2023-07-06
Added · Updated
This instruction establishes prudential rules for internal control systems applicable to credit institutions and financial companies in the Democratic Republic of Congo, including banks, savings banks, factoring companies, and electronic money institutions. It mandates the establishment of an internal control framework comprising operational controls, accounting controls, documentation systems, and IT security measures, with specific requirements for segregation of duties, audit trails, and cybersecurity incident reporting. The governing bodies and executive management are held responsible for defining risk appetite, approving internal control policies, and ensuring the adequacy of resources and procedures to manage risks effectively.
BANQUE CENTRALE DU CONGO
LE GOUVERNEUR
INSTRUCTION N° 17 AUX ETABLISSEMENTS DE CREDIT ET SOCIETES FINANCIERES RELATIVE AUX REGLES PRUDENTIELLES EN MATIERE DE CONTROLE INTERNE
(Modification n°3)
The Central Bank of Congo,
Having regard to the Organic Law No. 18/027 of December 13, 2018, on the organization and functioning of the Central Bank of Congo, particularly Articles 10, 11, and 25;
Having regard to Law No. 22/069 of December 27, 2022, on the activity and supervision of Credit Institutions, particularly Article 21;
Having regard to Law No. 22/068 of December 27, 2022, on the fight against money laundering and the financing of terrorism and the proliferation of weapons of mass destruction, particularly Titles I and III;
Having regard to Law No. 15/003 of February 12, 2015, on leasing activity, particularly Articles 6 and 7;
Enacts the following provisions:
PART I: GENERAL PROVISIONS
TITLE I: OBJECTIVE, SCOPE
Article 1:
This Instruction aims to define the prudential rules relating to risk management for credit institutions and financial companies referred to in Article 2.
Article 2:
This Instruction applies to the Credit Institutions and financial companies listed below, hereinafter referred to as "subject institutions":
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
2
BANQUE CENTRALE DU CONGO
CONTINUED, PAGE
TITLE II: DEFINITIONS
Article 3:
For the purposes of this Instruction, the following terms are defined as:
administrator: member of the deliberative body (Board of Directors) designated by the General Meeting of Shareholders;
executive administrator: administrator who is also a member of the executive body of the subject institution;
non-executive administrator: administrator who is not a member of the executive body of the subject institution;
independent administrator: non-executive administrator not affiliated with the subject institution. A free member of the Board of Directors who contributes, through their competence and freedom of judgment, to the board's capacity to fulfill its missions. They must be devoid of particular interest links of a professional (significant shareholder, employee, business relationship, service provider, etc.) or personal nature with the subject institution and its shareholders.
specialized committees: structures emanating from the deliberative body with the aim of assisting it in its control function;
ethics and compliance committee: a governance committee, emanating from the deliberative body, created to assist it in exercising its missions of surveillance regarding compliance, ethics, and deontology;
risk committee: a governance committee, emanating from the deliberative body, created to assist it in determining risk appetite, supervising the implementation by the executive body of the risk appetite statement, and ensuring the supervision of the risk management function;
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
3
BANQUE CENTRALE DU CONGO
CONTINUED, PAGE
audit committee: a governance committee, emanating from the deliberative body, created to assist it in exercising its supervision missions, notably the evaluation of the quality of the internal control system and the steering of internal audit;
conflicts of interest: a situation where the personal interests of a member of the governance bodies or a member of staff, or those of persons with whom they have a close family link, are not compatible with the interests of the credit institution and could, for this reason, influence the impartiality expected of them in the performance of their duties;
internal control system: the set of rules, methods, and control measures governing the organizational and operational structure of a credit institution. It includes reporting processes and control functions;
internal control committee: an internal operational committee that ensures operational coordination between the second and third-level internal control functions (permanent control of operational activities, compliance, risk management, and internal audit) under the chairmanship of the executive body;
risk management committee: an internal operational committee steered by the executive body, which implements the risk strategy defined by the deliberative body and ensures its proper application by operational services and the appropriate supervision provided by the head of the risk management function;
audit charter: an official document that defines the mission, powers, and responsibilities of the internal audit function within an entity;
Deliberative Body: the body responsible, on behalf of the shareholders, for defining the strategic direction of the institution and the effective supervision of activity management. It takes the form of a Board of Directors;
Executive Body: The body responsible, on behalf of the deliberative body, for the day-to-day management of the institution's activities as well as the effective steering of the implementation of the strategic objectives and risk policy set by the deliberative body. It corresponds to the General Management, Management Committee, or Steering Committee. It includes the General Director and the Deputy General Director(s);
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO
PART II: FUNCTIONS OF THE INTERNAL CONTROL SYSTEM
Article 4:
Subject institutions determine the structure and sizing of their internal control system based on the risk profile, as determined by the executive body and approved by the deliberative body. They take into account, in the architecture of control functions and their hierarchical positioning, the characteristics and typology of the activities they carry out.
