2023-12-28

Added · Updated

Instruction No. 26/GR/2023 on Internal Control and Risk Management Systems in Credit Institutions

The Central Bank of Mauritania mandates credit institutions to establish a comprehensive internal control and risk management framework comprising three lines of defense, distinct compliance and risk management functions, and periodic internal audit. The regulation defines key risk categories including credit, market, liquidity, operational, legal, concentration, systemic, leverage, and climate-related risks, while requiring specific organizational independence, reporting lines to the Board of Directors, and adherence to anti-money laundering standards. It further stipulates requirements for documentation, accounting organization, outsourcing of essential services, and reporting obligations to the regulator.

Banque Centrale de Mauritanie logo

Mauritania

Banque Centrale de Mauritanie

Click to view thumbnail

Islamic Republic of Mauritania République Islamique de Mauritanie

The Governor Le Gouverneur

Central Bank of Mauritania BANQUE CENTRALE DE MAURITANIE

Nouakchott, 21 DEC 2023

Instruction No. 26/GR/2023 On Internal Control and Risk Management Systems Within Credit Institutions

The Governor of the Central Bank of Mauritania

  • having regard to Law No. 73-118 of May 30, 1973, establishing the Central Bank of Mauritania,
  • having regard to Law No. 2018-034 of August 8, 2018, on the statutes of the Central Bank of Mauritania,
  • having regard to Law No. 2018-36bis of August 16, 2018, on the regulation of credit institutions,
  • having regard to Decree No. 041/2022 dated March 31, 2022, appointing the Governor of the Central Bank of Mauritania;
  • having regard to Law No. 2019-017 of February 20, 2019, on the fight against money laundering and terrorist financing,
  • having regard to Decree No. 2019-197/PM/MJ of October 23, 2019, implementing Law No. 2019-017 of February 20, 2019, on the fight against money laundering and terrorist financing,
  • having regard to Instruction No. 01/GR/2022 of March 31, 2022, on governance within banks,
  • Having regard to the deliberations of the Prudential, Resolution and Financial Stability Council dated November 24, 2023,

Decides,

Article 1: This Instruction aims to establish the internal control and risk management system that credit institutions must implement in application of Articles 7, 53 and 65 of Law No. 2018-36 bis of August 16, 2018, on the regulation of credit institutions, referred to in this text as the "banking law". The notion of credit institution is defined by Article 1 of the banking law.

Article 2: This Instruction defines the provisions applicable to the following areas:

I Organization of Internal Control II Documentation and Information System III Compliance Function IV Anti-Money Laundering and Counter-Terrorist Financing System V Risk Monitoring System VI Accounting Organization and Processing VII Outsourcing of Activities and Services VIII Obligations vis-à-vis the Central Bank of Mauritania

Article 2: For the application of this Instruction and the regulatory texts taken for its application, the following terms shall be understood as:

  • Effective Managers: persons who, in accordance with Article 58 of Instruction No. 01/GR/2022 on bank governance, ensure the effective management of the credit institution;
  • Credit Operations: all operations mentioned in Article 3, paragraphs 2 and 3 of the banking law;
  • Compliance Function: second-level internal control function responsible for the permanent monitoring of compliance;
  • Risk Management Function: second-level internal control function responsible for the permanent monitoring of risks;
  • Credit Risk: the risk incurred in the event of default by a counterparty or counterparties considered as the same group of related clients;
  • Market and Exchange Risks: interest rate risk, exchange rate risk, risk on stock markets or commodity markets, volatility risk;
  • Overall Interest Rate Risk or Interest Rate Risk on the Banking Portfolio: the risk incurred due to changes in interest rates resulting from all balance sheet and off-balance sheet operations, excluding, where applicable, operations subject to market and exchange risks;
  • Liquidity Risk: the risk for the credit institution not being able to meet its commitments at maturity, not being able to respond to depositor withdrawal requests, or not being able to unwind or offset a position due to market conditions or idiosyncratic factors, within a determined timeframe and at a reasonable cost; the transformation risk results from the mismatch between the maturity of assets and that of medium and long-term liabilities;
  • Operational Risk: the risk of losses arising from inadequate or failed internal processes, people and systems or from external events, including legal risk. Operational risk notably includes risks related to low-probability but high-impact events and internal and external fraud risks. It also includes IT risks and covers all activities of the credit institution, including payment services;
  • Legal Risk: the risk of any dispute with a counterparty, resulting from any imprecision, gap or insufficiency attributable to the credit institution in respect of its operations;
  • Maximum Potential Loss: the measure of the most adverse impact on results of changes in market conditions occurring over a given period and with a determined probability level;
  • Intermediation Risk: the risk of default by an order giver or counterparty during a transaction on financial instruments in which the credit institution provides its guarantee of good performance;
  • Business Continuity and Emergency Plan: a set of measures aimed at ensuring, under various crisis scenarios, including extreme shocks, the maintenance, where applicable, temporarily in a degraded mode, of service provision or other essential or important operational tasks of the credit institution, followed by the planned resumption of activities and limiting its losses;
  • Payment Means: payment means as defined in Article 3, paragraph 6 of the banking law;
  • Compliance Risk: the risk of judicial, administrative or disciplinary sanction, significant financial loss or reputational damage, arising from non-compliance with provisions specific to banking and financial activities, whether of a legislative or regulatory nature directly applicable, or whether they are professional and ethical standards, or instructions from effective managers taken notably in application of board of directors' guidelines;
  • Outsourced Activities: activities for which the credit institution entrusts to a third party, on a durable and habitual basis, the provision of services or other essential or important operational tasks through subcontracting;
  • Essential or Important Service Provision: any service provision or other operational tasks when an anomaly or failure in their exercise is likely to seriously harm the credit institution's ability to permanently comply with the conditions and obligations of its authorization and those related to the exercise of its activity, its financial performance or the continuity of its services and activities. Without prejudice to the assessment of any other task, the following tasks are not considered as essential or important service provisions: the provision to the credit institution of consulting services and other services not covered by its authorization and the purchase of standard services;
  • Concentration Risk: the risk arising from exposure to a counterparty or counterparties considered as the same group of related clients, to counterparties operating in the same economic sector or the same geographic zone, or to the granting of credits relating to the same activity;
  • Systemic Risk: risk of disturbance to the financial system likely to have serious repercussions on the financial system and the real economy;
  • Systemic Institution: a credit institution recognized as presenting a systemic risk;
  • Excessive Leverage Risk: risk of vulnerability of a credit institution, resulting from leverage or potential leverage that may require corrective measures not provided for in the business plan, including emergency sale of assets that could result in losses or revaluation of remaining assets;
  • Internal Audit Committee: technical committee of the Board of Directors, whose attributes are fixed by the Central Bank of Mauritania (Article 57 of the banking law), mentioned in Articles 33, 36, 42 to 44 of Instruction No. 01/GR/2022 on bank governance;
  • Risk Committee: technical committee of the Board of Directors mentioned in Articles 3, 33, 45, 46 and 47 of Instruction No. 01/GR/2022 on bank governance;
  • Nomination Committee: technical committee of the Board of Directors mentioned in Articles 18 and 37 of Instruction No. 01/GR/2022 on bank governance;
  • Remuneration Committee: technical committee of the Board of Directors mentioned in Articles 24 and 37 of Instruction No. 01/GR/2022 on bank governance;
  • Internal Sharia Compliance Committees: internal committees mentioned in Article 34 of the banking law;
  • Operational or Security Incident: an unexpected event or series of events that degrades or may degrade the proper functioning or security of the information system;
  • Risk Appetite: the overall level and types of risk that a credit institution is willing to accept to achieve its strategic objectives, which can be detailed in a business plan, in line with its equity level, its control and risk management capabilities, and the prudential and regulatory constraints to which it is subject;
  • Aggregation of Risk Data: the definition, collection and processing of risk data enabling credit institutions to measure their exposures and results with regard to their risk appetite;
  • Climate and Environmental Risks, so-called "Climate Risks": transition climate risks and physical climate risks;
  • Transition Climate Risks: risks related to financial losses caused, directly or indirectly, by the transition to an economy in line with international climate guidelines. They may stem, for example, from the rapid adoption of climate policies unfavorable to certain sectors of activity (fossil energy, transport...) or from the acceleration of technological progress;
  • Physical Climate Risks: financial risks related to the physical effects of climate change. These effects can be direct, for example damage to real estate assets or a drop in productivity, or indirect, such as disruption of supply chains;
  • Information System: the set of computer assets and data, as well as human resources enabling the processing of information of a credit institution;
  • IT Service: service provided by means of computer assets to internal or external users. An IT service notably includes the entry, processing, exchange, storage or destruction of data in order to carry out, support or monitor activities;
  • IT Risk: risk of loss resulting from inadequacy or failure affecting the organization, functioning, change or security of the information system. IT risk is an operational risk;
  • Information System Security: protection of the confidentiality, integrity and availability of data and computer assets, notably to guarantee their authenticity, accountability, responsibility and reliability.

