2012-02-17
Added · Updated
The Central Bank of Congo establishes prudential rules for internal control and compliance applicable to credit institutions, including banks, specialized financial institutions, financial companies, and savings banks. The instruction mandates that these entities implement an adequate internal control system adapted to their size, activities, and risk profile, defining the specific roles of deliberative bodies, executive bodies, audit committees, and internal audit functions. It further requires robust operational controls, accounting procedures, risk measurement systems, and business continuity plans to ensure financial reliability and regulatory adherence.
(Modification No. 1)
The Central Bank of Congo,
Having regard to Law 005/2002 of May 7, 2002, relating to the constitution, organization, and functioning of the Central Bank of Congo, particularly its Article 6;
Having regard to Law No. 003/2002 of February 2, 2002, relating to the activity and control of Credit Institutions, particularly its Title Three;
Decrees the prudential rules for internal control and compliance applicable to credit institutions.
Article 1 The Credit Institutions subject to this Instruction are:
Article 2 Subject Institutions must equip themselves with an adequate internal control device by adapting all devices covered by this Instruction to the nature and volume of their activities, their size, their locations, and the various types of risks to which they are exposed.
Article 3 For the application of this Instruction, the following terms are understood as: (i) deliberative body (board of directors, supervisory board, or any equivalent body) that ensures the strategic orientation of the institution and the effective supervision of the management of activities on behalf of shareholders. (ii) executive body (Management Committee, General Management, Board of Directors, or any equivalent body) responsible for the day-to-day management of the institution's activities and ensuring the effective steering of the process for achieving the strategic objectives set by the deliberative body. (iii) audit committee, an emanation of the deliberative body created to assist it in the exercise of its missions, particularly the evaluation of the quality of internal control and the assessment of the coherence of systems for identifying, measuring, monitoring, and controlling risks. (iv) compliance function, an independent function charged with monitoring compliance risk, defined as the risk of exposure of an institution to reputational risk, financial losses, or sanctions due to non-compliance with legal and regulatory provisions, standards and practices applicable to its activities, or codes of conduct. (v) business continuity plan, a written and detailed action plan describing, in the event of a major operational disruption, including an external shock, the procedures and systems necessary to maintain or restore within a predetermined time the essential activities and functions of an organization in order to limit the consequences of this disruption for the organization and the financial system as a whole.
Article 4 The internal control system consists of all provisions decided by the deliberative body and implemented by the executive body to ensure that the organization's activities are controlled at all levels. The internal control system consists at minimum of a permanent first-level control in operational units and a final-level control carried out by internal audit.
Article 5 Internal control includes in particular: a. a system for controlling operations and internal procedures; b. an accounting and information processing organization; c. systems for measuring, controlling, and monitoring risks and results; d. a documentation and information system.
Article 6 The internal control system is designed by the executive body and approved by the deliberative body. It includes provisions to ensure:
Chapter 1: Role of the Deliberative Body
Article 7 The deliberative body ensures the implementation and monitoring by the executive body of the internal control system. To this end, it proceeds, at least once a year, to examine the activity and results of internal control based on the information sent to it by the executive body in the forms provided for by this Instruction.
Article 8 The deliberative body is assisted, within the framework of internal control, by an audit committee having in particular the following duties:
Article 9 The audit committee must be chaired by a member of the deliberative body and, furthermore, composed exclusively of persons who do not have management responsibilities in the institution. These persons must have the experience and skills required in the financial and accounting fields as well as in audit activities. The committee reports directly to the deliberative body, which determines its operating procedures and to which it reports. Its role can in no case substitute that of internal audit.
Article 10 The audit committee holds, at least, two meetings per year. It may associate other persons with its work, particularly the head of internal control and the statutory auditors of the institution.
Article 11 The deliberative body clearly delimits the responsibilities of the members of the executive body and defines the terms of delegation of powers.
Article 12 Members of the deliberative and executive bodies ensure the promotion, within their institution, of a strong control culture that particularly emphasizes the necessity for each agent to perform their tasks in respect of the legal and regulatory provisions in force and internal directives and procedures. To this end, they adopt a training and information policy that highlights the institution's objectives and explains the means of achieving them.
