2019-12-19 | 39/POJK.03/2019Added
Commercial banks are required to develop and implement an effective anti-fraud strategy comprising prevention, detection, investigation, reporting, sanctions, monitoring, evaluation, and follow-up pillars. Banks must establish a dedicated unit or function to manage this strategy, report their strategy and periodic application reports to the Financial Services Authority (OJK) via specified offline and online systems, and submit reports on significant fraud incidents within strict deadlines. Failure to comply with these obligations subjects banks to administrative sanctions, including written reprimands, fines ranging from IDR 1,000,000 to IDR 30,000,000 per working day, downgrades in health status, and restrictions on business activities.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
COPY
REPUBLIC OF INDONESIA
NUMBER 39 /POJK.03/2019
CONCERNING
THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS BY THE GRACE OF THE ALMIGHTY GOD, THE BOARD OF COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY, Considering:
a. that banking business activities may be exposed to operational risks, one of which stems from fraud; b. that to minimize the occurrence of fraud, it is necessary to strengthen the internal control system through the implementation of an anti-fraud strategy by banks;
c. that based on the considerations referred to in letters a and b, it is necessary to establish a Financial Services Authority Regulation concerning the Implementation of Anti-Fraud Strategy for Commercial Banks;
Recalling:
CHAPTER I
GENERAL PROVISIONS
Article 1
In this Financial Services Authority Regulation:
Article 2
(1) Types of acts classified as Fraud consist of:
a. cheating; b. deception;
c. asset embezzlement;
d. information leakage; e. banking criminal offenses; and f. other acts.
(2) Other acts as referred to in paragraph (1) letter f are other acts that can be equated with Fraud in accordance with the provisions of legislation.
CHAPTER II
IMPLEMENTATION OF ANTI-FRAUD STRATEGY
Article 3
(1) Banks are required to formulate and implement an effective anti-Fraud strategy.
(2) The formulation and implementation of an effective anti-Fraud strategy as referred to in paragraph (1) must at least meet the guidelines for the implementation of anti-Fraud strategy contained in Appendix I, which is an integral part of this Financial Services Authority Regulation. (3) In formulating and implementing an effective anti-Fraud strategy, Banks are required to consider at least:
a. internal and external environmental conditions; b. the complexity of business activities;
c. the type, potential, and risk of Fraud; and
d. the adequacy of required resources.
Article 4
(1) The formulation and implementation of anti-Fraud strategy as referred to in Article 3 paragraph (1) must contain at least 4 (four) pillars.
(2) The 4 (four) pillars as referred to in paragraph (1) consist of:
a. prevention; b. detection;
c. investigation, reporting, and sanctions; and
d. monitoring, evaluation, and follow-up.
Article 5
(1) To control the risk of Fraud occurrence, Banks are required to implement risk management in accordance with the provisions of Financial Services Authority Regulations concerning the implementation of risk management for commercial banks and Financial Services Authority Regulations concerning the implementation of risk management for Sharia commercial banks and Sharia business units. (2) The implementation of risk management as referred to in paragraph (1) must at least contain strengthening of aspects:
a. active supervision by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. organizational structure and accountability; and
d. control and monitoring, as contained in Appendix I, which is an integral part of this Financial Services Authority Regulation.
Article 6
The Board of Directors and Board of Commissioners of Banks are required to implement anti-Fraud strategy in Banks.
Article 7
(1) Banks are required to form a work unit or function tasked with handling the implementation of anti-Fraud strategy within the Bank's organization.
(2) The work unit or function tasked with handling the implementation of anti-Fraud strategy within the Bank's organization as referred to in paragraph (1):
a. is responsible to the President Director; and b. has direct communication and reporting relationships to the Board of Commissioners.
(3) The head of the work unit or official in charge of the function tasked with handling the implementation of anti-Fraud strategy as referred to in paragraph (1) must possess:
a. expertise certificates in the field of anti-Fraud; and/or b. adequate experience in the field of banking or Sharia banking.
Article 8
(1) Banks, the Board of Directors, and/or members of the Board of Commissioners who do not meet the provisions as referred to in Article 3 paragraph (1), Article 3 paragraph (3), Article 6, and/or Article 7 paragraph (1) are subject to administrative sanctions in the form of written reprimands. (2) In the event that Banks, the Board of Directors, and/or members of the Board of Commissioners do not meet the provisions and have been subject to administrative sanctions as referred to in paragraph (1), Banks may be subject to administrative sanctions in the form of:
a. downgrade of the Bank's health status; b. prohibition to issue products or conduct new activities;
c. suspension of certain business activities; and/or
d. prohibition as a main party of a financial services institution, implemented in accordance with the provisions of Financial Services Authority Regulations concerning the re-evaluation of main parties of financial services institutions. (3) Banks that do not meet the provisions as referred to in Article 5 paragraph (1) are subject to administrative sanctions in accordance with the provisions of Financial Services Authority Regulations concerning the implementation of risk management for commercial banks and Financial Services Authority Regulations concerning the implementation of risk management for Sharia commercial banks and Sharia business units.
CHAPTER III
REPORTING
Article 9
(1) For monitoring the implementation of anti-Fraud strategy, Banks are required to submit to the Financial Services Authority:
a. anti-Fraud strategy as referred to in Article 3; and b. reports and/or corrections of reports on the implementation of anti-Fraud strategy.
(2) In the event of significant impact Fraud incidents, Banks are required to submit reports and/or corrections of reports on significant impact Fraud.
(3) Reports and/or corrections of reports on the implementation of anti-Fraud strategy as referred to in paragraph (1) letter b are formulated in the format contained in Appendix II, which is an integral part of this Financial Services Authority Regulation. (4) Reports and/or corrections of reports on significant impact Fraud as referred to in paragraph (2) are formulated in the format contained in Appendix III, which is an integral part of this Financial Services Authority Regulation.
Article 10
(1) Banks are required to adjust their existing anti-Fraud strategy with the guidelines for the implementation of anti-Fraud strategy as contained in Appendix I, which is an integral part of this Financial Services Authority Regulation. (2) Banks are required to submit the adjusted anti-Fraud strategy as referred to in paragraph (1) to the Financial Services Authority at the latest 3 (three) months after the entry into force of this Financial Services Authority Regulation.
Article 11
In the event of changes to the anti-Fraud strategy previously submitted to the Financial Services Authority as referred to in Article 9 paragraph (1) letter a, Banks are required to submit changes to the anti-Fraud strategy at the latest 7 (seven) working days after the changes are made.
Article 12
Banks are required to submit:
a. reports on the implementation of anti-Fraud strategy as referred to in Article 9 paragraph (1) letter b every semester for the end of June and end of December positions, at the latest on the 15th of the following month after the end of the reporting month; and b. reports on significant impact Fraud as referred to in Article 9 paragraph (2) at the latest 3 (three) working days after the Bank becomes aware of the occurrence of significant impact Fraud.
Article 13
(1) Banks are required to correct errors in data and/or information in reports on the implementation of anti-Fraud strategy and reports on significant impact Fraud previously submitted to the Financial Services Authority. (2) Corrections of errors in data and/or information as referred to in paragraph (1) are conducted based on findings by the Bank and/or findings by the Financial Services Authority.
Article 14
Banks are required to submit anti-Fraud strategy as referred to in Article 10 paragraph (2) and Article 11 offline to the Financial Services Authority through:
a. the Relevant Bank Supervision Department or Regional Office of the Financial Services Authority in Jakarta, for Banks with headquarters or branch offices of banks located abroad within the Special Capital Region of Jakarta Province and Banten Province; or b. Regional Office of the Financial Services Authority or Local Office of the Financial Services Authority according to the area where the Bank's headquarters is located, for Banks with headquarters outside the Special Capital Region of Jakarta Province and Banten Province.
