessment of strategic risk by Securities Companies that are members of the Stock Exchange. The basic concepts of strategic risk include the basic concepts of the strategic management process, the strategic management process in Securities Companies that are members of the Stock Exchange, sources of strategic risk, and the interrelationship between strategic risk and other risks.
The business world, including the business of Securities Companies that are members of the Stock Exchange, is often likened to a business competition field for market participants within it. Every decision and action taken will affect the results obtained, including the decision not to take any action can also affect the business conditions of the Securities Company that is a member of the Stock Exchange. Therefore, an adequate strategic management process is needed to achieve the desired objectives.
Generally, strategy can be defined as a series of tactics, approaches, methods, or actions taken by the Securities Company that is a member of the Stock Exchange in an effort to achieve specific objectives or targets set in the short, medium, or long term. In the strategic management process, the Securities Company that is a member of the Stock Exchange constantly strives to maximize its competitive advantage.
Figure 1. Strategic Management Process
Company Mission and Vision
Analysis of External Environment
Analysis of Internal Environment
Formulation of Strategic Objectives
Formulation of Strategy
Formulation of Work Program
Implementation of Strategy
Evaluation and Feedback
Strategic Decisions
Strategic decisions are decisions that have a significant impact on the performance of the Securities Company that is a member of the Stock Exchange in the medium and/or long term. Strategic decisions generally reflect the efforts of the Securities Company that is a member of the Stock Exchange to achieve the company's vision and mission.
The grouping of the strategic management process into stages as shown in Figure 1 is not intended to state that each stage is separate and occurs sequentially. This illustration is solely intended to facilitate the Securities Company that is a member of the Stock Exchange in understanding the essence of each stage. In practice, companies can perform several of these stages simultaneously; for example, strategy formulation can be done simultaneously with the analysis of the external and internal environments.
a. Analysis of External and Internal Environments At this stage, the company identifies strategic factors, namely external factors and internal factors that affect its business conditions.
External factors include opportunities and threats that come from outside the company and cannot be fully controlled by the company. Examples include macroeconomic conditions, technology, politics, law, social culture, government behavior, public behavior, customers, competitors, and employees. Internal factors include strengths and weaknesses within the company and are fully under the company's control. Examples include organizational structure, culture, and resources (infrastructure, financial, or human resources).
b. Formulation of Strategic Objectives
At this stage, the company defines and formulates the main objectives or targets to be achieved in the short, medium, or long term.
The main objectives and targets mentioned can be expressed in various forms of asset growth targets, income growth targets, financial conditions and performance, or market share, either for the entire company or based on specific business units. For the purposes of this guideline, the main objectives or targets mentioned will be referred to as strategic objectives.
c. Formulation of Strategy
After considering the results of the external and internal environmental analysis as referred to in letter a, the Board of Directors selects and establishes the strategy deemed best from several available alternative strategies in an effort to achieve the strategic objectives as referred to in letter b. Subsequently, the Board of Directors formulates and establishes policies to ensure that decisions and actions from all executive officials, senior managers, and operational staff at lower levels are aligned with and support the achievement of strategic objectives.
d. Formulation of Work Programs and Implementation of Strategy At this stage, the company translates strategic decisions as referred to in letter c into the form of business plans, work program plans, and budget requirements and procedures for all business units and supporting units. Included in this stage, the company conducts alignment and change management to ensure that all financial resources, infrastructure, human resources, internal procedures, information systems, and internal controls are adequate to support strategy implementation.
e. Evaluation and Feedback
At this stage, the company conducts a review and evaluation of the effectiveness of the strategies taken by comparing 'actual performance' with 'expected performance'. The results of the evaluation will be used by the management of the Securities Company that is a member of the Stock Exchange to take corrective actions in the form of strategy changes and improvements to address problems.
a. Planning
Strategic planning is a process whereby the Securities Company that is a member of the Stock Exchange establishes the overall direction and focus of the company, sets short, medium, and long-term priorities aligned with the company's mission and vision, and translates these priorities into strategies intended to achieve specific goals and objectives.
The benefits of strategic planning for the Securities Company that is a member of the Stock Exchange are (i) the ability to identify and assess risks arising from strategic plans and assess whether the Securities Company has the capacity to face such risks; and (ii) the ability to respond to negative impacts from changes in the business environment in a timely manner.
Strategic planning consists of 3 (three) main elements, namely: (1) setting strategic objectives; (2) strategy formulation; and (3) preparation of strategic plans.
The Board of Directors is required to ensure that the setting of strategic objectives is realistic and aligned with:
a) The business characteristics, risk profile, scale, and complexity of the business of the Securities Company that is a member of the Stock Exchange; b) The needs and expectations of stakeholders, including shareholders, Directors, customers, employees, and supervisory authorities; c) Business environment conditions (political, legal, economic, social, and technological conditions); and d) The ability of the Securities Company to absorb risks arising from the setting of strategic objectives.
The setting of strategic objectives must obtain approval and periodic review by the Board of Directors. Subsequently, the aforementioned strategic objectives must be documented and communicated to all relevant units and personnel.
The depth and scope of the analysis must be aligned with the scale and complexity of the business of the Securities Company that is a member of the Stock Exchange.
The identification and formulation process is intended so that the chosen strategy has considered various factors, both external and internal. The aforementioned identification process can use SWOT analysis (Strength-Weakness-Opportunity-Threat). O-T analysis is used to understand external factors faced by the Securities Company that is a member of the Stock Exchange, including industry analysis through PESTEL analysis (Politics, Economy, Social, Technology, Environment, and Legal/Regulation) as well as competitor analysis.
Meanwhile, S-W analysis is used to understand internal factors, including resources that are: (a) tangible, such as office networks, financial conditions, human resources (HR), and technology; and (b) intangible, such as vision, mission, corporate culture, reputation, organization, and customer loyalty.
The preparation of strategic plans must be based on strategic decisions made by the Board of Directors. In addition to describing the strategies taken and how they are implemented by the Securities Company that is a member of the Stock Exchange, the strategic plan must also provide information regarding the business philosophy of the Securities Company that is a member of the Stock Exchange, growth targets, risk levels to be taken, and other relevant factors. The depth and scope of the aforementioned strategic plans must be aligned with the scale and complexity of the Securities Company that is a member of the Stock Exchange.
Subsequently, the details of strategy implementation in the strategic plan are further elaborated in the form of business plans. A Business Plan is a written document describing the business activity plans of the Securities Company that is a member of the Stock Exchange over a period of 1 (one) year, including plans to improve business performance, and strategies to realize such plans in accordance with targets and times set, while still paying attention to the fulfillment of prudential regulations and the application of risk management.
The Business Plan of the Securities Company that is a member of the Stock Exchange must contain at least:
a) The setting of objectives for the Securities Company that is a member of the Stock Exchange to be achieved within a period of 1 (one) year; b) Strategies to achieve the objectives of the Securities Company that is a member of the Stock Exchange; c) Financial projections for the next 1 (one) year; and d) Realization of the previous year's business plan.
The aforementioned Business Plan is prepared by paying attention to:
a) The strategic plan of the Securities Company that is a member of the Stock Exchange; b) Internal and external factors that can affect the continuity of the business activities of the Securities Company that is a member of the Stock Exchange; c) The principle of prudence; and d) The application of risk management.
In the event that the Securities Company that is a member of the Stock Exchange plans to implement a long-term (multi-year) strategy, the Securities Company that is a member of the Stock Exchange is required to have adequate managerial succession plans to ensure that the Securities Company that is a member of the Stock Exchange always has managerial employees in sufficient numbers and competence to support the effective implementation of strategies sustainably.
The Securities Company that is a member of the Stock Exchange must ensure that the strategic plan can be implemented and is aligned with the level of risk tolerance and is supported by the availability of resources (e.g., employees, systems, and infrastructure), expertise, internal experts, and managerial capacity to implement the aforementioned strategic plan.
b. Implementation and Monitoring
The success and failure of strategies very much depend on: (a) whether the Securities Company that is a member of the Stock Exchange has adequate resources and competence to implement the strategy, and (b) whether the Securities Company that is a member of the Stock Exchange has the ability to monitor and control the progress of strategy implementation. Therefore, the Securities Company that is a member of the Stock Exchange is required to have an adequate process to monitor and control the progress of strategy implementation.
If needed, the Securities Company that is a member of the Stock Exchange needs to conduct stress tests on strategy implementation in order to: (1) identify any events or changes in the business environment that can have a negative impact on the fulfillment of initial assumptions from the strategic plan; and (2) measure the potential negative impact of such events on the business performance of the Securities Company that is a member of the Stock Exchange, both financially and non-financially.
c. Alignment and Change Management
The Securities Company that is a member of the Stock Exchange must conduct alignment of internal resources, internal processes, and change management (in the event that organizational and cultural changes are needed) before strategy implementation. In the event that strategy implementation requires cooperation and coordination among several business units, issues arising must have been understood and calculated before strategy implementation.
In conditions where strategy implementation requires changes (e.g., changes in organizational structure, changes in business processes, and changes in mindset) that have the potential to face resistance, the Securities Company that is a member of the Stock Exchange must prepare a change program to ensure the smoothness and effectiveness of the aforementioned changes. The Board of Directors and officials must lead such change programs.
d. Performance Evaluation and Feedback
The success of strategies is measured by comparing 'actual results' with 'expected results'. The performance evaluation process allows the Board of Directors to take corrective steps in a timely manner to respond to such deviations. Therefore, the Securities Company that is a member of the Stock Exchange is expected to be able to develop an effective performance evaluation system in order to monitor the progress of achieving financial or non-financial targets that have been set.
The Securities Company that is a member of the Stock Exchange must have systems and controls to monitor performance and report significant deviations to the Board of Directors. The performance assessment system must be approved and reviewed periodically by the Board of Directors to ensure its continuous appropriateness.
The performance assessment system is not only useful for monitoring performance but also provides useful information for timely strategy adjustments. Therefore, the Securities Company that is a member of the Stock Exchange must consider information originating from the performance assessment system when formulating and reviewing the strategy of the Securities Company that is a member of the Stock Exchange.
b. Weaknesses in the Strategy Formulation Process Strategic decision-making is one part of the strategy formulation process and reflects the strategy deemed best by the Board of Directors after considering available data/information, results of internal and external environmental analysis, and performance targets or strategic objectives to be achieved. However, the Board of Directors can make less than optimal decisions, thereby creating strategic risk if the Board of Directors has inadequate competence to support the effectiveness and accuracy of strategic decision-making.
c. Setting Strategic Objectives that are Too Aggressive
The setting of strategic objectives by the Board of Directors that is too aggressive but not accompanied by adequate resources and risk management has the potential to drive the Securities Company that is a member of the Stock Exchange to be exposed to excessive risk-taking.
The setting of strategic objectives generally reflects the level of risk appetite and risk tolerance of the Board of Directors. Generally, risk appetite and risk tolerance are risk levels willing to be taken by the Securities Company that is a member of the Stock Exchange as a consequence of conducting business.
Both risk appetite and risk tolerance set the limits of how large a risk on an entity (including Securities Companies) is prepared to accept such limits. Risk appetite is a high-level statement regarding the level of risk that top management can accept. A further formulation of risk appetite is risk tolerance, which is more specific regarding the level of deviation that can be accepted over established objectives.
d. Inaccuracies in Strategy Implementation
Several main factors causing the failure of the Securities Company that is a member of the Stock Exchange in implementing strategies include weaknesses in the strategy communication process to all employees, insufficient resources for strategy implementation, and weaknesses in monitoring and controlling the development of strategy implementation.
Strategic risk arises when the Board of Directors fails to clearly communicate strategic objectives as well as the roles and responsibilities of all officials/employees in business or supporting units in the strategy implementation process. As an impact, the Securities Company that is a member of the Stock Exchange fails to achieve the commitments, synergy, and alignment needed in an effort to achieve the established strategic objectives.
Deviations in meeting resources so that they do not match the initial assumptions established in the preparation of strategic plans have the potential to cause strategy implementation to be less than optimal, both in quality and time of completion.
e. Failure to Anticipate Changes in the Business Environment In dynamic and constantly changing business environment conditions, the Securities Company that is a member of the Stock Exchange must have the ability to understand business environment conditions continuously. The Securities Company that is a member of the Stock Exchange needs to identify opportunities and potential threats arising from changes in economic conditions, changes in technology, changes in customer needs, competitor expansion, or other forms of changes in the business environment. The Securities Company that is a member of the Stock Exchange is expected to be able to anticipate changes in the business environment effectively, among others, in the form of adjustments to strategies and business plans that have been prepared and the preparation of contingency plans for
crisis conditions. The results of such assessments must be used by Securities Companies that are Stock Exchange Members to adjust new strategies and revise existing business plans in order to ensure the effective achievement of organizational objectives.
f. Inadequate Information Systems
Data and information are the main lifeline of every correct and effective decision-making process. Securities Companies that are Stock Exchange Members with weak information systems tend to make less accurate decisions because they are not supported by complete, accurate, and up-to-date information regarding internal conditions or external business environment conditions. The need for information systems by Securities Companies that are Stock Exchange Members will continue to develop in line with the growth of business scale, product and service complexity, office network growth, and the organizational development of Securities Companies that are Stock Exchange Members. Therefore, Securities Companies that are Stock Exchange Members are required to ensure that information system capabilities align with the business development of Securities Companies that are Stock Exchange Members, so as to be able to support the effectiveness of strategic decision-making through the provision of accurate, complete, up-to-date, and continuous data/information.