Article 13 The deliberative body approves the overall risk management policy as well as the strategic orientations for the management of each risk taken individually.
Chapter 2: Role of the Executive Body
Article 14 The design and implementation of the internal control system fall to the executive body, which, for this purpose:
Article 15 The executive body ensures, on a permanent basis, the overall good functioning of the internal control system and takes the necessary measures to remedy, in a timely manner, any deficiency or insufficiency identified.
Article 16 The executive body develops the internal control manual which specifies in particular:
Chapter 1: General Provisions
Article 17 The system for controlling operations and internal procedures must allow subject institutions to ensure, under optimal conditions of security, reliability, and completeness, in particular:
Article 18 Subject institutions must, according to methods adapted to their size and the nature of their activities, have agents performing permanent or periodic controls. Permanent control of the conformity, security, and validation of operations performed and respect for other duties related to risk monitoring is ensured by agents dedicated to this function or other agents from operational activities. Periodic control of the conformity of operations, the level of risk incurred, respect for procedures, as well as the effectiveness and appropriateness of monitoring and risk management devices is ensured through investigations conducted by internal audit.
Article 19 Each service or operational unit must be equipped with a manual in which the procedures for performing the operations it is charged with carrying out are recorded. These manuals are defined by the executive body and approved by the deliberative body. These procedures fix in particular the terms of engagement, recording, reporting, and processing of operations as well as the corresponding accounting schemes.
Article 20 The levels of authority and responsibility as well as the areas of intervention of the different operational units must be clearly specified and delimited. A strict separation must be established between units charged, each in its own regard, with the initiation, execution, validation, accounting, and control of operations. Areas that present potential conflicts of interest or risks of overlap of competencies or responsibilities must be identified and subject to continuous monitoring, and be subject to regular evaluation with a view to eliminating these conflicts.
Article 21 The terms for executing operations performed daily by operational entities must include appropriate permanent control procedures to ensure the regularity, reliability, and security of these operations as well as respect for other duties related to the monitoring of associated risks.
Chapter 2: Internal Audit Device
Article 22 Subject institutions are required to develop an internal audit charter that defines in particular:
Article 23 The internal audit function ensures comprehensive monitoring of the internal control system and ensures its coherence through the evaluation of the different levels of control within the institution. It is directly attached to the deliberative body, which appoints its head.
Article 24 Internal audit is required to carry out periodic controls. To this end, it:
Article 25 Internal audit is charged with periodically evaluating the effectiveness of risk management processes and governance, internal procedures and policies, as well as the good functioning of the different levels of control. It also evaluates:
Article 26 The head of internal audit reports on the exercise of their mission to the executive body and monitors the implementation of corrective measures that are the subject of their recommendations. They inform the audit committee of identified deficiencies, recommendations formulated to strengthen internal control and risk management devices, and their implementation by the executive body and operational services. They also inform the head of the compliance function, referred to in this Instruction, of any deficiency related to the management of compliance risk.
Chapter 1: Accounting Control Device
Article 27 The accounting control device must allow subject institutions to ensure the reliability and completeness of their accounting and financial data and to ensure the availability of information at the appropriate time.
Article 28 The terms for accounting recording of operations in balance sheet and income statement accounts must provide for a set of procedures, called an audit trail, which allows:
Article 29 The information contained in accounting statements and that necessary for the calculation of management standards and prudential ratios, as well as periodic and prudential declarations intended for the Central Bank of Congo, must respect at least the provisions of the three bullet points of Article 28 of this Instruction.
Article 30 Securities and other values of the same nature held or managed for the account of third parties must be tracked through a physical inventory accounting that records their entries, exits, and holdings and be subject to periodic inventories. A distinction must be made between values received in free deposit and those serving as guarantees in favor of the institution itself or third parties.
