2023-12-28
Added · Updated
The Central Bank of Mauritania mandates credit institutions to establish a comprehensive internal control and risk management framework comprising three lines of defense, distinct compliance and risk management functions, and periodic internal audit. The regulation defines key risk categories including credit, market, liquidity, operational, legal, concentration, systemic, leverage, and climate-related risks, while requiring specific organizational independence, reporting lines to the Board of Directors, and adherence to anti-money laundering standards. It further stipulates requirements for documentation, accounting organization, outsourcing of essential services, and reporting obligations to the regulator.
Islamic Republic of Mauritania République Islamique de Mauritanie
The Governor Le Gouverneur
Central Bank of Mauritania BANQUE CENTRALE DE MAURITANIE
Nouakchott, 21 DEC 2023
Instruction No. 26/GR/2023 On Internal Control and Risk Management Systems Within Credit Institutions
The Governor of the Central Bank of Mauritania
Decides,
Article 1: This Instruction aims to establish the internal control and risk management system that credit institutions must implement in application of Articles 7, 53 and 65 of Law No. 2018-36 bis of August 16, 2018, on the regulation of credit institutions, referred to in this text as the "banking law". The notion of credit institution is defined by Article 1 of the banking law.
Article 2: This Instruction defines the provisions applicable to the following areas:
I Organization of Internal Control II Documentation and Information System III Compliance Function IV Anti-Money Laundering and Counter-Terrorist Financing System V Risk Monitoring System VI Accounting Organization and Processing VII Outsourcing of Activities and Services VIII Obligations vis-à-vis the Central Bank of Mauritania
Article 2: For the application of this Instruction and the regulatory texts taken for its application, the following terms shall be understood as:
I- Organization of Internal Control
Article 3: Credit institutions must establish a corporate culture that promotes the mastery and control of risks as well as compliance, and develop and maintain a solid and comprehensive internal control system. In this context, the operational services of credit institutions are the first responsible for the management of the risks they incur in the exercise of their activities and must put in place controls aimed at guaranteeing the compliance of their activity with internal and external requirements. Credit institutions must also have internal control functions endowed with appropriate and sufficient authority, stature and access to the Board of Directors and the Management Committee to fulfill their mission, taking into account the risks incurred in a prospective approach.
Article 4: Credit institutions are required to put in place an internal control system under the minimum conditions provided by this Instruction. The responsibility to ensure that the credit institution complies with its obligations under this regulation lies with the Board of Directors (Article 50 of the banking law), with the support of the Internal Audit Committee and the Risk Committee, and with the Management Committee (Article 39 of Instruction No. 01/GR/2022 on bank governance). The internal control system must be adapted, including in terms of staff and resources, to the nature and volume of the activities of credit institutions, the number of their locations and the different types of risks to which they are exposed. It must cover the entire organization, including the responsibilities and tasks of the Board of Directors and the Management Committee, as well as the activities of all business sectors and internal units, including internal control functions, outsourced activities and distribution channels.
Article 5: The internal control system includes:
Article 6: Internal control is organized into three levels of control which constitute as many lines of defense:
Article 7: For the control and validation of risky operations referred to in Article 6-1, the organization adopted by the credit institution must be designed to ensure strict independence between, on the one hand, the units responsible for the commitment of operations and, on the other hand, the units responsible for their validation, notably accounting, and their settlement. This independence must be ensured by a clear separation of functions, by procedures, notably IT, designed for this purpose, as well as by different hierarchical reporting of the units. Areas that present potential conflicts of interest or risks of overlap of competencies or responsibilities must be identified, circumscribed to the minimum, subject to continuous monitoring and regular evaluation. The remuneration of agents of units responsible for the validation of operations and controls of the second and third levels is set independently from that of the businesses whose operations they validate or verify, and at a sufficient level to have qualified and experienced personnel.
Article 8: Persons assigned to permanent control, the compliance function and the risk management function and periodic control, as well as their hierarchical managers, must not carry out any commercial, financial or accounting operations.
Article 9: Permanent controls carried out under Article 6-2 must follow a defined program, at a predetermined frequency, specifying what the different verification points are, the methods of implementation and reporting of the results of these controls. Credit institutions regularly ensure that the permanent control program covers all areas of activity and risk zones. They keep up to date a document on the credit institution's risk map specifying the measured or estimated degree of risks. The checks carried out are formalized so that they can be examined by the periodic control function, statutory auditors, external auditors and the Central Bank of Mauritania.
Article 10: For units responsible for risk management, compliance and permanent control functions, the organization of the credit institution must also be designed to ensure strict independence of these units from the operational units they are responsible for controlling. The heads of second-level permanent control, compliance control, periodic control and risk management functions are hierarchically attached to the effective managers of the credit institution and functionally to its Board of Directors. Due to the size of the credit institution and the nature of its activities, the responsibilities of second-level permanent control and compliance may be entrusted to the same person, with the prior agreement of the Central Bank of Mauritania.
