2026-08-13
Added · Updated
Regulated institutions must establish comprehensive risk-management programmes, independent risk management functions, and effective management information systems. Boards must oversee risk strategies, approve policies, and demand periodic reports, while management ensures day-to-day activities align with risk appetite. Institutions must hold Basel II compliant capital, test risk measurement tools, and maintain internal controls with clear separation of duties. External auditors must monitor compliance and notify the Bank of breaches. Institutions must also produce sufficient public disclosures and submit Regulatory Credit Exposure Categorisation templates.
Get BOB alerts — same-day email on every new publication.
PAPER 2
BANK OF BOTSWANA
PRUDENTIAL AUTHORITY AND
PAYMENTS OVERSIGHT
DEPARTMENT
GUIDELINES ON RISK MANAGEMENT
Issue Date: 13 August 2026
Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
Contents
Guidelines on Risk Management
(b) Foreign Exchange-Risk Measurement............................................................. 45
(c) Stress-Testing on Foreign Exchange Positions................................................ 45
(d) Foreign Exchange-Risk Monitoring and Control ............................................ 46
(e) Internal Controls and Independent Audits....................................................... 46
(f) Foreign Exchange-Risk Reporting................................................................... 47
7. LIQUIDITY RISK MANAGEMENT................................................................... 48
(a) Fundamental principle for the management of liquidity risk........................... 48
(b) Governance of liquidity risk management....................................................... 49
(c) Measurement and Management of Liquidity Risk........................................... 52
(e) Contingency Planning...................................................................................... 67
(f) Stock of Liquid Assets..................................................................................... 70
(g) Public disclosure .............................................................................................. 71
8. OPERATIONAL RISK MANAGEMENT........................................................... 80
(a) Operational Risk Culture ................................................................................. 80
(b) Operational-Risk Identification and Measurement.......................................... 80
(c) Operational-Risk Monitoring, Control and Mitigation.................................... 82
(d) Operational-Risk Reporting ............................................................................. 85
(e) Business Resiliency and Continuity................................................................. 86
9. COUNTRY AND TRANSFER RISK ................................................................... 88
10. COMPLIANCE RISK MANAGEMENT............................................................. 90
(a) Compliance-Risk Identification ....................................................................... 90
(b) Compliance-Risk Measurement....................................................................... 90
(c) Compliance-Risk Monitoring, Control and Mitigation ................................... 91
(d) Compliance-Risk Reporting............................................................................. 93
11. REPUTATIONAL RISK MANAGEMENT ........................................................ 94
(a) Identification of Reputational Risk.................................................................. 94
(b) Measurement of Reputational Risk.................................................................. 95
(c) Monitoring, Control and Mitigation of Reputational Risk .............................. 95
(d) Reporting of Reputational Risk ....................................................................... 96
Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
Guidelines on Risk Management risk); or which have (iii) similar tenors and reference curves, but in different currencies (currency basis risk). (i) Board of Directors - The highest body of authority in a regulated institution responsible for the regulated institution’s business and risk strategy, organisational financial soundness and governance. The board also provides effective oversight of senior management. (j) Contagion effects: the advent of the spread of negative or positive consequences of a financial or economic nature across countries or regions. (k) Contingency Funding Plan - A compilation of policies, procedures, and action plans for responding to severe disruptions to a regulated institution’s ability to fund some or all of its activities in a timely manner and at a reasonable cost. (l) Counterparty risk: the risk that a party to a transaction or contract will fail to fulfil its contractual obligations. (m) Credit swaps: contracts where one side pays an ongoing fee in exchange for a guarantee that upon default the insurance will pay the full principal amount due to the contract owner. (n) Enterprise-wide risk management: is the overall management of risk that an organisation takes and holds to achieve its strategic objectives. It is the sum of the various risks the organisation takes in the various categories and focuses on optimising the balance and interaction of the different types of risks. (o) Expected credit losses (ECL): is the probability-weighted estimate of credit losses (i.e., the present value of all cash shortfalls) over the expected life of a financial instrument. (p) Exposure - The amount of a regulated institution’s exposure is calculated as follows:
(a) The sum of all loans and credit facilities granted, either directly or indirectly, to a person or group of inter-related persons, such as:
(i) term loans, overdrafts, credit lines and other credit facilities; (ii) trade bills discounted, invoice discounts and factoring; (iii) credit substitutes, such as guarantees, acceptances, letters of credit and bills, and finance lease receivables; (iv) underwriting of debt and equity securities, and other forms of participations; (v) securitised assets and other transactions with recourse; (vi) credit derivatives, futures and forwards, swaps and option contracts such as credit default swaps and other derivatives; and Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(vii) contingent liabilities, such as commitments to extend credit, performance bonds and warranties. (b) Less the amount by which the above-listed accommodations are irrevocably secured by:
(i) eligible financial collateral meeting all the requirements of the Directive on the Revised International Convergence of Capital Measurement and Capital Standards for Botswana (Basel II Directive) placed with a regulated institution that granted the accommodation; or (ii) an eligible guarantee meeting all the requirements of the Basel II Directive; and (iii) For a guarantee to be considered eligible, the following conditions must be satisfied:
(a) The credit protection must represent a direct claim on the protection provider; (b) The guarantee or credit derivative must be explicitly referenced to specific exposures or a pool of exposures, such that the extent of the credit protection is clearly defined and incontrovertible; (c) The credit protection contract must not contain any clause that:
(i) allows the protection provider to unilaterally cancel the protection; (ii) increases the effective cost of the protection, as a result of the deteriorating credit quality of the protected exposure; (iii) prevents the protection provider from being obliged to pay out in a timely manner, in the event that the original obligor fails to make any payments due; and (iv) allows the maturity of the credit protection to be reduced by the protection provider. (d) It must be legally effective and enforceable in all jurisdictions which are relevant at the time of the conclusion of the credit agreement; (e) In addition to the legal certainty requirements for a guarantee to be eligible, the following conditions must also be satisfied:
(i) Upon default or non-payment by a counterparty, a regulated institution must have the right to pursue, in a timely manner, the guarantor, for any monies due under the claim, in respect of which the guarantee is provided; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(ii) The guarantor must either make a lump sum payment of all monies due under the claim to the regulated institution or assume the payment obligations of the counterparty that was covered by the guarantee; (iii) A regulated institution must have the right to receive any such payments from the guarantor, without first having to take legal action in order to pursue the counterparty for payment; (iv) The guarantee must be an explicitly documented obligation assumed by the guarantor; (v) The guarantee must cover all types of payments the underlying obligor is expected to make in respect of the claim; and (vi) Where a guarantee covers payment of the principal only, interest and other amounts not covered by the guarantee must be treated as the uncovered portion. (q) Foreign exchange settlement risks: is the risk of loss when a regulated institution in a foreign exchange transaction pays the currency it sold, but does not receive the currency it bought. (r) Funding Liquidity Risk: The risk that the regulated institution will not be able to efficiently meet both the expected and unexpected current and future cash flows and collateral needs without affecting either daily operations and/or the financial condition of the regulated institution. (s) Haircut: The reduction applied to an asset value because of the perceived risk of the asset falling in value in an immediate cash sale or liquidation; it is expressed as a percentage. A haircut is a reflection that the value of an underlying asset is volatile. (t) Interest rate sensitivity gap: measures the responsiveness of the asset and liability portfolio to changes in interest rates. (u) Interest rate swaps: is an agreement to exchange one stream of interest payments for another. (v) Liquid Assets - Freely transferable assets, unencumbered by any charge or lien whatsoever, located in Botswana and are central bank eligible, including:
(i) Treasury bills, Bank of Botswana Certificates, and other securities issued by the Botswana government or the Bank and maturing within 370 days; (ii) Negotiable instruments of such types as the Bank may approve and payable within a period of 184 days; and Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(iii) Such other assets as the Bank may from time to time, approve, provided that they: (1) have distinct denominations of at least P1 000; (2) are listed and actively traded by an exchange in Botswana, if instruments of public issue; (3) disclose the earliest possible date that a borrower may pre-pay; (4) are rated no less than AA- by an external credit assessment institution acceptable to the Bank; and (5) are otherwise acceptable to the Bank in accordance with the requirements for the Secured Lending Facility. (w) Liquidity - The ability of a regulated institution to fund asset growth and/or meet contractual obligations as they fall due, including obligations to fund loan and investment commitments, deposit withdrawals and other maturing liabilities, without incurring unacceptable capital losses. (x) Liquidity Risk - The risk of loss to a regulated institution resulting from inability to meet actual needs for cash or inadequate liquidity levels, which must be covered by funds obtained at excessive cost. (y) Liquidity-Risk Management - The process of ensuring that the regulated institution’s needs for funds, including maintaining the required level of liquidity and meeting expected and contingent cash needs can be regularly met at a reasonable cost. (z) Management-action-trigger limits: represents the management's tolerance for accepting the market risk related losses on a daily and cumulative month-to-date basis, especially on the trading portfolio. (aa) Management information system (MIS): A computer system consisting of hardware and software that serves as the backbone of an organisation's operations. (bb) Mark-to-market: is a measure of the fair value of accounts that can change over time, such as assets and liabilities. (cc) Net Funding Requirements - The liquid assets necessary to fund a regulated institution’s cash obligations and commitments in future, determined by performing a cash flow analysis in which all cash inflows are measured against all cash outflows to identify potential net shortfalls. (dd) Open Position - the difference between a regulated institution’s total of its foreign currency-denominated assets and liabilities, both spot and forward, in Pula currency (equivalent) balances. (ee) Optionality risk: refers to the risk that arises from price movements in instruments that are either automatic or behavioral to changes in interest rates. (ff) Regulated institution: bank or deposit-taking institution. (gg) Rehypothecate: Rehypothecation occurs when a regulated institution uses an asset, supplied as collateral on a debt by a borrower, and applies its value to cover its own obligations. In order to do so, the regulated institution may have access to Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management a variety of assets promised as collateral including tangible assets and various securities. (hh) Related Person - Includes all of the following without limitations: (1) Significant shareholder; (2) member of a board of directors or audit committee; (3) principal officer and senior management officials, (4) guarantor of a trust; (5) A person who maintains a trust on behalf of a regulated institution or its affiliate; (6) Any person who is related to such significant shareholder, member of a board of directors or audit committee, principal officer or family member or business interest; (7) subsidiary of a regulated institution; (8) company or undertaking in which at least a 5 percent interest is held by a regulated institution; (9) parent company of a regulated institution; (10) company that is under common control with a regulated institution; and (11) A company that holds at least a 5 percent interest of another company in which a regulated institution holds at least a 5 percent interest. (ii) Risk transfer: risk transfer is a risk management and control strategy that involves the contractual shifting of a pure risk from one party to another. (jj) Senior Management Official - Any person who is an officer of a regulated institution including those holding positions of managing director or chief executive officer (and deputies), chief financial or operations officer, chief lending officer, chief internal auditor, chief treasury officer (or their equivalents), and other heads of department (core banking functions) and/or others who are in a policymaking position. (kk) Stop loss: an advance order to sell an asset when it reaches a particular price point. It is used to limit loss or gain in a trade. (ll) Stress testing - is a generic term often used to describe various techniques and procedures employed by regulated institutions to gauge their potential vulnerability to exceptional but plausible events. Stress testing alerts regulated institution management to adverse unexpected outcomes related to a variety of risks and provides an indication of how much capital might be needed to absorb losses should large shocks occur. (mm)Swap: is a derivative contract through which two parties exchange financial instruments. (nn) Syndicated loans - credits granted by a group of regulated institutions to a borrower. (oo) Trade financing: is the financing and facilitation of trade of goods and services, locally and internationally. (pp) Trading book - a trading book consists of positions in financial instruments or commodities held either with a trading intent or in order to hedge other elements of the trading book. (qq) Unencumbered - Not pledged either explicitly or implicitly as security, collateral, guarantee and/or other credit-enhancement for any transaction. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(rr) Unexpected losses: Losses above expected levels.
(ss) Value at risk (VaR): is a method of calculating financial risk based on a defined probability level. It indicates the potential loss of a position/asset over a period of time with a given level of confidence. (tt) Yield curve risk: is a risk that arises when unanticipated shifts of the yield curve have adverse effects on a regulated institution’s income or underlying economic value. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
3. INTRODUCTION
3.1 Risk-taking is inherent in banking business. Excessive and poorly managed risk can,
however, lead to losses and thus pose a threat to the safety and soundness of a regulated institution. Therefore, the Bank places emphasis on the adequacy of a regulated institution’s management of risk and issues these Guidelines for the purpose of providing guidance to all regulated institutions on minimum standards and requirements for sound and effective management procedures and systems to be in place at every regulated institution.
3.2 For the purpose of these Guidelines, risk in a regulated institution refers to the possibility
that the outcome of an action or event could bring adverse impact on solvency, earnings, cash or, in general, sustainability of a regulated institution’s operations. Such outcomes could result in either direct diminution of a regulated institution’s earnings, or erosion of capital, loss of cash, or cash flow, or the imposition of constraints on a regulated institution’s ability to meet business objectives. These constraints could hinder a regulated institution’s capability to conduct business in a safe and sound manner, including the ability to effectively take advantage of opportunities that could enhance performance. As such, the board of directors (board) and senior management officials (Management) of a regulated institution are expected to ensure that the risk a regulated institution is taking is understandable, measurable, controllable and within a regulated institution’s capacity to readily withstand adverse effects.
3.3 Effective risk management is core to the success of every regulated institution and
encompasses all activities that affect a regulated institution’s risk profile. The board and Management of a regulated institution should put in place appropriate systems and infrastructure to identify, measure, monitor, control and report overall risks that a regulated institution may assume.
3.4 These Guidelines are aligned to the Basel Core Principles for Effective Banking
Supervision. Core Principle 15 on ‘risk management processes’ requires regulated institutions and banking groups to have comprehensive risk management processes (including effective board and senior management oversight) to identify, evaluate, monitor and control or mitigate all material risks, and to assess a regulated institution’s overall capital adequacy in relation to the risk profile. Risk-taking should be commensurate with the nature, size and complexity of a regulated institution and the degree of a regulated institution’s risk appetite and tolerance level. The risks a regulated institution may be exposed to depend on factors such as business activities, nature and type of products, business cycle, economic sectors, geographic location, business model and, in general, operating strategy.
3.5 These Guidelines are not intended to prescribe a uniform set of risk-management
strategies for all regulated institutions. The sophistication of processes, systems and internal controls for risk management is determined by the nature, size and complexity of the business activities of a regulated institution.
3.6 The guidance expressed in these Guidelines is not exhaustive; other relevant regulatory
requirements and applicable industry standards should also be taken into account as appropriate. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(a) Types of Material Banking Risks
3.7 The Bank assesses inherent risks using the expected impact on the supervised regulated
institution’s earnings, liquidity, capital, and, more broadly, set goals/objectives. Quantitative and qualitative factors are applied in the process of risk assessment. These Guidelines highlight some of the risks inherent in banking business as follows:
(i) Strategic Risk;
(ii) Credit Risk;
(iii) Market Risk;
(a) Interest Rate Risk;
(b) Foreign Exchange Risk;
(iv) Liquidity Risk;
(v) Operational Risk;
(vi) Country and Transfer Risk;
(vii) Compliance Risk; and
(viii) Reputational Risk.
3.8 These risks are intertwined; hence they should be managed in an integrated manner
(enterprise-wide risk management).
(b) Risk Management Process
3.9 Each regulated institution must prepare a comprehensive risk-management programme
(RMP) tailored to its needs and circumstances. The RMP should be reviewed at least annually. The RMP should, at the minimum, include the following elements:
(i) Risk Identification
3.10 In order to properly manage risk, a regulated institution must recognise and understand
risks that may arise from both existing and new business initiatives (interest rate processes, products, delivery channels, etc.). For example, risks inherent in a lending activity include credit, liquidity, interest rate and operational risks. Risk identification should be a continuing process, and should be understood at both transactional and portfolio levels. (ii) Risk Measurement
3.11 Risk should be measured accurately and timely in order to determine the impact on the
regulated institution’s profitability and capital. Risk measurement tools should be tested periodically for accuracy. Good risk-measurement systems assess the risks of both individual transactions and portfolios.
3.12 Where a regulated institution uses models to measure components of risk, such a
regulated institution should ensure that the board and Management understand the limitations and uncertainties relating to the output of the models and the risks inherent in their use. In addition, the output of such models should be a reasonable reflection of the risks assumed. A regulated institution should perform regular and independent validation; and testing of the models used. For example, an internal credit risk-rating Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management system and/or modelling should be validated using well-established external rating system/methodology. (iii) Risk Monitoring
3.13 A regulated institution should put in place an effective management information system
(MIS) to monitor risk levels and facilitate the timely review of risk positions and exceptions. Monitoring reports should be frequent, timely, accurate and informative. Such reports should be distributed to appropriate individuals for implementation, to be specifically identified in the regulated institution’s procedures. (iv) Risk Mitigation and Control
3.14 A regulated institution should establish and communicate risk limits through policies,
standards, and procedures which define responsibility and authority. These limits should serve as a means to control exposure to various risks associated with the regulated institution’s activities; they should have a process to authorise and document exceptions or changes to risk limits when warranted. A regulated institution may also apply various mitigating tools in minimising exposure to various risks. (c) Basic Elements of a Sound Risk Management System
3.15 A sound risk-management system should, at a minimum, have the following key
elements:
Guidelines on Risk Management
Management implements the procedures and controls necessary to comply with adopted policies.
3.18 Management is responsible for ensuring that the day-to-day activities of a regulated
institution are consistent with the regulated institution’s risk strategy. This includes risk appetite and policies approved by the board; establishing and communicating a strong awareness of an effective internal control environment and high ethical standards; as well as establishing clear guidance regarding the business and risk strategy such as risk limits, in order to ensure that activities undertaken by a regulated institution are within the risk appetite prescribed by the board of the regulated institution. (ii) Adequate Policies, Procedures, and Limits
3.19 The board and Management of a regulated institution should tailor the risk-management
policies and procedures to the types of risks that arise from the activities of the regulated institution. The regulated institution's policies and procedures should provide detailed guidance for the day-to-day implementation of broad business strategies and, generally, include limits designed to shield the regulated institution from excessive and imprudent risks. Senior management is expected to modify these tools when necessary to respond to changes in a regulated institution's activities or business conditions.
3.20 Every regulated institution should ensure that:
Guidelines on Risk Management
Guidelines on Risk Management
Guidelines on Risk Management
(e) Risk Disclosures
3.29 A regulated institution should make sufficient public disclosures that would allow
stakeholders to determine whether it identifies, assesses, monitors and controls/mitigates risks effectively. The amount and type of disclosures should correspond with the size, risk profile and complexity of the regulated institution’s operations, and evolving industry practices. The disclosures must include, at least, the following elements:
(i) A formal disclosure policy approved by the board of directors, which addresses the regulated institution’s approach to determining what risk disclosures it will make and the internal controls over the disclosure process; (ii) Implement a process for assessing the appropriateness of the regulated institution’s disclosures, including the verification and the frequency of the disclosures. The disclosures should be consistent with how senior management and the board assess and manage the risk of the bank; and (iii) The public relations function of the regulated institution or its designate should manage the communication of information to the market, so that it either builds reputation or minimises the impact of adverse reputation risk events. It should also be responsible for monitoring a regulated institution’s reputation within the market place. Depending on the nature, size and complexity, and the risk profile of a regulated institution, the specifics of the governance structure of the public relations function may vary.
3.30 These risk-management disclosures must, at a minimum, meet the requirements under
Pillar III of Basel II.
(f) Risk Capital
3.31 Consistent with the Basel II Directive, a regulated institution must hold Basel II
compliant capital to cushion all risks.
3.32 In addition, a regulated institution must ensure that well-defined processes are in place to
assess its capital adequacy in relation to its risk profile. Based on the material risks identified, a regulated institution should assess its overall capital adequacy, and develop a strategy for maintaining capital levels consistent with its risk profile and business plans. This should be reflected in a regulated institution’s capital planning process and the setting of internal capital targets. The capital planning process must be dynamic and forward-looking in relation to a regulated institution’s risk profile. In addition, a regulated institution should have a robust system for the continuous monitoring and reporting of risk exposures, and assess how its changing risk profile affects its capital.
3.33 For risks that are not easily quantifiable or related to capital, focus should be directed at
ensuring the effectiveness of their management and mitigation. Adequate systems and processes for managing these risks should be put in place and implemented effectively, with consideration for providing appropriate capital for any residual risks that cannot be reduced to satisfactory levels. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(g) Supervisory Expectations
3.34 In the discharge of their functions, supervisors shall apply a risk-based supervisory
approach to assess risk in a broader context than that reflected by the balance sheets of individual regulated institutions. That is, the supervisory “risk perimeter” shall extend beyond accounting consolidation concepts. In this regard, when compiling a regulated institution’s risk profile, the supervisor should consider risks arising from within an individual regulated institution (solo perspective), from its associated entities (banking group and group-wide basis) or from the prevailing macroeconomic environment. This is in line with the requirements of Principle 15 of the Basel Core Principles for Effective Banking Supervision, that requires the supervisor to develop and maintain a forwardlooking assessment of the risk profile of individual banks and banking groups, proportionate to their systemic importance; as well as to identify, assess and address risks emanating from regulated institutions.