Subject institutions take into account, where applicable, in the organization of their internal control system, the internal standards of the group to which they belong, while ensuring that the adopted provisions comply with this Instruction.
Likewise, subsidiaries, which they control exclusively or jointly, integrate into their internal control system the standards they define to ensure effective risk supervision on a consolidated basis, while ensuring compliance with the provisions of this Instruction.
Article 5:
The internal control system consists of a framework and functions put in place by the deliberative body and implemented by the executive body to ensure mastery, at all levels, of the activities and operations of the subject institution.
TITLE I: INTERNAL CONTROL FRAMEWORK
Article 6:
Subject institutions are required, in accordance with the provisions covered by this Instruction, to equip themselves with an adequate internal control framework adapted to the nature and volume of their activities, their size, their locations, and the various types of risks to which they are exposed.
The internal control framework notably includes:
- a system to control operations and internal procedures;
- an organization for the accounting of operations and information processing to ensure the reliability of the conditions for the collection, processing, dissemination, and retention of accounting and financial data;
CONTINUED, PAGE
5
BANQUE CENTRALE DU CONGO
- systems to measure, master, and monitor risks and results;
- a documentation and information system guaranteeing the effectiveness of internal channels for the circulation of documentation and information as well as their dissemination to third parties.
Article 7:
The internal control framework is developed and operates under the responsibility of the deliberative body and the executive body under the conditions provided for in Part III of this Instruction and the Instructions of the Central Bank of Congo relating to the governance of Credit Institutions and financial companies.
This principle of responsibility remains in constant application, even when a component of the internal control system is outsourced to a higher level of the group of affiliation.
CHAPTER I: SYSTEM FOR CONTROLLING OPERATIONS AND PROCEDURES
Article 8:
Subject institutions are required to develop and keep up to date procedure manuals relating to all their activities. These documents must notably describe the methods for recording, processing, and reporting information, the procedures for committing and monitoring operations, the corresponding accounting schemes, as well as reporting methods.
Each service or operational unit belonging to the internal control system must be equipped with a regularly updated manual in which the procedures for executing the operations it is charged with performing are recorded. These manuals are defined by the executive body, approved by the deliberative body, and then disseminated to personnel.
Article 9:
The levels of authority and responsibility as well as the areas of intervention of the different operational units must be clearly specified and delimited.
A strict separation must be established between the units charged, each in its own regard, with the initiation, execution, validation, accounting, and control of operations.
CONTINUED, PAGE
6
BANQUE CENTRALE DU CONGO
This independence must be ensured by different hierarchical attachments as well as by procedures, possibly computerized, which guarantee a strict separation of functions. In this case, the subject institution must be able to justify the adequacy of its choices of attachment and the procedures it implements based on its size, activities, and risk profile.
Areas that present potential conflicts of interest or risks of overlap of competencies or responsibilities must be identified, subject to enhanced supervision, and undergo regular evaluation with a view to resolving these conflicts.
Article 10:
The methods for executing operations carried out daily by operational units must include appropriate permanent control procedures of the first and second levels to ensure the regularity, reliability, and security of these operations as well as respect for other diligence related to the supervision of the risks associated with them. Control procedures must be determined based on the typology and level of risks inherent in the operations.
Article 11:
The system for controlling operations and procedures must allow subject institutions to ensure, under optimal conditions of security, reliability, and completeness, notably:
- the conformity of operations carried out, the organization, and internal procedures with current legal and regulatory provisions, professional and deontological standards and practices, as well as with internal instructions of the executive body taken in application of the orientations of the deliberative body;
- strict respect for decision-making and risk-taking policies and procedures, as well as management standards and limits set by the executive body;
- the quality of accounting and financial information intended for the deliberative body, the executive body, the Central Bank of Congo, or intended for publication;
- the conditions for evaluation, recording, retention, and availability of this information, particularly the existence and quality of the audit trail;
- the security and quality of information and communication systems;
- the execution within reasonable timeframes of corrective measures decided upon to remedy findings made by the various internal control and risk management functions.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
```markdown
BANQUE CENTRALE DU CONGO
CONTINUED, PAGE
## Article 12:
The internal control system must ensure the effective implementation, within prescribed deadlines, of the measures listed in Article 11.
