2023-07-06
Added · Updated
This instruction establishes prudential rules for internal control and risk management applicable to microfinance institutions, including credit and savings cooperatives, microfinance companies, and micro-credit enterprises. It mandates the implementation of a three-tier internal control system comprising first-level operational controls, second-level compliance and risk management functions, and independent third-level internal audit. The document defines key governance roles, risk appetite frameworks, and specific requirements for accounting controls, documentation, and information security, including the appointment of a dedicated IT security officer.
INSTRUCTION NO. 008 TO MICROFINANCE INSTITUTIONS ON PRUDENTIAL RULES FOR INTERNAL CONTROL AND RISK MANAGEMENT
(Modification No. 1)
The Central Bank of Congo,
Having regard to the Organic Law No. 18/027 of December 13, 2018, on the organization and functioning of the Central Bank of Congo, particularly Articles 10, 11, and 25;
Having regard to Law No. 22/069 of December 27, 2022, on the activity and supervision of Credit Institutions, particularly Article 21;
Having regard to Law No. 002/2002 of February 2, 2002, on provisions applicable to Savings and Credit Cooperatives;
Having regard to Law No. 11/020 of September 15, 2011, setting rules relating to the microfinance activity in the DRC;
Having regard to Law No. 22/068 of December 27, 2022, on the fight against money laundering and the financing of terrorism and the proliferation of weapons of mass destruction;
Enacts the following provisions:
Article 1:
This Instruction aims to define the prudential rules for internal control and risk management applicable to the microfinance institutions referred to in Article 2 of this Instruction.
Article 2:
This Instruction applies to the following microfinance institutions, hereinafter referred to as "subject institutions":
CENTRAL BANK OF CONGO CONTINUED, PAGE 2
Article 3:
For the purposes of this Instruction, the following terms are defined as:
risk appetite: the overall degree and types of risks, previously set and lower than the risk tolerance, that a subject institution is willing to assume to achieve its strategic objectives and activity plan;
audit charter: an official document that defines the mission, powers, and responsibilities of the internal audit function within an entity;
ethics and compliance committee: a governance committee, emanating from the deliberative body, created to assist it in exercising its missions of monitoring compliance, ethics, and deontology;
risk committee: a governance committee, emanating from the deliberative body, created to assist it in determining risk appetite, monitoring the implementation by the executive body of the risk appetite statement, and ensuring the supervision of the risk management function;
audit committee: a governance committee, emanating from the deliberative body, created to assist it in exercising its monitoring missions, notably the evaluation of the quality of the internal control system and the steering of internal audit;
internal control committee: an internal operational committee that ensures operational coordination between the second and third-level internal control functions (permanent control of operational activities, compliance, risk management, and internal audit) under the chairmanship of the executive body;
risk management committee: an internal operational committee steered by the executive body, which implements the risk strategy defined by the deliberative body and ensures its proper application by operational services and the appropriate supervision provided by the head of the risk management function;
conflicts of interest: a situation where the personal interests of a member of the governance bodies, a staff member, or those of persons with whom they have a close family link are not compatible with the interests of the subject institution and could, therefore, influence the impartiality expected of them in the performance of their duties;
deliberative body: the body responsible, on behalf of the shareholders, for defining the strategic direction of the institution and the effective supervision of the management of activities. It is constituted as a board of directors;
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO
Article 4:
The internal control system consists of a device and functions put in place by the deliberative body and implemented by the executive body to ensure control, at all levels, of the subject institution's activities and operations.
Article 5:
Subject institutions determine the structure and sizing of their internal control system based on their risk profile, as determined by the executive body and approved by the deliberative body. They take into account, in the architecture of control functions and their hierarchical positioning, the characteristics and typology of the activities they carry out.
Subject institutions take into account, where applicable, in the organization of their internal control system, the internal standards of the group to which they belong, while ensuring that the adopted provisions comply with this Instruction.
Article 6:
Subject institutions are required, in accordance with the provisions of this Instruction, to equip themselves with an adequate internal control device. This device must be adapted to the nature and volume of their activities, their size, their locations, and the various types of risks to which they are exposed.