Article 15
(1) Banks are required to submit reports and/or corrections of reports on the implementation of anti-Fraud strategy as well as reports and/or corrections of reports on significant impact Fraud as referred to in Article 12 and Article 13 online through the Financial Services Authority's reporting system. (2) In the event that the submission of reports and/or corrections of reports online through the Financial Services Authority's reporting system as referred to in paragraph (1) cannot yet be performed, Banks are required to submit reports and/or corrections of reports offline. (3) Banks are required to submit reports and/or corrections of reports offline as referred to in paragraph (2) to the Financial Services Authority through:
a. the Relevant Bank Supervision Department or Regional Office of the Financial Services Authority in Jakarta, for Banks with headquarters or branch offices of banks located abroad within the Special Capital Region of Jakarta Province and Banten Province; or b. Regional Office of the Financial Services Authority or Local Office of the Financial Services Authority according to the area where the Bank's headquarters is located, for Banks with headquarters outside the Special Capital Region of Jakarta Province and Banten Province.
Article 16
If the deadline for submitting anti-Fraud strategy as referred to in Article 10 paragraph (2) and the deadline for submitting reports on the implementation of anti-Fraud strategy as referred to in Article 12 letter a falls on a Saturday, Sunday, and/or other holidays, the anti-Fraud strategy and/or reports on the implementation of anti-Fraud strategy are submitted on the next working day.
Article 17
In the event that Banks experience force majeure so that they cannot submit:
a. anti-Fraud strategy as referred to in Article 10 paragraph (2); b. changes to the anti-Fraud strategy as referred to in Article 11; and/or
c. reports on the implementation of anti-Fraud strategy and reports on significant impact Fraud as referred to in Article 12,
until the deadline for submitting documents and/or reports, Banks are required to immediately notify the Financial Services Authority in writing to obtain an extension of the submission deadline.
Article 18
(1) Banks that do not meet the provisions as referred to in Article 9 paragraph (1), Article 9 paragraph (2), Article 10 paragraph (1), Article 13 paragraph (1), Article 14, and/or Article 15 are subject to administrative sanctions in the form of written reprimands. (2) Banks that do not submit anti-Fraud strategy as referred to in Article 10 paragraph (2), changes to the anti-Fraud strategy as referred to in Article 11, and/or reports on the implementation of anti-Fraud strategy and reports on significant impact Fraud as referred to in Article 12 are subject to administrative sanctions in the form of written reprimands and fines of IDR 1,000,000.00 (one million rupiah) per working day and at most IDR 30,000,000.00 (thirty million rupiah) per type of document or report. (3) Banks that do not submit anti-Fraud strategy and reports up to 30 (thirty) working days after the final deadline for submitting anti-Fraud strategy as referred to in Article 10 paragraph (2), changes to the anti-Fraud strategy as referred to in Article 11, and/or reports on the implementation of anti-Fraud strategy and reports on significant impact Fraud as referred to in Article 12 and have been subject to administrative sanctions in the form of fines of IDR 30,000,000.00 (thirty million rupiah) as referred to in paragraph (2), remain required to submit anti-Fraud strategy, changes to the anti-Fraud strategy, reports on the implementation of anti-Fraud strategy, and/or reports on significant impact Fraud. (4) In the event that Banks do not meet the provisions and have been subject to administrative sanctions as referred to in paragraph (1), paragraph (2), and/or paragraph (3), Banks may be subject to administrative sanctions in the form of:
a. downgrade of the Bank's health status; b. prohibition to issue products or conduct new activities;
c. suspension of certain business activities; and/or
d. prohibition as a main party of a financial services institution, implemented in accordance with the provisions of Financial Services Authority Regulations concerning the re-evaluation of main parties of financial services institutions.
Article 19
(1) Errors in data and/or information submitted in reports on the implementation of anti-Fraud strategy and reports on significant impact Fraud as referred to in Article 13 paragraph (1) are subject to administrative sanctions in the form of written reprimands and fines of IDR 100,000.00 (one hundred thousand rupiah) per incorrect entry and at most IDR 10,000,000.00 (ten million rupiah) per report. (2) Administrative sanctions in the form of written reprimands and fines as referred to in paragraph (1) are excluded for:
a. corrections that are updates of data and/or information submitted in previous reports; and/or b. corrections of the same reports and/or other reports resulting from corrections of errors in data and/or information in previous reports that have been subject to administrative sanctions.
CHAPTER IV
OTHER PROVISIONS
Article 20
The Bank's responsibility for losses suffered by customers or other parties arising from errors and/or negligence of the Board of Directors, Board of Commissioners, employees, and/or third parties working for the interests of the Bank is implemented in accordance with the provisions of legislation.
CHAPTER V
CLOSING PROVISIONS
Article 21
Upon the entry into force of this Financial Services Authority Regulation, Bank Indonesia Circular Letter Number 13/28/DPNP dated December 9, 2011 concerning the Implementation of Anti-Fraud Strategy for Commercial Banks is revoked and declared invalid.
Article 22
This Financial Services Authority Regulation enters into force on January 1, 2020.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
To ensure that everyone knows it, ordering the enactment of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia. Established in Jakarta on December 19, 2019
CHAIRMAN OF THE BOARD OF COMMISSIONERS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
Enacted in Jakarta on December 19, 2019
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2019 NUMBER 246
EXPLANATION
OF
REPUBLIC OF INDONESIA
NUMBER 39 /POJK.03/2019
CONCERNING
THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS
I. GENERAL
The increasingly complex banking business activities along with the very rapid development of the banking industry result in increased risk exposure for Banks. Banking business activities may be exposed to operational risks, one of which stems from Fraud. Considering the disclosure of several Fraud cases in the banking sector that harmed Banks and/or customers, adequate support is needed to uncover Fraud incidents and actions taken to handle Fraud must be able to provide a deterrent effect on perpetrators. To minimize the occurrence of Fraud, various strengthening of the Bank's internal control system is required, which simultaneously serves as support for the implementation of risk management in Banks. Furthermore, considering that Fraud incidents have the potential to cause losses to Banks but the level of loss recovery is still low, continuous prevention and improvement actions in the internal control system through the implementation of anti-Fraud strategy by Banks are very necessary.
In addition, to improve data accuracy and accelerate the submission of reports regarding the implementation of anti-Fraud strategy in Banks, it is deemed necessary to refine the format and procedures for Banks to submit reports to the Financial Services Authority, including the format of reports on the implementation of anti-Fraud strategy, so that it can provide added value, including better knowledge regarding the development of Fraud occurring in the banking industry, the banking industry's readiness to handle internal and external Fraud, and the assessment of the effectiveness of anti-Fraud strategies implemented by the banking industry.
Therefore, provisions concerning the implementation of anti-Fraud strategy need to be refined in a Financial Services Authority Regulation concerning the Implementation of Anti-Fraud Strategy for Commercial Banks.
II. ARTICLE BY ARTICLE
Article 1
Sufficiently clear.
Article 2
Paragraph (1)
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
The term banking criminal offenses refers to provisions contained in legislation concerning banking and Sharia banking.
Letter f
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Article 3
Paragraph (1)
Anti-Fraud strategy is part of the Bank's strategic policy, whose implementation is realized in the Fraud control system.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Article 4
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Letter a
The prevention pillar contains steps to reduce the potential risk of Fraud occurrence, including anti-Fraud awareness, vulnerability identification, and employee-related policies, as well as other steps necessary for Fraud prevention. Letter b The detection pillar contains steps to identify and discover Fraud in the Bank's business activities, including whistleblowing policies and mechanisms, surprise examinations, and supervision systems, as well as other steps necessary for Fraud detection. Letter c The investigation, reporting, and sanctions pillar contains steps for investigation or inquiry, reporting systems, and the imposition of sanctions on Fraud incidents in the Bank's business activities, as well as other steps necessary for investigation, reporting, and sanction imposition. Letter d The monitoring, evaluation, and follow-up pillar contains steps to monitor, evaluate, and follow up on Fraud, as well as other steps necessary for monitoring, evaluation, and follow-up.