I- Organization of Internal Control

Article 3: Credit institutions must establish a corporate culture that promotes the mastery and control of risks as well as compliance, and develop and maintain a solid and comprehensive internal control system. In this context, the operational services of credit institutions are the first responsible for the management of the risks they incur in the exercise of their activities and must put in place controls aimed at guaranteeing the compliance of their activity with internal and external requirements. Credit institutions must also have internal control functions endowed with appropriate and sufficient authority, stature and access to the Board of Directors and the Management Committee to fulfill their mission, taking into account the risks incurred in a prospective approach.

Article 4: Credit institutions are required to put in place an internal control system under the minimum conditions provided by this Instruction. The responsibility to ensure that the credit institution complies with its obligations under this regulation lies with the Board of Directors (Article 50 of the banking law), with the support of the Internal Audit Committee and the Risk Committee, and with the Management Committee (Article 39 of Instruction No. 01/GR/2022 on bank governance). The internal control system must be adapted, including in terms of staff and resources, to the nature and volume of the activities of credit institutions, the number of their locations and the different types of risks to which they are exposed. It must cover the entire organization, including the responsibilities and tasks of the Board of Directors and the Management Committee, as well as the activities of all business sectors and internal units, including internal control functions, outsourced activities and distribution channels.

Article 5: The internal control system includes:

  • a documentation and information system;
  • a system for controlling operations and internal procedures;
  • a legal and regulatory monitoring system and compliance control;
  • an anti-money laundering and counter-terrorist financing system;
  • systems for measuring, monitoring and controlling risks;
  • an accounting and information processing organization;
  • verifying safeguard measures to ensure business continuity in case of crisis;
  • ensuring in all cases that corrective measures required by the Central Bank of Mauritania, the Board of Directors or the effective managers of the credit institution are put in place and executed within a reasonable timeframe to reduce risks;
  • ensuring that the internal control system covers outsourced activities and subsidiaries in Mauritania or abroad;
  • verifying compliance with provisions relating to remuneration policies and practices, and general remuneration principles defined by the Board of Directors or, where applicable, competent general meetings;
  • contributing, for concerned operations, to compliance with Sharia.

Article 6: Internal control is organized into three levels of control which constitute as many lines of defense:

  1. the first level of control consisting of persons who ensure the day-to-day validation of risky operations and hierarchical control of activities and operations within operational services, with a frequency proportional to the risks incurred;
  2. the second level of control, consisting of (i) permanent second-level control, (ii) the compliance control function and (iii) the risk management function;
  3. the third level of periodic control of the compliance of operations, the level of risks actually incurred, the respect of procedures, the effectiveness and appropriateness of permanent control devices through investigations at central and local levels.

