2012-02-17

Added · Updated

Instruction No. 17 on Prudential Rules for Internal Control and Compliance (Modification No. 1)

The Central Bank of Congo establishes prudential rules for internal control and compliance applicable to credit institutions, including banks, specialized financial institutions, financial companies, and savings banks. The instruction mandates that these entities implement an adequate internal control system adapted to their size, activities, and risk profile, defining the specific roles of deliberative bodies, executive bodies, audit committees, and internal audit functions. It further requires robust operational controls, accounting procedures, risk measurement systems, and business continuity plans to ensure financial reliability and regulatory adherence.

Banque Centrale du Congo logo

DR Congo

Banque Centrale du Congo

Click to view thumbnail

INSTRUCTION No. 17 TO CREDIT INSTITUTIONS

ON PRUDENTIAL RULES FOR INTERNAL CONTROL AND COMPLIANCE

(Modification No. 1)

The Central Bank of Congo,

Having regard to Law 005/2002 of May 7, 2002, relating to the constitution, organization, and functioning of the Central Bank of Congo, particularly its Article 6;

Having regard to Law No. 003/2002 of February 2, 2002, relating to the activity and control of Credit Institutions, particularly its Title Three;

Decrees the prudential rules for internal control and compliance applicable to credit institutions.

PART I: PRUDENTIAL RULES FOR INTERNAL CONTROL

TITLE I: GENERAL PRINCIPLES

Article 1 The Credit Institutions subject to this Instruction are:

  • banks;
  • specialized financial institutions;
  • financial companies;
  • savings banks.

Article 2 Subject Institutions must equip themselves with an adequate internal control device by adapting all devices covered by this Instruction to the nature and volume of their activities, their size, their locations, and the various types of risks to which they are exposed.

Article 3 For the application of this Instruction, the following terms are understood as: (i) deliberative body (board of directors, supervisory board, or any equivalent body) that ensures the strategic orientation of the institution and the effective supervision of the management of activities on behalf of shareholders. (ii) executive body (Management Committee, General Management, Board of Directors, or any equivalent body) responsible for the day-to-day management of the institution's activities and ensuring the effective steering of the process for achieving the strategic objectives set by the deliberative body. (iii) audit committee, an emanation of the deliberative body created to assist it in the exercise of its missions, particularly the evaluation of the quality of internal control and the assessment of the coherence of systems for identifying, measuring, monitoring, and controlling risks. (iv) compliance function, an independent function charged with monitoring compliance risk, defined as the risk of exposure of an institution to reputational risk, financial losses, or sanctions due to non-compliance with legal and regulatory provisions, standards and practices applicable to its activities, or codes of conduct. (v) business continuity plan, a written and detailed action plan describing, in the event of a major operational disruption, including an external shock, the procedures and systems necessary to maintain or restore within a predetermined time the essential activities and functions of an organization in order to limit the consequences of this disruption for the organization and the financial system as a whole.

Article 4 The internal control system consists of all provisions decided by the deliberative body and implemented by the executive body to ensure that the organization's activities are controlled at all levels. The internal control system consists at minimum of a permanent first-level control in operational units and a final-level control carried out by internal audit.

Article 5 Internal control includes in particular: a. a system for controlling operations and internal procedures; b. an accounting and information processing organization; c. systems for measuring, controlling, and monitoring risks and results; d. a documentation and information system.

TITLE II: DESIGN, IMPLEMENTATION, AND MONITORING OF INTERNAL CONTROL ACTIVITIES

Article 6 The internal control system is designed by the executive body and approved by the deliberative body. It includes provisions to ensure:

  • the verification of operations and internal procedures;
  • the measurement, control, and monitoring of risks;
  • the reliability of the conditions for collecting, processing, disseminating, and retaining accounting and financial data;
  • the effectiveness of internal channels for the circulation of documentation and information as well as their dissemination to third parties.

Chapter 1: Role of the Deliberative Body

Article 7 The deliberative body ensures the implementation and monitoring by the executive body of the internal control system. To this end, it proceeds, at least once a year, to examine the activity and results of internal control based on the information sent to it by the executive body in the forms provided for by this Instruction.