Article 5
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Letter a
Sufficiently clear.
Letter b
The implementation of risk management in the form of Fraud control policies and procedures formulated by Banks needs to consider the size and complexity of the Bank's business activities. Letter c Sufficiently clear. Letter d Fraud control and monitoring is one of the important aspects of the Bank's internal control system in supporting the effectiveness of anti-Fraud strategy implementation. Fraud monitoring needs to be supplemented with adequate information systems in accordance with the complexity of business activities and the level of Fraud risk in Banks.
Article 6
The implementation of anti-Fraud strategy is carried out, among others, by fostering awareness of risks and anti-Fraud concern and culture throughout the Bank's organizational hierarchy and signing integrity pacts.
Article 7
Paragraph (1)
The formation of a work unit or function tasked with handling the implementation of anti-Fraud strategy within the Bank's organization is adjusted to the size and complexity of the Bank's business activities and must be accompanied by clear authority and responsibility. The work unit or function handling the implementation of anti-Fraud strategy can be held concurrently by other work units or functions that do not handle operations, finance, and accounting, so Banks do not need to form new work units or functions. Paragraph (2) Sufficiently clear. Paragraph (3) Letter a Sufficiently clear. Letter b Adequate experience in the field of banking or Sharia banking, among others, relates to operations, risk management, compliance, and/or Bank audits.
Article 8
Sufficiently clear.
Article 9
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Significant impact Fraud reports contain Fraud incidents estimated to have a significant negative impact on Banks and/or customers, including those that have the potential to become public attention, such as accumulations of several related Fraud incidents that may have the same modus operandi, perpetrator, and time of occurrence with different Fraud locations. Paragraph (3) Sufficiently clear. Paragraph (4) Sufficiently clear.
Article 10
Sufficiently clear.
Article 11
Sufficiently clear.
Article 12
Letter a
Example:
Reports on the implementation of anti-Fraud strategy for the end of June 2020 position are submitted at the latest on July 15, 2020.
Letter b
Banks become aware of Fraud after there is initial evidence believed to be a Fraud incident and known by the President Director.
Example:
Significant impact Fraud occurs on August 3, 2020, but is known by the Bank on Wednesday, August 5, 2020, so the Bank submits the significant impact Fraud report at the latest on Monday, August 10, 2020.
Article 13
Sufficiently clear.
Article 14
Sufficiently clear.
Article 15
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Submission of reports and/or corrections of reports offline is the submission of reports and/or corrections of reports by submitting data recordings of reports to the Financial Services Authority, among others, in the form of compact discs or flash drives. Paragraph (3) Sufficiently clear.
Article 16
Sufficiently clear.
Article 17
Force majeure includes, among others, fires, mass riots, war, armed conflict, sabotage, floods, and earthquakes that disrupt the Bank's operational activities, as declared or explained by competent officials or agencies. The Bank's obligation to immediately notify the Financial Services Authority in writing is intended so that the Bank notifies at the first opportunity when the situation and conditions permit.
Article 18
Clearly stated.
Article 19
Paragraph (1)
Clearly stated.
Paragraph (2)
Letter a
Corrections that constitute updates are corrections to fraud incidents that have been reported in previous reports.
Example:
Bank "X" submitted a report on the implementation of the anti-Fraud strategy as of the end of June 2020 on July 5, 2020, which contained fraud incidents involving external perpetrators, but did not fill in the "Identity Type", "Identity Number", and "Loss Amount (Recovery)" fields. On July 20, 2020, Bank "X" submitted a correction to the aforementioned report, which was completed with data and information on "Identity Type", "Identity Number", and "Loss Amount (Recovery)". Regarding this correction, although it was submitted after the reporting deadline of July 15, 2020, Bank "X" is not subject to administrative sanctions in the form of a written reprimand and fine because the fraud incident was reported on July 5, 2020, so the correction is categorized as an update.
Letter b
Example:
Bank "X" reported a fraud incident that occurred at the head office and was only discovered by the Bank on June 22, 2020, in a fraud report with significant impact on June 25, 2020. This significant impact fraud incident was also submitted in the report on the implementation of the anti-Fraud strategy as of the end of June 2020. Based on the findings of the Bank Supervisor on July 20, 2020, it was known that the significant impact fraud incident, in addition to occurring at the head office, also occurred at branch offices and was known by Bank "X" on June 22, 2020. In relation to this matter, the Financial Services Authority orders Bank "X" to correct the significant impact fraud report and the Bank is subject to administrative sanctions in the form of a written reprimand and fine. In addition to submitting the correction of the significant impact fraud report, the Bank also submits a correction to the report on the implementation of the anti-Fraud strategy as of the end of June 2020. Regarding the correction to the report on the implementation of the anti-Fraud strategy as of the end of June 2020, Bank "X" is exempted from administrative sanctions in the form of a written reprimand and fine because the Bank has been subject to administrative sanctions in the form of a written reprimand and fine for the correction of the significant impact fraud report.
Article 20
Legislation includes, among others, provisions of Financial Services Authority Regulations regarding consumer protection in the financial services sector.
The Bank's accountability does not eliminate the Bank's right to demand accountability from fraud perpetrators.
Article 21
Clearly stated.
Article 22
Clearly stated.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 6439
APPENDIX I
NUMBER 39 /POJK.03/2019
CONCERNING THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS GUIDELINES FOR THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR BANKS
I. BACKGROUND
To prevent operational deviation cases in banking and violations of legislation, particularly Fraud, which can cause losses, both directly and indirectly, to Banks, customers, and/or other parties, it is necessary to increase the effectiveness of internal controls, as an effort to minimize Fraud risk by implementing an anti-Fraud strategy.
In Law Number 7 of 1992 concerning Banking as amended by Law Number 10 of 1998 concerning Amendments to Law Number 7 of 1992 concerning Banking, among others, it is regulated that Directors, the Board of Commissioners, or Bank employees who intentionally request or receive, permit or approve to receive a remuneration, commission, additional money, service, money or valuable goods, for their own benefit or for the benefit of their family, to obtain or attempt to obtain for others in obtaining a down payment, bank guarantee, or credit facilities from the Bank, or for the purchase or discounting by the Bank of bills of exchange, promissory notes, checks, and commercial papers or other evidence of obligations, or to grant approval for others to carry out withdrawals of funds exceeding the credit limit at the Bank are threatened with criminal penalties. In this case, this also includes other actions such as giving or receiving bribes, which are types of acts classified as Fraud.
So far, both directly and indirectly, Fraud prevention has been implemented by Banks, among others, through the application of risk management, particularly internal control systems, and the implementation of good corporate governance. However, for the implementation of the anti-Fraud strategy to be more effective, efforts are still needed to increase a risk-aware culture so that Fraud prevention becomes the focus of attention and concern for all levels of the Bank's organization, both by the Directors, the Board of Commissioners, and Bank employees, which among others is manifested by the willingness to sign integrity pacts by the Directors, the Board of Commissioners, and Bank employees.
The effectiveness of Fraud control in business processes is the responsibility of the Directors and the Board of Commissioners, so a correct and comprehensive understanding of Fraud is needed by the Directors and the Board of Commissioners so that they can provide direction and foster awareness for Fraud risk control at the Bank.
The anti-Fraud strategy is a manifestation of the commitment of the Bank's Directors and Board of Commissioners in controlling Fraud, which is applied in the form of a Fraud control system. This strategy requires the Directors and the Board of Commissioners to optimize existing resources so that the Fraud control system can be implemented effectively and continuously.