Article 7: For the control and validation of risky operations referred to in Article 6-1, the organization adopted by the credit institution must be designed to ensure strict independence between, on the one hand, the units responsible for the commitment of operations and, on the other hand, the units responsible for their validation, notably accounting, and their settlement. This independence must be ensured by a clear separation of functions, by procedures, notably IT, designed for this purpose, as well as by different hierarchical reporting of the units. Areas that present potential conflicts of interest or risks of overlap of competencies or responsibilities must be identified, circumscribed to the minimum, subject to continuous monitoring and regular evaluation. The remuneration of agents of units responsible for the validation of operations and controls of the second and third levels is set independently from that of the businesses whose operations they validate or verify, and at a sufficient level to have qualified and experienced personnel.

Article 8: Persons assigned to permanent control, the compliance function and the risk management function and periodic control, as well as their hierarchical managers, must not carry out any commercial, financial or accounting operations.

Article 9: Permanent controls carried out under Article 6-2 must follow a defined program, at a predetermined frequency, specifying what the different verification points are, the methods of implementation and reporting of the results of these controls. Credit institutions regularly ensure that the permanent control program covers all areas of activity and risk zones. They keep up to date a document on the credit institution's risk map specifying the measured or estimated degree of risks. The checks carried out are formalized so that they can be examined by the periodic control function, statutory auditors, external auditors and the Central Bank of Mauritania.

Article 10: For units responsible for risk management, compliance and permanent control functions, the organization of the credit institution must also be designed to ensure strict independence of these units from the operational units they are responsible for controlling. The heads of second-level permanent control, compliance control, periodic control and risk management functions are hierarchically attached to the effective managers of the credit institution and functionally to its Board of Directors. Due to the size of the credit institution and the nature of its activities, the responsibilities of second-level permanent control and compliance may be entrusted to the same person, with the prior agreement of the Central Bank of Mauritania.

Article 11: The head of periodic control, referred to in Article 6-3, is responsible for the coherence and effectiveness of said control. He is appointed after agreement of the Internal Audit Committee. The head of periodic control reports on each mission to the Management Committee and presents the results of his missions to the Internal Audit Committee and the Board of Directors at a frequency that cannot exceed six months. The responsibility for second-level permanent control and periodic control cannot be entrusted to the same person. Periodic control implements a methodology based on the identification and measurement of significant risks of the credit institution to develop a periodic control program. This must be defined according to a multi-year plan, which cannot exceed three years, and cover all areas of activity and functions of the credit institution. It must be submitted to the Internal Audit Committee and validated by the Board of Directors; its execution is monitored by the Management Committee and reported to the Internal Audit Committee and the Board of Directors. The periodic control function must have sufficient resources, be informed diligently of major changes made by the credit institution to its risk management strategy, its processes and its policies. Outsourced activities, and notably important and essential service provisions, must be included in the scope of intervention of periodic control. Reports established following periodic controls give rise to recommendations to be implemented by the audited units, where applicable after decision by the effective managers; their follow-up must be ensured by the periodic control function which must report to the effective managers and the Internal Audit Committee. The Internal Audit Committee verifies the execution of corrective measures within a reasonable timeframe. The Board of Directors is informed at least twice a year of the recommendations issued and their implementation. The head of periodic control must be able to directly and of his own initiative inform the Risk Committee or the Internal Audit Committee and, where applicable, the Board of Directors, of the non-execution of decided corrective measures. Agents in charge of periodic control exercise their mission in total independence from the services they control. They can contact any member of staff and access any information they deem useful for the proper conduct of their mission. When the size of the credit institution does not justify the establishment of a periodic control system, missions may be entrusted to an external auditor after prior agreement of the Central Bank of Mauritania.

Article 12: The Internal Audit Committee must formulate an opinion on the compliance of the internal control organization with regard to Articles 4 to 11 of this Instruction before this organization or any modification of this organization is validated by the Board of Directors.

II- Documentation and Information System

Article 13. Credit institutions must have adequate information systems (both in normal times and in crisis periods) to measure, assess, and report on the size, composition, and quality of exposures at the credit institution level, for all types of risks described in Section 5 of this Instruction.

In particular, these systems must allow for the regular monitoring of operational risk profiles and significant operational exposures, as well as the aggregation and analysis of data relating to operational risk events, including internal loss data.

Risk reports from information systems must reflect the credit institution's risk profile, compliance with set limits and risk appetite, its capital and liquidity needs, and must be provided in a timely manner to the Board of Directors and senior management, in a format suitable for their use.

Credit institutions must develop and maintain appropriate capabilities for aggregating risk data and reporting, based on their risk profile. The Board of Directors and senior management of credit institutions must review and approve the credit institution's risk data aggregation and reporting framework, and ensure that adequate resources are allocated to it.

Credit institutions must have an internal control charter, including the internal control of the anti-money laundering and counter-terrorist financing framework, which specifies at least:

  • the organization of the internal control framework;
  • the areas of responsibility entrusted to the various committees in charge of internal control and risk monitoring, as well as the composition and meeting frequency of these committees;
  • the information procedures for the internal audit committee;
  • the tools and dashboards put in place within the framework of internal control and risk monitoring;
  • the distribution of different responsibilities among staff regarding internal control and risk monitoring;
  • the resources allocated to the internal control framework, including those defined in Article 6 of this Instruction;
  • how the provisions of Articles 6 to 11 of this Instruction regarding the separation of functions are implemented within the credit institution.

The internal control charter is submitted annually to the internal audit committee after being updated based on the evolution of the credit institution's risk profile and macroeconomic and market conditions. It must include the list of members of the internal audit committee, the risk committee, and the heads of various internal control functions. It is communicated to the Board of Directors for validation, and to the statutory auditors.

Article 14. Senior management is required to periodically assess and control the effectiveness of risk management policies, frameworks, and procedures implemented to comply with this Instruction, and to take appropriate measures to remedy any failures.

The Board of Directors is required to regularly review, with the help of the risk committee, the risk management policies, frameworks, and procedures implemented to comply with this Instruction, to assess their effectiveness, as well as any corrective measures taken in case of failures. To this end, the risk committee communicates, coordinates, and collaborates effectively with the internal audit committee.