Article 31 Subject institutions must ensure the completeness, quality, and reliability of information and evaluation and accounting methods by in particular:
Article 32 Subject institutions determine the level of information security deemed desirable with regard to the requirements of their business. They ensure the level of security retained and that their information systems are adapted. Control of information systems must in particular ensure that:
Article 33 Subject Institutions must:
Chapter 1: General Provisions
Article 34 Companies must put in place systems for analyzing, measuring, and monitoring all types of risks to which their activities expose them and in particular ensure that:
Article 35 Devices for analyzing, measuring, monitoring, and controlling risks and internal overall adequacy of own funds must be adapted to the nature, volume, and degree of complexity of the institution's activities.
Article 36 Institutions have strategies defining their objective in terms of regulatory own funds which must be in adequacy with their risk profile. They put in place reliable, comprehensive, and prospective systems and processes to evaluate and permanently maintain the levels and categories of own funds as well as their allocation considering the nature and level of risks to which they are, or could be, exposed.
Article 37 The systems and processes referred to in this Instruction must be documented and regularly revised. They must allow for periodic reporting to the deliberative and executive bodies on the adequacy of own funds to the risk profile and on any resulting discrepancies.
15 Article 38 The process for assessing the adequacy of regulatory capital must produce reasonable results regarding the capital requirement and the assessment of its adequacy with the establishment's risk profile. Establishments identify and explain the similarities and divergences between their assessments of regulatory capital and regulatory capital requirements.
Article 39 Credit, market, operational, overall interest rate, liquidity, and settlement-delivery risks must be maintained within the overall limits set by current regulations and/or set by the executive body and approved by the deliberative body. However, internally, the establishment may set its limits by the executive body and approved by the deliberative body while respecting the existing regulatory limits. Operational entities may benefit from specific limits which must be established consistently with the various overall limits. These limits are reviewed, as necessary and at least once a year, taking into account, in particular, the level of the establishment's capital.
Article 40 Compliance with the limits covered by this Instruction is checked regularly and unexpectedly and results in the preparation of a report for the attention of the executive and deliberative bodies. This report includes an explanation of breaches as well as the measures taken to remedy them and, if necessary, proposals and recommendations for modifying existing limits.
Article 41 Subject establishments must regularly re-examine their risk measurement systems and limit determination systems to verify their relevance in light of the evolution of activity, the market environment, and analysis techniques.
16 Article 42 The executive body of subject establishments must set up committees responsible for monitoring certain categories of specific risks, notably the credit risk committee, market risk committee, operational risk committee, and asset-liability management committee.
Article 43 Establishments must put in place a system for measuring, controlling, and monitoring risks related to new products and activities. This system must allow, in particular:
Chapter 2: Implementation of risk management and surveillance systems
Article 44 The measurement, control, and monitoring system for each risk must ensure that the risks to which the subject establishment may be exposed are correctly assessed and regularly monitored.
17 Article 45 In application of the provisions of this Instruction and the Instruction of the Central Bank of Congo on risk management and surveillance, subject establishments must implement for each significant risk a system for identifying, analyzing, measuring, monitoring, mitigating, and controlling risks, comprising in particular:
Chapter 3: Business Continuity Plan
Article 46 In application of the Instruction of the Central Bank of Congo on the business continuity plan, establishments must have business continuity plans enabling them to ensure the continuous operation of their essential activities and functions in order to limit losses in the event of major operational disruptions due to external events or related to operational risks. A person responsible for the business continuity plan must be appointed by the management body to ensure the implementation of measures related to this plan.
18 The effectiveness of the latter must be evaluated using tests whose frequency, depth, and detail depend on the importance of the risks related to the elements tested.
Chapter 4: Specific conditions applicable in matters of outsourcing
Article 47 Outsourced activities are those for which the subject establishment entrusts to a third party, on a lasting and habitual basis, the provision of essential service prestations through subcontracting.
Article 48 Subject establishments must ensure that any prestation that substantially contributes to the decision engaging the establishment vis-à-vis its clients to conclude a transaction is outsourced only to persons approved or authorized according to the standards required to exercise such activities.
