2016-04-14 | 10/SEOJK.05/2016Added · Updated
Non-Bank Financial Service Institutions (LJKNB) are required to establish risk management guidelines and submit self-assessment reports to the OJK, covering general oversight, specific risk types, and organizational preparation steps. The submission must be made online via the OJK's data communication system or, if unavailable, via official email, with specific email addresses assigned by institution type. The first report is due in 2017 for the 2016 period, and the regulation applies to insurance, reinsurance, pension funds, and financing companies, including Sharia-compliant entities.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.05/2016 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT AND SELF-ASSESSMENT REPORTS ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
In accordance with the mandate of Article 5 paragraph (3) and Article 6 paragraph (5) of the Financial Services Authority Regulation Number 1/POJK.05/2015 concerning the Implementation of Risk Management for Non-Bank Financial Service Institutions (State Gazette of the Republic of Indonesia Year 2015 Number 69, Supplement to the State Gazette of the Republic of Indonesia Number 5682), it is necessary to regulate further regarding the procedure for drafting guidelines for the implementation of risk management as well as the form, structure, and procedure for submitting self-assessment reports on the implementation of risk management for non-bank financial service institutions as follows:
I. GENERAL PROVISIONS
In this Circular Letter of the Financial Services Authority, the following terms are defined:
Non-Bank Financial Service Institution, hereinafter abbreviated as LJKNB, is an institution that conducts activities in the insurance, pension fund, and financing institution sectors, including:
a. general insurance companies, life insurance companies, and reinsurance companies, including those conducting all or part of their business based on Sharia principles as referred to in legislation concerning insurance; b. insurance brokers, reinsurance brokers, and insurance loss assessors as referred to in legislation concerning insurance;
c. pension funds, including those conducting all or part of their business based on Sharia principles as referred to in legislation concerning pension funds;
d. financing companies, including those conducting all or part of their business based on Sharia principles as referred to in legislation concerning financing institutions.
Board of Directors:
a. for general insurance companies, life insurance companies, reinsurance companies, insurance brokers, reinsurance brokers, insurance loss assessors, or financing companies, including those conducting all or part of their business based on Sharia principles, which are limited liability companies, is the Board of Directors as referred to in legislation concerning limited liability companies; b. for general insurance companies, life insurance companies, reinsurance companies, insurance brokers, reinsurance brokers, insurance loss assessors, or financing companies, including those conducting all or part of their business based on Sharia principles, which are cooperative legal entities, is the Management as referred to in legislation concerning cooperatives;
c. for pension funds, including those conducting all or part of their business based on Sharia principles, is the Management and/or the executor of the Management's duties as referred to in legislation concerning pension funds; or
d. for general insurance companies, life insurance companies, reinsurance companies, insurance brokers, reinsurance brokers, insurance loss assessors, including those conducting all or part of their business based on Sharia principles, which are joint venture legal entities, is the Board of Directors as referred to in the company's articles of association.
Board of Commissioners:
a. for general insurance companies, life insurance companies, reinsurance companies, insurance brokers, reinsurance brokers, insurance loss assessors, or financing companies, including those conducting all or part of their business based on Sharia principles, which are limited liability companies, is the Board of Commissioners as referred to in legislation concerning limited liability companies; b. for general insurance companies, life insurance companies, reinsurance companies, insurance brokers, reinsurance brokers, insurance loss assessors, or financing companies, including those conducting all or part of their business based on Sharia principles, which are cooperative legal entities, is the Supervisory Board as referred to in legislation concerning cooperatives;
c. for pension funds, including those conducting all or part of their business based on Sharia principles, is the Supervisory Board as referred to in legislation concerning pension funds; or
d. for general insurance companies, life insurance companies, reinsurance companies, insurance brokers, reinsurance brokers, insurance loss assessors, including those conducting all or part of their business based on Sharia principles, which are joint venture legal entities, is the Board of Commissioners as referred to in the company's articles of association.
Risk is the potential occurrence of an event that can cause losses to the LJKNB.
Strategic Risk is Risk arising from the failure to establish appropriate strategies in achieving the LJKNB's main objectives and targets.
Operational Risk is Risk arising from the inadequacy or failure of internal processes, people, information technology systems, and/or events originating from outside the LJKNB's environment.
Asset and Liability Risk is Risk arising from the failure to manage the LJKNB's assets and liabilities.
Management Risk is Risk arising from the LJKNB's failure to maintain the best composition of its management, namely the Board of Directors and Board of Commissioners, who possess high competence and integrity.
Governance Risk is Risk arising from the potential failure in the implementation of good governance of the LJKNB, inappropriate management style, control environment, and behavior of every party involved directly or indirectly with the LJKNB.
Funding Support Risk is Risk arising from the insufficiency of funds/capital available at the LJKNB, including the lack of access to additional funds/capital when facing losses or unexpected fund/capital needs.
Insurance Risk is the failure of insurance companies and reinsurance companies to meet obligations to policyholders and insured parties due to insufficient risk selection (underwriting) processes, premium setting (pricing), use of reinsurance, and/or claims handling.
Financing Risk is Risk arising from the failure of debtors and/or other parties to meet obligations to financing companies.
Risk Management is a series of procedures and methodologies used to identify, measure, monitor, and control Risks arising from the LJKNB's business activities.
Financial Services Authority, hereinafter abbreviated as OJK, is an independent institution that has the function, duties, and authority for regulation, supervision, examination, and investigation as referred to in laws concerning the financial services authority.
II. PROCEDURE FOR DRAFTING GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT FOR LJKNB
III. FORM AND STRUCTURE OF THE SELF-ASSESSMENT REPORT ON THE IMPLEMENTATION OF RISK MANAGEMENT
IV. PROCEDURE FOR SUBMITTING THE SELF-ASSESSMENT REPORT ON THE IMPLEMENTATION OF RISK MANAGEMENT
V. CLOSING
Determined in Jakarta on 14 April 2016
EXECUTIVE HEAD OF SUPERVISOR FOR INSURANCE, PENSION FUNDS, FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS FINANCIAL SERVICES AUTHORITY, signed FIRDAUS DJAELANI
Copy matches the original
Legal Director 1
Legal Department signed
Yuliana
APPENDIX I
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.05/2016 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT AND SELF-ASSESSMENT REPORTS ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT FOR INSURANCE COMPANIES AND REINSURANCE COMPANIES
As regulated in Article 2 of the Financial Services Authority Regulation Number 1/POJK.05/2015 concerning the Implementation of Risk Management for Non-Bank Financial Service Institutions, hereinafter referred to as LJKNB, LJKNB is required to implement Risk Management effectively, at least covering:
A. active supervision by the Board of Directors and Board of Commissioners; B. adequacy of policies, procedures, and Risk limit setting;
C. adequacy of Risk identification, measurement, monitoring, and control processes;
D. Risk Management information systems; and
E. comprehensive internal control systems.
Risk Management Principles are described as follows:
A. Active Supervision by the Board of Directors and Board of Commissioners The Board of Directors and Board of Commissioners are responsible for the effectiveness of the implementation of Risk Management in insurance companies and reinsurance companies, hereinafter referred to as Companies. Therefore, the Board of Directors and Board of Commissioners must:
In the event that the Company is the main entity of a financial conglomerate, the active supervision by the Board of Directors and Board of Commissioners also includes supervision of the Risk Management of that financial conglomerate. Matters to be considered in the implementation of active supervision by the Board of Directors and Board of Commissioners include the following:
directing and approving Risk Management policies, including strategies and Risk Management frameworks established in accordance with the Company's risk appetite and Risk tolerance;
evaluating Risk Management policies and strategies at least once a year or more frequently if there are significant changes in factors affecting the Company's business activities;
evaluating the Board of Directors' accountability and providing improvement directions regarding the implementation of Risk Management policies periodically. Evaluations are conducted to ensure that the Board of Directors manages Company activities and Risks effectively; and
forming a risk monitoring committee tasked with assisting the Board of Commissioners in monitoring the implementation of Risk Management drafted by the Board of Directors.
f. The authority and responsibilities of the Board of Directors, at least include:
drafting written and comprehensive Risk Management policies, strategies, and frameworks, including overall Risk limits and per-type Risk limits, considering the Company's risk appetite and Risk tolerance, and calculating the impact of Risks on capital adequacy. After receiving approval from the Board of Commissioners, the Board of Directors establishes the aforementioned policies, strategies, and Risk Management frameworks;
formulate, establish, and update procedures and tools to identify, measure, monitor, and control Risks;
formulate and establish transaction approval mechanisms, including those exceeding limits and authority at every level of position;
evaluate and/or update Risk Management policies, strategies, and frameworks at least once a year or at more frequent intervals in the event of significant changes in factors affecting the Company's business activities, Risk exposures, and/or Risk profiles;
have adequate understanding of Risks inherent in all business activities within the Company and be able to take necessary actions according to the Company's Risk profile, including by providing recommendations or proposals regarding the implementation of Risk Management to each work unit within the Company;
establish an organizational structure including clear authority and responsibilities at every level of position related to the implementation of Risk Management;
be responsible for the implementation of Risk Management policies, strategies, and frameworks approved by the Board of Commissioners, as well as evaluating and providing guidance based on reports submitted by work units performing Risk Management functions, including reports on Risk profiles;
ensure that all material Risks and the impacts thereof have been followed up on and submit accountability reports to the Board of Commissioners periodically. Such reports include, among others, reports on developments and issues related to material Risks, along with improvement steps that have been, are being, and will be taken;
ensure the implementation of improvement steps for issues or deviations in the Company's business activities found by work units performing internal audit functions;
develop a Risk Management culture, including Risk awareness at all levels of the organization, including adequate communication to all levels of the organization regarding the importance of effective internal controls;
ensure adequate financial support and infrastructure to manage and control Risks;
ensure that the Risk Management function has been implemented independently, reflected, among others, by:
a) separation of functions between work units performing Risk Management functions (identifying, measuring, monitoring, and controlling Risks) and work units performing internal control functions; and b) implementation of Risk Management free from conflicts of interest between work units; and
ensure that all policies, regulations, systems, procedures, and business activities conducted by the Company are in accordance with applicable laws and regulations.
B. Adequacy of Policies, Procedures, and Limit Setting Effective implementation of Risk Management must be supported by a framework covering Risk Management policies and procedures, as well as clearly established Risk limits, in line with the Company's vision, mission, and business strategy. The formulation of such Risk Management policies and procedures considers, among others, the type, complexity of business activities, Risk profile, and level of Risks to be taken, as well as regulations established by authorities and/or healthy Company practices.
Within the Risk Management framework, the Company must also include feedback loops based on accurate and quality information, objective management and assessment processes, which enable the taking of necessary actions at the right time to respond to changes in Risk profiles. This is necessary to ensure that decisions made by the Board of Directors and Board of Commissioners are implemented and the impacts of such decisions are monitored and reported in a timely and sufficiently frequent manner through good management information. Feedback loops are needed to maintain the Company's Risk Management framework relevance to changing conditions, with the aim of helping the Company meet strategic objectives and risk management goals. Furthermore, the implementation of the Company's Risk Management policies and procedures must be supported by adequate capital and HR quality.
In order to effectively control Risks, the policies and procedures held by the Company must be based on Risk Management strategies and supplemented with Risk tolerance and Risk limits. The setting of Risk tolerance and Risk limits considers the level of Risks to be taken (risk appetite), Risk tolerance (risk tolerance), and the Company's overall strategy.
In the event that the Company is part of a financial conglomerate, policies, procedures, and risk limit setting also cover Risks arising from the interconnections between members of the financial conglomerate.
Matters to be considered in establishing the Risk Management framework, including policies, procedures, and limits, include the following:
Level of Risks to be Taken (Risk Appetite) and Risk Tolerance (Risk Tolerance)
a. The level of Risks to be taken (risk appetite) is the level and type of Risks the Company is willing to take in order to achieve Company objectives. The level of Risks to be taken is reflected in the Company's business strategies and objectives. b. Risk tolerance (risk tolerance) is the maximum level and type of Risks established by the Company. Risk tolerance (risk tolerance) is an elaboration of the level of Risks to be taken (risk appetite).
c. [Text missing in source, implied continuation of a/b/d context]
d. The level of Risks to be taken (risk appetite) and Risk tolerance (risk tolerance) must be considered in the formulation of Risk Management policies, including in limit setting. e. In setting Risk tolerance (risk tolerance), the Company needs to consider the Company's business strategies and objectives, as well as the Company's ability to take Risks (risk bearing capacity).
Policies and Procedures
a. Risk Management policies are written directives for implementing Risk Management and must align with the Company's vision, mission, and business strategies, and their formulation must be coordinated with relevant functions or work units. b. Risk Management policies must describe the relationship between the Company's Risk tolerance limits, required capital needs, own capital, and the processes and methods for Risk monitoring.
c. Policies and procedures must be designed and implemented considering the characteristics and complexity of business activities, the level of Risks to be taken and Risk tolerance, Risk profiles, and regulations established by authorities and/or healthy Company practices.
d. The Company must have procedures and processes to implement Risk Management policies. Such procedures and processes are formulated in implementation guidelines that must be reviewed and updated periodically to accommodate changes. e. Risk Management policies must contain at least:
C. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
Risk identification, measurement, monitoring, and control are main parts of the Risk Management implementation process. Risk identification is proactive, covering all business activities of the Company and is conducted to analyze sources and the likelihood of Risks arising, as well as their impacts. Furthermore, the Company needs to measure Risks according to the characteristics and complexity of business activities. In monitoring the results of Risk measurements, the Company may establish independent work units from the transacting parties to monitor levels and trends and analyze Risk directions. In addition, the effectiveness of Risk Management implementation must be supported by Risk control, considering the results of Risk measurement and monitoring.
In the event that the Company is part of a financial conglomerate, risk identification, measurement, monitoring, and control also cover risks arising from the interconnections between members of the financial conglomerate. Matters to be considered in the implementation of risk identification, measurement, monitoring, and control include the following:
Risk Identification
a. The Company identifies all Risks periodically. b. The Company has methods or systems to identify Risks in all products and business activities of the Company.
c. Risk identification processes are conducted by analyzing all sources of Risks, at least conducted on Risks from Company products and activities, and ensuring that Risks from new products and activities have undergone adequate Risk Management processes before being introduced or operated.
d. Risk identification processes consider factors affecting Risks, including additional Risks originating from group members.
Risk Measurement
a. Risk measurement systems are used to measure the Company's Risk exposures as a reference for control. Risk measurement is conducted periodically for products and business lines, as well as all business activities of the Company. b. Such systems must be able to measure at least:
Risk and identify influences that have a significant impact on the Company's portfolio.
h. The Company must conduct regular stress testing and review the results of such stress testing, taking appropriate steps if the estimated future conditions exceed the acceptable tolerance level. These results are used as input when establishing or changing policies and limits.
i. The Company measures Risk based on its ability to assess its own Risks and its Company's capital position.
b. Monitoring is conducted by both operational units and units performing Risk Management functions.
c. Monitoring results are presented in periodic reports submitted to management for the purpose of Risk mitigation and necessary actions.
b. The Company's applied Risk control process must be adjusted to the Risk exposure, the level of Risk to be taken, and Risk tolerance.
c. Risk control can be carried out by the Company, including through hedging mechanisms and other Risk mitigation methods such as increasing the Company's capital to absorb potential losses.
d. The Company must have a framework that is responsive to changes occurring due to the types of Risks present in the Company.
e. The Company conducts regular self-assessments of the adequacy of Risk Management, including assessments of existing and required solvency levels.
D. Risk Management Information System
In order to support the processes of Risk identification, measurement, monitoring, and control, the Company must also develop a management information system adapted to the Company's characteristics, activities, and business complexity.
If the Company is the main entity of a financial conglomerate, the Risk Management information system also includes the information systems required for the implementation of Risk Management for that financial conglomerate. Matters to be considered in the implementation of the Risk Management information system include the following:
The Risk Management information system is part of the management information system that must be owned and developed according to the Company's needs for the effective implementation of Risk Management.
As part of the Risk Management process, the Company's Risk Management information system is used to support the implementation of Risk identification, measurement, monitoring, and control processes.
The Risk Management information system must ensure:
a. the availability of accurate, complete, informative, timely, and reliable information so that it can be used by the Board of Directors, Board of Commissioners, and related units in the implementation of Risk Management to assess, monitor, and mitigate the Risks faced by the Company, both overall/composite Risk and per Risk, and/or in the decision-making process by the Board of Directors; b. the effectiveness of Risk Management implementation, including policies, procedures, and Risk limit setting; and
c. the availability of information on the results (realization) of Risk Management implementation compared to targets set by the Company in accordance with Risk Management implementation policies and strategies.
The Risk Management information system and the information generated must be adapted to the Company's business characteristics and complexity and be adaptive to changes.
The adequacy of the scope of information generated from the Risk Management information system must be reviewed periodically to ensure that the scope is adequate according to the development of business complexity levels.
As part of the Risk Management information system, Risk profile reports are prepared periodically by the unit performing independent Risk Management functions relative to the unit conducting the Company's business activities. The frequency of submission of reports to the Board of Directors must be adjusted to needs, especially when market conditions change rapidly.
The Risk Management information system must support reporting to the Financial Services Authority (Otoritas Jasa Keuangan).
As part of the Risk Management information system, the Company must locate a data center in Indonesia, intended for law enforcement purposes and protection of data regarding insureds/policyholders/customers.
In developing new information system technology and software, the Company must ensure that the implementation of new information systems and technology will not disrupt the continuity of the Company's information systems.
If the Company decides to assign outsourced labor in software development and system improvement, the Company must ensure that the decision to appoint third parties is conducted objectively and independently. The outsourcing agreement/contract must include clauses regarding maintenance and updates, as well as anticipatory steps to prevent disruptions that may occur during operation.
Before implementing a new management information system, the Company must conduct testing to ensure that the processes and outputs generated have undergone effective development, testing, and re-evaluation processes, and the Company must ensure that historical accounting and management data can be accessed well by the new system/software.
The Company must organize and update system documentation, which includes hardware, software, database, parameters, process stages, assumptions used, data sources, and generated outputs, to facilitate inherent control and audit trail implementation.
The Company must prepare an effective back-up system and procedures to prevent disruptions in the Risk monitoring process, and conduct regular checks and re-evaluations of the back-up system.
The Company must ensure that all Risks inherent in all Company transactions and products, including new products and activities, can be integrated into the Company's management information system.
E. Comprehensive Internal Control System
The implementation of effective Risk Management must be complemented by a reliable internal control system. The effective implementation of an internal control system can help the Company protect its assets, ensure the availability of reliable financial and managerial reporting, increase the Company's compliance with applicable laws and regulations, and reduce the Risk of losses, deviations, and violations of prudential aspects. The establishment of a reliable and effective internal control system is the responsibility of all operational units, supporting units, and internal audit units.
If the Company is the main entity of a financial conglomerate, the internal control system must also include a comprehensive internal control system for the implementation of Risk Management for that financial conglomerate. Matters to be considered in the implementation of the internal control system include the following:
The Company implements an effective internal control system in the application of the Company's Risk Management by referring to established policies and procedures.
The internal control system in the implementation of Risk Management must at least include:
a. the alignment between the internal control system and the type and level of Risk inherent in the Company's business activities; b. the establishment of authority and responsibility for monitoring compliance with policies, procedures, and limits;
c. the establishment of reporting lines and clear separation of functions from operational units to units implementing internal control functions;
d. an organizational structure that clearly describes the duties and responsibilities of each unit and individual; e. accurate and timely financial and operational reporting; f. adequate procedures to ensure the Company's compliance with applicable laws and regulations; g. effective, independent, and objective review of the Company's framework policies and operational procedures; h. adequate testing and review of the management information system;
i. complete and adequate documentation of the scope, operational procedures, audit findings, and management responses based on audit results; and
j. regular and continuous verification and review of the handling of material weaknesses and management actions to correct deviations that occur.
The implementation of review of Risk Management implementation must at least include the following:
a. review and evaluation are primarily conducted by the unit performing Risk Management functions and other units functionally separated from the unit tasked with coordinating Risk Management implementation; b. review and evaluation are conducted periodically, at least annually by each unit in the Company, particularly the unit performing Risk Management functions;
c. the scope of review and evaluation can increase in frequency/intensity based on the development of the Company's Risk exposure, market changes, measurement methods, and Risk management;
d. specifically, review and evaluation of Risk measurement are conducted by each unit in the Company, particularly the unit performing Risk Management functions, and must at least include:
The results of the review assessment by the unit performing Risk Management functions are submitted to the Board of Commissioners, internal audit unit, compliance director, audit committee, and other relevant Directors as input for the improvement of the Risk Management framework and process.
Improvements based on internal and external audit findings must be monitored by the internal audit unit. Audit findings that have not been followed up must be reported by the internal audit unit to the Board of Directors to take necessary steps.
The Company's level of responsiveness to weaknesses and/or deviations occurring in applicable internal and external regulations.
II. GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT FOR EACH RISK
A. Strategic Risk
b. Strategic Risk stems from the Company's strategy not being in line with its environmental conditions, and the Company's implemented policies not being in line with its strategic position.
c. Strategic Risk can increase due to, among others, unstable political conditions, high inflation, and security stability.
Objective
The main objective of Risk Management for Strategic Risk is to minimize the possibility of Strategic Risk occurring that impacts the Company's business.
Implementation of Risk Management
The implementation of Risk Management for Strategic Risk for the Company must at least include:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management for Strategic Risk, in addition to conducting active supervision as referred to in item I.A, the Company must add the implementation of several matters in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibility of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Strategic Risk is conducted in an integrated manner with other Risk Management that can impact the Company's Strategic Risk profile. b) The Board of Directors and Board of Commissioners must formulate and approve strategic plans and business plans covering matters as regulated in applicable provisions and communicate them to officials and/or employees of the Company at every organizational level. c) The Board of Directors must ensure that any strategic issues arising can be effectively resolved by the relevant units and that monitoring of corrective actions is conducted by the strategic policy units. d) The Board of Directors must be actively involved in the formulation of marketing plans. e) The Board of Directors must monitor internal conditions (Company weaknesses and strengths) and the development of external factors/conditions that directly or indirectly influence the Company's strategy. f) The Board of Directors must ensure that the Company does not experience difficulties in fulfilling its obligations to policyholders/customers/insureds. g) The Board of Directors provides clear guidance regarding the level of Risk to be taken and the acceptable Risk tolerance of the Company.
Human Resources (HR)
The adequacy of HR for Strategic Risk refers to the scope of general implementation as referred to in item I.A.2.
Strategic Risk Management Organization
a) All of the Company's business units and supporting units are responsible for assisting the Board of Directors in formulating strategic planning and implementing strategies effectively. b) The Company must have a Risk Management function for Strategic Risk that monitors the development and implementation of strategy so that the possibility of Strategic Risk occurrence can be minimized. c) The Director overseeing the Risk Management function for Strategic Risk leads the change programs necessary for the implementation of established strategies.
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Strategic Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company must add the implementation of several matters in each aspect of policy, procedure, and limit setting, as follows:
b) The Company must establish strategic plans and the impact of such strategies on the Company's business and implement these policies. c) Strategic plans and strategy implementation are evaluated periodically to determine the effectiveness of the strategy. d) If the Company plans to implement long-term and sustainable strategies, the Company must have adequate managerial succession plans to support the effectiveness of sustainable strategy implementation. e) The Company must have adequate capital to support strategic plans. f) The Company's Risk Management strategy must at least include the setting of 4P (product, price, position, and promotion).
Risk Appetite and Risk Tolerance
The setting of Risk Appetite and Risk Tolerance for Strategic Risk refers to the scope of general implementation as referred to in item I.B.2.
Policies and Procedures
a) The Company must have adequate work plans for planning, setting, and implementing strategy. b) The Company must have adequate procedures to identify and respond to changes in the business environment. c) The Company must have procedures to measure progress achieved from the realization of business plans and performance according to established schedules.
Limits
Strategic Risk limits generally relate to boundaries of deviation from established strategic plans, such as budget deviation limits and target completion time deviation limits.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management through the processes of Risk identification, measurement, monitoring, and control for Strategic Risk, in addition to implementing processes as referred to in item I.C, the Company must add the implementation of several matters in each of the aforementioned processes, as follows:
Strategic Risk Identification
a) The Company must identify and document deviations or discrepancies resulting from the non-realization or ineffective implementation of established business strategies or business plans, particularly those having a significant impact on the Company's business lines. b) The Company must conduct Risk analysis, particularly regarding strategies requiring many resources and/or high risk, such as entering new market segments, offering new products/services, or acquiring new customers.
Strategic Risk Measurement
a) In measuring Strategic Risk, indicators/parameters such as the alignment of strategy with business environmental conditions, the Company's strategic position, strategy formulation and setting processes, and strategy plan implementation can be used. b) The Company can conduct stress tests on strategy implementation to (i) identify any events or business environmental changes that can negatively impact the fulfillment of initial assumptions of the strategic plan and (ii) measure the potential negative impact of such events on the Company's business performance, both financially and non-financially. c) Stress testing results must provide feedback to the strategy planning process. d) If stress testing results produce a Risk level higher than the Company's ability to absorb the specified Risk (Risk tolerance), the Company must develop strategies to mitigate the specified Risk.
Strategic Risk Monitoring
a) The Company has a process to monitor and control the periodic implementation of strategy development. Monitoring is conducted by, among others, paying attention to past loss experiences caused by Strategic Risk or deviations in strategy plan implementation. b) Strategic issues arising from operational and business environmental changes that have a negative impact on the Company's business or financial conditions are reported to the Board of Directors in a timely manner, accompanied by analysis of the impact on Strategic Risk and necessary corrective actions. c) The Company, through the Board of Directors, conducts internal and external monitoring of Strategic Risk, such as Company weaknesses and strengths and the development of external factors or conditions that directly or indirectly affect the Company.
Strategic Risk Control
The Company must have a system and controls to monitor strategy implementation, business decision-making, and the Company's response to external changes to ensure that taken Risks remain within tolerance limits and to report significant deviations or discrepancies to the Board of Directors. This Risk control system must be approved and regularly reviewed by the Board of Directors to ensure its continuous suitability. The Company must have a good strategy formulation and setting process and a good monitoring section for the Company's strategy plan implementation to ensure conditions after the implementation of such strategies regarding the Company's business.
d. Strategic Risk Management Information System In implementing Risk Management for Strategic Risk, in addition to implementing the management information system as referred to in item I.D, the Company must also
implement the following:
The Company must ensure that the information management system owned is adequate to support the strategic planning and decision-making process and is reviewed periodically.
The functional unit/department implementing Risk Management for Strategic Risk is responsible for ensuring that all material Risks arising from changes in the business environment and strategy implementation are reported to the Board of Directors in a timely manner.
e. Comprehensive Internal Control System
The adequacy of the internal control system in implementing Risk Management for Strategic Risk refers to the general scope of application in item I.E.
B. Operational Risk
a. Operational Risk is the potential failure of the Company in fulfilling obligations to insured parties and policyholders due to the inadequacy or failure of internal processes, human resources, information technology systems, and/or events originating from outside the Company's environment.
b. Sources of Operational Risk include the organizational structure, human resources, volume and workload, high level of Company complexity, inadequate information technology systems, Company fraud and legal issues, and disruptions to the Company's business.
c. Operational Risk may increase due to, among other things, hacker attacks on the Company's technology systems and the sudden resignation of key employees, resulting in organizational dysfunction.
The main objective of Risk Management for Operational Risk is to minimize the possibility of negative impacts arising from the inadequacy or failure of internal processes, human resources, information technology systems, and/or events originating from outside the Company's environment, which could cause the Company to fail in fulfilling its obligations to insured parties and policyholders.
The implementation of Risk Management for Operational Risk for the Company must at least cover:
a. Active Oversight by the Board of Directors and Board of Commissioners
In implementing Risk Management for Operational Risk, in addition to carrying out active oversight as referred to in item I.A, the Company must add the implementation of several aspects in each aspect of the active oversight of the Board of Directors and Board of Commissioners, as follows:
a) The Board of Directors and Board of Commissioners are responsible for developing an organizational culture aware of Operational Risk and fostering commitment to managing Operational Risk in accordance with the Company's business strategy.
b) The Company's Board of Directors creates a culture of objective disclosure of Operational Risk across all organizational elements so that Operational Risk can be identified quickly and mitigated appropriately.
c) The Board of Directors and Board of Commissioners are responsible for implementing Risk Management regarding fraud that may occur within the Company, including steps to be taken to minimize fraud within the Company.
d) The Board of Directors establishes effective reward policies, including remuneration and punishment, integrated into the performance evaluation system to support optimal Risk Management implementation.
e) The Board of Directors must ensure that the exercise of authority and responsibilities delegated to service providers has been carried out well and responsibly.
a) The Company must have an code of ethics applied to all employees at every level of the organization.
b) The Company must apply sanctions consistently to officials and employees proven to have committed deviations and violations.
a) The Company's business unit management or supporting unit management are risk owners responsible for the daily Operational Risk Management process and reporting specific problems and Operational Risks within their respective units according to the applicable reporting hierarchy.
b) To facilitate the Operational Risk Management process in the Company's business units or supporting units and ensure consistent implementation of Operational Risk Management policies, a dedicated operational risk officer may be appointed who has a dual reporting line, namely directly to the head of the Company's business unit or supporting unit. The responsibilities of the dedicated operational risk officer include developing specific risk indicators for the Company's business unit or supporting unit, determining escalation limits, and compiling Operational Risk Management reports.
b. Adequacy of Policies, Procedures, and Limit Setting
In implementing policies, procedures, and limit setting for Operational Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company must add the implementation of several aspects in each aspect of policies, procedures, and limit setting, as follows:
The formulation of strategy for Operational Risk refers to the general scope of application as referred to in item I.B.1. In addition, in formulating the strategy, the Company must also implement the following:
a) establish an information technology system to prevent fraud risks;
b) have computer devices, information technology systems, workrooms, office equipment, and administrative systems that support the Company's activities;
c) have an organizational structure that supports the Company's work pattern;
d) apply adequate asset and data security principles and business continuity management; and
e) consider the Company's office location, for example, being in a strategic place (close to consumers) and not in areas prone to natural disasters.