The guidelines for the implementation of the anti-Fraud strategy in these regulations direct Banks in conducting Fraud control through efforts that are not only aimed at prevention but also at detection and conducting investigations and improving the system as part of an integral strategy in controlling Fraud.
II. GENERAL GUIDELINES FOR THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY
In these guidelines, Fraud is defined as an act of deviation or tolerance that is intentionally carried out to deceive, cheat, or manipulate the Bank, customers, or other parties, which occurs in the Bank's environment and/or uses Bank facilities, thereby causing the Bank, customers, or other parties to suffer losses and/or the Fraud perpetrator to obtain financial benefits, both directly and indirectly. Types of acts classified as Fraud are fraud, deception, asset embezzlement, information leakage, banking criminal acts, and other acts that can be equated with Fraud.
Based on the approach to the Bank's business activities, the grouping of Fraud occurrence activities is distinguished as follows: funding, lending or financing, use of identity and data of other parties/customers, asset management, cyber usage, financial reporting, and other activities. The so-called other activities are Bank business activities outside of funding, lending or financing, use of identity and data of other parties/customers, asset management, cyber usage, and financial reporting.
The anti-Fraud strategy is the Bank's strategy in controlling Fraud, designed to develop, apply, and improve the anti-Fraud compliance program at the Bank, with reference to the process of Fraud occurrence and considering the characteristics and scope of the potential occurrence of Fraud, which is compiled comprehensively and integrally and implemented in the form of a Fraud control system. The implementation of the anti-Fraud strategy is part of the implementation of risk management, particularly those related to the internal control system aspect.
The success of the anti-Fraud strategy is influenced by internal and external environments that support the creation of conducive conditions so that all related parties can play an optimal role in implementing the Fraud control system at the Bank.
The structure of the anti-Fraud strategy as a whole combines the basic principles of risk management, particularly the internal control system and good corporate governance. The implementation of the anti-Fraud strategy in the form of a Fraud control system is elaborated through 4 (four) pillars of Fraud control strategy that are interrelated, namely: (i) prevention; (ii) detection; (iii) investigation, reporting, and sanctions; and (iv) monitoring, evaluation, and follow-up.
III. RISK MANAGEMENT IMPLEMENTATION
The implementation of the anti-Fraud strategy as part of the implementation of risk management cannot be separated from the scope of general risk management implementation. Therefore, the effectiveness of implementing the anti-Fraud strategy needs to be supported at least by strengthening the risk management aspect focused on Fraud control. These aspects include at least active supervision by the Directors and Board of Commissioners, policies and procedures, organizational structure and accountability, and control and monitoring. The minimum scope for each of these supporting aspects is as follows:
d. drafting and supervising the implementation of the anti-Fraud strategy comprehensively; e. developing human resource (HR) quality, particularly related to increasing awareness and Fraud control; f. monitoring and evaluating Fraud incidents and determining follow-up actions; and g. developing effective communication channels internally and for external parties to the Bank so that all officials and Bank employees understand and comply with applicable policies and procedures, including policies and procedures for Fraud control.
2. Policies and Procedures
Policies and procedures drafted by the Bank for the implementation of Fraud control need to consider the size of the Bank and the complexity of its business activities. For the implementation of policies and procedures to run effectively, these policies and procedures need to be communicated well to all levels of the Bank's organization and various parties related to the Bank. The aforementioned policies and procedures must be designed to reduce identified risks and can prevent behavior leading to Fraud actions. Matters to be noted in the drafting and implementation of Fraud prevention policies and procedures include at least:
a. commitment of the Directors and Board of Commissioners; b. establishment of a comprehensive internal control system and risk assessment procedures;
c. due diligence on third parties related to the Bank;
d. determination of remuneration according to duties and responsibilities; e. implementation of good corporate governance in Bank business activities; f. financial control and implementation of accounting in accordance with applicable financial accounting standards; g. avoidance of conflicts of interest in decision-making, delegation of authority, and separation of functions; h. Fraud reporting mechanisms, including whistleblowing system procedures;
i. enforcement of discipline and sanctions for violations of anti-Fraud rules;
j. communication and training on Fraud prevention policies and procedures; k. periodic monitoring and evaluation of Fraud prevention policies and procedures; and
l. other matters deemed necessary.
3. Organizational Structure and Accountability
To support the effectiveness of implementing the anti-Fraud strategy, the Bank has a work unit or function tasked with handling the implementation of the anti-Fraud strategy. Matters to be noted in the formation of such work units or functions include at least the following:
a. formation of work units or functions in the organizational structure is adjusted to the size and complexity of the Bank's business activities; b. determination of clear job descriptions and responsibilities;
c. accountability of the work unit or function to the President Director;
d. ensuring that communication and reporting relationships are directly to the Board of Commissioners; and e. tasks in the work unit or function must be carried out by HR with competence, integrity, and independence, and supported by clear accountability.
4. Control and Monitoring
In carrying out control and monitoring, the Bank takes steps to increase the effectiveness of implementing the anti-Fraud strategy at least as follows:
a. control through review by the Directors and Board of Commissioners as well as operational review by the internal audit work unit on the implementation of the anti-Fraud strategy; b. HR control aimed at increasing the effectiveness of task execution and Fraud control, for example, rotation policies, mutation policies, mandatory leave, and social or togetherness activities;
c. determination of separation of functions in the implementation of Bank activities across all levels of the organization, for example, the application of the four eyes principle in lending or financing activities with the aim that every party involved in such activities does not have the opportunity to commit and hide Fraud in the execution of their duties;
d. information system control supporting electronic processing, storage, and data security to prevent the potential for Fraud. The Bank has adequate contingency programs, including for data security. This information system control needs to be accompanied by the availability of an accounting system to guarantee the use of accurate and consistent data in recording and reporting the Bank's finances, among others through reconciliation or data verification periodically; and e. other controls and monitoring to increase the effectiveness of implementing the anti-Fraud strategy such as control, monitoring, and documentation of physical assets.
IV. ANTI-FRAUD STRATEGY
The anti-Fraud strategy, compiled comprehensively and integrally and implemented in the form of a Fraud control system, is applied using devices that are an elaboration of 4 (four) interrelated pillars as follows:
b. Vulnerability Identification
Vulnerability identification is a process to identify, analyze, and assess the potential risk of Fraud occurrence, which can be carried out periodically or in case of indications of Fraud. Generally, vulnerability identification is aimed at identifying the risk of Fraud occurrence inherent in every activity that has the potential to harm the Bank. The Bank conducts vulnerability identification in every activity, both sourced from internal and external information of the Bank. The results of identification, in addition to being documented and informed to all interested parties, are also updated periodically, especially in case of activities assessed as high risk for Fraud occurrence. Some internal Bank factors that can increase the likelihood of Fraud occurrence include, among others:
These policies are communicated transparently to all levels of the organization and applied consistently so as to generate trust in all Bank employees regarding the reliability and confidentiality of the complaint handling mechanism. b. Surprise Audit Surprise audit policies and mechanisms need to be carried out especially in business units and activities that are high risk or vulnerable to Fraud occurrence. The implementation of surprise audits can increase employee vigilance in carrying out duties.
c. Supervision System
The Supervision System is a testing or examination action carried out secretly without the knowledge or awareness of the party being tested or examined to monitor and test the effectiveness of anti-Fraud policies. The Supervision System can be carried out by independent parties and/or internal Bank parties periodically or whenever necessary.