Article 15. Credit institutions develop and keep up-to-date formalized procedures relating to their various activities. These documents must in particular describe the methods for recording, processing, and reporting information, accounting schemes, and procedures for committing and validating transactions, the associated risks, and the controls to be performed.

Each service or operational unit must have a manual in which the procedures for carrying out the operations it is responsible for are recorded: these procedures specify in particular the methods for commitment and validation, recording and processing of transactions, as well as the corresponding accounting schemes.

Credit institutions keep up-to-date, under the same conditions, documentation that specifies the means intended to ensure the proper functioning of internal control, including:

  • procedures relating to the security of information and communication systems and to emergency and business continuity plans;
  • a description of the systems for measuring, limiting, and monitoring risks;
  • a description of the system for information, validation, and control of accounting records.

The documentation is organized in such a way as to be made available, upon request, to the management committee, the Board of Directors and its internal audit and risk committees, the statutory auditors, and the Mauritanian Central Bank.

Article 16. Reports established following periodic controls are communicated to the management committee, the internal audit and risk technical committees, and, upon request, to the Board of Directors.

These reports are kept available to the Mauritanian Central Bank, the statutory auditors, and external auditors intervening at the request of the Mauritanian Central Bank.

Article 17. Once a year, credit institutions prepare a report on internal control in accordance with the model provided by the Mauritanian Central Bank. This report is submitted to the internal audit committee and the Board of Directors, which must validate it. This report includes, for the different categories of risks, including money laundering and terrorist financing risks mentioned in this Instruction:

  • a description of actions carried out within the framework of internal control, the results of these actions, any corrective measures that have been implemented, and the lessons learned;
  • an inventory of investigations carried out in application of Article 6 highlighting the main lessons learned and, in particular, the main deficiencies identified, as well as the follow-up of corrective measures taken;
  • a description of significant changes made in the areas of permanent, compliance, and periodic controls during the period under review, in particular to take into account the evolution of activity and risks;
  • a description of the conditions for applying procedures put in place for new activities;
  • a development regarding permanent and periodic controls of subsidiaries established in the Islamic Republic of Mauritania or abroad;
  • the presentation of the main planned actions in the field of control;
  • an annex listing transactions concluded with senior management, members of the Board of Directors, and, where applicable, with major shareholders in accordance with Articles 22 and 23 of the banking law and Articles 63, 64, and 65 of Instruction No. 01/GR/2022 on bank governance.

Article 18. The management committee must regularly report, at least once a semester, to the Board of Directors on the conditions under which the set risk limits are respected.

Article 19. Credit institutions define information procedures, at least quarterly, for the management committee and the risk committee, on the respect of risk limits, in particular when global limits are likely to be reached. The monitoring of compliance with limits is controlled quarterly by the risk committee.

Article 20. For the monitoring of their operations, and in particular for information intended for the management committee, the Board of Directors, and its risk and internal audit committees, credit institutions must develop adapted summary statements. Exceptions to policies, procedures, and limits must be immediately submitted for authorization to hierarchical managers and subject to immediate information of the management committee and the risk committee, and, where applicable, the internal audit committee and the Board of Directors.

Article 21. Once a year, credit institutions prepare a report on the measurement and monitoring of the risks to which they are exposed, in accordance with the model provided by the Mauritanian Central Bank. This report is submitted to the risk committee and the Board of Directors, which must validate it.

This report includes, for the different categories of risks, including money laundering and terrorist financing risks mentioned in this Instruction:

  • the credit institution's risk appetite statement and the presentation of its risk strategy and policy;
  • the list and presentation of significant risks retained by the credit institution;
  • the description of control measures put in place for each of these risks;
  • significant changes made to the organization of the risk control framework during the past fiscal year;
  • dashboards monitoring all risks, detailing the limits put in place, their possible evolution, and the evolution of risk indicators over the year in question, with reference to the results of previous years;
  • limit breaches observed during the year in question or malfunctions observed, the analyses carried out, corrective actions put in place, and their results;
  • risk analyses carried out in the context of implementing changes (new product, new activity, new process, new subsidiary, etc.) and actions put in place to mitigate risks;
  • an annex consisting of the results of the crisis simulation program and the conclusions of the credit institution following the analysis provided for in Article 36 of this Instruction;
  • an annex consisting of the capital adequacy report, as provided for in Article 42 of this Instruction, including in particular the actions taken to follow up on this report;
  • an annex consisting of the liquidity adequacy report, as provided for in Article 42 of this Instruction, including in particular the actions taken to follow up on this report;
  • an annex consisting of emergency funding plans provided for in Article 71 of this Instruction.

Credit institutions must also put in place adequate mechanisms for rapid information of the Mauritanian Central Bank for any event likely to result in a significant increase in their risk exposure likely to have important consequences on their financial situation or to harm the financial stability of the market.

III- Compliance Function

Article 22. Credit institutions designate a head of the compliance function, whose name is communicated to the Mauritanian Central Bank, responsible for ensuring the consistency and effectiveness of non-compliance risk control. He/She must not exercise any operational activity. He/She is appointed by senior management with the concurring opinion of the internal audit committee. He/She reports on his/her activities quarterly to the internal audit committee and semi-annually to the Board of Directors.

Article 23. The compliance function ensures monitoring of legal and regulatory developments in order to adapt, if necessary, the internal organization and procedures. It has sufficient resources to carry out its missions.

Article 24. Credit institutions provide for specific compliance review procedures, including systematic prior approval procedures, including a written opinion from the head of compliance or a person duly authorized by him/her for this purpose, for new products or for significant changes made to existing products. They also provide for a compliance control plan, which defines, according to a predetermined frequency, what the different verification points are, the methods for carrying them out and reporting their results.

Article 25. Procedures provide for the methods for centralizing with the head of the compliance function information relating to any malfunctions in the effective implementation of compliance obligations. They provide for the right for any manager or staff member to raise questions about these possible malfunctions with the compliance officer and the Mauritanian Central Bank.

These procedures are brought to the attention of all staff.