CHAPTER III
STRATEGIC RISK MANAGEMENT PRINCIPLES
The main objective of strategic risk management is to ensure that strategic risk is managed well so that the negative impact of incorrect strategic decision-making and failure to anticipate changes in the business environment can be minimized. Good strategic risk management must refer to basic principles that serve as the reference for Securities Companies that are Stock Exchange Members in managing strategic risk. In practice, each Securities Company that is a Stock Exchange Member needs to adjust to its business characteristics and complexity. Before assessing the quality of strategic risk management implementation, Securities Companies that are Stock Exchange Members need to understand the strategic management process as described in the previous chapter, which consists of 4 (four) stages, namely: (a) planning, (b) implementation and monitoring, (c) alignment and change management, and (d) performance evaluation and feedback. Furthermore, Securities Companies that are Stock Exchange Members assess the quality of strategic risk management implementation using basic strategic risk management principles which include: (1) strategic risk management governance, (2) strategic risk management framework, (3) strategic risk management process, information systems, and human resources, and (4) strategic risk internal controls.
a. Formulation of Strategic Risk Appetite and Risk Tolerance In the context of developing strategic risk management policies, the Board of Directors is required to provide clear direction regarding the risk appetite and risk tolerance of Securities Companies that are Stock Exchange Members. The Board of Directors is also required to ensure that these two aspects are reflected in the risk management policy by considering the business strategy and objectives of Securities Companies that are Stock Exchange Members as well as the risk-bearing capacity of the Securities Company. Formulating risk appetite is a very important matter in the strategic risk management of Securities Companies that are Stock Exchange Members. Such risk appetite will generally determine the formulation of strategies to be undertaken by Securities Companies that are Stock Exchange Members. Securities Companies that are Stock Exchange Members also need to clearly formulate the risk tolerance that can be taken and the level of return desired, while considering their capabilities. Risk tolerance can be realized in the form of limits established and used as a reference in strategic decision-making by Securities Companies that are Stock Exchange Members.
b. Active Supervision by the Board of Directors and Board of Commissioners The implementation of active supervision by the Board of Directors and Board of Commissioners for strategic risk includes the following:
a. Strategic Risk Management Strategy
b. Strategic Risk Management Organization
Securities Companies that are Stock Exchange Members may have a strategic risk management organization that clearly regulates the duties, responsibilities, and authority of all company organs in the strategic risk management process. All business units and support units are responsible for assisting the Board of Directors in formulating strategic planning and implementing that strategy effectively.
Duties and Responsibilities of Executive Officials and/or Business Unit Leaders
Executive officials and/or business unit leaders are responsible for assisting the Board of Directors in formulating strategies and ensuring the effectiveness of strategy implementation in the operational areas under their responsibility. These duties and responsibilities include at least:
a) Implementing strategic risk management policies according to criteria and standards established by the Board of Directors; b) Ensuring that strategic risk management practices and controls in business units and support units are consistent with the overall strategic risk management framework; c) Ensuring that business units and support units have policies, processes, procedures, and resources to support the effectiveness of the strategic risk management framework; d) Ensuring the effectiveness of strategic plan implementation through:
(1) Allocation of required resources;
(2) Human resource management that supports includes employee recruitment, training, and retention of employees with the expertise and knowledge required by Securities Companies that are Stock Exchange Members; (3) Establishment of clear authority and responsibility for employees with the competence and experience required by Securities Companies that are Stock Exchange Members; (4) Alignment of internal resource availability with the needs of the strategic management process; (5) Effective change management; and (6) Good understanding by employees at all levels of their role and function in the strategy implementation process. e) Monitoring and comparing the performance of business units with expected results and providing recommendations to the Board of Directors regarding steps to be taken to improve business unit performance; and f) Ensuring that all material risks arising from changes in the business environment and strategy implementation are reported to the Board of Directors and followed up in a timely manner.
Duties and Responsibilities of Strategic Risk Management Functions/Units
a) The main responsibility of the strategic risk management function is to assist the Board of Directors and executive officials in managing strategic risk and facilitating change management in order to continuously develop the performance of Securities Companies that are Stock Exchange Members. b) Involved in the strategic risk management process, particularly in the following aspects:
(1) Coordinating with all business units and support units in formulating strategic plans, including in the analysis of the business environment and strategy formulation in order to achieve strategic objectives; (2) Functioning as an independent risk control unit through the identification, measurement, and reporting of risks arising from strategic decisions (e.g., business expansion, new products, and services) and conducting stress tests on strategic plans; (3) Monitoring and evaluating the progress of strategic plan implementation, conducting independent reviews of performance, and reporting implementation progress and performance review results to the Board of Directors and executive officials; (4) Ensuring that all strategic issues and their impact on the achievement of strategic objectives have been followed up in a timely manner; (5) Assisting executive officials and/or business unit leaders in managing changes (e.g., changes in organizational structure, culture, technology, systems, and human resources) required before strategy implementation and ensuring the effectiveness of the change communication process; (6) Providing support and recommendations regarding opportunities and choices available for the continuous development and improvement of strategies; and (7) Preparing consolidated reports for the Board of Directors regarding strategic issues.
Duties and Responsibilities of the Internal Audit Function
The Internal Audit function is responsible for reviewing the adequacy of the strategic risk management framework of Securities Companies that are Stock Exchange Members. The results of such reviews and audits, including findings regarding issues and weaknesses of the Securities Company, must be reported directly to the Board of Directors. The Board of Directors (or a committee authorized by the Board of Directors, such as the Audit Committee), and executive officials are required to be involved in the process to ensure that the implementation of such reviews and audits has been conducted effectively and that identified issues have been followed up in a timely manner.
c. Policies, Procedures, and Limit Establishment
Risk Identification and Measurement
In conducting strategic risk identification, Securities Companies that are Stock Exchange Members are required to have methods or systems to conduct strategic risk identification for the business of Securities Companies that are Stock Exchange Members. The risk identification process is conducted by analyzing all sources of strategic risk as described in the previous chapter, which includes:
a) Inadequate environmental analysis results; b) Weaknesses in the strategy formulation process; c) Setting strategic objectives that are too aggressive; d) Inaccuracy in strategy implementation; and e) Failure to anticipate changes in the business environment. Securities Companies that are Stock Exchange Members must identify and account for deviations or discrepancies as a result of the non-realization or ineffectiveness of the implementation of established strategies or business plans. Furthermore, in measuring strategic risk, risk measurement methods can be conducted quantitatively and/or qualitatively. The selection of measurement methods is adjusted to the characteristics and complexity of business activities. The following are some matters that need attention:
a) Securities Companies that are Stock Exchange Members are required to identify and account for events and factors that contribute to the occurrence of deviations or discrepancies in the achievement of strategic plans, especially those that have a significant impact on the capital of Securities Companies that are Stock Exchange Members. b) In the event that Securities Companies that are Stock Exchange Members apply strategies that require many resources and are high risk (e.g., entering new market segments, acquisition strategies, or product and service diversification strategies), Securities Companies that are Stock Exchange Members are required to identify and measure the impact of the aforementioned strategies on other types of risks. c) The process of strategic risk identification and measurement must be proactive and cover all business activities of Securities Companies that are Stock Exchange Members and is conducted to analyze the sources, probability, and impact on the financial conditions and the success of Securities Companies that are Stock Exchange Members in achieving strategic objectives. d) Strategic risk measurement methods can be conducted both quantitatively and qualitatively. Strategic risk measurement methods must be evaluated and improved periodically (and whenever necessary) to ensure the suitability of assumptions, accuracy, fairness, and data integrity, as well as the procedures used to measure risk. e) The process of strategic risk identification and measurement (including the selection of risk measurement methods) must be adjusted to the characteristics and complexity of the business of Securities Companies that are Stock Exchange Members. f) Securities Companies that are Stock Exchange Members need to conduct tests on extreme conditions by conducting stress testing in order to: (i) identify any events or changes in the business environment that have a negative impact on the fulfillment of initial assumptions of strategic plans, and (ii) measure the impact of events or changes in the business environment on the business performance of Securities Companies that are Stock Exchange Members, both financially and non-financially. The results of stress testing must provide feedback in the strategy planning process, for example, determining whether the selected strategy is still relevant, or if a process of adjustment and cancellation of strategy is needed. g) In the event that the results of stress testing produce a risk rating higher than the established risk tolerance and limits, Securities Companies are required to develop contingency plans or strategies to mitigate the aforementioned risk. Contingency plans can include shifting strategic focus, changing business decisions and initiatives, postponing strategic investment decisions, or increasing internal capabilities and resources.
Risk Monitoring and Control
The risk monitoring and control process aims to manage risk so that strategic risk exposure does not exceed the established risk tolerance. In conducting risk monitoring, Securities Companies that are Stock Exchange Members must have adequate monitoring systems and procedures, which include among other things monitoring of the magnitude of strategic risk exposure, strategic risk tolerance, compliance with internal limits, and stress testing results as well as consistency of implementation with established policies and procedures. Such monitoring is conducted by both operational units and the Risk Management Function. The results of risk monitoring must be presented in periodic reports to the Board of Directors so that actions can be taken to mitigate the aforementioned risk. Securities Companies are required to have adequate strategic risk control systems referring to established policies and procedures. Furthermore, the results of monitoring are presented in periodic reports submitted to management in order to mitigate risk and take necessary actions. It is important to note that Securities Companies that are Stock Exchange Members must prepare a backup system and effective procedures to prevent disruptions in the risk monitoring process and conduct periodic checks and reassessments of the backup system. Securities Companies that are Stock Exchange Members are required to have a process to monitor the progress of strategy implementation periodically. The process of strategic risk monitoring can be conducted by measuring the success and level of deviation in fulfilling intermediate targets (milestones) established in the business plan
or work plan.
Securities Companies that are Stock Exchange Members must have a strategic risk monitoring system that includes, among other things, monitoring of strategic risk levels, compliance with internal limits, and stress test results, as well as consistency of implementation with established policies and procedures. Securities Companies that are Stock Exchange Members must have adequate risk control systems with reference to established policies and procedures. Furthermore, the risk control processes applied by Securities Companies that are Stock Exchange Members must be adjusted to the risk exposure or risk ratings to be taken and risk tolerance. Strategic risk control is carried out by Securities Companies that are Stock Exchange Members, among other things, by comparing 'actual results' with 'expected results' to ensure that the risks taken are still within tolerance limits and reporting significant deviations to the Board of Directors. Risk control methods include, among other things, risk mitigation through the preparation and implementation of contingency plans, or the addition of capital by Securities Companies that are Stock Exchange Members to absorb potential losses. Strategic issues arising from operational changes and business environment conditions that have a negative impact on the success of the strategy and the financial condition of the Securities Company must be reported to the Board of Directors in a timely manner, accompanied by an analysis of the impact and recommendations for necessary corrective actions.
b. Information Systems
The need of Securities Companies that are Stock Exchange Members for information system support will continue to develop in line with business growth, product/service complexity, and the addition of office networks of Securities Companies that are Stock Exchange Members. In managing Information Systems, Securities Companies that are Stock Exchange Members need to pay attention to the following:
c. Human Resources (HR)
Securities Companies that are Stock Exchange Members must effectively implement human resource management and development processes, including ensuring the availability of employees in the quantity and quality needed to support the successful implementation of strategy. In carrying out the responsibility of implementing risk management related to HR, the Board of Directors must:
and Executive Officials is fair, in line with Good Corporate Governance (GCG) principles and effective risk management;
6) Ensure the improvement of competence and integrity of leaders and personnel of business work units, risk management work units, and internal audit work units, by considering factors such as knowledge, experience/track record, and adequate ability in the field of risk management through continuous education and training programs, to ensure the effectiveness of the risk management process;
7) Place competent officials and staff in each work unit according to the nature, quantity, and complexity of the business of Securities Companies that are Stock Exchange Members;
8) Ensure that officials and staff placed in each of these work units have: (1) an understanding of the risks inherent in each product/activity of Securities Companies that are Stock Exchange Members; (2) an understanding of relevant risk factors and market conditions affecting the products/activities of Securities Companies that are Stock Exchange Members; (3) the ability to estimate the impact of changes in these factors on the continuity of the business of Securities Companies that are Stock Exchange Members; and (4) the ability to communicate the implications of the risk exposure of Securities Companies that are Stock Exchange Members to the Board of Directors and the Risk Management Committee in a timely manner; and
9) Ensure that all HR understands the strategy, risk appetite, and risk tolerance, as well as the risk management framework established by the Board of Directors and approved by the Board of Commissioners, and implements it consistently in the activities handled.