Article 8 The deliberative body is assisted, within the framework of internal control, by an audit committee having in particular the following duties:

  • supervise and control the internal control function;
  • approve the internal audit charter referred to in this Instruction as well as the annual internal control program;
  • ensure complete coverage of the bank's activities by internal controls and external audits;
  • ensure the adequacy of the internal control system to the bank's activities;
  • assess the adequacy of the human and material resources allocated to the internal control function;
  • ensure that internal controllers possess the necessary skills and propose, if necessary, measures to be taken at this level;
  • provide an assessment of the quality of the internal control system, particularly the coherence of risk measurement, monitoring, and control devices, and propose, where appropriate, complementary actions in this regard;
  • define the minimum risk areas that internal controllers and statutory auditors must cover;
  • verify the reliability and accuracy of financial information intended for the deliberative body and third parties, and provide an assessment of the relevance of the accounting methods adopted for the preparation of individual and consolidated accounts;
  • evaluate the relevance of corrective measures taken or proposed to address gaps or deficiencies identified in the internal control system;
  • recommend the choice of the bank's statutory auditors and external auditors, and supervise their relationship with the bank;
  • take note of activity reports and recommendations from the internal control function, statutory auditors, external auditors, and the supervisory authority, as well as the corrective measures taken.

Article 9 The audit committee must be chaired by a member of the deliberative body and, furthermore, composed exclusively of persons who do not have management responsibilities in the institution. These persons must have the experience and skills required in the financial and accounting fields as well as in audit activities. The committee reports directly to the deliberative body, which determines its operating procedures and to which it reports. Its role can in no case substitute that of internal audit.

Article 10 The audit committee holds, at least, two meetings per year. It may associate other persons with its work, particularly the head of internal control and the statutory auditors of the institution.

Article 11 The deliberative body clearly delimits the responsibilities of the members of the executive body and defines the terms of delegation of powers.

Article 12 Members of the deliberative and executive bodies ensure the promotion, within their institution, of a strong control culture that particularly emphasizes the necessity for each agent to perform their tasks in respect of the legal and regulatory provisions in force and internal directives and procedures. To this end, they adopt a training and information policy that highlights the institution's objectives and explains the means of achieving them.

Article 13 The deliberative body approves the overall risk management policy as well as the strategic orientations for the management of each risk taken individually.

Chapter 2: Role of the Executive Body

Article 14 The design and implementation of the internal control system fall to the executive body, which, for this purpose:

  • establishes the appropriate organizational structure and provides the necessary human and material resources for the implementation of the internal control system;
  • identifies all sources of internal and external risks;
  • defines adequate internal control procedures.

Article 15 The executive body ensures, on a permanent basis, the overall good functioning of the internal control system and takes the necessary measures to remedy, in a timely manner, any deficiency or insufficiency identified.

Article 16 The executive body develops the internal control manual which specifies in particular:

  • the constituent elements of each device and the means of their implementation (internal control procedures, internal control tools...);
  • the rules ensuring the independence of control devices from operational units;
  • the different levels of responsibility for control. This manual, approved by the deliberative body, is subject to periodic examination in order to adapt its provisions to legal and regulatory requirements as well as to the evolution of the institution's activity, the economic and financial environment, and analysis techniques.

TITLE III: SYSTEM FOR CONTROLLING OPERATIONS AND INTERNAL PROCEDURES

Chapter 1: General Provisions

Article 17 The system for controlling operations and internal procedures must allow subject institutions to ensure, under optimal conditions of security, reliability, and completeness, in particular:

  • the conformity of operations performed, the organization, and internal procedures with the legal and regulatory provisions in force as well as with professional and ethical standards and usages, and the internal instructions of the executive body taken in application of the orientations of the deliberative body;
  • strict respect of decision-making procedures and risk-taking as well as management standards and limits set by the executive body;
  • the quality of accounting and financial information intended for the deliberative body or the executive body, to be transmitted to the Central Bank, or to be published;
  • the conditions for evaluation, recording, retention, and availability of this information, particularly the existence of an audit trail;
  • the quality of information and communication systems.

Article 18 Subject institutions must, according to methods adapted to their size and the nature of their activities, have agents performing permanent or periodic controls. Permanent control of the conformity, security, and validation of operations performed and respect for other duties related to risk monitoring is ensured by agents dedicated to this function or other agents from operational activities. Periodic control of the conformity of operations, the level of risk incurred, respect for procedures, as well as the effectiveness and appropriateness of monitoring and risk management devices is ensured through investigations conducted by internal audit.