3. Investigation, Reporting, and Sanctions
The investigation, reporting, and sanctions pillar contains steps for investigation or inquiry, reporting systems, and the imposition of sanctions on Fraud incidents, which includes at least:
a. Investigation
Investigation is carried out to collect evidence related to incidents that are suspected to be Fraud actions. Investigation is an important part of the Fraud control system that sends a message to every related party that every indication of Fraud detected is always processed according to investigation standards and perpetrators are processed according to regulations. Investigation standards owned by the Bank include at least:
Comprehensive approach to financial issues investigated using standards and regulations. c) Forensic Computing; Forensic computing is a technique for conducting investigations and analysis through the collection and presentation of data evidence available in computers. d) Fieldwork and Interviews. Fieldwork is the investigation process to obtain assurance systematically through the objective collection of evidence.
2) The mechanism for implementing investigations to follow up on detection results while maintaining the confidentiality of obtained information.
b. Reporting
Banks establish effective reporting mechanisms regarding the implementation of investigations into discovered Fraud incidents. The reporting mechanism includes internal Bank reporting as well as reporting to the Financial Services Authority.
c. Imposition of Sanctions
Banks establish effective internal sanction policies to follow up on investigation results to create a deterrent effect for Fraud perpetrators. This policy must contain at least:
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana b. Evaluation
To support the implementation of evaluation, Banks need to maintain Fraud incident data. Incident data can be used as an evaluation aid. Fraud incident data must contain at least the data and information as stated in the report on the implementation of the Anti-Fraud Strategy (Appendix II of this Financial Services Authority Regulation) and the report on significant impact Fraud (Appendix III of this Financial Services Authority Regulation). Based on Fraud incident data and the results of the evaluation, weaknesses and causes of Fraud can be identified, and necessary handling and improvement steps can be determined, including strengthening the internal control system. A comprehensive evaluation of the Fraud control system must be conducted periodically.
c. Follow-up
Banks establish follow-up mechanisms based on the results of evaluations of Fraud incidents to improve weaknesses and strengthen the internal control system to prevent the recurrence of Fraud due to similar weaknesses. Determined in Jakarta on December 19, 2019
CHAIRMAN OF THE COMMISSIONERS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
APPENDIX II
NUMBER 39 /POJK.03/2019
REGARDING THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS
REPORT ON THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY
PT BANK .....
REPORT ON THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY SEMESTER ... YEAR ...
I. Development of Anti-Fraud Strategy Implementation
(Filled with a brief explanation regarding the results of evaluation and follow-up of the implementation of the Anti-Fraud Strategy in the reporting period)
II. Report on the Implementation of Anti-Fraud Strategy
A. Fraud Incident Table
B. Fraud Perpetrator Table
GUIDELINES FOR FILLING OUT THE REPORT ON THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY A. Fraud Incident Table
I. Fraud Incidents by Perpetrator (Must be Filled)
Filled with 1 (one) character in uppercase letters according to the code as follows:
Fraud Incidents by Perpetrator Code
Fraud Incidents with internal perpetrators A
Fraud Incidents with external perpetrators B
Fraud Incidents with internal and external perpetrators C
II. Fraud Incident ID (Must be Filled)
Filled with 6 (six) characters according to the sequence of Fraud incidents, with the first digit starting with the Fraud incident code by perpetrator, reflecting that the incident is a Fraud incident involving internal perpetrators, external perpetrators, or both internal and external perpetrators. Subsequently, digits 2 to 6 are filled with numbers according to the sequence of Fraud incidents. Example:
Fraud Incident with internal perpetrator for sequence number 1 is written as A00001.
III. Type of Fraud (Must be Filled)
Filled with 3 (three) characters according to the code as follows:
Type of Fraud Code
Fraud 201
Deception 202
Embezzlement of assets 203
Information leakage 204
Banking criminal acts 205
Other actions 209
Type of Fraud Description:
Must be filled if selecting "Other actions that can be equated with Fraud" in the "Type of Fraud" column (using free format).
IV. Activities Related to Fraud (Must be Filled)
Filled with 3 (three) characters according to the code as follows:
Activities Related to Fraud Code
Funding 301
Credit/Financing 302
Use of identity and data of other persons, parties, or customers 303 Asset management 304 Cyber usage 305 Financial statement presentation 306 Other activities 309 Explanation of activities related to Fraud based on the Bank's business activities is as follows:
Funding
Fraud occurring in the activity of gathering Third-Party Funds (DPK) conducted by the Bank.
Example:
a. Gathering DPK that is not recorded in the Bank's books or reports, nor in documents or business activity reports, transaction reports, or Bank accounts.
Explanation:
Inconsistencies or manipulation of recording incoming funds from customers in the form of savings, checking accounts, time deposits, and other forms of savings equated with savings, checking accounts, and time deposits, conducted by Bank employees or officials, resulting in recording discrepancies in the Bank's books. b. Withdrawal or cashing of DPK conducted not by the owner or their proxy, or by Bank employees, that is not recorded in the books or reports, nor in documents or business activity reports, transaction reports, or Bank accounts. Explanation:
Withdrawal or cashing of customer DPK for the personal interests of the Board of Directors, Board of Commissioners, employees, and/or other parties without the customer's permission and knowledge. Withdrawal or cashing of DPK can use, among others, fake deposit slips, fake checking account slips, and fake powers of attorney.
c. Depositing or transferring savings, checking accounts, or time deposits that are not recorded correctly in the books or reports, nor in documents or business activity reports, transaction reports, or Bank accounts.
d. Depositing or transferring savings, checking accounts, or time deposits that are recorded in the Bank's books without corresponding fund flows. e. Providing services to prime customers outside of procedures or regulations established by the Bank that cause losses to the Bank.
Credit/Financing
Fraud occurring in the activity of granting credit/financing conducted by the Bank, starting from the credit/financing application until the repayment of credit/financing by the debtor. Example:
a. Fictitious debtors
Explanation:
Granting credit/financing to one or more debtors using fake identities or the identities of other parties. b. Straw debtors Explanation:
Granting credit/financing to debtors using the debtor's actual identity but the funds are used by other parties.
c. Manipulation or falsification of credit/financing documents or information
Explanation:
Manipulation of documents or information by debtors and/or Bank parties to meet the requirements and eligibility for granting credit/financing or restructuring credit/financing, including:
g. Avoidance of violations of Maximum Credit Limit (BMPK) or Maximum Fund Disbursement Limit (BMPD) Explanation:
Splitting one credit/financing facility into several credit/financing facilities and granting credit/financing facilities through business groups or other parties to avoid BMPK/BMPD violations. h. Exceeding and/or abuse of authority Explanation:
Exceeding authority involves terminating credit/financing grants in amounts exceeding the authority limits of credit/financing officials/committees. Abuse of authority involves terminating credit grants not based on prudential principles.
i. Gratuities, cash back schemes, or bribery
Explanation:
The Board of Directors, Board of Commissioners, and/or Bank employees receive or request additional facilities from debtors as compensation for the disbursement of credit/financing. j. Granting credit/financing that violates prudential principles Explanation:
Granting of credit/financing by the Bank that violates prudential principles as regulated in applicable laws and regulations or the Bank's Standard Operating Procedures (SOP), including:
k. Repayment of credit/financing from funds resulting from the disbursement of new credit/financing intended to improve or maintain credit/financing collectibility
l. Manipulation of credit/financing collectibility
3. Use of Identity and Data of Other Persons, Parties, or Customers
Fraud occurring by using the identity and data of other persons, parties, or customers to conduct banking transactions without the knowledge and/or consent of the persons, parties, or customers. Example:
a. Misuse of customer Automated Teller Machine (ATM) cards. b. Illegal sale or exchange of customer data between Banks or third parties employed by the Bank.
4. Asset Management
Fraud occurring in the Bank's asset management activities, including cash.