The determination of risk appetite and risk tolerance for Operational Risk refers to the general scope of application in item I.B.2.
a) The Company has an adequate operational system.
b) The Company has an early warning system when there is a discrepancy between actual data and data held by the Company.
c) The Company must establish Operational Risk Management policies that must be internalized into the business processes of all business lines and supporting activities of the Company, including unique Operational Risk policies according to the needs of business lines and supporting activities.
d) The Company must have procedures that are derivatives of the Operational Risk Management Policy. These procedures may include:
(1) general controls, namely operational controls that are general across all business lines and supporting activities of the Company, such as segregation of duties or mandatory leave requirements; and
(2) specific controls, namely operational controls that are specific to each business line and supporting activity of the Company, such as policyholder document management.
e) The Company has early warning procedures to handle sudden changes in information technology systems that increase the likelihood of Operational Risk.
f) To reduce the possibility of Operational Risk arising from HR, the Company's Risk Management policies must at least contain policies regarding recruitment and placement according to organizational needs, competitive remuneration and incentive structures, training and development, periodic rotation, career planning and succession policies, and handling of termination of employment and labor union issues.
g) To reduce the possibility of Operational Risk arising from systems and infrastructure, the Company's Risk Management policies must be supported by procedures for accessing information management systems, accounting information systems, risk management systems, document room security, and data processing rooms.
h) To reduce the possibility of Operational Risk arising from external events, the Company's Risk Management policies must be supported, among others, by insurance protection for the Company's physical assets, backup systems, and work safety guarantees for certain high-risk job fields.
i) The Company has effective procedures to hinder, prevent, detect, report, and repair fraud that may occur within the Company.
j) To reduce the possibility of Operational Risk arising from the profile of insured/policyholders and prospective insured/policyholders, the Risk Management Policy must include the Company's obligation to conduct Customer Due Diligence (CDD) or Enhanced Due Diligence (EDD) periodically and consistently according to Operational Risk exposure. The implementation of CDD/EDD refers to all requirements and guidelines as regulated in applicable provisions regarding anti-money laundering and counter-terrorism financing. CDD/EDD must be supported by an effective internal control system, specifically the Company's efforts to prevent internal crimes (internal fraud).
The setting of limits for Operational Risk refers to the general scope of application as referred to in item I.B.4.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Operational Risk, in addition to carrying out processes as referred to in item I.C, the Company must add the implementation of several aspects in each of the aforementioned processes, as follows:
a) The Company must conduct identification and measurement of parameters affecting Operational Risk exposure, including the frequency and impact of:
(1) system failures and errors;
(2) information technology system weaknesses;
(3) customer relationship failures;
(4) accounting errors;
(5) asset calculation errors;
(6) fraud; and
(7) accounting manipulation.
b) The Company develops a database regarding:
(1) types and impacts of losses caused by Operational Risk based on risk identification results, consisting of loss data that may be predictable and those that are difficult to predict;
(2) control system violations; and
(3) other operational issues that may cause losses in the future.
c) The Company considers various internal and external factors in identifying and measuring Operational Risk, including:
(1) the Company's organizational structure, risk culture, HR management, organizational changes, and employee turnover;
(2) the Company's policyholder characteristics, products and activities, as well as the complexity of business activities and transaction volume;
(3) the design and implementation of systems and processes used; and
(4) the external environment, industry trends, market structure, including social and political conditions.
d) For Companies that have not yet developed special methods for identifying and measuring Operational Risk, the main source of Operational Risk information is internal audit findings related to Operational Risk.
In measuring Operational Risk, among others, indicators/parameters such as the size and organizational structure, HR, new business development, and the use of third-party services can be used.
a) The Company must conduct continuous monitoring of Operational Risk regarding all Operational Risk exposures and losses that may be caused by the Company's main activities, including by implementing an internal control system and providing periodic reports on losses caused by Operational Risk.
b) The Company must periodically review the factors causing Operational Risk and the impact of its losses.
a) Risk control is carried out consistently in accordance with the risk appetite, results of Operational Risk identification and measurement.
b) In implementing Operational Risk control, the Company may develop programs to mitigate Operational Risk, including securing information technology processes, and outsourcing certain operational activities of the Company.
c) In the event the Company develops information technology process security, the Company must ensure the security level of electronic data processing.
d) Control of information systems must ensure:
(1) periodic assessment of information system security, accompanied by corrective actions if necessary;
(2) the availability of backup procedures and emergency plans to ensure the Company's operational activities continue and prevent significant disruptions, which are tested periodically;
(3) the submission of information to the Board of Directors regarding the issues in paragraphs (1) and (2); and
(4) the availability of storage for information and documents related to analysis, programming, and data processing implementation.
e) The Company must have a support system, which must at least include:
(1) early error identification;
(2) efficient, accurate, and timely processing and settlement of all transactions; and
(3) confidentiality, truthfulness, and transaction security.
f) The Company must periodically review procedures, documentation, data processing systems, contingency plans, and other operational practices to reduce the possibility of human error.
g) The Company must have adequate policies and procedures, good Company administrative activities, good information technology system and technology management, good fraud and legal issue prevention, good HR management, and good third-party service provider management.
h) Employee recruitment is conducted by external parties such as HR consultants and organizations that independently analyze employee needs and carry out the employee recruitment process.
i) The Company provides training and mentoring to all Company employees.
d. Operational Risk Management Information System
In implementing Risk Management for Operational Risk, in addition to implementing the information management system as referred to in item I.D, the Company must also implement the following:
The information management system must be able to generate complete and accurate reports to detect and correct deviations in a timely manner.
The Company must have a reporting mechanism for Operational Risk that must, among others, provide information according to user needs, including the following:
a) Operational Risk profile and losses caused by Operational Risk;
b) results of various Operational Risk measurement methods and trends, and/or summaries of internal audit findings;
c) reports on the status and effectiveness of the implementation of action plans for operational risk issues;
d) reports on procedural deviations;
e) fraud incident reports; and
f) recommendations from the unit performing Risk Management functions regarding reviews conducted on the Company's Operational Risk assessment.
e. Comprehensive Internal Control System
In implementing Risk Management for Operational Risk, in addition to implementing internal control as referred to in item I.E, the Company must have a routine rotation system to avoid the potential for self-dealing, collusion, or concealment of documentation or transactions that are not normal.
C. Asset and Liability Risk
a. Asset and Liability Risk is the risk arising from the potential failure in asset management and liability management of the Company, which results in a lack of funds in fulfilling the Company's obligations as an Insurance Company to policyholders or the obligations of reinsurers to the Company that reinsures (ceding companies).
b. Asset and Liability Risk stems from poor asset management, poor liability management, and inadequate matching of assets and liabilities.
The main objective of Risk Management for Asset and Liability Risk is to ensure that the Company manages its assets and liabilities well so as not to cause a lack of funds in fulfilling the Company's obligations to policyholders/insured parties/customers or the obligations of reinsurers to the Company that reinsures (ceding companies).
The implementation of Risk Management for Asset and Liability Risk for the Company must at least cover:
a. Active Oversight by the Board of Directors and Board of Commissioners
In implementing Risk Management through active oversight by the Board of Directors and Board of Commissioners for Asset and Liability Risk, in addition to carrying out active oversight as referred to in item I.A, the Company must add the implementation of several aspects in each aspect of the active oversight of the Board of Directors and Board of Commissioners, as follows:
a) The Board of Commissioners must ensure that asset and liability management is carried out well so as not to negatively affect the Company's business.
b) The Board of Directors must ensure that assets owned by the Company are placed in investments or non-investments in accordance with the Risk Management policies implemented by the Company.
c) The Board of Directors must ensure that the Company has technical reserves that can fulfill obligations to policyholders and/or insured parties.
d) The Board of Directors must ensure that the Company will not experience mismatches between assets and liabilities, for example, due to changing economic conditions.
e) The Board of Directors formulates annual investment management plans.
The Board of Directors must ensure that each function/unit responsible for Asset and Liability Risk management has adequate HR competence. In addition, HR performing the Company's asset management functions must have adequate competence in asset management. In carrying out complex asset management, the Company's HR must be able to develop relevant models to mitigate Asset and Liability Risk. Such HR must also have expertise in developing and applying models to assess market conditions. Furthermore, the Company is responsible for placing HR performing asset management functions in the appropriate positions and organizational structure.
The Company must have adequate Asset and Liability Risk Management functions with clear authority and responsibilities for each unit performing Asset and Liability Risk Management functions. In addition, the Company must have a special committee handling assets and liabilities, for example, an investment management committee.
b. Adequacy of Policies, Procedures, and Limit Setting.
In implementing policies, procedures, and limit setting for Asset and Liability Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company must add the implementation of several aspects in each aspect of policies, procedures, and limit setting, as follows:
a) The Company records and evaluates assets and liabilities owned by the Company periodically.
b) The Board of Directors and Management monitor the assets and liabilities owned by the Company.
c) The Company establishes valuation strategies for unlisted investments.
d) The Company diversifies investments to avoid potential risks arising from investment failures.
e) The Company periodically calculates technical reserves to avoid discrepancies between incurred claim expenses and estimated claim expenses.
f) The Company maps owned assets to identify assets that are more liquid/illiquid than liabilities.
g) The Board of Directors and Management are responsive to issues regarding Asset and Liability Risk.
In implementing the determination of risk appetite and risk tolerance for Asset and Liability Risk, in addition to referring to the general scope of application as referred to in item I.B.2, the Company must add several aspects as follows:
a) The risk appetite statement must reflect the Company's perspective on Asset and Liability Risk. For example, the Company's statements regarding investment placement diversification, investment income, liquidity ratios, and profit acquisition. In addition, the risk appetite statement must support the achievement of the Company's established targets or objectives.
b) Risk tolerance for Asset and Liability Risk must reflect the Company's efforts to achieve its goals and be in accordance with the established risk appetite statement, such as the percentage of the Company's asset portfolio, the percentage of securities to be placed, future period profit targets, and insurance product marketing targets.
a) The Company has adequate asset management and liability management work plans.
b) The Company periodically reports on the Company's assets and liabilities to the Board of Commissioners.
c) Asset and liability management policies and procedures must at least include:
i. asset and liability composition;
ii. the level of assets maintained by the Company;
iii. investment diversification; and
iv. Asset and Liability Risk limits.
d) Risk Management in the Company is supported by appropriate policies and procedures, making it more directed and comprehensive.
e) The Company involves third parties in monitoring and managing the Company's assets and liabilities, for example, investment managers.
f) In choosing investment placements in instruments not traded on the stock exchange or in well-regulated financial markets, the Company conducts a procedure, for example, feasibility testing.
g) The Company has procedures for selecting securities, for example:
i. whether there is clear documentation, policy approval, and an approach to stock selection;
ii. the expert personnel owned by the Company regarding the securities selection function; and
iii. the supervision applied to ensure that
securities chosen for the investment portfolio have been in accordance with the investment objectives.
h) The Company has clear procedures for assessing hidden and non-standard risks related to the Company's asset placement in the form of investments that may cause the Company to incur losses.
i) The Company implements valuation policies for each type of investment.
j) The Company's Risk Management Policy explicitly states the asset-liability management (ALM) policy, which specifically explains the nature, role, and scope of ALM activities and their relationship with product development, pricing, and investment management.
k) The Company's Risk Management Policy is reflected in the investment policy, which is explicitly stated and contains:
i. the nature, role, and level of the Company's investment activities and how the Company meets the applicable regulations regarding investments; and
ii. Risk Management procedures that are in accordance with the Company's investment policy, for example, the types of complex or less transparent investment placements.
l) The ALM Policy must understand the dependency between assets and liabilities and consider the correlation of each Risk on each asset.
a) Asset and Liability Risk Limits must be consistent and relevant to the Company's asset and liability composition.
b) Policies regarding limits must be applied consistently to manage Asset and Liability Risk, including to limit the investments made by the Company.
c) Asset and Liability Risk Limits may include, among others, the amount of investments made by the Company, the calculation of the time gap difference between assets and liabilities, and the measurement method in forming technical reserves.
c. Adequacy of the Risk Identification, Measurement, Monitoring, and Control Process
In implementing Risk Management for Asset and Liability Risk, in addition to carrying out the processes as referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
a) In order to identify Asset and Liability Risk, the Company must analyze all sources of Asset and Liability Risk. Sources of Asset and Liability Risk include, among others, the management of the Company's assets and liabilities.
b) The analysis is conducted to determine the amount of assets owned and the amount of liabilities that must be met by the Company so that there is no mismatch between assets and liabilities.
c) The Company must conduct an analysis to determine the impact of investment risk on Asset and Liability Risk.
d) The Company must conduct valuation of assets in the form of investments and non-investments.
e) The Company must form technical reserves using appropriate methods and assumptions so that the Company can meet its obligations to policyholders/ceding companies.
In measuring Asset and Liability Risk, the Company can use indicators/parameters such as asset assessment, investment objectives, the use of methods and assumptions in forming technical reserves, mismatches between assets and liabilities in foreign currency (currency gap), and liquidity levels. In addition, the Company must also use solvency level measurements for the present and for the future by considering existing Risks, as one of the indicators in measuring Asset and Liability Risk.
The work unit that carries out the Risk Management function for Asset and Liability Risk monitors and reports Asset and Liability Risk occurring to the Company's Board of Directors both ad hoc at the time of the occurrence of Asset and Liability Risk and periodically.
a) Asset and Liability Risk control is carried out by the Company, among others, through the Board of Directors' concern for asset and liability management objectives, monitoring of asset and liability management from an actuarial perspective, and the establishment of objectives.
b) The Company conducts periodic evaluations regarding the implementation of the investment strategies it has implemented. Matters that need to be considered in the investment strategy are:
(1) investment risks and returns, including performance benchmarks;
(2) asset allocation;
(3) diversification;
(4) liquidity and cash flow;
(5) the Company's ability to meet existing or future liabilities;
(6) valuation methods and frequency; and
(7) reserves and reserve formation policies.
c) The Company may involve third parties to conduct assessments of assets owned by the Company, both those listed and not listed on the exchange.
d) The Company must have high concern from the Board of Directors or Board of Commissioners regarding asset and liability management objectives, adequate asset and liability management, good investment risk management, and strong controls in conducting asset valuation.
d. Asset and Liability Risk Management Information System
In implementing Risk Management through the implementation of a management information system for Asset and Liability Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to implement the following:
The Company must have a good Management Information System (MIS) to support reporting on asset and liability management risk issues.
The Company's policies in asset and liability management can be accessed through an electronic system.
The Company uses automation (computerization) in conducting asset and liability assessments.
e. Comprehensive Internal Control System
In implementing Risk Management for Asset and Liability Risk, in addition to implementing internal controls as referred to in item I.E, the Company needs to have an internal control system for Asset and Liability Risk, among others, to ensure the Company's responsiveness to deviations from generally applicable standards, regulations, and/or applicable legislation.
D. Governance Risk
a. Governance Risk is the risk of the Company's failure to achieve its objectives due to the Company's failure to maintain the best composition of management with high competence and integrity. The management referred to in Governance Risk includes the Board of Directors and the Board of Commissioners.
b. Sources of Governance Risk include, among others, inadequate appointment and dismissal of the Board of Directors and Board of Commissioners, insufficient and inappropriate composition and proportion of the Board of Directors and Board of Commissioners relative to the Company's needs, inadequate competence and integrity of the Board of Directors and Board of Commissioners that do not support the duties and authorities of the Board of Directors and Board of Commissioners, and poor leadership of the Board of Directors and Board of Commissioners.
c. Governance Risk can increase, among others, due to the unavailability of adequate remuneration systems for the Board of Directors and Board of Commissioners.
The main objective of Risk Management for Governance Risk is to ensure that the Company maintains the best composition of the Board of Directors and Board of Commissioners with high competence and integrity so that the Company can achieve its objectives.
The implementation of Risk Management for Governance Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners
In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Governance Risk, in addition to carrying out active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Governance Risk is carried out in an integrated manner with other Risk Management that can impact the Company's Governance Risk profile.
b) The Board of Directors and Board of Commissioners must ensure that the Company has an adequate internal selection system that is applied continuously/consistently.
c) The Board of Directors and Board of Commissioners must inform and remind shareholders regarding regulations related to the appointment and dismissal of the Board of Directors and Board of Commissioners when the General Meeting of Shareholders (GMS) is held.
d) The Board of Directors must ensure that the implementation of Risk Management is carried out effectively in implementing aspects related to Governance Risk such as selection, appointment of the Board of Directors and Board of Commissioners, and others.
HR adequacy for Governance Risk refers to the general implementation scope as referred to in item I.A.2.
In the implementation of Risk Management for Governance Risk, the Company has an organ that supports the Company's business activities by considering, among others:
a) clarity of duties and responsibilities of the Board of Directors and Board of Commissioners based on the competence and expertise possessed, so that the Board of Directors and Board of Commissioners are adaptive to changing market needs; and
b) methods to ensure that the Board of Directors and Board of Commissioners appointed by the controller do not have conflicts of interest with the Company's business activities.
In addition, the Company may also form a special work unit responsible for assessing the leadership, competence, and integrity of the Board of Directors and Board of Commissioners.
b. Adequacy of Policies, Procedures, and Limit Setting
In implementing policies, procedures, and limit setting for Governance Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policy, procedure, and limit setting, as follows:
a) The Risk Management Strategy for Governance Risk covers all risk causes, including the appointment and dismissal and leadership of the Board of Directors and Board of Commissioners.
b) The Risk Management Strategy for Governance Risk has the ability to minimize the possibility of Governance Risk emerging, for example, by conducting background checks on prospective Board of Directors/Board of Commissioners candidates.
The establishment of the level of Risk to be taken and Risk tolerance for Governance Risk refers to the general implementation scope as referred to in item I.B.2.
a) The Company must have written policies and procedures containing regulations regarding competence and capability as a member of the Board of Directors or Board of Commissioners in order to achieve the Company's objectives.
b) The Company may form a special work unit to handle unexpected events due to sudden changes in the number and composition of the Board of Directors and Board of Commissioners.
c) The Company must have specific standards and criteria in submitting the names of prospective Board of Directors/Board of Commissioners candidates to shareholders.
d) The Company must have specific standards and criteria in the selection of prospective Board of Directors/Board of Commissioners candidates conducted by shareholders.
e) The Company must have procedures regarding the appointment documents of the Board of Directors/Board of Commissioners that are in accordance with applicable regulations/laws.
a) Governance Risk limits generally are not limits that can be quantified financially.
b) The Company needs to apply Risk tolerance for Governance Risk.
c) Limits for Governance Risk are used to reduce Risks arising, including due to the minimum number of the Company's Board of Commissioners.
c. Adequacy of the Risk Identification, Measurement, Monitoring, and Control Process
In implementing Risk Management for Governance Risk, in addition to carrying out the processes as referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
a) The Company must record and account for every event related to Governance Risk, for example, the number of the Board of Directors/Board of Commissioners composition, meetings attended by the Board of Directors/Board of Commissioners, and meeting minutes involving the Board of Directors/Board of Commissioners.
b) The Company assesses the procedures and legality of documents related to the appointment and dismissal of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring.
c) The Company uses the results of fitness and propriety tests, work experience, education and training, and the behavior of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring.
d) The Company can use several information sources to identify Governance Risk, among others, media news and information obtained from authorities regarding the background/characteristics of prospective Board of Directors/Board of Commissioners candidates.
In measuring Governance Risk, among others, indicators/parameters can be used such as the establishment of procedures and legality of documents related to the appointment and dismissal of the Board of Directors/Board of Commissioners, ownership of composition and proportion of the Board of Directors and Board of Commissioners in accordance with applicable legislation, and the establishment of criteria for good competence and integrity for the Board of Directors/Board of Commissioners.
a) The Company monitors the legality of documentation for the appointment and dismissal of the Board of Directors/Board of Commissioners through a specific work unit, for example, the Risk Management work unit.
b) In monitoring data, the number, and composition of the Board of Directors and Board of Commissioners, the Company develops an electronic system to monitor all data of the Board of Directors and Board of Commissioners.
c) The Company can cooperate with third parties to monitor the leadership, competence, and integrity of the Board of Directors/Board of Commissioners.
a) The Company must immediately follow up on and address reports that the Company's Board of Directors/Board of Commissioners have taken actions contrary to applicable regulations.
b) The Company develops guidelines regarding criteria for prospective Board of Directors/Board of Commissioners candidates, guidelines regarding the process of appointment, replacement, and dismissal of the Board of Directors/Board of Commissioners.
c) Governance Risk mitigation or events causing Governance Risk are carried out by considering the materiality of the problem and costs.
d) In order to control Governance Risk on a larger scale in the future, preventive and recovery actions for Governance Risk that have been carried out need to be followed by improvements in control weaknesses and procedures that trigger the occurrence of Governance Risk.
e) The Board of Directors/Board of Commissioners receive periodic education to improve the competence and capability of the Board of Directors/Board of Commissioners.
f) The HR work unit must ensure that every governance problem that arises can be resolved effectively by the relevant work unit and that monitoring of corrective actions is carried out by the HR work unit.
g) The Board of Directors and Board of Commissioners develop succession planning.
d. Governance Risk Management Information System
In implementing Risk Management for Governance Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to implement the following:
The Company has a system that shows a complete profile of the Board of Directors/Board of Commissioners.
The Company has regular procedures and reporting mechanisms for Governance Risk/events causing Governance Risk, both in writing and through electronic systems.
The Company has an early warning system mechanism to provide signals to management so that it can carry out the necessary response and mitigation.
The Company has a management information system that records steps for Governance Risk mitigation.
e. Comprehensive Internal Control System
In implementing Risk Management for Governance Risk, in addition to implementing internal controls as referred to in item I.E, the Company also needs to implement the following:
An independent and continuous review system of the effectiveness of the Risk Management process implementation for Governance Risk, which at least contains an evaluation of the administrative process for nominating the Board of Directors/Board of Commissioners and the effectiveness of the implementation of the work unit or officers who monitor the selection of the Board of Directors/Board of Commissioners.
An internal review system by a specific independent work unit to help evaluate the overall selection process and assess whether the Company has implemented selection standards and criteria correctly.
An efficient and effective reporting system to provide adequate information to the Board of Commissioners, Board of Directors, and audit committee.
Internal audit of the Governance Risk process is carried out periodically, which among others covers the identification of whether:
a) selection activities are in line with established policies and procedures;
b) all authorizations are carried out within the guidelines provided; and
c) there are weaknesses in the Risk Management process for Governance Risk, policies and procedures, including any exceptions to policies, procedures, and limits.
E. Governance Risk
a. Governance Risk is the potential failure in the implementation of good governance, inappropriate management style, control environment, and behavior of every party involved directly or indirectly with the Company.
b. Sources of Governance Risk include the Company's governance guidelines being inadequate, the Company not implementing good governance principles, and the Company not implementing Risk Management adequately.
c. Governance Risk can increase, among others, due to intervention from other parties resulting in failure in the implementation of good governance.
The main objective of Risk Management for Governance Risk is to minimize the risk of good governance not being implemented in the Company.
The implementation of Risk Management for Governance Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners
In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Governance Risk, in addition to carrying out active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Governance Risk is carried out in an integrated manner with other Risk Management that can impact the Company's Governance Risk profile.
b) The Board of Commissioners must monitor the effectiveness of the implementation of the governance function in the Company and be followed by all parties within the Company.
c) The Board of Commissioners compile the Board of Commissioners' activity report, which is part of the report on the implementation of the Company's good governance.
d) The Board of Commissioners hold Board of Commissioners meetings.
e) The Board of Directors and Board of Commissioners must ensure that the Company has a code of ethics as a guide for ethical behavior for the Board of Commissioners, Board of Directors, and all employees.
f) The Board of Directors is responsible for risk management in carrying out business activities through the development and implementation of a Risk Management framework within the Company.
g) The Board of Directors must periodically report the progress of its business activities as evidence of accountability to shareholders.
h) The Board of Directors and Board of Commissioners must carry out their functions in accordance with applicable regulations in accordance with their respective obligations.
The Board of Directors must ensure that every function and work unit responsible for the management of Governance Risk has HR with adequate competence. The adequacy of HR for Governance Risk refers to the general implementation scope as referred to in item I.A.2. In addition, to support good Company governance, the Company has a work unit or employees who carry out compliance functions.
a) All employees, including the Company's work unit management and supporting Company activities, must be part of the implementation structure for Risk Management for Governance Risk, considering that governance is the entirety of the Company's activities.
b) The establishment of organizational structure, devices, and completeness of work units/functions related to the implementation of Risk Management for Governance Risk must be adjusted to the characteristics and complexity of the Company's business activities.
b. Adequacy of Policies, Procedures, and Limit Setting
In implementing policies, procedures, and limit setting for Governance Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policy, procedure, and limit setting, as follows:
a) The Risk Management Strategy for Governance Risk must cover strategies for all activities with significant Governance Risk exposure. The strategy must clearly state the direction of the Company's governance.
b) The Risk Management Strategy for Governance Risk must be in line with the Company's objectives to implement good Company governance.
c) The Risk Management Strategy for Governance Risk includes the Company's strategic values, including openness, accountability, and responsibility.
d) The Company has a risk management strategy to improve the Company's governance value.
The establishment of the level of Risk to be taken and Risk tolerance for Governance Risk refers to the general implementation scope as referred to in item I.B.2.
a) The Company has a system that can identify, assess, and measure the adequacy and effectiveness of governance implementation in the Company.
b) The Company has a work unit that monitors the implementation of the Company's values across all elements of the Company.
c) The Company has a work plan to implement good Company governance, which includes governance guidelines
manage, openness, accountability, responsibility, independence, fairness and equality, and Risk Management.
d) The Board of Commissioners receives reports regarding the implementation of good corporate governance in the Company at least 1 (one) time in one year.
e) The Company has appropriate policies and procedures to ensure the fulfillment of internal policies and statutory regulations.
The limits applied in the Company are limits determined based on self-assessments conducted by the Company. For example, regarding limits on transparency in the implementation of good corporate governance, the Company can determine boundaries regarding the extent to which the Company is transparent in implementing corporate governance, self-assessment limits, and limits regarding action plans.
c. Adequacy of the Risk Identification, Measurement, Monitoring, and Control Process
In implementing Risk Management through the process of identification, measurement, monitoring, and control of Risk for Governance Risk, in addition to carrying out the processes referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
The Company must conduct identification and analysis of several factors that can increase the exposure of Governance Risk, such as:
a) availability and completeness of governance guidelines; b) openness in disclosure and provision of relevant information regarding the Company; c) changes in management style, influence of the control environment, and behavior of parties directly or indirectly involved with the Company; and
d) intervention from shareholders, the Board of Commissioners, and other parties.
In measuring Governance Risk, among others, indicators/parameters such as the completeness of adequate governance guidelines, the principles of openness, accountability, responsibility, independence, fairness and equality, and Risk Management implemented well can be used.
The work unit carrying out the Risk Management function for Governance Risk monitors and reports Governance Risk that occurs to the Company's Board of Directors both at any time and periodically.
a) In the context of controlling Governance Risk, the Company must ensure that the Company has governance guidelines established formally by the Board of Directors. b) Control of Governance Risk can be done in several ways, among others by mitigating Risk, completeness of governance guidelines, and transparency of the Board of Directors/Board of Commissioners in making decisions. c) The Company has an early detection system to prevent potential losses to the Company. d) The Company conducts assessment and management of Risk in the context of controlling Governance Risk. e) The Board of Directors and Board of Commissioners apply the principles of openness, accountability, responsibility, independence, fairness and equality, and Risk Management in running the Company. f) In the context of controlling Governance Risk, the Company has clearly established the functions and duties of each work unit so that each party can carry out their functions and duties well. g) The Company has guidelines and applies performance measures and reward and punishment systems well to all levels within the Company. h) The Company is not under the dominance of third parties and is not influenced by the interests of third parties and is free from conflicts of interest with such third parties. i) The Company conducts periodic evaluations regarding the implementation of Risk Management at least once in one year. j) The Company has guidelines regulating business relations with business partners.
d. Risk Management Information System for Governance Risk
In implementing Risk Management for Governance Risk, in addition to carrying out the management information system referred to in item I.D, the Company also needs to implement the following things:
e. Comprehensive Internal Control System
In implementing Risk Management for Governance Risk, in addition to carrying out internal control as referred to in item I.E, the Company needs to have an internal control system for Governance Risk, among others, to ensure the Company's level of responsiveness to deviations from generally applicable standards, regulations, and/or applicable statutory regulations. The internal control system in the Company can refer to 5 (five) components issued by the Committee of Sponsoring Organization of the Treadway Commission (COSO), namely the control environment, risk assessment, control procedures, monitoring, and information and communication.