Article 49 Subject establishments that outsource activities must:
Article 50 Subject establishments that outsource an essential service prestation to their activity must retain full mastery of their activity. They must in particular respect the following provisions: (i) activity outsourcing must:
19
TITLE VI: ON THE DOCUMENTATION AND INFORMATION SYSTEM
Article 51 Subject establishments must draft and keep up to date procedure manuals relating to their various activities. These documents must in particular describe the methods for recording, processing, and reporting information, accounting schemes, and procedures for committing transactions.
Subject establishments must establish, under the same conditions, documentation that specifies the means intended to ensure the proper functioning of internal control, in particular: • the different levels of responsibility; • the attributions assigned and the means allocated to the functioning of internal control devices; • the rules ensuring the independence of these devices under the conditions provided for in Article 20 of this Instruction; • procedures relating to the security of information and communication systems and to business continuity plans; • a description of the systems for measuring, limiting, monitoring, and controlling risks; • the organization method of the compliance control device; The documentation is organized in such a way as to be made available, upon request, to the deliberative body, the executive body, the audit committee, the statutory auditors, and the Central Bank of Congo.
Article 52 Reports established following controls carried out within the framework of the devices referred to in Article 24 of this Instruction are communicated to the executive body and, at its request, to the deliberative body and, if applicable, to the audit committee.
These reports are kept at the disposal of the statutory auditors and the Financial Intermediaries Supervision Department of the Central Bank of Congo.
Article 53 At least twice a year, the deliberative body must examine the activity and results of internal control based on the information transmitted to it for this purpose by the executive body and, if applicable, by the audit committee. When an audit committee exists, this examination may take place only once a year.
21 Article 54 The executive body must regularly inform, at least once a year, the deliberative body and, if applicable, the audit committee: • of the essential elements and main lessons that can be drawn from the monitoring of non-compliance risk and the risk measures to which the subject establishment is exposed; • of the measures taken to ensure business continuity and the assessment of the effectiveness of the devices in place; • of the measures taken to ensure the control of outsourced activities and the potential risks resulting therefrom for the subject establishment. When the deliberative body is not associated with the setting of limits; the executive body informs it and, if applicable, the audit committee, of the decisions taken in this matter. Furthermore, it informs them regularly, at least once a year, of the conditions under which the set limits are respected.
A copy of this report must be sent to the Financial Intermediaries Supervision Department of the Central Bank of Congo, no later than March 31 following the end of the fiscal year.
Article 55 At least once a year, subject establishments are required to prepare a report on the conditions under which internal control is ensured. This report includes in particular: • an inventory of audits carried out highlighting the main lessons and, in particular, the main deficiencies identified as well as a follow-up of corrective measures taken; • a description of significant modifications made in the field of internal control during the period under review, in particular to take into account the evolution of activity and risks; • a description of the conditions for applying the procedures put in place for new activities;
22 • the presentation of the main projected actions in the field of internal control. A copy of this report must be sent to the Financial Intermediaries Supervision Department of the Central Bank of Congo, no later than March 31 following the end of the fiscal year.
Article 56 The person responsible for the business continuity plan must prepare, at least once a year, a report on the business continuity plan which he addresses to the executive body. The latter transmits said report to the deliberative body or to the audit committee. A copy of this report must be sent to the Financial Intermediaries Supervision Department of the Central Bank of Congo, no later than March 31 following the end of the fiscal year.
PART II: COMPLIANCE FUNCTION
Chapter 1: On the object and definition of the compliance function
Article 57 Subject establishments must equip themselves with a "compliance" function. The "Compliance" function is understood to be the independent function responsible for monitoring non-compliance risk, which is defined as the risk of exposure of an establishment to reputational risk, financial losses, or sanctions due to non-observance of legal and regulatory provisions, standards and practices applicable to its activities, or codes of conduct, hereinafter referred to as "current standards".