In this context, the deliberative body is responsible for taking into account the system of operations and internal procedures, and the executive body is responsible for their implementation.
## CHAPTER II: ACCOUNTING CONTROL FRAMEWORK
## Article 13:
The framework for controlling the accounting of operations must allow subject institutions to ensure the reliability and completeness of the recording of their accounting and financial data and to ensure the availability of information in accordance with the current financial sector accounting legislation.
## Article 14:
The methods for accounting recording of operations in regulatory and published financial statements must provide for a set of procedures guaranteeing the audit trail, allowing:
- to reconstruct all operations in chronological order;
- to justify any information with an original document from which it must be possible to trace back through an uninterrupted path to the summary document and vice versa;
- to explain the evolution of accounting balances from one closing to another by means of the retention of the recording of movements affecting accounting items.
Any exception to the preceding principles, regarding the justification of an accounting balance or the publication of information, must be the subject of a detailed justification, published as an annex to the financial statements and approved by the statutory auditors.
## Article 15:
The information contained in accounting statements and that necessary for the calculation of management standards and prudential ratios as well as periodic and prudential declarations intended for the Central Bank of Congo must respect the provisions of the previous article of this Instruction.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
---
BANQUE CENTRALE DU CONGO
CONTINUED, PAGE
## Article 16:
Securities and other assets held or managed on behalf of third parties must be subject to rigorous monitoring through a "physical" accounting that faithfully records their entries, exits, and holdings and which is subject to internal controls and periodic inventories.
A distinction must be made between values received in free deposit and those serving as collateral in favor of the subject institution itself or third parties. Values allocated as collateral must be duly listed in the accounting system.
## Article 17:
Subject institutions must ensure the completeness, quality, and reliability of information, evaluation methods, and accounting of operations, notably by:
- regular control of the adequacy of methods and parameters retained for the evaluation of operations;
- regular evaluations of the accounting information system and information processing with regard to the general principles of prudence, fidelity, sincerity, and security as well as the conformity of accounting schemes with current rules;
- regular reconciliation, for operations involving exchange rate risks or other market risks, between results calculated by operational units and accounting results obtained based on current evaluation rules. Any significant discrepancy observed must be justified and brought to the attention of the executive body.
## Article 18:
Subject institutions must retain all files and documentation necessary to justify their accounting balances from the date of the closing that was subject to verification during the last on-site inspection by the Central Bank of Congo, and at least from the date of the closing of the penultimate exercise relative to the current exercise.
This provision applies without prejudice to other current legal and regulatory provisions relating to the retention of information.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
---
BANQUE CENTRALE DU CONGO
CONTINUED, PAGE
## CHAPTER III: DOCUMENTATION AND INFORMATION SYSTEM
## Article 19:
Subject institutions are required to establish and keep up to date documentation that specifies the devices intended to ensure the proper functioning of internal control, notably:
- the different levels of responsibility;
- the attributions assigned and the means allocated to the functioning of internal control devices;
- the rules that ensure the independence of these devices under the conditions provided by this Instruction;
- procedures relating to the security of information and communication systems and the business continuity plan;
- a description of systems for measuring, limiting, monitoring, and mastering risks;
- the mode of organization and functioning of the compliance control framework.
The documentation system must be organized to ensure the availability of documentation, upon request by the deliberative body, the executive body, the audit committee, or other specialized committees of the deliberative body provided for in regulatory provisions relating to corporate governance, statutory auditors, and the Central Bank of Congo.
This documentation is also made available to other internal committees authorized to access it.
## Article 20:
Subject institutions, belonging to a group established in the Democratic Republic of Congo or abroad, are required to have on site all documents concerning them relating to audits, controls, procedures, or strategic decisions on activity or internal control and risk management policy, established at the group level or by any external auditor or consultant.
## Article 21:
Reports established following periodic controls are communicated to the executive body, the audit committee, and, where applicable, to the deliberative body at its request.
Under the same conditions, the documents referred to in Article 20 are transmitted to the aforementioned bodies.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
```markdown
BANQUE CENTRALE DU CONGO
These reports and documents are made available to statutory auditors and the Central Bank of Congo.
## CHAPTER IV: IT SECURITY MANAGEMENT
### Article 22
Subject institutions must define the level of IT security deemed desirable with regard to the requirements of their sectors of activity. They ensure that their information systems are adapted to the risks inherent in their operations and the characteristics of their organization and operating modes.