F. Funding Support (Capital) Risk
a. Funding Support (Capital) Risk is Risk that arises due to insufficient funds/capital in the Company, including lack of access to additional funds/capital in facing losses or unexpected fund/capital needs. b. The Company's capitalization describes the Company's ability to absorb unexpected losses caused by, among others, an increase in the ratio of claims beyond expectations, poor investment results, or other unexpected events.
c. Funding Support (Capital) Risk stems from low funding (capital) capability and weak additional funding (capital).
The main objective of Risk Management for Funding Support (Capital) Risk is to ensure that the Risk Management process can minimize the possibility of the Company having weak funding capability and low additional funding so that the Company cannot absorb unexpected losses.
The implementation of Risk Management for Funding Support (Capital) Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners
In implementing Risk Management for Funding Support (Capital) Risk, in addition to carrying out active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Funding Support (Capital) Risk is carried out integrated with other Risk Management that can impact the Company's Funding Support (Capital) Risk profile. b) The Director overseeing the finance function has an important role in Risk Management for Funding Support (Capital) Risk with responsibilities at least as regulated in applicable provisions regarding the implementation of the general company's funding function, among others:
(1) formulating Risk Management policies containing written and comprehensive risk strategies and frameworks, considering the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance); (2) having adequate understanding of Risks inherent in all business activities within the Company and being able to take necessary actions according to the Funding Support (Capital) Risk profile; (3) establishing compliance systems and procedures to be used to formulate the Company's internal regulations and guidelines; (4) minimizing the Company's Funding Support (Capital) Risk; and (5) taking preventive actions so that policies and/or decisions taken by the Board of Directors do not deviate from applicable statutory regulations. c) The Board of Directors must ensure that the Company has sufficient funding capability according to the Company's Risk level. d) The Board of Directors must ensure that asset placement in the form of investment and/or non-investment can provide additional capital to the Company.
Officials and staff in all work units of the Company understand the impact caused by all Risks that can result in the emergence of Funding Support (Capital) Risk.
a) The Company must have an adequate Risk Management function for Funding Support (Capital) Risk with clear authority and responsibilities for each work unit carrying out the Risk Management function for Funding Support (Capital) Risk. b) The Company must have an independent financial work unit with duties, authority, and responsibilities at least as regulated in applicable provisions regarding the implementation of the Company's financial function, among others:
(1) creating steps to support the creation of a Company with strong funding support; (2) having written work programs and conducting identification, measurement, monitoring, and control related to Risk Management for Funding Support (Capital) Risk; (3) assessing and evaluating the effectiveness, adequacy, and suitability of the Company's policies, systems, and procedures with applicable statutory regulations; (4) conducting review and/or recommending updates and improvements to the Company's policies, regulations, systems, and procedures to align with Company regulations and applicable statutory regulations; (5) making efforts to ensure that the Company's policies, regulations, systems, and procedures and business activities comply with Company regulations and applicable statutory regulations; and (6) carrying out other tasks related to the financial function.
b. Adequacy of Policies, Procedures, and Limit Setting
In implementing policies, procedures, and limit setting for Funding Support (Capital) Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policies, procedures, and limit setting, as follows:
a) The Board of Directors monitors funding in the Company as an anticipatory measure when unexpected losses occur. b) The Board of Commissioners monitors investments owned by the Company. c) The Company must ensure that the minimum ratio of solvency achievement level complies with applicable regulations and is sufficient to overcome unexpected losses. d) The Company has capital management standards aimed at ensuring the Company has sufficient funds for all risks faced and implements the determined standards. e) The Company has a strategy that allows the Company to have sufficient access to additional funding.
The determination of the level of Risk to be taken and Risk tolerance for Funding Support (Capital) Risk refers to the general implementation scope as referred to in item I.B.2.
a) The policy must clearly contain:
(1) funding support management policy;
(2) minimum solvency ratio of the Company;
(3) minimum Company capital 1 times the minimum equity capital required; and (4) monitoring and controlling the Company's capital position. b) The Company has ease of access to the capital market, shareholders, or affiliated parties in order to increase capitalization. c) The Company has procedures for requesting capital additions. d) The Company has a policy regarding the utilization of profitability derived from investment and non-investment.
a) The Company must ensure consistency between various different types of limits. b) Limit setting can be established hierarchically for each level of the Company's organization, for example, overall limits, additional funding (capital) limits, solvency ratio limits, and funding capability (capital) limits.
c. Adequacy of the Risk Identification, Measurement, Monitoring, and Control Process
In implementing Risk Management for Funding Support (Capital) Risk, in addition to carrying out the processes as referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
The Company must conduct identification and analysis of several factors that can increase the exposure of Funding Support (Capital) Risk, such as:
a) the amount (volume) and materiality of unexpected losses of the Company due to products and diverse activities carried out; b) sources of additional capital for the Company; and c) calculation of Minimum Risk-Based Capital (MMBR) using a schedule so that the Company can know the Company's total MMBR.
In measuring Funding Support (Capital) Risk, among others, indicators/parameters such as the Company's weak funding capability and low additional funding can be used.
The Company must conduct self-assessment (self assessment) on the quality and adequacy of funding support sources in order to meet the Company's capitalization needs and minimum required capital, considering the capital quality criteria set by the regulator and other factors considered relevant. Subsequently, the work unit carrying out the Risk Management function for Funding Support (Capital) Risk monitors and reports Funding Support (Capital) Risk that occurs to the Company's Board of Directors both at any time when Funding Support (Capital) Risk occurs and periodically. In addition, the Company monitors the adequacy of the Company's capital and monitoring when the solvency achievement ratio is below the minimum solvency target level determined.
a) The Company periodically evaluates the Company's solvency achievement ratio. b) The Company monitors and controls the Company's capital position. c) Profits obtained by the Company, both from investment and non-investment, must be allocated and distributed appropriately to units within the Company so as not to create the possibility of Funding Support (Capital) Risk occurring. d) Self-assessment of Risk Management conducted by the Company must at least cover all relevant Risks including liquidity and underwriting risks and additional Risks resulting from group membership, in order to identify the relationship between Risk Management and the quality of capital needed and available. e) As part of the Risk Management self-assessment, the Company needs to do the following:
(1) assess the quality and adequacy of capital sources to meet capital regulations and additional capital needs; and (2) conduct analysis on the sustainability of its business including projections of future financial conditions to continue to meet applicable capital regulations.
d. Risk Management Information System for Funding Support (Capital) Risk
The implementation of the management information system for Funding Support (Capital) Risk refers to the general implementation scope as referred to in item I.D. In addition, the Company needs to meet the following things:
e. Comprehensive Internal Control System
In implementing Risk Management for Funding Support (Capital) Risk, in addition to carrying out internal control as referred to in item I.E, the Company needs to have an internal control system for Funding Support (Capital) Risk, among others, to ensure the Company's level of responsiveness to poor investment results, unexpected losses, and claim ratios beyond expectations, and other unexpected events.
G. Insurance Risk
a. Insurance Risk is the potential failure of the Company to fulfill obligations to insured parties and policyholders as a result of insufficient risk selection (underwriting) processes, premium setting (pricing), reinsurance usage, and/or claim handling. b. Generally, the sources of Risk from Insurance Risk consist of 3 (three) things, namely insurance business characteristics, product mix/diversification, and reinsurance structure.
The main objective of Risk Management for Insurance Risk is to minimize the possibility of insufficient risk selection (underwriting) processes, premium setting (pricing), reinsurance usage, and/or claim handling so that the Company cannot fulfill obligations to insured parties and policyholders.
The implementation of Risk Management for Insurance Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners
In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Insurance Risk, in addition to carrying out active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Insurance Risk is carried out integrated with other Risk Management that can impact the Company's Insurance Risk profile. b) The Board of Directors must ensure that every problem that has the potential to cause Insurance Risk can be effectively resolved by the relevant work unit and monitoring is carried out on corrective actions for such potential. c) The Board of Directors ensures that marketed products have been analyzed and adjusted to market needs. d) The Board of Directors must establish a product development strategy plan and product evaluation. e) The Board of Directors must ensure that standard operating procedures applicable in the Company comply with best practices, including the underwriting process, claim handling, and product distribution.
HR adequacy for Insurance Risk refers to the general implementation scope as referred to in item I.A.2. In addition, the Company needs to have an effective actuarial function capable of evaluating and providing advice to the Company at least regarding technical provisions and premium rate setting in accordance with applicable regulations. A healthy actuarial function is one that places the right HR and has sufficient understanding in the field of actuarial science so that the Company can carry out its activities properly.
In addition to referring to the general scope of Risk Management organization implementation as referred to in item I.A.3, the Company can form work units that can support Insurance Risk mitigation, among others, marketing units and public relations units, and form work units or insurance product development committees.
b. Adequacy of Policies, Procedures, and Limit Setting
In implementing policies, procedures, and limit setting for Insurance Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policies, procedures, and limit setting, as follows:
d) Risk Management Strategy for Insurance Risk must include strategies for all activities with significant Insurance Risk exposure. The strategy must clearly contain the risk selection process, premium setting, reinsurance usage, and claim handling. e) Risk Management Strategy for Insurance Risk must align with the Company's objectives to fulfill its obligations to policyholders. f) The Company has adequate management and control of Insurance Risk for product design/development, premium setting, underwriting, claims, liability valuation, reinsurance, and distribution.
g) The Company provides educational opportunities to the Board of Directors and management to increase the Board of Directors' and management's understanding of Insurance Risk. h) The Company carries out strategies regarding business lines/product types to be selected/marketed. i) The Company has a specific work unit handling claims.
The determination of the level of Risk to be taken and Risk tolerance for Insurance Risk refers to the general implementation scope as referred to in item I.B.2.
a) The Company has policies and procedures regarding product development. b) Product development is adjusted to the Company's policies and procedures and applicable regulations. c) Policies and procedures related to product design and new products involve employees with adequate expertise and experience, among others. d) The Company maps the impact created by the dominance of Insurance Risk on the entire business line. e) The Company has a policy regarding the underwriting process. f) Premium setting procedures comply with the underwriting process so that there is no failure to fulfill obligations to policyholders. g) Policies regarding the selection of types of Risks covered and types of products marketed comply with the underwriting process. h) Formal procedures for monitoring Insurance Risk become part of the Company's framework and contain, among others, Risk Management strategies, and the Company's Risk Management procedures and policies. i) The Company conducts periodic evaluations of factors from products assessed as part of Insurance Risk,
for example, the type of Risk covered, benefit payment methods, and product types.
4) Limit
a) The Company must establish limits on the provision and distribution of products that can increase Insurance Risk. b) The Company needs to apply Risk tolerance for Insurance Risk. c) Limits for Insurance Risk are used to reduce Risks arising, including those from the types of products marketed by the Company.
c. Adequacy of the Risk Identification, Measurement, Monitoring, and Control Process
In implementing Risk Management for Insurance Risk, in addition to carrying out the process as referred to in item I.C, the Company needs to add the application of several items in each of the aforementioned processes, as follows:
iii. inability of the reinsurer to meet claim payment liabilities; and
iv. failures in the production process, inability of human resources or systems to perform well, or other adverse events.
2) Insurance Risk Measurement
In measuring Insurance Risk, indicators/parameters can include, among others, the comparison between insurance products with a term of up to 1 (one) year and insurance products with a term of more than 1 (one) year, the comparison of the proportion of low-risk insurance product portfolios to the total insurance product portfolio, the comparison of incurred claims to estimated claims, and the comparison of the proportion of retained risk to the proportion of risk transferred or reinsured.
3) Insurance Risk Monitoring
a) The work unit carrying out the Risk Management function for Insurance Risk monitors and reports Insurance Risk occurrences to the Company's Board of Directors both ad hoc when Insurance Risk occurs and periodically. b) The Company monitors the portfolio and its impact on the underwriting decision-making process.
4) Insurance Risk Control
a) The Board of Directors and management monitor Insurance Risk so that the Board of Directors and management know the current conditions regarding the Insurance Risk profile. b) The Company updates underwriting procedures, claim procedures, policy terms, liability valuation, product distribution, and the scope of reinsurance. c) The Company receives input from third parties regarding premium setting, for example, from actuaries. d) The Company provides training to enhance the Board of Directors' understanding of Insurance Risk. e) The Company develops product design by first conducting market needs analysis.
f) The Company sets premiums based on several criteria, for example, actuarial assumptions and claim estimates. g) The Company conducts the underwriting process as a form of control over Insurance Risk. h) Independent parties review the Company. i) Underwriting procedures have been well applied and implemented in the Company. j) The Company's business work unit or the Company's actuary periodically monitors new business and the underwriting function. d. Insurance Risk Management Information System In implementing Risk Management for Insurance Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to apply the following:
APPENDIX II
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 10 /SEOJK.05/2016
REGARDING
GUIDELINES FOR RISK MANAGEMENT IMPLEMENTATION AND SELF-ASSESSMENT REPORT OF RISK MANAGEMENT IMPLEMENTATION FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
To
The Financial Services Authority u.p. Insurance and BPJS Health Supervision Directorate Merdeka Tower Building, 25th Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110 SELF-ASSESSMENT REPORT ON RISK MANAGEMENT IMPLEMENTATION INSURANCE COMPANY/REINSURANCE COMPANY YEAR … PT XYZ (Company Address)
SELF-ASSESSMENT REPORT
ON RISK MANAGEMENT IMPLEMENTATION
INSURANCE COMPANY/REINSURANCE COMPANY
Company Name :
Business Type : (1) Life (2) General (3) Reinsurance Assessment Date :
Report Position Date :
A. GENERAL INFORMATION
Shareholders or equivalent :
No. Name Ownership Value
(In Rupiah)
Ownership Percentage
1.
2. etc.
Board of Directors:
No. Name Position Term of Office
1.
2.
3. etc.
Board of Commissioners:
No. Name Position Term of Office
1.
2.
3. etc.
B. INSURANCE FINANCIAL INFORMATION
Description Value (Rupiah)*
Assets
Investments
Liabilities
Technical Reserves
Gross Premiums
Gross Claims
Total Solvency Ratio
Total Minimum Risk-Based Capital (MMBR)
Solvency Achievement Ratio (%)
Total Number of Policyholders (persons)*
D. RISK MANAGEMENT IMPLEMENTATION FOR EACH TYPE OF RISK
Risk Management Information System
…………… (Filled with a description of how the company's information system supports Risk Management implementation over Operational Risk) Comprehensive Internal Control System …………… (Filled with a description of how internal controls including the compliance function are carried out by the company for Operational Risk)
3. Asset and Liability Risk
Scope of Risk Management Implementation Description Active Supervision by Board of Directors and Board of Commissioners …………… (Filled with a description of active supervision by the Board of Directors and Board of Commissioners over Asset and Liability Risk) Adequacy of Policies, Procedures, and Risk Limit Setting …………… (Filled with a description of risk appetite, risk tolerance, and risk limit setting over Asset and Liability Risk) Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes …………… (Filled with a description of the identification, measurement, monitoring, and control processes over Asset and Liability Risk) Risk Management Information System …………… (Filled with a description of how the company's information system supports Risk Management implementation over Asset and Liability Risk) Comprehensive Internal Control System …………… (Filled with a description of how internal controls including the compliance function are carried out by the company for Asset and Liability Risk)
4. Management Risk
Scope of Risk Management Implementation Description Active Supervision by Board of Directors and Board of Commissioners …………… (Filled with a description of active supervision by the Board of Directors and Board of Commissioners over Management Risk)
Adequacy of Policies, Procedures, and Risk Limit Setting …………… (Filled with a description of risk appetite, risk tolerance, and risk limit setting over Management Risk) Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes …………… (Filled with a description of the identification, measurement, monitoring, and control processes over Management Risk) Risk Management Information System …………… (Filled with a description of how the company's information system supports Risk Management implementation over Management Risk) Comprehensive Internal Control System …………… (Filled with a description of how internal controls including the compliance function are carried out by the company for Management Risk)
5. Governance Risk
Scope of Risk Management Implementation Description Active Supervision by Board of Directors and Board of Commissioners …………… (Filled with a description of active supervision by the Board of Directors and Board of Commissioners over Governance Risk) Adequacy of Policies, Procedures, and Risk Limit Setting …………… (Filled with a description of risk appetite, risk tolerance, and risk limit setting over Governance Risk) Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes …………… (Filled with a description of the identification, measurement, monitoring, and control processes over Governance Risk) Risk Management Information System …………… (Filled with a description of how the company's information system supports Risk Management implementation over Governance Risk) Comprehensive Internal Control System …………… (Filled with a description of how internal controls including the compliance function are carried out by the company for Governance Risk)
Comprehensive Internal Control System
…………… (Filled with a description of how internal controls including the compliance function are carried out by the company for Insurance Risk) Prepared by, Acknowledged, (Signature) (Signature) (Name) (Name) (Position) (Position) Determined in Jakarta on April 14, 2016 EXECUTIVE HEAD OF SUPERVISOR OF INSURANCE, PENSION FUNDS, LENDING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS FINANCIAL SERVICES AUTHORITY, sd FIRDAUS DJAELANI Copy in accordance with the original Legal Director Legal Department sd Yuliana
APPENDIX III
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 10 /SEOJK.05/2016
REGARDING
GUIDELINES FOR RISK MANAGEMENT IMPLEMENTATION AND SELF-ASSESSMENT REPORT OF RISK MANAGEMENT IMPLEMENTATION FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
GUIDELINES FOR RISK MANAGEMENT IMPLEMENTATION FOR INSURANCE BROKERAGE COMPANIES, REINSURANCE BROKERAGE COMPANIES, AND INSURANCE LOSS ADJUSTERS As regulated in Article 2 of Financial Services Authority Regulation Number 1/POJK.05/2015 regarding Risk Management Implementation for Non-Bank Financial Service Institutions, hereinafter referred to as NBFIs, NBFIs are required to implement Risk Management effectively, which at least covers:
A. active supervision by the Board of Directors and Board of Commissioners; B. adequacy of policies, procedures, and risk limit setting;
C. adequacy of risk identification, measurement, monitoring, and control processes;
D. risk management information system; and
E. comprehensive internal control system.
Risk Management principles are described as follows:
A. Active Supervision by Board of Directors and Board of Commissioners The Board of Directors and Board of Commissioners are responsible for the effectiveness of Risk Management implementation in insurance brokerage companies, reinsurance brokerage companies, and insurance loss adjusters, hereinafter referred to as the Company. Therefore, the Board of Directors and Board of Commissioners must:
understand the Risks faced by the Company;
provide clear direction;
actively supervise and mitigate Risk;
develop a Risk Management culture in the Company;
ensure an adequate organizational structure;
establish clear tasks and responsibilities for each work unit; and
ensure the adequacy of the quantity and quality of human resources to support effective Risk Management implementation.
Matters to be noted in the implementation of active supervision by the Board of Directors and Board of Commissioners include the following:
Authority and Responsibility of the Board of Directors and Board of Commissioners
a. Risk Management implementation is adequate according to the characteristics, complexity, and Risk profile of the Company. b. The Board of Directors and Board of Commissioners must have a good understanding of the types and levels of Risk inherent in the Company's business activities.
c. In supporting Risk Management implementation, the Board of Directors and Board of Commissioners must ensure that the Company implements Risk Management.
d. The Board of Directors is responsible for Risk assessment and capital adequacy. e. The authority and responsibility of the Board of Commissioners, at least include:
directing and approving Risk Management policies including strategies and Risk Management frameworks established in accordance with the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) of the Company;
evaluating Risk Management policies and strategies at least once a year or more frequently if there are changes in factors significantly affecting the Company's business activities;
evaluating the accountability of the Board of Directors and providing improvement directions regarding the implementation of Risk Management policies periodically. Evaluation is conducted to ensure that the Board of Directors manages Company activities and Risks effectively; and
forming a risk monitoring committee tasked with assisting the Board of Commissioners in monitoring the implementation of Risk Management prepared by the Board of Directors.
f. The authority and responsibility of the Board of Directors, at least include:
preparing written and comprehensive Risk Management policies, strategies, and frameworks including overall Risk limits and per Risk type, considering the level of Risk to be taken and Risk tolerance according to Company conditions and calculating the impact of Risk on capital adequacy. After receiving approval from the Board of Commissioners, the Board of Directors establishes the aforementioned Risk Management policies, strategies, and frameworks;
preparing, establishing, and updating procedures and tools to identify, measure, monitor, and control Risk;
preparing and establishing transaction approval mechanisms, including those exceeding limits and authority for each job level;
evaluating and/or updating Risk Management policies, strategies, and frameworks at least once a year or more frequently if there are changes in factors significantly affecting the Company's business activities, Risk exposure, and/or Risk profile;
having adequate understanding of Risks inherent in all business activities within the Company and being able to take necessary actions according to the Company's Risk profile, among others by providing recommendations or proposals regarding Risk Management implementation;
establishing an organizational structure including clear authority and responsibilities at each job level related to Risk Management implementation;
being responsible for the implementation of Risk Management policies, strategies, and frameworks approved by the Board of Commissioners and evaluating and providing directions based on reports submitted;
ensuring that all material Risks and their impacts have been followed up and submitting accountability reports to the Board of Commissioners periodically. The aforementioned reports include progress reports and issues related to material Risks accompanied by improvement steps that have been, are being, and will be taken;
ensuring the implementation of improvement steps for problems or deviations in the Company's business activities found by the work unit performing the internal audit function;
developing a Risk Management culture including Risk awareness at all organizational levels, including among others
adequate communication to all levels of the organization regarding the importance of effective internal controls;
11) ensuring sufficient financial support and infrastructure to manage and control Risks;
12) ensuring that the Risk Management function has been implemented independently as reflected among others by:
a) separation of functions between work units performing the Risk Management function which performs risk identification, measurement, monitoring and control from work units performing the internal control function; and b) application of Risk Management free from conflicts of interest between work units; and
13) ensuring that all policies, regulations, systems, and procedures, as well as business activities carried out by the Company are in accordance with applicable legislation.
B. Sufficiency of Policies, Procedures, and Limit Setting Effective implementation of Risk Management must be supported by a framework encompassing Risk Management policies and procedures as well as clearly established Risk limits in line with the Company's vision, mission, and business strategy. The formulation of such Risk Management policies and procedures is carried out taking into account among other things the type, complexity of business activities, Risk profile, and level of Risk to be taken, as well as regulations set by authorities and/or healthy Company practices.
In the Risk Management framework, the Company must also include feedback loops based on accurate and quality information, management and objective assessment processes, which enable the taking of necessary actions at the right time to respond to changes in the Risk profile. This is necessary to ensure that decisions made by the Board of Directors and Board of Commissioners are implemented and the impact of such decisions is monitored and reported in a timely and sufficiently frequent manner through good management information. Feedback loops are needed to keep the Company's Risk Management framework relevant to changing conditions with the aim of helping the Company meet strategic and Risk management objectives. In addition, the implementation of the Company's Risk Management policies and procedures must be supported by adequate capital and quality HR.
In order to effectively control Risks, the policies and procedures owned by the Company must be based on Risk Management strategy and supplemented with Risk tolerance and Risk limits. The setting of Risk tolerance and Risk limits is carried out taking into account the level of Risk to be taken (risk appetite), Risk tolerance (risk tolerance), and the Company's overall strategy.
In the event that the Company is part of a financial conglomerate, policies, procedures, and risk limit setting also cover Risks arising from the interconnection between members of such financial conglomerate.
Matters to be considered in establishing the Risk Management framework including policies, procedures, and limits are as follows:
taken (risk appetite) and the Company's Risk tolerance (risk tolerance). d. The level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) must be considered in the formulation of Risk Management policies, including in limit setting. e. In setting Risk tolerance (risk tolerance), the Company needs to consider the Company's business strategy and objectives as well as the Company's ability to take Risks (risk bearing capacity).
Formulation of business continuity plans meets among other things the following:
b) flexible to respond to various unexpected and specific disturbance scenarios, i.e., description of certain conditions and actions required immediately; c) periodic testing and evaluation of business continuity plans; and d) The Board of Directors must test, review, and update business continuity plans periodically to ensure the effectiveness of the business continuity plans prepared. f. Risk Management policies and procedures are adequately documented and communicated to all employees. g. Risk Management policy must be relevant to the types of Risks determined, both Risks related to business strategy and those related to the Company's daily operations. h. Risk Management policy must elaborate the relationship between the Company's tolerance limits, regulations regarding capitalization, and Risk monitoring methods.
C. Sufficiency of Risk Identification, Measurement, Monitoring, and Control Processes
Risk identification, measurement, monitoring, and control are main parts of the Risk Management implementation process. Risk identification is proactive, covers all Company business activities, and is carried out in order to analyze sources and the likelihood of Risks arising and their impact. Subsequently, the Company needs to measure Risks in accordance with the characteristics and complexity of business activities. In monitoring the results of Risk measurement, the Company can establish independent work units from the party conducting the transaction to monitor the level and trends and analyze the direction of Risks. In addition, the effectiveness of Risk Management implementation needs to be supported by Risk control considering the results of Risk measurement and monitoring.
In the event that the Company is part of a financial conglomerate, risk identification, measurement, monitoring, and control also cover risks arising from the interconnection between members of such financial conglomerate. Matters to be considered in the implementation of the identification, measurement, monitoring, and control processes include among other things as follows:
Risk Identification
a. The Company identifies all Risks periodically. b. The Company has methods or systems to identify Risks in all Company business activities.
c. The Risk identification process is carried out by analyzing all Risk sources at least conducted against Risks from Company activities and ensuring that Risks from new activities have gone through a proper Risk Management process before being introduced or run.
d. The Risk identification process is carried out taking into account factors affecting Risks including additional Risks originating from group members.
Risk Measurement
a. Risk measurement systems are used to measure the Company's Risk exposure as a reference for carrying out control. Risk measurement is carried out periodically for both business lines and all Company business activities. b. Selection of measurement methods is adjusted to the characteristics and complexity of business activities.
c. Risk measurement systems must be evaluated and improved periodically or whenever necessary to ensure consistency of assumptions, accuracy, fairness, and data integrity, as well as procedures used to measure Risks.
d. The Risk measurement process must clearly contain validation processes, validation frequency, data and information documentation requirements, and evaluation requirements for assumptions used, before a model is applied by the Company. e. Stress tests are conducted to complement the Risk measurement system by estimating the Company's potential losses under abnormal market conditions using specific scenarios to see the sensitivity of the Company's performance to changes in Risk factors and identify influences that have a significant impact on the Company's portfolio. f. The Company needs to conduct stress testing periodically and review the results of such stress testing and take appropriate steps if estimated future conditions exceed acceptable tolerance levels. These results are used as input during the setting or change of policies and limits. g. The Company measures Risks based on the Company's ability to assess its own Risks and the Company's capital position.
Risk Monitoring
a. The Company must have monitoring systems and procedures which among other things include monitoring of the magnitude of Risk exposure, Risk tolerance, internal limit compliance, and stress testing results as well as consistency of implementation with established policies and procedures. b. Monitoring is carried out by both operational work units and work units performing the Risk Management function.
c. Monitoring results are presented in periodic reports submitted to management in order to mitigate Risks and take necessary actions.
Risk Control
a. The Company must have control methods for Risks referring to established policies and procedures. b. The Risk control process applied by the Company must be adjusted to Risk exposure as well as the level of Risk to be taken and Risk tolerance.
c. Risk control can be carried out by the Company, among other things, by establishing short, medium, and long-term business plans, field surveys to absorb market targets, hedging mechanisms, and other Risk mitigation methods such as increasing the Company's capital to absorb potential losses.
d. The Company must have a responsive framework to changes occurring due to the types of Risks present in the Company.
D. Risk Management Information System
In order to support the process of risk identification, measurement, monitoring, and control, the Company also needs to develop an information management system adapted to the Company's characteristics, activities, and business complexity. In the event that the Company is the main entity of a financial conglomerate, the Risk Management information system also includes the information systems required for the implementation of the financial conglomerate's Risk Management. Matters that need to be considered in the implementation of the Risk Management information system include the following:
E. Comprehensive Internal Control System
The process of implementing effective Risk Management must be supported by a reliable internal control system. The effective implementation of an internal control system can help the Company in protecting its assets, ensuring the availability of reliable financial and managerial reporting, increasing the Company's compliance with applicable laws and regulations, and reducing the Risk of losses, deviations, and violations of prudential aspects. The implementation of a reliable and effective Company internal control system is the responsibility of all operational work units, supporting work units, and internal audit work units. In the event that the Company is the main entity of a financial conglomerate, the internal control system must also include a comprehensive internal control system for the implementation of the financial conglomerate's Risk Management. Matters that need to be considered in the implementation of the internal control system include the following:
II. GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT FOR EACH RISK
A. Strategic Risk
B. Operational Risk
Authority and Responsibilities of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners are responsible for developing an organizational culture aware of Operational Risk and fostering commitment to managing Operational Risk in accordance with the Company's business strategy. b) The Company's Board of Directors creates a culture of objective disclosure of Operational Risk across all organizational elements so that Operational Risk can be identified quickly and mitigated appropriately. c) The Board of Directors and Board of Commissioners are responsible for the implementation of Risk Management regarding fraud that may occur within the Company, including steps to be taken to minimize fraud within the Company. d) The Board of Directors establishes effective reward policies, including remuneration and punishment, integrated into the performance evaluation system to support optimal Risk Management implementation. e) The Board of Directors must ensure that the exercise of authority and responsibilities delegated to service providers has been carried out well and responsibly.