3.35 Consistent with the Basel II Directive, the supervisor shall ensure that regulated
institutions periodically disclose to the market their risk-management practices to promote and maintain public confidence. Such risk disclosure and transparency will allow market participants to understand more fully a regulated institution’s risk profile and thereby reduce market uncertainties about the regulated institution’s financial strength. (h) External Auditors
3.36 Consistent with the requirements of the Banking Act, relevant accounting standards and
international best practice and Guidelines on banks’ audit committees, annual independent external audit and publication of audited financial statements, a regulated institution’s external auditor should monitor its compliance with the requirements of these guidelines. Where there is a breach or non-compliance, such auditor must notify the Bank as soon as practical. Furthermore, the auditor should always communicate in writing to those charged with governance all significant audit findings and reportable matters, including poor risk management practices. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
4. STRATEGIC RISK MANAGEMENT
4.1 Strategic risk is a possible source of loss that might arise from the pursuit of an
unsuccessful business plan. For example, strategic risk might arise from making poor business decisions, from the substandard execution of decisions, from inadequate resource allocation, or from failure to respond adequately to changes in the business environment.
4.2 Strategic risk can arise from either internal or external risk factors. Internal factors are
under the control of the regulated institution and can affect or deter the implementation of the strategic plan. Such factors include the organisational structure; culture, work processes and procedures; personnel; and information and technology. External risk factors are factors which the regulated institution has minimal or no control over and can also affect or deter the realisation of the goals determined in the strategic plan. Such factors may include competition; change of target customers; technological changes; economic factors and regulations. (a) Strategic Planning Process
4.3 A regulated institution should put in place a strategic plan, which should be supported by
a realistic budget. A strategic plan clarifies a regulated institution’s overall purpose, defines goals and priorities and determines practical approaches for achieving targeted priorities. Therefore, it should encompass the following:
(i) support or participation of the board, delegated committees, senior management and staff from various departments; (ii) adequacy of information in developing assumptions in relation to economic factors, technological changes, changes in law, position of the regulated institution compared to competitors, current competitive position, future market trends and customer needs, among others; (iii) consistency of the operational plans with the overall objective of a regulated institution; (iv) assessment of actual performance against strategic plans; and (v) a regulated institution should periodically evaluate actual performance against the strategic plan in order to monitor and adjust its plans appropriately. The evaluation should be measurable, and with adequate frequency. (b) Strategic Risk Identification
4.4 Identification and measurement of strategic risk can be determined through strategic
planning and the preparatory process of a strategic plan. Both the strategic plan and the operational plan, as well as the budget, should be consistent with the business scope, complexity, external environment and internal factors of the regulated institution, including the size and resources. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
4.5 The strategic risk management policy should provide general guidelines to strategic risk
management. The policy should contain at least the following: definition of strategic risk; sources of strategic risk; risk mitigation factors and a regulated institution’s accepted tolerance for strategic risk exposure.
4.6 Management should fully participate and carefully decide on the basis of information that
business and strategic plans are feasible and appropriate. Management should ensure good communication and cooperation between all employees and departments involved in the strategic planning process. (c) Strategic Risk Measurement
4.7 A regulated institution should establish and maintain a management information system
(MIS) which enables the board to identify and measure the risks associated with the regulated institution’s strategic plan. The level of sophistication of the system should depend on the nature, scale and complexity of the business segments within the business plan of a regulated institution. The MIS should enable Management to monitor:
(i) current and forecast economic conditions;
(ii) current and forecast industry and market conditions; (iii) exposure to different sectors and associated sector risks; and (iv) mechanisms that are in place to identify exceptions to limits and guidelines, and corrective action required. (d) Strategic Risk Mitigation, Monitoring and Control
4.8 A regulated institution needs strong internal control systems to ensure that it is not unduly
exposed to strategic risks. Hence, a regulated institution should adopt and implement robust strategic risk mitigation measures and techniques to enhance the achievement of strategic objectives. These include engaging requisitely qualified and experienced board and Management, formulation of strategic and operational plans, high quality personnel and proper training, comprehensive risk-management systems and adequate access to information, as well as timely and efficient introduction of new products or services. Internal controls should ensure that:
(i) a regulated institution’s structure establishes clear lines of authority; (ii) a regulated institution’s systems and structures provide for business continuity planning; and (iii) the process of setting up and reviewing strategic and business plans are comprehensive and carefully adhered to.
4.9 Internal and external audits are integral to the implementation of a risk-management
process to control risk associated with a regulated institution’s business strategy. To carry out their function effectively, Internal Auditors should have appropriate skills, knowledge and authority as well as independence within a regulated institution to ensure that senior management reacts to and acts upon their recommendations.
4.10 A regulated institution’s internal audit function should, among other things, perform
periodic checks on whether the strategic risk-management system is properly Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management implemented and the established policies and control procedures in respect of risk management are complied with. (e) Strategic Risk Reporting
4.11 The reporting of strategic risk should be entrusted to an independent functional unit
within a regulated institution. Reporting could be in the form of performance reporting, on-going monitoring and/or appraisal to the board.
4.12 In order to enable effective risk reporting, the board and senior management should
ensure the availability of information systems which can identify and measure strategic risk in an accurate, reliable and regular manner. The information systems should be able to provide information required to support implementation of a regulated institution’s strategic plans. Therefore, the information systems should be able to collect financial, accounting and other data, such as data on economic conditions, competition, technology and regulatory requirements. Furthermore, to remain effective, a regulated institution should review its MIS regularly and subject it to regular upgrades and modification.
4.13 Reporting should be done, at least once a year; in order to provide timely and adequate
information to judge the changing nature of the regulated institution’s strategic risk profile and evaluate compliance with the stated policy objectives and constraints. This notwithstanding, any material changes of information on a regulated institution’s strategic risk profile or other items of the strategic plan prone to rapid change must be reported in the interim. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
5. CREDIT RISK 2
5.1 This section provides guidance on sound practices in credit risk management. While the
principles contained in this section are, in the main, applicable to the business of lending, should be applied to all activities where credit risk is present.
5.2 Credit risk is defined as the risk that a counterparty will fail to perform fully its financial
obligations, or the potential that a regulated institution borrower or counterparty will fail to meet its obligations in accordance with agreed terms. It could arise from multiple activities, such as default of loan or bond obligation, or from the guarantor, credit enhancement provider or derivative counterparty failing to meet its obligations. Credit risk also includes credit concentration risk and insider lending.
5.3 The goal of credit risk management is to maximise a regulated institution’s risk-adjusted
rate of return by maintaining credit risk exposures within acceptable parameters. A regulated institution needs to manage the credit risk inherent in the entire portfolio, as well as the risk in individual credits or transactions. The effective management of credit risk is a critical component of a comprehensive approach to risk management and is essential to the long-term success of any banking organisation.
5.4 For most regulated institutions, loans are the largest and most obvious source of credit
risk. However, other sources of credit risk exist throughout the activities of a regulated institution, including in the banking book and trading book, and both on and off-balance sheet items. For example regulated institutions face credit risk (or counterparty risk) in various financial transactions other than loans, including on inter-bank transactions, trade financing, foreign exchange transactions, financial futures, swaps, bonds, equities, options, and in the extension of commitments and guarantees, and the settlement of transactions.
5.5 The sound practices for the effective management of credit risk set out in this section
addresses the following areas:
(a) Credit risk management, policies and procedures; (b) Credit risk identification and measurement; (c) Credit risk monitoring and control; and (d) Credit risk reporting. (a) Establishing an Appropriate Credit Risk Environment
5.6 A regulated institution should formulate and implement a structured credit risk
management strategy, which will include credit-risk policies and related processes. The strategy should be approved and reviewed regularly (at least annually) by the board of directors. The strategy and policies should cover the various activities of the regulated institution in which credit exposure is a significant risk and should reflect the regulated institution’s risk appetite, risk profile and capital strength. 2 Reference Documents: Guidelines on the Revised International Convergence of Capital Measurement and Capital Standards for Botswana (Basel II) (September 8, 2015); Basel Core Principles for Effective Banking Supervision (September 2012) (Principles 17, 18, 19, 20 and 21); Principles for the Management of Credit Risk (September 2000). Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
5.7 The credit-risk strategy should establish the objectives for assuming, identifying,
measuring, monitoring, reporting and controlling or mitigating credit risk.
5.8 Sound credit risk management involves managing the risk and reward relationship and
controlling and minimising credit risk across a wide spectrum, such as exposure type, economic sector, geographical location, currency, maturity, target markets, desired portfolio mix and anticipated profitability. This might also include identification of target markets and other desirable outcomes such as levels of diversification and concentration tolerance.
5.9 A regulated institution’s comprehensive credit risk management programme should:
(a) identify existing or potential credit risks to which the regulated institution is exposed in conducting its business activities and developing and implementing sound and prudent credit policies to effectively manage and control these risks; (b) develop and implement effective credit granting, documentation and collection processes; and (c) develop and implement comprehensive procedures to effectively monitor and control the nature, character and quality of the credit portfolio.
5.10 The Management of a regulated institution should implement the credit strategy approved
by the board of directors. The board should ensure that senior management is fully capable of managing the credit activities conducted by the regulated institution and that such activities are effected based on the risk strategy, policies and tolerance levels approved by the board.
5.11 The senior management of a regulated institution should develop policies and
procedures for identifying, measuring, monitoring and controlling credit risk. The policies should be designed and implemented in the context of internal and external factors such as the regulated institution’s level of capital, management and staff capabilities, credit needs in the regulated institution’s market area, anticipated future growth and technology.
5.12 Policies and procedures that are properly developed and implemented should enable the
regulated institution to:
(a) maintain sound credit-granting standards;
(b) identify, measure, monitor and control credit risk at both individual and portfolio levels; (c) properly evaluate new business opportunities; and (d) identify and administer problem credits.
5.13 For a regulated institution’s credit policy to be considered adequate, it should, at a
minimum, address the following:
(i) types of credit offered by the regulated institution, by exposure type (commercial, consumer, real estate, etc.), economic sector, geographic location, currency, maturity, target markets and desired portfolio mix; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(ii) guidelines which, at a minimum, address the goals for portfolio mix and risk diversification, and the regulated institution’s plans for monitoring and taking appropriate corrective action, if deemed necessary, on any concentrations that may exist; (iii) detail the structure of the credit approval authority and process, approval limits and approval lending authority of each loan officer, management or board credit committee, including procedures for granting exceptions; (iv) responsibility of the board of directors in reviewing, ratifying or approving loans; (v) indicate acceptable collateral and terms and conditions under which unsecured loans would be granted; (vi) terms and conditions for both price and non-price related items, including maturity and payment structure, interest rate, fees and collateral; (vii) limitations on the maximum volume of credits, individually and by exposure type; (viii) credit documentation, monitoring and classification; (ix) appropriate and adequate collection procedures, including, but not limited to, actions to be taken against borrowers who default; and (x) reporting and internal communication of exceptions.
5.14 A regulated institution should provide a system to conduct credit risk management under
Directive on the Revised International Convergence of Capital Measurement and Capital Standards for Botswana (Basel II) in a manner suited to the risk management approach it has adopted. (b) Credit Risk Identification and Measurement
5.15 A regulated institution should have methodologies that enable it to quantify the risk
involved in exposures to individual borrowers or counterparties. A regulated institution should use measurement techniques that are appropriate to the complexity and level of the risks involved in its activities, based on robust data, and subject to periodic validation (e.g., externally validated internal rating model).
5.16 A regulated institution should have objective and precise statistical techniques, such as
value at risk, for the measurement of credit risk quantity. A regulated institution should also be able to analyse credit risk at the product and portfolio level, in order to identify any particular sensitivities or concentrations.
5.17 A regulated institution should have a management information systems (MIS) and
analytical techniques that enable Management to measure the credit risk inherent in all on and off-balance sheet activities. The MIS should provide adequate information on the composition of the credit portfolio, including identification of any concentrations of risk. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
5.18 The regulated institution’s information system should be able to aggregate credit
exposures to individual borrowers and counterparties by type, economic sectors, country, geographical area and currency.
5.19 The regulated institution’s MIS should monitor actual exposures against established
limits and all exposures should be included in a risk-limit measurement system. The exposures approaching risk limits should be brought to the attention of senior management. Exceptions to credit-risk limits should be reported to senior management, on a meaningful and timely basis.
5.20 The measurement of credit risk should take into account:
(i) the specific nature of the credit (loan, derivative, overdraft, etc.) and its contractual and financial conditions (maturity, reference rate, etc.); (ii) the exposure profile until maturity in relation to potential market movements; (iii) the existence of credit risk mitigants, such as collateral or guarantees; and (iv) the potential for default based on the internal credit risk rating.
5.21 A regulated institution should periodically employ stress testing and back testing in
evaluating the quality of its credit risk-assessment models and establish internal tolerance limits for differences between expected and actual outcomes; and have processes for updating limits, as conditions warrant. The validation of internal credit risk assessment models should be subject to periodic review by qualified, independent individuals (e.g., internal, external auditors and financial institution supervisors):
5.22 Stress testing of the credit portfolio should involve identifying possible events or future
changes in economic conditions that could have unfavourable effects on a regulated institution’s credit exposures and assessing the regulated institution’s ability to withstand such changes. Three areas that a regulated institution could usefully examine are:
(a) economic or industry downturns (both in the whole economy and in particular sectors); (b) market risk events (interest rate risk and foreign exchange risk); credit-risk events higher than expected levels of delinquencies and defaults; and (c) liquidity conditions.
5.23 Stress testing could range from relatively simple alterations in assumptions about one
or more financial, structural or economic variables to the use of highly sophisticated financial models.
5.24 The output of the tests should be reviewed periodically by senior management and
appropriate action taken in cases where the results exceed agreed tolerances. Stress-test analyses should include contingency plans regarding actions management might take Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management given certain scenarios. The output should also be incorporated into the process for assigning and updating policies and limits. Credit Granting Processes
5.25 A regulated institution should operate within sound, well-defined credit-granting criteria.
These criteria should include a clear indication of the regulated institution’s target market and a thorough understanding of the borrower or counterparty as well as the purpose and structure of the credit and its source of repayment.
5.26 A regulated institution’s credit-granting approval process should establish accountability
for decisions taken and designate who has the absolute authority to approve credits or changes in credit terms. Approval authorities should be commensurate with the expertise of the individuals involved.
5.27 Each regulated institution should develop a clear understanding of the credit risk involved
in more complex credit-granting activities. For example, loans to certain industry sectors, asset securitisation, customer-written options, credit derivatives (e.g., credit swaps, interest rate swaps) and credit-linked notes.
5.28 All extensions of credit should be made free of conflict of interest and on an arm’s-length
basis. Extensions of credit should be made subject to the criteria and processes described in the regulated institution’s credit granting process.
5.29 Material transactions 3 with related parties should be subject to the approval of the board
(excluding board members with conflict of interest), and in certain circumstances (e.g., a large loan to a major shareholder) reported to the Bank.
5.30 A regulated institution that participates in loan syndications or other such loan consortia
should not place undue reliance on the credit risk analysis done by the lead underwriter or on external commercial loan credit ratings. All syndicate participants should perform their own due diligence, including independent credit risk analysis and review of syndicate terms prior to committing to the syndication. Each regulated institution should analyse the risk and return on syndicated loans in the same manner as directly sourced loans.
5.31 A regulated institution could utilise techniques to mitigate credit risk consistent with the
standardardised approach for credit risk as outlined in Annexure 3 of the Basel II Directive. Transactions should, however, be entered into primarily on the strength of the borrower’s credit worthiness and ability to repay the facility in accordance with the agreed terms. Collateral should neither be a substitute for a comprehensive assessment of the borrower or counterparty nor should it compensate for insufficient information. A regulated institution should have policies covering the acceptability of various forms of collateral, procedures for the ongoing valuation of such collateral and a process to ensure that collateral is, and continues to be, enforceable and realisable. With regard to guarantees, a regulated institution should evaluate the level of coverage being provided in relation to the credit quality and legal capacity of the guarantor. 3 Refer to Section 17 of the Banking Act Cap. 46:04 and Banking Regulation 9 for material transactions. Also refer to Guidelines on Transactions with Related Parties and Guidelines on Large Exposures Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(c) Credit Risk Monitoring and Control
5.32 A regulated institution should develop appropriate credit limits, consistent with the
regulated institution’s risk appetite, risk profile and capital strength which are understood by, and regularly communicated to all relevant staff. Limits should be defined in line with the Guidelines on Large Exposures and a regulated institution must ensure that it complies with these guidelines.
5.33 A regulated institution should have procedures to identify situations where, in
considering credits, it is appropriate to classify a group of obligors as connected counterparties and, thus, as a single borrower. This would include aggregating exposures to a group of accounts exhibiting financial interdependence, including corporate or non-corporate, where they are under common ownership or control or with strong connecting links. A regulated institution should have procedures for aggregating exposures to individual clients across business activities.
5.34 A regulated institution should establish overall credit limits at the level of individual
borrowers and counterparties, and groups of connected counterparties that aggregate in a comparable and meaningful manner, the different types of exposures, both in the banking and trading book and on and-off-balance sheet. The limits should also be established for particular industries or economic sectors, countries, geographic regions and specific products. The limits established should comply with those stipulated in the Banking Act, Regulations and/or Guidelines, where necessary.
5.35 A regulated institution may manage credit concentrations and other portfolio issues
using such mechanisms as loan sales, credit derivatives, securitisation programmes and other secondary loan markets, provided that it has policies and procedures, as well as adequate controls, in place for these mechanisms.
5.36 A regulated institution is encouraged to develop and utilise an internal credit risk rating
system in managing and monitoring credit risk. The rating system should be consistent with the nature, size and complexity of a regulated institution’s activities. Large loans, as determined by the board, must be individually assessed and rated using the internal credit grading (rating) system. Other smaller loans or groups of smaller loans (i.e., schemes), may be classified on the basis of either a credit risk grading system, payment delinquency status or credit scoring system.
5.37 Where internal ratings are assigned to an individual borrower or counterparty at the time
the credit is granted, such rating should be reviewed on a periodic basis and be assigned a new rating when conditions either improve or deteriorate. It is also important that the consistency and accuracy of ratings is examined periodically by a function such as an independent credit review group.
5.38 A regulated institution must validate internally generated credit ratings/scoring by
mapping such ratings to the ratings of the recognised external credit rating agencies outlined in the Revised Directive on the International Convergence of Capital Measurement and Capital Standards for Botswana. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
5.39 Exposures with credit risk grades for individually assessed loans that are either large,
complex, high risk, deteriorating ratings or problem credits should be subject to additional oversight and monitoring; for example, through more frequent visits from credit officers and inclusion on a watch list that is regularly reviewed by the board and senior management. The internal credit risk ratings could be used by line management in different departments to track the current characteristics of the credit portfolio and help determine necessary changes to the credit strategy of the regulated institution.
5.40 A regulated institution should maintain proper documentation for each credit
accommodation. Credit documentation requirements for each type of credit accommodation offered by the regulated institution should be listed in its credit granting standards.
5.41 The credit files should include all the information necessary to ascertain the current
financial condition of the borrower or counterparty, as well as sufficient information to enable decision making. Credit files should, at a minimum, include credit application, current financial statements, financial analysis, record of all credit reviews, reference letters, appraisal, record of all guarantees and securities, record of terms and conditions of the facility and internal credit ratings. Asset/Credit Classification
5.42 At the minimum, a regulated institution should classify its assets into the following
regulatory credit classification categories:
(a) Standard or Pass
5.43 A credit is in the “pass/standard category if there are no:
(i) Material or significant performance problems (the credit is current and the borrower is complying, and is expected to continue to comply, with all terms of the contract); or (ii) Technical and/or legal documentation deficiencies. (b) Special Mention or Watch
5.44 A credit should be in the “special mention” or watch category if it is currently protected,
but potentially weak. That is, assets with potential weaknesses that may, if not checked or corrected, weaken the asset as a whole or potentially jeopardise a borrower’s repayment capacity in the future. This would, for example, include credit given through inadequate loan agreement or covenants, a lack of control over collateral, or incomplete or inadequate documentation, as well as adverse trends which are not yet serious enough for a classification of Substandard. (c) Substandard
5.45 A credit should be classified as “sub-standard” if it has one or more well-defined
weaknesses that make the full collection of principal and interest questionable. This would include, for example, (i) deterioration of the borrower’s financial condition, Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management including net worth and/or repayment capacity; (ii) the pledged collateral (if any) is undocumented, insufficient, or deteriorating; (iii) the borrower’s financial information is absent or unsatisfactory; (iv) other adverse factors exist, which cause concern regarding the ability of the borrower to repay the credit in accordance with the existing repayment terms, such as delinquency of 90 days, significant deviation from original source of repayment or carryover debt; and/or (v) an actual breach of the contract has occurred.
5.46 All accommodations that are three (3) months in arrears should be, at a minimum, be
classified as “Substandard”.