Article 19 Each service or operational unit must be equipped with a manual in which the procedures for performing the operations it is charged with carrying out are recorded. These manuals are defined by the executive body and approved by the deliberative body. These procedures fix in particular the terms of engagement, recording, reporting, and processing of operations as well as the corresponding accounting schemes.

Article 20 The levels of authority and responsibility as well as the areas of intervention of the different operational units must be clearly specified and delimited. A strict separation must be established between units charged, each in its own regard, with the initiation, execution, validation, accounting, and control of operations. Areas that present potential conflicts of interest or risks of overlap of competencies or responsibilities must be identified and subject to continuous monitoring, and be subject to regular evaluation with a view to eliminating these conflicts.

Article 21 The terms for executing operations performed daily by operational entities must include appropriate permanent control procedures to ensure the regularity, reliability, and security of these operations as well as respect for other duties related to the monitoring of associated risks.

Chapter 2: Internal Audit Device

Article 22 Subject institutions are required to develop an internal audit charter that defines in particular:

  • the position, powers, and objectives of the internal audit function;
  • the responsibilities of this function and the nature of its work;
  • the terms for communicating the results of its control missions.

Article 23 The internal audit function ensures comprehensive monitoring of the internal control system and ensures its coherence through the evaluation of the different levels of control within the institution. It is directly attached to the deliberative body, which appoints its head.

Article 24 Internal audit is required to carry out periodic controls. To this end, it:

  • relies on a methodology allowing the identification of significant risks incurred by the institution;
  • prepares a multi-year audit plan approved by the audit committee and distributes its resources accordingly;
  • has sufficient resources and staff with appropriate training and the required experience to understand and evaluate the activities to be audited;
  • has access, for the needs of its mission, to archives, files, and data.

Article 25 Internal audit is charged with periodically evaluating the effectiveness of risk management processes and governance, internal procedures and policies, as well as the good functioning of the different levels of control. It also evaluates:

  • the financial communication process and examines the reliability and accuracy of information communicated to third parties;
  • internal models for measuring and monitoring risks;
  • internal procedures for evaluating the adequacy of the institution's own funds;
  • the overall approach to business continuity management within the institution;
  • controls performed by the compliance function.

Article 26 The head of internal audit reports on the exercise of their mission to the executive body and monitors the implementation of corrective measures that are the subject of their recommendations. They inform the audit committee of identified deficiencies, recommendations formulated to strengthen internal control and risk management devices, and their implementation by the executive body and operational services. They also inform the head of the compliance function, referred to in this Instruction, of any deficiency related to the management of compliance risk.

TITLE IV: ACCOUNTING ORGANIZATION AND INFORMATION PROCESSING

Chapter 1: Accounting Control Device

Article 27 The accounting control device must allow subject institutions to ensure the reliability and completeness of their accounting and financial data and to ensure the availability of information at the appropriate time.

Article 28 The terms for accounting recording of operations in balance sheet and income statement accounts must provide for a set of procedures, called an audit trail, which allows:

  • reconstructing operations in chronological order;
  • justifying any information with an original document from which it must be possible to go back in an uninterrupted chain to the summary document and vice versa;
  • explaining the evolution of balances from one closing to another by retaining the movements that affected accounting items.

Article 29 The information contained in accounting statements and that necessary for the calculation of management standards and prudential ratios, as well as periodic and prudential declarations intended for the Central Bank of Congo, must respect at least the provisions of the three bullet points of Article 28 of this Instruction.

Article 30 Securities and other values of the same nature held or managed for the account of third parties must be tracked through a physical inventory accounting that records their entries, exits, and holdings and be subject to periodic inventories. A distinction must be made between values received in free deposit and those serving as guarantees in favor of the institution itself or third parties.

Article 31 Subject institutions must ensure the completeness, quality, and reliability of information and evaluation and accounting methods by in particular:

  • periodic control of the adequacy of the methods and parameters retained for the evaluation of operations;
  • regular evaluations of the accounting information system and information processing with regard to general objectives of prudence and security as well as the conformity of accounting schemes with current rules;
  • for operations involving market risks, a reconciliation, at least at the end-of-month closing date, between the results calculated by operational units and the accounting results obtained based on current evaluation rules. Significant observed discrepancies must be justified and brought to the attention of the executive body.