Human Resources (HR)
a) The Company must have an code of ethics applied to all employees at every organizational level. b) The Company must apply sanctions consistently to officials and employees proven to have committed deviations and violations.
Operational Risk Management Organization
a) The Company's business unit management or support unit management are risk owners responsible for the Risk Management process for daily Operational Risk and reporting specific Operational Risk issues within their respective units according to the applicable reporting levels. b) To facilitate the Risk Management process for Operational Risk in the Company's business units or support units and ensure consistent implementation of Operational Risk Management policies, dedicated operational risk officers may be appointed who have a dual reporting line, namely directly to the head of the Company's business unit or support unit. The responsibilities of the dedicated operational risk officer include developing specific risk indicators for the Company's business unit or support unit, determining escalation limits, and compiling Operational Risk Management reports.
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Operational Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the application of several items in each aspect of policy, procedure, and limit setting, as follows:
Risk Management Strategy
The formulation of strategy for Operational Risk refers to the general scope of implementation as referred to in item I.B.1. In addition, in formulating strategy, the Company also needs to apply the following:
a) establish a system and information to prevent the occurrence of fraud risk; b) have computer devices, information technology systems, workrooms, office equipment, and administrative systems that support the Company's activities; c) have an organizational structure that supports the Company's work pattern; d) apply adequate asset and data security principles and business continuity management; and e) consider the Company's office, for example, being in a strategic location (close to consumers) and not in an area prone to natural disasters.
Risk Appetite and Risk Tolerance
The determination of the level of Risk to be taken and Risk Tolerance for Operational Risk refers to the general scope of implementation in item I.B.2.
Policies and Procedures
a) The Company has an adequate operational system. b) The Company must establish Operational Risk Management policies that must be internalized into the Company's support activities, including Operational Risk policies that are unique according to the needs of support activities. c) The Company must have procedures that are derived from the Operational Risk Management Policy. These procedures can be:
(1) general controls, namely operational controls that are general across all support activities of the Company, for example, separation of functions or the requirement to take leave; and (2) specific controls, namely operational controls that are specific to each support activity of the Company, for example, documentation of insureds and/or service users. d) The Company has early warning procedures to handle sudden changes in information technology systems that impact the likelihood of Operational Risk occurring. e) To reduce the likelihood of Operational Risk arising from HR, the Company's Risk Management policy must at least contain policies regarding recruitment and placement according to organizational needs, competitive remuneration and incentive structures, training and development, periodic rotation, career planning and succession policies, and handling of employment termination and labor union issues. f) To reduce the likelihood of Operational Risk arising from systems and infrastructure, the Company's Risk Management policy must be supported by procedures for access to management information systems, accounting information systems, risk management systems, document room security, and data processing rooms. g) To reduce the likelihood of Operational Risk arising from external events, the Company's Risk Management policy must be supported, among others, by insurance protection for the Company's physical assets, backup systems, and occupational safety guarantees for high-risk job fields. h) For insurance brokerage companies, to reduce the likelihood of Operational Risk arising from the profile of insureds/policyholders/customers and prospective insureds/policyholders/customers, the Risk Management policy must include the obligation of the insurance brokerage company to conduct Customer Due Diligence (CDD) or Enhanced Due Diligence (EDD) periodically and consistently in accordance with the Operational Risk exposure. The implementation of CDD/EDD refers to all requirements and guidelines as regulated in applicable provisions regarding anti-money laundering and counter-terrorism financing. CDD/EDD must be supported by an effective internal control system, particularly efforts to prevent the insurance brokerage company from internal crimes (internal fraud).
Limit
The setting of limits for Operational Risk refers to the general scope of implementation as referred to in item I.B.4.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Operational Risk, in addition to implementing processes as referred to in item I.C, the Company needs to add the application of several items in each of the aforementioned processes, as follows:
Operational Risk Identification
a) The Company must conduct identification and measurement of parameters that influence Operational Risk exposure, including frequency and impact of:
(1) system failures and errors;
(2) weaknesses in information technology systems; (3) failure of customer relationships; (4) accounting errors; (5) asset calculation errors; (6) fraud; and (7) accounting manipulation. b) The Company develops a database regarding:
(1) types and impacts of losses caused by Operational Risk based on risk identification results, consisting of loss data that can be predicted or difficult to predict; (2) violations of control systems; and (3) other operational issues that may cause losses in the future. c) The Company considers various internal and external factors in conducting Operational Risk identification and measurement, including:
(1) the Company's organizational structure, risk culture, HR management, organizational changes, and employee turnover; (2) the Company's policyholder characteristics, products and activities, as well as business activity complexity and transaction volume; (3) the design and implementation of systems and processes used; and (4) the external environment, industry trends, market structure, including social and political conditions. d) For Companies that have not developed special methods for Operational Risk identification and measurement, the main source of Operational Risk information is audit findings (internal or external) related to Operational Risk.
Operational Risk Measurement
In measuring Operational Risk, among others, indicators/parameters such as size and organizational structure, HR, new business development, and use of third-party services can be used.
Operational Risk Monitoring
a) The Company must conduct continuous monitoring of Operational Risk across all Operational Risk exposures and losses that can be caused by the Company's main activities, among others, by implementing an internal control system and providing periodic reports on losses caused by Operational Risk. b) The Company must periodically review the causes of Operational Risk and the impact of its losses.
Operational Risk Control
a) Risk control is carried out consistently in accordance with the Risk Appetite, results of Operational Risk identification and measurement. b) In the implementation of Operational Risk control, the Company can develop programs to mitigate Operational Risk, among others, securing information technology processes, and outsourcing some of the Company's operational activities. c) In the event the Company develops information technology process security, the Company must ensure the security level of electronic data processing. d) Control of information systems must ensure:
(1) periodic assessment of information system security, accompanied by corrective actions if necessary; (2) availability of backup procedures and emergency plans to ensure the Company's operational activities run smoothly and prevent significant disruptions, which are tested periodically; (3) submission of information to the Board of Directors regarding issues in paragraphs (1) and (2); and (4) availability of storage for information and documents related to analysis, programming, and execution of data processing. e) The Company must have a support system, which at least covers:
(1) early error identification;
(2) efficient, accurate, and timely processing and settlement of all transactions; and (3) confidentiality, truthfulness, and transaction security. f) The Company must periodically review procedures, documentation, data processing systems, contingency plans, and other operational practices to reduce the likelihood of human error. g) The Company must have adequate policies and procedures, good Company administrative activities, good information technology system and technology management, good fraud and legal issue prevention, good HR management, and good third-party service provider management. h) Employee recruitment can be carried out by external parties such as independent HR consultants and is conducted based on employee needs analysis. i) The Company provides training and mentoring to all Company employees.
d. Operational Risk Management Information System In implementing Risk Management for Operational Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to apply the following:
e. Comprehensive Internal Control System
In implementing Risk Management for Operational Risk, in addition to implementing internal controls as referred to in item I.E, the Company needs to have a routine rotation system to avoid potential self-dealing, collusion, or concealment of documentation or transactions that are not normal.
C. Governance Risk
Definition
a. Governance Risk is the risk of the Company's failure to achieve the Company's objectives due to the Company's failure to maintain the best composition of managers who have high competence and integrity. The term "managers" in Governance Risk includes the Board of Directors and Board of Commissioners. b. Sources of Governance Risk include, among others, inadequate appointment and dismissal of the Board of Directors and Board of Commissioners, insufficient and inappropriate composition and proportion of the Board of Directors and Board of Commissioners relative to the Company's needs, inadequate competence and integrity of the Board of Directors and Board of Commissioners that do not support their duties and authorities, and poor leadership of the Board of Directors and Board of Commissioners.
c. Governance Risk can increase, among others, due to the unavailability of an adequate remuneration system for the Board of Directors and Board of Commissioners.
Objective
The main objective of Risk Management for Governance Risk is to ensure that the Company maintains the best composition of the Board of Directors and Board of Commissioners who have high competence and integrity so that the Company can achieve its objectives.
Implementation of Risk Management
The implementation of Risk Management for Governance Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Governance Risk, in addition to implementing active supervision as referred to in item I.A, the Company needs to add the application of several items in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibilities of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Governance Risk is carried out in an integrated manner with other Risk Management that can impact the Company's Governance Risk profile. b) The Board of Directors and Board of Commissioners must ensure that the Company has an adequate internal selection system that is applied continuously/consistently. c) The Board of Directors and Board of Commissioners must inform and remind shareholders regarding provisions related to the appointment and dismissal of the Board of Directors and Board of Commissioners when holding the General Meeting of Shareholders (GMS). d) The Board of Directors must ensure that the implementation of Risk Management is carried out effectively in the implementation of aspects related to Governance Risk, such as selection, appointment of the Board of Directors and Board of Commissioners, and others.
Human Resources (HR)
Adequacy of HR for Governance Risk refers to the general scope of implementation as referred to in item I.A.2.
Governance Risk Management Organization
In the implementation of Risk Management for Governance Risk, the Company has an organ that supports the Company's business activities by considering, among others:
a) clarity of duties and responsibilities of the Board of Directors and Board of Commissioners based on competence and expertise possessed, so that the Board of Directors and Board of Commissioners are adaptive to changing market needs; and b) methods to ensure that the Board of Directors and Board of Commissioners appointed by the controller do not have conflicts of interest with the Company's business activities. In addition, the Company can also form a special unit responsible for assessing the leadership, competence, and integrity of the Board of Directors and Board of Commissioners.
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Governance Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the application of several items in each aspect of policy, procedure, and limit setting, as follows:
Risk Management Strategy
a) Risk Management Strategy for Governance Risk covers all risk causes, including appointment and dismissal, and leadership of the Board of Directors and Board of Commissioners. b) Risk Management Strategy for Governance Risk has the ability to minimize the likelihood of Governance Risk emerging, for example, by conducting background checks on prospective Directors/Commissioners.
Risk Appetite and Risk Tolerance
The determination of the level of Risk to be taken and Risk Tolerance for Governance Risk refers to the general scope of implementation as referred to in item I.B.2.
Policies and Procedures
a) The Company must have written policies and procedures containing provisions regarding competence and capability as Directors in order to achieve the Company's objectives. b) The Company can form a special unit to handle unexpected incidents due to sudden changes in the number and composition of the Board of Directors and Board of Commissioners. c) The Company must have specific standards and criteria in submitting names of prospective Directors/Commissioners to shareholders. d) The Company must have specific standards and criteria in the selection of prospective Directors/Commissioners conducted by shareholders. e) The Company must have procedures regarding documents for the appointment of Directors/Commissioners that comply with applicable regulations/laws.
Limit
a) Governance Risk limits are generally not limits that can be quantified financially. b) The Company needs to apply Risk Tolerance for Governance Risk. c) Limits for Governance Risk are used to reduce Risks arising, including due to the minimum number of the Company's Directors/Commissioners.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Governance Risk, in addition to implementing processes as referred to in item I.C, the Company needs to add the application of several items in each of the aforementioned processes, as follows:
Governance Risk Identification
a) The Company must record and document every event related to Governance Risk, for example, the number of the composition of the Board of Directors, meetings attended by the Board of Directors/Board of Commissioners, and meeting minutes involving the Board of Directors/Board of Commissioners. b) The Company assesses the procedures and legality of documents related to the appointment and dismissal of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring. c) The Company uses the results of suitability and probity tests, work experience, education and training, and the behavior of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring. d) The Company can use several information sources to identify Governance Risk, including media reporting and information obtained from authorities regarding the background/characteristics of prospective Directors/Commissioners.
Governance Risk Measurement
In measuring Governance Risk, among others, indicators/parameters such as the establishment of procedures and legality of documents related to the appointment and dismissal of the Board of Directors/Board of Commissioners, ownership of composition and proportion of the Board of Directors/Board of Commissioners in accordance with applicable regulations, and the establishment of criteria for good competence and integrity for the Board of Directors/Board of Commissioners can be used.
Governance Risk Monitoring
a) The Company monitors the legality of documentation for the appointment and dismissal of the Board of Directors/Board of Commissioners through a specific unit, for example, the Risk Management unit. b) In monitoring data, number, and composition of the Board of Directors and Board of Commissioners, the Company develops an electronic system to monitor all data of the Board of Directors and Board of Commissioners. c) The Company can cooperate with third parties to monitor the leadership, competence, and integrity of the Board of Directors/Board of Commissioners.
Governance Risk Control
a) The Company must immediately follow up and address reports that the Company's Directors/Commissioners have taken actions contrary to applicable regulations. b) The Company develops guidelines regarding criteria for prospective Directors/Commissioners, guidelines regarding the process of appointment, replacement, and dismissal of the Board of Directors/Board of Commissioners. c) Governance Risk mitigation or events causing Governance Risk are carried out by considering the materiality of the issues and costs. d) In order to control greater Governance Risk in the future, preventive and remedial actions taken for Governance Risk must be followed by improvements to control weaknesses and procedures that trigger the occurrence of Governance Risk. e) The Board of Directors/Board of Commissioners receive periodic education to improve the competence and capability of the Board of Directors/Board of Commissioners.
d. Governance Risk Management Information System In implementing Risk Management for Governance Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to apply the following:
The Company has a system that shows a complete profile of the Board of Directors/Board of Commissioners.
The Company has regular procedures and a reporting mechanism for Governance Risk/incidents causing Governance Risk, both in writing and through electronic systems.
The Company has an early warning system mechanism to provide signals to management so that the necessary response and mitigation can be carried out.
The Company has a management information system that records the steps of Management Risk mitigation.
e. Comprehensive Internal Control System
In implementing Risk Management for Managerial Risk, in addition to implementing internal controls as referred to in item I.E, the Company also needs to implement the following:
D. Governance Risk
Definition
a. Governance Risk is the potential failure in the implementation of good governance, the inappropriateness of management style, the control environment, and the behavior of every party involved directly or indirectly with the Company. b. Sources of Governance Risk include inadequate governance guidelines owned by the Company, the Company not applying good governance principles, and the Company not applying Risk Management adequately.
c. Governance Risk can increase, among others, due to intervention from other parties resulting in the failure of the implementation of good governance.
Objective
The main objective of Risk Management for Governance Risk is to minimize the risk of the non-implementation of good governance in the Company.
Implementation of Risk Management
The implementation of Risk Management for Governance Risk for the Company at least covers:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Governance Risk, in addition to implementing active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Established in Jakarta on 14 April 2016
EXECUTIVE HEAD OF SUPERVISOR OF INSURANCE, PENSION FUNDS, FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS FINANCIAL SERVICES AUTHORITY, signature FIRDAUS DJAELANI Copy in accordance with the original Legal Director 1 Legal Department signature Yuliana
APPENDIX IV
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.05/2016 CONCERNING GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT AND SELF-ASSESSMENT REPORT ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
To
Yth. Financial Services Authority u.p. Directorate of Non-Bank Financial Service Support Services Menara Merdeka Building, 20th Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
SELF-ASSESSMENT REPORT
ON THE IMPLEMENTATION OF RISK MANAGEMENT OF INSURANCE BROKERAGE COMPANY, REINSURANCE BROKERAGE COMPANY, OR INSURANCE LOSS ASSESSOR COMPANY *) YEAR … PT XYZ (Company Address) *) strike out what is not necessary
SELF-ASSESSMENT REPORT
ON THE IMPLEMENTATION OF RISK MANAGEMENT OF INSURANCE BROKERAGE COMPANY, REINSURANCE BROKERAGE COMPANY, OR INSURANCE LOSS ASSESSOR COMPANY *) Company Name :
Business Type : (1) Insurance Broker (2) Reinsurance Broker (3) Insurance Loss Assessor Assessment Date :
Report Position Date :
A. GENERAL INFORMATION
Shareholders or equivalent :
No. Name Ownership Value
(In Rupiah)
Ownership Percentage
1.
2. etc.
Board of Directors:
No. Name Position Term of Office
1.
2.
3. etc.
Board of Commissioners:
No. Name Position Term of Office
1.
2.
3. etc.
B. COMPANY FINANCIAL INFORMATION
Description Value (Rupiah)*
Assets
Own Capital
Investments
Premium Receivables
Premium Payables
Commission Payables
Other Payables
Intermediation Service Revenue
Retained Premium Ratio (%)
Total Insured/Service Users
C. SUMMARY OF GENERAL RISK MANAGEMENT IMPLEMENTATION
D. IMPLEMENTATION OF RISK MANAGEMENT FOR EACH TYPE OF RISK
APPENDIX V
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.05/2016 CONCERNING GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT AND SELF-ASSESSMENT REPORT ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT
PENSION FUND
As regulated in Article 2 of Financial Services Authority Regulation Number 1/POJK.05/2015 concerning the Implementation of Risk Management for Non-Bank Financial Service Institutions which is hereinafter referred to as LJKNB, LJKNB is required to implement Risk Management effectively, which at least covers:
A. active supervision by the Board of Directors and Board of Commissioners; B. adequacy of policies, procedures, and risk limits;
C. adequacy of risk identification, measurement, monitoring, and control processes;
D. Risk Management information system; and
E. comprehensive internal control system.
Risk Management principles are described as follows:
A. Active Supervision by the Board of Directors and Board of Commissioners The Board of Directors and Board of Commissioners are responsible for the effectiveness of the implementation of Risk Management in the Pension Fund. Therefore, the Board of Directors and Board of Commissioners must:
then the Board of Directors sets the aforementioned Risk Management policies, strategies, and framework;
2) formulate, establish, and update procedures and tools for identifying, measuring, monitoring, and controlling Risk;
3) formulate and establish transaction approval mechanisms, including those exceeding limits and authority for each job level;
4) evaluate and/or update the policies, strategies, and Risk Management framework at least once a year or at a higher frequency if there are significant changes in factors affecting the Pension Fund's business activities, Risk exposure, and/or Risk profile;
5) have adequate understanding of the Risks inherent in all Pension Fund business activities and be able to take necessary actions according to the Pension Fund's Risk profile, including by providing recommendations or proposals regarding the implementation of Risk Management to each work unit in the Pension Fund;
6) establish an organizational structure including clear authority and responsibilities at each job level related to the implementation of Risk Management;
7) be responsible for the implementation of the Risk Management policies, strategies, and framework approved by the Board of Commissioners, and evaluate and provide guidance based on reports submitted by work units performing Risk Management functions, including reports on the Risk profile;
8) ensure that all material Risks and the impacts thereof have been followed up on and submit accountability reports to the Board of Commissioners periodically. The aforementioned reports include, among others, reports on developments and issues related to material Risks accompanied by improvement steps that have been, are being, and will be taken;
9) ensure the implementation of improvement steps for issues or deviations in the Pension Fund's business activities found by the work unit performing the internal audit function;
10) develop a Risk Management culture, including Risk awareness at all levels of the organization, including adequate communication to all levels of the organization regarding the importance of effective internal control;
11) ensure adequate financial support and infrastructure for managing and controlling Risk;
12) ensure that the Risk Management function has been implemented independently, reflected by, among others:
a) separation of functions between work units performing Risk Management functions (identifying, measuring, monitoring, and controlling Risk) and work units performing the internal control function; and b) implementation of Risk Management free from conflicts of interest between work units.
13) ensure that all policies, regulations, systems, and procedures, as well as business activities conducted by the Pension Fund, comply with applicable legislation.
Human Resources (HR)
In carrying out the responsibilities for implementing Risk Management related to HR, the Board of Directors must:
a. establish clear HR qualifications for each job level related to the implementation of Risk Management; b. ensure the adequacy of the quantity and quality of existing HR in the pension fund and ensure that the aforementioned HR understands their tasks and responsibilities, both for main work units, work units performing Risk Management functions, and supporting work units responsible for implementing Risk Management;
c. develop employee recruitment, development, and training systems, including managerial succession plans and adequate remuneration to ensure the availability of competent employees in the field of Risk Management;
d. ensure the improvement of competence and integrity of leaders, personnel of the Pension Fund's main work units, work units performing Risk Management functions, and work units performing internal audit functions, by considering factors such as adequate knowledge, experience/track record, and abilities in the field of Risk Management through continuous education and training programs, to guarantee the effectiveness of the Risk Management process; e. place competent officials and staff in each work unit according to the nature, volume, and complexity of the Pension Fund's business activities; f. ensure that officials and staff placed in each work unit as referred to in letter c have:
Risk Management Organization
In order to implement effective Risk Management, the Pension Fund's Board of Directors establishes an organizational structure by considering the following:
a. The organizational structure formulated must be accompanied by clarity of general tasks and responsibilities as well as related to the implementation of Risk Management in all work units, adjusted to the business objectives and policies, size, and complexity of the Pension Fund's business activities. b. The organizational structure must be designed to ensure that work units performing internal control functions and work units performing Risk Management functions are independent from the Pension Fund's main work units.
c. The organizational structure should be designed so that work units performing Risk Management functions have direct access and reporting to the Board of Directors and Board of Commissioners, usually for matters such as:
B. Adequacy of Policies, Procedures, and Limit Setting The implementation of effective Risk Management must be supported by a framework covering Risk Management policies and procedures as well as clearly established Risk limits in line with the Pension Fund's vision, mission, and strategy. The formulation of Risk Management policies and procedures is carried out by considering, among others, the type, complexity of business activities, Risk profile, and level of Risk to be taken, as well as regulations set by authorities and/or healthy Pension Fund practices. In addition, the implementation of the Risk Management policies and procedures owned by the Pension Fund must be supported by adequate funding and HR quality.
In order to control Risk effectively, the policies and procedures owned by the Pension Fund must be based on Risk Management strategy and supplemented with Risk tolerance and Risk limits. The establishment of Risk tolerance and Risk limits is carried out by considering the level of Risk to be taken (risk appetite), Risk tolerance (risk tolerance), and the Pension Fund's overall strategy.
Matters that need to be considered in establishing the Risk Management framework, including policies, procedures, and limits, include the following:
Risk Management Strategy
a. Pension Funds formulate Risk Management strategy in accordance with the Pension Fund's overall business strategy by considering the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance). b. Risk Management strategy is formulated to ensure that the Pension Fund's Risk exposure is managed in a controlled manner in accordance with the Pension Fund's internal policies and procedures and legislation.
c. Risk Management strategy is formulated based on the following general principles:
Level of Risk to be Taken (Risk Appetite) and Risk Tolerance (Risk Tolerance)
a. The level of Risk to be taken (risk appetite) is the level and type of Risk willing to be taken by the Pension Fund in order to achieve Pension Fund objectives. The level of Risk to be taken is reflected in the Pension Fund's business strategy and objectives. b. Risk tolerance (risk tolerance) is the maximum level and type of Risk established by the Pension Fund. Risk tolerance (risk tolerance) is an elaboration of the level of Risk to be taken (risk appetite). [Note: Text segment 'diambil (risk appetite) dan toleransi Risiko (risk tolerance) Dana' appears to be a continuation or fragment from previous sentence in source, integrated contextually above] d. The level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) must be considered in the formulation of Risk Management policies, including in limit setting. e. In establishing Risk tolerance (risk tolerance), the Pension Fund needs to consider the Pension Fund's business strategy and objectives as well as the Pension Fund's ability to take Risk (risk bearing capacity).
Policies and Procedures
a. Risk Management policy is written guidance in implementing Risk Management and must be in line with the Pension Fund's vision, mission, and business strategy, and in its formulation must be coordinated with relevant functions or work units. b. Policies and procedures must be designed and implemented by considering the characteristics and complexity of business activities, the level of Risk to be taken and Risk tolerance, Risk profile, and regulations set by authorities and/or healthy Pension Fund practices.
c. Pension Funds must have procedures and processes to implement Risk Management policies. Such procedures and processes are formulated in implementation guidelines that must be reviewed and updated periodically to accommodate changes that occur.
d. Risk Management policies must at least contain:
Limits
a. Pension Funds must have Risk limits that are in accordance with the level of Risk to be taken (risk appetite), Risk tolerance (risk tolerance), and the Pension Fund's overall strategy by considering the Pension Fund's funding capacity to absorb Risk exposure or losses arising, past loss experience, HR capability, and compliance with applicable external regulations. b. Procedures and establishment of Risk limits must at least cover:
C. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
Risk identification, measurement, monitoring, and control are main parts of the Risk Management implementation process. Risk identification is proactive, covers all Pension Fund activities, and is carried out to analyze the sources and likelihood of Risk occurrence and its impact. Furthermore, Pension Funds need to perform Risk measurement in accordance with the characteristics and complexity of the Pension Fund. In monitoring the results of Risk measurement, the Pension Fund can establish an independent work unit from the party conducting transactions to monitor the level and trends and analyze the direction of Risk. In addition, the effectiveness of Risk Management implementation needs to be supported by Risk control by considering the results of Risk measurement and monitoring.
Matters that need to be considered in carrying out the identification, measurement, monitoring, and control processes include the following:
Risk Identification
a. Pension Funds identify all Risks periodically. b. Pension Funds have methods or systems to identify Risk in all Pension Fund products and activities.
c. The Risk identification process is carried out by analyzing all Risk sources, at least conducted against Risks from Pension Fund products and activities, and ensuring that Risks from new products and activities have gone through an adequate Risk Management process before being introduced or run.
d. Factors affecting Risk and funding include, among others, Pension Fund characteristics, type of Pension Fund, operations, strategy, liquidity risk, and type of Pension Fund.
Risk Measurement
a. Risk measurement systems are used to measure Pension Fund Risk exposure as a reference for carrying out control. Risk measurement is carried out periodically for both products and all business activities of the Pension Fund. b. The system must at least be able to measure:
Risk Monitoring
a. Pension Funds must have monitoring systems and procedures that include, among others, monitoring of the magnitude of Risk exposure, Risk tolerance, internal limit compliance, and stress testing results as well as consistency of implementation with established policies and procedures. b. Monitoring is carried out by both operational work units and work units performing Risk Management functions.
c. Monitoring results are presented in periodic reports submitted to management for Risk mitigation and necessary actions.
Risk Control
a. Pension Funds must have risk control methods by referring to established policies and procedures. b. The risk control process implemented by Pension Funds must be adjusted to the risk exposure, the level of risk to be taken, and risk tolerance.
c. Risk control can be carried out by Pension Funds, including through hedging mechanisms and other risk mitigation methods to absorb potential losses.
d. Pension Funds must have a framework that is responsive to changes occurring due to the types of risks present in the Pension Fund.
D. Risk Management Information System
In order to support the process of risk identification, measurement, monitoring, and control, Pension Funds also need to develop a management information system that is adjusted to the characteristics, activities, and complexity of the Pension Fund.
Matters that need to be considered in the implementation of the Risk Management Information System are as follows:
E. Comprehensive Internal Control System
The implementation of effective Risk Management must be supplemented by a reliable internal control system. The effective implementation of an internal control system can help Pension Funds in preserving their assets, ensuring the availability of trustworthy financial and managerial reporting, increasing the Pension Fund's compliance with applicable laws and regulations, and reducing the risk of losses, deviations, and violations of prudential aspects. The implementation of a reliable and effective Pension Fund internal control system is the responsibility of all operational work units, support work units, and internal audit work units.
Matters that need to be considered in the implementation of the internal control system are as follows:
II. Guidelines for Risk Management Implementation for Each Risk
A. Strategic Risk
Definition
a. Strategic Risk is the potential failure of the Pension Fund to realize obligations to participants due to the unsuitability or failure in planning, setting, and implementing strategy, making appropriate business decisions, and/or the Pension Fund's lack of responsiveness to external changes. b. Strategic Risk stems from the strategy owned and run by the Pension Fund being inconsistent with its environmental conditions, and/or the Pension Fund's implemented policies being inconsistent with the Pension Fund's strategic position.
c. Strategic Risk can increase, among other things, due to unstable political conditions, high inflation, and security stability.
Objective
The main objective of Risk Management for Strategic Risk is to minimize the possibility of Strategic Risk occurring that impacts the Pension Fund's business activities.