The control of information systems must notably allow ensuring:
- the periodic evaluation, at least annually, of the security level of computer systems and, where applicable, the implementation of corrective actions to reduce risks;
- the existence of the business continuity plan and IT recovery procedures to ensure the continuity of operations in the event of serious difficulties affecting the functioning of computer systems.
The control of information systems extends from the creation, modification, and retention of information to documentation relating to analyses, programming, modification, and execution of operational processes.
### Article 23
Subject institutions are required to immediately transmit to the Regulatory and Control Authority and the committee for concertation and the fight against cybercrime any intrusion or attempt that affects the integrity of their information system.
### Article 24
The deliberative body evaluates, on the proposal of the executive body, the IT stakes weighing on the activity of the subject institution and approves the choices made to ensure the appropriate functioning or evolution of the information system, also taking into account the cyber dimension, as well as the budgets allocated to it.
The deliberative body also approves the choices made regarding IT security, notably to validate policies and communication with personnel.
---
BANQUE CENTRALE DU CONGO
The deliberative body ensures the definition by the executive body of lines of responsibility and objectives assigned to heads of IT development and production functions, as well as to the information security officer.
The deliberative and executive bodies must have clear and precise information and ensure the quality and relevance of the information communicated to them.
### Article 25
Second-level internal control and internal audit must ensure that:
- the organization and means implemented effectively favor good management, proper functioning, and security of the information system. To this end:
- information systems must be organized in an orderly and effective manner, based on maps of applications, systems, and networks, also taking into account cyber risks;
- new projects or equipment must be deployed on time, according to defined budgets and satisfy user needs;
- the operation of the information system must take place under satisfactory availability conditions and incidents minimized;
- information systems must be certified as compliant with the IT security reference framework, at least every three (3) years;
- the existing business continuity framework allows the continuation of activity under satisfactory conditions for users;
- the information system produces reliable data facilitating adequate risk steering.
### Article 26
---
Information security is ensured by an IT security officer, a role dedicated and independent of the one responsible for the operational management of the information system. In cases where the size of the regulated establishment does not justify the appointment of a dedicated information security officer, the risk management function assumes this role.
---
BANQUE CENTRALE DU CONGO
The IT security officer ensures that IT security issues are properly addressed and organized within the regulated establishment and that they give rise to the issuance of internal rules whose implementation he supervises. Changes to the information system, notably projects, the use of new techniques, and outsourcing, are systematically subject to security analyses submitted to him, also considering the cyber dimension.
Furthermore, he must ensure that:
- the hardware equipment of the information system is adequately protected against physical and logical risks of intrusion or destruction;
- access management and user authentication of the information system are controlled;
- data are protected in terms of confidentiality through protection solutions based on their level of sensitivity;
- detection mechanisms used to identify abnormal actions on systems and data are in place to detect potential internal or external fraud activities;
- technological monitoring through continuous learning, particularly regarding cybersecurity, is followed by the deliberative body and the executive body.
### Article 27:
Regulated establishments are required to participate in the consultation and anti-cybercrime committee affecting financial institutions.
## TITLE II: FUNCTIONAL COMPONENTS OF INTERNAL CONTROL
### Article 28:
The internal control system consists of three complementary, non-exclusive functions, as follows:
1. first-level permanent control ensured by operational staff themselves;
2. second-level permanent control ensured, retrospectively and on a recurring basis, by dedicated teams for compliance control and quality control of the implementation of operational processes, which do not exercise operational functions.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
```markdown
BANQUE CENTRALE DU CONGO
This control is composed of the following three functions:
- the function of permanent control of operational activities;
- the compliance function;
- the risk management function.
3. third-level control performed periodically, under the responsibility of the deliberative body through its Audit Committee, by an independent internal audit function intervening on documents or on-site within the framework of missions.
Article 29:
Regulated establishments ensure a strict separation of control functions at the first, second, and third levels.
Within the second-level control, they ensure a strict separation between the compliance, permanent control of operational activities, and risk management functions.
When the size of the regulated establishment does not allow entrusting the responsibility of some of these functions to different persons, regulated establishments request prior authorization from the Central Bank of Congo, in accordance with regulatory provisions regarding approval and authorization.
First-level permanent control may, in no case, be merged with another level of control.
Article 30:
The functions of head of second-level permanent control in its three components and those of head of third-level periodic control must be entrusted to senior management executives, presenting all guarantees of morality, honorability, competence, and professional experience.