(d) Doubtful
5.47 A credit shall be classified as “doubtful” when weaknesses exist which make collection
or repayment in full, highly questionable and improbable based upon currently existing circumstances, conditions and the estimated recoverable amount of the pledged collateral (if any). Such credits generally display high levels of delinquency and the possibility of loss is very high. However, because of certain important and reasonably specific pending factors, which may work to the advantage and strengthening of the credit, classification of the credit as “loss” is deferred until its more exact status is determined. Pending factors may include a merger/ acquisition and capital injection. .
5.48 All accommodations that are four (4) to six (6) months in arrears should be, at a minimum,
be classified as “doubtful”.
(e) Loss
5.49 At the time of classification, the credit is deemed uncollectable and of such little value
that it should not continue to be included on the accounts and financial statements of the regulated institution. The classification of credit as loss does not mean that the credit has no recovery or salvage value, but that the regulated institution should not defer writing it off even though at least part of the value could be recovered in the future. Such classification does not cancel the borrower’s obligation to repay, nor does it mean that the regulated institution should not continue to exercise its full legal right to collection or payment. Loans classified as loss may have severe delinquency, unsecured and/or not well secured and not in the process of collection. Overdrafts considered loss may be hardcore, stagnant for a long period of time and unsecured or not well secured.
5.50 All accommodations that are more than six (6) months in arrears should be considered
for classification as “Loss”,
Performing and Non-Performing Status of Credit Exposures
5.51 For regulatory reporting and disclosure purposes, credit exposures shall be broadly
categorised as “performing” and “non-performing”; where performing exposures shall consist of “standard” exposures and “special mention” exposures (subject to such exposures not having significant credit risk as per the prevailing accounting standards). Non-performing exposures shall consist of all “special mention” exposures with significant credit risk as per applicable accounting standards, sub-standard, doubtful and loss, as well as all credit exposures that meet the definition of non-performing loans outlined in paragraphs 5.54-5.57 below. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
Mapping Regulatory Non-performing Assets (NPA) Frameworks with the Accounting Concept of Impaired Assets – Interim Approach
5.52 A regulated institution should map the five regulatory categories of credit exposures onto
the accounting concept of impaired assets (IFRS 9) as detailed below. Pass credit exposures shall map onto Stage 1. Stage 3 shall consist of sub-standard, doubtful and loss exposures, while the special-mention exposures shall be disaggregated into performing and non-performing (as per paragraph 5.51) and the performing portion would form part of Stage 1, while the non-performing portion will map onto Stage 2. Regulatory Credit Exposure Categorisation Standard/ Pass Special Mention/Watc h SubSta nda rd Doubtful Loss Performing Non-performing IFRS 9 Categorisation Stage 1 Stage 2 Stage 2 Stage 3 Frequency of asset classification
5.53 Asset reclassification should be done on a monthly basis. However, if between these
reviews the regulated institution gains knowledge of a significant deterioration in the quality of an individual credit or in part of the regulated institution’s portfolio, the regulated institution should reclassify such credit exposures to reflect their true status. Identification of non-performing exposures
5.54 Non-performing exposures should always be categorised for the whole exposure,
including when non-performance relates to only a part of the exposure, for instance, unpaid interest. For off-balance sheet exposures, such as loan commitments or financial guarantees, the whole exposure is the entire cancellable nominal amount.
5.55 The following exposures shall be considered as non-performing:
(a) all exposures that are “defaulted” under the Basel II framework; (b) all exposures that are credit-impaired (having experienced a downward adjustment to their valuation due to deterioration of their creditworthiness) according to the applicable accounting framework; (c) all other exposures that are not defaulted or impaired but nevertheless:
(i) are material exposures that are more than 90 days past due; or (ii) where there is evidence that full repayment based on the contractual terms, original or, when applicable, modified (e.g., repayment of principal and interest) is unlikely without the regulated institution’s realisation of collateral, whether or not the exposure is current and regardless of the number of days the exposure is past due. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(d) forborne exposures 4 should be identified as non-performing when they meet the specific criteria provided for in this definition.
5.56 Collateralisation or received guarantees should have no direct influence on the
categorisation of an exposure as non-performing. That is, the collateralisation or guarantee status does not influence the past-due status, including the counting of pastdue days and the determination of the exposure as nonperforming, once the materiality and overdue days threshold have been met. When the relevant criteria are met, an exposure should be categorised as non-performing even if the collateral value exceeds the amount of the past-due exposure. Re-categorisation of non-performing exposures as performing
5.57 An exposure ceases to be non-performing and can be re-categorised as performing when
all the following criteria are simultaneously met:
(a) the counterparty does not have any material exposure more than 90 days past due; (b) repayments have been made when due over a period of at least three continuous months as specified by the supervisor. A longer repayment period shall be required for non-performing forborne exposures as detailed in paragraphs 5.58 – 5.64; (c) the counterparty’s situation has improved to the extent that the full repayment of the exposure is likely, according to the original or, when applicable, modified conditions; and (d) the exposure is not “defaulted” according to the Basel II standard or “impaired” according to the applicable accounting framework.
5.58 The following situations will not lead to the re-categorisation of a non-performing
exposure as performing:
(a) partial write-off of an existing non-performing exposure, (i.e., when a regulated institution writes off part of a non-performing exposure that it deems to be uncollectible); (b) repossession of collateral on a non-performing exposure, until the collateral is actually disposed of and the regulated institution realises the proceeds (when the exposure is kept on balance sheet, it is deemed non-performing); or (c) extension or granting of forbearance measures to an exposure that is already identified as non-performing subject to the relevant exit criteria for nonperforming exposures. The re-categorisation of a non-performing exposure as performing should be made at the same level (i.e., at counterparty or transaction level) as when the exposure was originally categorised as non-performing. 4 See paragraph 5.59 Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
Identification of forbearance
5.59 Forbearance includes concessions that are granted due to the counterparty’s financial
difficulty on any exposure in the form of a loan, a debt security or an off-balance sheet item (e.g., loan commitments or financial guarantees) regardless of the measurement method for accounting purposes.
5.60 The identification of an exposure as forborne does not affect its categorisation as impaired
for accounting purposes or as defaulted in accordance with the regulatory framework.
5.61 Refinancing an existing exposure with a new contract due to the financial difficulty of a
counterparty could qualify as a concession, even if the terms of the new contract are no more favourable for the counterparty than those of the existing transaction.
5.62 A forborne exposure will be identified as such until it meets both of the following exit
criteria:
(a) When all payments, as per the revised contractual terms, have been made in a timely manner over a continuous repayment period not less than one year (probation period for reporting). The starting date of the probation period should be the scheduled start of payments under the revised terms, regardless of the performing or non-performing status of the exposure at the time that forbearance was granted; and (b) The counterparty has resolved its financial difficulty.
5.63 Forbearance may be granted on performing or non-performing exposures. When
forbearance is applied to a non-performing exposure, the exposure should remain nonperforming. When forbearance is applied to a performing exposure, the regulated institution then needs to assess whether the exposure meets the non-performing criteria, even if the forbearance resulted in a new exposure. When the original exposure would have been categorised as non-performing at the time of granting forbearance, had the forbearance not been granted, the new exposure should be categorised as non-performing.
5.64 When a forborne exposure under the probation period is granted new forbearance, this
should trigger a re-start of the probation period, and regulated institutions should consider whether the exposure should be categorised as non-performing. Similarly, when a forborne exposure becomes non-performing during the 12-month probation period, the probation period starts again.
5.65 A regulated institution must not use forbearance practices to avoid categorising loans as
non-performing. Therefore, the definition prohibits the upgrading of a non-performing exposure by granting forbearance measures and requires a separate categorisation for forbearance exposures. Treatment of Accrued Interest on Impaired Credits
5.66 Accrued interest on any loan in arrears exceeding three months should be suspended.
Such accrued interest should only be released to income when both the interest and the past due principal amounts have been collected in cash. This principle should be applied Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management to overdrafts in excess of authorised limits and any other credits, investments, etc., which do not perform in accordance with agreed terms for a defined period, in this case 90 days and above.
5.67 A regulated institution should cease to accrue interest on a credit as soon as it is identified
as impaired. At a minimum, the following credits should be placed on non-accrual status:
(i) All adversely classified credits
(ii) Credits 90 days or more past due. (A regulated institution may determine in its own credit policy that certain types of credits should be subject to non-accrual when delinquent for less than 90 days). Capital Requirements for Impaired Credits (non-performing for more than 90 days)
5.68 A regulated institution should hold capital for any unsecured portion of any loan that is
past due for more than 90 days, net of specific provisions (including partial write-offs), as prescribed in the Basel II Directive. Credit Impairment Provisions
5.69 A regulated institution must compute credit impairment provisions in terms of the
relevant accounting standards and such provisions shall be accordingly mapped onto the corresponding prudential credit exposure categorisation. Loan-Loss Provisioning Policy
5.70 A regulated institution should develop and implement comprehensive procedures and
information systems to monitor the quality of its loan portfolio. These procedures should define criteria for identifying and reporting potential problem credits and other transactions to ensure that they are subject to more frequent monitoring, as well as possible corrective action, classification and/or provisioning.
5.71 A loan should be identified as a problem asset when there is reason to believe that all
amounts due, including principal and interest, will not be collected in accordance with the contractual terms of the loan agreement. A loan should be re-classified as performing when all arrears have been cleared and the loan has been brought fully to current status; repayments have been made in a timely manner over a continuous period (with evidence of continued collection), in accordance with the agreed contractual terms.
5.72 A loan shall be classified as impaired if the regulated institution considers that the obligor
is unlikely to pay its credit obligations to the regulated institution in full, without recourse by the regulated institution to the legal actions allowed under the agreement and law, such as realising security (if held); and/or the obligor is past due for more than 90 days on any material credit obligation to the regulated institution. Overdraft facilities will be considered as being impaired once the customer has breached an advised limit.
5.73 A regulated institution’s provisioning policy should clearly set out how the regulated
institution will manage problem credits. Responsibility for such credits may be assigned to the originating business function, a specialised workout section, or a combination of Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management the two, depending upon the size and nature of the credit and the reason for its problems.
5.74 Loan accounting policies and practices should be selected and applied in a consistent way
that reasonably ensures that the loan and loan loss provisioning information is reliable and verifiable.
5.75 The provisioning policy and processes should ensure that the regulated institution
maintains adequate provisions for identified and expected losses in accordance with the prevailing applicable accounting standards. In addition, a regulated institution must provision for expected credit losses (ECL) from the time a loan is originated, rather than awaiting “trigger events” signaling imminent losses. Such provisioning should be forward looking (based on reasonable and supportable information that includes historical, current and forecast information). Furthermore, a regulated institution must hold adequate capital to absorb unexpected losses. The regulated institution’s policies and process for grading and classifying its loans and provisioning should take into account off-balance sheet exposures as well.
5.76 A regulated institution is required to ensure that valuation, classification and provisioning
for significant exposures are conducted on an individual item basis. A regulated institution should set an appropriate threshold for the purpose of identifying significant exposures and to regularly review set thresholds. The remainder of the portfolio should be segmented into groups of loans with similar credit risk characteristics for evaluation and analysis on a collective basis. A regulated institution may use different methods on group loans for the purpose of assessing credit risk and valuation. For example, loans may be grouped on the basis of one or more of the following characteristics: estimated default probabilities or credit risk grades, loan type, product type, market segment, geographical location, collateral type or past-due status.
5.77 A regulated institution should be able to demonstrate, for individually assessed loans that
are, or likely to be impaired, how the amount of any impairment is determined and measured. This includes proof of existence of procedures describing the impairment measurement techniques available and steps performed to determine which technique is most appropriate in a given situation. If a regulated institution determines that observable data does not indicate that impairment exists for an individually assessed loan, the regulated institution should include the loan in a group of loans with similar credit risk characteristics for collective impairment evaluation.
5.78 For groups of loans that are collectively assessed for impairment, estimated credit losses
should reflect consideration of the regulated institution's historical net charge-off rate of the groups, adjusted upward or downward for changes in trends, conditions and other relevant factors that affect repayment of the loans in these groups as of the evaluation date.
5.79 In estimating probability of defaults, loss given defaults and loan losses, a regulated
institution may determine either a single amount or a range of possible amounts. In the latter case, a regulated institution should recognise an impairment loss equal to the best estimate within the range after considering all relevant information about conditions existing at the measurement date that is available before it completes its prudential reports or financial statements. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
5.80 Provisions or loan loss reserves held for future or presently unidentified losses which are
freely available to meet losses which subsequently materialise, qualify for inclusion within tier II capital. However, provisions ascribed to identified deterioration of particular assets or known liabilities, whether individual or grouped, do not qualify for inclusion as
part of tier II capital.
(c) Credit Risk Reporting
5.81 A regulated institution should establish a system of independent, on-going assessment of
its credit risk management processes and the results of such reviews should be communicated directly to senior management and the board of directors.
5.82 A regulated institution should have an efficient internal credit review and reporting
system in order to manage effectively the regulated institution’s various portfolios. Internal audits of the credit risk processes should be conducted on a periodic basis and it should assess compliance with the regulated institution’s credit policies and procedures. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
6. MARKET RISK 5
6.1 Market risk emanates from movements in market prices, in particular, changes in interest
rates yields, foreign exchange rates, equity and commodity prices.
6.2 Principle 22 of the Basel Core Principles for Effective Banking Supervision states that a
regulated institution must have adequate market risk management processes, which take into account its risk appetite, risk profile, systemic importance and capital strength, by taking into account market and macroeconomic conditions and the risk of a significant deterioration in market liquidity. Prudent policies and processes, as well as roles and responsibilities for the identification, measuring, monitoring and control of market risk, must be clearly articulated. (a) Market Risk Identification
6.3 A regulated institution should establish a sound and comprehensive process for the
identification of market risk, which should, among other things, include the following:
(i) a framework to identify market risk;
(ii) an appropriately detailed structure of risk limits, guidelines and other parameters used to govern market risk taking; (iii) an appropriate management information system (MIS) for measuring, monitoring and controlling market risk, including transactions between and with related parties; and (iv) accounting policies on the treatment of market risk.
6.4 A regulated institution should incorporate a market risk management process into its
overall risk management system, to enable it to understand and manage its consolidated risk exposure more effectively. Where a regulated institution is part of a financial services group, the risk management process should also be integrated with that of the group, where practical.
6.5 The market-risk management system should be commensurate with the scope, size and
complexity of a regulated institution’s trading and other financial activities and the market risks assumed. It should also enable the various market risk exposures to be accurately and adequately measured, monitored and controlled. (b) Market Risk Measurement
6.6 A regulated institution’s risk management system should be able to quantify risk
exposures and monitor changes in market risk factors (e.g., changes in interest rates, foreign exchange rates and equity prices) and other market conditions on a daily basis. 5 Reference Documents: Guidelines on Capital Measurements and Capital Standards for Botswana (September 8, 2015); Basel Core Principles for Effective Banking Supervision (September 2012); Principle 22 for the Management of Market Risk (2011) (Principle 22). Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
The risk management system should, wherever feasible, be able to assess the probability of future losses.
6.7 A regulated institution must perform stress tests to identify potential vulnerability to
exceptional but plausible events or changes in economic conditions on a regulated institution’s market risk exposures and assess its ability to withstand such changes. Stress-testing should alert regulated institution management to any adverse unexpected outcomes related to market risk and provide an indication of how much capital might be needed to absorb losses, should large shocks occur.
6.8 A regulated institution should ensure that its treasury and financial derivative valuation
processes are robust and independent of its trading function. Models and supporting statistical analyses used in valuations and stress tests should be appropriate, consistently applied and have reasonable assumptions. These should be validated before deployment. Staff involved in the validation process should be adequately qualified and independent of the trading and model development functions. Models and analyses should be periodically reviewed to ascertain the position data, the accuracy of volatility, valuation and risk factor calculations, as well as the reasonableness of the correlation and stress test assumptions. More frequent reviews may be necessary if there are changes in models or in the assumptions resulting from developments in market conditions.
6.9 The market risk management process should, where appropriate, include regular scenario
analysis and stress tests. Scenario analysis and stress tests should be both quantitative and qualitative.
6.10 Scenario analysis and stress testing should, as far as possible, be conducted on a regulated
institution-wide basis, taking into account the effects of unusual changes in market and non-market risk factors. Such factors include prices, volatilities, market liquidity, historical correlations and assumptions in stressed market conditions, the regulated institution’s vulnerability to worst case scenarios or the default of a large counterparty and maximum cash inflow and outflow assumptions. (c) Market risk Monitoring and Control
6.11 A regulated institution should have a business unit dedicated to the management of
market risks. . Typically, monitoring of market risk is also the responsibility of the assetliability management committee (ALCO). The ALCO should meet on a frequency that is commensurate with the regulated institution’s business activities. The terms of reference, composition, quorum and frequency of meetings should also be formalised and clearly documented.
6.12 The board and senior management should regularly review the results of scenario
analyses and stress testing for market risk, including the major assumptions that underpin them. (d) Market Risk Reporting
6.13 Reports detailing the market risk exposure of the regulated institution should be produced
using a reliable management information system and reviewed by the board on a regular basis. These reports should, at a minimum, include the following:
Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(i) summaries of the regulated institution's aggregate market risk exposures by product, market, currency and duration (e.g., interest rate and foreign exchange exposures and/or any other types of market risk the regulated institution may be exposed to); results of stress tests for market risk, including those assessing breakdowns in key assumptions and parameters; (ii) summaries of the findings of reviews of market risk policies, procedures, and the adequacy of the market-risk measurement systems, including any findings of internal and external auditors or any other independent reviewer; (iii) reports demonstrating compliance with internal policies and prudential limits on market risk, including exceptions; and Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
INTEREST RATE RISK 6
6.14 Interest rate risk is the exposure of a regulated institution’s on-and off-balance sheet
positions to adverse movements in interest rates, resulting in a loss to earnings and, consequently, possible erosion of capital.
6.15 The changes in interest rates affect a regulated institution’s earnings by altering interest
sensitive income and expenses. Interest rate changes also affect the underlying value of a regulated institution’s assets, liabilities and off-balance sheet instruments, through changes in the present value of future cash flows (and, in some cases, the cash flows themselves).
6.16 While interest rate risk is assumed by regulated institutions as part of normal financial
intermediation, excessive interest rate risk poses a significant threat to a regulated institution’s financial condition. In this regard, the board and senior management should design and implement sound interest rate-risk management systems that minimise the regulated institution’s vulnerability to adverse movements in interest rates.
6.17 Principle 23 of Core Principles for Effective Banking Supervision stipulates that banks
are required to have an appropriate interest rate-risk strategy and interest rate-risk management framework that provides a comprehensive bank-wide view of interest rate risk. This includes policies and processes to identify, measure, evaluate, monitor, report and control or mitigate material sources of interest rate risk.
6.18 An interest rate-risk management process encompasses risk identification, measurement,
monitoring and control.
(a) Interest Rate-Risk Identification
6.19 The primary sources of interest rate risk include:
(i) re-pricing risk, which arises from timing differences in the maturity (fixed rate) and re-pricing (floating rate) of regulated institution assets, liabilities and offbalance sheet positions; (ii) basis risk, which arises from imperfect correlation in the adjustment of the rates earned and paid on different instruments with otherwise similar re-pricing characteristics; (iii) yield curve risk, which arises when unanticipated shifts of the yield curve have adverse effects on a regulated institution’s income or underlying economic value; and (iv) optionality risk, which arises from the options that are either explicit or imbedded in many regulated institution assets, liabilities and off-balance sheet portfolios. If not adequately managed, the asymmetrical pay-off characteristics of instruments with optionality features can pose significant risk, particularly to those who sell 6 Basel Committee on Banking Supervision (Principle 23) Principles for the Management and Supervision of Interest Rate Risk (2004). Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management them, since the options held, either explicit or embedded, are generally exercised to the advantage of the holder, and the disadvantage of the seller. (b) Interest Rate-Risk Measurement
6.20 A regulated institution should have interest rate-risk measurement systems that capture
all sources of interest rate risk and that assess the effect of interest rate changes in ways that are consistent with the scope of its activities. The assumptions underlying the risk measurement system should be clearly understood by the board and senior management, who should have an integrated view of interest rate risk across products and business lines.
6.21 Interest rate-risk measurement systems should assess the effects of rate changes on both
earnings and economic value. In addition, a regulated institution should ensure that all material positions stemming from both on and off-balance sheet positions are incorporated into the measurement system on a timely basis.
6.22 The methodology for measuring interest rate risk should be based on adequate
information on current positions, market conditions and instrument characteristics. A regulated institution should have at least two techniques for measuring interest rate risk.
6.23 The techniques that can be used to measure market risks (i.e., interest rate risk, foreign
exchange/currency risk) include gap analysis (maturity/repricing schedule), duration, simulation and value at risk (VaR). Gap analysis
6.24 To evaluate earnings exposure, interest rate-sensitive liabilities in each maturity time
band should be subtracted from the corresponding interest rate-sensitive assets to produce a repricing “gap” for that time band. This gap should be multiplied by an assumed change in interest rates to yield an approximation of the change in net interest income that would result from such an interest rate movement. Therefore, the size of the gap for a given time band gives an indication of the regulated institution’s repricing risk exposure.