Risk Management Implementation
The implementation of Risk Management for Strategic Risk for Pension Funds must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management for Strategic Risk, besides carrying out active supervision as referred to in item I.A, Pension Funds need to add the implementation of several matters in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibility of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Strategic Risk is carried out in an integrated manner with other Risk Managements that can impact the Pension Fund's Strategic Risk profile. b) The Board of Directors and Board of Commissioners must formulate and approve strategic plans and business plans and communicate them to officials and/or employees of the Pension Fund at every organizational level. c) The Board of Directors must ensure that any strategic problems that arise can be resolved effectively by the relevant work units and monitoring of corrective actions by the strategic policy work unit is conducted. d) The Board of Directors must be actively involved in the formulation of marketing plans (specifically for DPLK). e) The Board of Directors must monitor internal conditions (weaknesses and strengths of the Pension Fund) and the development of external factors/conditions that directly or indirectly affect the Pension Fund's strategy. f) The Board of Directors must ensure that the Pension Fund does not experience difficulties in fulfilling its obligations to participants, pensioners, and entitled parties. g) The Board of Directors provides clear guidance regarding the level of risk to be taken and the risk tolerance acceptable to the Pension Fund.
Human Resources (HR)
The adequacy of HR for Strategic Risk refers to the scope of implementation in general as referred to in item I.A.2.
Strategic Risk Management Organization
a) All main work units of the Pension Fund and support work units are responsible for assisting the Board of Directors in formulating strategic planning and implementing strategies effectively. b) Pension Funds must have a Risk Management function for Strategic Risk that monitors the development and implementation of strategies so that the possibility of Strategic Risk arising can be minimized. c) The Director overseeing the Risk Management function for Strategic Risk leads the change programs required in order to implement the established strategies.
b. Adequacy of Policies, Procedures, and Limit Establishment In implementing policies, procedures, and limit establishment for Strategic Risk, besides implementing policies, procedures, and limit establishment as referred to in item I.B, Pension Funds need to add the implementation of several matters in each aspect of policies, procedures, and limit establishment, as follows:
Risk Management Strategy
a) In formulating strategy, the Pension Fund evaluates its competitive position in the industry. In this regard, the Pension Fund needs to:
(1) understand the environmental, economic, and industry conditions of the Pension Fund where it operates, including how environmental changes impact business, products, technology, and office networks; (2) measure the strengths and weaknesses of the Pension Fund related to competitive position, the Pension Fund's business position in the financial industry, financial performance, organizational structure, and Risk Management, infrastructure for current and future business needs, managerial capability, and the availability and limitations of the Pension Fund's resources; (3) analyze all available strategy alternatives so that they align with the scale and complexity of the Pension Fund. b) Pension Funds must establish strategic plans and the impact of such strategies on the Pension Fund's business activities and implement these policies. c) Strategic plans and strategy implementation are evaluated periodically to determine the effectiveness of the strategy. d) If the Pension Fund plans to implement long-term and sustainable strategies, the Pension Fund has adequate managerial succession plans to support the effective implementation of strategies sustainably. e) Pension Funds have adequate funding to support strategic plans.
Risk Appetite and Risk Tolerance
The establishment of risk appetite and risk tolerance for Strategic Risk refers to the scope of implementation in general as referred to in item I.B.2.
Policies and Procedures
a) Pension Funds must have adequate planning, setting, and implementation work plans for strategies. b) Pension Funds must have adequate procedures to identify and respond to changes in the business environment. c) Pension Funds must have procedures to measure the progress achieved from the realization of business plans and performance according to the established schedule.
Limits
Strategic Risk limits generally relate to boundaries of deviation from established strategic plans, such as budget deviation limits and target completion time deviation limits.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management through the processes of risk identification, measurement, monitoring, and control for Strategic Risk, besides implementing processes as referred to in item I.C, Pension Funds need to add the implementation of several matters in each of the aforementioned processes, as follows:
Strategic Risk Identification
a) Pension Funds must identify and document deviations or discrepancies as a result of the non-realization or ineffective implementation of established business strategies or business plans, especially those having a significant impact on pension products/types of programs. b) Pension Funds must conduct risk analysis, especially regarding strategies that require many resources and/or are high-risk, such as entering new market shares, offering new pension products/types of programs, or attracting new participants.
Strategic Risk Measurement
a) In measuring Strategic Risk, among other things, indicators/parameters such as the alignment of strategy with business environmental conditions, the Pension Fund's strategic position, the strategy formulation and setting process, and strategy implementation can be used. b) Pension Funds can conduct stress tests on strategy implementation in order to (i) identify any events or business environmental changes that can negatively impact the fulfillment of initial assumptions from strategic plans and (ii) measure the potential negative impact of such events on the Pension Fund's business performance, both financially and non-financially. c) Stress testing results must provide feedback to the strategic planning process. d) If stress testing results produce a risk level higher than the Pension Fund's ability to absorb the risk in question (risk tolerance), then the Pension Fund develops strategies to mitigate the risk in question.
Strategic Risk Monitoring
a) Pension Funds must have a process to monitor and control the periodic development of strategy implementation. Monitoring is conducted, among other things, by paying attention to past loss experiences caused by Strategic Risk or deviations in the implementation of strategic plans. b) Strategic issues arising from operational and business environmental changes that have a negative impact on the Pension Fund's business conditions or financial conditions are reported to the Board of Directors in a timely manner, accompanied by an impact analysis on Strategic Risk and necessary corrective actions. c) The Pension Fund, through the Board of Directors, conducts internal and external monitoring of Strategic Risk, such as weaknesses and strengths of the Pension Fund and the development of factors or external conditions that directly or indirectly affect it.
Strategic Risk Control
Pension Funds must have systems and controls to monitor strategy implementation, business decision-making, and the Pension Fund's response to external changes to ensure that taken risks remain within tolerance limits and to report significant deviations or discrepancies to the Board of Directors. Such Risk Control systems must be approved and reviewed periodically by the Board of Directors to ensure their continuous suitability. Pension Funds must have a good strategy formulation and setting process and have a good monitoring section for the implementation of the Pension Fund's strategic plan so as to ensure the conditions after the implementation of such strategies against the Pension Fund's business activities.
d. Strategic Risk Management Information System In implementing Risk Management for Strategic Risk, besides implementing the management information system as referred to in item I.D, Pension Funds also need to implement the following matters:
e. Comprehensive Internal Control System
The adequacy of the internal control system in the implementation of Risk Management for Strategic Risk refers to the scope of implementation in general in item I.E.
B. Operational Risk
Definition
a. Operational Risk is the potential failure of the Pension Fund to realize obligations to participants, pensioners, and entitled parties as a result of the unsuitability or failure of internal processes, human resources, information technology systems, and/or the occurrence of events originating from outside the Pension Fund's environment. b. Sources of Operational Risk are organizational structure, HR, volume and workload owned, high level of Pension Fund complexity, inadequate information systems and technology, Pension Fund fraud and legal problems, and disruptions to the Pension Fund's business.
c. Operational Risk can increase, among other things, due to hacker attacks on the Pension Fund's technology systems and the sudden resignation of key personnel (key person), resulting in the organization not functioning.
Objective
The main objective of Risk Management for Operational Risk is to minimize the possibility of negative impacts arising from the unsuitability or failure of internal processes, human resources, information technology systems, and/or the occurrence of events originating from outside the Pension Fund's environment, thereby causing company failure in realizing obligations to participants.
Risk Management Implementation
The implementation of Risk Management for Operational Risk for Pension Funds must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management, besides carrying out active supervision as referred to in item I.A, Pension Funds need to add the implementation of several matters in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
c) The Board of Directors establishes effective reward policies, including remuneration and punishment, integrated into the performance evaluation system to support optimal Risk Management implementation.
d) The Board of Directors must ensure that the exercise of authority and responsibilities delegated to service providers has been carried out well and responsibly.
Human Resources (HR)
a) Pension Funds must have an code of ethics enforced for all employees at every organizational level. b) Pension Funds must consistently apply sanctions to officials and employees proven to have committed deviations and violations.
Operational Risk Management Organization
a) Management of the main work units or supporting work units of the Pension Fund are risk owners responsible for the Risk Management process for daily Operational Risks, and reporting problems and Operational Risks specifically within their work units according to the applicable reporting levels. b) To facilitate the Risk Management process for Operational Risks in the main work units or supporting work units of the Pension Fund and ensure consistency in the application of Operational Risk Management policies, a dedicated operational risk officer may be appointed who has a dual reporting line, namely directly to the management of the main or supporting work units. The responsibilities of the dedicated operational risk officer include developing specific risk indicators for the main or supporting work units of the Pension Fund, determining escalation limits, and compiling Operational Risk Management reports.
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Operational Risks, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, Pension Funds need to add the application of several matters in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
The formulation of strategies for Operational Risks refers to the general scope of application as referred to in item I.B.1. In addition, in formulating strategies, Pension Funds must also apply the following matters:
a) establish a technology and information system to prevent fraud risks; b) have computer devices, information technology systems, workrooms, office equipment, and administrative systems that support Pension Fund activities; c) have a structure that supports the Pension Fund's work pattern; d) apply adequate asset and data security principles and business continuity management; and
Risk Appetite and Risk Tolerance
The determination of risk levels to be taken and risk tolerance for Operational Risks refers to the general scope of application in item I.B.2.
Policies and Procedures
a) Pension Funds have adequate operational systems. b) Pension Funds must establish Operational Risk Management policies that must be internalized into the process of all business activities and supporting activities of the Pension Fund, including Operational Risk policies that are unique according to the needs of business lines and supporting activities. c) Pension Funds must have procedures that are derivatives of Operational Risk Management Policies. These procedures can be:
(1) general controls, namely operational controls that are general to all business activities and supporting activities of the Pension Fund, such as separation of functions or the requirement to take leave; and (2) specific controls, namely operational controls that are specific to each business activity and supporting activity of the Pension Fund, such as the management of participant, pensioner, and entitled party documents. d) Pension Funds have early warning procedures to handle sudden changes in information technology systems that impact increasing the likelihood of Operational Risks. e) To reduce the likelihood of Operational Risks arising from HR, Pension Fund Operational Risk Management policies must at least contain policies on recruitment and placement according to organizational needs, competitive remuneration and incentive structures, training and development, periodic rotation, career planning and succession policies, and handling of termination of employment and labor union issues. f) To reduce the likelihood of Operational Risks arising from systems and infrastructure, Pension Fund Operational Risk Management policies must be supported by procedures for access to management information systems, accounting information systems, risk management systems, security in document rooms, and data processing rooms. g) To reduce the likelihood of Operational Risks arising from external events, Pension Fund Operational Risk Management policies must be supported, among others, by insurance protection for the Pension Fund's physical assets, backup systems, and occupational safety guarantees for specific high-risk job fields. h) For financial institution pension funds, to reduce the likelihood of Operational Risks arising from the profile of participants, pensioners, entitled parties, and prospective participants, pensioners, and entitled parties, Operational Risk Management policies must include the obligation of financial institution pension funds to conduct Customer Due Diligence (CDD) or Enhanced Due Diligence (EDD) periodically and consistently according to Operational Risk exposure. The application of CDD/EDD refers to all requirements and guidelines as regulated in applicable provisions regarding anti-money laundering and counter-terrorism financing. CDD/EDD must be supported by effective internal control systems, specifically efforts to prevent financial institution pension funds from internal crimes (internal fraud).
Limits
The setting of limits for Operational Risks refers to the general scope of application as referred to in item I.B.4.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In applying Risk Management for Operational Risks, in addition to implementing processes as referred to in item I.C, Pension Funds need to add the application of several matters in each of the aforementioned processes, as follows:
Operational Risk Identification
a) Pension Funds must conduct identification and measurement of parameters that influence Operational Risk exposure, including the frequency and impact of:
(1) system failures and errors;
(2) information technology system weaknesses;
(3) customer relationship failures;
(4) accounting errors;
(5) asset calculation errors;
(6) fraud; and
(7) accounting manipulation. b) Pension Funds develop a database regarding:
(1) types and impacts of losses caused by Operational Risks based on risk identification results, consisting of loss data that may be predictable or difficult to predict; (2) violations of control systems; and (3) other operational issues that may cause losses in the future. c) Pension Funds consider various internal and external factors in conducting identification and measurement of Operational Risks, including:
(1) Pension Fund organizational structure, risk culture, HR management, organizational changes, and employee turnover; (2) Pension Fund participant characteristics, pension program types/products and activities, as well as business activity complexity and transaction volume; (3) design and implementation of systems and processes used; and (4) external environment, industry trends, market structure including social and political conditions. d) For Pension Funds that have not yet developed special methods for identifying and measuring Operational Risks, the main source of Operational Risk information is internal audit findings related to Operational Risks.
Operational Risk Measurement
In measuring Operational Risks, among others, indicators/parameters such as organizational size and structure, HR, new business development, and the use of third-party services can be used.
Operational Risk Monitoring
a) Pension Funds must conduct continuous monitoring of Operational Risks against all Operational Risk exposures and losses that may be caused by the main activities of the Pension Fund, including by applying internal control systems and providing periodic reports on losses caused by Operational Risks. b) Pension Funds must periodically review the causes of Operational Risks and the impact of their losses.
Operational Risk Control
a) Risk controls are carried out consistently according to the risk appetite level, results of Operational Risk identification and measurement. b) In applying Operational Risk controls, Pension Funds can develop programs to mitigate Operational Risks, including securing information technology processes, and outsourcing some operational activities of the Pension Fund. c) In the event that Pension Funds develop information technology process security, Pension Funds must ensure the security level of electronic data processing. d) Controls on information systems must ensure:
(1) periodic assessment of information system security, accompanied by corrective actions if necessary; (2) the availability of backup procedures and emergency plans to ensure the operation of Pension Fund activities and prevent significant disruptions, which are tested periodically; (3) the submission of information to the Board of Directors regarding issues in paragraphs (1) and (2); and (4) the availability of storage for information and documents related to analysis, programming, and data processing implementation. e) Pension Funds must have support systems, at least covering:
(1) early error identification;
(2) efficient, accurate, and timely processing and settlement of all transactions; and (3) confidentiality, truthfulness, and transaction security. f) Pension Funds must periodically review procedures, documentation, data processing systems, contingency plans, and other operational practices to reduce the likelihood of human error. g) Pension Funds must have adequate policies and procedures, good Pension Fund administrative activities, good information technology system and technology management, good fraud and legal issue prevention, good HR management, and good third-party service provider management. h) Employee recruitment is conducted by external parties such as HR consultants and organizations that independently analyze employee needs and carry out the employee recruitment process. i) Pension Funds provide training and mentoring to all Pension Fund employees.
d. Operational Risk Management Information System In applying Risk Management for Operational Risks, in addition to implementing management information systems as referred to in item I.D, Pension Funds must also apply the following matters:
e. Comprehensive Internal Control System
In applying Risk Management for Operational Risks, in addition to implementing internal controls as referred to in item I.E, Pension Funds must have a routine rotation system to avoid potential self-dealing, collusion, or concealment of documentation or transactions that are not normal.
C. Asset and Liability Risks
Definition
a. Asset and Liability Risks are risks that occur due to potential failures in the management of Pension Fund assets and liabilities, which result in funding shortages in fulfilling obligations to participants, pensioners, and entitled parties. b. Asset and Liability Risks originate from poor asset management, poor liability management, and inadequate asset-liability matching.
Objective
The main objective of Risk Management for Asset and Liability Risks is to ensure that Pension Funds manage their assets and liabilities well so as not to cause funding shortages in fulfilling the Pension Fund's obligations to participants, pensioners, and entitled parties.
Risk Management Implementation
The implementation of Risk Management for Asset and Liability Risks for Pension Funds must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Asset and Liability Risks, in addition to implementing active supervision as referred to in item I.A, Pension Funds need to add the application of several matters in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibilities of the Board of Directors and Board of Commissioners
a) The Board of Commissioners must ensure that asset and liability management is carried out well so as not to negatively affect the Pension Fund's business activities. b) The Board of Directors must ensure that assets owned by the Pension Fund are placed in investments according to the Risk Management policies applied by the Pension Fund. c) The Board of Directors must ensure that the Pension Fund has sufficient funds to meet obligations to participants, pensioners, and entitled parties. d) The Board of Directors must ensure that the Pension Fund will not experience mismatches between assets and liabilities, for example, due to changing economic conditions. e) The Board of Directors formulates annual investment management plans.
Human Resources (HR)
The Board of Directors must ensure that each function/work unit responsible for Asset and Liability Risk management has HR with adequate competence. In addition, HR performing Pension Fund asset management functions must have adequate competence in asset management. In the event of managing complex assets, Pension Fund HR must be able to develop relevant models to mitigate Asset and Liability Risks. Such HR must also have expertise in developing and applying models to assess market conditions. Furthermore, Pension Funds are responsible for placing HR performing asset management functions in the appropriate positions and organizational structure.
Asset and Liability Risk Management Organization
Pension Funds must have adequate Asset and Liability Risk Management functions with clear authority and responsibilities for each work unit performing Asset and Liability Risk Management functions. In addition, Pension Funds must have specialized management committees handling assets and liabilities, for example, investment management committees.
b. Adequacy of Policies, Procedures, and Limit Setting.
In implementing policies, procedures, and limit setting for Asset and Liability Risks, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, Pension Funds need to add the application of several matters in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) Pension Funds conduct periodic recording and evaluation of assets and liabilities owned by the Pension Fund. b) The Board of Directors monitors the assets and liabilities owned by the Pension Fund. c) Pension Funds establish valuation strategies for investments not listed on the stock exchange. d) Pension Funds conduct diversified investments to avoid potential risks resulting from investment failures. e) Pension Funds map owned assets to identify assets that are more liquid/illiquid than liabilities. f) The Board of Directors is quick to respond to issues regarding Asset and Liability Risks.
Risk Appetite and Risk Tolerance
In implementing the determination of risk levels to be taken and risk tolerance for Asset and Liability Risks, in addition to referring to the general scope of application as referred to in item I.B.2, Pension Funds need to add several matters as follows:
a) The risk appetite statement must reflect the Pension Fund's perspective on Asset and Liability Risks. For example, the Pension Fund's statement regarding investment style, assumptions used by actuaries, and funding quality. In addition, the risk appetite statement must support the achievement of the Pension Fund's established targets or goals. b) Risk tolerance for Asset and Liability Risks must describe the Pension Fund's efforts to achieve its goals and be consistent with the established risk appetite statement, such as the percentage of the Pension Fund's asset portfolio, determining the percentage of securities to be placed, funding quality targets, and future investment return targets.
Policies and Procedures
a) Pension Funds have adequate asset management and liability management work plans. b) Pension Funds periodically report on the Pension Fund's assets and liabilities to the Board of Commissioners. c) Asset and liability management policies and procedures must at least include:
i. asset and liability composition;
ii. the level of assets maintained by the Pension Fund;
iii. investment diversification; and
iv. Asset and Liability Risk limits.
d) Risk Management in Pension Funds is supported by appropriate policies and procedures, making it more directed and comprehensive. e) Pension Funds involve third parties in monitoring and managing Pension Fund assets and Liabilities, for example, investment managers. f) In choosing investment placements in instruments not traded on the stock exchange or in well-regulated financial markets, Pension Funds conduct procedures, for example, feasibility tests. g) Pension Funds have procedures for selecting securities, for example:
i. whether there is clear documentation, approval of policies and approaches for stock selection;
ii. the expert personnel owned by the Pension Fund regarding the securities selection function; and
iii. supervision applied to ensure that securities selected for the investment portfolio are consistent with investment objectives.
h) Pension Funds conduct valuation policies for each type of investment. i) Pension Fund Operational Risk Management is reflected in explicit investment policies, which include:
i. the nature, role, and level of the Pension Fund's investment activities and how the Pension Fund meets applicable investment regulations; and
ii. Risk Management procedures consistent with the Pension Fund's investment policies, for example, the type of complex or less transparent investment placements.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In applying Risk Management for Asset and Liability Risks, in addition to implementing processes as referred to in item I.C, Pension Funds need to add the application of several matters in each of the aforementioned processes, as follows:
Asset and Liability Risk Identification
c) In order to identify Asset and Liability Risks, Pension Funds must conduct analysis of all sources of Asset and Liability Risks. Sources of Asset and Liability Risks include the management of Pension Fund assets and liabilities. d) Analysis is conducted to determine the amount of assets owned and the amount of liabilities that must be met by the Pension Fund so that there is no mismatch between assets and liabilities. e) Pension Funds must conduct analysis to determine the impact of investment risks on Asset and Liability Risks. f) Pension Funds must conduct asset valuation in the form of investments and non-investments. g) Pension Fund actuaries must conduct actuarial calculations using appropriate methods and assumptions so that the Pension Fund can meet obligations to participants, pensioners, and entitled parties.
Asset and Liability Risk Measurement
In measuring Asset and Liability Risks, Pension Funds can use indicators/parameters including asset valuation, investment objectives, the use of methods and assumptions in determining wealth for funding, mismatches between assets and liabilities in foreign currencies (currency gap), and liquidity levels.
Asset and Liability Risk Monitoring
Work units performing Asset and Liability Risk Management functions monitor and report Asset and Liability Risks to the Board of Directors, both whenever Asset and Liability Risks occur and periodically.
Asset and Liability Risk Control
a) Asset and Liability Risk controls are conducted by Pension Funds, including the Board of Directors' concern for asset and liability management objectives, monitoring of asset and liability management from an actuarial perspective, and the establishment of investment objectives. b) Pension Funds conduct periodic evaluations regarding the implementation of investment strategies that have been carried out. Matters that need
considered in the investment strategy are:
(1) investment risks and returns, including performance benchmarks; (2) asset allocation; (3) diversification; (4) liquidity and cash flow; (5) the Pension Fund's ability to meet existing or future liabilities; and (6) valuation methods and frequency; c) Pension Funds may involve third parties to conduct assessments of assets owned by the Pension Fund, whether listed or unlisted on the exchange. d) Pension Funds must have high concern from the Board of Directors or Board of Commissioners regarding asset and liability management objectives, adequate asset and liability management, effective investment risk management, and strong controls in asset valuation. d. Asset and Liability Risk Management Information System In implementing Risk Management through the execution of an information management system for Asset and Liability Risk, in addition to executing the information management system as referred to in item I.D, Pension Funds must also implement the following:
to ensure the Pension Fund's responsiveness level to deviations from generally applicable standards, regulations, and/or applicable legislation.
D. Governance Risk
b) methods to ensure that the Board of Directors and Board of Commissioners appointed by controllers have no conflicts of interest with Pension Fund activities.
Furthermore, Pension Funds may also form special work units responsible for assessing the leadership, competence, and integrity of the Board of Directors and Board of Commissioners. b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Governance Risk, in addition to executing policies, procedures, and limit setting as referred to in item I.B, Pension Funds must add the implementation of several aspects in each aspect of policies, procedures, and limit setting, as follows:
c) Pension Funds use the results of ability and propriety tests, work experience, education and training, and the behavior of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring. d) Pension Funds may use several information sources to identify Governance Risk, including media news and information obtained from authorities regarding the background/characteristics of prospective Board of Directors/Board of Commissioners.
2) Governance Risk Measurement
In measuring Governance Risk, among other things, indicators/parameters can be used such as setting procedures and legality of documents related to the appointment and dismissal of the Board of Directors/Board of Commissioners, ownership of composition and proportion of the Board of Directors and Board of Commissioners in accordance with applicable laws/regulations, and the establishment of criteria for good competence and integrity for the Board of Directors/Board of Commissioners.
3) Governance Risk Monitoring
a) Pension Funds monitor the legality of documentation for the appointment and dismissal of the Board of Directors/Board of Commissioners through specific work units, for example, Risk Management work units. b) In monitoring data, the number, and composition of the Board of Directors and Board of Commissioners, Pension Funds develop electronic systems to monitor all data of the Board of Directors and Board of Commissioners. c) Pension Funds may cooperate with third parties to monitor the leadership, competence, and integrity of the Board of Directors/Board of Commissioners.
4) Governance Risk Control
a) Pension Funds must immediately follow up and address reports that the Pension Fund's Board of Directors/Board of Commissioners have taken actions contrary to applicable regulations.
b) Pension Funds develop guidelines regarding criteria for prospective Board of Directors/Board of Commissioners, guidelines regarding the appointment, replacement, and dismissal processes of the Board of Directors and Board of Commissioners. c) Governance Risk mitigation or events causing Governance Risk are conducted by considering the materiality of the issues and costs. d) In order to control greater Governance Risk in the future, preventive and recovery actions for Governance Risk that have been taken must be followed by improvements in control weaknesses and procedures that triggered the occurrence of Governance Risk. e) The Board of Directors/Board of Commissioners receive periodic education to enhance the competence and capabilities of the Board of Directors and Board of Commissioners. f) The HR work unit must ensure that every governance issue arising can be resolved effectively by the relevant work unit and that monitoring of improvement actions is conducted by the HR work unit. g) The Board of Directors and Board of Commissioners develop succession planning. d. Governance Risk Management Information System In implementing Risk Management for Governance Risk, in addition to executing information management systems as referred to in item I.D, Pension Funds must also implement the following:
b. Sources of Corporate Governance Risk include Pension Funds having inadequate governance guidelines, Pension Funds not applying good governance principles, and Pension Funds not implementing Risk Management adequately.
c. Corporate Governance Risk may increase, among other reasons, due to interventions from other parties resulting in failures in the implementation of good governance.
2. Objective
The primary objective of Risk Management for Corporate Governance Risk is to minimize the risk of good governance not being implemented in Pension Funds.
3. Implementation of Risk Management
Implementation of Risk Management for Corporate Governance Risk for Pension Funds must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners and Board of Commissioners for Corporate Governance Risk, in addition to executing active supervision as referred to in item I.A, Pension Funds must add the implementation of several aspects in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
e) The Board of Directors and Board of Commissioners must ensure that the Pension Fund has a code of ethics as a guide for ethical behavior for the Board of Commissioners, Board of Directors, and all employees. f) The Board of Directors is responsible for risk management in conducting business activities through the development and implementation of Risk Management frameworks internally within Pension Funds. g) The Board of Directors must periodically report business activity developments as evidence of accountability to the founders of the Pension Fund. h) The Board of Directors and Board of Commissioners must perform their functions in accordance with applicable regulations according to their respective obligations.
2) Human Resources (HR)
The Board of Directors must ensure that every function and work unit responsible for managing Corporate Governance Risk has HR with adequate competence. HR adequacy for Corporate Governance Risk refers to the general implementation scope as referred to in item I.A.2. Furthermore, in supporting Pension Fund governance, Pension Funds have work units or employees performing compliance functions.
3) Corporate Governance Risk Management Organization
a) All employees, including Pension Fund management work units and supporting activities of Pension Funds, must be part of the Risk Management implementation structure for Corporate Governance Risk, considering that governance is the entirety of Pension Fund activities. b) The establishment of organizational structures, devices, and completeness of work units/functions related to the implementation of Risk Management for Corporate Governance Risk must be adjusted to the characteristics and complexity of Pension Funds. b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting
for Corporate Governance Risk, in addition to executing policies, procedures, and limit setting as referred to in item I.B, Pension Funds must add the implementation of several aspects in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) Risk Management Strategy for Corporate Governance Risk must cover strategies for all activities with significant exposure to Corporate Governance Risk. Such strategies must clearly state the direction of Pension Fund governance. b) Risk Management Strategy for Corporate Governance Risk must align with Pension Fund objectives to implement Pension Fund governance. c) Risk Management Strategy for Corporate Governance Risk covers the strategic values of Pension Funds, including transparency, accountability, and responsibility. d) Pension Funds have risk management strategies to enhance the value of Pension Fund governance.
Risk Appetite and Risk Tolerance
Setting the level of Risk to be taken and Risk Tolerance for Governance Risk refers to the general implementation scope as referred to in item I.B.2.
Policies and Procedures
a) Pension Funds have systems that can identify, assess, and measure the adequacy and effectiveness of implementing governance in Pension Funds. b) Pension Funds have work units that monitor the implementation of Pension Fund values across all elements of Pension Funds. c) Pension Funds have work plans to implement Pension Fund governance, including governance guidelines, transparency, accountability, responsibility, independence, fairness and equity, and Risk Management. d) The Board of Commissioners receives reports on the implementation of governance in Pension Funds at least 1 (one) time in 1 (one) year. e) Pension Funds have appropriate policies and procedures to ensure the fulfillment of internal policies and applicable laws/regulations.
Limits
Limits applied in Pension Funds are limits determined based on self-assessments conducted by Pension Funds. For example, limits regarding transparency in implementing Pension Fund governance, Pension Funds can determine limits regarding the extent to which Pension Funds are transparent in implementing Pension Fund governance, self-assessment limits, and limits regarding action plans.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management through the processes of identification, measurement, monitoring, and control of Risk for Corporate Governance Risk, in addition to executing processes as referred to in item I.C, Pension Funds must add the implementation of several aspects in each process, as follows:
Corporate Governance Risk Identification
Pension Funds must conduct identification and analysis of several factors that can increase exposure to Corporate Governance Risk, such as:
a) availability and completeness of governance guidelines; b) transparency in disclosure and provision of relevant information regarding Pension Funds; c) changes in management style, influence of the control environment, and behavior of parties involved directly or indirectly with Pension Funds; and d) interventions from founders, the Board of Commissioners, and other parties.
Corporate Governance Risk Measurement
In measuring Corporate Governance Risk, among other things, indicators/parameters can be used such as the completeness of adequate governance guidelines, principles of transparency, accountability, responsibility, independence, fairness and equity, and Risk Management implemented well.