Article 26. Credit institutions put in place procedures to monitor and evaluate the effective implementation of actions aimed at remedying any malfunction in the implementation of compliance obligations.

Credit institutions provide all their staff with training on compliance issues and compliance control procedures, adapted to the operations they perform.

Article 27. Credit institutions put in place a framework to guarantee regular and as frequent as possible monitoring of changes that may occur in the texts applicable to their operations and, as such, immediate information of all concerned members of their staff.

IV- Anti-Money Laundering and Counter-Terrorist Financing Framework

Article 28. Credit institutions put in place an anti-money laundering and counter-terrorist financing organization, internal procedures, an internal control system, and a risk classification in accordance with Law No. 2019-017 of February 20, 2019, relating to the fight against money laundering and terrorist financing, referred to in this text as "AML CFT Law", and Decree No. 2019-197/P.M/M.J/ implementing Law No. 2019-017 of February 20, 2019, relating to the fight against money laundering and terrorist financing, as well as Instruction No. 06/GR/2019 relating to control requirements for the fight against money laundering and terrorist financing.

Article 29. Credit institutions ensure that personnel whose activity is exposed to money laundering and terrorist financing risks are able to show vigilance appropriate to these risks. To this end, credit institutions ensure that the training and information of these persons are adapted to their activities.

Article 30. Credit institutions must ensure that internal control verifies, within the framework of the anti-money laundering and counter-terrorist financing framework, that:

  • the transactions executed by credit institutions, as well as their organization and their anti-money laundering and counter-terrorist financing and asset freezing framework, are in compliance with the internal procedures they have defined and with legal and regulatory provisions, in particular the AML CFT Law, the AML CFT Decree, and the aforementioned Instruction No. 06/GR/2019;
  • the policy mentioned in Article 10 of the AML CFT Decree and defined by the Board of Directors, as well as the decisions and instructions taken for its implementation by senior management, are respected;
  • the quality of information intended for the head of the compliance function in the context of his/her role within the anti-money laundering and counter-terrorist financing framework, to senior management, the Board of Directors, the Mauritanian Central Bank, and the Mauritanian Financial Intelligence Unit is guaranteed;
  • control devices for the compliance of their transactions with local rules on the fight against money laundering and terrorist financing and asset freezing have been put in place by subsidiaries and branches of credit institutions established abroad;
  • the quality of information and communication systems that contribute to the implementation of obligations relating to the fight against money laundering and terrorist financing and asset freezing is ensured.

V- Risk Monitoring Framework

1- General Provisions

Article 31. Credit institutions must have a risk monitoring framework adapted to their risk appetite, systemic importance, size, complexity, and taking into account market and macroeconomic conditions.

It includes in particular a risk appetite statement prepared by the Board of Directors and a risk appetite, explaining the level and type of risks that the credit institution wishes to assume, proposed by the management committee, reviewed and approved by the Board of Directors.

The risk monitoring framework must be broken down for each significant risk, documented by policies and procedures, and must allow for the identification, measurement, control, monitoring, control, or mitigation of risks. Risk management policies must be reviewed at least annually by the Board of Directors, validated by it after any modification related to changes in the credit institution's risk profile, macroeconomic environment, or market conditions. Credit institutions must take their risks, including liquidity risks, into account when setting their rates, measuring their performance, and during the validation process for new products for all their significant activities.

Article 32. The risk monitoring framework of credit institutions must offer a global view of risks, extending to all their business sectors and units, including internal control functions. It must:

  • allow credit institutions to make informed decisions regarding risk-taking;
  • encompass balance sheet and off-balance sheet risks, emerging risks, and climate-related financial risks, reputational, strategic, and support risks for other entities, as well as real and future risks to which credit institutions may be exposed;
  • address all risks incurred by the credit institution, including credit, market, and exchange rate risks, interest rate risks, liquidity risks, concentration risks, operational risks (including IT, legal, compliance, particularly in AML CFT matters, and other financial crimes), climate, and strategic risks;
  • allow for the assessment of the overall adequacy of capital and liquidity with regard to the credit institution's risk appetite and risk profile;
  • ensure the control and monitoring of said risks through a global internal limits framework; this framework includes a regulatory limit, when it exists, an internal limit more stringent than the regulatory limit, and an alert limit itself more stringent than the internal limit;
  • implement an escalation in case of breach of the aforementioned limits: breach of the alert limit, escalation by immediate information to the management committee for action; breach of the internal limit, escalation by immediate information to the Board of Directors for action;
  • include at least the risks specified in Articles 44 to 82 of this Instruction;
  • assess the vulnerability of the credit institution to crisis situations through crisis simulation programs.

Risks must be maintained within the global internal limits approved by the Board of Directors. These limits must be reviewed as necessary and at least once a year, taking into account, in particular, current regulations and the level of the credit institution's net capital.

Article 33. The monitoring of compliance with the limits referred to in Article 32 must be carried out continuously and result in a report addressed to the management committee and the Board of Directors. This report must include an analysis of the reasons motivating any possible breaches, as well as, if necessary, proposals and/or recommendations relating thereto.

Article 34. Credit institutions put in place and update a risk map taking into account internal factors such as the complexity of the organization, the nature of the activities carried out, and the quality of the systems, as well as external factors such as economic conditions and regulatory developments.

Article 35. Credit institutions must identify, monitor, and manage all climate-related financial risks as well as emerging risks that could harm their financial situation, in particular their capital and liquidity resources. They must ensure that their risk appetite and risk monitoring framework take into account all climate-related financial risks and emerging risks to which they are exposed, and establish a reliable approach to identify, measure, monitor, and manage these risks.

Article 36. : The prospective crisis simulation program must be adapted to the systemic importance, size, and complexity of the credit institution. The crisis simulation program must cover, at a minimum, unless the significance of exposures is justified, credit and concentration risk, market and exchange rate risk, interest rate risk in the banking book, liquidity risk, and operational risk. The crisis simulation program of a credit institution must take into account all significant sources of risk and adopt plausible adverse scenarios. Its results must be integrated into the credit institution's decision-making and risk management processes (including emergency arrangements) and into the assessment of its capital and liquidity levels.