CHAPTER IV
STRATEGIC RISK ASSESSMENT
The procedures for strategic risk assessment are general guidelines for Securities Companies that are Stock Exchange Members, which can be adjusted to the complexity, business scale, and conditions of the Securities Company conducting business as an Underwriter of Securities and/or a Broker-Dealer that is a Stock Exchange Member.
The assessment process of strategic risk is carried out through several stages as shown in Figure 3 below:
Step 1:
Collect various information related to strategic risk. This information can be obtained from Know Your Securities Company (KYSC) prepared by Securities Companies that are Stock Exchange Members or other information. Step 2:
Map the obtained information into parameters/indicators for Inherent Risk assessment, then conduct comprehensive and structured analysis to determine the Inherent Risk rating by considering the definition of strategic Inherent Risk ratings. Step 3:
Conduct comprehensive and structured analysis to assess the quality of implementation of strategic risk management carried out by Securities Companies that are Stock Exchange Members and provide a rating of the quality of implementation of risk management by considering the definition of the quality rating of implementation of strategic risk management. Step 4:
Conduct comprehensive and structured analysis of Inherent Risk and the quality of implementation of risk management, then determine the strategic risk rating.
Figure 3. Strategic Risk Assessment Thinking Flow
which will show the strategic choices that need to be made and implemented by Member Securities Companies.
In this regard, it is important to consider the future of Member Securities Companies and assess whether the current strategy of Member Securities Companies is appropriate for their strategic position. If not, Member Securities Companies need to consider what changes are required and whether Member Securities Companies are able to implement the aforementioned changes.
Member Securities Companies must understand their company's strategic position in the financial industry, based on factors including:
To assess the strategic position, Member Securities Companies need to gather the above information and information related to the competitive advantages possessed by Member Securities Companies, namely things that can add value and the main business of Member Securities Companies. Competitive advantages can be defined as:
The strategic position of Member Securities Companies can provide indications regarding the level of success/failure of Securities Companies in achieving their goals, based on factors including market strength and past success levels. Securities Companies must know and believe in the competitive advantages they possess. If Member Securities Companies do not possess the aforementioned competitive advantages, Member Securities Companies must also understand their weaknesses in the markets/sectors they choose so that they can adjust strategies to achieve goals in accordance with the vision and mission of Member Securities Companies. The more strategic the position held by Member Securities Companies, the easier it is for Member Securities Companies to direct the implementation of their strategies in accordance with the market positions they have achieved, thereby enabling market enrichment and deepening.
d. Achievement of Realization of Member Securities Companies' Business
This parameter is considered historical (past performance). The level of success of Member Securities Companies' strategies in the past does not guarantee similar levels of success in the future. However, this parameter can still be used to measure the quality of strategic risk management of Member Securities Companies (with the assumption that there are no significant changes in the composition of the Board of Directors, the number and quality of key employees in business lines that contribute significantly to the revenue of Member Securities Companies, information system conditions, or infrastructure).
In the event that past data shows (i) a high level of deviation between strategic targets and the achievement results of Member Securities Companies; or (ii) a trend of increasing deviation levels in recent years, Member Securities Companies need to identify the factors causing the aforementioned deviations. Subsequently, based on this identification, Member Securities Companies can conclude whether similar causal factors have the potential to disrupt the success of Member Securities Companies' strategies currently and in the future.
In the event that Member Securities Companies assess that their company's strategic risk profile has the potential to increase in the short term, the assessment of the deviation level can be conducted without having to wait for the annual report on strategic achievement realization, for example, conducted quarterly.
Based on the assessment of Inherent Risk using various indicators as described above, Member Securities Companies conduct a comprehensive and structured analysis to obtain a conclusion on Strategic Inherent Risk and set the appropriate rating. The Strategic Inherent Risk Rating is Rating 1 (low), Rating 2 (low-medium), Rating 3 (medium), Rating 4 (medium-high), and Rating 5 (high). A smaller rating order indicates a lower Strategic Inherent Risk condition with reference to Table A.
In assessing the quality of strategic risk management implementation, Member Securities Companies need to consider the adequacy of their strategic management processes and the application of strategic risk management principles as described in CHAPTER II and CHAPTER III.
The assessment of the quality of strategic risk management implementation is conducted based on 4 (four) pillars, namely: (a) strategic risk governance; (b) strategic risk management framework; (c) strategic risk management process, information systems, and human resources; and (d) strategic risk control.
a. Strategic Risk Governance
The assessment of this factor is conducted by evaluating aspects: (i) the adequacy and effectiveness of the strategic risk management structure; and (ii) the level of understanding of the Board of Directors.
Risk appetite and risk tolerance describe the risk ratings willing to be accepted by Securities Companies in conducting business and efforts to achieve established strategic goals or targets.
Setting risk appetite and risk tolerance that is too high tends to cause Member Securities Companies to take excessive risk. On the other hand, setting risk appetite that is too low also has the potential to reduce the competitive ability of Member Securities Companies because it is too conservative and fails to meet stakeholder expectations. Therefore, in setting risk appetite, Member Securities Companies need to consider and balance stakeholder expectations with the internal resource capabilities of Member Securities Companies in absorbing risk (called risk bearing capacity). Risk bearing capacity generally includes capital factors, profitability, and qualitative factors such as Good Corporate Governance (GCG), internal controls, and risk management.
In implementation, perhaps not many Member Securities Companies can articulate risk appetite explicitly, so Member Securities Companies must examine the company's risk appetite through various documents and business strategies run by Member Securities Companies. Examples of risk appetite include the plan of Member Securities Companies to enter certain business segments such as repo transactions (repurchase agreement) and setting repo transactions with specific profit targets and loss targets that must not exceed a certain percentage of the overall profit of Member Securities Companies as well as target amounts of margin financing that are not too large in proportion to the overall assets of Member Securities Companies.
Subsequently, the aforementioned risk appetite is elaborated in more detail into specific numbers in the risk tolerance of Member Securities Companies. In this case, the aforementioned plan of Member Securities Companies is conducted with risk tolerance that the ratio of the aforementioned repo and collateral must not be less than 150% within the next 1 year and if there are losses, they must not exceed 10% of the total operational profit of Member Securities Companies.
The assessment of this indicator aims to determine the level of understanding, including competence, of the Board of Directors in formulating strategic plans and making strategic decisions. Some information that can serve as the basis for assessment by Member Securities Companies includes:
a) Educational background and work experience of each member of the Board of Directors; b) Historical performance data of each member of the Board of Directors in the past; c) The Board of Directors' views on (1) the focus of business of Member Securities Companies in the medium and long term, including if there are plans to change certain business focuses; (2) business prospects, opportunities, and threats both arising from competitor behavior and overall economic conditions; and (3) strategic issues that have been successfully identified and have the potential to hinder the success of the business of Member Securities Companies.
a) The level of active supervision by the Board of Directors shown by the level of understanding and responsiveness of the Board of Directors in following up reports regarding strategic issues reported to them; b) The Board of Commissioners and the Board of Directors must formulate and approve strategic plans and business plans that cover matters as regulated in applicable provisions and communicate them to officials and/or employees of Member Securities Companies at every level of the organization; c) The Board of Directors is responsible for the implementation of strategic risk management which includes:
(1) Ensuring that established strategic goals are aligned with the mission and vision, culture, business direction, and risk tolerance of Member Securities Companies; (2) Approving strategic plans and any changes to strategic plans, and conducting periodic reviews (at least once a year) of strategic plans to ensure their appropriateness; and (3) Ensuring that the structure, culture, infrastructure, financial conditions, manpower, and managerial competence, systems, and controls existing in Member Securities Companies are appropriate and adequate to support the implementation of established strategies; d) The Board of Directors is responsible for ensuring the adequacy and effectiveness of the strategic risk management structure. As an example, in conducting SWOT analysis and Business Plans, Member Securities Companies must have the ability to articulate the risk appetite and risk tolerance of Member Securities Companies to achieve strategic goals that must be well understood by the Board of Directors and Commissioners so that the determination of these matters can be implemented well later on.
b. Strategic Risk Management Framework
a) In formulating strategies, Member Securities Companies are required to evaluate the competitive position of Member Securities Companies in the industry. In this regard, Member Securities Companies need to:
(1) Understand the business, economic, and industry environment conditions of Member Securities Companies where Member Securities Companies operate, including how environmental changes impact the business, products, technology, and office network of Member Securities Companies; (2) Measure the strengths and weaknesses of Member Securities Companies related to competitive position, business position of Member Securities Companies in the industry, financial performance, organizational structure and risk management, infrastructure for current and future business needs, managerial capabilities, and availability and limitations of resources of Member Securities Companies; and (3) Analyze all available strategy alternatives after considering the strategic goals and risk tolerance of Member Securities Companies. The depth and scope of analysis must be in line with the scale and complexity of the business of Member Securities Companies. b) Member Securities Companies must establish strategic plans and business plans in writing and implement these policies consistently. c) Strategic plans and business plans must be evaluated and adjusted if there are deviations from targets to be achieved due to significant external and internal changes. d) Member Securities Companies are required to have adequate managerial succession plans to support the effective implementation of strategies sustainably. e) Member Securities Companies are required to have sufficient funding sources to support the implementation of strategic plans.
The assessment of this factor is conducted by evaluating the following aspects:
a) There is an organizational structure of Securities Companies that supports the effective implementation of strategic risk management. Subsequently, Member Securities Companies assess the adequacy and effectiveness of the aforementioned structure by considering aspects including the suitability of the organizational structure to support the success of the business strategy of Member Securities Companies as well as organizational structure support in realizing good governance and the effectiveness of the organizational structure in supporting the process of identification, measurement, monitoring, and control of strategic risks. b) Clarity of duties and responsibilities of the management of Member Securities Companies or business unit leaders regarding strategic risk management contained in a clear governance and organizational structure. The assessment of this indicator starts by assessing whether Member Securities Companies have a strategic risk management structure, namely written documentation that clearly elaborates the responsibilities of each organizational organ (Board of Directors, executive officials, business units, and control units) in the strategic risk management process. Subsequently, the level of deviation between written documentation and actual practice of the role of each organ in the organizational process of strategic risk management is noted. c) All business units and support units are responsible for assisting the Board of Directors in formulating strategic plans and implementing strategies effectively. d) Business units and support units are responsible for ensuring that:
(1) Strategic risk management practices and controls in business units are consistent with the overall strategic risk management framework; (2) Business units and support units have policies, procedures, and resources to support the effectiveness of the strategic risk management framework; (3) The strategic planning work unit is responsible for assisting the Board of Directors in managing strategic risks and facilitating change management in the context of sustainable company development.
The assessment of this factor is conducted by evaluating the following aspects:
a) Member Securities Companies must have adequate policies, processes, and procedures to formulate and approve strategic plans. b) Member Securities Companies must have adequate procedures to identify and respond to changes in the business environment. c) Member Securities Companies must have procedures to measure the progress achieved from the realization of business plans and performance according to the established schedule. d) Adequate policies and procedures of Member Securities Companies related to strategic risk management in accordance with the complexity of the business of Member Securities Companies, including policies for exceptions to existing policies and procedures. e) Consistency of policies, procedures, and limits on the implementation of strategic risk management with risk appetite, risk tolerance, human resource capabilities, and information systems of Member Securities Companies.
As an example, during the preparation of SWOT analysis or business plans, Member Securities Companies must pay attention to the suitability of policies, procedures, including the determination of necessary limits, and adequate organization so that the desired strategy can be achieved well.
c. Risk Management Process, Information Systems, and Human Resources
In assessing the implementation of strategic risk management, Member Securities Companies need to pay attention to the application of strategic risk management principles as described in Chapter III as well as several matters as follows:
a) Securities Companies must identify and account for deviations or discrepancies as a result of the non-realization or ineffectiveness of the implementation of established business strategies or business plans, especially those that have a significant impact on the capital of Member Securities Companies. b) Member Securities Companies must conduct risk analysis, especially regarding strategies that require many resources and/or are high risk, such as strategies to enter new market shares, acquisition strategies, or diversification strategies in the form of products and services.
a) In measuring strategic risks, parameters such as the level of complexity of the business strategy of Member Securities Companies, the business position of Member Securities Companies in the Securities Industry, and the achievement of business plans can be used. b) Member Securities Companies can conduct stress tests on strategy implementation in order to (i) identify any events or changes in the business environment that can have a negative impact on the fulfillment of initial assumptions from strategic plans and (ii) measure the potential negative impact of the aforementioned events on the business performance of Securities Companies, both financially and non-financially. c) Stress test results must provide feedback to the strategy planning process. d) In the event that stress test results produce a risk rating higher than the ability of Member Securities Companies to absorb the aforementioned risk (risk tolerance), Member Securities Companies are required to develop contingency plans or strategies to mitigate the aforementioned risk.
a) Member Securities Companies are required to have a process to monitor and control the implementation of strategies periodically. Monitoring is conducted, among others, by paying attention to past loss experiences caused by strategic risks or deviations in the implementation of strategic plans. b) Strategic issues arising from operational and business environment changes that have a negative impact on the business conditions or financial conditions of Member Securities Companies must be reported to the Board of Directors promptly, accompanied by an analysis of the impact on strategic risks and necessary corrective actions.