Article 32 Subject institutions determine the level of information security deemed desirable with regard to the requirements of their business. They ensure the level of security retained and that their information systems are adapted. Control of information systems must in particular ensure that:

  • the security level of computer systems is periodically assessed and, if necessary, corrective actions are taken;
  • computer backup procedures are available to ensure the continuity of operations in the event of serious difficulties in the functioning of computer systems. Control of information systems extends to the retention of information and documentation relating to analyses, programming, and execution of treatments.

Article 33 Subject Institutions must:

  • have business continuity plans;
  • ensure that their organization and the availability of their human, real estate, technical, and financial resources are subject to regular assessment with regard to risks related to business continuity;
  • ensure the coherence and effectiveness of business continuity plans within the framework of a global plan that integrates the objectives defined by the executive body and, if necessary, approved by the deliberative body.

TITLE V: SYSTEM FOR MEASURING, CONTROLLING, AND MONITORING RISKS

Chapter 1: General Provisions

Article 34 Companies must put in place systems for analyzing, measuring, and monitoring all types of risks to which their activities expose them and in particular ensure that:

  • credit, market, operational, interest rate, liquidity, delivery-settlement risks, as well as risks related to outsourced activities, are correctly evaluated and controlled;
  • processes for evaluating the overall adequacy of regulatory own funds with regard to these risks are put in place.

Article 35 Devices for analyzing, measuring, monitoring, and controlling risks and internal overall adequacy of own funds must be adapted to the nature, volume, and degree of complexity of the institution's activities.

Article 36 Institutions have strategies defining their objective in terms of regulatory own funds which must be in adequacy with their risk profile. They put in place reliable, comprehensive, and prospective systems and processes to evaluate and permanently maintain the levels and categories of own funds as well as their allocation considering the nature and level of risks to which they are, or could be, exposed.

Article 37 The systems and processes referred to in this Instruction must be documented and regularly revised. They must allow for periodic reporting to the deliberative and executive bodies on the adequacy of own funds to the risk profile and on any resulting discrepancies.

15 Article 38 The process for assessing the adequacy of regulatory capital must produce reasonable results regarding the capital requirement and the assessment of its adequacy with the establishment's risk profile. Establishments identify and explain the similarities and divergences between their assessments of regulatory capital and regulatory capital requirements.

Article 39 Credit, market, operational, overall interest rate, liquidity, and settlement-delivery risks must be maintained within the overall limits set by current regulations and/or set by the executive body and approved by the deliberative body. However, internally, the establishment may set its limits by the executive body and approved by the deliberative body while respecting the existing regulatory limits. Operational entities may benefit from specific limits which must be established consistently with the various overall limits. These limits are reviewed, as necessary and at least once a year, taking into account, in particular, the level of the establishment's capital.

Article 40 Compliance with the limits covered by this Instruction is checked regularly and unexpectedly and results in the preparation of a report for the attention of the executive and deliberative bodies. This report includes an explanation of breaches as well as the measures taken to remedy them and, if necessary, proposals and recommendations for modifying existing limits.

Article 41 Subject establishments must regularly re-examine their risk measurement systems and limit determination systems to verify their relevance in light of the evolution of activity, the market environment, and analysis techniques.

16 Article 42 The executive body of subject establishments must set up committees responsible for monitoring certain categories of specific risks, notably the credit risk committee, market risk committee, operational risk committee, and asset-liability management committee.

Article 43 Establishments must put in place a system for measuring, controlling, and monitoring risks related to new products and activities. This system must allow, in particular:

  • the approval, by the deliberative body or by a committee created for this purpose, of any new product or new activity involving a significant level of risk that deviates from the previously established risk strategy, as well as the implementation of risk identification procedures;
  • the definition of the conditions required for the design of a new product or the launch of a new activity, in particular its description, the analysis of the impact of the resulting risks on the establishment's activities, the identification of necessary technical and human resources, the listing of authorized counterparties, and the procedures to be used for the management and assessment of associated risks.

Chapter 2: Implementation of risk management and surveillance systems

Article 44 The measurement, control, and monitoring system for each risk must ensure that the risks to which the subject establishment may be exposed are correctly assessed and regularly monitored.