6.25 The size of the interest rate movement used in the analysis can be based on a variety of
factors, which include historical experience, simulation of potential future interest rate movements and the judgment of regulated institution management.
6.26 A regulated institution should adopt the time bands as specified in the Directive on the
Revised International Convergence of Capital Measurement and Capital Standards for Botswana (Basel II). Duration
6.27 Duration is the weighted-average term to maturity of assets/liabilities or the percentage
change in the economic value of a position that will occur given a small change in the level of interest rates. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
6.28 Duration-based weights can be used in combination with the maturity/re-pricing schedule
to provide a rough approximation of the change in a regulated institution’s economic value that would occur given a particular change in the level of market interest rates. In some cases, different weights should be used for differences in the coupon rates and maturities (for instance, one weight for assets and another for liabilities);
6.29 In addition, different interest rate changes are sometimes used for different time bands,
generally to reflect differences in the volatility of interest rates along the yield curve. The weighted gaps are aggregated across time bands to produce an estimate of the change in economic value of the regulated institution that would result from the assumed changes in interest rates; and
6.30 A regulated institution should adopt the time bands as specified in the Basel II
Directive
Simulation Approaches
6.31 A regulated institution with a complex risk profile or which uses complex financial
instruments, should employ more sophisticated interest rate-risk measurement systems than those based on simple maturity/re-pricing schedules. These simulation techniques typically involve detailed assessments of the potential effects of changes in interest rates on earnings and economic value, by simulating the potential direction of interest rates and their impact on cash flows. The following simulation approaches are recommended:
(i) Static simulation
(ii) Dynamic simulation
(iii) Value at risk (i.e., probable loss in a portfolio over a specified period) by using the parametric method or variance/covariance approach, historical simulation; or Monte Carlo method.
6.32 A regulated institution using VaR models should carry out back tests.
6.33 VaR is not unique to market risk as it can also be used to measure other types of risk,
namely, credit and operational risks.
Stress-Testing
6.34 A regulated institution must perform stress testing to identify potential vulnerability to
exceptional but plausible events on financial risks in general and interest risk exposures, in particular, to assess the regulated institution’s ability to withstand such changes or shocks. Stress testing should alert regulated institution management to any adverse unexpected outcomes related to, say, interest rate risk and provide an indication of how much capital might be needed to absorb losses, should large shocks occur.
6.35 The following are typical factors that must be considered when stress-testing for interest
rate risk: all likely sources of interest rate risk, including re-pricing risk; basis risk; yield curve risk and optionality risk.
6.36 Stress scenarios to be used for interest rate risk should include:
Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(i) historical scenarios in which sharp changes in interest rates were experienced; (ii) hypothetical changes in the general level of interest rates; (iii) changes in the relationships between key market rates (i.e., basis risk), for example, an increase in term and savings deposit rates and interbank rate, but no change in the prime lending rate, and a drop in the prime lending rate, but no change in term and savings deposit rates and the interbank rate; (iv) changes in interest rates in individual time bands to different relative levels (i.e., yield curve risk); (v) changes in the liquidity of key financial markets or changes in the volatility of market rates; and (vi) changes in key business assumptions and parameters, in particular, changes in assumptions used for illiquid instruments and instruments with uncertain contractual maturities help in the understanding of a regulated institution’s risk profile.
6.37 Management and the board should periodically review both the design and results of such
stress tests, and ensure that appropriate contingency plans are in place. (c) Interest Rate-Risk Monitoring and Control
6.38 Interest rate risk management policies and procedures should be clearly defined and
consistent with the nature and complexity of a regulated institution’s activities.
6.39 Interest rate-risk management policies and procedures should:
(i) specify limits for all types of instruments, portfolios and activities; (ii) delineate lines of responsibility and accountability over interest rate-risk management decisions; (iii) clearly define authorised instruments, either specifically or by their characteristics, hedging strategies and position-taking opportunities; (iv) delineate a clear set of regulated institution procedures for acquiring specific instruments, managing portfolios and controlling a regulated institution’s aggregate interest rate risk exposure; and (v) clearly define approvals necessary for exceptions to policies, limits and authorisations.
6.40 The procedures for undertaking new instruments or new strategies should at least contain
these features:
(i) description of the relevant product or strategy; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(ii) identification of the resources required to establish sound and effective interest raterisk management of the product or activity; (iii) analysis of the impact of the proposed activities on a regulated institution’s overall financial condition and capital levels; (iv) procedures to be used to measure, monitor and control the risks of the proposed product or activity; and (v) review and approval by the board, at least on an annual basis, of new instruments or new strategies.
6.41 At a minimum, a regulated institution should have limits in the following categories:
(i) change in the net portfolio value;
(ii) value at risk (VaR);
(iii) factor sensitivity;
(iv) interest rate sensitivity gap;
(v) impact on earnings; and
(vi) impact on capital.
6.42 Interest rate-risk limits should be linked to specific scenarios of movements in market
interest rates. Specified scenarios should take account of the full range of possible sources of interest rate risk to a regulated institution. (d) Interest Rate-Risk Reporting
6.43 The board should review interest rate risk reports on a regular basis to assess whether
such risk exposures are detailed and, at a minimum, include the following:
(i) summaries of a regulated institution’s aggregate exposures; (ii) a regulated institution’s compliance with policies and limits; (iii) key assumptions, such as non-maturity deposit behaviour and prepayment information; (iv) results of stress tests, including those assessing breakdowns in key assumptions and parameters; (v) adequacy of internal controls; and (vi) summaries of the findings of reviews of interest rate-risk policies, procedures and Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management the adequacy of the interest rate-risk measurement systems, including any findings of internal and external auditors.
6.44 Reports produced by the regulated institution and external auditors or other outside
parties on interest rate risk exposures, should be made available to the supervisory authority. FOREIGN EXCHANGE RISK 7
6.45 Foreign exchange risk is the potential adverse impact on earnings and economic value
due to exchange rate movements. This involves settlement risk, which arises when a regulated institution incurs financial loss due to foreign exchange positions taken in both the trading and banking books. Foreign exchange positions arise from the following activities:
(i) trading in foreign currencies through spot, forward and option transactions as market maker or position taker, including the unhedged positions arising from customer-driven foreign exchange transactions; (i) holding foreign currency positions in the banking book (e.g., in the form of loans, bonds, deposits or cross-border investments); or (ii) engaging in derivative transactions (e.g., structured notes, synthetic investments and structured deposits) that are denominated in foreign currency for trading or hedging purposes.
6.46 There are various forms of risks that can emanate from a foreign exchange transaction,
which include:
(i) exchange rate risk, which is the risk of loss as a result of adverse movements in the exchange rate; (ii) interest rate risk, which arises from maturity mismatches on foreign currency positions; (iii) credit risk, which is due to counterparty default on foreign exchange loans or contracts; and (iv) sovereign risk, which arises from country risk or political risk.
6.47 A regulated institution should, therefore, have a comprehensive risk management
framework for all material risks inherent to the lifecycle of a foreign exchange transaction. (a) Foreign Exchange-Risk Identification
6.48 Foreign exchange-risk exposures fall into structural and trading categories. Foreign
exchange risk can be split into:
7 Basel Committee on Banking Supervision (Principle 22), Supervisory Guidance for Managing Risk Associated with the Settlement of Foreign Exchange Transactions (2013). Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(i) translation exposure, which arises from accounting-based changes in consolidated financial statements caused by changes in exchange rates; (ii) transaction exposure, which occurs when exchange rates change between the time that an obligation is incurred and the time it is settled, thus affecting actual cash flows; and (iii) economic exposure, which reflects the change in the present value of a regulated institution’s expected future cash flows, as a result of an unexpected change in exchange rates or exploded exchange rates. (b) Foreign Exchange-Risk Measurement
6.49 A regulated institution should have measurement systems that take into account all the
sources of foreign exchange risk. The systems should evaluate the effect of foreign exchange rate changes on profitability and economic value of the regulated institution. The measurement systems should:
(i) evaluate all foreign exchange risks by maturity, on both gross and net bases, arising from the full range of a regulated institution’s assets, liabilities and off-balance sheet positions; (ii) use a short-hand method where the overall position is computed by taking, in absolute terms, the greater of either net foreign currency liabilities or net foreign currency assets exposures. (iii) employ accepted financial models or methods for measuring risk of foreign exchange options; (iv) be able to calculate comprehensive risk-factor sensitivities for the purpose of capturing the non-linearity nature of price risk of foreign exchange positions; (v) have accurate and timely data; (vi) incorporate daily mark-to-market of trading positions; and (vii) enable regulated institutions to monitor their foreign exchange settlement risks in real time, in order to ensure that settlement limits will not be exceeded. (c) Stress-Testing on Foreign Exchange Positions
6.50 A regulated institution should conduct stress tests on its foreign currency positions. The
stress tests assess the impact of changes in exchange rates on the profitability and economic value of a regulated institution’s equity. Stress-testing results should be incorporated in the review of business strategies, policies and limits on foreign exchange risk. The assumptions used in the stress-testing model should be clearly documented and reviewed from time to time to reflect changes in the operating environment. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(d) Foreign Exchange-Risk Monitoring and Control
6.51 Foreign exchange-risk monitoring processes should be established to evaluate the
performance of a regulated institution’s risk strategies/policies and procedures in achieving its overall goals. The monitoring function should be independent of business units taking risk and should report directly to senior management/board. Ordinarily, the middle office, which is responsible for verification of transactions, should perform the risk review function in relation to day-to-day activities. Being a highly specialised function, it should be staffed with people who have relevant expertise and knowledge. The unit should also prepare reports for the information of senior management, as well as the regulated institution’s ALCO.
6.52 The middle office should regularly reconcile positions of traders to ensure that they are
within assigned limits. Internal reports comparing actual positions against internal limits should be routinely prepared for management. A regulated institution should have management information systems that provide accurate and timely information. Periodic and frequent revaluations at current market rates should permit the monitoring of a regulated institution’s profits or losses on its foreign exchange book.
6.53 A comprehensive framework of limits to control foreign exchange-risk exposures should
be established for different levels of reporting. The foreign currency exposure thresholds are set at 5 percent for minor currencies, 15 percent for major (i.e., vehicle currencies) and 30 percent for a composite, comprising both minor and major currencies, as a percentage of audited unimpaired capital. At a minimum, a regulated institution should have the following limits for foreign exchange operations:
(i) open position limits for individual currencies to which a regulated institution has material exposures, both during the day and overnight. Where limits are assigned to a group of currencies, the risk measures should be aggregated on a gross basis; (ii) open position limits on the aggregate of all currencies, both during the day and overnight; (iii) open position limits by each centre where the regulated institution operates; (iv) stop loss and/or management-action-trigger limits; and (v) limits for settlement risk of all counterparties.
6.54 The limits should be reviewed at least annually or more frequently in line with changes
in the operating environment.
(e) Internal Controls and Independent Audits
6.55 A regulated institution should conduct periodic reviews of its internal control and risk
management process for foreign exchange risk to ensure its integrity, accuracy and reasonableness. Such reviews should be conducted by parties independent to the function being reviewed. The reviews should, among others, ensure:
(i) accuracy and completeness of recording of all foreign exchange transactions; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(ii) effective segregation of duties between foreign exchange trading, settlement and accounting functions; and (iii) effectiveness and accuracy of reporting of excesses of limits and other exceptions.
6.56 Particular attention should be drawn to irregularities in profit and loss, abnormal foreign
exchange trading patterns or trends (e.g., unusually large gross positions) and frequent excesses of limits. Internal auditors should ensure that such incidents are properly followed through. Any issues concerning controls in the foreign exchange trading area should be appropriately and timely elevated to senior management.
6.57 A regulated institution should promptly respond to findings regarding any violations of
established procedures and ensure that there are adequate procedures for addressing weaknesses or irregularities noted by risk control functions, internal or external auditors and supervisory authorities.
6.58 Internal auditors and other risk control functions should be adequately staffed and have
sufficient expertise and authority for reviewing the foreign exchange trading business. (f) Foreign Exchange-Risk Reporting
6.59 The types of reports vary depending upon the overall foreign exchange risk profile of a
regulated institution. At a minimum, the reports should contain:
(i) individual and aggregate foreign exchange-risk exposures; (ii) information on adherence to policies and limits; and (iii) findings of risk reviews on foreign exchange-risk policies and procedures, including any findings of internal/external auditors.
6.60 A regulated institution is required to report foreign currency positions weekly, as
specified in the Foreign Currency Exposure Directive, BOBA 1/04. The Directive prescribes the maximum amount which any regulated institution may hold or the amount of debt which it may incur in foreign currencies, generally or in any specified currency or currencies. The prudential limits are set for exposure per currency and for the overall foreign currency risk exposure in the Directive. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7. LIQUIDITY RISK MANAGEMENT
7.1 Liquidity is the ability of a regulated institution to fund increases in assets and meet
obligations, as they come due, without incurring unacceptable losses. The fundamental role of regulated institutions in the maturity transformation of short-term deposits into long-term loans makes regulated institutions inherently vulnerable to liquidity risk, both of a regulated institution-specific nature and that which affects markets as a whole. Virtually, all financial transactions or commitments have implications for a regulated institution’s liquidity position. Effective liquidity risk management enhances a regulated institution ’ s ability to meet cash-flow obligations, which are uncertain, as cash-flow obligations are affected by external events. Sound liquidity-risk management is also important because a liquidity shortfall at a single regulated institution can have system-wide repercussions.
7.2 At a minimum, a regulated institution’s liquidity risk management framework should
focus on the following areas: governance of liquidity-risk management, measurement and management of liquidity risk, and public disclosure (fundamental principle for the management and supervision of liquidity risk 8 ). The Bank follows the thirteen principles for sound liquidity risk management of the BCBS, and the following sections are structured around those principles. (a) Fundamental principle for the management of liquidity risk Principle 1: A bank is responsible for the sound management of liquidity risk. A bank should establish a robust liquidity-risk management framework that ensures it maintains sufficient liquidity, including a cushion of unencumbered, high-quality liquid assets, to withstand a range of stress events, including those involving the loss or impairment of both unsecured and secured funding sources.
7.3 A regulated institution should establish a robust liquidity-risk management framework
that is well integrated into the regulated institution-wide risk-management process. A primary objective of the liquidity risk management framework should be to ensure with a high degree of confidence that it is in a position to both address its daily liquidity obligations and withstand a period of liquidity stress affecting both secured and unsecured funding, the source of which could be regulated institution-specific or market-wide. In addition to maintaining sound liquidity-risk governance and management practices, a regulated institution should hold an adequate liquidity cushion in the form of readily marketable assets 9 to be in a position to survive such periods of liquidity stress. 10 A regulated institution should demonstrate that its liquidity cushion is commensurate with the complexity of its on- and off-balance-sheet activities, the 8 Basel Committee on Banking Supervision (Principle 24), Principles for Sound Liquidity Risk Management and Supervision (2008). Includes high quality liquid assets listed in the LCR guidelines. 10 Also see the Bank’s LCR Guidelines, which requires banks to comply with the minimum LCR requirement. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management liquidity of its assets and liabilities, the extent of its funding mismatches and the diversity of its business mix and funding strategies. A regulated institution should use appropriate assumptions about the marketability of assets and its access to both secured and unsecured funding, during periods of stress. Moreover, a regulated institution should not allow competitive pressures to compromise the integrity of its liquidity risk management, control functions, limit systems and liquidity cushion. (b) Governance of liquidity risk management Principle 2: A bank should clearly articulate a liquidity-risk tolerance that is appropriate for the business strategy of the organisation and its role in the financial system.
7.4 A regulated institution should set a liquidity-risk tolerance in the light of its business
objectives, strategic direction and overall risk appetite. The board of directors is ultimately responsible for the liquidity-risk assumed by a regulated institution and the manner in which this risk is managed and therefore should establish the regulated institution’s liquidity-risk tolerance. The tolerance, which should define the level of liquidity risk that the regulated institution is willing to assume, should be appropriate for the business strategy of the regulated institution and its role in the financial system and should reflect the regulated institution’s financial condition and funding capacity. The tolerance should ensure that the regulated institution manages its liquidity strongly in normal times in such a way that it is able to withstand a prolonged period of stress. The risk tolerance should be articulated in such a way that all levels of management clearly understand the trade-off between risks and profits. There are a variety of qualitative and quantitative ways in which a regulated institution can express its risk tolerance. Principle 3: Senior management should develop a strategy, policies and practices to manage liquidity risk in accordance with the risk tolerance and to ensure that the bank maintains sufficient liquidity. Senior management should continuously review information on the bank’s liquidity developments and report to the board of directors on a regular basis. A bank’s board of directors should review and approve the strategy, policies and practices related to the management of liquidity at least annually and ensure that senior management manages liquidity risk effectively.
7.5 Senior management is responsible for developing and implementing a liquidity risk
management strategy in accordance with the regulated institution’s risk tolerance. The strategy should include specific policies on liquidity management, such as the composition and maturity of assets and liabilities; the diversity and stability of funding sources; the approach to managing liquidity in different currencies, across borders, and across business lines and legal entities; the approach to intra-day liquidity management; and the assumptions on the liquidity and marketability of assets. The strategy should take account of liquidity needs under normal conditions as well as liquidity implications under periods of liquidity stress, the nature of which may be institution-specific or market-wide or a combination of the two. The strategy may include various high-level quantitative and qualitative targets. The board of directors should approve the strategy and policies and review them at least annually. The board should ensure that senior Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management management translates the strategy into clear guidance and operating standards (e.g., in the form of policies, controls or procedures) for staff. The board should also ensure that senior management and appropriate personnel have the necessary expertise and that the regulated institution has processes and systems to measure, monitor, and control all sources of liquidity risk.
7.6 The liquidity strategy should be appropriate for the nature, scale and complexity of a
regulated institution’s activities. In formulating the strategy, the regulated institution should take into consideration its legal structures (e.g., mix of foreign branches versus foreign operating subsidiaries, if applicable), key business lines, the breadth and diversity of markets, products, and jurisdictions in which it operates, and home and host regulatory requirements.
7.7 Senior management should determine the structure, responsibilities and controls for
managing liquidity risk and for overseeing the liquidity positions of all legal entities, branches and subsidiaries in the jurisdictions in which a regulated institution is active, and outline these elements clearly in the regulated institution’s liquidity policies. The structure for managing liquidity (i.e., the degree of centralisation or decentralisation of a regulated institution’s liquidity risk management) should take into consideration any legal, regulatory or operational restrictions on the transfer of funds.
7.8 In addition, senior management and the board should have a thorough understanding of
the close links between funding liquidity 11 risk and market liquidity risk, as well as how other risks, including credit, market, operational and reputation risks affect the regulated institution’s overall liquidity-risk strategy.
7.9 The liquidity strategy, key policies for implementing the strategy, and the liquidity risk
management structure should be communicated throughout the organisation by senior management. All business units conducting activities that have an impact on liquidity should be fully aware of the liquidity strategy and operate under the approved policies, procedures, limits and controls. Individuals responsible for liquidity risk management should maintain close links with those monitoring market conditions, as well as with other individuals with access to essential information, such as credit risk managers. Moreover, liquidity risk and its potential interaction with other risks should be included in the risks addressed by risk management committees and/or independent risk management functions.
7.10 Senior management should ensure that the regulated institution has adequate internal
controls to ensure the integrity of its liquidity risk management process. Senior management should ensure that operationally independent, appropriately trained and competent personnel are responsible for implementing internal controls. It is important 11 Funding liquidity risk is the risk that a bank will not be able to meet efficiently both expected and unexpected current and future cash flow and collateral needs without affecting either daily operations or the financial condition of the bank. Market liquidity risk is the risk that a bank cannot easily offset or eliminate a position at the market price because of inadequate market depth or market disruption. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management that personnel in independent control functions have the skills and authority to challenge information and modelling assumptions provided by business lines. When significant changes affect the effectiveness of controls and revisions, or enhancements to internal controls are warranted, senior management should ensure that necessary changes are implemented in a timely manner. Internal audit should regularly review the implementation and effectiveness of the agreed framework for controlling liquidity risk.
7.11 Senior management should closely monitor current trends and potential market
developments that may present significant, unprecedented and complex challenges for managing liquidity risk so that they can make appropriate and timely changes to the liquidity strategy as requirement. It should also define the specific procedures and approvals necessary for exceptions to policies and limits, including the escalation procedures and follow-up actions to be taken for breaches of limits. Further, senior management should ensure that stress tests, contingency funding plans and liquidity cushions are effective and appropriate for the regulated institution.
7.12 The board should regularly review reports on the liquidity position of the regulated
institution. The board should be informed immediately of new or emerging liquidity concerns. These include increasing funding costs or concentrations, the growing size of a funding gap, the drying up of alternative sources of liquidity, material and/or persistent breaches of limits, a significant decline in the cushion of unencumbered, highly liquid assets, or changes in external market conditions which could signal future difficulties. The board should ensure that senior management takes appropriate remedial actions to address the concerns. Principle 4 12: A bank should incorporate liquidity costs, benefits and risks in the internal pricing, performance measurement and new product approval process for all significant business activities (both on- and off-balance sheet), thereby aligning the risk-taking incentives of individual business lines with the liquidity-risk exposures their activities create for the bank as a whole.