In this regard, credit institutions must have reliable, effective, and comprehensive systems and procedures to assess and permanently maintain the amounts, composition, and internal allocation of capital they deem appropriate, taking into account the nature and level of risks to which they are or could be exposed. In particular, these systems and procedures take into account the results of crisis simulation programs to ensure the credit institution's ability to maintain its solvency above regulatory thresholds in the event of a crisis.

Corrective measures are necessary if significant failures are observed in the crisis simulation program or if the results of crisis simulations are not adequately taken into account in the credit institution's decision-making process.

The crisis simulation program must:

  • promote the identification and control of risks at the level of the credit institution;
  • be based on sufficiently severe but plausible assumptions and take into account feedback effects and interactions between risks;
  • benefit from the active participation of the board of directors and senior management; and
  • be appropriately documented as well as regularly maintained and updated.

The crisis simulation program must result in a report communicated to the management committee, the risk committee, and the board of directors.

Article 37. : Credit institutions must regularly review the risk monitoring framework to verify its relevance with regard to the evolution of activity, the market environment, and analysis techniques.

Article 38. : The risk monitoring framework is subject to regular internal control, both permanent and periodic, aimed at ensuring that it remains comprehensive and appropriate and that it is correctly implemented.

2- Risk Management Function

Article 39. : Credit institutions must set up a risk management function responsible in particular for:

  • actively participating in the development of the risk monitoring framework;
  • ensuring the implementation of effective processes for measuring, controlling, and monitoring all risks;
  • identifying and controlling the risks to which the credit institution is exposed;
  • ensuring that the level of risks incurred is compatible with the credit institution's strategic directions, its risk appetite, and the limits mentioned in Article 32 above;
  • identifying and analyzing emerging risks related to changes in the credit institution's environment.

The risk management function covers all significant risks, has sufficient material and staffing resources, the necessary authority to fulfill its missions, and access to the board of directors.

Article 40. : The appointment or dismissal of the head of the risk management function, as well as any other change related to this position, must be approved by the board of directors after opinion from the risk committee. The credit institution must inform the Central Bank of Mauritania without delay of the resignation or dismissal of the head of the risk management function and indicate the reason in the event of dismissal.

The head of the risk management function must at all times possess the honorability, knowledge, skills, and experience necessary to perform their duties.

Article 41. : The head of the risk management function must have a sufficiently high hierarchical position to allow them to exercise their function independently. They are hierarchically attached to the senior management of the credit institution and functionally attached to the risk committee and the board of directors.

In the event of risk developments that seriously affect or are likely to seriously affect the credit institution, the head of the risk management function may report directly to the risk committee and the board of directors.

The Central Bank of Mauritania may at any time summon the head of the risk management function to examine any subject related to their missions.

3- Capital and Liquidity Adequacy

Article 42. : Credit institutions must put in place a framework to assess the adequacy of their capital and liquidity with regard to the permanent compliance with their regulatory obligations. In particular, they must assess the amount of capital required based on their risk profile as well as their strategy and business model, permanently maintain a capital level in compliance by taking into account appropriate capital management buffers, prospectively plan this capital level over a period of three [3] years, and assess the level of high-quality liquid assets or other sources of liquidity or financing necessary to meet their regulatory obligations in all circumstances.

The capital adequacy analysis, provided for in Article 64 of the banking law, must be carried out annually and as necessary when needed, cover all risks to which the credit institution is exposed, be prospective over three [3] years, take into account the results of crisis simulation programs, and result in a capital adequacy report communicated to the management committee, the risk committee, and the board of directors.

The liquidity adequacy analysis must be carried out annually and as necessary when needed, cover all risks to which the credit institution is exposed, be prospective over three [3] years, take into account the results of crisis simulation programs, and result in a liquidity adequacy report communicated to the management committee, the risk committee, and the board of directors.

Article 43. : Credit institutions must determine a capital allocation amount for significant risks, taking into account in particular credit and concentration risks, market risks, general interest rate risk, liquidity and transformation risks, operational and legal risks, and climate risks. Credit institutions must define corrective management actions if necessary to ensure the adequacy of their capital over a period of three [3] years.

4- Credit and Concentration Risks

Article 44. : For the purposes of this instruction, credit risk is the risk of loss incurred in the event of default by a counterparty or counterparties considered as the same group of clients. It results in particular from uncertainty regarding the ability or willingness of counterparties or clients to fulfill their obligations. It materializes by (i) the failure by a client or counterparty to meet its financial obligations or (ii) by the deterioration of the credit quality of this client, counterparty, or group as defined by Instruction No. 11/GR/2012.

Article 45. : Credit institutions must have sufficient resources and an adequate credit and concentration risk management process that takes into account, prospectively, their risk appetite, risk profile, market conditions, and macroeconomic factors. This process includes prudent policies and procedures allowing:

  • to identify, measure, evaluate, monitor, report, and control or mitigate credit risks (including counterparty credit risk) and concentration risks;
  • to evaluate, classify, and monitor all credit exposures (including off-balance sheet exposures and restructured exposures);
  • to identify and manage problem assets;
  • to establish provisions, ensure an appropriate and prudent level of provisioning, in accordance with relevant regulatory provisions, and write off problematic exposures whose recovery is unlikely or whose recovery value is very low.

The complete credit lifecycle is covered by the credit risk management framework, including the granting and initial assessment of credit, as well as the continuous management of the credit institution's loan and investment portfolios.

The assessment of default risk, the classification of exposures, and their provisioning are carried out on an individual basis, at least for significant exposures. To this end, institutions set an appropriate threshold for the identification of significant exposures and review it regularly.

In accordance with Article 53 of the banking law, the management committee is assisted by a credit committee in which the head of the risk management function or their representative must participate.

The credit committee must analyze significant commitments and formulate decision proposals to the management committee. It ensures the solvency and good conduct of beneficiaries and ensures that, both in substance and form, the commitments granted respect professional rules. On delegation from the management committee, it may grant credits within the limits approved by the board of directors and report to the management committee.