Corporate Governance Risk Monitoring
Work units performing Risk Management functions for Corporate Governance Risk monitor and report Corporate Governance Risk occurring to the Board of Directors, both occasionally and periodically.
Corporate Governance Risk Control
a) In order to control Corporate Governance Risk, Pension Funds must ensure that Pension Funds have governance guidelines established formally by the Board of Directors. b) Corporate Governance Risk control can be conducted through several ways, including mitigating Risk, completeness of governance guidelines, and transparency of the Board of Directors/Board of Commissioners in making decisions. c) Pension Funds have early detection systems to prevent potential losses to Pension Funds. d) Pension Funds conduct assessment and management of Risk in the context of controlling Corporate Governance Risk. e) The Board of Directors and Board of Commissioners apply principles of transparency, accountability, responsibility, independence, fairness and equity, and Risk Management in operating Pension Funds. f) In order to control Corporate Governance Risk, Pension Funds have clearly defined the functions and duties of each work unit so that each party can perform their functions and duties well. g) Pension Funds have guidelines and apply performance measures and reward and punishment systems well to all levels of Pension Funds.
h) Pension Funds are not under the dominance of third parties and are not influenced by the interests of third parties, and are free from conflicts of interest with such third parties.
i) Pension Funds conduct periodic evaluations regarding the implementation of Risk Management at least once a year.
j) Pension Funds have guidelines governing business relationships with business partners.
d. Risk Management Information System for Governance Risk
In implementing Risk Management for Governance Risk, in addition to implementing the risk management information system as referred to in item I.D, Pension Funds must also apply the following:
Pension Funds have regular procedures and reporting mechanisms for Governance Risk/incidents causing Governance Risk, both in writing and through electronic systems, including discussions in board/management meetings.
Pension Funds have an early warning system mechanism to provide signals to management so that the necessary response and mitigation can be carried out.
Pension Funds have an electronic system containing a self-assessment of Governance Risk.
e. Comprehensive Internal Control System
In implementing Risk Management for Governance Risk, in addition to implementing internal controls as referred to in item I.E, Pension Funds must have an internal control system for Governance Risk, among others, to ensure the Pension Fund's responsiveness to deviations from generally applicable standards, regulations, and/or applicable legislation. The internal control system of Pension Funds can refer to 5 (five) components issued by the Committee of Sponsoring Organization of the Treadway Commission (COSO), namely the control environment, risk assessment, control procedures, monitoring, and information and communication.
F. Funding Support Risk
a. Funding Support (Capitalization) Risk is Risk arising from insufficient funds/capital of the Pension Fund, including lack of access to additional funds/capital when facing losses or unexpected fund/capital needs.
b. Funding Support describes the Pension Fund's ability to meet its obligations to participants and the employer's ability to finance its pension program until the end of the Pension Fund's operation.
b. Funding Support Risk stems from low funding capability and weak additional funding.
The main objective of Risk Management for Funding Support Risk is to ensure that the Risk Management process can minimize the possibility of the Pension Fund having weak funding capability and low additional funding, so that the Pension Fund cannot absorb unexpected losses.
The implementation of Risk Management for Funding Support Risk for Pension Funds must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners
In implementing Risk Management for Funding Support Risk, in addition to implementing active supervision as referred to in item I.A, Pension Funds must add the application of several matters in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Funding Support Risk is carried out integrated with other Risk Management that can impact the Pension Fund's Funding Support Risk profile.
b) Directors who oversee the finance function have an important role in Risk Management for Funding Support Risk with responsibilities at least as regulated in provisions regarding the implementation of the Pension Fund's funding function, including:
(1) formulating Risk Management policies containing written and comprehensive risk strategies and frameworks, considering the level of Risk to be taken (risk appetite) and risk tolerance (risk tolerance);
(2) having adequate understanding of Risks inherent in all business activities in the Pension Fund and being able to take necessary actions according to the Funding Support Risk profile;
(3) establishing compliance systems and procedures to be used to formulate internal regulations and guidelines of the Pension Fund;
(4) minimizing Funding Support Risk of the Pension Fund; and
(5) taking preventive actions so that policies and/or decisions taken by the Board of Directors do not deviate from applicable legislation;
c) The Board of Directors must ensure that the Pension Fund has sufficient funding capability.
d) The Board of Directors must ensure that asset placements in the form of investments can provide additional funding to the Pension Fund.
e) The Board of Directors must ensure that employers contribute premiums to the Pension Fund consisting of normal premiums and additional premiums (in case of deficit).
Officials and staff in all work units of the Pension Fund understand the impact caused by all Risks that can result in Funding Support Risk.
a) Pension Funds must have an adequate Risk Management function for Funding Support Risk with clear authority and responsibility for each work unit carrying out the Risk Management function for Funding Support Risk.
b) Pension Funds must have an independent finance work unit with tasks, authority, and responsibilities at least as regulated in provisions regarding the implementation of the Pension Fund's finance function, including:
(1) making steps to support the creation of a Pension Fund with strong funding support;
(2) having written work programs and conducting identification, measurement, monitoring, and control related to Risk Management for Funding Support Risk;
(3) assessing and evaluating the effectiveness, adequacy, and suitability of policies, systems, and procedures owned by the Pension Fund with applicable legislation;
(4) conducting reviews and/or recommending updates and improvements to policies, regulations, systems, and procedures owned by the Pension Fund to be in accordance with Pension Fund regulations and applicable legislation;
(5) making efforts to ensure that policies, regulations, systems, and procedures, and business activities of the Pension Fund are in accordance with Pension Fund regulations and applicable legislation; and
(6) performing other tasks related to the finance function.
b. Adequacy of Policies, Procedures, and Limit Setting
In implementing policies, procedures, and limit setting for Funding Support Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, Pension Funds must add the application of several matters in each aspect of policies, procedures, and limit setting, as follows:
a) The Board of Directors monitors funding in the Pension Fund as a form of anticipation when unexpected losses occur.
b) Pension Funds must ensure that the quality of Pension Fund funding is in accordance with applicable regulations and is sufficient to overcome unexpected losses.
c) Pension Funds have funding management standards aimed at ensuring the Pension Fund has sufficient funds for all risks faced and implements the established standards.
d) Pension Funds have strategies that enable the Pension Fund to have sufficient access to additional funding.
The determination of the level of Risk to be taken and Risk tolerance for Funding Support Risk refers to the general application scope as referred to in item I.B.2.
a) The policies must clearly contain:
(1) funding support management policies;
(2) policies regarding premium setting;
(3) policies regarding minimum quality of Pension Fund funding; and
(4) monitoring and controlling the Pension Fund's asset position.
b) Pension Funds have ease of access to founders or employers to add funding.
c) Pension Funds have procedures for making requests for additional funding.
d) Pension Funds have policies regarding the utilization of profitability from investments.
a) Pension Funds must ensure consistency between various types of different limits.
b) Limit setting can be established hierarchically for each level of the Pension Fund organization, for example, overall limits, additional funding limits, liquidity ratio limits, and funding capability limits.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Funding Support Risk, in addition to implementing processes as referred to in item I.C, Pension Funds must add the application of several matters in each of the aforementioned processes, as follows:
Pension Funds must conduct identification and analysis of several factors that can increase the exposure of Funding Support Risk, such as:
a) the amount (volume) and materiality of unexpected losses of the Pension Fund due to pension products/types of pension programs and diverse activities carried out;
b) sources of additional funds for the Pension Fund;
c) failure of the Board of Directors in managing wealth;
d) the absence of actuarial assumption changes that generate surplus or increase deficits for the Pension Fund;
e) changes in the financial condition of employers; and
f) business prospects.
In measuring Funding Support Risk, among others, indicators/parameters such as the Pension Fund's funding capability and additional funding capability can be used.
Pension Funds must conduct self-assessment of funding quality and adequacy of funding support sources in order to meet their obligations by considering the funding quality criteria established by regulators and other relevant factors. Subsequently, work units carrying out the Risk Management function for Funding Support Risk monitor and report Funding Support Risk that occurs to the Board of Directors, both at any time when Funding Support Risk occurs and periodically. In addition, Pension Funds conduct monitoring when there are premium receivables with an age exceeding the minimum maturity date determined.
a) Pension Funds conduct periodic evaluations of financial ratios such as liquidity ratios, actuarial obligations, and solvency ratios.
b) Pension Funds monitor and control the Pension Fund's funding position.
c) Pension Funds conduct business plans and actuarial obligation projections.
d. Risk Management Information System for Funding Support Risk
The implementation of the information management system for Funding Support Risk refers to the general application scope as referred to in item I.D. In addition, Pension Funds must fulfill the following:
Pension Funds have a system to convey the adequacy of Pension Fund funding to founders; and
the Risk Management Information System for Funding Support Risk must be able to facilitate Pension Funds to ensure the adequacy of Pension Fund funds to face all existing Risks.
e. Comprehensive Internal Control System
In implementing Risk Management for Funding Support Risk, in addition to implementing internal controls as referred to in item I.E, Pension Funds must have an internal control system for Funding Support Risk, among others, to ensure the Pension Fund's responsiveness to poor investment results, unexpected losses, and other unexpected matters.
Established in Jakarta on 14 April 2016
EXECUTIVE HEAD OF SUPERVISOR
INSURANCE, PENSION FUNDS,
LENDING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY, sd
FIRDAUS DJAELANI
Copy in accordance with the original
Legal Director 1
Legal Department
Yuliana
APPENDIX VI
FINANCIAL SERVICES AUTHORITY CIRCULAR LETTER
NUMBER 10 /SEOJK.05/2016
REGARDING
GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT AND SELF-ASSESSMENT REPORT ON RISK MANAGEMENT IMPLEMENTATION FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
To
Yth. Financial Services Authority u.p. Directorate of Pension Fund and BPJS Ketenagakerjaan Supervision Menara Merdeka Tower Building, 22nd Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
SELF-ASSESSMENT REPORT
ON THE IMPLEMENTATION OF PENSION FUND RISK MANAGEMENT YEAR … PENSION FUND XYZ (Pension Fund Address)
SELF-ASSESSMENT REPORT
ON THE IMPLEMENTATION OF PENSION FUND RISK MANAGEMENT Name of Pension Fund :
Type of Pension Fund : (1) DPPK PPMP (2) DPPK PPIP (3) DPLK Assessment Date :
Report Position Date :
A. GENERAL INFORMATION
Founders and Partner Founders:
No. Name Description Number of Participants
1.
2. etc.
Managers:
No. Name Position Term of Office
1.
2.
3. etc.
Supervisory Board:
No. Name Position Term of Office
1.
2.
3. etc.
B. PENSION FUND FINANCIAL INFORMATION
Description Value (Rupiah) Ratio per Net Assets Net Assets Investments Normal Premium Receivables Additional Premium Receivables Other Receivables Other Assets Operating Results* Funding Ratio (PPMP) Solvency Ratio (PPMP) Return on Investment (ROI)* Number of Participants
C. SUMMARY OF GENERAL Implementation of Risk Management
D. IMPLEMENTATION OF RISK MANAGEMENT FOR EACH TYPE OF RISK
APPENDIX VII
FINANCIAL SERVICES AUTHORITY CIRCULAR LETTER
NUMBER 10 /SEOJK.05/2016
REGARDING
GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT AND SELF-ASSESSMENT REPORT ON RISK MANAGEMENT IMPLEMENTATION FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT
LENDING COMPANIES
As regulated in Article 2 of Financial Services Authority Regulation Number 1/POJK.05/2015 regarding Risk Management Implementation for Non-Bank Financial Service Institutions hereinafter referred to as LJKNB, LJKNB is required to implement Risk Management effectively, which at least covers:
A. active supervision by the Board of Directors and Board of Commissioners; B. adequacy of policies, procedures, and Risk limit setting;
C. adequacy of risk identification, measurement, monitoring, and control processes;
D. Risk Management information system; and
E. comprehensive internal control system.
Risk Management principles are described as follows:
A. Active Supervision by the Board of Directors and Board of Commissioners The Board of Directors and Board of Commissioners are responsible for the effectiveness of Risk Management implementation in lending companies hereinafter referred to as Companies. Therefore, the Board of Directors and Board of Commissioners must:
understand the Risks faced by the Company;
provide clear direction;
conduct active supervision and Risk mitigation;
develop a Risk Management culture in the Company;
ensure adequate organizational structure;
establish clear tasks and responsibilities for each work unit; and
ensure the adequacy of the quantity and quality of human resources to support the effective implementation of Risk Management.
In the event that the Company is the main entity of a financial conglomerate, the active supervision by the Board of Directors and Board of Commissioners also includes supervision of the financial conglomerate's Risk Management. Matters that need to be considered in the implementation of active supervision by the Board of Directors and Board of Commissioners include the following matters:
Authority and Responsibilities of the Board of Directors and Board of Commissioners
The implementation of Risk Management must be adequate according to the Company's characteristics, complexity, and Risk profile. b. The Board of Directors and Board of Commissioners must have a good understanding of the types and levels of Risk inherent in the Company's business activities.
c. In supporting the implementation of Risk Management, the Board of Directors and Board of Commissioners must ensure that each work unit within the Company implements Risk Management.
d. The Board of Directors is responsible for the Company's Risk assessment. e. The authority and responsibilities of the Board of Commissioners include, at a minimum:
directing and approving Risk Management policies, including strategies and the Risk Management framework established in accordance with the Company's risk appetite and risk tolerance;
evaluating Risk Management policies and strategies at least once a year or more frequently if there are significant changes in factors affecting the Company's business activities;
evaluating the accountability of the Board of Directors and providing corrective guidance on the implementation of Risk Management policies periodically. Evaluations are conducted to ensure that the Board of Directors manages the Company's activities and Risks effectively; and
forming a risk monitoring committee tasked with assisting the Board of Commissioners in monitoring the implementation of Risk Management prepared by the Board of Directors.
f. The authority and responsibilities of the Board of Directors include, at a minimum:
formulating written and comprehensive Risk Management policies, strategies, and frameworks, including overall Risk limits and per Risk type, considering the Company's risk appetite and risk tolerance, and calculating the impact of Risk on capital adequacy. After receiving approval from the Board of Commissioners, the Board of Directors establishes the aforementioned policies, strategies, and frameworks;
formulating, establishing, and updating procedures and tools to identify, measure, monitor, and control Risk;
formulating and establishing transaction approval mechanisms, including those exceeding limits and authority for each job level;
evaluating and/or updating Risk Management policies, strategies, and frameworks at least once a year or more frequently if there are significant changes in factors affecting the Company's business activities, Risk exposure, and/or Risk profile;
having adequate understanding of the Risk inherent in all business activities within the Company and being able to take necessary actions according to the Company's Risk profile, including providing recommendations or proposals regarding Risk Management implementation to each work unit in the Company;
establishing the organizational structure, including clear authority and responsibilities at each job level related to Risk Management implementation;
being responsible for the implementation of Risk Management policies, strategies, and frameworks approved by the Board of Commissioners, and evaluating and providing guidance based on reports submitted by work units performing Risk Management functions, including reports on Risk profiles;
ensuring that all material Risks and their impacts have been followed up on and submitting accountability reports to the Board of Commissioners periodically. Such reports include progress reports and issues related to material Risk, along with corrective steps that have been, are being, and will be taken;
ensuring the implementation of corrective steps for issues or deviations in the Company's business activities found by the internal audit function work unit;
developing a Risk Management culture, including Risk awareness at all organizational levels, including adequate communication to all organizational levels regarding the importance of effective internal controls;
ensuring adequate financial support and infrastructure to manage and control Risk;
ensuring that the Risk Management function is implemented independently, reflected in:
a) the separation of functions between work units performing Risk Management functions (identifying, measuring, monitoring, and controlling Risk) and work units performing internal control functions; and b) Risk Management implementation free from conflicts of interest among work units;
ensuring that all Company policies, regulations, systems, procedures, and business activities comply with applicable laws and regulations.
In carrying out the responsibilities for Risk Management implementation regarding HR, the Board of Directors must:
a. establish clear HR qualifications for each job level related to Risk Management implementation; b. ensure the adequacy of the quantity and quality of HR in the Company and ensure that such HR understands their tasks and responsibilities, for business work units, work units performing Risk Management functions, and supporting work units responsible for implementing Risk Management;
c. develop employee recruitment, development, and training systems, including managerial succession plans and adequate remuneration to ensure the availability of competent employees in Risk Management;
d. ensure the improvement of competence and integrity of leaders, business work unit personnel, Risk Management function work unit personnel, and internal audit function work unit personnel, considering factors such as knowledge, experience/track record, and adequate ability in Risk Management through continuous education and training programs, to guarantee the effectiveness of the Risk Management process; e. place competent officials and staff in each work unit according to the nature, volume, and complexity of the Company's business activities; f. ensure that officials and staff placed in each work unit as referred to in letter e have:
In order to implement effective Risk Management, the Company's Board of Directors establishes an organizational structure considering the following:
a. The organizational structure must be accompanied by clear general tasks and responsibilities, as well as those related to Risk Management implementation, for all work units, adjusted to the Company's business objectives and policies, size, and complexity of business activities. b. The organizational structure must be designed to ensure that work units performing internal control functions and work units performing Risk Management functions are independent from the Company's business work units.
c. The organizational structure should be designed so that work units performing Risk Management functions have access and can report directly to the Board of Directors and Board of Commissioners, including regarding self-assessment of the Company's Risk and steps to be taken to manage such Risk; assessment of changes in the Company's Risk profile; and management of Risk related to strategy, such as the Company's strategy, mergers and acquisitions, and investments.
d. The head of the work unit performing Risk Management functions must have the authority and obligation to inform the Board of Directors and Board of Commissioners of any event that may have a material impact on the Company's Risk Management system. e. The adequacy of the delegation of authority framework is adjusted to the characteristics and complexity of business activities, the Company's risk appetite, and the experience and expertise of the personnel. Delegated authority must be reviewed periodically to ensure that the authority is consistent with current conditions and the performance level of the relevant official.
B. Adequacy of Policies, Procedures, and Limit Setting
Effective Risk Management implementation must be supported by a framework covering Risk Management policies and procedures, as well as clearly established Risk limits, in line with the Company's vision, mission, and business strategy. The formulation of Risk Management policies and procedures considers, among other things, the type, complexity of business activities, Risk profile, risk appetite, and regulations set by authorities and/or sound Company practices.
In the Risk Management framework, the Company should include a feedback loop based on accurate and quality information, management processes, and objective assessment, enabling the taking of necessary actions at the right time to respond to changes in the Risk profile. This is necessary to ensure that decisions made by the Board of Directors and Board of Commissioners are implemented and the impact of such decisions is monitored and reported in a timely and sufficiently frequent manner through good management information. A feedback loop is needed to keep the Company's Risk Management framework relevant to changing conditions, with the aim of helping the Company meet strategic and risk management objectives. Furthermore, the implementation of the Company's Risk Management policies and procedures must be supported by adequate capital and HR quality.
In order to effectively control Risk, the Company's policies and procedures must be based on Risk Management strategy and supplemented with risk tolerance and Risk limits. The setting of risk tolerance and Risk limits considers the risk appetite, risk tolerance, and the Company's overall strategy.
In the event that the Company is part of a financial conglomerate, policies, procedures, and Risk limit setting also cover Risk arising from the interconnection among members of the financial conglomerate.
Matters to be considered in establishing the Risk Management framework, including policies, procedures, and limits, include the following:
d. Risk appetite and risk tolerance must be considered in the formulation of Risk Management policies, including in limit setting. e. In establishing risk tolerance, the Company needs to consider the Company's strategy and objectives, as well as the Company's ability to take Risk (risk bearing capacity).
the establishment of Risk related to the Company's products and transactions based on the Company's analysis of Risk inherent in each business activity and transaction conducted and to be conducted according to the characteristics and complexity of business activities;
the establishment of methods for identifying, measuring, monitoring, and controlling Risk, as well as the Risk Management information system to accurately assess Risk exposure in each business activity and transaction, and Company business activities;
the establishment of data to be reported, report formats, and types of information to be included in Risk Management reports so as to reflect Risk exposure that becomes a consideration in business decision-making while still adhering to the principle of prudence;
the establishment of authority and hierarchical limit sizes, including transaction limits requiring Board of Directors approval, and the establishment of risk tolerance as the limit of potential loss that can be absorbed by the Company's capital adequacy, and monitoring tools for the development of the Company's Risk exposure;
the establishment of Risk values and Risk levels as a basis for the Company to determine corrective steps for specific business activities, Company transactions, and business activity areas, and to evaluate the implementation results of Risk Management policies and strategies;
an organizational structure that clearly formulates the roles and responsibilities of the Board of Commissioners, Board of Directors, committees, Risk Management work units, operational work units, internal audit work units, and other supporting work units;
the establishment of an internal control system in the implementation of Risk Management to ensure compliance with applicable external and internal regulations, effectiveness and efficiency of Company operational activities, effectiveness of Risk culture at all organizational levels, and the availability of accurate, complete, useful, and timely management and financial information;
business continuity plan (or business continuity management) policy for the worst possible external and internal conditions, so that the Company's business continuity can be maintained, including disaster recovery plan and contingency plan.
The formulation of the business continuity plan meets the following, among other things:
b) is flexible to respond to various unexpected and specific disturbance scenarios, i.e., specific conditions and actions required immediately; c) periodic testing and evaluation of the business continuity plan; and d) the Board of Directors periodically updates the business continuity plan to ensure the effectiveness of the formulated business continuity plan. f. Risk Management policies and procedures are adequately documented and communicated to all employees. g. Risk Management policies must be relevant to the types of Risk determined, both Risk related to business strategy and Risk related to the Company's daily operations.
C. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
Risk identification, measurement, monitoring, and control are main parts of the Risk Management implementation process. Risk identification is proactive, covering all Company business activities and is conducted to analyze the sources and likelihood of Risk occurrence and its impact. Subsequently, the Company needs to measure Risk according to the characteristics and complexity of business activities. In monitoring Risk measurement results, the Company can establish an independent work unit from the transacting party to monitor the level and trends and analyze the direction of Risk. In addition, the effectiveness of Risk Management implementation needs to be supported by Risk control considering the results of Risk measurement and monitoring.
In the event that the Company is part of a financial conglomerate, risk identification, measurement, monitoring, and control also cover risk arising from the interconnection among members of the financial conglomerate. Matters to be considered in the implementation of the identification, measurement, monitoring, and control processes include the following.
Risk Identification
a. The Company identifies all Risk periodically. b. The Company has methods or systems to identify Risk in all business activities and Company business operations.
c. The Risk identification process is conducted by analyzing all Risk sources, at a minimum conducted against Risk from business activities and Company operations, and ensuring that Risk from new business activities and operations has undergone an adequate Risk Management process before being introduced or run.
d. The Risk identification process considers factors affecting Risk, including additional Risk originating from group members.
Risk Measurement
a. The Risk measurement system is used to measure the Company's Risk exposure as a reference for control. Risk measurement is conducted periodically for both types of business activities and all Company business operations. b. The system must be able to measure, at a minimum:
ensure the consistency, accuracy, reasonableness, and integrity of data, as well as the procedures used to measure Risk. f. The Risk measurement process must clearly include the validation process, validation frequency, data and information documentation requirements, and evaluation requirements for the assumptions used, before a model is applied by the Company. g. Stress testing is conducted to complement the Risk measurement system by estimating the Company's potential losses under abnormal market conditions using specific scenarios, in order to observe the Company's performance sensitivity to changes in Risk factors and to identify influences that have a significant impact on the Company's portfolio. h. The Company must conduct stress testing periodically, review the results of such stress testing, and take appropriate steps if the estimated conditions exceed the acceptable level of tolerance. These results are used as input when determining or changing policies and limits.
i. The Company measures Risk based on the Company's ability to assess its own Risks and the Company's capital position.
Risk Monitoring
a. The Company must have a monitoring system and procedures that include, among others, monitoring of the magnitude of Risk exposure, Risk tolerance, compliance with internal limits, and the results of stress testing, as well as the consistency of implementation with the established policies and procedures. b. Monitoring is conducted by both the operating work units and by the work units performing the Risk Management function.
c. Monitoring results are presented in periodic reports submitted to management for the purpose of Risk mitigation and necessary actions.
Risk Control
a. The Company must have methods for controlling Risk, referring to the established policies and procedures. b. The Company's applied Risk control process must be adjusted to the Risk exposure, the level of Risk to be taken, and Risk tolerance.
c. Risk control can be carried out by the Company, including through hedging mechanisms and other Risk mitigation methods such as increasing the Company's capital to absorb potential losses.
d. The Company must have a framework that is responsive to changes occurring due to the types of Risk present in the Company.
D. Risk Management Information System
In order to support the processes of identification, measurement, monitoring, and control of Risk, the Company also needs to develop a management information system adapted to the Company's characteristics, activities, and complexity of business operations. In the event that the Company is the main entity of a financial conglomerate, the Risk Management information system also includes the information systems necessary for the implementation of Risk Management for that financial conglomerate. Matters to be considered in the implementation of the Risk Management information system include the following:
E. Comprehensive Internal Control System
The implementation of effective Risk Management must be supplemented by a reliable internal control system. The effective implementation of the internal control system can help the Company in maintaining its assets, ensuring the availability of reliable financial and managerial reporting, increasing the Company's compliance with applicable laws and regulations, and reducing the Risk of losses, deviations, and violations of prudence aspects. The implementation of the Company's reliable and effective internal control system is the responsibility of all operational work units, supporting work units, and internal audit work units. In the event that the Company is the main entity of a financial conglomerate, the internal control system must also include a comprehensive internal control system for the implementation of Risk Management for that financial conglomerate. Matters to be considered in the implementation of the internal control system include the following:
II. GUIDELINES FOR IMPLEMENTING RISK MANAGEMENT FOR EACH RISK
A. Strategic Risk
as referred to in item I.D, the Company must also implement the following:
B. Operational Risk
inadequacy or failure of internal processes, people, information technology systems, and/or events originating from outside the Company's environment, thereby causing the Company to fail in realizing its obligations to policyholders and policyholders.
3. Implementation of Risk Management
The implementation of Risk Management for Operational Risk for the Company must at least include:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management for Operational Risk, in addition to carrying out active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibility of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners are responsible for developing an organizational culture that is aware of Operational Risk and fostering commitment in managing Operational Risk in accordance with the Company's business strategy. b) The Company's Board of Directors creates a culture of objective disclosure of Operational Risk across all organizational elements so that Operational Risk can be identified quickly and mitigated appropriately. c) The Board of Directors establishes effective reward policies, including remuneration and punishment, integrated into the performance evaluation system in order to support the implementation of optimal Risk Management. d) The Board of Directors must ensure that the exercise of authority and responsibilities delegated to service providers has been carried out well and responsibly.
Human Resources (HR)
a) The Company must have an ethical code applied to all employees at every level of the organization. b) The Company must apply sanctions consistently to officials and employees proven to have committed deviations and violations.
Operational Risk Management Organization
a) The Company's business work unit management or supporting work unit management is the risk owner responsible for the daily Risk Management process for Operational Risk and reporting specific problems and Operational Risks in their respective work units according to the applicable reporting levels. b) To facilitate the Risk Management process for Operational Risk in the Company's business work units or supporting work units and ensure the consistent implementation of Operational Risk Management policies, a dedicated operational risk officer may be appointed who has a dual reporting line, namely directly to the head of the Company's business work unit or supporting work unit. The responsibilities of the dedicated operational risk officer include developing specific Risk indicators for the Company's business work unit or supporting work unit, determining escalation limits, and compiling Operational Risk Management reports. b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Operational Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
The formulation of strategy for Operational Risk refers to the general scope of implementation as referred to in item I.B.1. In addition, in formulating the strategy, the Company must also implement the following:
a) establish a technology and information system to prevent Fraud Risk; b) have computer devices, information technology systems, workrooms, office equipment, and administrative systems that support the Company's activities; c) have a structure that supports the Company's work pattern; d) apply adequate asset and data security principles and business continuity management; and e) consider the location of the Company's offices, for example, being in a strategic place (close to consumers) and not in areas prone to natural disasters.
Risk Appetite and Risk Tolerance
The determination of the level of Risk to be taken and Risk tolerance for Operational Risk refers to the general scope of implementation in item I.B.2.
Policies and Procedures
a) The Company has an adequate operational system. b) The Company has an early warning system when there is a discrepancy between actual data and data owned by the Company. c) The Company must establish Operational Risk Management policies that must be internalized into the business process of all types of business activities and supporting activities of the Company, including unique Operational Risk policies according to the needs of the type of business activity and supporting activities. d) The Company must have procedures that are derived from the Operational Risk Management Policy. These procedures can be:
(1) general controls, namely operational controls that are general for all types of business activities and supporting activities of the Company, for example, separation of functions or the requirement to take leave; and (2) specific controls, namely operational controls that are specific to each type of business activity and supporting activity of the Company, for example, debtor document management. e) The Company has early warning procedures to handle sudden changes in information technology systems that impact the increased possibility of Operational Risk. f) To reduce the possibility of Operational Risk arising from HR, the Company's Risk Management policy must at least contain policies on recruitment and placement according to organizational needs, competitive remuneration and incentive structures, training and development, periodic rotation, career planning and succession policies, and handling of employment termination and labor union issues. g) To reduce the possibility of Operational Risk arising from systems and infrastructure, the Company's Risk Management policy must be supported by procedures for access to management information systems, accounting information systems, risk management systems, document room security, and data processing rooms. h) To reduce the possibility of Operational Risk arising from external events, the Company's Risk Management policy must be supported, among others, by insurance protection for the Company's physical assets, backup systems, and occupational safety guarantees for certain high-risk job fields. i) To reduce the possibility of Operational Risk arising from the profile of customers/consumers and prospective customers/consumers, the Risk Management policy must include the Company's obligation to conduct Customer Due Diligence (CDD) or Enhanced Due Diligence (EDD) periodically and consistently in accordance with Operational Risk exposure. The implementation of CDD/EDD refers to all requirements and guidelines as regulated in applicable provisions regarding anti-money laundering and counter-terrorism financing. CDD/EDD must be supported by an effective internal control system, specifically the Company's efforts to prevent internal crime (internal fraud).