Article 11: The head of periodic control, referred to in Article 6-3, is responsible for the coherence and effectiveness of said control. He is appointed after agreement of the Internal Audit Committee. The head of periodic control reports on each mission to the Management Committee and presents the results of his missions to the Internal Audit Committee and the Board of Directors at a frequency that cannot exceed six months. The responsibility for second-level permanent control and periodic control cannot be entrusted to the same person. Periodic control implements a methodology based on the identification and measurement of significant risks of the credit institution to develop a periodic control program. This must be defined according to a multi-year plan, which cannot exceed three years, and cover all areas of activity and functions of the credit institution. It must be submitted to the Internal Audit Committee and validated by the Board of Directors; its execution is monitored by the Management Committee and reported to the Internal Audit Committee and the Board of Directors. The periodic control function must have sufficient resources, be informed diligently of major changes made by the credit institution to its risk management strategy, its processes and its policies. Outsourced activities, and notably important and essential service provisions, must be included in the scope of intervention of periodic control. Reports established following periodic controls give rise to recommendations to be implemented by the audited units, where applicable after decision by the effective managers; their follow-up must be ensured by the periodic control function which must report to the effective managers and the Internal Audit Committee. The Internal Audit Committee verifies the execution of corrective measures within a reasonable timeframe. The Board of Directors is informed at least twice a year of the recommendations issued and their implementation. The head of periodic control must be able to directly and of his own initiative inform the Risk Committee or the Internal Audit Committee and, where applicable, the Board of Directors, of the non-execution of decided corrective measures. Agents in charge of periodic control exercise their mission in total independence from the services they control. They can contact any member of staff and access any information they deem useful for the proper conduct of their mission. When the size of the credit institution does not justify the establishment of a periodic control system, missions may be entrusted to an external auditor after prior agreement of the Central Bank of Mauritania.
Article 12: The Internal Audit Committee must formulate an opinion on the compliance of the internal control organization with regard to Articles 4 to 11 of this Instruction before this organization or any modification of this organization is validated by the Board of Directors.
II- Documentation and Information System
Article 13. Credit institutions must have adequate information systems (both in normal times and in crisis periods) to measure, assess, and report on the size, composition, and quality of exposures at the credit institution level, for all types of risks described in Section 5 of this Instruction.
In particular, these systems must allow for the regular monitoring of operational risk profiles and significant operational exposures, as well as the aggregation and analysis of data relating to operational risk events, including internal loss data.
Risk reports from information systems must reflect the credit institution's risk profile, compliance with set limits and risk appetite, its capital and liquidity needs, and must be provided in a timely manner to the Board of Directors and senior management, in a format suitable for their use.
Credit institutions must develop and maintain appropriate capabilities for aggregating risk data and reporting, based on their risk profile. The Board of Directors and senior management of credit institutions must review and approve the credit institution's risk data aggregation and reporting framework, and ensure that adequate resources are allocated to it.
Credit institutions must have an internal control charter, including the internal control of the anti-money laundering and counter-terrorist financing framework, which specifies at least:
The internal control charter is submitted annually to the internal audit committee after being updated based on the evolution of the credit institution's risk profile and macroeconomic and market conditions. It must include the list of members of the internal audit committee, the risk committee, and the heads of various internal control functions. It is communicated to the Board of Directors for validation, and to the statutory auditors.
Article 14. Senior management is required to periodically assess and control the effectiveness of risk management policies, frameworks, and procedures implemented to comply with this Instruction, and to take appropriate measures to remedy any failures.
The Board of Directors is required to regularly review, with the help of the risk committee, the risk management policies, frameworks, and procedures implemented to comply with this Instruction, to assess their effectiveness, as well as any corrective measures taken in case of failures. To this end, the risk committee communicates, coordinates, and collaborates effectively with the internal audit committee.
Article 15. Credit institutions develop and keep up-to-date formalized procedures relating to their various activities. These documents must in particular describe the methods for recording, processing, and reporting information, accounting schemes, and procedures for committing and validating transactions, the associated risks, and the controls to be performed.
Each service or operational unit must have a manual in which the procedures for carrying out the operations it is responsible for are recorded: these procedures specify in particular the methods for commitment and validation, recording and processing of transactions, as well as the corresponding accounting schemes.
Credit institutions keep up-to-date, under the same conditions, documentation that specifies the means intended to ensure the proper functioning of internal control, including:
The documentation is organized in such a way as to be made available, upon request, to the management committee, the Board of Directors and its internal audit and risk committees, the statutory auditors, and the Mauritanian Central Bank.
Article 16. Reports established following periodic controls are communicated to the management committee, the internal audit and risk technical committees, and, upon request, to the Board of Directors.
These reports are kept available to the Mauritanian Central Bank, the statutory auditors, and external auditors intervening at the request of the Mauritanian Central Bank.