The head of the risk management function must provide an independent opinion on the commitments studied by the credit committee but does not participate in the granting decision when the credit committee has received a delegation to grant credits. The deliberations and, if applicable, the decisions of the credit committee are recorded in deliberation minutes, and credit institutions maintain an audit trail of commitment decisions available to the Central Bank of Mauritania.

Article 46. : The credit risk management framework must ensure that the risks to which the credit institution may be exposed due to the default of a counterparty are correctly assessed and monitored. It includes a framework for identifying exceptional events and communicating them to the management committee and, if necessary, to the board of directors to initiate remedial actions as soon as possible.

Article 47. : The processes and criteria for assessing credit risk, as well as the responsibilities of persons and bodies authorized to commit the credit institution, must be defined and recorded in writing. They must allow:

  • to approve new exposures by ensuring a thorough understanding of the risk profile and characteristics of borrowers that could have a significant impact on the performance of these exposures;
  • to renew and refinance existing exposures; and
  • to identify the appropriate decision-making authority based on the size and complexity of the exposures.

These rules must be adapted to the characteristics of the credit institution, in particular its size, the nature, and volume of its activities.

Article 48. : Credit institutions must have a credit risk selection procedure and a risk measurement system allowing them in particular:

  • to identify and aggregate all their on-balance sheet and off-balance sheet risks on the same counterparty, group, or sector as defined by Instruction No. 11/GR/2012;
  • to classify commitments by risk level based on qualitative and quantitative information;
  • to apprehend and control concentration risk through documented procedures.

Article 49. : Loan or commitment decision processes, including when organized by delegation, must be clearly formalized and adapted to the characteristics of the credit institution, in particular its size, organization, and the nature of its activity.

Unless, in the case of low-value operations whose limits are set by the general management and approved by the board of directors, credit institutions ensure, including within the framework of delegation procedures, that loan or commitment decisions are taken by at least two people and that credit files are also analyzed by the risk management function.

Article 50. : Credit applications must result in the creation of files containing all quantitative and qualitative information related to the applicant and necessary for file study and decision-making, including accounting documents, asset statements for the last fiscal year, salary or income certificates, or any other document serving as such.

Information must cover both the credit applicant themselves and the entities with which they form a group of related counterparties considered as the same beneficiary, taking into account the legal and financial links and/or the significant degree of dependence existing between them.

Credit files must be regularly monitored and updated, at least annually. Credit institutions must complete these files at least quarterly for counterparties whose receivables are in arrears or who present significant risks or volumes.

Credit files must be securely stored and archived to prevent any risk of fraud.

Article 51. : Credit institutions must put in place a counterparty rating system allowing for relevant differentiation of default risk, regularly review the related methodology, with regard in particular to the performance of this system, and apply this system at least once a year to each of their counterparties. In particular, this system must allow for differentiating, within healthy receivables, the credit quality of counterparties. For retail client exposures, the rating system may be based on automated data processing.

The assigned ratings must be used in the credit granting process, risk management policy, pricing, and internal capital allocation policy.

Article 52. : The assessment of credit risk takes into account in particular the nature of the activities carried out by the applicant, their financial situation, total indebtedness, the asset base of major shareholders or partners, as well as their repayment capacity.

It also takes into account any other information allowing a more complete assessment of the risk, such as the competence of management, the economic environment in which the credit applicant carries out their activity, potential country risk, and proposed guarantees.

Article 53. : Credit granting decisions must take into account their profitability, ensuring that the forecast analysis of direct and indirect charges and revenues is as comprehensive as possible and covers in particular operational and financing costs, the cost corresponding to the beneficiary's default risk during the credit operation, and the cost of remunerating capital.

The management committee must carry out, at least semi-annually, a post-facto analysis of the profitability of credit operations.

Credits granted to the same counterparty (individual client or group of related natural or legal persons presenting a unique risk for the lending institution) must be listed and centralized monthly. Those incurred by sector must also be monthly.

Article 54. : Credits granted to clients benefiting from facilities greater than or equal to 10% of net own funds must be subject to particular quarterly monitoring by the management committee and the risk committee, both on an individual basis and at the group level as defined by Instruction No. 11/GR/2012.

Article 55. : Facilities granted to natural or legal persons related to the credit institution, as defined by Article 23 of the banking law, and granted in accordance with the law and instructions of the Central Bank of Mauritania must be subject to particular monitoring. The credit committee and internal control must ensure compliance with the aforementioned law and instructions. The composition and evolution of balances of this nature must be subject to specific and permanent monitoring by internal control and be brought to the attention of the internal audit committee, the board of directors, and the statutory auditors.

The board of directors must also be informed of any operation likely to generate a conflict between the interests of the credit institution and those of the aforementioned persons. In application of Article 22 of the banking law, it must in particular give its prior approval to any commitment in favor of the aforementioned persons.

Article 56. : Facilities considered as non-performing loans with regard to current regulations must be recorded in the appropriate accounts of the banking chart of accounts and result in the constitution of required provisions and must be managed according to Instruction No. 05/GR/2014.

Provisioning and write-off methods and levels must be subject to an effective review and validation process, controlled by the risk management function.

Credit institutions have adequate and appropriate policies, procedures, and organizational resources for:

  • the review and classification of exposures;
  • the early identification of deteriorating exposures;
  • the permanent monitoring of problem exposures; and
  • the recovery of non-performing loans.

Article 57. : The balances of non-performing loans, as well as the results of amicable or judicial efforts undertaken for their recovery, must be regularly, and at least at the end of each quarter, brought to the attention of the risk committee. The risk committee must also be kept informed of the balances of all restructured receivables and the evolution of their repayment.

Article 58. : Credit institutions must carry out, at least quarterly, an analysis of the evolution of the quality of their commitments. This review must in particular allow determining, for operations of significant importance, any necessary reclassifications within internal categories of credit risk level assessment, as well as allocations to doubtful receivable accounting headings and appropriate provisioning levels. The result of this review, and the accompanying analysis, must be brought to the attention of the risk committee.