17 Article 45 In application of the provisions of this Instruction and the Instruction of the Central Bank of Congo on risk management and surveillance, subject establishments must implement for each significant risk a system for identifying, analyzing, measuring, monitoring, mitigating, and controlling risks, comprising in particular:

  • the definition of the establishment's policy regarding each risk, formulated by the executive body and approved by the deliberative body;
  • the organization of activities generating this risk, with specific limit procedures;
  • the operational conditions for managing activities generating this risk;
  • risk measurement procedures,
  • risk monitoring procedures;
  • procedures for permanent and periodic risk control;
  • information on risk provided to the deliberative and executive bodies and to the Central Bank of Congo;
  • risk mitigation procedures put in place by the establishment.

Chapter 3: Business Continuity Plan

Article 46 In application of the Instruction of the Central Bank of Congo on the business continuity plan, establishments must have business continuity plans enabling them to ensure the continuous operation of their essential activities and functions in order to limit losses in the event of major operational disruptions due to external events or related to operational risks. A person responsible for the business continuity plan must be appointed by the management body to ensure the implementation of measures related to this plan.

18 The effectiveness of the latter must be evaluated using tests whose frequency, depth, and detail depend on the importance of the risks related to the elements tested.

Chapter 4: Specific conditions applicable in matters of outsourcing

Article 47 Outsourced activities are those for which the subject establishment entrusts to a third party, on a lasting and habitual basis, the provision of essential service prestations through subcontracting.

Article 48 Subject establishments must ensure that any prestation that substantially contributes to the decision engaging the establishment vis-à-vis its clients to conclude a transaction is outsourced only to persons approved or authorized according to the standards required to exercise such activities.

Article 49 Subject establishments that outsource activities must:

  • ensure that their control system includes their outsourced activities;
  • equip themselves with control devices for their outsourced activities.

Article 50 Subject establishments that outsource an essential service prestation to their activity must retain full mastery of their activity. They must in particular respect the following provisions: (i) activity outsourcing must:

  • give rise to a written contract between the external provider and the subject establishment;

19

  • fall within the framework of a formalized policy for controlling external providers defined by the subject establishment. (ii) Subject establishments must ensure, in their relations with their external providers, that the latter:
  • commit to a level of quality responding to the normal functioning of the service and, in the event of an incident, leading to recourse to backup mechanisms;
  • implement backup mechanisms in the event of serious difficulty affecting service continuity or that their own plan takes into account the impossibility for the external provider to provide their service;
  • cannot impose a substantial modification of the services they provide without the prior agreement of the subject establishment;
  • comply with the procedures defined by the subject establishment concerning the organization and implementation of the control of the services they provide;
  • allow them, whenever necessary, access, if appropriate on site, to any information on the services made available to them, in compliance with regulations relating to the communication of information;
  • report regularly on how the outsourced activity is exercised as well as their financial situation.

TITLE VI: ON THE DOCUMENTATION AND INFORMATION SYSTEM

Article 51 Subject establishments must draft and keep up to date procedure manuals relating to their various activities. These documents must in particular describe the methods for recording, processing, and reporting information, accounting schemes, and procedures for committing transactions.

Subject establishments must establish, under the same conditions, documentation that specifies the means intended to ensure the proper functioning of internal control, in particular: • the different levels of responsibility; • the attributions assigned and the means allocated to the functioning of internal control devices; • the rules ensuring the independence of these devices under the conditions provided for in Article 20 of this Instruction; • procedures relating to the security of information and communication systems and to business continuity plans; • a description of the systems for measuring, limiting, monitoring, and controlling risks; • the organization method of the compliance control device; The documentation is organized in such a way as to be made available, upon request, to the deliberative body, the executive body, the audit committee, the statutory auditors, and the Central Bank of Congo.

Article 52 Reports established following controls carried out within the framework of the devices referred to in Article 24 of this Instruction are communicated to the executive body and, at its request, to the deliberative body and, if applicable, to the audit committee.

These reports are kept at the disposal of the statutory auditors and the Financial Intermediaries Supervision Department of the Central Bank of Congo.

Article 53 At least twice a year, the deliberative body must examine the activity and results of internal control based on the information transmitted to it for this purpose by the executive body and, if applicable, by the audit committee. When an audit committee exists, this examination may take place only once a year.

21 Article 54 The executive body must regularly inform, at least once a year, the deliberative body and, if applicable, the audit committee: • of the essential elements and main lessons that can be drawn from the monitoring of non-compliance risk and the risk measures to which the subject establishment is exposed; • of the measures taken to ensure business continuity and the assessment of the effectiveness of the devices in place; • of the measures taken to ensure the control of outsourced activities and the potential risks resulting therefrom for the subject establishment. When the deliberative body is not associated with the setting of limits; the executive body informs it and, if applicable, the audit committee, of the decisions taken in this matter. Furthermore, it informs them regularly, at least once a year, of the conditions under which the set limits are respected.