Their hierarchical position in the organizational chart of regulated establishments must confer upon them the necessary authority to issue an independent opinion vis-à-vis operational departments.
Heads of permanent control of operational activities, compliance, risk management, and internal audit must hold a hierarchical rank immediately below general management.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO
CHAPTER I: FIRST-LEVEL PERMANENT CONTROL
Article 31:
Regulated establishments are required to set up a first-level control function in each operational unit, responsible for ensuring the daily processing of operations according to principles and procedures defined by hierarchy, and notably guaranteeing the separation of sensitive functions and respect for the establishment's risk-taking policy.
Article 32:
First-level controls are performed by:
- hierarchical managers, primarily;
- distinct operational staff, where applicable, in the form of cross-checks;
- operational teams themselves, within the framework of their usual activities to ensure traceability of their actions;
- automated features provided for this purpose in the information systems for processing operations.
In each of these types of organization, control processes are organized to ensure the separation of sensitive functions, under the conditions stated in Article 37.
Traceability of first-level controls must be ensured.
CHAPTER II: SECOND-LEVEL PERMANENT CONTROL
Section I: Second-level control of operational activity
Article 33:
The second-level permanent control device of regulated establishments is organized into three functions with different missions, namely:
- second-level control of operational activity;
- the compliance function;
- the risk management function.
In small regulated establishments, some of these functions may be grouped and entrusted to single managers under the conditions provided in this Instruction and regulatory provisions regarding approvals and authorizations.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO
Article 34:
Regulated establishments are required, according to modalities adapted to their size, risk profile, and nature of their activities, to have staff performing second-level permanent controls on all operational activities and independently from the units ensuring the processing of these activities.
• Organization
Article 35:
The second-level control function of operational activity is entrusted to a senior manager hierarchically attached to the executive body and benefiting from a strengthened functional link with the deliberative body.
Article 36:
The manager and staff of the second-level control function of operational activity must have appropriate expertise to control all activities. They report on controls performed using formalized reporting states, auditable by third-level periodic control or by the Central Bank of Congo.
Article 37:
Regulated establishments belonging to a group may outsource within the same group and entrust to centralized shared functions components of second-level permanent control, with the exception of the compliance function.
However, such outsourcing must meet the following conditions:
- it can only occur after prior agreement of the Central Bank of Congo under conditions defined by regulatory provisions regarding approval and authorization;
- no component of the second-level permanent control function can be entrusted or subcontracted to an entity outside the group of affiliation. Furthermore, within the group of affiliation, control functions must necessarily be entrusted to banking entities, which must be subject to the prudential supervisory authority of their country of establishment under conditions equivalent to those applicable in the Democratic Republic of Congo;
- each of the entities entrusted with part of the second-level permanent control functions, in matrix organization schemes, must present all guarantees of independence from the operational units they control;
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
# BANQUE CENTRALE DU CONGO
## CONTINUED, PAGE 16
- the configuration and functional testing of the information systems for monitoring the regulated establishment's operations must be performed under the control of its executive body, taking into account its risk profile. The control program established based on this profile with the assistance of the executive body must be formalized and approved by the deliberative body of the regulated establishment;
- a review of the results of all controls performed by external entities responsible for second-level permanent control is performed at a close frequency that cannot exceed one month. All these results must be available on-site in an exploitable form to be made available, if necessary, to the Central Bank of Congo;
- the regulated establishment must have on-site all documentation, procedures, and justifications of configurations related to the organization of second-level permanent control concerning it. All this documentation must be written in French;
- direct and unrestricted access to external heads of second-level permanent control must be ensured and organized by the regulated establishment upon simple request of the Central Bank of Congo under modalities defined by the latter.
In the event of outsourcing a component of second-level permanent control, responsibility for it remains fully assumed by the deliberative body and the executive body of the regulated establishment, each regarding their own part, or failing that, by a locally designated internal control manager approved by the Central Bank of Congo under conditions provided by regulatory provisions regarding approvals and authorizations.
### Approval
**Article 38:**
The appointment of the head of second-level control of operational activity is subject to prior approval by the Central Bank of Congo under conditions provided by regulatory provisions regarding approvals and authorizations.
The cessation of their functions must be brought to the knowledge of the Central Bank of Congo under the same conditions.