23 Chapter 2: On the role of the deliberative and executive bodies
Article 58 The deliberative body has the role, in particular, of:
Article 59 The executive body has the missions, in particular, of:
24
Chapter 3: On the organization of the compliance function
Article 60 The organization of the compliance function meets the following conditions:
25 Chapter 4: On the compliance policy
Article 61 The compliance policy must identify in particular the fundamental aspects of non-compliance risk, explain the principles fixed by the deliberative body, define the role and objectives of the "compliance" function, and implement a continuous training program. This policy must also provide for the drafting of a "compliance" charter which:
exposes the objectives of the compliance function, establishes its independence, and defines its responsibilities and competencies;
describes the relations with other functions responsible for risk management and control as well as with the internal audit function;
clearly specifies the reporting lines, relations, and reporting between the various entities involved in the management and control of non-compliance risk, specifying in particular that the responsibility for delegated tasks lies with the "compliance" function;
grants the "compliance" function the right of access to any information necessary for the execution of its missions;
confers on the "compliance" function the right to conduct investigations;
establishes the right to contact the executive body and, if applicable, the deliberative body or members of the audit committee or an ad hoc committee;
defines the modalities and conditions under which this function may resort, if necessary, to external experts.
Chapter 5: On the responsibilities of the "compliance" function
Article 62 The compliance function is responsible for the following aspects: (i) listing of current standards
26 The "compliance" function must list the various "current standards" governing the exercise of the establishment's activities. These standards must be communicated to all concerned personnel.
(ii) identification and assessment of non-compliance risk The "compliance" function must identify the different non-compliance risks incurred by the establishment and proceed to their assessment to determine their importance as well as the consequences resulting therefrom. To this end, it establishes procedures for:
(iii) procedures and instructions for the implementation of the "compliance" policy The "compliance" function ensures that the establishment has standards governing the exercise of daily operations of all its activities. These standards must be an integral part of the instructions, procedures, and internal controls for domains directly related to "compliance". For activities that do not directly fall under "compliance", the "compliance" function is involved and consulted during the preparation and implementation of operational procedures and internal controls.
(iv) verification of respect for the "compliance" policy The "compliance" function must regularly verify compliance with the policy, procedures, and instructions regarding "compliance".
27 It also puts in place procedures and indicators allowing the analysis and monitoring of detected problems as well as recommending corrective measures to be taken to remedy them.
(v) centralization of information on "compliance" problems The "compliance" function must have procedures for centralizing all information on problems and malfunctions identified with respect to "Current Standards". In the case where the establishment belongs to a group of interests, these procedures must cover the modalities for centralizing information emanating from this establishment.
(vi) awareness and training of personnel The establishment must raise awareness among all its personnel regarding the importance of the "compliance" function and ensure their training on "compliance" control procedures related to the operations they perform.
(vii) documentation and internal reporting The "compliance" function must document the work carried out in accordance with assigned responsibilities, in particular to trace interventions as well as observations retained. It reports to the executive body and, if applicable, to the deliberative body or an audit committee or an ad hoc committee, the problems and malfunctions observed at the level of procedures or even at the level of the "compliance" policy as well as the measures taken in this regard. It must also periodically communicate these malfunctions to internal audit.
28 Chapter 6: Control of the "Compliance" Function by Internal Audit Article 63 The activities of the "compliance" function must be included within the scope of internal audit. Internal audit must assess the operation and effectiveness of this function. Internal audit must communicate to the head of the "compliance" function any malfunctions, regarding the risk of non-compliance, identified within the framework of its control missions. Chapter 7: Foreign Establishments Article 64 Establishments must ensure that their subsidiaries and branches abroad put in place a control mechanism for the risk of non-compliance of their operations. This mechanism provides for control procedures for compliance with the "Applicable Standards" of the host country as well as the application of this Instruction. Chapter 8: Information System Article 65 The head of compliance must prepare, at least once a year, a report on their activities which they address to the executive body. The latter transmits said report to the deliberative body or the audit committee. A copy of this report must be sent to the Direction for the Supervision of Financial Intermediaries of the Central Bank of Congo, no later than March 31 following the end of the fiscal year. TITLE VII: TRANSITIONAL AND FINAL PROVISIONS Article 66 Any failure to comply with the provisions of this Instruction leads to the application of sanctions provided for by the legal and regulatory texts in force.
29 Article 67 This Instruction enters into force on January 1, 2010, and annuls all prior provisions contrary to it. Done in Kinshasa, on J-C. MASANGU MULONGO Governor
More like this from BCC
We email you every new BCC publication the day it's published.