Member Securities Companies must have systems and controls to monitor performance, including financial performance, by comparing 'actual results' with 'expected results' to ensure that the risks taken are still within tolerance limits and to report significant deviations to the Board of Directors. Such risk control systems must be approved and reviewed periodically by the Board of Directors to ensure their ongoing appropriateness.
The assessment of this indicator focuses on assessing the ability of information systems in:
a) Ensuring that owned information systems are adequate to support the process of strategic planning and decision-making and are reviewed periodically; b) Monitoring external business environment conditions and any changes (for example, technological developments, macroeconomics, and competition levels) that have the potential to threaten the business conditions of Member Securities Companies and the success of Member Securities Companies in achieving established targets or strategic goals; c) Ensuring that there is periodic and incidental reporting and discussion regarding strategic issues to the Board of Directors and Board of Commissioners; and d) The work unit/function that implements strategic risk management is responsible for ensuring that all material risks arising from changes in the business environment and strategy implementation are reported to the Board of Directors promptly.
The assessment of this indicator aims to measure the effectiveness of the human resource management and development process in order to guarantee the availability of employees in the quantity and quality needed to support the success of strategy formulation and implementation.
Specifically for strategic risks, the assessment of the effectiveness of the aforementioned human resource management and development process can be conducted by specifically assessing the following factors:
a) Does Member Securities Companies have policies regarding human resource management and development in order to ensure the adequacy of human resources (both quantity and quality) to support current business needs as well as future growth? b) How is the adequacy and effectiveness of human resources in supporting the success of Member Securities Companies' strategies currently? c) How is the effectiveness of training and development programs in improving employee skills? d) How to ensure that the remuneration system for the Board of Directors, Board of Commissioners, and Executive Officials is fair, in line with GCG principles and effective risk management? e) How is the incentive scheme provided by Securities Companies in order to motivate, improve performance, attract, and retain employees with the expertise needed by Member Securities Companies? f) How can Member Securities Companies minimize excessive dependence on key employees and how can Member Securities Companies develop managerial succession plans to anticipate potential resignations and retirements of the aforementioned key employees.
As an example, during the preparation of Business Plans, Member Securities Companies must ensure that Member Securities Companies have adequate SIM and HR to reassure that the Business Plan preparation process can be carried out well.
d. Control of Strategic Risks
The assessment of this indicator focuses on the assessment of the level of
effectiveness of the review and independent audit process in ensuring the integrity and effectiveness of the existing strategic risk management framework in Securities Companies that are Members of the Stock Exchange.
The assessment is conducted by examining the following aspects:
As an example, when preparing SWOT analysis and Business Plans, Securities Companies that are Members of the Stock Exchange must apply adequate controls, including review by the FAI and external auditors if necessary.
Based on the assessment of the quality of strategic risk management implementation using various indicators as described above, Securities Companies that are Members of the Stock Exchange conduct a comprehensive and structured analysis to obtain a conclusion on the quality of strategic risk management implementation and set a rating consistent with that conclusion. The ratings for the quality of strategic risk management implementation are Rating 1 (Strong), Rating 2 (Satisfactory), Rating 3 (Fair), Rating 4 (Marginal), and Rating 5 (Unsatisfactory). A lower rating order indicates better quality of strategic risk management implementation, referring to Table B.
a. Determination of Strategic Risk Rating
Based on the assessment of Inherent Risk and the quality of risk management implementation for each type of risk, the strategic risk rating is determined. The risk rating is the risk inherent in the activities of Securities Companies that are Members of the Stock Exchange after considering the implementation of risk management. The risk rating can be set by Securities Companies that are Members of the Stock Exchange by referring to the risk rating matrix as presented in Table 1. The risk rating matrix is indicative and can be used by Securities Companies that are Members of the Stock Exchange to map strategic risks resulting from the combination of Inherent Risk ratings and the quality level of strategic risk management implementation. In certain conditions, Securities Companies that are Members of the Stock Exchange may use comprehensive and structured analysis to set a higher or lower rating, provided it is considered more appropriate to describe the strategic risk rating.
Table 1. Strategic Risk Assessment Matrix
| Inherent Risk | Risk Management: Strong (Very Adequate) | Risk Management: Satisfactory (Adequate) | Risk Management: Fair (Fairly Adequate) | Risk Management: Marginal (Inadequate) | Risk Management: Unsatisfactory (Very Inadequate) |
|---|---|---|---|---|---|
| Low (Low) | 1 | 2 | 3 | 4 | 5 |
| Low to Moderate (Low-Medium) | 2 | 4 | 6 | 8 | 10 |
| Moderate (Medium) | 3 | 6 | 9 | 12 | 15 |
| Moderate to High (Medium-High) | 4 | 8 | 12 | 16 | 20 |
| High (High) | 5 | 10 | 15 | 20 | 25 |
Based on Table 1, the range and strategic risk ratings are as follows:
Table 2. Strategic Risk Rating Range
| Range | Rating |
|---|---|
| 1.00 - 2.99 | I |
| 3.00 - 4.99 | II |
| 5.00 - 9.99 | III |
| 10.00 - 15.99 | IV |
| 16.01 - 25.00 | V |
In certain conditions where the conditions in the worksheet are less relevant for determining the strategic risk rating according to the actual situation, Securities Companies that are Members of the Stock Exchange may exercise judgment using comprehensive and structured analysis to set a higher or lower rating, provided it is considered more appropriate to describe the strategic risk rating of the Securities Company that is a Member of the Stock Exchange, and this must be recorded in the conclusion of each strategic risk indicator as documentation.
Based on the risk rating assessment, the future risk direction is subsequently analyzed to assess its impact and provide input on the steps that Securities Companies that are Members of the Stock Exchange need to take to strengthen strategic risk management.
b. Trends and Direction of Strategic Risks
In addition to determining risk ratings, Securities Companies that are Members of the Stock Exchange determine whether the direction of strategic risk is estimated to increase, stabilize, or decrease. The determination of risk direction can be done by considering factors such as:
Table A. Definition of Strategic Risk Ratings
| No | Strategic Risk Parameter | Low (Low) | Low to Moderate (Low-Medium) | Moderate (Medium) | Moderate to High (Medium-High) | High (High) |
|---|---|---|---|---|---|---|
| Potential losses caused by strategic risk | The potential losses caused by strategic risk are classified as very small or almost non-existent during a certain period in the future, without considering the aspect of the quality of strategic risk management implementation. | The potential losses caused by strategic risk are classified as small during a certain period in the future, without considering the aspect of the quality of strategic risk management implementation. | The potential losses caused by strategic risk are classified as moderate during a certain period in the future, without considering the aspect of the quality of strategic risk management implementation. | The potential losses caused by strategic risk are classified as quite high during a certain period in the future, without considering the aspect of the quality of strategic risk management implementation. | The potential losses caused by strategic risk are very high during a certain period in the future, without considering the aspect of the quality of strategic risk management implementation. | |
| 1. | Alignment of Strategy and Securities Company | The Securities Company has competitive advantages that are stable, and there are no threats from competitors. | The Securities Company has less competitive advantage and competitor threats are minor. | The Securities Company has moderate competitive advantage and there are threats from competitors. | The Securities Company has competitive advantages, or there are significant threats from competitors. | The Securities Company has competitive advantages, and there are very significant threats from competitors. |
| 2. | Strategic Positioning of Securities Company in the Industry | The Products/business activities of the Securities Company that is a Member of the Stock Exchange are classified as stable, not complex, and diversified. | The Products/business activities of the Securities Company that is a Member of the Stock Exchange are classified as not complex and diversified. | The Products/business activities of the Securities Company that is a Member of the Stock Exchange are generally diversified, but some are classified as complex. | Some Products/business activities of the Securities Company that is a Member of the Stock Exchange are concentrated and classified as complex. | Products/business activities are highly concentrated and classified as complex. |
| 3. | Low-Risk and High-Risk Strategies | • The Strategy of the Securities Company that is a Member of the Stock Exchange is classified as conservative or low-risk.<br>• The Securities Company that is a Member of the Stock Exchange continues existing strategies with a high level of strategy success. | • The Strategy of the Securities Company that is a Member of the Stock Exchange is low-risk but with an increasing trend.<br>• The Securities Company that is a Member of the Stock Exchange continues the same strategy or has some new strategies but still within the core business and competencies of the Securities Company. | • The Strategy of the Securities Company that is a Member of the Stock Exchange is classified as moderate-risk.<br>• The level of success of the Strategy of the Securities Company that is a Member of the Stock Exchange is classified as moderate due to threats from competitors. | • The Strategy of the Securities Company that is a Member of the Stock Exchange is classified as moderate-risk but with an increasing trend.<br>• The Securities Company that is a Member of the Stock Exchange applies strategies to enter new businesses/markets with an uncertain level of success. | • The Strategy of the Securities Company that is a Member of the Stock Exchange is classified as high-risk.<br>• The majority of the Strategies of the Securities Company that is a Member of the Stock Exchange shift to new areas that are not core business and competencies of the Securities Company. |
| 4. | Achievement of Business Realization | The Achievement of Business Realization of the Securities Company is very good. | The Achievement of the Business Plan of the Securities Company that is a Member of the Stock Exchange is good. | The Achievement of the Business Plan of the Securities Company that is a Member of the Stock Exchange is fairly good. | The Achievement of the Business Plan of the Securities Company that is a Member of the Stock Exchange is not good. | The Achievement of the Business Plan of the Securities Company that is a Member of the Stock Exchange is poor. |
Table B. Definition of Strategic Risk Management Implementation Quality Ratings
| No | Reputational Risk Parameter | Strong (Very Adequate) | Satisfactory (Adequate) | Fair (Fairly Adequate) | Marginal (Inadequate) | Unsatisfactory (Very Inadequate) |
|---|---|---|---|---|---|---|
| Quality of strategic risk management implementation | The quality of strategic risk management implementation is classified as very adequate. Although there are weaknesses, they are classified as minor and can be ignored. | The quality of strategic risk management implementation is classified as adequate. There are some weaknesses but they can be resolved in the short term (normal business cycle). | The quality of strategic risk management implementation is classified as fair. Although it meets minimum requirements, there are some weaknesses that require attention from the management of the Securities Company that is a Member of the Stock Exchange. | The quality of strategic risk management implementation is classified as weak. There are some fundamental weaknesses in various aspects of strategic risk management that require immediate corrective action. | The quality of strategic risk management implementation is classified as very weak. There are critical weaknesses in various aspects of strategic risk management, the resolution of which is beyond the capability of the management of the Securities Company that is a Member of the Stock Exchange. | |
| 1. | Alignment of Strategy and Business Environment | • Follow-up on independent review has been implemented very adequately.<br>• Generally, there are no significant weaknesses based on the results of independent review.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.<br>• Strategic risk information system is very good, generating comprehensive and integrated strategic risk reports for the Board of Commissioners and Board of Directors.<br>• Human resources are very adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is very effective in supporting risk management implementation. | • Follow-up on independent review has been implemented adequately.<br>• There are weaknesses but not significant based on the results of independent review.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.<br>• Strategic risk information system is good, including strategic risk reporting to the Board of Commissioners and Board of Directors.<br>• Human resources are adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is effective in supporting risk management implementation. | • Follow-up on independent review has been implemented fairly adequately.<br>• There are weaknesses that are fairly significant based on the results of independent review, requiring management attention.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is fairly adequate.<br>• There are minor weaknesses but can be easily repaired.<br>• Human resources are fairly adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is fairly effective in supporting risk management implementation. | • Follow-up on independent review is less adequate.<br>• There are significant weaknesses based on the results of independent review, requiring immediate corrective action.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is inadequate.<br>• There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate improvement.<br>• Significant weaknesses in the strategic risk information system, including reporting to the Board of Commissioners.<br>• Human resources are less adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is less effective in supporting risk management implementation. | • Follow-up on |