Article 7:
The internal control device notably includes:
Subject institutions must have a management information system.
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 5
## CHAPTER I: SYSTEM FOR CONTROLLING OPERATIONS AND INTERNAL PROCEDURES
### Article 8:
The system for controlling operations and internal procedures must enable subject institutions to ensure, under optimal conditions of security, reliability, and completeness, notably:
- the conformity of operations carried out, the organization, and internal procedures with current legal and regulatory provisions, professional and ethical standards and practices, as well as with internal instructions of the executive body taken in application of the orientations of the deliberative body;
- strict respect for decision-making and risk-taking policies and procedures, as well as management standards and limits set by the executive body;
- the quality of accounting and financial information intended for the deliberative body, the executive body, the Central Bank of Congo, or the public;
- the conditions for the evaluation, recording, retention, and availability of this information, particularly the existence and quality of the audit trail;
- the security and quality of information and communication systems;
- the execution within reasonable timeframes of corrective measures decided upon to remedy findings made by the various internal control and risk management functions.
### Article 9:
Subject institutions are required to draft and keep up to date procedure manuals relating to all their activities. These documents must notably describe the methods for recording, processing, and reporting information, the procedures for engaging and monitoring operations, the corresponding accounting schemes, as well as reporting methods.
Each service or operational unit belonging to the internal control system must be equipped with a regularly updated manual in which the procedures for executing the operations it is charged with performing are recorded. These manuals are defined by the executive body, approved by the deliberative body, and then disseminated to personnel.
## CHAPTER II: ACCOUNTING CONTROL DEVICE
### Article 10:
The device for controlling the accounting of operations must enable subject institutions to ensure the reliability and completeness of the recording of their accounting and financial data and to ensure the availability of information in accordance with the current accounting legislation of the financial sector.
---
CENTRAL BANK OF CONGO CONTINUED, PAGE 6
### Article 11:
The methods for accounting recording of operations in regulatory and published financial statements must provide for a set of procedures guaranteeing the audit trail, enabling:
- the reconstruction of all operations in chronological order;
- the justification of any information by an original document from which it must be possible to trace back through an uninterrupted path to the summary document and vice versa;
- the explanation of the evolution of accounting balances from one closing to the next by retaining the recording of movements affecting accounting items.
Any exception to the preceding principles, regarding the justification of an accounting balance or the publication of information, must be the subject of a detailed justification, published in the annexes of the financial statements and approved by the statutory auditors.
### Article 12:
The information contained in accounting statements and that necessary for the calculation of management standards and prudential ratios, as well as periodic and prudential declarations intended for the Central Bank of Congo, must comply with the provisions of the previous article of this Instruction.
## CHAPTER III: DOCUMENTATION AND INFORMATION SYSTEM
### Article 13:
Subject institutions are required to establish and keep up to date documentation that specifies the devices intended to ensure the proper functioning of internal control, notably:
- the different levels of responsibility;
- the attributes assigned and the means allocated to the functioning of internal control devices;
- the rules that ensure the independence of these devices under the conditions provided for in this Instruction;
- procedures relating to the security of information and communication systems and the business continuity plan;
- the description of systems for measuring, limiting, monitoring, and controlling risks;
- the mode of organization and functioning of the compliance control device.
---
CENTRAL BANK OF CONGO CONTINUED, PAGE 7
The documentation system must be organized to ensure the availability of documentation, upon request by the deliberative body, the executive body, the audit committee, or other specialized committees of the deliberative body provided for in Instruction No. 007, the statutory auditors, and the Central Bank of Congo.
### Article 14:
Subject institutions belonging to a group established in the Democratic Republic of Congo or abroad are required to have on site all documents concerning them relating to audits, controls, procedures, or decisions on activity orientation or internal control and risk management policy, established at the group level or by any external auditor or consultant.
## CHAPTER IV: INFORMATION SECURITY MANAGEMENT
### Article 15:
Subject institutions must define the level of information security deemed desirable in relation to the requirements of their sectors of activity. They ensure that their information systems are adapted to the risks inherent in their operations and to the characteristics of their organization and operating modes.