A copy of this report must be sent to the Financial Intermediaries Supervision Department of the Central Bank of Congo, no later than March 31 following the end of the fiscal year.

Article 55 At least once a year, subject establishments are required to prepare a report on the conditions under which internal control is ensured. This report includes in particular: • an inventory of audits carried out highlighting the main lessons and, in particular, the main deficiencies identified as well as a follow-up of corrective measures taken; • a description of significant modifications made in the field of internal control during the period under review, in particular to take into account the evolution of activity and risks; • a description of the conditions for applying the procedures put in place for new activities;

22 • the presentation of the main projected actions in the field of internal control. A copy of this report must be sent to the Financial Intermediaries Supervision Department of the Central Bank of Congo, no later than March 31 following the end of the fiscal year.

Article 56 The person responsible for the business continuity plan must prepare, at least once a year, a report on the business continuity plan which he addresses to the executive body. The latter transmits said report to the deliberative body or to the audit committee. A copy of this report must be sent to the Financial Intermediaries Supervision Department of the Central Bank of Congo, no later than March 31 following the end of the fiscal year.

PART II: COMPLIANCE FUNCTION

Chapter 1: On the object and definition of the compliance function

Article 57 Subject establishments must equip themselves with a "compliance" function. The "Compliance" function is understood to be the independent function responsible for monitoring non-compliance risk, which is defined as the risk of exposure of an establishment to reputational risk, financial losses, or sanctions due to non-observance of legal and regulatory provisions, standards and practices applicable to its activities, or codes of conduct, hereinafter referred to as "current standards".

23 Chapter 2: On the role of the deliberative and executive bodies

Article 58 The deliberative body has the role, in particular, of:

  • establishing the basic principles of the compliance policy to which the establishment must adhere in the exercise of its activities;
  • ensuring the implementation, by the executive body, of a compliance function and promoting a positive attitude towards compliance;
  • approving the policy and "compliance" charter established by the executive body;
  • annually evaluating the management of non-compliance risk by the establishment, based on specific reporting established by the executive body. This mission may, however, be delegated to the audit committee or to an ad hoc committee attached to the deliberative body.

Article 59 The executive body has the missions, in particular, of:

  • setting up a compliance function and designating its head;
  • drafting the compliance policy and charter and ensuring their implementation;
  • permanently ensuring the adequacy of the "compliance" policy relative to the size of the establishment as well as to the nature, volume, and complexity of its activities. It also verifies the implementation and respect of this policy and takes, without delay, the necessary corrective measures to rectify the deficiencies identified by the "compliance" function or by internal audit;
  • keeping the deliberative body informed on non-compliance risks incurred;

24

  • preparing at least once a year a report, addressed to the deliberative body or the audit committee or an ad hoc committee, on the achievement of the compliance function's objectives, the human and material means implemented for this purpose, the main work of this function, any identified deficiencies, the corrective measures decided upon and their follow-up.

Chapter 3: On the organization of the compliance function

Article 60 The organization of the compliance function meets the following conditions:

  • the compliance function is an structure independent of operational entities and directly attached to the executive body;
  • it ensures the coordination of non-compliance risk management within the establishment;
  • the compliance function must be exclusive of the exercise of any other function within the establishment to avoid any potential conflict of interest;
  • certain tasks related to the responsibilities of the compliance function may be delegated to services, cells, or departments. In this case, the compliance function assumes a coordination role between the entities responsible for executing the tasks resulting from its responsibilities;
  • when the size of the establishment justifies it, the executive body may assume responsibility for the "compliance" function itself;
  • outsourcing the "compliance" function to a third party is not authorized. However, the establishment may resort to the expertise or technical means of third parties. It may establish, if applicable, a functional link with the "compliance" function of the group to which it belongs;
  • persons in charge of the compliance function must possess a high level of competence in the field of banking and financial activities and an in-depth knowledge of current rules and standards.