7.13 Senior management should appropriately incorporate liquidity costs, benefits and risks
in the internal pricing, performance measurement and new product approval process for all significant business activities (both on- and off-balance sheet). It should also ensure that a regulated institution’s liquidity management process includes measurement of the liquidity costs, benefits and risks implicit in all significant business activities, including activities that involve the creation of contingent exposures, which may not immediately have a direct balance-sheet impact. These costs, benefits and risks should then be explicitly attributed to the relevant activity, so that line management incentives are consistent with and reinforce the overarching liquidity-risk tolerance and strategy of the regulated institution, with costs assigned as appropriate to positions, portfolios, or individual transactions. This assignment of liquidity costs, benefits and risks should incorporate factors related to the anticipated holding periods of assets and liabilities, their market liquidity-risk characteristics, and any other relevant factors, including the benefits from having access to relatively stable sources of funding, such as some types of retail deposits. 12 Requirement only for D-SIBs. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.14 The quantification and attribution of these risks should be explicit and transparent at the
line management level and should include consideration of how liquidity would be affected under stressed conditions.
7.15 The analytical framework should be reviewed as appropriate to reflect changing
business and financial market conditions and so maintain the appropriate alignment of incentives. Moreover, liquidity risk costs, benefits and risks should be addressed explicitly in the new product approval process. (c) Measurement and Management of Liquidity Risk Principle 5: A bank should have a sound process for identifying, measuring, monitoring and controlling liquidity risk. This process should include a robust framework for comprehensively projecting cash flows arising from assets, liabilities and off-balancesheet items over an appropriate set of time horizons.
7.16 A regulated institution should define and identify the liquidity risk to which it is exposed
for all legal entities, branches and subsidiaries in the jurisdictions in which it is active. A regulated institution’s liquidity needs and the sources of liquidity available to meet those needs depend significantly on the regulated institution’s business and product mix, balance-sheet structure and cash-flow profiles of its on- and off-balance sheet obligations. As a result, a regulated institution should evaluate each major on- and offbalance-sheet position, including the effect of contingent exposures that may affect the regulated institution’s sources and uses of funds, and determine how it can affect liquidity risk.
7.17 A regulated institution should consider the interactions between exposures to funding
liquidity risk and market liquidity risk 13. A regulated institution that obtains liquidity from capital markets should recognise that these sources may be more volatile and expensive than traditional retail deposits. For example, under conditions of stress, investors in money market instruments may demand higher compensation for risk, require roll over at considerably shorter maturities, or refuse to extend loans at all. Moreover, reliance on the full functioning and liquidity of financial markets may not be realistic as asset and funding markets may dry up in times of stress. Market illiquidity may make it difficult for a regulated institution to raise funds by selling assets and thus increase the need for funding liquidity.
7.18 A regulated institution should ensure that assets are prudently valued according to
relevant financial reporting and supervisory standards. A regulated institution should fully factor into its risk management the consideration that valuations may deteriorate under market stress, and take this into account when assessing the feasibility and impact on liquidity position of an asset sale during stress. For example, a regulated institution’s sale of assets under duress to raise liquidity could put pressure on earnings and capital and further reduce counterparties’ confidence in the regulated institution, further constraining its access to funding markets. In addition, a large asset sale by one regulated institution may prompt further price declines for that type of asset due to the market’s difficulty to absorb the sale. 13 See footnote 3 for definitions of funding liquidity risk and market liquidity risk. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.19 A regulated institution should recognise and consider the strong interactions between
liquidity risk and the other types of risk to which it is exposed. Various types of financial and operating risks, including interest rate, credit, operational, legal and reputational risks, may influence a regulated institution’s liquidity profile. Liquidity risk can arise from perceived or actual weaknesses, failures or problems in the management of other risk types. A regulated institution should identify events that could have an impact on market and public perceptions about its soundness, particularly in wholesale markets.
7.20 Liquidity measurement involves assessing a regulated institution’s cash inflows against
its outflows and the liquidity value of its assets to identify the potential for future net funding shortfalls. A regulated institution should be able to measure and forecast its prospective cash flows for assets, liabilities, off-balance-sheet commitments and derivatives over a variety of time horizons, under normal conditions and a range of stress scenarios, including scenarios of severe stress.
7.21 Regarding the time horizons over which to identify, measure, monitor and control
liquidity risk, a regulated institution should ensure that its liquidity risk-management practices are integrated and consider a variety of factors. These factors include vulnerabilities to changes in liquidity needs and funding capacity on an intra-day basis; day-to-day liquidity needs and funding capacity over short- and medium-term horizons up to one year; longer-term liquidity needs over one year; and vulnerabilities to events, activities and strategies that can put a significant strain on internal cash-generation capability.
7.22 A regulated institution should identify, measure, monitor and control its liquidity-risk
positions for
(i) future cash flows of assets and liabilities; (ii) sources of contingent liquidity demand and related triggers associated with offbalance-sheet positions; (iii) currencies in which a regulated institution is active; and (iv) correspondent, custody and settlement activities. Future cash flows of assets and liabilities
7.23 A regulated institution should have a robust liquidity-risk management framework
providing prospective, dynamic cash-flow forecasts that include assumptions on the likely behavioural responses of key counterparties to changes in conditions and are carried out at a sufficiently granular level. A regulated institution should make realistic assumptions about its future liquidity needs for both the short and long term that reflect the complexities of its underlying businesses, products and markets. A regulated institution should analyse the quality of assets that could be used as collateral in order to assess their potential for providing secured funding in stressed conditions. A regulated institution also should attempt to manage the timing of incoming flows in relation to known outgoing sources to achieve an appropriate maturity distribution for its sources and uses of funds. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.24 In estimating the cash flows arising from its liabilities, a regulated institution should
assess the “stickiness” of its funding sources—that is, their tendency not to run off quickly under stress. In particular, for large wholesale funds providers, both secured and unsecured, a regulated institution should assess the likelihood of roll-over of funding lines and the potential for fund providers to behave similarly under stress and therefore consider the possibility that secured and unsecured funding might dry up in times of stress. For secured funding with overnight maturity, a regulated institution should not assume that the funding will automatically roll over. In addition, a regulated institution should assess the availability of term funding back up facilities and the circumstances under which they can be used. A regulated institution should also consider factors that influence the “stickiness” of retail deposits, such as size, interestrate sensitivity, geographical location of depositors and the deposit channel (e.g., direct, internet or brokered). Sources of contingent liquidity demand and related triggers associated with offbalance-sheet positions
7.25 A regulated institution should identify, measure, monitor and control potential cash
flows relating to off-balance-sheet commitments and other contingent liabilities. The regulated institution should also have a robust framework for projecting the potential consequences of undrawn commitments being drawn, considering the nature of the commitment and creditworthiness of the counterparty, as well as exposures to business and geographical sectors, as counterparties in the same sectors may be affected by stress at the same time.
7.26 A regulated institution should monitor, at the inception and throughout the life of a
transaction, potential risks arising from the existence of recourse provisions in asset sales, the extension of tenure of liquidity facilities and the early amortisation triggers of certain asset securitisation transactions.
7.27 A regulated institution’s processes for identifying and measuring contingent funding
risks should consider the nature and size of the regulated institution’s potential noncontractual obligations, as they can give rise to the regulated institution supporting related off-balance-sheet vehicles in times of stress, for example, securitisation and conduit programmes, where the regulated institution considers such support vital to maintaining access to funding. Similarly, in times of stress, reputational concerns might prompt a regulated institution to purchase assets from money market or other investment funds that it manages or with which it is otherwise affiliated.
7.28 Given the customised nature of many of the contracts that underlie undrawn
commitments and off-balance-sheet instruments, trigger events 14 for these contingent liquidity risks can be difficult to model. It is incumbent upon the management of the 6 Triggering events are events that enable commitments to be drawn upon and thus may create a liquidity need. For example, triggering events could include changes in economic variables or conditions, credit rating downgrades, country risk, specific market disruptions (e.g., commercial paper), and the alteration of contracts by governing legal, accounting, or tax systems and other similar changes. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management risk-originating business activity, as well as the liquidity risk management group, to implement systems to analyse these liquidity trigger events effectively and to measure how changes to underlying risk factors could cause draws against these facilities, even if there has been no historical evidence of such draws. This analysis should include appropriate assumptions about the behaviour of both the regulated institution and its obligors or counterparties.
7.29 The management of liquidity risks of certain off-balance-sheet items is of particular
importance due to the difficulties that many regulated institutions have in assessing the related liquidity risks that could materialise in times of stress. Those items include financial derivatives and guarantees and commitments. Financial derivatives
7.30 A regulated institution should incorporate cash flows related to the repricing, exercise
or maturity of financial derivatives contracts in its liquidity risk analysis, including the potential for counterparties to demand additional collateral in an event such as a decline in the regulated institution’s credit rating or creditworthiness or a decline in the price of an underlying asset. Timely confirmation of over the counter derivative transactions is fundamental to such analyses, because unconfirmed trades call into question the accuracy of a regulated institution’s measures of potential exposure. Guarantees and commitments
7.31 Undrawn loan commitments, letters of credit and financial guarantees represent a
potentially significant drain of funds for a regulated institution. A regulated institution may be able to ascertain a ‘normal’ level of cash outflows under routine conditions, and then estimate the scope for an increase in these flows during periods of stress. For example, an episode of financial market stress may trigger a substantial increase in the amount of drawdowns of letters of credit provided by the regulated institution to its customers. Similarly, liquidity risk can arise when a regulated institution relies on committed lines of credit or guarantees provided by others. Currencies in which a regulated institution is active
7.32 A regulated institution should assess its aggregate foreign-currency liquidity needs and
determine acceptable currency mismatches. A regulated institution should undertake a separate analysis of its strategy for each currency in which it has significant activity, considering potential constraints in times of stress. The size of foreign-currency mismatches should take into account (a) the regulated institution’s ability to raise funds in foreign-currency markets; (b) the likely extent of foreign currency back-up facilities available in its domestic market; (c) the ability to transfer a liquidity surplus from one currency to another, and across jurisdictions and legal entities; and (d) the likely convertibility of currencies in which the regulated institution is active, including the potential for impairment or complete closure of foreign-exchange swap markets for particular currency pairs. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.33 A regulated institution should be aware of and have the capacity to manage liquidityrisk exposures arising from the use of foreign currency deposits and short-term credit
lines to fund domestic-currency assets as well as the funding of foreign-currency assets with domestic currency. A regulated institution should take account of the risks of sudden changes in foreign exchange, exchange rates or market liquidity, or both, which could sharply widen liquidity mismatches and alter the effectiveness of foreign exchange hedges and hedging strategies.
7.34 Moreover, a regulated institution should assess the likelihood of loss of access to the
foreign exchange markets as well as the likely convertibility of the currencies in which the regulated institution carries out its activities. A regulated institution should incorporate these aspects in its contingency strategy (as part of its contingency funding plan) if the regulated institution runs significant liquidity-risk positions in a specific currency. Correspondent, custody and settlement activities
7.35 A regulated institution should understand and have the capacity to manage how the
provision of correspondent, custodian and settlement bank services can affect its cash flows. Given that the gross value of customers’ payment traffic (inflows and outflows) can be very large, unexpected changes in these flows can result in large net deposits, withdrawals or line-of-credit draw-downs that affect the overall liquidity position of the correspondent or custodian bank, both on an intra-day and overnight basis. A bank also should understand and have the capacity to manage the potential liquidity needs it would face as a result of the failure-to-settle procedures of payment and settlement systems in which it is a direct participant. Measurement tools
7.36 A regulated institution should employ a range of customised measurement tools, or
metrics, as there is no single metric that can comprehensively quantify liquidity risk. To obtain a forward-looking view of liquidity-risk exposures, a regulated institution should use metrics that assess the structure of the balance sheet, as well as metrics that project cash flows and future liquidity positions, taking into account off-balance-sheet risks. These metrics should span vulnerabilities across business-as-usual and stressed conditions over various time horizons. Under business-as-usual conditions, prospective measures should identify needs that may arise from projected outflows relative to routine sources of funding. Under stress conditions, prospective measures should be able to identify funding gaps at various horizons, and in turn serve as a basis for liquidity risk limits and early warning indicators.
7.37 Management should tailor the measurement and analysis of liquidity risk to the
regulated institution’s business mix, complexity and risk profile. The measurement and analysis should be comprehensive and incorporate the cash flows and liquidity implications arising from all material assets, liabilities, off-balance sheet positions and other activities of the regulated institution. The analysis should be forward-looking and strive to identify potential future funding mismatches so that the regulated institution can assess its exposure to the mismatches and identify liquidity sources to mitigate the potential risks. In the normal course of measuring, monitoring and analysing its sources and uses of funds, a regulated institution should project cash flows over time under a Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management number of alternative scenarios. These pro-forma cash-flow statements are an essential tool for adequately managing liquidity risk. These projections serve to produce a “cashflow mismatch” or “liquidity-gap” analysis that can be based on assumptions of the future behaviour of assets, liabilities and off-balance sheet items, and then used to calculate the cumulative net excess or shortfall over the time frame for the liquidity assessment. Measurement should be performed over incremental time periods to identify projected and contingent flows, taking into account the underlying assumptions associated with potential changes in cash-flows.
7.38 Given the crucial role of assumptions in projecting future cash flows, a regulated
institution should take steps to ensure that its assumptions are reasonable, documented and periodically reviewed and approved. The assumptions around the duration of demand deposits and assets, liabilities, and off-balance-sheet items with uncertain cash flows and the availability of alternative sources of funds during times of liquidity stress are of particular importance. Assumptions about the market liquidity of such positions should be adjusted according to market conditions or institution-specific circumstances.
7.39 Banks are furthermore required to take note of the monitoring tools as introduced by
the BCBS. These metrics capture specific information related to a regulated institution’s cash flows, balance-sheet structure, available unencumbered collateral and certain market indicators. Whereas these indicators can assist the supervisor to assess the liquidity risk of a regulated institution, regulated institutions themselves should also use these metrics as part of measurement tools. In addition to the measurement of contractual maturity mismatches, regulated institutions should also measure concentration of funding, the level of available unencumbered assets and the LCR by significant currency at a minimum. Liquidity risk control through limits
7.40 A regulated institution should set limits to control its liquidity risk exposure and
vulnerabilities. A regulated institution should regularly review such limits and corresponding escalation procedures. Limits should be relevant to the business in terms of its location, complexity of activity, nature of products, currencies and markets served.
7.41 Limits should be used for managing day-to-day liquidity within and across lines of
business and legal entities under normal conditions. For example, a commonly employed type of limit constrains the size of cumulative contractual cash-flow mismatches (e.g., the cumulative net funding requirement as a percentage of total liabilities) over various time horizons. This type of limit also may include estimates of outflows resulting from the drawdown of commitments or other obligations of the regulated institution. Another limit example is the top 20 depositor-concentration exposure.
7.42 The limit framework also should include measures aimed at ensuring that the regulated
institution can continue to operate in a period of market stress, institution-specific stress and a combination of the two. Simply stated, the objective of such measures is to ensure that, under stress conditions, available liquidity exceeds liquidity needs. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
Early warning indicators
7.43 While management and staff have the responsibility to use judgement to identify and
manage underlying risk factors, a regulated institution should also design a set of indicators to aid this process to identify the emergence of increased risk or vulnerabilities in its liquidity-risk position or potential funding needs. Such early warning indicators should identify any negative trend and cause an assessment and potential response by management to mitigate the regulated institution’s exposure to the emerging risk.
7.44 Early warning indicators can be qualitative or quantitative and include
Guidelines on Risk Management
Monitoring system
7.46 A regulated institution should have a reliable management information system designed
to provide the board of directors, senior management and other appropriate personnel with timely and forward-looking information on the liquidity position of the regulated institution. The management information system should have the ability to calculate liquidity positions in all of the currencies in which the bank conducts business—both on a subsidiary/branch basis in all jurisdictions in which the regulated institution is active and on an aggregate group basis. It should capture all sources of liquidity risk, including contingent risks and the related triggers and those arising from new activities, and have the ability to deliver more granular and time-sensitive information during stress events. To effectively manage and monitor its net funding requirements, a regulated institution should have the ability to calculate liquidity positions on an intraday basis, on a day-to-day basis for the shorter time horizons, and over a series of more distant time periods thereafter. The management information system should be used in day-to-day liquidity risk management to monitor compliance with the regulated institution’s established policies, procedures and limits.
7.47 To facilitate liquidity risk monitoring, senior management should agree on a set of
reporting criteria, specifying the scope, manner and frequency of reporting for various recipients (such as the board, senior management, asset-liability committee) and the parties responsible for preparing the reports. Reporting of risk measures should be done on a frequent basis (e.g., daily reporting for those responsible for managing liquidity risk, and at each board meeting during normal times, with more frequent reporting in times of stress) and should compare current liquidity exposures to established limits to identify any emerging pressures and limit breaches. Breaches in liquidity risk limits should be reported, and thresholds and reporting guidelines should be specified for escalation to management levels, the board and to the supervisor. Principle 6: A bank should actively monitor and control liquidity-risk exposures and funding needs within and across legal entities, business lines and currencies, taking into account legal, regulatory and operational limitations to the transferability of liquidity.
7.48 Regardless of its organisational structure and degree of centralised or decentralised
liquidity-risk management, a regulated institution should actively monitor and control liquidity risks at the level of individual legal entities, and foreign branches and subsidiaries, and the group as a whole, incorporating processes that aggregate data across multiple systems in order to develop a group-wide view of liquidity-risk exposures and identify constraints on the transfer of liquidity within the group.
7.49 For each country in which it is active, a regulated institution should ensure that it has
the necessary expertise about country-specific features of the legal and regulatory regime that influence liquidity risk management, including arrangements for dealing with failed banks, deposit insurance, and central bank operational frameworks and collateral policies. This knowledge should be reflected in liquidity-risk management processes. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.50 In the case of a localised systemic stress event, a bank should have processes in place
to allow for allocation of liquidity and collateral resources to affected entities, to the extent that transferability is permitted. A regulated institution should also consider the possibility that a local event could lead to a liquidity strain across the whole group due to reputational contagion (i.e., when market counterparties assume that a problem at one entity implies a problem for the group as a whole). The group as a whole, and individual legal entities, should be resilient to such shocks to a degree consistent with the board’s defined risk tolerance.
7.51 To mitigate the potential for reputational contagion, effective communication with
counterparties, credit rating agencies and other stakeholders when liquidity problems arise is of vital importance. In addition, contingency funding plans, liquidity cushions and multiple sources of funding are mechanisms that may mitigate reputational contagion.
7.52 The specific market characteristics and liquidity risks of positions in foreign currencies
should be taken into account, particularly where fully developed foreign exchange markets do not exist. For currencies trading in well-developed foreign exchange markets, a more global approach to management of the currency may be taken, including the use of swaps. However, the regulated institution should critically assess the risk that the ability to swap currencies may erode rapidly under stressed conditions.
7.53 Assumptions regarding the transferability of funds and collateral should be transparent
in liquidity risk management plans that are available for supervisory review. A regulated institution’s assumptions should fully consider regulatory, legal, accounting, credit, tax and internal constraints on the effective movement of liquidity and collateral. They should also consider the operational arrangements needed to transfer funds and collateral across entities and the time required to complete such transfers under those arrangements. Principle 7: A bank should establish a funding strategy that provides effective diversification in the sources and tenor of funding. It should maintain an ongoing presence in its chosen funding markets and strong relationships with funds providers to promote effective diversification of funding sources. A bank should regularly gauge its capacity to raise funds quickly from each source. It should identify the main factors that affect its ability to raise funds and monitor those factors closely to ensure that estimates of fund raising capacity remain valid.
7.54 A regulated institution should diversify available funding sources in the short, medium
and long term. Diversification targets should be part of the medium- to long-term funding plans and be aligned with the budgeting and business planning process. Funding plans should take into account correlations between sources of funds and market conditions. The desired diversification should also include limits by counterparty, secured versus unsecured market funding, instrument type, securitisation vehicle, currency, and geographic market.
7.55 Regulated institutions should limit concentration in any one particular funding source
or tenor. Some regulated institutions are increasingly reliant on wholesale funding, which tends to be more volatile than retail funding. Consequently, these regulated institutions should ensure that wholesale funding sources are sufficiently diversified to Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management maintain timely availability of funds at the right maturities and at reasonable costs. Furthermore, regulated institutions reliant on wholesale funding should maintain a relatively higher proportion of unencumbered, highly liquid assets than regulated institutions that rely primarily on retail funding. For institutions active in multiple currencies, access to diverse sources of liquidity in each currency is required, since regulated institutions are not always able to swap liquidity easily from one currency to another.
7.56 Senior management should be aware of the composition, characteristics and
diversification of the regulated institution’s assets and funding sources. Senior management should regularly review the funding strategy in the light of any changes in the internal or external environments. Managing market access
7.57 An essential component of ensuring funding diversity is maintaining market access.
Market access is essential for effective liquidity-risk management, as it affects both the ability to raise new funds and to liquidate assets. Senior management should ensure that market access is being actively managed, monitored and tested by the appropriate staff.