Limit
The setting of limits for Operational Risk refers to the general scope of implementation as referred to in item I.B.4.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Operational Risk, in addition to carrying out the processes as referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
Identification of Operational Risk
a) The Company must conduct identification and measurement of parameters that influence Operational Risk exposure, including the frequency and impact of:
(1) system failures and errors;
(2) weaknesses in information technology systems; (3) failure of customer relationships; (4) accounting errors; (5) asset calculation errors; (6) fraud; and (7) accounting manipulation. b) The Company develops a database regarding:
(1) types and impacts of losses caused by Operational Risk based on the results of Risk identification, in the form of loss data that can be predicted or difficult to predict; (2) violations of control systems; and (3) other operational issues that can cause losses in the future. c) The Company considers various internal and external factors in conducting identification and measurement of Operational Risk, including:
(1) the Company's organizational structure, Risk culture, HR management, organizational changes, and employee turnover; (2) debtor characteristics, products and activities, as well as the complexity of business activities and transaction volume;
(3) the design and implementation of systems and processes used; and (4) the external environment, industry trends, market structure including social and political conditions. d) For Companies that have not yet developed special methods to conduct identification and measurement of Operational Risk, the main source of Operational Risk information is internal audit findings related to Operational Risk. e) The Company has financing agreements with debtors that must at least contain:
(1) type of business activity and financing method:
(2) agreement number and date;
(3) identity of the parties;
(4) financed goods or services;
(5) value of financed goods or services;
(6) amount of receivables and financing installments; (7) financing term and interest rate; (8) collateral object (if any); (9) details of costs related to the financing provided; (10) clear fiduciary burden clauses, if there is a fiduciary burden in financing activities; (11) mechanism in case of disputes and choice of dispute resolution venue; (12) provisions regarding the rights and obligations of the parties; and (13) provisions regarding penalties.
2) Measurement of Operational Risk
In measuring Operational Risk, among others, indicators/parameters can be used in the form of size and organizational structure, HR, new business development, and the use of third-party services.
3) Monitoring of Operational Risk
a) The Company must conduct continuous monitoring of Operational Risk against all Operational Risk exposures and losses that can be caused by the Company's main activities, among others, by applying an internal control system and providing periodic reports on losses caused by Operational Risk. b) The Company must periodically review the factors causing Operational Risk and the impact of its losses.
4) Control of Operational Risk
a) Risk control is carried out consistently in accordance with the level of Risk to be taken, and the results of identification and measurement of Operational Risk. b) In the implementation of Operational Risk control, the Company can develop programs to mitigate Operational Risk, among others, by securing information technology processes, and outsourcing some of the Company's operational activities. c) In the event that the Company develops information technology process security, the Company must ensure the level of security of electronic data processing. d) Control of information systems must ensure:
(1) periodic assessment of information system security, accompanied by corrective actions if necessary; (2) availability of backup procedures and emergency plans to ensure the smooth operation of the Company's activities and prevent significant disruptions, which are tested periodically; (3) submission of information to the Board of Directors regarding issues in paragraphs (1) and (2); and (4) availability of storage for information and documents related to analysis, programming, and implementation of data processing. e) The Company must have a support system, which must at least include:
(1) early identification of errors;
(2) efficient, accurate, and timely processing and settlement of all transactions; and (3) confidentiality, truthfulness, and security of transactions.
f) The Company must periodically review procedures, documentation, data processing systems, contingency plans, and other operational practices to reduce the possibility of human error. g) The Company must have adequate policies and procedures, good Company administrative activities, good management of information systems and technology, good fraud and legal issue prevention, good HR management, and good third-party service provider management. h) Employee recruitment is carried out by external parties such as HR consultants and organizations that independently analyze employee needs and carry out the employee recruitment process. i) The Company provides training and mentoring to all Company employees. d. Operational Risk Management Information System In implementing Risk Management for Operational Risk, in addition to implementing the management information system as referred to in item I.D, the Company must also implement the following:
Asset and Liability Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) The Company records and evaluates assets and liabilities owned by the Company periodically. b) The Board of Directors and Management monitor the assets and liabilities owned by the Company. c) The Company assesses asset exposure and liability exposure that have interest rate and exchange rate risks. d) The Company maps the assets owned to know which assets are more liquid/illiquid than liabilities. e) The Company categorizes consumers. f) The Board of Directors and Management are responsive to issues regarding asset and liability risks.
Risk Appetite and Risk Tolerance
a) The risk appetite statement must reflect the Company's perspective on Asset and Liability Risk. For example, the Company's statement regarding diversification of investment placements, investment income, liquidity ratios, and profit acquisition. In addition, the risk appetite statement must support the achievement of the Company's established targets or goals. b) Risk Tolerance for Asset and Liability Risk must reflect the Company's efforts to achieve its goals and be in accordance with the established risk appetite statement, such as the percentage of direct participation portfolios, setting profit targets for the upcoming period, and financing disbursement targets.
Policies and Procedures
a) The Company has an adequate asset management and liability management work plan. b) The Company reports periodically on the Company's assets and liabilities to the Board of Commissioners. c) Asset and liability management policies and procedures must at least include:
i. composition of assets and liabilities;
ii. the level of assets maintained by the Company; and
iii. Asset and Liability Risk limits.
d) Risk Management in the Company is supported by appropriate policies and procedures so as to become more directed and comprehensive. e) The Company has a reporting mechanism containing issues of asset and liability management risk, legal risk, and other risks that affect the Company's performance. f) The Company has procedures for setting and reviewing financing disbursement guidelines. g) The Company has procedures for formulating and setting annual financing plans.
Limit
a) Asset and Liability Risk limits must be consistent and relevant to the composition of assets and liabilities of the Company. b) Policies regarding limits must be applied consistently to manage Asset and Liability Risk, among others, to limit the financing receivables conducted by the Company. c) Asset and Liability Risk limits may include, among others, the amount of direct participation conducted by the Company, the calculation of the difference between assets and liabilities in foreign currency (currency gap), and the amount of financing receivables.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Asset and Liability Risk, in addition to carrying out the processes as referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
Identification of Asset and Liability Risk
a) In order to identify Asset and Liability Risk, the Company must analyze all sources of Asset and Liability Risk. Sources of Asset and Liability Risk include, among others, the management of the Company's assets and liabilities. b) The analysis is conducted to determine the amount of assets owned and the amount of liabilities to be fulfilled by the Company, so that there is no mismatch between assets and liabilities. c) The Company must conduct an analysis to determine the impact of financing receivables on Asset and Liability Risk. d) The Company must value assets influenced by interest rates and exchange rates.
Measurement of Asset and Liability Risk
In measuring Asset and Liability Risk, the Company may use indicators/parameters such as potential losses due to interest rate and exchange rate risks, the ratio of financing receivables to total assets, mismatches between assets and liabilities in foreign currency (currency gap), and the assessment of exposure to assets and liabilities with interest rate and exchange rate risks.
Monitoring of Asset and Liability Risk
The work unit implementing the Risk Management function for Asset and Liability Risk monitors and reports Asset and Liability Risk occurring to the Company's Board of Directors, both ad hoc when Asset and Liability Risk occurs and periodically.
Control of Asset and Liability Risk
a) The Company's control of Asset and Liability Risk is carried out, among others, through the Board of Directors' concern regarding the placement of capital contributions and the monitoring of financing disbursement. b) The Company must have high concern from the Board of Directors or Board of Commissioners regarding the objectives of asset and liability management, adequate management of owned assets and liabilities, proper investment risk management, and strong controls in asset valuation.
d. Asset and Liability Risk Management Information System In implementing Risk Management through the implementation of a management information system for Asset and Liability Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to implement the following:
e. Comprehensive Internal Control System
In implementing Risk Management for Asset and Liability Risk, in addition to implementing internal controls as referred to in item I.E, the Company needs to have an internal control system for Asset and Liability Risk, among others, to ensure the Company's responsiveness to deviations from generally applicable standards, regulations, and/or applicable legislation.
D. Governance Risk
Definition
a. Governance Risk is the risk of the Company's failure to achieve its objectives due to the Company's failure to maintain the best composition of management having high competence and integrity. The management referred to in Governance Risk includes the Board of Directors and the Board of Commissioners. b. Sources of Governance Risk include, among others, inadequate appointment and dismissal of the Board of Directors and Board of Commissioners, insufficient and inappropriate composition and proportion of the Board of Directors and Board of Commissioners relative to the Company's needs, inadequate competence and integrity of the Board of Directors and Board of Commissioners that do not support their duties and authorities, and poor leadership of the Board of Directors and Board of Commissioners.
c. Governance Risk can increase, among others, due to the unavailability of adequate remuneration systems for the Board of Directors and Board of Commissioners.
Objective
The main objective of Risk Management for Governance Risk is to ensure that the Company maintains the best composition of the Board of Directors and Board of Commissioners having high competence and integrity, so that the Company is avoided from failure in achieving its objectives.
Implementation of Risk Management
The implementation of Risk Management for Governance Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Governance Risk, in addition to implementing active supervision as referred to in item I.A, the Company needs to add the implementation of several items in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibility of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Governance Risk is carried out in an integrated manner with other Risk Management that can impact the Company's Governance Risk profile. b) The Board of Directors and Board of Commissioners must ensure that the Company has an adequate internal selection system that is applied continuously/consistently. c) The Board of Directors and Board of Commissioners must inform and remind shareholders regarding regulations concerning the appointment and dismissal of the Board of Directors and Board of Commissioners when the General Meeting of Shareholders (GMS) is held, which can be proven by the GMS minutes. d) The Board of Directors must ensure that the implementation of Risk Management is carried out effectively in the implementation of aspects related to Governance Risk, such as selection, appointment of the Board of Directors and Board of Commissioners, and others.
Human Resources
The adequacy of Human Resources for Governance Risk refers to the scope of general implementation as referred to in item I.A.2.
Organization of Governance Risk Management
In the implementation of Risk Management for Governance Risk, the Company has an organ that supports the Company's business activities by considering, among others:
a) clarity of duties and responsibilities of the Board of Directors and Board of Commissioners based on the competence and expertise possessed, so that the Board of Directors and Board of Commissioners are adaptive to changing market needs; and b) methods to ensure that the Board of Directors and Board of Commissioners appointed by the controller do not have conflicts of interest with the Company's business activities. In addition, the Company may also form a special work unit responsible for assessing the leadership, competence, and integrity of the Board of Directors and Board of Commissioners.
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Governance Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several items in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) The Risk Management Strategy for Governance Risk covers all causes of risk, including the appointment and dismissal and leadership of the Board of Directors and Board of Commissioners. b) The Risk Management Strategy for Governance Risk has the ability to minimize the possibility of Governance Risk emerging, for example, by conducting background checks on prospective Board of Directors/Board of Commissioners candidates.
Risk Appetite and Risk Tolerance
The determination of the level of Risk to be taken and Risk Tolerance for Governance Risk refers to the scope of general implementation as referred to in item I.B.2.
Policies and Procedures
a) The Company must have written policies and procedures containing regulations regarding competence and capability as a member of the Board of Directors or Board of Commissioners in order to achieve the Company's objectives. b) The Company may form a special work unit to handle unexpected incidents due to sudden changes in the number and composition of the Board of Directors and Board of Commissioners. c) The Company must have specific standards and criteria in submitting names of prospective Board of Directors/Board of Commissioners candidates to shareholders. d) The Company must have specific standards and criteria in the selection of prospective Board of Directors/Board of Commissioners candidates conducted by shareholders. e) The Company must have procedures regarding the appointment documents of the Board of Directors/Board of Commissioners that comply with applicable regulations/laws.
Limits
a) Governance Risk limits generally are not limits that can be quantified financially. b) The Company needs to apply Risk Tolerance for Governance Risk. c) Limits for Governance Risk are used to reduce Risks arising, including due to the unfulfilled minimum number of the Company's Board of Commissioners.
c. Adequacy of the Process of Identification, Measurement, Monitoring, and Control of Risk
In implementing Risk Management for Governance Risk, in addition to implementing the process as referred to in item I.C, the Company needs to add the implementation of several items in each of the aforementioned processes, as follows:
Identification of Governance Risk
a) The Company must record and account for every event related to Governance Risk, for example, the number of the composition of the Board of Directors/Board of Commissioners, meetings attended by the Board of Directors/Board of Commissioners, and meeting minutes involving the Board of Directors/Board of Commissioners. b) The Company assesses the procedures and legality of documents related to the appointment and dismissal of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring. c) The Company uses the results of fitness and propriety tests, work experience, education and training, and the behavior of the Board of Directors and Board of Commissioners to identify the possibility of Governance Risk occurring. d) The Company may use several information sources to identify Governance Risk, including mass media reporting and information obtained from authorities regarding the background/characteristics of prospective Board of Directors/Board of Commissioners candidates.
Measurement of Governance Risk
In measuring Governance Risk, among others, indicators/parameters such as the determination of procedures and legality of documents related to the appointment and dismissal of the Board of Directors/Board of Commissioners, ownership of the composition and proportion of the Board of Directors and Board of Commissioners in accordance with applicable legislation, and the determination of criteria for good competence and integrity for the Board of Directors/Board of Commissioners can be used.
Monitoring of Governance Risk
a) The Company monitors the legality of documentation for the appointment and dismissal of the Board of Directors/Board of Commissioners through a specific work unit, for example, the Risk Management work unit. b) In monitoring data, the number, and composition of the Board of Directors and Board of Commissioners, the Company develops an electronic system to monitor all data of the Board of Directors and Board of Commissioners. c) The Company may cooperate with third parties to monitor the leadership, competence, and integrity of the Board of Directors/Board of Commissioners.
Control of Governance Risk
a) The Company must immediately follow up and address reports that the Company's Board of Directors/Board of Commissioners have taken actions contrary to applicable regulations. b) The Company develops guidelines regarding criteria for prospective Board of Directors/Board of Commissioners candidates, guidelines regarding the process of appointment, replacement, and dismissal of the Board of Directors/Board of Commissioners. c) Mitigation of Governance Risk or events causing Governance Risk is carried out by considering the materiality of the issues and costs. d) In order to control Governance Risk more significantly in the future, preventive and recovery actions taken for Governance Risk need to be followed by improvements in control weaknesses and procedures that trigger the occurrence of Governance Risk. e) The Board of Directors/Board of Commissioners receive periodic education to improve the competence and capability of the Board of Directors/Board of Commissioners. f) The Human Resources work unit must ensure that every governance issue that arises can be resolved effectively by the relevant work unit and that monitoring of improvement actions is conducted by the Human Resources work unit. g) The Board of Directors and Board of Commissioners develop succession planning.
d. Governance Risk Management Information System In implementing Risk Management for Governance Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to implement the following:
e. Comprehensive Internal Control System
In implementing Risk Management for Governance Risk, in addition to implementing internal controls as referred to in item I.E, the Company also needs to implement the following:
E. Governance Risk (Corporate Governance Risk)
Definition
a. Governance Risk is the potential failure in the implementation of good governance, inappropriate management style, control environment, and behavior of every party involved directly or indirectly with the Company. b. Sources of Governance Risk include the Company's governance guidelines being inadequate, the Company not implementing good governance principles, and the Company not implementing Risk Management adequately.
c. Governance Risk can increase, among others, due to intervention from other parties resulting in failure in the implementation of good governance.
Objective
The main objective of Risk Management for Governance Risk is to minimize the risk of good governance not being implemented in the Company.
Implementation of Risk Management
The implementation of Risk Management for Governance Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Governance Risk, in addition to implementing active supervision as referred to in item I.A, the Company needs to add the implementation of several items in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
Authority and Responsibility of the Board of Directors and Board of Commissioners
a) The Board of Directors and Board of Commissioners must ensure that Risk Management for Governance Risk is carried out in an integrated manner with other Risk Management that can impact the Company's Governance Risk profile. b) The Board of Commissioners must monitor the effectiveness of the implementation of the governance function in the Company, followed by all parties within the Company. c) The Board of Commissioners compile a report on the activities of the Board of Commissioners, which is part of the report on the implementation of good governance by the Company. d) The Board of Commissioners hold Board of Commissioners meetings. e) The Board of Directors and Board of Commissioners must ensure that the Company has a code of ethics as a guide for ethical behavior for the Board of Commissioners, Board of Directors, and all employees. f) The Board of Directors is responsible for risk management in conducting business activities through the development and implementation of a Risk Management framework within the Company. g) The Board of Directors must report the progress of business activities periodically as proof of accountability to shareholders. h) The Board of Directors and Board of Commissioners must perform their functions in accordance with applicable regulations according to their respective obligations.
Human Resources (HR)
The Board of Directors must ensure that every function and work unit responsible for the management of Governance Risk has Human Resources with adequate competence. The adequacy of Human Resources for Governance Risk refers to the scope of general implementation as referred to in item I.A.2. In addition, to support good corporate governance, the Company has a work unit or employees who perform compliance functions.
Organization of Governance Risk Management
a) All employees, including business unit management and the Company's support activities, must be part of the implementation structure of Risk Management for Governance Risk, considering that governance is the entirety of the Company's activities. b) The determination of organizational structure, devices, and completeness of work units/functions related to the implementation of Risk Management for Governance Risk must be adjusted to the characteristics and complexity of the Company's business activities.
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Governance Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several items in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) The Risk Management Strategy for Governance Risk must cover strategies for all activities with significant Governance Risk exposure. This strategy must clearly state the direction of the Company's governance. b) The Risk Management Strategy for Governance Risk must be in line with the Company's objectives to implement good corporate governance. c) The Risk Management Strategy for Governance Risk includes the strategic values of the Company, including transparency, accountability, and responsibility. d) The Company has a risk management strategy to increase the value of the Company's governance.
Risk Appetite and Risk Tolerance
The determination of the level of Risk to be taken and Risk Tolerance for Governance Risk refers to the scope of general implementation as referred to in item I.B.2.
Policies and Procedures
a) The Company has a system that can identify, assess, and measure the adequacy and effectiveness of the implementation of governance in the Company. b) The Company has a work unit that monitors the implementation of the Company's values across all elements of the Company. c) The Company has a work plan to implement good corporate governance, which includes governance guidelines, transparency, accountability, responsibility, independence, fairness and equity, and Risk Management. d) The Board of Commissioners receives reports regarding the implementation of good governance in the Company at least 1 (one) time in one year. e) The Company has appropriate policies and procedures to ensure the fulfillment of internal policies and applicable legislation.
Limits
The limits applied in the Company are limits determined based on self-assessment conducted by the Company. For example, regarding limits on transparency in the implementation of good corporate governance, the Company can determine boundaries on how transparent the Company is in implementing corporate governance, self-assessment limits, and limits on action plans.
c. Adequacy of the Process of Identification, Measurement, Monitoring, and Control of Risk
In implementing Risk Management through the processes of identification, measurement, monitoring, and control of Risk for Governance Risk, in addition to implementing the processes as referred to in item I.C, the Company needs to add the implementation of several items in each of the aforementioned processes, as follows:
Identification of Governance Risk
The Company must conduct identification and analysis of several factors that can increase Governance Risk exposure, such as:
a) availability and completeness of governance guidelines; b) transparency in disclosure and provision of relevant information regarding the Company; c) changes in management style, influence of the control environment, and behavior of parties involved directly or indirectly with the Company; and d) intervention from shareholders, the Board of Commissioners, and other parties.
Measurement of Governance Risk
In measuring Governance Risk, among others, indicators/parameters such as the completeness of adequate governance guidelines, principles of transparency, accountability, responsibility, independence, fairness and equity, and Risk Management implemented well can be used.
Monitoring of Governance Risk
The work unit implementing the Risk Management function for Governance Risk monitors and reports Governance Risk occurring to the Company's Board of Directors, both ad hoc and periodically.
Control of Governance Risk
a) In order to control Governance Risk, the Company must ensure that the Company has governance guidelines formally established by the Board of Directors. b) Control of Governance Risk can be carried out through several methods, among others, mitigating Risk, completeness of governance guidelines, and transparency of the Board of Directors/Board of Commissioners in making decisions. c) The Company has an early detection system to prevent potential losses to the Company. d) The Company conducts assessment and management of Risk
in order to control Governance Risk. e) The Board of Directors and Board of Commissioners apply the principles of openness, accountability, responsibility, independence, fairness, and equality, and Risk Management in running the Company. f) In order to control Governance Risk, the Company has clearly established the functions and duties of each work unit so that each party can perform their functions and duties well. g) The Company has guidelines and applies performance measures and reward and punishment systems well to all levels of the Company. h) The Company is not dominated by third parties and is not influenced by the interests of third parties and is free from conflicts of interest with such third parties. i) The Company conducts periodic evaluations regarding the implementation of Risk Management at least once a year. j) The Company has guidelines governing business relationships with business partners.
d. Governance Risk Management Information System In implementing Risk Management for Governance Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to implement the following:
e. Comprehensive Internal Control System
In implementing Risk Management for Governance Risk, in addition to implementing internal control as referred to in item I.E, the Company needs to have an internal control system for Governance Risk among others to ensure the Company's responsiveness to deviations from generally applicable standards, regulations, and/or applicable legislation. The Company's internal control system can refer to 5 (five) components issued by the Committee of Sponsoring Organization of the Treadway Commission (COSO), namely control environment, risk assessment, control procedures, monitoring, and information and communication.
F. Funding Capital Risk (Capital Support)
Definition
a. Funding Capital Risk (Capital Support) is Risk that arises due to insufficient funds/capital in the Company, including lack of access to additional funds/capital when facing losses or unexpected funding/capital needs. b. The Company's capitalization describes the Company's ability to absorb unexpected losses resulting from the management of the Company's assets and liabilities.
c. Funding Capital Risk (Capital Support) stems from low funding (capital) capacity and weak additional funding (capital).
Objective
The main objective of Risk Management for Funding Capital Risk (Capital Support) is to ensure that the Risk Management process can minimize the possibility of the Company having weak funding capacity and low additional funding so that the Company cannot absorb unexpected losses.
Implementation of Risk Management
Implementation of Risk Management for Funding Capital Risk (Capital Support) for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management for Funding Capital Risk (Capital Support), in addition to implementing active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Funding Capital Risk (Capital Support), in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) The Board of Directors monitors capitalization in the Company as a form of anticipation when unexpected losses occur. b) The Board of Commissioners monitors the assets owned by the Company. c) The Company must ensure that the minimum ratio of financial health achievement is in accordance with applicable provisions and sufficient to overcome unexpected losses. d) The Company has capital management standards aimed at ensuring the Company has sufficient capital for all risks faced and implements the determined standards. e) The Company has a strategy that allows the Company to have sufficient access to additional funding.
Level of Risk to be Taken (Risk Appetite) and Risk Tolerance (Risk Tolerance)
The determination of the level of Risk to be taken and Risk tolerance for Funding Capital Risk (Capital Support) refers to the general implementation scope as referred to in item I.B.2.
Policies and Procedures
a) The policy must clearly contain the results of the assessment of the Financing Company's conditions against capitalization risk, liquidity, assets, operations, and the performance of the Financing Company. Measurement of financial health ratios includes:
(1) capitalization ratio;
(2) quality of financing receivables;
(3) profitability; and
(4) liquidity. b) The Company has ease of access to the capital market, shareholders, or affiliated parties in order to add capitalization. c) The Company has procedures for requesting additional capital. d) The Company has a policy regarding the utilization of profitability derived from investment and non-investment.
Limit
a) The Company must ensure consistency between various types of different limits. b) Limit setting can be established hierarchically for each level of the Company's organization, for example, overall limits, additional funding (capitalization) limits, financial health ratio limits, and funding capacity (capitalization) limits.
c. Adequacy of Risk Identification, Measurement, Monitoring, and Control Processes
In implementing Risk Management for Funding Capital Risk (Capital Support), in addition to implementing processes as referred to in item I.C, the Company needs to add the implementation of several things in each of the aforementioned processes, as follows:
d. Funding Capital Risk (Capital Support) Management Information System The implementation of the management information system for Funding Capital Risk (Capital Support) refers to the general implementation scope as referred to in item I.D. In addition, the Company needs to fulfill the following:
e. Comprehensive Internal Control System
In implementing Risk Management for Funding Capital Risk (Capital Support), in addition to implementing internal control as referred to in item I.E, the Company needs to have an internal control system for Funding Capital Risk (Capital Support) among others to ensure the Company's ability to generate profit, the Company's responsiveness to poor investment results, unexpected losses, and other unexpected events.
G. Financing Risk
Definition
a. Financing Risk is a risk that occurs due to the failure of debtors and/or other parties to fulfill obligations to the Financing Company. b. Sources of Financing Risk are the composition of financing receivable portfolios and high concentration levels, inadequate financing distribution strategies, low quality of financing receivables, inadequate reserve provisions made by the Company, and external factors that can impact the debtor's ability to fulfill their obligations.
Objective
The main objective of Risk Management for Financing Risk is to minimize the possibility of debtors and/or other parties failing to fulfill obligations to the Company.
Implementation of Risk Management
Implementation of Risk Management for Financing Risk for the Company must at least cover:
a. Active Supervision by the Board of Directors and Board of Commissioners In implementing Risk Management through active supervision by the Board of Directors and Board of Commissioners for Financing Risk, in addition to implementing active supervision as referred to in item I.A, the Company needs to add the implementation of several things in each aspect of active supervision by the Board of Directors and Board of Commissioners, as follows:
b. Adequacy of Policies, Procedures, and Limit Setting In implementing policies, procedures, and limit setting for Financing Risk, in addition to implementing policies, procedures, and limit setting as referred to in item I.B, the Company needs to add the implementation of several things in each aspect of policies, procedures, and limit setting, as follows:
Risk Management Strategy
a) Risk Management Strategy for Financing Risk must include strategies for all activities with significant Financing Risk exposure. The strategy must clearly contain the risk selection process, financing determination for consumers, and handling of non-performing financing. b) Risk Management Strategy for Financing Risk must facilitate consumers in fulfilling their obligations to the Company. c) The Company periodically evaluates factors from products assessed as part of Financing Risk. d) The Company implements strategies regarding business activities to be selected. e) Risk Management Strategy for Financing Risk is the consistency of financing distribution strategies or plans in accordance with risk appetite and risk tolerance. f) Risk Management Strategy for Financing Risk must align with the Company's objectives to maintain financing quality, profit, and business growth.
Level of Risk to be Taken (Risk Appetite) and Risk Tolerance (Risk Tolerance)
The determination of the level of Risk to be taken and Risk tolerance for Financing Risk refers to the general implementation scope as referred to in item I.B.2.
Policies and Procedures
a) In Financing Risk policies covering the implementation of Risk Management for Financing Risk for all of the Company's business activities, a framework for healthy funding provision and funding provision policies must be established, including policies and procedures for controlling Financing concentration Risk. The Company must have clearly established procedures for funding provision approval, including changes, updates, and refinancing. b) The Company must have policies and procedures to ensure that all funding provision is carried out in a controlled manner (arm's length basis). If the Company has policies that allow in certain conditions to carry out funding provision outside normal policies, then such policies must clearly contain criteria, requirements, and procedures including steps to control or mitigate Risk from the aforementioned funding provision. c) The Company must have policies and procedures to identify the existence of Financing concentration Risk. d) The Company must develop and implement policies and procedures appropriately so that it can:
(1) support healthy funding provision;
(2) monitor and control Financing Risk, including Financing concentration Risk; (3) correctly evaluate in utilizing new business opportunities; and (4) identify and handle problematic financing. e) The Company's policies must contain information needed in providing healthy financing, including among others financing objectives and payment sources, debtor Risk profile and its mitigation, and sensitivity level to economic and market condition developments, ability to repay, debtor's business ability and field of business conditions, and debtor's position in a specific industry, financing requirements submitted including agreements designed to anticipate changes in debtor Risk exposure in the future. f) The Company's policies also contain factors that need to be considered in the financing approval process, including among others:
(1) profitability level, including by conducting comprehensive estimated cost and revenue analysis, including estimated costs if default occurs, and capital requirement calculations.