### Article 16:
Information security is ensured by an information security officer, a function dedicated and independent from that in charge of the operational management of the information system. In the case where the size of the subject institution does not justify the appointment of a dedicated information security officer, the risk management function assumes this role.
The information security officer ensures that information security issues are properly addressed and organized within the subject institution and that they give rise to the issuance of internal rules which he supervises the implementation of. Developments in the information system, notably projects, the use of new techniques, and outsourcing, are systematically subject to security analyses submitted to him, also considering the cyber dimension.
Furthermore, he must ensure that:
- the hardware equipment of the information system is subject to adequate protection against physical and logical risks of intrusion or destruction;
- access management and user authentication of the information system are controlled;
- data is protected in full confidentiality through protection solutions according to their degree of sensitivity;
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 8
Article 17:
The internal control system consists of three (3) complementary functions, not exclusive of one another, as follows:
permanent first-level control ensured by the operational staff themselves;
permanent second-level control ensured, retrospectively and recurrently, by dedicated teams controlling the compliance and quality of the implementation of operational processes, which do not exercise operational functions.
This control is composed of the following three functions:
the permanent control function of operational activities;
the compliance function;
the risk management function.
third-level control performed periodically, under the responsibility of the deliberative body through its audit committee, by an independent internal audit function intervening on documents or on-site within the framework of missions.
Article 18:
Subject institutions ensure a strict separation of first, second, and third-level control functions.
Within the second-level control, they ensure a strict separation between the compliance, permanent control of operational activities, and risk management functions.
The heads of permanent control of operational activities, compliance, risk management, and internal audit must be approved by the Central Bank of Congo under the conditions provided for in Instruction No. 41.
First-level permanent control cannot, in any case, be merged with another level of control.
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 9
Article 19:
The functions of head of second-level permanent control in its three components and those of head of third-level periodic control must be entrusted to senior management executives, presenting all guarantees of morality, honorability, competence, and professional experience.
They are appointed by the executive body, after prior agreement of the deliberative body. The latter must also approve their dismissal or cessation of functions.
Their hierarchical positioning in the organizational chart of subject institutions must confer upon them the necessary authority to issue an independent opinion vis-à-vis operational departments.
The heads of permanent control of operational activities, compliance, risk management, and internal audit must hold a hierarchical rank immediately below the General Management.
Article 20:
Subject institutions are required to put in place in each operational unit a first-level control function, charged with ensuring on a daily basis the processing of operations according to the principles and procedures defined by the hierarchy, and notably guaranteeing the separation of sensitive functions and respect for the institution's risk-taking policy.
Article 21:
First-level controls are performed by:
Article 22:
The second-level permanent control device of subject institutions is organized into three functions with different missions, namely:
Subject institutions may request prior authorization from the Central Bank of Congo to merge certain second-level control functions under the conditions provided for in Instruction No. 41.
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 10
Article 23:
Subject institutions are required, according to methods adapted to their size, risk profile, and the nature of their activities, to have staff performing second-level permanent controls on all operational activities and independently from the units ensuring the processing of these activities.
Article 24:
Subject institutions must equip themselves with a second-level control function for operational activity.
Article 25:
The head and staff of the second-level control function for operational activity must have the appropriate expertise to control all activities. They report on the controls performed using formalized reporting states, auditable by third-level periodic control or by the Central Bank of Congo.
Article 26:
The second-level operational activity control ensures the proper execution of first-level permanent controls. In this context, it has at its disposal surveillance tools to ensure that operational units comply with the activity procedures defined by the deliberative body and implemented by the executive body. It determines a program of recurring controls focusing primarily on the most sensitive operational processes of the supervised establishment, as provided for by the risk map, to ensure the rigor of their execution in accordance with the procedures approved by the deliberative body.
The second-level operational activity control function ensures the proper execution of corrective measures decided following controls carried out by it, by the periodic third-level control, and, where applicable, by the Central Bank of Congo.
The findings made by the second-level operational activity control function are formalized to ensure their traceability and auditability. They are communicated to the concerned operational units for correction without delay, with a copy to the executive body. Control reports may also recommend general recommendations aimed at improving the quality of operational processes.