7.58 Managing market access can include developing markets for asset sales or
strengthening arrangements under which a regulated institution can borrow on a secured or unsecured basis. A regulated institution should maintain an active presence within markets relevant to its funding strategy. This requires an ongoing commitment and investment in adequate and appropriate infrastructures, processes and information collection. A regulated institution should not assume that it can access markets in a timely manner for which it has not established the necessary systems or documentation, or where these arrangements have not been periodically used or the regulated institution has not confirmed that willing counterparties are in place. The inclusion of loan-sale clauses in loan documentation and the regular use of some asset-sales markets may help enhance a regulated institution’s ability to execute asset sales with various counterparties in times of stress. In all cases, a regulated institution should have full knowledge of the legal framework governing potential asset sales and ensure that documentation is reliable and legally robust.
7.59 Normally reliable funding markets can be disrupted when put under stress. A regulated
institution should consider the impact of both market disruptions and name specific risk on cash flows and access to short- and long-term funding markets.
7.60 A regulated institution should identify and build strong relationships with current and
potential investors, even in funding markets facilitated by brokers or other third parties. Where appropriate, a bank should also establish and maintain a relationship with the central bank. Building strong relationships with various key providers of funding can give a bank insights into providers’ behaviour in times of bank-specific or market-wide shocks and provide a line of defence should a liquidity problem arise. The frequency of contact and of use of a funding source is a possible indicator of the strength of a funding relationship. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.61 Although developing and maintaining strong relationships with funds providers is
important, a regulated institution should take a prudent view of how those relationships will be strained in times of stress. Institutions that reliably provide funds in normal conditions may not do so in times of widespread stress because of uncertainty about their own liquidity needs. In the formulation of its stress test scenarios and contingency funding plan, a regulated institution should consider these second-order effects and take into account that sources of funds may dry up and that markets may close.
7.62 In addition, increased uncertainty about a regulated institution’s repayment ability can
cause significant deterioration in the willingness of counterparties to provide funding. In such situations the quality and strength of a regulated institution’s capital cushion can positively influence the willingness of counterparties to maintain funding relationships. Stress test scenarios and contingency funding plans should consider the effects that losses and the resulting reduction in capital can have on the regulated institution’s ability to maintain funding relationships.
7.63 A regulated institution needs to identify alternative sources of funding that strengthen
its capacity to withstand a variety of severe yet plausible institution-specific and marketwide liquidity shocks. Depending on the nature, severity and duration of the liquidity shock, potential sources of funding include the following:
Guidelines on Risk Management that reflect such events and use the outcomes as a basis for construction of a contingency plan, including, potentially, the development of back-up service arrangements to avoid cash-flow bottlenecks.
7.66 When a regulated institution chooses to rely on correspondents or custodians to conduct
payment and settlement activities, the regulated institution should assure itself that this arrangement allows it to meet obligations on a timely basis and to manage its intra-day liquidity risks under a variety of circumstances. In particular, a regulated institution should recognise the potential for operational or financial disruptions at its correspondent or custodian to disrupt the regulated institution’s own liquidity management, and it should have alternative arrangements in place to ensure it can continue to meet its obligations in such situations. Principle 9: A bank should actively manage its collateral positions, differentiating between encumbered and unencumbered assets. A bank should monitor the legal entity and physical location where collateral is held and how it may be mobilised in a timely manner.
7.67 A regulated institution should have the ability to calculate all of its collateral positions,
including assets currently pledged relative to the amount of security required and unencumbered assets available to be pledged. A regulated institution’s level of available collateral should be monitored by legal entity, by jurisdiction and by currency exposure, and systems should be capable of monitoring shifts between intra-day and overnight or term collateral usage. 15 A regulated institution should be aware of the operational and timing requirements associated with accessing the collateral, given its physical location (i.e., the custodian bank or securities settlement system with which the collateral is held).
7.68 A regulated institution should assess the eligibility of each major asset class for
pledging as collateral with central banks (for intra-day credit, overnight and term lending operations, and borrowing understanding facilities) and the acceptability of assets to major counterparties and funds providers in secured funding markets. A regulated institution should diversify its sources of collateral, taking into consideration capacity constraints, name-specific concentrations, the sensitivity of prices, haircuts and collateral requirements under conditions of name-specific and market-wide stress, and the availability of funds from private-sector counterparties in various market stress scenarios.
7.69 Effective collateral management requires a regulated institution to be in a position to
meet a range of collateral needs, including longer-term structural, short-term and intraday considerations. A regulated institution should have sufficient collateral to meet expected and unexpected borrowing needs and potential increases in margin requirements over different timeframes, depending upon the regulated institution’s funding profile. 8 In some cases, collateral pledged to a central bank can be used to support intra-day, overnight or longer-term credit. A given asset can provide collateral support for only one type of credit facility at a time, creating the need for effective collateral management, given competing demands. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
Principle 10: A bank should conduct stress tests on a regular basis for a variety of short-term and protracted institution-specific and market-wide stress scenarios (individually and in combination) to identify sources of potential liquidity strain and to ensure that current exposures remain in accordance with a bank’s established liquidityrisk tolerance. A bank should use stress-test outcomes to adjust its liquidity-risk management strategies, policies and positions and to develop effective contingency plans.
7.70 While a regulated institution typically manages liquidity under normal circumstances,
it should also be prepared to manage liquidity under stressed conditions. A regulated institution should perform stress tests or scenario analyses on a regular basis in order to identify and quantify its exposures to possible future liquidity stresses, analysing possible impacts on the institution’s cash flows, liquidity position, profitability and solvency. The results of these stress tests should be discussed by management and, on that basis, should form the basis for taking remedial or mitigating actions to limit the regulated institution’s exposures, build up a liquidity cushion and adjust its liquidity profile to fit its risk tolerance. The results of stress tests should also play a key role in shaping the regulated institution’s contingency planning and in determining the strategy and tactics to deal with events of liquidity stress. As a result, stress testing and contingency planning are closely intertwined. Stress testing process
7.71 Stress tests should enable a regulated institution to analyse the impact of stress scenarios
on its consolidated group-wide liquidity position as well as on the liquidity position of individual entities and business lines. Regardless of the organisational structure of the regulated institution and the degree of centralised liquidity risk management, it is important for a regulated institution to understand where risks could arise. A regulated institution should assess whether additional tests are warranted for individual entities (i.e., subsidiaries and branches) within the group (if applicable) that are exposed to significant liquidity risks. Tests should consider the implication of the scenarios across different time horizons, including on an intra-day basis. The extent and frequency of testing should be commensurate with the size of the regulated institution and its liquidity-risk exposures, as well as with the relative importance of the regulated institution within the financial systems in which it operates. Regulated institutions should have the capability to increase the frequency of tests in special circumstances, such as in volatile market conditions or at the request of the supervisor.
7.72 The active involvement of senior management is vital to the stress-testing process.
Senior management should demand that rigorous and challenging stress scenarios be considered, even in times when liquidity is plentiful. Scenarios and assumptions
7.73 In designing stress scenarios, the nature of a regulated institution’s business, activities
and vulnerabilities should be taken into consideration so that the scenarios incorporate the major funding and market liquidity risks to which the regulated institution is exposed. These include risks associated with its business activities, products (including complex financial instruments and off-balance sheet items) and funding sources. The Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management defined scenarios should allow the regulated institution to evaluate the potential adverse impact these factors can have on its liquidity position.
7.74 History may serve as one guide when designing stress tests. Historical events may,
however, not prove to be a good predictor of future events. A banker’s judgment plays an important role in the design of stress tests. A regulated institution should carefully consider the design of scenarios and the variety of shocks used. A regulated institution should consider short-term and protracted, as well as institution-specific and marketwide, stress scenarios in its stress tests, including a simultaneous drying up of market liquidity in several previously highly liquid markets; severe constraints in accessing secured and unsecured funding; restrictions on currency convertibility; and severe operational or settlement disruptions affecting one or more payment or settlement systems. Regardless of how strong its current liquidity situation appears to be, a regulated institution should consider the potential impact of severe stress scenarios.
7.75 A regulated institution should specifically take into account the link between reductions
in market liquidity and constraints on funding liquidity. This is particularly important for regulated institutions with significant market share in, or heavy reliance upon, specific funding markets. A regulated institution should also consider the insights and results of stress tests performed for various other risk types when stress testing its liquidity position and consider possible interactions with these other types of risk.
7.76 A regulated institution should recognise that stress events may simultaneously give rise
to time-critical liquidity needs in multiple currencies and multiple payment and settlement systems. Moreover, these liquidity needs could arise both from the regulated institution’s own activities and from those of its customer banks (e.g., when the regulated institution acts as correspondent for other regulated institutions’ settlement obligations). They could also arise from the special roles a regulated institution might play in a given settlement system, such as acting as a back-up liquidity provider or settlement bank.
7.77 Tests should reflect accurate timeframes for the settlement cycles of assets that might
be liquidated, and the time required to transfer liquidity across borders. In addition, if a regulated institution relies upon liquidity outflows from one system to meet obligations in another, it should consider the risk that operational or settlement disruptions might prevent or delay expected flows across systems. The scenario is relevant for regulated institutions relying upon intra-group transfers or centralised liquidity management.
7.78 A regulated institution should take a conservative approach when setting stress testing
assumptions. Taking account of the type and severity of the scenario, a regulated institution needs to consider the appropriateness of a number of assumptions, potentially including the following list. This list is illustrative, as a regulated institution should use assumptions that are relevant to its business.
Guidelines on Risk Management
Guidelines on Risk Management
7.82 To identify and analyse factors that could have a significant impact on its liquidity
profile, a regulated institution may conduct an analysis of the sensitivity of stress test results to certain key assumptions. Such sensitivity analyses can provide additional indications of a regulated institution’s degree of vulnerability to certain factors. Utilisation of results
7.83 Senior management should review stress test scenarios and assumptions as well as the
results of the stress tests. The regulated institution’s choice of scenarios and related assumptions should be well documented and reviewed together with the stress test results. Stress test results and vulnerabilities and any resulting actions should be reported to and discussed with the board and the Bank. Senior management should integrate the results of the stress testing process into the regulated institution’s strategic planning process (e.g., regulated institution management could adjust its asset-liability composition) and the bank’s day-to-day risk management practices (e.g., through monitoring sensitive cash flows or reducing concentration limits). The results of the stress tests should be explicitly considered in the setting of internal limits.
7.84 Senior management should decide how to incorporate the results of stress tests in
assessing and planning for related potential funding shortfalls in the institution's contingency funding plan. To the extent that projected funding deficits are larger than (or projected funding surpluses are smaller than) implied by the regulated institution’s liquidity risk tolerance, management should consider whether to adjust its liquidity position or to bolster the regulated institution’s contingency plan in consultation with the board. (e) Contingency Planning Principle 11: A bank should have a formal contingency funding plan (CFP) that clearly sets out the strategies for addressing liquidity shortfalls in emergency situations. A CFP should outline policies to manage a range of stress environments, establish clear lines of responsibility, include clear invocation and escalation procedures and be regularly tested and updated to ensure that it is operationally robust.
7.85 A contingency funding plan (CFP) is the compilation of policies, procedures and action
plans for responding to severe disruptions to a regulated institution’s ability to fund some or all of its activities in a timely manner and at a reasonable cost.
7.86 CFPs should be commensurate with a regulated institution’s complexity, risk profile,
scope of operations and role in the financial systems in which the regulated institution operates. CFPs should include a clear description of a diversified set of viable, readily available and flexibly deployable potential contingency funding measures for preserving liquidity and covering cash-flow shortfalls in various adverse situations. Contingency plans should articulate available potential contingency-funding sources and the amount of funds a regulated institution estimates can be derived from these sources; clear escalation/prioritisation procedures detailing when and how each of the actions can and should be activated; and the lead time needed to tap additional funds from each of the contingency sources. The CFP should provide a framework with a high degree of flexibility so that a regulated institution can respond quickly in a variety of situations. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.87 The CFP’s design plans and procedures should be closely integrated with the regulated
institution’s ongoing analysis of liquidity-risk and with the results of the scenarios and assumptions used in stress tests. Therefore, the plan should address different time horizons, including intra-day. Statement of plan, contingency procedures, roles and responsibilities
7.88 CFPs should prepare the regulated institution to manage a range of scenarios of severe
liquidity stress that include both institution-specific and more general market-wide stress, as well as the potential interaction between them. The plan should include a diversified menu of options for management to have an overview of the potentially available contingency measures. Regulated institutions should also examine the time periods for which measures can be carried out under various assumptions and stresses.
7.89 CFPs should contain clear policies and procedures that will enable the regulated
institution’s management to make timely and well-informed decisions, execute contingency measures swiftly and proficiently, and communicate effectively to implement the plan efficiently, including:
Guidelines on Risk Management
Design of contingency funding plans
7.92 When designing its CFP, a regulated institution should account for (a) the impact of
stressed market conditions on its ability to sell or securitise assets; (b) the link between asset market and funding liquidity (e.g., the extensive or complete loss of typically available market funding options); (c) second-round and reputational effects related to execution of contingency funding measures; and (d) the potential to transfer liquidity across group entities, borders and lines of business, taking into account legal, regulatory, operational and time zone restrictions and constraints. These elements should reflect previous experiences of the regulated institution or other institutions, expert judgment, market practice and insights that the institution has gained via the performance of stress tests.
7.93 A regulated institution’s CFP (as well as day-to-day liquidity risk management) should
reflect central bank lending programmes and collateral requirements, including facilities that form part of normal liquidity-management operations (e.g., the availability of seasonal credit). The inclusion of central bank lending in a CFP should consider the types of lending facilities, acceptable collateral, the operational procedures to access central bank funds and potential reputational risk involved in accessing them.
7.94 The CFP should also include potential steps to meet payments on an intraday basis (see
principle 8). In situations where intra-day liquidity sources become scarce, a regulated institution should have the ability to identify essential payments and to sequence or
schedule payments on the basis of priority. In the event of severe disruptions, it is also
important that a regulated institution has the ability to acquire additional sources of intra-day liquidity, including by identifying and mobilising additional collateral. As with stress tests, the CFP should acknowledge that time-critical settlement needs may arise not only from the regulated institution’ own transactions, but also from those of its customers, and from its provision of services to payment and settlement systems (e.g., by acting as a contingency liquidity provider). The CFP should take into account the risk management procedures of all relevant systems and therefore be sufficiently robust to handle simultaneous disruptions in multiple payment and settlement systems.
7.95 It is particularly important that in developing and analysing CFPs and stress scenarios,
the relevant institution personnel are aware of the operational procedures needed to transfer liquidity and collateral across different entities and systems and the restrictions that govern such transfers. Realistic timelines for such transfers should be incorporated into liquidity modelling. Assets that are intended to be pledged for collateral in the event that back-up funding sources are used must be in a legal entity and location consistent with management’s funding plans. Testing, update and maintenance
7.96 CFPs should be reviewed and tested regularly to ensure their effectiveness and
operational feasibility. Key aspects of this testing include ensuring that roles and responsibilities are appropriate and understood, confirming that contact information is up to date, proving the transferability of cash and collateral (especially across borders and entities) and reviewing that the necessary legal and operational documentation is in place to execute the plan at short notice. A regulated institution should regularly test key assumptions, such as the ability to sell or buy-back certain assets or periodically Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management draw down credit lines. Management should review all aspects of the plan, following each exercise and ensure that follow-up actions are delivered. Senior management should review and update the CFP at least every year for the board’s approval, or more often as business or market circumstances change.
7.97 The CFP should be consistent with the regulated institution’s business continuity plans
and should be operational under situations where business continuity arrangements have been invoked. Therefore, a regulated institution should ensure effective coordination between teams managing liquidity crises and business continuity. Liquidity-crisis team members and alternates should have ready access to CFPs on and off site. CFPs should be maintained in a corporate central repository as well as at locations that would facilitate quick implementation by responsible parties under emergency situations. (f) Stock of Liquid Assets Principle 12: A bank should maintain a cushion of unencumbered, high-quality liquid assets to be held as insurance against a range of liquidity stress scenarios, including those that involve the loss or impairment of unsecured and typically available secured funding sources. There should be no legal, regulatory or operational impediment to using these assets to obtain funding.
7.98 A crucial element of a regulated institution’s resilience to liquidity stress is the
continuous availability of an adequate cushion of unencumbered, high-quality liquid assets that can be sold or pledged to obtain funds in a range of stress scenarios. The size of the cushion of unencumbered, high-quality liquid assets held as insurance against liquidity stress should be explicitly related to the estimates of liquidity needs under stress. Estimates of liquidity needs during periods of stress should incorporate both contractual and non-contractual cash flows, including the possibility of funds being withdrawn, and they should assume the inability to obtain unsecured funding as well as the loss or impairment of access to funds secured by assets other than the safest, most liquid assets.
7.99 The size of the liquidity cushion should be aligned with the risk tolerance of a regulated
institution. Key considerations include assumptions about the size of cash flow mismatches, the duration and severity of stress and the liquidation or borrowing value of assets (i.e., the estimated cash available to the regulated institution if assets are liquidated or used as collateral for secured funding) in stress situations. A regulated institution should ensure that its liquid asset cushion is sized to maintain sufficient resilience to unexpected stress while it continues to meet its daily payment and settlement obligations on a timely basis for the duration of the stress. In doing so, the regulated institution should take into account other tools and resources it has available to manage intra-day risks.
7.100 With respect to the composition of its liquidity cushion, a regulated institution should
hold a core of the most reliably liquid assets, such as cash and high-quality 16 government bonds or similar instruments, to guard against the most severe stress scenarios. For insuring against less intense, but longer duration stress events, a regulated 16 See the Bank’s Guidelines on Liquidity Coverage Ratio for the classification of high-quality liquid assets. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management institution may choose to widen the composition of the cushion to hold other unencumbered liquid assets that are marketable (i.e., can be sold or used as collateral in sale and repurchase agreements) without resulting in substantial losses or discounts.
7.101 The marketability of individual assets may differ depending on the stress scenario and
timeframe involved. General characteristics that tend to increase the liquidity of an asset include the transparency of its structure and risk profile; ease and certainty of valuation; central bank eligibility; depth of the market for the asset, including holdings of the regulated institution relative to normal market turnover; and the institution’s own name and presence in the relevant markets. A regulated institution should not assume that a liquid market will exist for a given asset in all stress scenarios simply because such a market exists in normal times. There should be no legal, regulatory or operational impediment to the use of these assets to obtain funding, as these assets should be always available to meet liquidity needs as they arise. The regulated institution should be ready and prepared to use these assets in the event of severe stress. The cushion should, however, provide a backstop, rather than the first line of defence.
7.102 A regulated institution should be realistic about how much cash it will be able to obtain
from the relevant central bank against eligible assets. Moreover, a regulated institution should not rely on the possibility of a central bank altering the amount of or the terms on which it provides liquidity because of changes in the market. (g) Public disclosure Principle 13: A bank should publicly disclose information on a regular basis that enables market participants to make an informed judgement about the soundness of its liquidity risk management framework and liquidity position.
7.103 A regulated institution should disclose all appropriate information about its
management of liquidity risk to enable its shareholders and other stakeholders to make an informed judgment about the regulated institution’s ability to meet its liquidity needs. Such information should include (a) the regulated institution’s organisation to manage its liquidity risk; (b) roles and responsibilities of the board, senior management and any committees established to implement and monitor the implementation of the framework; (c) an outline of liquidity tolerance acceptable and how compliance is effected; (d) an outline of any limit-setting policies; (e) information about any stress tests conducted; and (f) information about the liquid asset ratio, liquidity coverage ratio and net stable funding ratio.
7.104 A regulated institution should follow the Circular on Pillar 3 Market Disclosure to
comply with this principle.
LIQUIDITY MONITORING TOOLS
7.105 The appendix outlines metrics to be used as consistent monitoring tools. These metrics
capture specific information related to a regulated institution’s cash flow, balance-sheet Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management structure, available unencumbered collateral and certain market indicators.
7.106 These metrics, together with the LCR standard, provide the cornerstone of information
that assists the Bank to assess the liquidity risk of a bank. In utilising these metrics, the Bank will take action when potential liquidity difficulties are signaled through a negative trend in the metrics, or when a deteriorating liquidity position is identified, or when the absolute result of the metric identifies a current or potential liquidity problem.
7.107 The liquidity monitoring tools described in this appendix are not standards and thus do
not have minimum required thresholds. However, the Bank reserves the right to set supervisory requirements for any of the liquidity metrics as required.
7.108 The metrics discussed include the following:
(a) Contractual maturity mismatch
(b) Concentration of funding
(c) Available unencumbered assets
(d) LCR by significant currency
(e) Market related monitoring tools
(a) Contractual maturity mismatch
(i) Objective
7.108 The contractual maturity mismatch profile identifies the gaps between the contractual
inflows and outflows of liquidity for defined time bands. These maturity gaps indicate how much liquidity a bank would potentially need to raise in each of these time bands if all outflows occurred at the earliest possible date. This metric provides insight into the extent to which the bank relies on maturity transformation under its current contracts. (ii) Definition and practical application of the metric Contractual cash and security inflows and outflows from all on- and off-balance sheet items, mapped to defined time bands based on their respective maturities.