| independent review is inadequate or non-existent.<br>• There are very significant weaknesses based on the results of independent review, where corrective actions are beyond the capability of management.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is inadequate.<br>• There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement.<br>• Fundamental weaknesses in the strategic risk information system.<br>• Human resources are inadequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is not effective in supporting risk management implementation. | ||||||
| 2. | Strategic Positioning of Securities Company in the Industry | • Follow-up on independent review has been implemented very adequately.<br>• Generally, there are no significant weaknesses based on the results of independent review.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.<br>• Strategic risk information system is very good, generating comprehensive and integrated strategic risk reports for the Board of Commissioners and Board of Directors.<br>• Human resources are very adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is very effective in supporting risk management implementation. | • Follow-up on independent review has been implemented adequately.<br>• There are weaknesses but not significant based on the results of independent review.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.<br>• Strategic risk information system is good, including strategic risk reporting to the Board of Commissioners and Board of Directors.<br>• Human resources are adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is effective in supporting risk management implementation. | • Follow-up on independent review has been implemented fairly adequately.<br>• There are weaknesses that are fairly significant based on the results of independent review, requiring management attention.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is fairly adequate.<br>• There are minor weaknesses but can be easily repaired.<br>• Human resources are fairly adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is fairly effective in supporting risk management implementation. | • Follow-up on independent review is less adequate.<br>• There are significant weaknesses based on the results of independent review, requiring immediate corrective action.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is inadequate.<br>• There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate improvement.<br>• Significant weaknesses in the strategic risk information system, including reporting to the Board of Commissioners.<br>• Human resources are less adequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is less effective in supporting risk management implementation. | • Follow-up |
| on independent review is inadequate or non-existent.<br>• There are very significant weaknesses based on the results of independent review, where corrective actions are beyond the capability of management.<br>• Implementation of independent review by the internal audit unit and functions conducting independent review is inadequate.<br>• There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement.<br>• Fundamental weaknesses in the strategic risk information system.<br>• Human resources are inadequate in terms of quantity and competence in the strategic risk management function.<br>• Internal control system is not effective in supporting risk management implementation. | ||||||
| 3. | Low-Risk and High-Risk Strategies | • Formulation of risk appetite and risk tolerance is very adequate and aligned with the strategic objectives and business strategy of the Securities Company that is a Member of the Stock Exchange as a whole.<br>• Strategic risk management process is very adequate in identifying, measuring, monitoring, and controlling strategic risks and is aligned with strategic objectives and business strategy as a whole.<br>• Board of Directors and Board of Commissioners have very good awareness and understanding of strategic risk management and sources of strategic risk.<br>• Strategic risk management culture is very strong and has been internalized very well across the organization.<br>• Internal control system is very effective in supporting risk management implementation. | • Formulation of risk appetite and risk tolerance is adequate but not always aligned with strategic objectives and business strategy of the Securities Company as a whole.<br>• Strategic risk management process is adequate in identifying, measuring, monitoring, and controlling strategic risks.<br>• Board of Directors and Board of Commissioners have good awareness and understanding of strategic risk management.<br>• Strategic risk management culture is strong and has been internalized well at all levels of the organization.<br>• Internal control system is effective in supporting risk management implementation. | • Formulation of risk appetite and risk tolerance is fairly adequate and not aligned with strategic objectives and business strategy of the Securities Company as a whole.<br>• Strategic risk management process is fairly adequate in identifying, measuring, monitoring, and controlling strategic risks.<br>• Board of Directors and Board of Commissioners have fairly good awareness and understanding of strategic risk management.<br>• Strategic risk management culture is fairly strong and has been internalized fairly well but not always implemented consistently.<br>• Internal control system is fairly effective in supporting risk management implementation. | • Formulation of risk appetite and risk tolerance is less adequate and not aligned with strategic objectives and business strategy of the Securities Company as a whole.<br>• Strategic risk management process is less adequate in identifying, measuring, monitoring, and controlling strategic risks.<br>• Significant weaknesses in awareness and understanding of the Board of Commissioners and Board of Directors regarding strategic risk management.<br>• Strategic risk management culture is weak and has not been internalized well at each work unit level.<br>• Internal control system is less effective in supporting risk management implementation. | • Formulation of risk appetite and risk tolerance is inadequate and not linked to strategic objectives and business strategy of the Securities Company as a whole.<br>• Strategic risk management process is inadequate in identifying, measuring, monitoring, and |
| controlling strategic risks.<br>• Awareness and understanding of the Board of Commissioners and Board of Directors regarding strategic risk management is very weak.<br>• Strategic risk management culture is not strong or does not exist at all.<br>• Internal control system is not effective in supporting risk management implementation. |
No Parameter
Reputational Risk
Strong
(Very Sufficient)
Satisfactory
(Sufficient)
Fair
(Fairly Sufficient)
Marginal
(Insufficient)
Unsatisfactory
(Not Sufficient) good at all levels of the organization.
No Parameter
Reputational Risk
Strong
(Very Sufficient)
Satisfactory
(Sufficient)
Fair
(Fairly Sufficient)
Marginal
(Insufficient)
Unsatisfactory
(Not Sufficient) independent, has clear duties and responsibilities, and has run very well.
No Parameter
Reputational Risk
Strong
(Very Sufficient)
Satisfactory
(Sufficient)
Fair
(Fairly Sufficient)
Marginal
(Insufficient)
Unsatisfactory
(Not Sufficient) well by employees.
Table C. Recommended Documents
Reputational Risk Parameter Documents/Information
i
WORKSHEET FORMAT
SECURITIES COMPANY RISK MANAGEMENT ASSESSMENT
ii
TABLE OF CONTENTS
Operational Risk Management Assessment Worksheet Format ...................... 1
Credit Risk Management Assessment Worksheet Format ............................. 65
Market Risk Management Assessment Worksheet Format .............................. 87
Liquidity Risk Management Assessment Worksheet Format ....................... 94
Compliance Risk Management Assessment Worksheet Format.................... 114
Legal Risk Management Assessment Worksheet Format ......................... 118
Reputational Risk Management Assessment Worksheet Format ....................... 122
Strategic Risk Management Assessment Worksheet Format ....................... 129
Operational Risk Management Assessment Worksheet Format Operational Risk Risk Measurement Classification Mitigation Classification Parameter
I. Business Complexity
Indicator
Operational Risk Risk Measurement Classification Mitigation Classification State) for third parties Rating Securities Company's current rating as a trader intermediary for Securities that are Equity, unit of participation in mutual funds and Debt Securities (Corporate and State) for third parties and/or for PE portfolio Securities Company as a Participant in Debt Securities transactions Rating Securities Company's current rating trades Securities that are Equity, unit of participation in mutual
Operational Risk Risk Measurement Classification Mitigation Classification funds, Debt Securities (Corporate and State), and/or Derivative Securities for third parties and/or for PE portfolio Securities Company as a Participant in Debt Securities transactions Securities Company conducts transactions Repo, Reverse Repo, Lending and Borrowing of Funds and Securities. Rating Securities Company's current rating trades Securities that are Equity, unit of participation in mutual funds, Debt Securities
Operational Risk Risk Measurement Classification Mitigation Classification (Corporate and State), Derivative Securities and/or other Securities not listed, for third parties and/or for PE portfolio Securities Company as a Participant in Debt Securities transactions, Issuer of Securities Securities Company conducts transactions Repo, Reverse Repo, Lending and Borrowing of Funds and Securities.
2. Complexity
of Service
Trading
Rating
Securities Company has PPE license
Operational Risk Risk Measurement Classification Mitigation Classification Rating Securities Company has PPE license, PEE Securities Company has Online Trading Rating Securities Company has PPE / PEE license Securities Company has Online Trading Securities Company has license margin and Short Selling Rating Securities Company has PPE/ PEE or PPE/ PEE license
Operational Risk Risk Measurement Classification Mitigation Classification Securities Company has Online Trading Securities Company has license margin and Short Selling Rating Securities Company has PPE/ PEE or PPE/ PEE license Securities Company has Online Trading Securities Company has license margin and Short Selling Securities Company has license
Operational Risk Risk Measurement Classification Mitigation Classification Algorithm Trading and DMA
3. Complexity
of Clients
Rating
Securities Company has NPR
Inland and/or Domestic Institutional
Clients
Active NPR up to
500 and Institutional
Clients up to 5
Rating
Securities Company has NPR
Inland and/or
Domestic Institutional
Clients
Active NPR 501 up to 1000 and
Operational Risk Risk Measurement Classification Mitigation Classification Institutional Clients 6 to Rating Securities Company has NPR Inland and/or Domestic Institutional Clients and/or Foreign Clients Active NPR up to 5,000 and Institutional Clients up to 10, or NPR of Securities Company includes Employees of Securities Company Rating Securities Company has NPR
Operational Risk Risk Measurement Classification Mitigation Classification Inland and/or Domestic Institutional Clients and/or Foreign Clients Active NPR 5001 up to 10000 and Institutional Clients up to 10 NPR of Securities Company includes Employees of Securities Company Rating Securities Company has NPR Inland and/or Domestic Institutional Clients and/or Foreign Clients
Operational Risk Risk Measurement Classification Mitigation Classification Active NPR > 10000 and Institutional Clients > 10 NPR of Securities Company includes Employees of Securities Company
II. Human Resources
Indicator
Operational Risk Risk Measurement Classification Mitigation Classification No outsourcing employees POS is reviewed periodically and updated Number of Remote Trading Users equals the number of WPE Has Employee Workload Analysis Employees in core functions (VD3) Securities Company all have WPE licenses Has a list of disgraced WPE Rating Employee turnover < 5% where no core employees move Rating Has POS employee recruitment Licensed employee turnover < 5% POS is implemented, supervised, and audited Number of outsourcing employees is none POS is reviewed incidentally and updated
Operational Risk Risk Measurement Classification Mitigation Classification Number of Remote Trading Users equals the number of WPE Has Employee Workload Analysis Employees in core functions of Securities Company mostly have WPE licenses Does not have a list of disgraced WPE Rating Employee turnover <5% where < 50% core employees Rating Does not have POS employee recruitment Licensed employee turnover 5% - 10% Has written Policy regarding employee recruitment Number of outsourcing employees (remisiers) < 25% of marketing staff The written policy is implemented, supervised, and audited Number of Remote Trading Users > number of WPE The written policy is reviewed periodically and updated
Operational Risk Risk Measurement Classification Mitigation Classification Only Employees in core functions of Securities Company are required to have licenses have obtained WPE license Has Employee Workload Analysis Does not have a list of disgraced WPE Rating Employee turnover 5% to 10%, where > 50% core employees Rating Does not have POS employee recruitment Licensed employee turnover 10% to 50% Has a written Policy not regarding employee recruitment Number of outsourcing employees (remisiers) 25% - 50% of marketing staff Does not have Workload Analysis employees
Operational Risk Risk Measurement Classification Mitigation Classification Number of Remote Trading Users > number of WPE Does not have a list of disgraced WPE Only Employees in core functions of Securities Company are required to have licenses have obtained WPE license Rating Employee turnover > 10%, where > 50% core employees Rating Does not have POS employee recruitment Licensed employee turnover > 50% Does not have Employee recruitment Policy Number of outsourcing employees (remisiers)
50% of marketing
staff
Does not have Workload Analysis employees
Number of Remote Trading
Users > number of WPE
Does not have a list of disgraced WPE
Operational Risk Risk Measurement Classification Mitigation Classification There are Employees in core functions of Securities Company who are required to have licenses do not have WPE license
2. Human Error Rating
Frequency of incidents <2 times in 1 year
Rating
Has hierarchical Approval in Business Processes (4 eyes) Has no material impact Provide periodic training to employees 100% penalty to the perpetrator Rating Frequency of incidents 3 times to 10 times Rating Has hierarchical Approval in Business Processes (4 eyes) Has no material impact Provide periodic training to employees
Operational Risk Risk Measurement Classification Mitigation Classification Frequency limit of 3 times to 5 times replaced by 100% by the perpetrator Rating Frequency of incidents 3 times to 10 times Rating Has hierarchical Approval in Business Processes (4 eyes) There is a material impact Provide periodic training to employees Frequency limit of 6 times to 10 times replaced by 100% by the perpetrator Rating Frequency of incidents <10x Rating Has hierarchical Approval in Business Processes (4 eyes) <50% of human error incidents have material impact Does not provide training to employees Frequency limit >10 times replaced by 50% by the perpetrator