Example:
a. Use of cash in the vault by the Board of Directors, Board of Commissioners, and/or Bank employees for personal interests and not recorded in the Bank's books. b. Cash theft conducted by exploiting weaknesses in software and/or hardware on Bank ATMs and/or ATM cards.
c. Misuse of Bank vehicles for the personal interests of the Board of Directors, Board of Commissioners, and/or Bank employees.
d. Sale of Foreclosed Collateral (AYDA) by Bank employees to debtors at unreasonable prices to obtain personal profit for employees. e. Employees failing to record the purchase or sale of Bank-owned assets. f. Inflating (marking up) office building rental costs for personal profit, the Board of Directors, Board of Commissioners, and/or Bank employees.
g. Manipulation of deposits and withdrawals in placement accounts at other banks by the Bank's Board of Directors. h. Placement, investment, or participation of Bank funds not in accordance with the Bank's SOP conducted by employees colluding with other parties.
i. Withdrawal of cash without underlying transactions and not recorded in the appropriate position.
5. Cyber Usage
Fraud occurring using computers, computer networks, and/or electronic media to deceive the Bank, customers, persons, or other parties to obtain information and customer personal data. Example:
a. Hacking or Cracking
Explanation:
Unauthorized use or search for access to Bank or customer data in the banking system, including through electronic banking. b. Phishing Explanation:
Actions to obtain customer personal information by impersonating authorized parties via email to direct customers to access specific links in the email.
c. Skimming
Explanation:
Use of machines or cameras installed on ATMs with the intent to steal card information and customer Personal Identification Number (PIN) numbers when customers use the ATM. d. Social Engineering Explanation:
Actions to obtain customer information such as PIN, card numbers, and/or other information by contacting customers via telephone, short message service (sms), or other media to inform about prize giveaways and request customers to contact specific phone numbers or open specific websites.
e. Viruses, malware, ransomware
Explanation:
Programs designed with the intent to damage, infiltrate, and/or steal information or confidential data of the Bank and/or customers in the Bank's electronic systems.
6. Financial Statement Presentation
Fraud occurring in the presentation of the Bank's financial statements, including financial statements not presented in accordance with generally accepted accounting principles and/or not in accordance with the actual financial condition, including incorrect recording, such as inflating (marking up) costs and fictitious costs in the books or Bank reports. Example:
Manipulation or manipulation of the Bank's financial statements (window dressing).
Explanation:
Manipulation of financial statements so that the Bank's performance appears better than the actual financial condition or successfully achieves established targets.
7. Other Activities
Fraud occurring in every aspect of Bank activities other than the categories grouped above (numbers 1 to 6).
V. Fraud Description or Modus Operandi (Must be Filled)
Filled with a description of the Fraud that occurred, up to 4000 characters (using free format), accompanied by uploading a PDF file containing the detailed description. In the event that there is no detailed description, a PDF file must still be uploaded.
VI. Fraud Location (Must be Filled)
Payment Point of Islamic Commercial Banks 60
Mobile Cash/Car Cash/Floating Cash of Islamic Commercial Banks 61 Representative Office of Islamic Commercial Banks Abroad 62 ATM/CDM/CRM of Islamic Commercial Banks 63 Islamic Services of Commercial Banks 64 Conventional commercial banks with Islamic business units must fill in the Islamic Business Unit of Commercial Banks (code 04) for Fraud incidents occurring in offices that perform the functions of that Islamic business unit.
2. Fraud Location Description
Filled with 4 (four) characters according to the city/regency code contained in the Financial Information Service System (SLIK) guidelines as referred to in Financial Services Authority regulations regarding reporting and requesting debtor information through SLIK.
VII. Division or Work Unit Where Fraud Occurred (Must be Filled)
Filled with the name of the division or work unit where the Fraud occurred or was directly impacted by the Fraud (using free format).
VIII. Affected Party (Must be Filled)
The affected party is the Bank, customers, and/or other parties. Filled with 3 (three) characters according to the code as follows:
Affected Party Code
Bank 001
Customer 002
Other Parties 003
In the event that more than one party is affected, it is filled in the following row with the same Fraud Incident ID.
IX. Time (Must be Filled)
XII. Actions for Fraud Handling (Must be Filled)
Actions for fraud handling are the Bank's response to Fraud incidents, either in the form of actions against perpetrators, affected parties, or other actions.
Filled with 2 (two) characters according to the code as follows:
Actions for Fraud Handling Code
Issuance of Warning Letters 01
Rotation or Transfer 02
Demotion 03
Resignation 04
Termination of Employment Relationship 05
Blocking of Debit/Credit Cards 06
Blocking of Accounts 07
Replacement of Debit/Credit Cards 08
Police Reporting or Legal Action 09
Compensation 10
Other Actions 19
In the event that there is more than one action for fraud handling, it is filled in the following row with the same Fraud Incident ID.
Description of Actions for Fraud Handling:
Must be filled if selecting "Other Actions" in the "Actions for Fraud Handling" column (using free format).
XIII. Corrective Actions for Fraud Prevention (Must be Filled)
Filled with 3 (three) characters according to the code as follows:
Corrective Actions for Fraud Prevention Code
Human Resources 100
Internal Control System 200
Information Technology 300
Implementation of Anti-Fraud Strategy 400
Other Actions 900
In the event that there is more than one corrective action for fraud prevention, it is filled in the following row with the same Fraud Incident ID.
Description of Corrective Actions for Fraud Prevention
Filled with a description of the corrective actions taken by the Bank to prevent similar Fraud incidents in the future (using free format).
Implementation Time Target
Filled with the implementation time target for the corrective actions taken by the Bank (using free format).
Implementation Realization
Filled with the realization of the implementation time target for the corrective actions taken by the Bank (using free format).
B. Fraud Perpetrator Table
Fraud Perpetrators are parties involved in Fraud incidents.
I. Fraud Incident ID (Must be Filled)
Filled with 6 (six) characters according to the Fraud Incident ID involving the perpetrator. The Fraud Incident ID in the Fraud Perpetrator Table must match the Fraud Incident ID in the Fraud Incident Table. In the event that there is a Fraud incident where the perpetrator is not yet known, the Fraud Incident ID must still be filled in the Fraud Perpetrator Table.
II. Internal/External (Must be Filled)
Filled with 3 (three) characters according to the Fraud perpetrator code.
Fraud Perpetrator Code
Internal 001
External 002
III. Perpetrator Identity
For external Fraud perpetrators, if the Fraud perpetrator is a company, the Gender, Place of Birth, and Date of Birth columns do not need to be filled.
For external Fraud perpetrators, if the perpetrator is unknown, the Gender, Identity Address, Domicile Address, Place of Birth, and Date of Birth columns do not need to be filled.
Name (Must be Filled)
Filled with the name of the Fraud perpetrator without titles, as stated in the identity document.
For external fraud perpetrators, if the perpetrator's name is unknown, that column must still be filled (cannot be left blank) and the Bank must define the name of the unknown perpetrator. Example: unknown client.
2. Identity Type (Must be Filled)
Filled with 3 characters according to the identity type code.
Identity Type Code Description
ID Card (National Identity Number) 001 Indonesian National Fraud Perpetrator Passport (Passport Number) 002 Foreign National Fraud Perpetrator Taxpayer Identification Number (NPWP) 003 Fraud Perpetrator in the name of a company Unknown 009
3. Identity Number (Must be Filled)
Filled with the identity number according to the selected identity type.
Identity numbers for unknown identity types use a unique code created by the Bank.
If the identity number contains characters other than letters and numbers, those characters do not need to be included.
Example:
If the Fraud Perpetrator has an NPWP number 49.810.734.1-035.000, then the Identity Number column is filled with 498107341035000.