Article 27:
The head of the second-level operational activity control function presents the results of its controls to the deliberative body at least twice a year, using appropriate summary statements.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 11
In the event of persistent non-implementation of corrective actions recommended at the end of its controls, it transmits a special report to the executive body, or directly to the deliberative body, according to the modalities defined by the supervised establishment.
Section 2: Compliance Function
Article 28:
Supervised establishments are required to establish a compliance control function, responsible for ensuring the compliance of their activities with current laws and regulations, including those relating to the fight against money laundering and terrorist financing and the proliferation of weapons, as well as to the ethical and deontological rules defined by the deliberative body. These rules must be formalized in an ethics charter or code of deontology disseminated to all staff and members of the governance bodies.
Article 29:
The Ethics and Compliance Committee has the role, in particular, to:
Article 30
The deliberative body has the role, in particular, to:
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 12
Article 31:
The executive body has the mission, in particular, to:
Article 32:
The organization of the compliance function must meet the following conditions:
Article 33:
The compliance policy must identify in particular the fundamental aspects of non-compliance risk, explain the principles set by the deliberative body, define the role and objectives of the compliance function, and set up a continuous training program.
This policy must also provide for the development of a compliance charter that:
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 13
Article 34:
The supervised establishment is required to designate a person in charge of the compliance function.
The compliance function is notably responsible for the following missions:
The compliance function ensures that the supervised establishment has norms governing the exercise of daily operations of all its activities. These norms must be an integral part of the instructions, operational procedures, and internal control for areas directly related to compliance.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 14
Article 35:
The compliance function is also involved, for activities that do not directly fall under compliance, in the preparation and implementation of operational and internal control procedures, in particular:
the regular verification of compliance with the policy, procedures, and instructions in matters of compliance. It also sets up indicators to analyze and monitor detected problems as well as to recommend corrective measures to be taken;
the centralization of all information on problems and malfunctions identified with respect to current norms. In the case where the supervised establishment belongs to a group, these procedures must cover the modalities for centralizing information emanating from the group;
the awareness-raising and training of all its staff, including executives, on the importance and procedures for compliance control related to the operations they perform.
Article 36:
The compliance function must issue a prior conforming opinion before any launch of a new product, new activity, any substantial modification in the marketing policy of a product line, or any entry into a new market. Exceptional acquisition or disposal of asset operations must also be subject to a prior conforming opinion from compliance.
In the event of non-takeover of a negative opinion from compliance, the head of compliance is required to inform the executive body, or directly the deliberative body. The executive body establishes an annual report provided for in this Instruction in which this opinion and the follow-up given to it are mentioned.
Article 37:
The activities of the compliance function must be included in the scope of intervention of internal audit. The latter must evaluate the functioning and effectiveness of this function.
Internal audit must communicate to the head of the compliance function any malfunctions related to non-compliance risk identified within the framework of its control missions.
Article 38:
The head of the compliance function must prepare, at least once a year, a report on its activities which he addresses to the executive body. The latter transmits said report to the deliberative body via the Supervisory Board or Audit Committee.
A copy of this report must be sent to the Direction of the Supervision of Financial Intermediaries of the Central Bank of Congo, no later than the sixth month following the end of the previous fiscal year.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO
CONTINUED, PAGE
15
Article 39:
The compliance function must document the work carried out in accordance with the responsibilities assigned, in particular to trace interventions as well as observations retained.
It reports to the executive body and, where applicable, to the deliberative body, audit/Supervisory Board and Ethics and Compliance committees, on the problems and malfunctions observed at the level of procedures, the compliance policy, as well as the measures taken in this regard.
It must also communicate these malfunctions to internal audit.
Section 3: Risk Management
Article 40:
Supervised establishments must put in place a risk management system allowing the identification, analysis, measurement, monitoring, or control of risks of different natures to which their activities expose them.
This system must be adapted to the nature, volume, and degree of complexity of the activities and operations of the supervised establishment and adjusted regularly according to its risk profile and the evolution of markets.