The head of second-level control of operational activity is appointed by the executive body, after prior agreement of the deliberative body. The latter must also approve, in advance, the determination of their remuneration, their dismissal, or the cessation of their functions.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
---
## CONTINUED, PAGE 17
**Article 39:**
The outsourcing of part of the second-level control of operational activity at the level of the group of affiliation requires prior agreement of the Central Bank of Congo under modalities provided by regulatory provisions regarding approvals and authorizations.
### Missions
**Article 40:**
Second-level control of operational activity ensures the proper execution of first-level permanent controls. In this context, it has at its disposal surveillance tools to ensure that operational units respect activity procedures defined by the deliberative body and implemented by the executive body. It determines a program of recurring controls prioritizing the most sensitive operational processes of the regulated establishment, as provided by the risk map, to ensure the rigor of their execution in accordance with procedures approved by the deliberative body.
The second-level control function of operational activity ensures the proper execution of corrective measures decided following controls performed by it, by third-level periodic control, and, if necessary, by the Central Bank of Congo.
Findings made by second-level control of operational activity are formalized to ensure their traceability and audit. They are communicated to the concerned operational units for correction without delay with a copy to the executive body. Control reports may also recommend general recommendations aimed at improving the quality of operational processes.
**Article 41:**
The head of the second-level control function of operational activity presents the results of their controls to the deliberative body at least twice a year, using adapted summary states.
In the event of persistent non-implementation of corrective actions recommended following their controls, they transmit a special report to the executive body, or directly to the deliberative body, under modalities defined by the regulated establishment.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
---
## CONTINUED, PAGE 18
### Section II: Compliance Control
#### Organization
**Article 42:**
Regulated establishments are required to equip themselves with a compliance control function, responsible for ensuring the compliance of their activities with laws and regulations in force, notably those relating to the fight against money laundering and terrorist financing and the proliferation of weapons, as well as to the rules of ethics and deontology defined by the deliberative body. These rules must be formalized in an ethics charter or code of deontology disseminated to all personnel and members of corporate bodies.
**Article 43:**
The compliance control function must meet the following conditions:
- be directly attached to the executive body;
- have a strengthened functional link with the deliberative body. This link is exercised directly or through the ethics and compliance committee, emanating from the deliberative body, constituted and operating under conditions provided in this Instruction and by regulatory provisions regarding corporate governance;
- coordinate the management of non-compliance risk within the regulated establishment;
- be independent of operational units and exclusive of the exercise of any other function within the regulated establishment.
When the regulated establishment is small and its risk profile justifies it, the head of second-level risk management control, subject to the agreement of the Central Bank of Congo, may assume responsibility for the compliance control function.
Outsourcing the responsibility of the compliance function to a third party is not authorized; however, the regulated establishment may resort to expertise or technical means provided by a third-party entity. It may establish, if necessary, a functional link with the compliance control function of the group to which it belongs, subject to prior agreement of the Central Bank of Congo.
The manager and staff in charge of the compliance control function must possess a high level of competence in the field of banking and financial activities and an in-depth knowledge of rules and standards in force.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO
CONTINUED, PAGE
## Article 44:
Within the framework of the compliance function, the deliberative body has the role notably of:
- determining the principles of the compliance policy to which the regulated establishment must adhere in the exercise of its activities;
- appointing members of the ethics and compliance committee;
- ensuring the implementation, by the executive body, of a compliance control function and promoting the adherence of all personnel, at all levels of the organization, to compliance within the regulated establishment;
- approving the compliance policy and charter, the ethics policy and charter, the principles and code of deontology established by the executive body;
- annually evaluating the management of non-compliance risk of the regulated establishment, based on specific reports established by the executive body.
## Article 45:
The ethics and compliance committee is composed of at least three administrators not belonging to the audit committee. It meets at least three times a year.
The president of the ethics and compliance committee cannot hold this function concurrently with that of the audit committee or the risk committee, except in the case of merger with the latter.
The ethics and compliance committee has the role notably of:
- supervising and controlling the compliance control function;
- ensuring the compliance of the regulated establishment's activities with the legislative, regulatory, and administrative framework in force;
- examining correspondence exchanges between the regulated establishment and supervisory authorities;
- issuing opinions on the draft code of deontology of the regulated establishment, as well as any other document concerning the ethics and compliance policy elaborated by the executive body;
- examining reports of internal controls performed to ensure the proper execution of the aforementioned policy;
- examining alerts exercised by personnel using their right to alert in matters of compliance, as well as reports produced by the compliance control function;
- giving prior opinion for any project of exercising activities abroad and the implementation of new products.
---
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe
Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
---
More like this from BCC
We email you every new BCC publication the day it's published.