2021-01-26
Added · Updated
The Dutch Central Bank (DNB) provides guidance on formulating and embedding an integrity risk appetite within financial institutions, emphasizing the scope, senior management responsibility, and operational integration of this framework. The document outlines the three lines of defense model, assigning specific roles to business units, risk/compliance functions, and internal audit in defining, monitoring, and auditing integrity risks. It also addresses de-risking practices, encouraging institutions to manage high-risk clients through specialized teams rather than categorical exclusion, provided individual risk assessments are conducted. This guidance is non-binding and aims to help institutions align their integrity risk management with strategic objectives and regulatory expectations.
Introduction 3 1 SIRA as the basis for risk management 4 2 Designing the integrity risk appetite 5 3 De-risking 8 4 Status of this good practice 9 Contents
3 Good practice Integrity Risk Appetite DNB has recently emphasized the quality of systematic integrity risk analyses (SIRAs) as the basis for good risk management. An important part of the risk management cycle is that financial institutions make continuous conscious choices regarding integrity risks (money laundering, terrorist financing, corruption, etc.): which risks does your financial institution want to accept, and which risks must be avoided or reduced by implementing control measures? Your institution is best served making these choices if it has formulated a clear integrity risk appetite. DNB aligns with the FSB report 'Principles for An Effective Risk Appetite Framework' of 18 November 2013. We have previously also drawn attention to the financial risk appetite in the context of the research 'Effectiveness of Risk Management'¹. DNB provides further information on the integrity risk appetite, following the findings from the current exploratory research conducted in 2016 into the definition of integrity risk appetite. The aim of this exploratory research was to determine to what extent financial institutions had explicitly defined their risk appetite regarding integrity risks, and whether they actually made conscious choices regarding the handling of the various integrity risks associated with the business model and the exercise of business activities. As announced in June 2016 and in later news bulletins, we mainly investigated whether the outcomes of the SIRA were tested against the integrity risk appetite and the involvement and role of employees/departments in its formulation. Our research has shown that many financial institutions cannot clearly explain how they define their integrity risk appetite and what function this serves within their organization. To help in designing and defining a good integrity risk appetite, we provide further explanation in this brochure. In this context, we also discuss the topic of de-risking, one of the ways financial institutions deal with integrity risks. In de-risking, in the definition also used by the Financial Action Task Force (FATF), categorical farewell is taken of clients because there are unacceptable integrity risks, but without an individual risk assessment having taken place. 1 Available at https://www.dnb.nl/publicatie/publicaties-dnb/nieuwsbrieven/nieuwsbrief-banken/nieuwsbrief-banken-mei-2014/dnb307212.jsp).
5 Good practice Integrity Risk Appetite DNB considers it important that your institution, when designing the integrity risk appetite, considers three aspects of the integrity risk appetite: ▪ the scope of the integrity risk appetite ▪ the responsibility of senior management for establishing, communicating, and monitoring the integrity risk appetite ▪ the operational embedding of the integrity risk appetite in business operations and the role distribution between the different lines of defense. These points are explained in more detail below. Scope of integrity risk appetite In the integrity risk appetite, it is ideally indicated per type of activity and/or product which type of risk is relevant and what appetite fits with it. Ideally, this is thought about at the level of different scenarios. This requires the involvement of all disciplines within your organization that are involved in these aspects. Schematically, the use of an integrity risk appetite looks as follows: 2 Designing the integrity risk appetite As stated earlier, establishing and maintaining the integrity risk appetite is in practice often an iterative process. This means that this process is repeated periodically (and whenever there is reason to do so). Senior management responsibility Senior management (especially the board) bears the ultimate responsibility for the risk profile of the financial institution. This means that they make the choices to accept, avoid, control, or outsource certain risks. To clarify the role of senior management, reference can also be made to the description prepared by the Financial Stability Board for this purpose. The responsibilities include, among others: ▪ ensuring congruence between the integrity risk appetite and the strategic objectives of the financial institution in the short and (medium) long term. Products, Services & Transactions Countries Employees & Internal Culture Integrity risk appetite Accept Avoid Control Outsource Clients & Delivery Channels Third Parties
7 Good practice Integrity Risk Appetite customers, who generated only a small part of the bank's revenue and profit. Due to this small size, it was financially unattractive for the bank to set up and execute all control measures necessary to reduce the integrity risks to an acceptable level, with an individual risk assessment and mitigation. However, the bank also believed it would be incorrect to stop serving this group of customers as a whole. Therefore, the bank decided to place the service provision to this sector within a specialized team. Within this team, existing processes and procedures from other departments are used, which better guarantee sufficient control over integrity risks. By serving a specific group of high-risk clients through a specialized team, the bank was able to continue its service provision to this group of clients, within the limits of its own integrity risk appetite. Role distribution three lines of defense Mapping risks and developing appropriate control measures requires input from multiple organizational units, such as compliance, risk, audit, product development, policy, sales, and others. This involvement is also needed to embed the chosen policy and actually put the procedures into practice. This aligns with the requirements in the Bpr Wft, where Article 10, third and fourth paragraphs, states that the financial institution must inform all relevant organizational units of the policy and procedures, and that the institution must ensure their execution. Each line of defense has its own responsibility regarding the integrity risk appetite. The first line formulates the integrity risk appetite for its specific business unit, which of course is in line with the integrity risk appetite of the entire financial institution. It also provides sufficient justification for this, for example with scenarios and data analysis. Finally, the first line ensures the correct application of the formulated integrity risk appetite. The second line, in addition to its involvement in formulating the integrity risk appetite, is responsible for testing the integrity risk appetite against applicable laws and regulations, as well as for independently monitoring the application of the integrity risk appetite within daily operations. The third line conducts independent audits to provide senior management with the assurance that all business units operate in accordance with the formulated integrity risk appetite.
9 Good practice Integrity Risk Appetite 4 Status of this good practice Good practice of De Nederlandsche Bank N.V. of 28 September 2017, containing a guideline regarding Integrity Risk Appetite [citation title 'Good practice Integrity Risk Appetite'] Disclaimer This good practice does not provide mandatory recommendations for the application of regulations concerning the honest and controlled business operations of, in particular, banks, pension funds, insurers, payment institutions, and trust offices (hereinafter: financial institutions). Using this good practice, De Nederlandsche Bank N.V. expresses its views on the behaviors observed or expected in policy practice, which in its opinion constitute a good application of the rules to which this good practice relates. With this good practice, De Nederlandsche Bank N.V. aims to achieve that financial institutions, taking their own circumstances into account, include what is stated therein in their considerations, without being obliged to do so. The good practice provides insight into the behavior observed or expected by DNB in policy practice, is of an indicative nature, and does not exclude that for institutions a different, possibly stricter, application of the underlying rules may be required. The consideration regarding the application rests with these institutions themselves. Related laws and regulations This Good Practice relates to the following laws and regulations: ▪ Articles 3:10 and 3:17 of the Financial Supervision Act (Wft) in conjunction with Article 10 of the Prudential Rules Wft Decision (Bpr Wft) ▪ Article 19 of the Financial Assessment Framework Pension Funds Decision (Bftk) in conjunction with Article 14 of the Implementation Pension Act Decision (BuP) ▪ Article 10 of the Trust Offices Supervision Act (Wtt) in conjunction with Article 4 of the Honest Business Operations Wtt Regulation (RIB Wtt)