Operational Risk Risk Measurement Classification Mitigation Classification Rating Frequency of incidents >10x Rating Does not have hierarchical Approval in Business Processes (4 eyes) >50% of incidents human error have material impact Does not provide training to employees 0% penalty to the perpetrator
3. Fraud Rating
Never happened
Fraud
Rating
Has written policy regarding anti-fraud/ handling fraud Has POS regarding anti-fraud/handling fraud POS and/or written policy regarding anti-fraud/ handling fraud has been implemented, supervised, and audited
Operational Risk Risk Measurement Classification Mitigation Classification POS and/or written policy regarding anti-fraud/ handling fraud is reviewed periodically and updated Improvement steps due to fraud are fast and comprehensive Has insider trading mitigation policy Has a Policy for compensation due to fraud Has penalties that are firm, consistent and progressive Has a block leave policy
Operational Risk Risk Measurement Classification Mitigation Classification Rating Fraud Occurred Rating Has written policy regarding anti-fraud/ handling fraud Loss value is not significant so that if the PE incurs losses, it does not result in average PE NAV being in a condition EWS <120% (Loss Value/(average NAV after subtracting the minimum value required over 6 months)) Has POS regarding anti-fraud/handling fraud POS and/or written policy regarding anti-fraud/ handling fraud
Operational Risk Risk Measurement Classification Mitigation Classification has been implemented, supervised, and audited POS and/or written policy regarding anti-fraud/ handling fraud is reviewed incidentally and updated Improvement steps due to fraud are slow and not comprehensive Has insider trading mitigation policy Has a Policy for compensation due to fraud Has penalties that are firm, consistent and progressive Does not have a block leave policy
Operational Risk Risk Measurement Classification Mitigation Classification Rating Fraud Occurred Rating Has written policy regarding anti-fraud/ handling fraud Loss value is not significant so that if the PE incurs losses, it does not result in average PE NAV being in a condition EWS <120% (Loss Value/( average NAV after subtracting the minimum value required over 6 months)) Has POS regarding anti-fraud/handling fraud POS and/or written policy regarding anti-fraud/ handling fraud
Operational Risk Risk Measurement Classification Mitigation Classification has been implemented, supervised, and audited POS and/or written policy regarding anti-fraud/ handling fraud is reviewed incidentally and updated Improvement steps due to fraud are slow and not comprehensive Has insider trading mitigation policy Does not have a Policy for compensation due to fraud Does not have penalties that are firm, consistent and progressive Does not have a block leave policy
Operational Risk Risk Measurement Classification Mitigation Classification Rating Fraud Occurred Rating Has anti-fraud policy/ handling fraud Loss value is very significant so that if the PE incurs losses that result in average PE NAV being in a condition EWS <120% (Loss Value/( average NAV after subtracting the minimum value required over 6 months)) Does not have POS regarding anti- fraud/handling fraud No Improvement Steps due to fraud Has insider trading mitigation policy
Operational Risk Risk Measurement Classification Mitigation Classification Does not have a Policy for compensation due to fraud Does not have penalties that are firm, consistent and progressive Does not have a block leave policy Rating Fraud Occurred Rating Does not have a policy anti-fraud/ handling fraud Loss value is very significant so that if the PE incurs losses that result in average PE NAV not meeting regulations (Loss Value/( average Does not have POS regarding anti- fraud/handling fraud
Operational Risk Risk Measurement Classification Mitigation Classification NAV after subtracting the minimum value required over 6 months)) No Improvement Steps due to fraud Does not have insider trading mitigation policy Does not have a Policy for compensation due to fraud Does not have penalties that are firm, consistent and progressive Does not have a block leave policy
III. Information
Technology
Operational Risk Risk Measurement Classification Mitigation Classification
Operational Risk Risk Measurement Classification Mitigation Classification resolving Information IT Documentation Problems Rating Complexity of products and transactions rating 2 Rating Frequency of FO capacity testing (Mock Trading) according to mandatory mock trading at IDX Complexity of trading services rating 2 Has more connections than required by IDX (at least 1 backup connection) Periodic maintenance 1 month to 3 months once Has a Business Continuity Plan (BCP)
Operational Risk Risk Measurement Classification Mitigation Classification regarding front office and back office systems IT Human Resources and vendors are fast in resolving Information Rating Complexity of products and transactions rating 3 Rating Frequency of FO capacity testing (Mock Trading) less than mandatory mock trading at IDX Complexity of trading services rating 3 Has more than 1 connection (backup connection) Periodic system maintenance 3 months to 6 months once Has a Business Continuity Plan (BCP)
Operational Risk Risk Measurement Classification Mitigation Classification regarding front office and back office systems IT Human Resources are slow in resolving Information Rating Complexity of products and transactions rating 4 Rating Frequency of FO capacity testing (Mock Trading) less than mandatory mock trading at IDX Complexity of trading services rating 4 Has more than 1 connection (backup connection) Periodic system maintenance >6 months once Has a Business Continuity Plan (BCP)
Operational Risk Risk Measurement Classification Mitigation Classification regarding front office and back office systems IT Human Resources are slow escalating to vendors but vendors are fast in resolving Information Rating Complexity of products and transactions rating 5 Rating Does not conduct FO capacity testing (Mock Trading) Complexity of trading services rating 5 Does not have more than 1 connection (backup connection) No periodic system maintenance
Operational Risk Risk Measurement Classification Mitigation Classification Does not have a Business Continuity Plan (BCP) regarding front office and back office systems IT Human Resources are slow escalating to vendors and vendors are slow in resolving Information
2. System unable
to support business complexity of the company
Rating realtime
Rating
Securities Company ensures support for main systems and integrated FO and BO system capacity (BOFIS storage capacity according to standards from IDX
Operational Risk Risk Measurement Classification Mitigation Classification storage) is adequate No system problems System capacity updates (storage) periodic and has alerts Complexity of products and transactions rating 1 Frequency of FO capacity testing (Mock) according to needs, more often than mandatory mock trading at IDX Complexity of trading services rating 1 Backup frequency every day and has colocation server System updates (updating) automated
Operational Risk Risk Measurement Classification Mitigation Classification Rating batching < 1 hour Rating Securities Company ensures support for main systems and integrated FO and BO system capacity (storage capacity) is adequate BOFIS according to standards from IDX There are system problems and have a minor impact on PE operations (forwarding orders, database, reports) System capacity updates (storage) periodic but do not have alerts Complexity of products and transactions rating 2 Frequency of FO capacity testing (Mock) according to mandatory mock trading at IDX
Operational Risk Risk Measurement Classification Mitigation Classification Complexity of trading services rating 2 Backup frequency every day and has colocation server System updates (updating) not automatic Rating batching per session IDX Trading Rating Securities Company ensures support for main systems but not integrated FO and BO system capacity (storage capacity) is adequate BOFIS according to standards from IDX There are system problems and have a minor impact on PE operations System capacity updates (storage) not scheduled and do not have alerts
Operational Risk Risk Measurement Classification Mitigation Classification (forwarding orders, database, reports) Complexity of products and transactions rating 3 Frequency of FO capacity testing (Mock) according to mandatory mock trading at IDX Complexity of trading services rating 3 Backup frequency every day and does not have co-location server System updates (updating) not automatic Rating batching 1 day Rating Securities Company ensures support for main systems but not integrated
Operational Risk Risk Measurement Classification Mitigation Classification
Operational Risk Classification Risk Measurement Risk Mitigation
System FO and BO capacity (storage capacity) is adequate BOFIS complies with BEI standards System issues are frequent and have minor operational impact on SE (order forwarding, database, reports) System capacity (storage) updates are unscheduled and lack alerts Product and transaction complexity rank 4 FO capacity testing frequency (Mock) complies with mandatory mock trading at BEI Trading service complexity rank 4 Daily backup frequency and lack of co-location server
Operational Risk Classification Risk Measurement Risk Mitigation System updating is not automatic Ranking Batching 1 day Ranking Securities Company ensures support systems are present but not integrated System FO and BO capacity (storage capacity) is inadequate BOFIS does not comply with BEI standards System issues are frequent and have major operational impact on SE (order forwarding, database, reports) System capacity (storage) updates are unscheduled and lack alerts
Operational Risk Classification Risk Measurement Risk Mitigation Product and transaction complexity rank 5 FO capacity testing frequency (Mock) never performed (mandatory mock trading at BEI never performed) Trading service complexity rank 5 No daily backup and lack of co-location server System updating is not automatic
3. System can still be intervened manually
Ranking
Main system complies with business complexity (FO) – no support systems Ranking Access rights have been granted
Operational Risk Classification Risk Measurement Risk Mitigation Realtime Has POS system on trading services Trading service complexity rank 1 POS implemented, supervised, and examined No automated ordering services POS reviewed periodically and updated No algo trading Has automated trading policy Ranking Main system does not comply with business complexity (FO), support systems are few and integrated Ranking Access rights have been granted
Operational Risk Classification Risk Measurement Risk Mitigation Automation and batching < 1 hour Has POS system on trading services Trading service complexity rank 2 POS implemented, supervised, and examined Automated ordering services exist, system is at SE POS reviewed incidentally and updated Number of algo trades <5 Has automated trading policy Ranking Main system does not comply with business complexity (FO), support systems Ranking Access rights have been granted, but are not yet adequate
Operational Risk Classification Risk Measurement Risk Mitigation Many and integrated Automation and batching Per trading session BEI Has POS system on trading services Trading service complexity rank 3 POS implemented, supervised, and examined Automated ordering services exist, system is at Third Party POS reviewed incidentally and not updated Number of algo trades <5 Has automated trading policy Ranking Main system does not comply with Ranking Access rights have been granted, but are not yet adequate
Operational Risk Classification Risk Measurement Risk Mitigation Business complexity (FO), support systems are few and not integrated Automation and batching 1 day No POS system on trading services, but has Unwritten Policy Trading service complexity rank 4 Unwritten Policy implemented, supervised, and examined Automated ordering services exist, system is at Third Party Unwritten Policy reviewed incidentally and updated Number of algo trades >5 No automated trading policy
Operational Risk Classification Risk Measurement Risk Mitigation Ranking Main system does not comply with business complexity (FO), support systems are many and not integrated Ranking No access rights. Automation and batching >1 day No POS or policy regarding systems on trading services Trading service complexity rank 5 No automated trading policy Automated ordering services exist, system is at Third Party
Operational Risk Classification Risk Measurement Risk Mitigation Number of algo trades >5 Lack of stable network Ranking Product and transaction complexity rank 1 Ranking Has connections exceeding BEI requirements (minimum 1 backup connection) Trading service complexity rank 1 Maintenance performed regularly up to once a month Has Business Continuity Plan (BCP) regarding front office and back office systems IT personnel are fast in resolving IT issues Ranking Product and transaction complexity rank 2 Ranking Has connections exceeding
Operational Risk Classification Risk Measurement Risk Mitigation BEI requirements (minimum 1 backup connection) Trading service complexity rank 2 Regular maintenance once a month to 3 months Has Business Continuity Plan (BCP) regarding front office and back office systems IT personnel and vendors are fast in resolving IT issues Ranking Product and transaction complexity rank 3 Ranking Has connections exceeding 1 (backup connection) Trading service complexity rank 3 System maintenance every 3 to 6 months
Operational Risk Classification Risk Measurement Risk Mitigation Has Business Continuity Plan (BCP) regarding front office and back office systems IT personnel are slow in resolving IT issues Ranking Product and transaction complexity rank 4 Ranking Has connections exceeding 1 (backup connection) Trading service complexity rank 4 System maintenance every >6 months Has Business Continuity Plan (BCP) regarding front office and back office systems IT personnel are slow in escalating to vendors
Operational Risk Classification Risk Measurement Risk Mitigation But vendors are fast in resolving IT issues Ranking Product and transaction complexity rank 5 Ranking Does not have connections exceeding 1 (backup connection) Trading service complexity rank 5 Does not perform regular system maintenance No Business Continuity Plan (BCP) regarding front office and back office systems IT personnel are slow in escalating issues to vendors and vendors are slow in resolving IT issues
Operational Risk Classification Risk Measurement Risk Mitigation
5. Possibility of system accessed by unauthorized parties.
Ranking
Product and transaction complexity rank 1
Ranking
Has POS related to company information security Trading service complexity rank 1 POS implemented, supervised, and examined Periodic review of POS related to company information security and updated Company has comprehensive transaction instruction validation mechanism Company has Network Infrastructure
Operational Risk Classification Risk Measurement Risk Mitigation Equipped with Firewall, Intrusion Prevention System (IPS), or Intrusion Detection System (IDS) Antivirus updates performed routinely Company has password combination creation rules Company performs routine password changes for front office and back office system administrators Company has appropriate ratio between Number of IT personnel
Operational Risk Classification Risk Measurement Risk Mitigation And number of information systems.