4. Gender
Filled with 1 (one) character according to the gender code of the Fraud Perpetrator as follows:
Gender Code
Male L
Female P
If the Fraud Perpetrator is in the name of a company or unknown, the Gender column does not need to be filled.
5. Identity Address
Filled with the identity address as stated in the Fraud Perpetrator's identity document.
b. A person who approves, participates in approving, or signs;
c. A person who performs or participates in performing an act based on orders from other parties, with or without pressure, and who should know or should suspect that the act or order performed is contrary to applicable regulations and does not attempt to refuse to perform the act or order; or
d. A person who performs an act due to a specific promise or reward.
Involved Party 002 The Involved Party is a person who, in carrying out duties, positions, and/or due to orders from other parties, with or without pressure, performs or participates in performing an act, and who should know or should suspect that the act or order performed is contrary to applicable regulations, but who has attempted
to refuse to perform the act or order.
V. Perpetrator Position (Must be Filled if Internal Fraud Perpetrator)
b. Position Description
Filled with the Fraud Perpetrator's position name at the Bank (using free format).
Example: Credit Account Officer (AO), Credit Group Head.
2. At the time the Fraud was discovered
a. Filled with 3 (three) characters according to the position code Position Code Description President Director 001 Director 002 Compliance Director 003 Director who oversees the compliance function. Principal Commissioner 004 Commissioner 005 Sharia Supervisory Board 006 Executive Officer 007 Officers who are directly responsible to members of the Board of Directors or have significant influence on Bank policy and/or operations. Non-Executive Officer 018 All officers other than Executive Officers. Non-Officer Employee 019 All employees other than Executive Officers and Non-Executive Officers. Experts and Consultants 010 No longer working at the Bank:
Career Retirement 041
Early Retirement 042
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Dismissed 043
Resigned 044
Contract/Assignment Ended 045
Deceased 046 b. Position Description
Filled with the Fraud Perpetrator's position name at the Bank (using free format).
Example: Credit AO, Credit Group Head.
VI. Perpetrator Description (Must be Filled if External Fraud Perpetrator is Known)
Filled with 3 (three) characters according to the code as follows:
Position Code
Customer 001
Parties directly related to the Bank (among others vendors, investors, suppliers, state officials, or partners) 002 Parties not directly related to the Bank 003
VII. Imposition of Sanctions (Must be Filled)
Filled according to the actions for handling Fraud in the Fraud Incident Table (using free format) according to the Fraud Incident ID involving that perpetrator. Determined in Jakarta on December 19, 2019
CHAIRMAN OF COMMISSIONERS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
APPENDIX III
NUMBER 39 /POJK.03/2019
REGARDING THE IMPLEMENTATION OF ANTI-FRAUD STRATEGY FOR COMMERCIAL BANKS
SIGNIFICANT IMPACT FRAUD REPORT
Fraud reported through this report is a Fraud incident with significant impact based on the significance criteria in the Bank's anti-fraud strategy implementation guidelines. A. Fraud Incident Table B. Fraud Perpetrator Table
GUIDELINES FOR FILLING OUT THE SIGNIFICANT IMPACT FRAUD REPORT A. Fraud Incident Table
I. Fraud Incident by Perpetrator (Must be Filled)
Filled with 2 (two) characters in capital letters according to the code as follows:
Fraud Incident by Perpetrator Code
Fraud Incident with internal perpetrator AS
Fraud Incident with external perpetrator BS
Fraud Incident with internal and external perpetrators CS
II. Fraud Incident ID (Must be Filled)
Filled with 6 (six) characters according to the sequence of Fraud incidents with the first 2 (two) digits starting with the Fraud incident code according to the perpetrator, reflecting that the incident is a significant impact Fraud incident involving internal perpetrators, external perpetrators, or internal and external perpetrators. Subsequently, digits 3 to 6 are filled with numbers according to the sequence of Fraud incidents. Example:
A significant impact Fraud incident with internal perpetrator for sequence number 1 is written as AS0001.
III. Type of Fraud (Must be Filled)
Filled with 3 (three) characters according to the code as follows:
Type of Fraud Code
Fraud 201
Deception 202
Embezzlement of assets 203
Information leakage 204
Banking criminal acts 205
Other actions 209
Type of Fraud Description:
Must be filled if choosing "Other actions that can be equated with Fraud" in the "Type of Fraud" column (using free format).
IV. Fraud-Related Activities (Must be Filled)
Filled with 3 (three) characters according to the code as follows:
Fraud-Related Activity Code
Funding 301
Lending/Financing 302
Use of identity and data of others, other parties, or customers 303 Asset management 304 Cyber usage 305 Financial statement presentation 306 Other activities 309 Explanation of fraud-related activities based on Bank operational activities is as follows:
Funding
Fraud occurring in the activity of gathering Third Party Funds (DPK) conducted by the Bank.
Example:
a. Gathering DPK not recorded in the Bank's books or reports, nor in documents or business activity reports, transaction reports, or Bank accounts.
Explanation:
Discrepancies or manipulation of recording incoming funds from customers in the form of savings, checking accounts, deposits, and other forms of savings equated with savings, checking accounts, or deposits, conducted by Bank employees or officers, resulting in recording discrepancies in the Bank's books. b. Withdrawal or cashing of DPK not done by the owner or their proxy, or by Bank employees not recorded in the books or reports, nor in documents or business activity reports, transaction reports, or Bank accounts. Explanation:
Withdrawal or cashing of customer DPK for the personal interests of the Board of Directors, Board of Commissioners, employees, and/or other parties without the customer's permission and knowledge. Withdrawal or cashing of DPK can use among others fake deposit slips, fake checking account slips, and fake powers of attorney.
c. Depositing or transferring savings, checking accounts, or deposits not recorded correctly in the books or reports, nor in documents or business activity reports, transaction reports, or Bank accounts.
d. Depositing or transferring savings, checking accounts, or deposits recorded in the Bank's books without accompanying fund flows. e. Providing services to prime customers outside procedures or regulations established by the Bank that cause losses to the Bank.
Lending/Financing
Fraud occurring in the activity of granting loans/financing conducted by the Bank, starting from the loan/financing application until repayment by the debtor. Example:
a. Fictional debtor
Explanation:
Granting loans/financing to one or more debtors using fake identities or other parties' identities. b. Fronting debtor Explanation:
Granting loans/financing to a debtor using the debtor's actual identity but the funds are used by other parties.
c. Manipulation or falsification of loan/financing documents or information
Explanation:
Manipulation of documents or information by the debtor and/or Bank parties to meet requirements and eligibility for granting loans/financing or restructuring loans/financing, including:
k. Repayment of loans/financing from the disbursement of new loans/financing intended to improve or maintain loan/financing collectibility.
l. Manipulation of loan/financing collectibility;
3. Use of Identity and Data of Others, Other Parties, or Customers
Fraud occurring by using the identity and data of others, other parties, or customers to conduct banking transactions without the knowledge and/or consent of the others, other parties, or customers. Example:
a. Misuse of customer ATM cards. b. Illegal sale or exchange of customer data between Banks or third parties employed by the Bank.
4. Asset Management
Fraud occurring in the Bank's asset management activities, including cash.
Example:
a. Use of cash in the vault by the Board of Directors, Board of Commissioners, and/or Bank employees for personal interests and not recorded in the Bank's books. b. Cash theft conducted by exploiting weaknesses in software and/or hardware on Bank ATM machines and/or ATM cards.
c. Misuse of Bank vehicles for personal interests of the Board of Directors, Board of Commissioners, officers, and/or Bank employees.
d. Sale of AYDA by Bank employees to debtors at unfair prices to obtain personal profit for employees. e. Employees not recording the purchase or sale of Bank-owned assets. f. Inflating (marking up) office building rental costs for personal gain, Board of Directors, Board of Commissioners, and/or Bank employees.
g. Manipulation of deposits and withdrawals in accounts at other banks by the Bank's President Director. h. Placement/Investment/Participation of Bank funds not in accordance with Bank SOPs conducted by employees colluding with other parties.
i. Withdrawal of cash without underlying transactions and not recorded in the appropriate position.