Credit institutions must put in place a framework for managing and evaluating collateral and guarantees held against credits. The evaluation of collateral and guarantees reflects their net value, taking into account market conditions and the time necessary for their realization.

The determination of the appropriate provisioning level takes into account guarantees for which credit institutions must ensure effective implementation possibilities, compliance with regulatory conditions provided for by Instruction No. 05/GR/2014 regulating the classification of receivables and the constitution of provisions, as well as the existence of a recent prudent-based evaluation.

The review of commitments results in the preparation of a semi-annual report on credit risks, according to a framework defined by the Central Bank of Mauritania. This report is submitted to the risk committee and the board of directors.

Article 59. : Credit institutions must analyze concentration risks on debtors or groups of debtors, economic and geographical sectors, and put in place appropriate limits.

Article 60. : Credit institutions regularly carry out crisis simulations to assess the vulnerability of their credit portfolio in the event of a downturn or deterioration in the quality of their counterparties, in particular those included in the list of sensitive receivables.

5- Market and Exchange Rate Risks

Article 61. : Market risk is the risk associated with price variations having an impact on assets and liabilities valued at market prices. Exchange rate risk corresponds to the risk incurred by the credit institution in the event of variations in currency exchange rates due to the credit institution's short and long currency positions.

Article 62. : Credit institutions must have systems for monitoring transactions carried out on their own account, including transactions not covered with clients, allowing in particular to:

  • measure the market risks of securities held in the portfolio, and the positions and results generated by these transactions;
  • measure foreign exchange risk, calculate the positions and results related thereto;
  • evaluate the concentration and counterparty risk linked to foreign currency transactions;
  • perform intra-day monitoring of positions, particularly foreign exchange positions;
  • guarantee the accuracy of position calculations. Periodically, credit institutions evaluate the economic results related to operations and activities generating market and foreign exchange risk exposures. When they have significant activity, credit institutions complement these market and foreign exchange risk measures with a global measure of their risk that prioritizes an approach based on the notion of maximum potential loss.

Article 63. : Credit institutions put in place a system of limits for market and foreign exchange risk, at the global level, and if necessary, at a more detailed level. These limits are consistent with current regulations as well as the credit institution's risk appetite and are validated by the board of directors. The level of limits must be appropriate with regard to the financial footprint and take into account the degrees of exposure to other categories of risk. When market and foreign exchange risk is significant, compliance with limits must be subject to daily monitoring.

Article 64. : Credit institutions must establish and monitor exposure limits for foreign exchange risk relative to their net equity according to Instruction No. 07/GR/2023 on banks' foreign exchange positions. These limits are consistent with the credit institution's risk appetite and are validated by the board of directors.

Article 65. : For the management of market and foreign exchange risk, credit institutions put in place:

  • effective information systems allowing to identify, aggregate, monitor and communicate to the management committee and the board of directors, in a precise and timely manner, the exposure to market and foreign exchange risk;
  • monitoring and exception reporting processes that guarantee rapid action at the appropriate level of the management committee or the board of directors of the credit institution, as appropriate.

6- Global Interest Rate Risk

Article 66. : Credit institutions must assess their exposure to global interest rate risk at least once a year. The measurement system must be adapted to the nature of their operations and activities, allowing them in particular:

  • to take into account positions and flows, certain or predictable, resulting from all balance sheet and off-balance sheet operations;
  • to apprehend the different global interest rate risk factors to which these operations expose them;
  • to periodically evaluate the impact of these different factors, when they are significant, on their results and their equity.

Article 67. : Credit institutions set limits for global interest rate risk in line with their risk appetite. The determination of the amount of these limits must take into account different interest rate variation hypotheses, including very unfavorable scenarios with regard to the credit institution's risk profile. For the management of global interest rate risk, credit institutions put in place:

  • effective information systems allowing to identify, aggregate, monitor and communicate to the management committee, the risk committee and the board of directors, in a precise and timely manner, the exposure to risk;
  • monitoring and exception reporting processes that guarantee rapid action at the appropriate level of the management committee or the board of directors of the credit institution, as appropriate.

7- Liquidity and Transformation Risks

Article 68. : Credit institutions must have prudent policies and procedures, validated by the board of directors, consistent with the credit institution's risk appetite, in order to identify, measure, monitor, report and control or mitigate liquidity and transformation risk on a permanent and prospective basis. These policies and procedures must be adapted to the credit institution's risk profile, the nature and volume of its operations, as well as its funding channels. The assumptions underlying decisions related to the management of these risks must be reviewed regularly and take into account the macroeconomic and market context.

Article 69. : Credit institutions must monitor their cash situation on a daily basis and put in place forecast cash flow tables, at different time horizons.

Article 70. : Credit institutions set limits for liquidity and transformation risks. The determination of these limits must take into account different hypotheses. Liquidity crisis situations, in particular, must be taken into account to determine the limit amounts.

Article 71. : Emergency funding plans to address any liquidity crisis must be put in place. Credit institutions must maintain cash and other immediately available assets in order to be able to face a liquidity crisis. They must:

  • analyze their liquidity needs within the framework of alternative scenarios;
  • maintain a buffer of high-quality, unencumbered liquid assets that can be used without hindrance to meet their needs in times of crisis;
  • diversify sources (including counterparties, instruments, currencies and markets) and the duration of funding, as well as regularly review concentration limits on the liability side;
  • obtain, as needed, additional refinancing lines;
  • regularly evaluate their ability to sell assets. Emergency funding plans are an integral part of the annual risk management report provided for in Article 21. Emergency funding plans must be properly documented, set out the credit institution's strategy for addressing liquidity shortfalls for a range of crisis situations, without the credit institution depending on the support of the Central Bank of Mauritania. Emergency funding plans establish clear lines of responsibility, include clear communication plans, including with the Central Bank of Mauritania, and

More like this from BCM

We email you every new BCM publication the day it's published.

Share