(2) consistency in pricing, which is done by considering the Risk level, especially the debtor's overall conditions and the quality and ease of liquidation of collateral used as security. g) The Company must have procedures for financing analysis, approval, and administration, which among others contain:
(1) delegation of authority in funding provision decision-making procedures that must be clearly formalized; (2) separation of functions between those conducting financing analysis, approval, and administration within the framework of decision-making procedure delegation mechanisms for funding provision; (3) work units that conduct periodic reviews to determine or update the quality of financing exposed to Financing Risk; (4) development of financing administration systems, which include:
(a) efficiency and effectiveness of financing administration operations, including monitoring documentation, contract requirements, financing agreements, and collateral binding; (b) accuracy and timeliness of information provided for management information systems; (c) adequate separation of functions/tasks; (d) feasibility of controlling all back office procedures; and (e) compliance with written internal policies and procedures and applicable regulations. (5) The Company must account for, document, and update all quantitative and qualitative information and material evidence in financing archives used in conducting assessment and review. h) The Company maps the impact created by Financing Risk dominance on overall types of business activities. i) The Company provides educational opportunities to the Board of Directors and management to increase the Board of Directors' and management's understanding of Financing Risk. j) Formal Financing Risk monitoring procedures become part of the Company's framework and contain among others Risk Management strategy, and the Company's Risk Management procedures and policies.
k) Policies and procedures related to new products, including involving employees with adequate expertise and experience, and others.
l) The Company has policies and procedures related to the disbursement of financing.
m) The development of financing receivable types is adjusted to the Company's policies and procedures and applicable regulations.
n) The Company's policies and procedures provide a framework for conducting the process of identifying, measuring, monitoring, and controlling Financing Risk.
o) Policies and procedures that establish the roles and responsibilities of each function within the organization, including front office, credit recovery unit, middle office, back office, audit, and compliance functions.
p) Policies and procedures cover the establishment of direction regarding the diversification of the financing disbursement portfolio, considering target markets and overall strategy, including desired portfolio composition targets, exposure limits for counterparties, both individually and in groups, industries or economic sectors, geographical areas, and products to be issued.
a) The Company must establish limits for the provision and disbursement of financing that can increase Financing Risk.
b) The Company needs to apply Risk Tolerance for Financing Risk.
c) Limits for Financing Risk are used to reduce risks arising, including those from the types of business activities offered by the Company.
d) The reliability of the process for establishing exposure limits for debtors individually or in groups, which among others can be based on internal risk ratings established for such debtors, where debtors with better risk ratings can be granted higher exposure limits.
e) The adequacy of review procedures and their periodic implementation regarding the policy on establishing limits, which is conducted formally and well-documented.
f) The reliability of mechanisms to anticipate the occurrence of policy, procedure, and limit breaches/exemptions, among others through approval by higher authority holders, risk analysis, cost-benefit analysis, and well-documented.
c. Adequacy of the Process of Identification, Measurement, Monitoring, and Control of Risk
In implementing Risk Management for Financing Risk, in addition to carrying out the processes as referred to in item I.C, the Company needs to add the implementation of several items in each of the aforementioned processes, as follows:
a) The Company identifies the nature, type, and complexity of business activities, including financing disbursement.
b) In identifying Financing Risk, it is necessary to consider guidelines, regulations, procedures, and policies contained within the Company.
c) In identifying Financing Risk, factors that may affect the level of Financing Risk in the future must be considered, such as the possibility of changes in economic conditions and the occurrence of natural disasters.
d) The Company can identify Financing Risk among others through the composition of financing receivable portfolios and the quality of financing receivables.
e) The Company identifies Financing Risk by measuring problematic financing receivables, such as credit scoring analysis, migration analysis of financing receivable quality, or the use of other statistical models, in accordance with the type, volume, and complexity of Financing Risk.
f) In stress testing, it is necessary to identify things that may happen or potential changes in economic conditions in the future that can have negative effects on the Company's financing exposure and how the Company's ability to withstand such conditions.
In measuring Financing Risk, among others, indicators/parameters can be used in the form of comparisons between the ratio of financing receivables to total assets, the comparison of financing to core debtors to total financing, and the comparison of low-quality financing to total financing.
a) The work unit carrying out the Risk Management function for Financing Risk to monitor and report Financing Risk to the Company's Board of Directors both ad hoc when Financing Risk occurs and periodically.
b) The Company monitors the portfolio and global economic conditions as both can increase the likelihood of Financing Risk occurring.
c) The Company can monitor target markets by analyzing concentration risk based on economic sectors or portfolio categories using ratios, for example, the financing ratio per economic sector and the financing ratio per portfolio category.
d) The Company monitors Financing Risk using systems to monitor financing disbursement conditions, both for individual debtors and debtor groups, including monitoring based on portfolios to avoid concentration risk.
e) The adequacy of monitoring systems that allow for the early identification of problematic financing receivables to gain the attention of the Board of Directors and Board of Commissioners, including determining the adequacy of provisions.
f) The adequacy of monitoring systems regarding compliance with the Company's strategic direction and Financing Risk tolerance established by the Board of Directors and Board of Commissioners.
g) Adequacy of monitoring is conducted regarding compliance with established limits, including early identification of financing disbursements exceeding limits, and adequate escalation mechanisms.
h) Reporting systems that can convey information in a timely manner and adjusted to management needs, at minimum covering financing in arrears, problematic financing, watch list exposures, provisions formed, detailed risk profiles, portfolio risk concentration, and economic trends.
i) The Company monitors Financing Risk when:
(1) Most of the financing receivable exposures owned by the Company have high inherent risk, the ratio of exposure with nominal characteristics of each exposure is small, financing structure and terms & conditions are simple, most of the debtor's business is not exposed to external influences, and the level of dependence on the business cycle relative to total financing receivable exposure is between 40% and 50%.
(2) Most of the financing receivable portfolios owned by the Company consist of few financing disbursements with high amounts.
(3) Financing exposure to individual debtors or to groups of debtors affects the overall portfolio (ratio 30% - 40%).
(4) Financing exposure to related parties of the Company affects the overall portfolio (ratio 30 - 40%).
(5) Concentration of financing receivable exposure in economic sectors vulnerable to business cycle changes and economic conditions, such as manufacturing and transportation industries, is high (concentration between 30-40% of total financing receivable exposure).
(6) Concentration of financing receivable exposure in target markets vulnerable to business cycle changes and economic conditions, such as professionals or entrepreneurs, is high (concentration ≥30% of total financing receivable exposure).
(7) The growth rate of problematic financing (non-performing financing) owned by the Company is high, above the average industry growth rate for problematic financing.
(8) The ratio of low-quality financing receivables, i.e., low-quality receivables (including current restructured financing receivables) to total financing receivables owned by the Company is high (ratio <7%).
(9) The ratio of problematic financing receivables (NPF), i.e., problematic financing receivables to total financing receivables owned by the Company is high (ratio <5%).
(10) The ratio of total restructured financing to total financing receivables owned by the Financing Company is high (ratio <7%).
j) The Company conducts monitoring when liquidity, profitability, capital adequacy ratios, and the quality of financing receivables are below the minimum requirements of applicable regulations.
a) The Board of Directors and management monitor Financing Risk so that the Board of Directors and management know the current condition regarding the Financing Risk profile.
b) The Company updates procedures for establishing the quality of financing receivables and financing disbursement.
c) The Company determines the adequacy of provisions for the purpose of controlling Financing Risk.
d) The Company controls Financing Risk through recording the portfolios owned by the Company.
e) In the context of controlling Financing Risk, the Company conducts evaluations in the management of Financing Risk.
f) The reliability of control actions against Financing Risk and their consistency with the level of risk taken and risk tolerance. Generally, some control actions that can be taken include restructuring, loss provisioning, and other improvement steps, among others, reformulation of financing disbursement strategy, improvement of internal ratings.
g) The timeliness of control actions taken.
h) The clarity and accountability of those responsible for controlling Financing Risk.
i) Regarding the management of problematic financing receivables or those experiencing impairment, it is necessary to pay attention to the consistency and effectiveness of restructuring authority, for example, the suitability of financing structure, collection procedures including the possibility of collateral takeover, monitoring systems for restructured financing, formation of provisions, and documentation of restructured financing.
d. Financing Risk Management Information System
In implementing Risk Management for Financing Risk, in addition to implementing the management information system as referred to in item I.D, the Company also needs to implement the following:
The Risk Management information system for Financing Risk must be able to provide data that is accurate, complete, informative, timely, and reliable regarding the total number of debtors and reports on Financing Risk limit exemptions so that it can be used by the Board of Directors to identify the existence of Financing Risk;
The Company has a management information system that can ensure the integrity of data used in calculating liabilities;
The adequacy of the Risk Management information system to support the process of identifying, measuring, monitoring, and controlling Financing Risk, which allows the Board of Commissioners, Board of Directors, and all levels of management to perform supervisory functions, including determining the adequacy of the Company's capital adequacy ratio;
The management information system must be able to provide current and timely information regarding the level of Financing Risk to the Board of Commissioners, Board of Directors, and relevant officials in the implementation of Risk Management, and determine whether the Company's performance is aligned with the Financing Risk strategy established;
The information system allows relevant officials to analyze financing risk at the individual product and portfolio levels to identify specific sensitivities or concentrations. In this regard, the following must be considered:
a) the nature and characteristics of financing disbursement;
b) exposure profile until maturity linked to potential market changes; and
c) the existence of collateral or guarantees;
the potential for default based on internal risk rating;
the information system must ensure that exposures approaching established risk limits receive attention from management;
the adequacy of information coverage must be reviewed periodically by business line managers and the Board of Directors to ensure that existing information is appropriate for the Company's business complexity;
the information system can support reporting needs to supervisory authorities; and
management's commitment in allocating budgets for system development, as well as the pattern of information system development (in-house or through vendors), maintenance mechanisms, system modifications, and upgrades, including outsourcing mechanisms.
e. Comprehensive Internal Control System
In implementing Risk Management through the implementation of an internal control system for Financing Risk, in addition to implementing internal controls as referred to in item I.E, the Company also needs to implement the following:
an independent and continuous review system regarding the effectiveness of the implementation of the Risk Management process for Financing Risk, which at least contains an evaluation of the financing disbursement strategy process, the accuracy of the implementation of risk measurement methods or the assessment of risk levels, and the effectiveness of the implementation of work units or officers who monitor the Company's business activities or operations;
an internal review system by individuals independent of the Company's business units to help evaluate the overall business process;
an efficient and effective reporting system to provide adequate information to the Board of Commissioners, Board of Directors, and audit committee (if any); and
internal audit of the Financing Risk process is conducted periodically, which among others includes identifying whether:
a) business activities are aligned with established policies and procedures;
b) all authorizations are carried out within the guidelines provided; and
c) there are weaknesses in the Risk Management process for Financing Risk, policies and procedures, including any exemptions to policies, procedures, and limits.
Established in Jakarta on 14 April 2016
EXECUTIVE HEAD OF SUPERVISOR
OF INSURANCE, PENSION FUNDS,
FINANCING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY, signed
FIRDAUS DJAELANI
Copy matches the original
Legal Director 1
Legal Department signed
Yuliana
APPENDIX VIII
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.05/2016 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT AND SELF-ASSESSMENT REPORTS ON RISK MANAGEMENT IMPLEMENTATION FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
To
The Financial Services Authority u.p. Directorate of Financing Institution Supervision Menara Merdeka Building, 19th Floor Jl. Budi Kemuliaan I No. 2 Jakarta 10110
SELF-ASSESSMENT REPORT
ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR FINANCING COMPANIES YEAR … PT XYZ (Company Address)
SELF-ASSESSMENT REPORT
ON THE IMPLEMENTATION OF RISK MANAGEMENT FOR FINANCING COMPANIES Company Name :
Company Status : (1) Joint Venture (2) National Private (3) State-Owned Enterprise Assessment Date :
Report Position Date :
A. GENERAL INFORMATION
Shareholders or equivalent :
No. Name Ownership Value
(In Rupiah)
Ownership Percentage
1.
2. etc.
Board of Directors:
No. Name Position Term of Office
1.
2.
3. etc.
Board of Commissioners:
No. Name Position Term of Office
1.
2.
3. etc.
B. FINANCIAL INFORMATION OF THE FINANCING COMPANY Description Value (Thousand Rupiah)* Assets Financing Receivables Loans Equity Value Current Profit/Loss Capital Adequacy Ratio Equity to Paid-up Capital Ratio Financing to Asset Ratio (FAR) Non Performing Financing (NPF) Gearing Ratio Total Number of Debtors
C. SUMMARY OF GENERAL RISK MANAGEMENT IMPLEMENTATION
Active Supervision by the Board of Directors and Board of Commissioners
…………… (Filled with a description of the role of the Board of Directors and Board of Commissioners in Risk Management and the Risk Management organizational structure)
Adequacy of Policies, Procedures, and Risk Limit Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment)
Adequacy of the Process of Identification, Measurement, Monitoring, and Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control risk processes)
Risk Management Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management)
Comprehensive Internal Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company)
D. IMPLEMENTATION OF RISK MANAGEMENT FOR EACH TYPE OF RISK
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Strategic Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Strategic Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Strategic Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Strategic Risk)
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Operational Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Operational Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Operational Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Operational Risk)
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Asset and Liability Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Asset and Liability Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Asset and Liability Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Asset and Liability Risk)
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Governance Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Governance Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Governance Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Governance Risk)
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Management Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Management Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Management Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Management Risk)
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Capital Support Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Capital Support Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Capital Support Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Capital Support Risk)
Adequacy of Policies,
Procedures, and Risk Limit
Establishment
…………… (Filled with a description of risk appetite, risk tolerance, and risk limit establishment over Financing Risk)
Adequacy of Process
Identification, Measurement,
Monitoring, and
Control of Risk
…………… (Filled with a description of the identification, measurement, monitoring, and control processes over Financing Risk)
Risk Management
Information System
…………… (Filled with a description of how the company's information system supports the implementation of Risk Management over Financing Risk)
Comprehensive Internal
Control System
…………… (Filled with a description of how internal control including the compliance function is carried out by the company for Financing Risk)
Prepared by, Acknowledged,
(Signature) (Signature)
(Name) (Name)
(Position) (Position)
Established in Jakarta on 14 April 2016
EXECUTIVE HEAD OF SUPERVISOR
OF INSURANCE, PENSION FUNDS,
FINANCING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY, signed
FIRDAUS DJAELANI
Copy matches the original
Legal Director 1
Legal Department signed
Yuliana
APPENDIX IX
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 10 /SEOJK.05/2016 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF RISK MANAGEMENT AND SELF-ASSESSMENT REPORTS ON RISK MANAGEMENT IMPLEMENTATION FOR NON-BANK FINANCIAL SERVICE INSTITUTIONS
As regulated in Article 2 of Financial Services Authority Regulation Number 1/POJK.05/2015 concerning the Implementation of Risk Management for Non-Bank Financial Service Institutions (hereinafter referred to as LJKNB), LJKNB is required to implement Risk Management effectively, which at a minimum covers:
A. Active supervision by the Board of Directors and Board of Commissioners; B. Adequacy of policies, procedures, and the establishment of Risk limits;
C. Adequacy of the process for identifying, measuring, monitoring, and controlling Risk;
D. Risk Management information system; and
E. Comprehensive internal control system.
The Risk Management principles are elaborated as follows:
The Board of Directors and Board of Commissioners are responsible for the effectiveness of the implementation of Risk Management in insurance companies, reinsurance companies, pension funds, and financing companies that carry out all or part of their business with Sharia principles (hereinafter referred to as Sharia LJKNB). Therefore, the Board of Directors and Board of Commissioners must:
In the event that Sharia LJKNB is the main entity of a financial conglomerate, the active supervision by the Board of Directors and Board of Commissioners also includes supervision over the Risk Management of that financial conglomerate.
Matters that need to be considered in the implementation of active supervision by the Board of Directors and Board of Commissioners include the following:
b. The Board of Directors and Board of Commissioners must have a good understanding of the types and levels of Risk inherent in the business activities of Sharia LJKNB.
c. In supporting the implementation of Risk Management, the Board of Directors and Board of Commissioners must ensure that each operational unit in Sharia LJKNB implements Risk Management.
d. The Board of Directors is responsible for Risk assessment and capital adequacy.
e. The authority and responsibility of the Board of Commissioners, at a minimum, include:
directing and approving Risk Management policies, including strategies and Risk Management frameworks established in accordance with the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) of Sharia LJKNB;
evaluating Risk Management policies and strategies at least once a year or at more frequent intervals in the event of significant changes in factors affecting the business activities of Sharia LJKNB;
evaluating the accountability of the Board of Directors and providing improvement directions regarding the implementation of Risk Management policies periodically. Evaluations are conducted to ensure that the Board of Directors manages the activities and Risks of Sharia LJKNB effectively; and
establishing a risk monitoring committee tasked with assisting the Board of Commissioners in monitoring the implementation of Risk Management formulated by the Board of Directors.
f. The authority and responsibility of the Board of Directors, at a minimum, include:
formulating written and comprehensive Risk Management policies, strategies, and frameworks, including overall Risk limits and per Risk type, considering the Risk level to be taken and Risk tolerance according to the conditions of Sharia LJKNB, and calculating the impact of Risk on capital adequacy. After receiving approval from the Board of Commissioners, the Board of Directors establishes the aforementioned policies, strategies, and Risk Management frameworks;
formulating, establishing, and updating procedures and tools to identify, measure, monitor, and control Risk;
formulating and establishing transaction approval mechanisms, including those exceeding limits and authority for each level of position;
evaluating and/or updating Risk Management policies, strategies, and frameworks at least once a year or at more frequent intervals in the event of significant changes in factors affecting the business activities of Sharia LJKNB, Risk exposure, and/or Risk profile;
having adequate understanding of the Risks inherent in all business activities within Sharia LJKNB and being able to take necessary actions according to the Risk profile of Sharia LJKNB, including providing recommendations or proposals regarding the implementation of Risk Management to each operational unit in Sharia LJKNB;
establishing an organizational structure, including clear authority and responsibilities at each level of position related to the implementation of Risk Management;
being responsible for the implementation of Risk Management policies, strategies, and frameworks approved by the Board of Commissioners, and evaluating and providing directions based on reports submitted by operational units performing Risk Management functions, including reports on Risk profiles;
ensuring that all material Risks and their impacts have been followed up and submitting accountability reports to the Board of Commissioners periodically. Such reports include reports on the development and problems related to material Risks, along with improvement steps that have been, are being, and will be taken;
ensuring the implementation of improvement steps for problems or deviations in the business activities of Sharia LJKNB discovered by operational units performing internal audit functions;
developing a Risk Management culture, including Risk awareness at all levels of the organization, including adequate communication to all levels of the organization regarding the importance of effective internal controls;
ensuring adequate financial support and infrastructure to manage and control Risk;
ensuring that the Risk Management function has been implemented independently, reflected by:
a) the separation of functions between operational units performing Risk Management functions (identifying, measuring, monitoring, and controlling Risk) and operational units performing internal control functions; and
b) the implementation of Risk Management being free from conflicts of interest between operational units; and
In carrying out the responsibilities for implementing Risk Management regarding HR, the Board of Directors must:
a. establish clear HR qualifications for each level of position related to the implementation of Risk Management;
b. ensure the adequacy of the quantity and quality of existing HR in Sharia LJKNB and ensure that such HR understands their duties and responsibilities, whether for business operational units, units performing Risk Management functions, or supporting units responsible for implementing Risk Management;
c. develop employee recruitment, development, and training systems, including managerial succession plans and adequate remuneration to ensure the availability of competent employees in the field of Risk Management;
d. ensure the enhancement of competence and integrity of leaders, business operational unit personnel, Risk Management function unit personnel, and internal audit function unit personnel, considering factors such as adequate knowledge, experience/track record, and abilities in the field of Risk Management through continuous education and training programs, to guarantee the effectiveness of the Risk Management process;
e. place competent officials and staff in each operational unit according to the nature, volume, and complexity of the business activities of Sharia LJKNB;
f. ensure that officials and staff placed in each operational unit as referred to in letter e have:
understanding of the Risks inherent in each product/activity of Sharia LJKNB;
understanding of relevant Risk factors and market conditions affecting the products/activities of Sharia LJKNB, and the ability to estimate the impact of changes in those factors on the sustainability of Sharia LJKNB; and
the ability to communicate the implications of Sharia LJKNB's Risk exposure to the Board of Directors and committees performing Risk Management functions in a timely manner; and
g. ensure that all HR understand the strategies, Risk levels to be taken, and Risk tolerance, and the Risk Management framework established by the Board of Directors and approved/noted by the Board of Commissioners, and implement them consistently in the activities they handle.
In order to implement effective Risk Management, the Board of Directors of Sharia LJKNB establishes an organizational structure considering the following:
a. The organizational structure formulated must be accompanied by clear duties and responsibilities in general and regarding the implementation of Risk Management in all operational units, adjusted to the business objectives and policies, size, and complexity of the business activities of Sharia LJKNB.
b. The organizational structure must be designed to ensure that operational units performing internal control functions and operational units performing Risk Management functions are independent of the business operational units of Sharia LJKNB.
c. The organizational structure must be designed so that operational units performing Risk Management functions have direct access and reporting to the Board of Directors and/or Board of Commissioners, usually for the following matters:
assessment of Risk and Risk exposure positions, and steps to be taken to manage such Risk;
assessment of changes in the Risk profile of Sharia LJKNB;
assessment of established Risk limits (if applicable);
Risk Management issues related to strategy, such as corporate strategy, mergers and acquisitions, and investments; and
assessment of Risks that have occurred and identification of appropriate improvement actions for such Risks.
d. The head of the operational unit performing Risk Management functions must have the authority and obligation to inform the Board of Directors and/or Board of Commissioners of any events that may have a material impact on the Risk Management system of Sharia LJKNB.
e. The adequacy of the framework for delegating authority must be adjusted to the characteristics and complexity of business activities, the Risk level to be taken by Sharia LJKNB, and the experience and expertise of the personnel involved. Delegated authority must be reviewed periodically to ensure that such authority is in accordance with current conditions and the performance level of the relevant officials.
In addition to the above, active supervision from the Sharia Supervisory Board is required to be responsible for the compliance of Sharia LJKNB with Sharia principles in all business processes of Sharia LJKNB.
The authority and responsibility of the Sharia Supervisory Board are to carry out supervision duties and provide advice and suggestions to the Board of Directors so that the activities of Sharia LJKNB are in accordance with Sharia principles. The authority and responsibility of the Sharia Supervisory Board, at a minimum, include:
The implementation of effective Risk Management must be supported by a framework covering Risk Management policies and procedures, as well as clearly established Risk limits, in line with the vision, mission, and business strategy of Sharia LJKNB. The formulation of Risk Management policies and procedures is carried out considering, among other things, the type, complexity of business activities, Risk profile, and Risk level to be taken, as well as regulations established by the authority and/or healthy practices of Sharia LJKNB. In addition, the implementation of Risk Management policies and procedures owned by Sharia LJKNB must be supported by adequate capital and HR quality.
In order to control Risk effectively, the policies and procedures owned by Sharia LJKNB must be based on Risk Management strategy and supplemented with Risk tolerance and Risk limits. The establishment of Risk tolerance and Risk limits is carried out considering the Risk level to be taken (risk appetite), Risk tolerance (risk tolerance), and the overall strategy of Sharia LJKNB.
In the event that Sharia LJKNB is part of a financial conglomerate, policies, procedures, and risk limit establishment also include Risks arising from the interconnection between members of that financial conglomerate.
Matters that need to be considered in establishing the Risk Management framework, including policies, procedures, and limits, include the following:
a. Sharia LJKNB formulates Risk Management strategy in accordance with the overall business strategy, considering the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance).
b. Risk Management strategy is formulated to ensure that the Risk exposure of Sharia LJKNB is managed in accordance with internal policies and procedures of Sharia LJKNB, as well as applicable laws and regulations.
c. Risk Management strategy is formulated based on the following general principles:
Risk Management strategy must be long-term oriented to ensure the sustainability of Sharia LJKNB, considering economic conditions/cycles;
comprehensive Risk Management strategy can control and manage the Risk of Sharia LJKNB both individually and group-wide; and
achieve the expected capital adequacy accompanied by adequate resource allocation.
d. Risk Management strategy is formulated considering the following factors:
economic and industry developments and their impact on the Risk of Sharia LJKNB;
the organization of Sharia LJKNB, including the adequacy of HR and supporting infrastructure;
the financial condition of Sharia LJKNB, including the ability to generate profit, and the ability of Sharia LJKNB to manage Risks arising from changes in external and internal factors; and
the mix and diversification of products/business activities.
e. The Risk Management Policy of Sharia LJKNB links Risk Management with capital management (required capital and equity).
f. Risk Management Policy must link Risk Management with the objectives, strategy, and current conditions of Sharia LJKNB.
g. The Board of Directors must effectively communicate the Risk Management strategy to all operational units, managers, and relevant staff to be clearly understood.
h. The Board of Directors must periodically review the Risk Management strategy, including its impact on the financial performance of Sharia LJKNB, to determine whether changes to the Risk Management strategy of Sharia LJKNB are necessary.
a. The Risk level to be taken (risk appetite) is the level and type of Risk willing to be taken by Sharia LJKNB in order to achieve Sharia LJKNB's objectives. The Risk level to be taken is reflected in the business strategy and objectives of Sharia LJKNB.
b. Risk tolerance (risk tolerance) is the level and type of Risk set at a maximum by Sharia LJKNB. Risk tolerance (risk tolerance) is an elaboration of the Risk level to be taken (risk appetite).
d. The Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) of Sharia LJKNB must be considered in the formulation of Risk Management policies, including in the establishment of limits.
e. In establishing Risk tolerance (risk tolerance), Sharia LJKNB needs to consider the business strategy and objectives of Sharia LJKNB, as well as the ability of Sharia LJKNB to take Risk (risk bearing capacity).
a. Risk Management Policy is written direction in implementing Risk Management and must be in line with the vision, mission, and business strategy of Sharia LJKNB, and its formulation must be coordinated with related functions or operational units.
b. Risk Management Policy must describe the relationship between Sharia LJKNB's Risk tolerance limits, required capital needs, equity, and the processes and methods for Risk monitoring.
c. Policies and procedures must be designed and implemented considering the characteristics and complexity of business activities, the Risk level to be taken and Risk tolerance, Risk profile, and regulations established by the authority and/or healthy practices of Sharia LJKNB.
d. Sharia LJKNB must have procedures and processes to implement Risk Management policies. Such procedures and processes are formulated in implementation guidelines that must be reviewed and updated periodically to accommodate changes that occur.
e. Risk Management Policy must at a minimum contain:
the establishment of Risks related to products and transactions of Sharia LJKNB based on the results of Sharia LJKNB's analysis of Risks inherent in each product/business activity and transaction of Sharia LJKNB that have been and will be carried out according to the characteristics and complexity of the business activities of Sharia LJKNB;
the establishment of methods for identifying, measuring, monitoring, and controlling Risk, as well as Risk Management information systems to accurately assess Risk exposure for each product/business activity and transaction of Sharia LJKNB, as well as business activities of Sharia LJKNB;
the establishment of data to be reported, report formats, and types of information to be included in Risk Management reports so that they reflect Risk exposure considered in making business decisions while still observing prudence principles;
the establishment of authority and limit sizes hierarchically, including transaction limits requiring Board of Directors approval, and the establishment of Risk tolerance as the limit of potential losses that can be absorbed by the capital adequacy of Sharia LJKNB, and monitoring tools for the development of Risk exposure of Sharia LJKNB;
the establishment of risk values and risk levels as the basis for Sharia LJKNB to determine improvement steps for products/business activities, transactions of Sharia LJKNB, and specific business activity areas, and to evaluate the implementation results of Risk Management policies and strategies;
an organizational structure that clearly formulates the roles and responsibilities of the Board of Commissioners, Board of Directors, committees, Risk Management operational units, operational units, internal audit units, and other supporting operational units;
the establishment of an internal control system in the implementation of Risk Management to ensure compliance with applicable external and internal regulations, the effectiveness and efficiency of Sharia LJKNB's operational activities, the effectiveness of Risk culture at each level of the organization of Sharia LJKNB, and the availability of accurate, complete, timely, and useful management and financial information;
business continuity plan (BCP) or business continuity management policies regarding the worst possible external and internal conditions, so that the sustainability of Sharia LJKNB can be maintained, including disaster recovery plans and contingency plans.
The formulation of business continuity plans meets the following requirements, among others:
b) is flexible to respond to various unexpected and specific disruption scenarios, i.e., specific conditions and immediate required actions;
c) periodic testing and evaluation of business continuity plans; and
d. The Board of Directors must periodically update business continuity plans to ensure the effectiveness of the formulated business continuity plans.
f. Risk Management policies and procedures are adequately documented and communicated to all employees.
g. Risk Management policies owned by Sharia LJKNB include, among others, asset and liability management policies that clearly describe the determination of the nature of assets and liabilities, the role of asset and liability management activities, and the relationship between product development, valuation functions, and investment management.
h. Risk Management policies must be relevant to the types of Risks determined, both Risks related to business strategy and those related to the daily operations of Sharia LJKNB.
i. Risk Management policies must describe the relationship between Sharia LJKNB's tolerance limits, regulations regarding capital, capital, and Risk monitoring methods.
j. In the event that Sharia LJKNB is a Sharia insurance company, Risk Management policies include policies related to underwriting.
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.