5. Cyber Usage
Fraud occurring using computers, computer networks, and/or electronic media to deceive the Bank, customers, individuals, or other parties to obtain customer personal information and data. Example:
a. Hacking or Cracking
Explanation:
Unauthorized use or search for access into Bank or customer data in banking systems including through electronic banking. b. Phishing Explanation:
Actions to obtain customer personal information by impersonating authorized parties via email to direct customers to access specific links in the email.
c. Skimming
Explanation:
Use of machines or cameras installed on ATM machines to steal card information and customer PIN numbers when customers use ATM machines. d. Social Engineering Explanation:
Actions to obtain customer information such as PIN, card numbers, and/or other information by contacting customers via telephone, SMS, or other media to inform about giving prizes and requesting customers to contact specific phone numbers or open specific websites. e. Virus, malware, or ransomware Explanation:
Programs designed with the intent to damage, infiltrate, and/or steal information or secret data of the Bank and/or customers in the Bank's electronic systems.
6. Financial Statement Presentation
Fraud occurring in the presentation of the Bank's financial statements, including financial statements not presented in accordance with generally accepted accounting principles and/or not in accordance with actual financial conditions, including incorrect recording such as inflating (marking up) costs and fictitious costs in the books or Bank reports. Example:
Manipulation or manipulation of the Bank's financial statements (window dressing).
Explanation:
Manipulation of financial statements to make the Bank's performance appear better than the actual financial condition or to successfully achieve established targets.
7. Other Activities
Fraud occurring in every aspect of Bank activities other than the categories grouped above (numbers 1 to 6).
V. Fraud Description or Modus Operandi (Must be Filled)
Filled with a description of the Fraud that occurred, maximum 4000 characters (using free format), and accompanied by uploading a PDF file containing detailed descriptions. If there are no detailed descriptions, the PDF file must still be uploaded.
VI. Fraud Location (Must be Filled)
Sub-Branch Office (Foreign) of Sharia Commercial Banks 57 Cash Office of Sharia Commercial Banks 58 Functional Office of Sharia Commercial Banks 59 Payment Point of Sharia Commercial Banks 60 Mobile Cash/Car Cash/Floating Cash of Sharia Commercial Banks 61 Representative Office of Sharia Commercial Banks abroad 62 ATM/CDM/CRM of Sharia Commercial Banks 63 Sharia Services of Commercial Banks 64 Conventional commercial banks with Sharia business units must fill in Sharia Business Unit of Commercial Banks (code 04) for Fraud incidents occurring in offices carrying out the functions of that Sharia business unit.
2. Fraud Location Description
Filled with 4 (four) characters according to the city/regency code stated in the Financial Information Service System (SLIK) guidelines as referred to in the Financial Services Authority regulations regarding reporting and requesting debtor information through SLIK.
VII. Division or Work Unit Where Fraud Occurred (Must be Filled)
Filled with the name of the division or work unit where the Fraud occurred or was directly affected by the Fraud (using free format).
VIII. Time (Must be Filled)
III. Perpetrator Identity (Must be Filled)
For external fraud perpetrators, if the fraud perpetrator is in the name of a company, the Gender, Place of Birth, and Date of Birth columns do not need to be filled. For external fraud perpetrators, if the fraud perpetrator is unknown, the Gender, Identity Address, Domicile Address, Place of Birth, and Date of Birth columns do not need to be filled.
Name (Must be Filled)
Filled with the fraud perpetrator's name without titles according to what is stated in the identity document.
For external fraud perpetrators, if the fraud perpetrator's name is unknown, that column must still be filled (cannot be left blank) and the Bank must define the name of the unknown perpetrator. Example: unknown client.
Identity Type (Must be Filled)
Filled with 3 (three) characters according to the identity type.
Identity Type Code Description
ID Card (National Identity Number) 001 Indonesian National Fraud Perpetrator Passport (Passport Number) 002 Foreign National Fraud Perpetrator Taxpayer Identification Number (NPWP) 003 Fraud Perpetrator in the name of a company Unknown 009
Identity Number (Must be Filled)
Filled with the identity number according to the selected identity type.
Identity numbers for unknown identity types use a unique code created by the Bank.
If the identity number contains characters other than letters and numbers, those characters do not need to be included.
Example:
If the Fraud Perpetrator has an NPWP number 49.810.734.1-035.000, then the Identity Number column is filled with 498107341035000.
Gender
Filled with a character of 1 (one) digit according to the fraud perpetrator's gender code as follows:
Gender Code
Male L
Female P
In the event that the fraud perpetrator is a company or unknown, the Gender column does not need to be filled.
Identity Address (Must be filled if the Fraud Perpetrator is Internal)
Filled with the identity address as stated in the fraud perpetrator's identity document.
Domicile Address (Must be filled if the Fraud Perpetrator is Internal)
Filled with the domicile address with information (using a free format, except for city or regency, province, and country which refer to the SLIK attachment as referred to in the Financial Services Authority regulations regarding reporting and requesting debtor information through SLIK):
a. Street/block; b. House number;
c. RT/RW;
d. Village/Sub-district; e. District; f. City/Regency; g. Province; h. Country; and
i. Postal Code.
Place of Birth (Must be filled if the Fraud Perpetrator is Internal)
Filled with the fraud perpetrator's place of birth as stated in the identity document.
Date of Birth (Must be filled if the Fraud Perpetrator is Internal)
Date of birth is filled (year/month/day) with a filling format of YYYYMMDD according to the date stated in the identity document.
Example:
Date of birth December 15, 1975, written as 19751215.
IV. Perpetrator Position (Must be filled if the Fraud Perpetrator is Internal)
Position Code Description
President Director 001
Director 002
Compliance Director 003 Director who oversees the compliance function.
Principal Commissioner 004
Commissioner 005
Sharia Supervisory Board 006
Executive Officer 007 Official who is directly responsible to a member of the Board of Directors or has significant influence over the Bank's policy and/or operations. Non-Executive Officer 018 All officials other than Executive Officers. Non-Officer Employee 019 All employees other than Executive Officers and Non-Executive Officers. Expert and Consultant 010
b. Position Description
Filled with the fraud perpetrator's position name at the Bank (using a free format).
Example: Credit AO, Credit Group Head.
Position Code Description
President Director 001
Director 002
Compliance Director 003 Director who oversees the compliance function.
Principal Commissioner 004
Commissioner 005
Sharia Supervisory Board 006
Executive Officer 007 Official who is directly responsible to a member of the Board of Directors or has significant influence over the Bank's policy and/or operations. Non-Executive Officer 018 All officials other than Executive Officers. Non-Officer Employee 019 All employees other than Executive Officers and Non-Executive Officers. Expert and Consultant 010 No longer working at the Bank:
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Retired Career 041
Early Retirement 042
Dismissed 043
Resigned 044
Contract/Assignment Ended 045
Deceased 046
b. Position Description (Must be filled if the Fraud Perpetrator is Internal) Filled with the fraud perpetrator's position name at the Bank (using a free format). Example: Credit AO, Credit Group Head.
V. Perpetrator Description (Must be filled if the External Fraud Perpetrator is Known)
Filled with a character of 3 (three) digits according to the code as follows:
Position Code
Customer 001
Parties directly related to the Bank (including vendors, investors, suppliers, state officials, or partners) 002 Parties not directly related to the Bank 003
Determined in Jakarta on December 19, 2019
CHAIRMAN OF THE COMMISSIONERS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
WIMBOH SANTOSO
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.