Company does not allow information exchange via flash disk, personal email, and other data storage media Company records every user activity for each information system Company has clean desk policy Limits physical access rights to server rooms Conducts socialization regarding system security
Operational Risk Classification Risk Measurement Risk Mitigation Has development area for development Has vendor agreement Ranking Product and transaction complexity rank 2 Ranking Company has POS related to company information security Trading service complexity rank 2 POS implemented, supervised, and examined Company performs incidental review of POS related to company information security and updates it Company has transaction instruction validation
Operational Risk Classification Risk Measurement Risk Mitigation Comprehensive mechanism Company has Network Infrastructure Equipped with Firewall, Intrusion Prevention System (IPS), or Intrusion Detection System (IDS) Antivirus updates performed routinely Company Does not have password combination creation rules Company performs routine password changes for front office and back office system
Operational Risk Classification Risk Measurement Risk Mitigation Administrators Company has 1:1 ratio between Number of IT Personnel and Number of Information Systems, no backup for each Information System Company allows information exchange via flash disk, personal email, and other data storage media Company records every user activity for each information system Company Does not have clean desk policy
Operational Risk Classification Risk Measurement Risk Mitigation Limits physical access rights to server rooms Does Not conduct socialization regarding system security Has development area for development Has vendor agreement Ranking Product and transaction complexity rank 3 Ranking Company has POS related to company information security Trading service complexity rank 3 POS implemented, supervised, and examined Company performs incidental review of POS related to
Operational Risk Classification Risk Measurement Risk Mitigation Company information security and does not update it Company has comprehensive transaction instruction validation mechanism Company has Network Infrastructure Equipped with Firewall, Intrusion Prevention System (IPS), or Intrusion Detection System (IDS) Antivirus updates performed routinely Company Does not have rules
Operational Risk Classification Risk Measurement Risk Mitigation Password combination creation Company performs routine password changes for front office and back office system administrators Company has ratio > 1:2 between Number of IT Personnel and Number of Information Systems, no Backup for each Information System Company allows information exchange via flash disk, personal email, and other data storage media
Operational Risk Classification Risk Measurement Risk Mitigation Company records every user activity for each information system Company Does not have clean desk policy Limits physical access rights to server rooms Does not conduct socialization regarding system security Has development area for development Has vendor agreement Ranking Product and transaction complexity rank 4 Ranking Company Does not have POS related to company
Operational Risk Classification Risk Measurement Risk Mitigation Information security, but has Unwritten Policy Trading service complexity rank 4 Unwritten Policy implemented, supervised, and examined Unwritten Policy reviewed incidentally and updated Company has comprehensive transaction instruction validation mechanism Company has Network Infrastructure Equipped with Firewall, Intrusion Prevention System (IPS),
Operational Risk Classification Risk Measurement Risk Mitigation Or Intrusion Detection System (IDS) Antivirus updates performed routinely Company Does not have password combination creation rules Company Does not perform routine password changes for front office and back office system administrators Company has ratio > 1:5 between Number of IT Personnel and Number of Information Systems, no
Operational Risk Classification Risk Measurement Risk Mitigation Backup for each Information System Company allows information exchange via flash disk, personal email, and other data storage media Company Does not record every user activity for each information system Company Does not have clean desk policy Limits physical access rights to server rooms Conducts socialization regarding system security
Operational Risk Classification Risk Measurement Risk Mitigation Has development area for development Has vendor agreement Ranking Ranking Company Does not have POS or policy related to company information security Company Does Not have comprehensive transaction instruction validation mechanism Company Does Not have Network Infrastructure equipped with
Operational Risk Classification Risk Measurement Risk Mitigation Firewall, Intrusion Prevention System (IPS), or Intrusion Detection System (IDS) Antivirus updates performed routinely Company Does not have password combination creation rules Company Does not perform routine password changes for front office and back office system administrators Company has ratio > 1:5 between Number of IT Personnel
Operational Risk Classification Risk Measurement Risk Mitigation And Number of Information Systems, no Backup for each Information System Company allows information exchange via flash disk, personal email, and other data storage media Company Does not record every user activity for each information system Company Does not have clean desk policy Does Not Limit physical access rights to server rooms
Operational Risk Classification Risk Measurement Risk Mitigation Does Not conduct socialization regarding system security Does Not Have development area for development Does Not Have vendor agreement
Format of the Credit Risk Management Assessment Worksheet
Institutional Client Delivery Failure Value: 0 < x < Rp1,616,977,677 POS implemented, supervised and examined Frequency of Institutional Client Delivery Failure: 1 time - 29 times POS reviewed incidentally and updated Frequency of Institutional Client Delivery Failure Stagnation: 1 time - 29 times Rank 3 Average transaction value of institutional client purchases in the last six months:
Rp64,190,679,274 -
Rp109,565,802,707
Rank 3 Has POS related to institutional client default mechanism that is inadequate or written policy other than POS Institutional Client Delivery Failure Value:
POS implemented, supervised and examined
Rp1,616,977,677 -
Rp2,425,466,516
Frequency of Institutional Client Delivery Failure:
30 times - 59 times
POS not reviewed and not updated
Frequency of Institutional Client Delivery Failure Stagnation: 30 times - 59 times Rank 4 Average transaction value of institutional client purchases in the last six months:
Rp109,565,802,707 -
Rp171,956,597,428
Rank 4 Has Policy but unwritten
Institutional Client Delivery Failure Value:
Rp2,425,466,516 -
Rp3,990,765,187
Frequency of Institutional Client Delivery Failure:
60 times - 89 times
Frequency of Institutional Client Delivery Failure Stagnation: 60 times - 89 times Rank 5 Average transaction value of institutional client purchases in the last six months: < Rp171,956,597,428 Rank 5 No POS or policy Institutional Client Delivery Failure Value > Rp3,990,765,187 Frequency of Institutional Client Delivery Failure: > 89 times
Frequency of Institutional Client Delivery Failure Stagnation: >89 times
Value of Delivery Failure of Other Securities Firms: 0 < x < Rp4,041,529,699 POS implemented, supervised and examined Frequency of Delivery Failure of Other Securities Firms: 1 time - 3 times POS reviewed incidentally and updated Frequency of Delivery Failure Stagnation of Other Securities Firms: 1 time - 3 times Rank 3 Value of sales transactions to other Securities Firms in the last six months:
Rp12,448,194,326 -
Rp17,494,217,660
Rank 3 Has POS related to other Securities Firms' delivery failure mechanism that is inadequate or written policy other than POS Value of Delivery Failure of Other Securities Firms:
POS implemented, supervised and examined
Rp4,041,529,699 -
Rp5,837,533,942
Frequency of Delivery Failure of Other Securities Firms: 4 times - 5 times POS not reviewed and not updated Frequency of Delivery Failure Stagnation of Other Securities Firms: 4 times - 5 times Rank 4 Value of sales transactions to other Securities Firms in the last six months:
Rp17,494,217,660 -
Rp23,381,244,882
Rank 4 Has Policy but unwritten
Value of Delivery Failure of Other Securities Firms:
Rp5,837,533,942 -
Rp8,531,540,306
Frequency of Delivery Failure of Other Securities Firms: 6 times - 8 times Frequency of Delivery Failure Stagnation of Other Securities Firms: 6 times - 8 times Rank 5 Value of sales transactions to other Securities Firms in the last six months:
Rp23,381,244,882
Rank 5 No POS or policy
Value of Delivery Failure of Other Securities Firms: > Rp8,531,540,306 Frequency of Delivery Failure of Other Securities Firms: > 8 times
Frequency of Delivery Failure Stagnation of Other Securities Firms: >8 times
POS not reviewed and not updated
Rank 4 Value of securities transactions of Securities Firms with counterparties other than LKP conducted outside the exchange (OTC) in the last 6 months (July - December 2015):
Rp35,162,448,293 -
Rp56,152,380,310
Rank 4 Has Policy but unwritten
Rank 5 Value of securities transactions of Securities Firms with counterparties other than LKP conducted outside the exchange (OTC) in the last 6 months (July - December 2015): > Rp56,152,380,310 Rank 5 No POS or policy
Rank 2 6-Month Average Ratio of Margin Financing/Collateral: 16%- 39% Rank 2 Has POS related to margin financing but does not cover segregation of authority for financing provision and haircut calculation method 6-Month Average Ratio of Margin Financing/Equity: 3%-6% POS implemented, supervised and examined POS reviewed incidentally and updated Rank 3 6-Month Average Ratio of Margin Financing/Collateral: 39%- 54% Rank 3 Has POS related to margin financing but does not cover margin account opening mechanism, client criteria, forced sell mechanism, and haircut calculation method
6-Month Average Ratio of Margin Financing/Equity: 6%-8%.
POS implemented, supervised and examined
POS reviewed periodically and updated
Rank 4 6-Month Average Ratio of Margin Financing/Collateral: 54%- 77% Rank 4 Has adequate POS related to margin financing covering the process of opening Margin Securities Accounts which contains rights and obligations of each party, Client Criteria, Margin Call Mechanism, Forced Sell Execution Mechanism, Segregation of Authority for Financing Provision, Application of Haircut, Haircut Method, Authority of each party.
6-Month Average Ratio of Margin Financing/Equity: 8%-11% POS not implemented, supervised and examined POS not reviewed periodically and not updated Rank 5 6-Month Average Ratio of Margin Financing/Collateral: >77% Rank 5 No POS or policy 6-Month Average Ratio of Margin Financing/Equity: >11%
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
Ranking 1
Ranking 2
Ranking 3
Ranking 4
Ranking 5
| Compliance Risk | Risk Measurement Classification | Mitigation Classification |
|---|---|---|
| 1. Number of Sanctions Given | Ranking 1: (Number of Written Warnings x 5%) + (Fines x 15%), Activity Restrictions (x30%), Suspension (x50%) is 0 or never received written warnings. | Ranking 1: Has POS related to follow-up on OJK and Exchange inspection findings. No fines. POS implemented, supervised, and audited. No recurrence of violations. POS reviewed periodically and updated. All functions comply with Regulations. No violations of POS ever occurred. |
| Ranking 2: (Number of Written Warnings x 5%) + (Fines x 15%), Activity Restrictions (x30%), Suspension (x50%) is 0 to > 0.25. | Ranking 2: Has POS related to follow-up on OJK and Exchange inspection findings. Total fines are not significant compared to the average difference in MKBD value (last 3 years). POS implemented, supervised, and audited. No recurrence of violations. POS reviewed incidentally and updated. | |
| Ranking 3: (Number of Written Warnings x 5%) + (Fines x 15%), Activity Restrictions (x30%), Suspension (x50%) is 0.26 to > 0.5. | Ranking 3: Only has written policy other than POS related to follow-up on OJK and Exchange inspection findings. Total fines are significant compared to MKBD difference but do not cause average MKBD (last 3 years) to enter EWS. Written policy implemented, supervised, and audited. Written policy not reviewed periodically and not updated. No significant violations of the Written Policy ever occurred. | |
| Ranking 4: (Number of Written Warnings x 5%) + (Fines x 15%), Activity Restrictions (x30%), Suspension (x50%) is 0.51 to 1. | Ranking 4: There is a policy but it is not written. Total fines have a significant impact on MKBD difference, causing average MKBD (last 3 years) to enter EWS (<120%). Recurs 50% of previous findings. | |
| Ranking 5: (Number of Written Warnings x 5%) + (Fines x 15%), Activity Restrictions (x30%), Suspension (x50%) is > 1. | Ranking 5: No POS and no policy. Total fines have a significant impact on MKBD difference, causing average MKBD (last 3 years) to not meet minimum requirements. There are functions in the Company that still need improvement and have not implemented regulations due to inadequate infrastructure. Recurs all previous findings. |
| Legal Risk | Risk Measurement Classification | Mitigation Classification |
|---|---|---|
| 1. Company Receives Lawsuits/Litigation | Ranking 1: No Litigation process against the Securities Company is ongoing. | Ranking 1: Securities Company appoints legal counsel/has competent legal staff. Has very adequate POS. POS implemented, supervised, and audited. POS reviewed periodically and updated. No violations of POS ever occurred. |
| Ranking 2: There is a litigation process against the Securities Company by Securities Company customers. | Ranking 2: Securities Company appoints legal counsel/has competent legal staff. Lawsuit value is not significant (does not cause average MKBD Value of the Securities Company to be in EWS condition (<120%)). Litigation process handled adequately. POS implemented, supervised, and audited. POS reviewed incidentally and updated. | |
| Ranking 3: There is a litigation process against the Securities Company by Securities Company customers. | Ranking 3: Securities Company appoints legal counsel/has competent legal staff. Lawsuit value is not significant (causes average MKBD Value of the Securities Company to be in EWS condition (110% < MKBD value < 120%)). Only has written policy. Written policy implemented, supervised, and audited. Written policy not reviewed periodically and not updated. No significant violations of the Written Policy ever occurred. | |
| Ranking 4: There is a litigation process against the Securities Company by Securities Company customers. | Ranking 4: Securities Company appoints legal counsel/has competent legal staff. Lawsuit value is not significant (causes average MKBD Value of the Securities Company to be in EWS condition (100% < MKBD Value < 110%)). There is a policy but it is not written. Litigation process handled adequately. | |
| Ranking 5: There is a litigation process against the Securities Company by Securities Company customers. | Ranking 5: Securities Company does not appoint legal counsel/does not have legal staff. Lawsuit value is not significant (causes average MKBD Value of the Securities Company to not meet the required minimum MKBD value). No policy. Not handled (does not attend court hearings/in absentia). |
Format of the Reputational Risk Management Assessment Work Sheet
I. Complaints
Level 1: No complaints
Level 1: Has a whistleblowing system
Has SOPs with coverage that includes the flow of receipt, handling, resolution, and segregation of authority SOPs are implemented, supervised, and audited SOPs are reviewed periodically and updated No violations of SOPs have ever occurred
Level 2: Complaints exist and all have been resolved
Level 2: No whistleblowing system exists
Type of customer complaints is not significant Has SOPs with coverage that includes the flow of receipt, handling, resolution, and segregation of authority These complaints do not recur SOPs are implemented, supervised, and audited SOPs are reviewed incidentally and updated
Level 3: Complaints exist but some are not yet resolved
Level 3: No whistleblowing system exists
Type of customer complaints is quite significant and affects the performance of the Securities Company and its relationship with customers (e.g., related to services) Recurring complaints Only has written policies regarding complaint handling Written policies are implemented, supervised, and audited Written policies are not reviewed periodically and are not updated No significant violations of written policies have ever occurred
Level 4: Complaints exist but some are not yet resolved
Level 4: Has policies but they are not written Type of customer complaints is significant and affects the performance of the Securities Company and its relationship with customers Recurring complaints
Level 5: Complaints exist and none are handled
Level 5: Has no SOPs or policies related to complaint handling Type of customer complaints is very significant and affects the performance of the Securities Company and its relationship with customers Recurring complaints
II. Negative News
Frequency, type, impact of negative news, and media used.