25 Chapter 4: On the compliance policy

Article 61 The compliance policy must identify in particular the fundamental aspects of non-compliance risk, explain the principles fixed by the deliberative body, define the role and objectives of the "compliance" function, and implement a continuous training program. This policy must also provide for the drafting of a "compliance" charter which:

  • exposes the objectives of the compliance function, establishes its independence, and defines its responsibilities and competencies;

  • describes the relations with other functions responsible for risk management and control as well as with the internal audit function;

  • clearly specifies the reporting lines, relations, and reporting between the various entities involved in the management and control of non-compliance risk, specifying in particular that the responsibility for delegated tasks lies with the "compliance" function;

  • grants the "compliance" function the right of access to any information necessary for the execution of its missions;

  • confers on the "compliance" function the right to conduct investigations;

  • establishes the right to contact the executive body and, if applicable, the deliberative body or members of the audit committee or an ad hoc committee;

  • defines the modalities and conditions under which this function may resort, if necessary, to external experts.

Chapter 5: On the responsibilities of the "compliance" function

Article 62 The compliance function is responsible for the following aspects: (i) listing of current standards

26 The "compliance" function must list the various "current standards" governing the exercise of the establishment's activities. These standards must be communicated to all concerned personnel.

(ii) identification and assessment of non-compliance risk The "compliance" function must identify the different non-compliance risks incurred by the establishment and proceed to their assessment to determine their importance as well as the consequences resulting therefrom. To this end, it establishes procedures for:

  • checking the "compliance" of operations carried out with respect to current rules and standards;
  • identification and measurement of non-compliance risks inherent to any new type of activity, product, clientele, or significant transformation of existing products;
  • permanent monitoring of modifications or changes that may occur in the texts applicable to operations carried out by the establishment.

(iii) procedures and instructions for the implementation of the "compliance" policy The "compliance" function ensures that the establishment has standards governing the exercise of daily operations of all its activities. These standards must be an integral part of the instructions, procedures, and internal controls for domains directly related to "compliance". For activities that do not directly fall under "compliance", the "compliance" function is involved and consulted during the preparation and implementation of operational procedures and internal controls.

(iv) verification of respect for the "compliance" policy The "compliance" function must regularly verify compliance with the policy, procedures, and instructions regarding "compliance".

27 It also puts in place procedures and indicators allowing the analysis and monitoring of detected problems as well as recommending corrective measures to be taken to remedy them.

(v) centralization of information on "compliance" problems The "compliance" function must have procedures for centralizing all information on problems and malfunctions identified with respect to "Current Standards". In the case where the establishment belongs to a group of interests, these procedures must cover the modalities for centralizing information emanating from this establishment.

(vi) awareness and training of personnel The establishment must raise awareness among all its personnel regarding the importance of the "compliance" function and ensure their training on "compliance" control procedures related to the operations they perform.

(vii) documentation and internal reporting The "compliance" function must document the work carried out in accordance with assigned responsibilities, in particular to trace interventions as well as observations retained. It reports to the executive body and, if applicable, to the deliberative body or an audit committee or an ad hoc committee, the problems and malfunctions observed at the level of procedures or even at the level of the "compliance" policy as well as the measures taken in this regard. It must also periodically communicate these malfunctions to internal audit.

28 Chapter 6: Control of the "Compliance" Function by Internal Audit Article 63 The activities of the "compliance" function must be included within the scope of internal audit. Internal audit must assess the operation and effectiveness of this function. Internal audit must communicate to the head of the "compliance" function any malfunctions, regarding the risk of non-compliance, identified within the framework of its control missions. Chapter 7: Foreign Establishments Article 64 Establishments must ensure that their subsidiaries and branches abroad put in place a control mechanism for the risk of non-compliance of their operations. This mechanism provides for control procedures for compliance with the "Applicable Standards" of the host country as well as the application of this Instruction. Chapter 8: Information System Article 65 The head of compliance must prepare, at least once a year, a report on their activities which they address to the executive body. The latter transmits said report to the deliberative body or the audit committee. A copy of this report must be sent to the Direction for the Supervision of Financial Intermediaries of the Central Bank of Congo, no later than March 31 following the end of the fiscal year. TITLE VII: TRANSITIONAL AND FINAL PROVISIONS Article 66 Any failure to comply with the provisions of this Instruction leads to the application of sanctions provided for by the legal and regulatory texts in force.

29 Article 67 This Instruction enters into force on January 1, 2010, and annuls all prior provisions contrary to it. Done in Kinshasa, on J-C. MASANGU MULONGO Governor

More like this from BCC

We email you every new BCC publication the day it's published.

Share