Supervised establishments must put in place processes for the global evaluation of prudential own funds with regard to these risks.
Article 41:
The risks to which supervised establishments are exposed are notably credit or counterparty risk, market risk, operational risk, interest rate risk, liquidity risk, as well as those related to outsourced activities.
The supervised establishment must implement, for each significant risk, a device for the identification, analysis, measurement, monitoring, mitigation, and control of risks comprising in particular:
563, Boulevard Colonel Tshatshi - Kinshasa - Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO
Article 42: The supervised establishment is required to establish a risk map that must meet the following characteristics:
Article 43: The risk map must take into account, in addition to the detail of exposures of each risk of the supervised establishment concerning all its operational processes, relevant and adapted information and indicators of the activity of said establishment, in particular:
Article 44: The deliberative body is required, based in particular on the risk indicators identified in the risk map, the macroeconomic environment of the supervised establishment, its financial situation, the expectations and support of its shareholders, to determine and approve the risk tolerance, representing the absolute limit to which the supervised establishment can be exposed without calling into question the continuity of operations. This limit must be compatible with the level of own funds and regulatory prudential requirements. The risk tolerance must be contained in a formalized document, revised and approved at least once a year by the deliberative body or as needed.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO
Any operation or incident that would lead to crossing the risk tolerance threshold defined by the deliberative body must be brought without delay to the knowledge of the latter and to the Central Bank of Congo by the risk manager of the supervised establishment.
Article 45: The level of residual risk resulting from the map must be subject to formal acceptance by the deliberative body, after revision by the executive body. When the level of residual risk is judged excessive or if it is not in conformity with the risk appetite policy established by the deliberative body, additional risk mitigation measures must be taken and be subject to monitoring of their effective impact on the reduction of residual risk. Failing this, the risk acceptance strategy must be modified accordingly and approved by the deliberative body. The risk appetite policy must be contained in a document approved at least once a year by the deliberative body. It provides, on the one hand, for quantitative criteria expressed in terms of revenues, the level of own funds, risk indicators, liquidity, and any other relevant parameter, and, on the other hand, for qualitative orientations concerning reputation and ethical risks as well as the framework for the fight against money laundering and terrorist financing and proliferation.
Article 46: The supervised establishment is required to put in place a risk management and monitoring policy allowing the adaptation of the intensity of its monitoring measures to the level of sensitivity of the risks incurred. The risk management and monitoring policy must be formalized and validated by the executive body and approved by the deliberative body. It must specify the operating modes of the risk management function, the distribution of roles and responsibilities, and the information exchanges between the various stakeholders such as heads of operational business lines, the risk management head, the executive body, the risk committee, the deliberative body, and other heads of internal control functions. The risk management and monitoring policy must provide that risk zones identified as the most sensitive are subject to enhanced management and monitoring measures.
Article 47: The supervised establishment is required to designate a person in charge of the risk management function.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 18
The risk management function has the missions, in particular:
- to develop, for submission to the executive body, the risk management policy based on prudent procedures that allow the detection, analysis, measurement, monitoring, mitigation, and control of risks, with a view to its approval by the deliberative body;
- to coordinate and globally monitor the execution of the risk appetite policy defined by the deliberative body according to risk tolerance;
- to regularly re-examine risk measurement systems, the modalities for determining limits and their configuration to verify their relevance with regard in particular to the evolution of activity, the market environment, analysis techniques, and its risk profile;
- to issue a prior opinion before any launch of a new product, new activity, any substantial modification in the marketing policy of a product line, or any entry into a new market as well as on acquisition or disposal of asset operations. The aforementioned opinion includes an evaluation of the risks incurred, an appreciation of the conditions for risk control, and an opinion on the follow-up to be given to the project from the point of view of risk management;
- to organize an escalation procedure in the event of non-takeover of its negative opinion with a view to a decision at a higher delegation level. This procedure must provide for immediate information by any means to the deliberative body when it is implemented.
**Article 48:**
The deliberative and executive bodies are required to maintain within the global limits set by current regulations, the exposures of the supervised establishment to credit, exchange, and other market risks, global interest rate risk, liquidity, and operational risks.