7.109 A bank should report contractual cash and security flows in the relevant time bands
based on the residual contractual maturity. The Bank will determine the specific template, including required time bands, by which data must be reported. The Bank will define the time buckets which will assist in understanding the bank’s cash-flow position. Possibilities include requesting the cash flow mismatch to be constructed for the
Guidelines on Risk Management such as interest rate swaps and options should also be included to the extent that their contractual maturities are relevant to the understanding of the cash flows.
7.111 At a minimum, the data collected from the contractual maturity mismatch should
provide data on the categories outlined in the LCR. Some additional accounting (nondated) information, such as capital or non-performing loans may need to be reported separately. (iii) Contractual cash-flow assumptions
7.112 No roll-over of existing liabilities is assumed to take place. For assets, the bank is
assumed not to enter into any new contracts.
7.113 Contingent liability exposures that would require a change in the state of the world (such
as contracts with triggers based on a change in prices of financial instruments or a downgrade in the bank's credit rating) need to be detailed, grouped by what would trigger the liability, with the respective exposures clearly identified.
7.114 A bank should record all securities flows to allow the supervisor to monitor securities
movements that mirror corresponding cash-flows as well as the contractual maturity of collateral swaps and any uncollateralised stock lending/borrowing where stock movements occur without any corresponding cash-flows.
7.115 A bank should report separately the customer collateral received that the bank is
permitted to rehypothecate as well as the amount of such collateral that is rehypothecated at each reporting date. The report will highlight instances when the bank is generating mismatches in the borrowing and lending of customer collateral. (iv) Use of the metric
7.116 Banks will provide the raw data to the Bank with no assumptions included in the data.
Given that the metric is based solely on contractual maturities with no behavioural assumptions, the data will not reflect actual future forecast flows under the current, or future, strategy or plans, that is, under a going-concern view. Contractual maturity mismatches do not capture outflows that a bank may make in order to protect its franchise, even where contractually there is no obligation to do so.
7.117 Banks should also conduct their own maturity mismatch analyses based on goingconcern behavioural assumptions of the inflows and outflows of funds in both normal
situations and under stress. These analyses should be based on strategic and business plans and should be shared and discussed with the supervisor, and the data provided in the contractual maturity mismatch should be used as a basis of comparison. When banks are contemplating material changes to their business models, they are required to submit projected mismatch reports as part of an assessment of impact of such changes on prudential supervision. Examples of such changes include potential major acquisitions or mergers or the launch of new products that have not yet been contractually entered into. The Bank will assess whether the assumptions underpinning the projected mismatches are prudent. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.118 A bank should be able to indicate how it plans to bridge any identified gaps in its
internally generated maturity mismatches and explain why the assumptions applied differ from the contractual terms. The Bank will review the explanations and assess the feasibility of the bank’s funding plans. (b) Concentration of funding (i) Objective
7.119 This metric is meant to identify those sources of wholesale funding that are of such
significance that withdrawal of this funding could trigger liquidity problems. The metric thus encourages the diversification of funding sources. (ii) Definition and practical application of the metric (i) Funding liabilities sourced from each significant counterparty as a % of total liabilities (ii) Funding liabilities sourced from each significant product/instrument as a % of total liabilities (iii) List of asset and liability amounts by significant currency (iii) Calculation of the metric
7.120 The numerator for (i) and (ii) is determined by examining funding concentrations by
counterparty or type of instrument/product. Banks should monitor both the absolute percentage of the funding exposure and significant increases in concentrations. Significant counterparties
7.121 The numerator for counterparties is calculated by aggregating the total of all types of
liabilities to a single counterparty or group of connected or affiliated counterparties, as well as all other direct borrowings, both secured and unsecured, which the bank can determine arise from the same counterparty 17 (such as for overnight commercial paper/certificate of deposit (CP/CD) funding).
7.122 A significant counterparty is defined as a single counterparty or group of connected or
affiliated counterparties accounting in aggregate for more than one percent of the bank’s balance sheet, although in some cases there may be other defining characteristics based on the funding profile of the bank. A group of connected counterparties is, in this context, defined in the same way as in the Guidelines on Large Exposure in the case of consolidated reporting for solvency purposes. Intra-group deposits and deposits from related parties should be identified specifically under this metric, regardless of whether 17 For some funding sources, such as debt issuances that are transferable across counterparties (such as CP/CD funding dated longer than overnight), it is not always possible to identify the counterparty holding the debt. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management the metric is being calculated at a legal entity or group level, owing to the potential limitations to intra-group transactions in stressed conditions. Significant instruments/products
7.123 The numerator for a type of instrument/product should be calculated for each
individually significant funding instrument/product, as well as by calculating groups of similar types of instruments/products.
7.124 A significant instrument/product is defined as a single instrument/product or group of
similar instruments/products that in aggregate amount to more than 1 percent of the bank’s total balance sheet. Significant currencies
7.125 To capture the amount of structural currency mismatch in a bank’s assets and liabilities,
banks are required to provide a list of the amount of assets and liabilities in each significant currency.
7.126 A currency is considered significant if the aggregate liabilities denominated in that
currency amount to at least 5 percent of the bank’s total liabilities. Time horizons
7.127 The above metrics should be reported separately for the time horizons of less than 1
month, 1–3 months, 3–6 months, 6–12 months, and for longer than 12 months. (iv) Use of the metric
7.128 In using this metric to determine the extent of funding concentration to a certain
counterparty, both the Bank and supervised bank must recognise that it may not be possible to identify the actual funding counterparty for many types of debt. 18 The actual concentration of funding sources therefore could most likely be higher than this metric indicates. The list of significant counterparties could change frequently, particularly during a crisis. The Bank shall consider the potential for hedging behaviour on the part of funding counterparties in the case of an institution-specific problem. In addition, under market-wide stress, multiple funding counterparties and the bank itself may experience concurrent liquidity pressures, making it difficult to sustain funding, even if sources appear well diversified.
7.129 In interpreting this metric, a bank must recognise that the existence of bilateral funding
transactions may affect the strength of commercial ties and the amount of the net outflow. 19
18 For some funding sources, such as debt issuances that are transferable across counterparties (such as CP/CD funding dated longer than overnight), it is not always possible to identify the counterparty holding the debt. 19 Where the monitored bank also extends funding or has large unused credit lines outstanding to the “significant counterparty”. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.130 To capture potential foreign-exchange risk, comparison of the amount of assets and
liabilities by currency will provide the Bank with a baseline for discussions with the banks about how they manage any currency mismatches through swaps and forwards. It is meant to provide a base for further discussions with the banks rather than provide a snapshot view of the potential risk. (c) Available unencumbered assets (i) Objective
7.131 These metrics provide the Bank with data on the quantity and key characteristics,
including currency denomination and location, of banks’ available unencumbered assets. These assets have the potential to be used as collateral to raise additional HQLA or secured funding in secondary markets or are eligible at central banks and may potentially be additional sources of liquidity for the bank. (ii) Definition and practical application of the metric (i) Available unencumbered assets that are marketable as collateral in secondary markets and (ii) Available unencumbered assets that are eligible for central banks’ standing facilities
7.132 A bank is to report the amount, type and location of available unencumbered assets that
could serve as collateral for secured borrowing in secondary markets at prearranged or current haircuts at reasonable costs.
7.133 Likewise, a bank should report the amount, type and location of available
unencumbered assets that are eligible for secured financing with relevant central banks at prearranged (if available) or current haircuts at reasonable costs for standing facilities only (i.e., excluding emergency assistance arrangements). This would include collateral that has already been accepted at the central bank but remains unused. For assets to be counted in this metric, the bank must have already put in place the operational procedures that would be needed to monetise the collateral.
7.134 A bank should report separately the customer collateral received that the bank is
permitted to deliver or re-pledge, as well as the part of such collateral that it is delivering or re-pledging at each reporting date.
7.135 In addition to providing the total amounts available, a bank should report these items
categorised by significant currency. A currency is considered significant if the aggregate stock of available unencumbered collateral denominated in that currency amounts to at least 5 percent of the associated total amount of available unencumbered collateral (for secondary markets or the central bank).
7.136 Furthermore, a bank must report the estimated haircut that the secondary market or
central bank would require for each asset. In the case of the latter, a bank would be expected to reference, under business as usual, the haircut required by the central bank that it would normally access. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
7.137 As a second step after reporting the relevant haircuts, a bank should report the expected
monetised value of the collateral (rather than the notional amount) and where the assets are actually held, in terms of the location of the assets and what business lines have access to those assets. (iii) Use of the metric
7.138 This metric are useful for examining the potential for a bank to generate an additional
source of HQLA or secured funding. They will provide a standardised measure of the extent to which the LCR can be quickly replenished after a liquidity shock either via raising funds in private markets or using central bank standing facilities. The metrics do not, however, capture potential changes in counterparties’ haircuts and lending policies that could occur under either a systemic or idiosyncratic event and could provide false comfort that the estimated monetised value of available unencumbered collateral is greater than it would be when it is most needed. The Bank shall keep in mind that these metrics do not compare available unencumbered assets with the amount of outstanding secured funding or any other balance sheet scaling factor. To gain a more complete picture, the information generated by these metrics shall be complemented with the maturity mismatch metric and other balance sheet data. (d) LCR by significant currency (i) Objective
7.139 While it is required that LCR be met in one single currency, to better capture potential
currency mismatches, both the Bank and supervised banks should also monitor LCR in significant currencies. The monitoring would make it easy for both a bank and the Bank to track potential currency mismatches that might arise. (ii) Definition and practical application of the metric Foreign Currency LCR = Stock of HQLA in each significant currency/total net cash outflows over a 30-day time period in each significant currency (Note: Amount of total net foreign-exchange cash outflows should be net of foreignexchange hedges)
7.140 The stock of high-quality foreign exchange assets and total net foreign exchange cash
outflows should mirror LCR for common currencies. 20
7.141 A currency is considered significant if the aggregate liabilities denominated in that
currency amount is at least 5 percent of a bank’s total liabilities.
7.142 As the foreign currency LCR is not a standard but a monitoring tool, it does not have
an internationally defined minimum requirement. Nonetheless, the Bank shall set Cash flows from assets, liabilities and off-balance sheet items will be computed in the currency that the counterparties are obliged to deliver to settle a contract, independent of the currency to which the contract is indexed (or linked), or the currency whose fluctuation it is intended to hedge. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management minimum monitoring ratios for the foreign-exchange LCR, below which the Bank should be alerted. In this case, the ratio at which the Bank should be alerted would depend on the monitoring thresholds. The Bank shall evaluate a banks’ ability to raise funds in foreign currency markets and the ability to transfer liquid assets from one currency to another and across jurisdictions and legal entities. Therefore, the ratio should be higher for currencies in which the Bank evaluate a bank’s ability to raise funds in foreign currency markets or the ability to transfer liquid assets from one currency to another and across jurisdictions and legal entities to be limited. (iii) Use of the metric
7.143 This metric is meant to allow both the Bank and banks to track potential currency
mismatches that could arise in a time of stress.
(e) Market-related monitoring tools
(i) Objective
High-frequency market data with little or no time lag can be used as an early warning indicator in monitoring potential liquidity challenges at banks. (ii) Definition and practical application of the metric
7.144 While there are many types of data available in the market, the Bank will monitor data
at the following levels to focus on potential liquidity challenges:
Guidelines on Risk Management
Bank-specific information
7.148 To monitor whether the market is losing confidence in a particular institution or has
identified risks at an institution, it is useful to collect information on equity prices, credit default swap (CDS) spreads, money-market trading prices, the situation of roll-overs and prices for funding tenures, the price/yield of bank debenture or subordinated debt in the secondary market. (iii) Use of the metric/data
7.149 Information such as equity prices and credit spreads is readily available. However, the
accurate interpretation of such information is important. For instance, the same CDS spread in numerical terms may not necessarily imply the same risk across markets due to market-specific conditions such as low market liquidity. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
8. OPERATIONAL RISK MANAGEMENT 21
8.1 Operational risk is defined as the risk of loss resulting from inadequate or failed internal
processes, people and systems or from external events. Therefore, operational-risk management seeks to identify why a loss occurred and at the broadest level includes the breakdown into four causes: people, processes, systems and external factors.
8.2 Every regulated institution should establish a comprehensive system, which will enable
it to identify, assess, monitor and control or mitigate operational risk. This includes, codifying all policies and procedures for risk management controls, designing the operational-risk assessment methodology and establishing a risk-reporting system for operational risk. (a) Operational Risk Culture
8.3 A regulated institution with a strong culture of risk management and ethical business
practices is less likely to experience potentially damaging operational risk events and it is better placed to deal effectively with those events when they occur.
8.4 The board should establish a code of conduct, which sets clear expectations for the
integrity and ethical values of the highest standard and identify acceptable business practices and prohibited conflicts. Clear expectations and accountabilities ensure that its employees understand their roles and responsibilities for risk, as well as their authority to act.
8.5 Compensation policies should be aligned to the regulated institution’s statement of risk
appetite and tolerance, long-term strategic direction, financial goals and overall safety and soundness. They should also appropriately balance risk and reward.
8.6 The board of directors should approve and review a risk appetite and tolerance
statement for operational risk that articulates the nature, types and levels of operational risk that the regulated institution is willing to assume.
8.7 Senior management should ensure that all staff members of the regulated institution are
accorded training on operational risk. The training should reflect the seniority, role and responsibilities of the individuals for whom it is intended. (b) Operational-Risk Identification and Measurement
8.8 Senior management should identify and assess the operational risk inherent in all
material products, activities, processes and systems to make sure that the inherent risks and incentives are well understood.
8.9 Effective risk identification considers both internal and external factors. Sound risk
assessment allows the regulated institution to better understand its risk profile and allocate risk management resources and strategies most effectively. 21 Reference Documents: Guidelines on the Revised International Convergence of Capital Measurement and Capital Standards for Botswana (Basel II) (September 8, 2015); Basel Core Principles for Effective Banking Supervision (Principle 25), and Principles for the Sound Management of Operational Risk (2011) Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
8.10 The following are some of the tools, which may be used for identifying, measuring and
assessing operational risk:
(i) Audit Findings: While audit findings primarily focus on control weaknesses and vulnerabilities, can also provide insight into the inherent risk, due to internal or external factors; (ii) External Data Collection and Analysis: External data elements consist of gross operational loss amounts, dates and recoveries. Relevant causal information for operational loss events occurring at organisations other than the regulated institution could be compared with internal loss data, or used to explore possible weaknesses in the control environment or consider previously unidentified risk exposures; (iii) Business Process Mapping: identifies the key risk points in the overall business process. Process maps can reveal individual risks, risk inter-dependencies and areas of control or risk management weakness; (iv) Risk and Performance Indicators: Key performance indicators (KPIs) provide insight into the main drivers of exposure associated with key risks and the status of operational processes, which may, in turn, provide insight into operational weaknesses, failures and potential loss. Risk and performance indicators are often paired, with escalation triggers to warn when risk levels approach or exceed thresholds/limits and/or prompt mitigation measures; (v) Scenario Analysis: Scenario analysis involves obtaining expert opinion of business line managers and risk managers to identify potential operational risk events and assess their potential outcome. Given the subjectivity of the scenario process, a robust governance framework is essential to ensure the integrity and consistency of the process. (vi) Internal Loss Data Collection and Analysis: Internal operational-loss data provides meaningful information for assessing a regulated institution’s exposure to operational risk and the effectiveness of internal controls. The regulated institution may also find it useful to capture and monitor operational risk contributions to credit and market-risk related losses in order to obtain a more complete view of its operational risk exposure; (vii) Risk Assessments: In a risk assessment/risk self-assessment, a regulated institution assesses the processes underlying its operations against a library of potential threats and vulnerabilities and considers their potential impact. A similar approach, risk control self-assessments (RCSA), evaluates inherent risk (the risk before controls are considered), the effectiveness of the control environment, and residual risk (the risk exposure after controls are considered). Scorecards build on RCSAs by weighting residual risks to provide a means of translating the RCSA output into metrics that give a relative ranking of the control environment; (viii) Measurement: Larger institutions may find it useful to quantify their exposure to Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management operational risk by using the output of the risk assessment tools as inputs into a model that estimates operational-risk exposure. (ix) Comparative Analysis: Comparative analysis consists of comparing the results of the various assessment tools to provide a more comprehensive view of a regulated institution’s operational risk profile.
8.11 A regulated institution should ensure that the internal pricing and performance
measurement mechanisms appropriately take into account operational risk. Where operational risk is not considered, risk-taking incentives might not be appropriately aligned with the risk appetite and tolerance.
8.12 A regulated institution should systematically track and record the frequency, severity
and other information on individual loss events. Such data could provide meaningful information for assessing the regulated institution’s exposure to operational risk and developing a policy to mitigate or control that risk. (c) Operational-Risk Monitoring, Control and Mitigation
8.13 The board and senior management should implement a process to regularly monitor
operational-risk profiles and material exposures to losses.
8.14 A regulated institution should have a strong control environment that utilises policies,
processes and systems; appropriate internal controls; and appropriate risk mitigation and/or transfer strategies. Internal controls should be designed to provide reasonable assurance that a regulated institution will have efficient and effective operations; safeguard its assets; produce reliable financial reports; and comply with applicable laws and regulations. A sound internal control programme should, at the minimum, comprise the following components, which are integral to the risk management process:
(i) Management oversight of the risk control practices; (ii) Risk recognition and assessments; (iii) Control activities and segregation of duties; (iv) Information and communication; and (v) Monitoring activities and correction of deficiencies.
8.15 Control processes and procedures should include a system for ensuring compliance with
policies. Examples of principal elements of a policy compliance assessment include:
(i) top-level reviews of progress towards stated objectives; (ii) verifying compliance with management controls; (iii) review of the treatment and resolution of instances of non-compliance; (iv) evaluation of the required approvals and authorisations to ensure accountability to an appropriate level of management; (v) tracking reports for approved exceptions to thresholds or limits, management overrides and other deviations from policy; and Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(vi) ensuring the adequacy and effectiveness of controls.
8.16 The regulated institution should institute segregation of duties. Assignments that
establish conflicting duties for individuals or a team without dual controls or other risk -mitigation measures may enable concealment of losses, errors or other inappropriate actions. Therefore, areas of potential conflict of interest should be identified, minimised and be subject to careful independent monitoring and review.
8.17 A regulated institution should also ensure that internal controls are adequate and
effective for each function, process or products. Examples of these controls include:
(i) clearly established authorities and/or processes for approval; (ii) close monitoring of adherence to assigned risk thresholds or limits; (iii) safeguards for access to, and use of, assets and records; (iv) appropriate staffing level and training, to ensure competence in the discharge of the responsibilities; (v) on-going processes to identify business lines or products where returns appear to be out of line with targets or expected outcomes; (vi) regular verification and reconciliation of transactions and accounts; and (vii) Staff leave policy that provides for officers and employees being absent from their duties for a period of not less than two consecutive weeks at least once a year.
8.18 Effective use and sound implementation of technology can contribute to an effective
control environment. However, automated processes introduce risks that must be addressed through sound technology governance and infrastructure risk management programmes.
8.19 The use of technological products, activities, processes and delivery channels exposes
a regulated institution to strategic, operational and reputational risks, and the possibility of material financial loss. Therefore, a regulated institution should have an integrated approach to identifying, measuring, monitoring, controlling and managing technology risks. The integrated approach should encompass the following key aspects:
(i) governance and oversight controls that ensure that technology and outsourcing arrangements are aligned with and supportive of a regulated institution’s business objectives; (ii) policies and procedures that facilitate identification and assessment of risk; (iii) establishment of a risk appetite and tolerance statement, as well as performance expectations, to assist in controlling and managing risk; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(iv) implementation of an effective control environment and the use of risk-transfer strategies that mitigate risk; and (v) monitoring processes that test for compliance with policy thresholds or limits.
8.20 Management should ensure that a regulated institution has a sound technology
infrastructure, which meets current and long-term business requirements by providing sufficient capacity for normal activity levels, as well as peaks during periods of market stress; ensuring data and system integrity, security and availability; and supporting integrated and comprehensive risk management.
8.21 Mergers and acquisitions (M/As) resulting in fragmented and disconnected-technology
infrastructure, cost-cutting measures or inadequate investment, can undermine a regulated institution’s ability to aggregate and analyse information across risk dimensions or the consolidated enterprise, particularly during periods of high growth. Management should make appropriate capital investment or otherwise provide for a robust infrastructure, particularly before M/As are consummated, high-growth strategies are initiated, or new products are introduced.