Level 1: Never received negative news
Level 1: Always uses the right of reply for negative news (if any) Has adequate SOPs regarding the use of the right of reply related to negative news in the media SOPs are implemented, supervised, and audited SOPs are reviewed periodically and updated No violations of SOPs have ever occurred
Level 2: Uses the right of reply for negative news 75% of the frequency of news coverage
Level 2: Has SOPs with less than adequate coverage, but SOPs are implemented, supervised, and reviewed SOPs are implemented, supervised, and audited SOPs are reviewed incidentally and updated
Level 3: Uses the right of reply for negative news 50% of the frequency of news coverage
Level 3: Does not have SOPs but has written policies to implement the handling and resolution of negative news Written policies are implemented, supervised, and audited Written policies are not reviewed periodically and are not updated No significant violations of written policies have ever occurred
Level 4: Has received negative news
Level 4: Uses the right of reply for negative news 25% of the frequency of news coverage Type of Negative News and Media for Negative News has a significant impact Has policies but they are not written
Level 5: Has received negative news
Level 5: Never uses the right of reply for negative news Type of Negative News and Media for Negative News has a very significant impact No SOPs and no policies exist
Format of the Strategic Risk Management Assessment Work Sheet
Level 1: Securities Company, as a Stock Exchange Member, has stable competitive advantages, and there are no threats from competitors
Level 1: Follow-up on independent reviews has been carried out very adequately. Generally, there are no significant weaknesses based on independent review results. Implementation of independent review by the internal audit unit and the function performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. Strategic Risk Information System is Very Good, producing comprehensive and integrated strategic risk reports to the Board of Commissioners and Board of Directors. Generally, human resources are very adequate in terms of quantity and competence.
Level 2: Securities Company has competitive advantages and competitor threats are minor.
Level 2: Follow-up on independent reviews has been carried out adequately. There are weaknesses but they are not significant based on independent review results. Implementation of independent review by the internal audit unit and the function performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. Strategic Risk Information System is Good, including strategic risk reporting to the Board of Commissioners and Board of Directors. There are minor weaknesses but they can be easily fixed. Human resources are adequate in terms of quantity and competence in the strategic risk management function.
Level 3: Securities Company, as a Stock Exchange Member, has moderate competitive advantages and there are threats from competitors.
Level 3: Follow-up on independent reviews has been carried out sufficiently adequately. Implementation of independent review by the internal audit unit and the function performing independent review is sufficiently adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention. There are weaknesses that are quite significant based on independent review results that require management attention. Strategic Risk Information System meets minimum expectations but has some weaknesses, including reporting to the Board of Commissioners and Board of Directors that require management attention. Generally, human resources are sufficiently adequate in terms of quantity and competence.
Level 4: Securities Company, as a Stock Exchange Member, lacks competitive advantages, or there are significant threats from competitors.
Level 4: Follow-up on independent reviews is inadequate. Implementation of independent review by the internal audit unit and the function performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate improvement. There are significant weaknesses based on independent review results that require immediate corrective action. Significant weaknesses in Strategic Risk Information System, including reporting to the Board of Commissioners and Board of Directors, require immediate improvement. Human resources are inadequate in terms of quantity and competence.
Level 5: Securities Company, as a Stock Exchange Member, has no competitive advantages, and there are very significant threats from competitors.
Level 5: Follow-up on independent reviews is inadequate or non-existent. Implementation of independent review by the internal audit unit and the function performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement. Follow-up on independent reviews is inadequate or non-existent. There are very significant weaknesses based on independent review results where corrective actions are beyond the management's capability. Human resources are inadequate in terms of quantity and competence in the strategic risk management function.
Level 1: Products/business activities of the Securities Company, as a Stock Exchange Member, are stable, not complex, and diversified.
Level 1: Follow-up on independent reviews has been carried out very adequately. Generally, there are no significant weaknesses based on independent review results. Implementation of independent review by the internal audit unit and the function performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. Strategic Risk Information System is Very Good, producing comprehensive and integrated strategic risk reports to the Board of Commissioners and Board of Directors. Generally, human resources are very adequate in terms of quantity and competence.
Level 2: Products/business activities of the Securities Company, as a Stock Exchange Member, are not complex and diversified.
Level 2: Follow-up on independent reviews has been carried out adequately. There are weaknesses but they are not significant based on independent review results. Implementation of independent review by the internal audit unit and the function performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. Strategic Risk Information System is Good, including strategic risk reporting to the Board of Commissioners and Board of Directors. There are minor weaknesses but they can be easily fixed. Human resources are adequate in terms of quantity and competence in the strategic risk management function.
Level 3: Products/business activities of the Securities Company, as a Stock Exchange Member, are generally diversified, but some are considered complex.
Level 3: Follow-up on independent reviews has been carried out sufficiently adequately. Implementation of independent review by the internal audit unit and the function performing independent review is sufficiently adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention. There are weaknesses that are quite significant based on independent review results that require management attention. Strategic Risk Information System meets minimum expectations but has some weaknesses, including reporting to the Board of Commissioners and Board of Directors that require management attention. Generally, human resources are sufficiently adequate in terms of quantity and competence.
Level 4: Some products/business activities of the Securities Company, as a Stock Exchange Member, are concentrated and considered complex.
Level 4: Follow-up on independent reviews is inadequate. Implementation of independent review by the internal audit unit and the function performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate improvement. There are significant weaknesses based on independent review results that require immediate corrective action. Significant weaknesses in Strategic Risk Information System, including reporting to the Board of Commissioners and Board of Directors, require immediate improvement. Human resources are inadequate in terms of quantity and competence.
Level 5: Products/business activities are very concentrated and considered complex.
Level 5: Follow-up on independent reviews is inadequate or non-existent. Implementation of independent review by the internal audit unit and the function performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement. There are very significant weaknesses based on independent review results where corrective actions are beyond the management's capability. Fundamental weaknesses in Strategic Risk Information System. Human resources are inadequate in terms of quantity and competence.
Level 1: Strategy of the Securities Company, as a Stock Exchange Member, is considered conservative or low-risk.
Level 1: Formulation of risk ratings to be taken (risk appetite) and risk tolerance is very adequate and aligned with the strategic objectives and business strategy of the Securities Company, as a Stock Exchange Member, as a whole. Strategic risk management process is very adequate in identifying, measuring, monitoring, and controlling strategic risks. The Board of Directors and Board of Commissioners have very good awareness and understanding of strategic risk management, sources of strategic risk, and strategic risks. Strategic risk management culture is very strong and has been internalized very well at all levels of the organization.
Level 2: Strategy of the Securities Company, as a Stock Exchange Member, is low-risk but with an increasing trend.
Level 2: Formulation of risk ratings to be taken (risk appetite) and risk tolerance is adequate and aligned with the strategic objectives and business strategy of the Securities Company, as a Stock Exchange Member, as a whole. Strategic risk management process is adequate in identifying, measuring, monitoring, and controlling strategic risks. The Board of Directors and Board of Commissioners have good awareness and understanding of strategic risk management. Strategic risk management culture is strong and has been internalized well at all levels of the organization.
Level 3: Strategy of the Securities Company, as a Stock Exchange Member, is considered moderate-risk.
Level 3: Formulation of risk ratings to be taken (risk appetite) and risk tolerance is sufficiently adequate but not always aligned with the strategic objectives and business strategy of the Securities Company as a whole. Strategic risk management process is sufficiently adequate in identifying, measuring, monitoring, and controlling strategic risks. The Board of Directors and Board of Commissioners have sufficiently good awareness and understanding of strategic risk management. Strategic risk management culture is sufficiently strong and has been internalized sufficiently well but is not always implemented consistently.
Level 4: Strategy of the Securities Company, as a Stock Exchange Member, is considered moderate-risk but with an increasing trend.
Level 4: Formulation of risk ratings to be taken (risk appetite) and risk tolerance is inadequate and not aligned with the strategic objectives and business strategy of the Securities Company as a whole. Strategic risk management process is inadequate in identifying, measuring, monitoring, and controlling strategic risks. Implementation of duties by the Board of Directors and Board of Commissioners is generally inadequate. There are weaknesses in various assessment aspects that require immediate improvement. Strategic risk management culture is not strong and has not been internalized well at every work unit level.
Level 5: Strategy of the Securities Company, as a Stock Exchange Member, is considered high-risk.
Level 5: Formulation of risk ratings to be taken (risk appetite) and risk tolerance is inadequate and has no connection with the strategic objectives and business strategy of the Securities Company as a whole. Strategic risk management process is inadequate in identifying, measuring, monitoring, and controlling strategic risks. Implementation of duties by the Board of Directors and Board of Commissioners is inadequate. There are significant weaknesses in almost all assessment aspects and corrective actions are beyond the capability of the Securities Company. Strategic risk management culture is not strong or does not exist at all.
Level 1: Achievement of Business Realization of the Securities Company is very good
Level 1: Generally, human resources are very adequate in terms of quantity and competence. The Board of Directors and Board of Commissioners have very good awareness and understanding of strategic risk management, sources of strategic risk, and strategic risks. Strategic risk management culture is very strong and has been internalized very well at all levels of the organization. Implementation of duties by the Board of Directors and Board of Commissioners as a whole is very adequate. Strategic risk management policies and procedures are very adequate and available for all strategic risk management areas, aligned with implementation, and well understood by employees.
Level 2: Achievement of the business plan of the Securities Company, as a Stock Exchange Member, is good.
Level 2: Human resources are adequate in terms of quantity and competence. The Board of Directors and Board of Commissioners have good awareness and understanding of strategic risk management. Strategic risk management culture is strong and has been internalized well at all levels of the organization. Implementation of duties by the Board of Directors and Board of Commissioners is generally adequate. There are some weaknesses but they are not significant and can be fixed immediately. Strategic risk management policies and procedures are adequate and available for all strategic risk management areas, aligned with implementation, and well understood by employees, although there are minor weaknesses.
Level 3: Achievement of the business plan of the Securities Company, as a Stock Exchange Member, is fairly good.
Level 3: Generally, human resources are sufficiently adequate in terms of quantity and competence. Implementation of duties by the Board of Directors and Board of Commissioners is generally sufficiently adequate. There are weaknesses in some assessment aspects that need management attention. Strategic risk management culture is sufficiently strong and has been internalized sufficiently well but is not always implemented consistently. Implementation of duties by the Board of Directors and Board of Commissioners is generally sufficiently adequate. There are weaknesses in some assessment aspects that need management attention. Strategic risk management policies and procedures are sufficiently adequate but not well understood by employees, resulting in inconsistent implementation.
Level 4: Achievement of the business plan of the Securities Company, as a Stock Exchange Member, is not good.
Level 4: Human resources are inadequate in terms of quantity and competence. Implementation of duties by the Board of Directors and Board of Commissioners is generally inadequate. There are weaknesses in various assessment aspects that require immediate improvement. Strategic risk management culture is not strong and has not been internalized well at every work unit level. Implementation of duties by the Board of Directors and Board of Commissioners is generally inadequate. There are weaknesses in various assessment aspects that require immediate improvement. Significant weaknesses in policies, procedures, and strategic risk limits.
Level 5: Achievement of the business plan of the Securities Company, as a Stock Exchange Member, is not good.
Level 5: Human resources are inadequate in terms of quantity and competence in the strategic risk management function. Implementation of duties by the Board of Directors and Board of Commissioners is inadequate. There are significant weaknesses in almost all assessment aspects and corrective actions are beyond the capability of the Securities Company. Strategic risk management culture is not strong or does not exist at all. Implementation of duties by the Board of Directors and Board of Commissioners is inadequate. There are significant weaknesses in almost all assessment aspects and corrective actions are beyond the capability of the Securities Company. Significant weaknesses in the strategic risk management function that require fundamental improvement.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Determined in Jakarta on August 26, 2021
EXECUTIVE HEAD
OF CAPITAL MARKET SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
HOESEN
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.