The executive body may assign specific exposure limits to operational entities, established in a manner consistent with the different global limits.
The supervised establishment is required to ensure the regular updating of said limits, at least once a year, taking into account in particular the level of its own funds and the evolution of risks as it results from the regularly updated risk map.
**Article 49:**
---
Exposure limits to risks must be monitored automatically using features provided for this purpose in the information management systems of the various activities.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
```markdown
CENTRAL BANK OF CONGO CONTINUED, PAGE 19
Exceedances of limits must trigger automated alerts to the hierarchical managers in charge of the relevant activities, according to their level of delegation, as well as to the head of the risk management function and, where applicable, to the executive body and other internal control functions.
The handling of exceedances and alerts must be subject to formalized processes monitored by the aforementioned managers in order to implement appropriate regularization measures ensuring their traceability.
**Article 50:**
The specialized risk committee is required to inform the deliberative body of any malfunctions affecting compliance with the risk appetite policy of the regulated institution.
The deliberative body must set a threshold beyond which it must be systematically informed of significant incidents affecting the financial situation, compliance with prudential regulation, or activity. An emergency procedure must be established to inform it without delay of any major incident likely to seriously jeopardize business continuity.
The deliberative body, assisted by the specialized risk committee, must approve the risk management framework in accordance with the risk appetite policy it defines. It instructs, where applicable, the executive body to make any necessary adjustments to strengthen this framework.
**Article 51:**
The head of the risk management function is required, at least once per quarter, to present the results of risk monitoring to the deliberative body and its specialized risk committee using appropriate summary reports.
It must produce an annual report on the exercise of its risk management and monitoring responsibilities, which is integrated into the annual internal control and risk management report transmitted to the Central Bank of Congo under the conditions provided by this Instruction.
**CHAPTER III: THIRD-LEVEL CONTROL**
**Article 52**
Third-level control or periodic control is ensured by an independent function in charge of internal audit, which has the mission of verifying, in particular, the compliance of operations, the management of incurred risks, compliance with procedures and regulations, the effectiveness and compliance of risk monitoring and management frameworks, as well as any other subject relating to the activity of the regulated institution and its subsidiaries.
This periodic control is carried out through on-site control missions.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 20
**Article 53:**
Internal audit is functionally attached to the audit committee or Supervisory Council. The audit committee or Supervisory Council holds at least four meetings per year. It may associate with its work the heads of the internal control and risk management functions, as well as the statutory auditors of the regulated institution, and summon any useful person to these works.
**Article 54:**
In application of the audit charter or internal control charter approved by the deliberative body, the audit committee or Supervisory Council has, in particular, the following responsibilities:
- supervise and control the internal control functions;
- approve the annual or multi-annual programs of second-level permanent control and internal audit;
- ensure complete coverage of the regulated institution's activities by internal controls and internal or external audits;
- ensure that all activities of the regulated institution are verified by internal audit according to a cycle whose duration cannot exceed three years, adjustable according to the risk profile;
- ensure the adequacy of the internal control system to the activities of the regulated institution;
- assess the adequacy of the human resources and material means allocated to the internal control functions;
- ensure that internal controllers and auditors possess the necessary skills and propose, if necessary, measures to strengthen their expertise;
- provide an assessment of the quality of the internal control system, in particular the coherence of the devices for identification, analysis, measurement, monitoring, and management of risks, and propose, where applicable, appropriate corrective actions;
- verify the reliability and accuracy of financial information intended for the deliberative body, the Central Bank of Congo, and third parties, and provide an assessment of the relevance of the accounting methods adopted for the preparation of individual and consolidated accounts;
- evaluate the relevance of corrective measures taken or proposed to fill gaps or deficiencies identified in the processing of operations, following control or audit reports, where applicable, in the internal control system;
- ensure the effective and rapid implementation of corrective measures recommended by the control and audit functions and, where applicable, alert the deliberative body or directly the Central Bank of Congo in case of non-implementation;
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
More like this from BCC
We email you every new BCC publication the day it's published.