8.22 Outsourcing is another business strategy that can expose a regulated institution to
strategic, operational and reputational risks and the possibility of material financial loss. Therefore, the board and senior management are responsible for understanding the operational risks associated with outsourcing arrangements and ensuring that effective risk-management policies and practices are in place to manage the risk in outsourcing activities. Outsourcing policies and risk management activities should encompass, among others, the following:
(i) procedures for determining whether and how activities can be outsourced; (ii) processes for conducting due diligence in the selection of potential service providers; (iii) sound structuring of the outsourcing arrangement, including ownership and confidentiality of data, as well as termination rights; (iv) programmes for managing and monitoring the risks associated with the outsourcing arrangement, including the financial condition of the service provider; (v) establishment of an effective control environment within a regulated institution and the service provider; (vi) development of viable contingency plans; and (vii) execution of comprehensive contracts and/or service level agreements with a clear allocation of responsibilities between the outsourcing provider and the regulated institution. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
8.23 In circumstances where internal controls do not adequately address risk and exiting the
risk is not a reasonable option, Management can complement controls by seeking to transfer the risk to another party, such as through third party insurance. The board should determine the maximum loss exposure a regulated institution is willing to take and has the financial capacity to absorb, and should perform an annual review of a regulated institution's risk and insurance management programme. While the specific insurance or risk-transfer needs of a regulated institution should be determined on an individual basis, many jurisdictions have regulatory requirements that must be taken into consideration.
8.24 Consistent with the requirement of Section 24(2) of the Banking Act, 2023, a regulated
institution must cover operational risk relating to professional negligence or create a reserve out of its income, specifically for professional negligence and related risks.
8.25 Risk transfer is an imperfect substitute for sound controls and risk-management
programmes. Therefore, a regulated institution should view risk transfer tools as complementary to, rather than a replacement for, thorough internal operational-risk control. Having mechanisms in place to quickly identify, recognise and rectify distinct operational risk errors can greatly reduce exposures. Careful consideration should be given to the extent to which risk-mitigation tools, such as insurance, truly reduce risk, transfer the risk to another business sector or area, or create a new risk (e.g., counterparty risk). (d) Operational-Risk Reporting
8.26 Operational-risk reports may contain internal financial, operational and compliance
indicators, as well as external market or environmental information about events and conditions that are relevant to decision making. Operational-risk reports should include:
(i) breaches of the regulated institution’s risk appetite and tolerance statement, as well as thresholds or limits; (ii) details of recent significant internal operational risk events and losses; and (iii) relevant external events and any potential impact on the regulated institution and operational risk capital.
8.27 Data capture and risk-reporting processes should be analysed periodically with a view
to continuously enhancing risk management performance, as well as advancing riskmanagement policies, procedures and practices.
8.28 Appropriate reporting mechanisms should be in place at the board, senior management
and business line levels that support proactive management of operational risk.
8.29 A regulated institution should continuously improve the quality of operational-risk
reporting by ensuring that its reports are comprehensive, accurate, consistent and actionable across business lines and products. Risk reports should be manageable in scope and volume because effective decision-making can be impeded by deficient or excessive amounts of data. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
8.30 Reporting should be timely and a regulated institution should be able to produce reports
in both normal and stressed-market conditions. The frequency of reporting should reflect the risks involved and the pace and nature of changes in the operating environment.
8.31 Reports generated by (and/or for) supervisory authorities should also be reported
internally to senior management and the board, where appropriate.
(e) Business Resiliency and Continuity
8.32 A regulated institution should have business resiliency and continuity plans in place to
ensure an ability to operate on an ongoing basis and limit losses in the event of severe business disruption.
8.33 A regulated institution can be exposed to disruptive events, some of which may be
severe and result in inability to fulfil some or all of its business obligations. To provide resiliency against this risk, a regulated institution should establish business continuity plans commensurate with the nature, size and complexity of its operations. Such plans should take into account different types of likely or plausible scenarios to which the regulated institution may be vulnerable.
8.34 Continuity management should incorporate business impact analysis, recovery
strategies, testing, training and awareness programmes, communication and crisismanagement programmes. A regulated institution should identify critical business operations, key internal and external dependencies and appropriate resilience levels. Plausible disruptive scenarios should be assessed for their financial, operational and reputational impact, and the resulting risk assessment should be the foundation for recovery priorities and objectives. Continuity plans should establish contingency strategies, recovery and resumption procedures and communication plans for informing management, employees, regulatory authorities, customers, suppliers, and, where appropriate, civil authorities.
8.35 A regulated institution should periodically review its continuity plans to ensure that
contingency strategies remain consistent with current operations, risks, threats, resiliency requirements and recovery priorities. Training and awareness programmes should be implemented to ensure that staff can effectively execute contingency plans. Plans should be tested periodically to ensure that recovery and resumption objectives and timeframes can be met. Where possible, a regulated institution should participate in disaster recovery and business continuity testing with key service providers. Results of formal testing activity should be reported to senior management and the board.
8.36 The regulated institution is required to conduct regular stress-test scenarios. The stress
tests should be rigorous, forward looking and capable of identifying possible events or changes in market conditions that could adversely impact the regulated institution’s business operations and assess the regulated institution’s ability to withstand such changes. Such stress testing should alert management to any adverse unexpected outcomes related to operational risk and provide an indication of how much capital might be needed to absorb losses should large shocks occur. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
8.37 A regulated institution must hold adequate capital to absorb operational-risk losses.
Computation of such capital must be consistent with the entity’s determination of the regulatory capital charge for operational risk under the Revised International Convergence of Capital Measurement and Capital Standards for Botswana (Basel II). Money Laundering and Financial Crime Risks
8.38 All regulated institutions must ensure full compliance with the Financial Action Task
Force (FATF) Recommendations and all applicable legal, regulatory and operational measures for combating money laundering, terrorist financing and the financing of weapons of mass destruction, and other related threats to the integrity of the Botswana financial system.
8.39 Consistent with the requirements of the FATF Recommendations and the Financial
Intelligence (FIA) Act (CAP 08:07), all regulated institutions must undertake preventative measures to prevent their entities from being used as conduits for money laundering and terrorism-financing activities. Such preventive measures, should, at a minimum, include customer due diligence, record keeping and additional measures for specific customers and activities, such as politically exposed persons (PEPs), correspondent banking, money or value transfer services, wire transfers, etc.
8.40 A regulated institution should identify applicable risks and develop policies for the
effective management of money laundering and terrorist financing risks.
8.41 Every regulated institution should adopt a risk-based approach (RBA) in the
management of AML/CFT risks in order to target their resources more effectively and apply preventive measures that are commensurate with the nature of risks. In implementing a RBA, regulated institutions should have in place processes to identify, assess, monitor, manage and mitigate money laundering and terrorist financing risks. Where there are elevated risks, regulated institutions should take enhanced measures to manage and mitigate those risks.
8.42 All regulated institutions must ensure full compliance with the sanction laws and/or
requirements related to terrorist financing as issued by the FIA and/or the United Nations Security Council (UNSC). In addition to the UNSC sanction lists, a regulated institution may comply with sanction lists issued by jurisdictions in which the institution has correspondent banking relationships, to minimise the risk of being de-risked. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
9. COUNTRY AND TRANSFER RISK 22
9.1 When a regulated institution engages in granting credit internationally, it assumes in
addition to standard credit risk, risk associated with conditions in the home country of a foreign borrower or counterparty (country and transfer risk). Country or sovereign risk encompasses the entire spectrum of risks arising from the economic, political and social environments of a foreign country that may have potential consequences for foreigners’ debt and equity investments in that country. Transfer risk focuses more specifically on a borrower’s capacity to obtain the foreign exchange necessary to service its cross-border debt and other contractual obligations. In all instances of international transactions, a regulated institution needs to understand the integration of financial markets and the potential for spill-over effects from one country to another or contagion effects for an entire region.
9.2 A regulated institution that engages in granting credit outside Botswana should,
therefore, have adequate policies and procedures, approved by the regulated institution’s board of directors, that identify, measure, evaluate, monitor, report and control country and transfer risk in their international lending and investment activities. The processes should be consistent with the risk profile, systemic importance and risk appetite of the regulated institution. It should take into account market and macroeconomic conditions and provide a comprehensive institution-wide view of country and transfer-risk exposure.
9.3 Country exposures (including intra-group exposures) should be identified, monitored
and managed on a regional and individual country basis, and the regulated institution should ensure adherence to established limits. Regulated institutions are required to monitor and evaluate developments in country and transfer risk and apply appropriate counter measures. The monitoring of country and transfer risk factors should incorporate:
(i) the potential default of foreign private sector counterparties arising from countryspecific economic factors; and (ii) the enforceability of loan agreements and timing and ability to realise collateral under national legal frameworks.
9.4 A regulated institution should have information systems, risk-management systems and
internal control systems that accurately aggregate, monitor and report country exposures (including intra-group exposures) on a timely basis, and ensure adherence to established country-exposure limits.
9.5 A regulated institution is required to include appropriate scenarios into its stress-testing
programme to reflect country and transfer-risk analysis for risk-management purposes. Such stress tests should be performed to identify potential vulnerability to exceptional but plausible events on a regulated institution’s exposure to country and transfer risks and assess the institution’s ability to withstand such changes. The results of stress 22 Basel Committee on Banking Supervision, Core Principles for Effective Banking Supervision (2012) (Principle 21); Research Paper on “Management of Banks’ International Lending (Country Risk Analysis and Country Exposure Measurement and Control”) (March 1982). Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management testing should alert the management to any adverse unexpected outcomes and provide an indication of how much capital might be needed to absorb losses should large shocks occur.
9.6 A regulated institution should regularly submit sufficient information, on a timely basis,
on country and transfer risk for review by the Bank.
Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
10. COMPLIANCE RISK MANAGEMENT 23
10.1 Compliance risk is the risk of legal or regulatory sanctions, material financial loss, or
loss of reputation, which an institution may suffer, as a result of its failure to comply with laws, regulations, prudential guidelines, supervisory actions and directives, rules, internal policies and procedural guidelines, and codes of conduct applicable to its banking activities.
10.2 Compliance risk arises from failure by an institution to conduct its business in
accordance with the business and contractual legal principles applicable in each of the jurisdictions where the institution conducts its business; this could result in unenforceable contracts, litigation, or other adverse consequences. Compliance risk can lead to the revocation of a licence, fines and penalties, payment of damages, deteriorating position in the market, reduced expansion potential, lack of contract enforceability, as well as reputational risk. (a) Compliance-Risk Identification
10.3 Common sources of compliance risk are:
(i) violations or non-compliance with laws and regulations and prescribed standards; (ii) lack of or inadequate compliance with contractual obligations and other legal documentation; (iii) inadequate identification of rights and responsibilities between the regulated institution and its customers; (iv) complaints by customers and other counterparties; (v) harming the interest of third parties; and (vi) litigation procedures, potential exposure and nature of pending or threatened litigation. (b) Compliance-Risk Measurement
10.4 Compliance risk is not easy to measure. A regulated institution needs to define the
appropriate approach to assessing each identified source of risk.
There are various tools used for identifying and assessing compliance risk, such as:
(i) self-assessment - this is where a regulated institution conducts a qualitative assessment of its operations against a list of potential risk vulnerabilities; (ii) risk indicators - these are statistics or matrices that can provide insight into a regulated institution’s risk position; and 23 Basel Committee on Banking Supervision, Compliance and the Compliance Function in Banks (2005); and Basel Committee on Banking Supervision, Corporate Governance Principles for Banks (2014) Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(iii) risk mapping - in this process, various departments or units are outlined by risk types and levels in order to enable effective development of procedures and mitigation measures for the risks identified.
10.5 Compliance risk can also be measured by regular legal reviews of the regulated
institution’s different products and services, and their relevant documentation in order to ensure that all contracts comply with laws and regulations. This review may take place on each transaction individually or may cover the legal adequacy of standardised documentation and procedures. (c) Compliance-Risk Monitoring, Control and Mitigation
10.6 Compliance-risk mitigation factors would include putting in place appropriate
compliance-risk management processes and an effective compliance function in the regulated institution.
10.7 In collaboration with the compliance function, senior management should:
(i) implement the compliance-risk management system approved by the board; (ii) implement an effective organisational structure for compliance-risk management, and be in regular contact with employees that are directly responsible for conducting compliance-risk management (institution’s compliance staff and lawyers); (iii) ensure that all employees are working in order to protect the regulated institution’s reputation; (iv) ensure that sufficient human and technical resources are devoted for compliancerisk management; and (v) ensure that there is on-going compliance-risk management training.
10.8 The size of the regulated institution and complexity of its business activities dictate the
scope of the compliance function and its staffing requirements (number and competencies). Compliance responsibilities may be discharged by staff in different departments or all compliance responsibilities may be conducted by the compliance unit/department.
10.9 The compliance function should be independent, with sufficient resources and clearly
specified activities. The compliance staff, especially the head of compliance, should not be in a position where conflict of interest between his/her compliance responsibilities may arise.
10.10 The head of the compliance function should be a member of senior management and
should not have direct business line responsibilities.
10.11 Compliance risk should be included in the risk-assessment methodology of the
regulated institution. An audit programme that covers the adequacy and effectiveness of a regulated institution’s compliance function should be established, including testing Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management of controls commensurate with the perceived level of risk. This principle implies that the compliance function and the internal audit function should be separate to ensure that the activities of the compliance function are subject to independent review. The audit function should, however keep the head of compliance informed of any audit findings related to compliance risk management. Policies and Procedures
10.12 Compliance-risk management policies and procedures should be clearly defined and
consistent with the nature and complexity of a regulated institution’s activities. The compliance policy should address the following issues:
(i) define responsibilities and ultimately ensure that the board and senior management are fully acquainted with material compliance events; (ii) its relationship with other risk-management functions within the regulated institution and with the internal audit function; (iii) in cases where compliance responsibilities are carried out by staff in different departments, how these responsibilities are to be allocated among the departments; (iv) express its right to obtain access to information necessary to carry out its responsibilities and the corresponding duty of staff to cooperate in supplying this information; (v) its right to conduct investigation of possible breaches of the compliance policy; (vi) its right to freely express and disclose its findings to senior management; and (vii) its right of direct access to the board of directors or a sub-committee of the board. Internal Controls
10.13 The audit with respect to compliance risk should be incorporated into the annual plan
of the regulated institution’s internal audit function.
10.14 The internal audit function should, within its scope of operations, cover the following
aspects of compliance-risk management:
(i) verify that compliance-risk management policies and procedures have been implemented effectively across the regulated institution; (ii) assess the effectiveness of controls for mitigating fraud and risks to reputation; (iii) determine that senior management takes appropriate corrective actions when compliance failures are identified; (iv) ensure that the scope and frequency of the audit plan/programme is appropriate to the compliance-risk exposures; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(v) determine the level of senior management compliance with the Bank’s directives; and (vi)analyse the timeliness and accuracy of compliance risk reports to senior management and the board of directors. (d) Compliance-Risk Reporting
10.15 A regulated institution is responsible for monitoring its compliance-risk profiles on an
ongoing basis by reviewing defined compliance-risk indicators in order to provide management with early warning. The results of these monitoring activities should be included in the regulated institution’s periodic reports.
10.16 A robust MIS should enable the regulated institution to generate data and reports for
use by the board and management.
10.17 A regulated institution should establish a database which should contain, among others,
the type of legal documents (contracts, memorandum of understanding, etc.), period of document validation, and responsible department/unit for document enforcement. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
11. REPUTATIONAL RISK MANAGEMENT 24
11.1 Reputational risk is the potential that negative publicity regarding a regulated
institution’s business practices, whether true or not, will cause a decline in market share, revenue, credibility and lead to costly litigation. Reputational risk may result from a regulated institution’s failure to effectively manage any or all of the other risk types. This risk is real, but not easy to measure.
11.2 Reputational risk can emerge at all business levels and has the following key
components:
(i) corporate reputation risk: this relates to a regulated institution’s performance, strategy, execution and delivery of its services; and (ii) operational or business reputation risk: where an activity, action or stance taken by a regulated institution, any of its affiliates or its officials will impair its image with one or more of its stakeholders, resulting in loss of business and/or disproportionate decrease in the value of the regulated institution. (a) Identification of Reputational Risk
11.3 A regulated institution should conduct a risk-diagnostic review to identify potential
reputational risk areas. The board should require Management to use proven analysis methodologies, as well as independent and objective reviews designed to bring out and analyse both quantitative and qualitative-risk factors and review critical control points within the regulated institution.
11.4 This process should assist the regulated institution to uncover the key risk factors with
high likelihood to give rise to reputational risk. A regulated institution should ensure that the analysis methodology used is highly sensitive to the regulated institution’s particular needs and requirements as well as risk issues emanating from the industry. The review process should be objective.
11.5 Reputational risk could be inherent in the type of business embarked on, or emanate
from environmental and/or governance factors. Therefore, the risk-management methodologies employed must be broad enough to reach all risks in each category. (i) Inherent Reputational Risk
11.6 This risk can arise from the intrinsic feature of products and/or services or mode of their
delivery, which negatively impacts on market and customer satisfaction. Therefore, inherent risks mainly derive from challenges in operational risk, quality assurance and customer satisfaction. (ii) Environmental Risk
11.7 This risk arises from the environment within which business is conducted
(e.g., geographic, industrial, political and societal). Although these aspects are not 24 Basel Committee on Banking Supervision, Risk Management Principles for Electronic Banking (2001). Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management related to the quality of the products or services, they can negatively impact market and customer brand acceptance. (iii) Governance and Control Risk
11.8 These risks arise from losses as a result of inadequate or failed internal processes, staff
and systems. These may also include losses caused by a regulated institution’s failure to adhere to applicable laws, regulations, industry standards or practices, which negatively impact on the market and customer’s perception of the integrity of a regulated institution. (b) Measurement of Reputational Risk
11.9 In order to capture reputational risk, the board should adopt a risk template specifically
developed to identify the structure of the control environment, as well as the specific type of risk controls and metrics, which will be put in place across the regulated institution. The reputational-risk template should conform directly to the risk definition and should include risk-tolerance levels, with special emphasis on potentially high-risk areas. Controls and metrics should address the categories of reputational risk from a qualitative perspective.
11.10 Further to the risk templates, both subjective and objective risk standards should be
incorporated in the template. Particular attention should be given to risks whose consequences are capable of causing adverse events in other divisions of a regulated institution (domino risks). A regulated institution should also note that some risks interact with and affect one another (collide), hence actions taken or not taken in one area will have material consequences on the whole institution. (c) Monitoring, Control and Mitigation of Reputational Risk
11.11 Risk monitoring/control should at the least encompass the following:
(i) establishment of strong enterprise risk-management policies and procedures throughout the organisation, including an effective anti-fraud programme; (ii) reinforcement of a risk-management culture by creating awareness at all staff levels; (iii) instilling ethics throughout the organisation by enforcing a code of conduct for the board, management and staff; (iv) development of a comprehensive system of internal controls and practices, including those related to computer systems and transactional websites; (v) compliance with current laws and regulations and enforcing existing policies and procedures; Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
(vi) implementation of independent testing and transactional testing on a regular basis; (vii) responding promptly and accurately to regulators, oversight professionals (such as internal and external auditors), and law enforcement officers, media; and (viii) establishment of a crisis-management team in the event there is a significant action that may trigger a negative impact on the organisation.
11.12 Reputational-risk management should be an ongoing activity. A regulated institution
should develop a reputational-risk database and identify key controls and tracking reports. As part of an ongoing management of the risk, the board should require staffawareness training at all levels of the regulated institution, with special training regarding potential high-risk areas. Finally, all aspects of reputational-risk management should be subject to an internal audit review. (d) Reporting of Reputational Risk
11.13 Preserving a strong reputation revolves around effectively communicating and building
solid relationships. Communication between a regulated institution and its stakeholders can be a foundation for a high reputation. Timely and accurate financial reports, informative newsletters and excellent customer service are important tools for reinforcing a regulated institution's credibility and entrenching the trust of its stakeholders.
11.14 Reputational risk is managed through strong corporate governance, the tone of which
should be set from the top; a regulated institution's board of directors and senior management should actively support reputational-risk awareness by demanding accurate and timely management information.
11.15 A regulated institution should consider the following key elements for managing
reputational risk:
(i) maintaining timely and efficient communications among shareholders, customers, the board of directors and employees; (ii) positive information about a regulated institution should also be communicated appropriately to the market place; and (iii) management should be fully aware of an event that has the potential to impact a regulated institution’s reputation. All material events should immediately be escalated to the compliance or risk manager, managing director or public relations office. A regulated institution should also ensure that there is no general release of information to the public or press without approval from senior management. Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Guidelines on Risk Management
11.16 Reputational-risk reports should be timely and accurate. Communication related to
reputational risk, both in-house and with external parties, should be managed by a regulated institution’s public relations/communications office. Issued this …………………………………....… day of 2026 _____________________________ DIRECTOR PRUDENTIAL AUTHORITY AND PAYMENTS OVERSIGHT DEPARTMENT Docusign Envelope ID: 46E92347-058A-8E48-82A4-2710A156E6BB 13 August 2026 Docusign Envelope ID: 902D232E-2977-8444-8201-D244834F0185
Note from RegAlert. AI assistants can read this document in full, and search 70,000+ more, through the RegAlert MCP connector (https://mcp.regalert.today/mcp). Free with an account. How to connect ChatGPT, Claude or Cursor.
Read the rest free
Source: Bank of Botswana — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BOB
We email you every new BOB publication the day it's published.