Article 17. Once a year, credit institutions prepare a report on internal control in accordance with the model provided by the Mauritanian Central Bank. This report is submitted to the internal audit committee and the Board of Directors, which must validate it. This report includes, for the different categories of risks, including money laundering and terrorist financing risks mentioned in this Instruction:
Article 18. The management committee must regularly report, at least once a semester, to the Board of Directors on the conditions under which the set risk limits are respected.
Article 19. Credit institutions define information procedures, at least quarterly, for the management committee and the risk committee, on the respect of risk limits, in particular when global limits are likely to be reached. The monitoring of compliance with limits is controlled quarterly by the risk committee.
Article 20. For the monitoring of their operations, and in particular for information intended for the management committee, the Board of Directors, and its risk and internal audit committees, credit institutions must develop adapted summary statements. Exceptions to policies, procedures, and limits must be immediately submitted for authorization to hierarchical managers and subject to immediate information of the management committee and the risk committee, and, where applicable, the internal audit committee and the Board of Directors.
Article 21. Once a year, credit institutions prepare a report on the measurement and monitoring of the risks to which they are exposed, in accordance with the model provided by the Mauritanian Central Bank. This report is submitted to the risk committee and the Board of Directors, which must validate it.
This report includes, for the different categories of risks, including money laundering and terrorist financing risks mentioned in this Instruction:
Credit institutions must also put in place adequate mechanisms for rapid information of the Mauritanian Central Bank for any event likely to result in a significant increase in their risk exposure likely to have important consequences on their financial situation or to harm the financial stability of the market.
III- Compliance Function
Article 22. Credit institutions designate a head of the compliance function, whose name is communicated to the Mauritanian Central Bank, responsible for ensuring the consistency and effectiveness of non-compliance risk control. He/She must not exercise any operational activity. He/She is appointed by senior management with the concurring opinion of the internal audit committee. He/She reports on his/her activities quarterly to the internal audit committee and semi-annually to the Board of Directors.
Article 23. The compliance function ensures monitoring of legal and regulatory developments in order to adapt, if necessary, the internal organization and procedures. It has sufficient resources to carry out its missions.
Article 24. Credit institutions provide for specific compliance review procedures, including systematic prior approval procedures, including a written opinion from the head of compliance or a person duly authorized by him/her for this purpose, for new products or for significant changes made to existing products. They also provide for a compliance control plan, which defines, according to a predetermined frequency, what the different verification points are, the methods for carrying them out and reporting their results.
Article 25. Procedures provide for the methods for centralizing with the head of the compliance function information relating to any malfunctions in the effective implementation of compliance obligations. They provide for the right for any manager or staff member to raise questions about these possible malfunctions with the compliance officer and the Mauritanian Central Bank.
These procedures are brought to the attention of all staff.
Article 26. Credit institutions put in place procedures to monitor and evaluate the effective implementation of actions aimed at remedying any malfunction in the implementation of compliance obligations.
Credit institutions provide all their staff with training on compliance issues and compliance control procedures, adapted to the operations they perform.
Article 27. Credit institutions put in place a framework to guarantee regular and as frequent as possible monitoring of changes that may occur in the texts applicable to their operations and, as such, immediate information of all concerned members of their staff.
IV- Anti-Money Laundering and Counter-Terrorist Financing Framework
Article 28. Credit institutions put in place an anti-money laundering and counter-terrorist financing organization, internal procedures, an internal control system, and a risk classification in accordance with Law No. 2019-017 of February 20, 2019, relating to the fight against money laundering and terrorist financing, referred to in this text as "AML CFT Law", and Decree No. 2019-197/P.M/M.J/ implementing Law No. 2019-017 of February 20, 2019, relating to the fight against money laundering and terrorist financing, as well as Instruction No. 06/GR/2019 relating to control requirements for the fight against money laundering and terrorist financing.
Article 29. Credit institutions ensure that personnel whose activity is exposed to money laundering and terrorist financing risks are able to show vigilance appropriate to these risks. To this end, credit institutions ensure that the training and information of these persons are adapted to their activities.
Article 30. Credit institutions must ensure that internal control verifies, within the framework of the anti-money laundering and counter-terrorist financing framework, that:
V- Risk Monitoring Framework
1- General Provisions
Article 31. Credit institutions must have a risk monitoring framework adapted to their risk appetite, systemic importance, size, complexity, and taking into account market and macroeconomic conditions.
It includes in particular a risk appetite statement prepared by the Board of Directors and a risk appetite, explaining the level and type of risks that the credit institution wishes to assume, proposed by the management committee, reviewed and approved by the Board of Directors.
The risk monitoring framework must be broken down for each significant risk, documented by policies and procedures, and must allow for the identification, measurement, control, monitoring, control, or mitigation of risks. Risk management policies must be reviewed at least annually by the Board of Directors, validated by it after any modification related to changes in the credit institution's risk profile, macroeconomic environment, or market conditions. Credit institutions must take their risks, including liquidity risks, into account when setting their rates, measuring their performance, and during the validation process for new products for all their significant activities.
Article 32. The risk monitoring framework of credit institutions must offer a global view of risks, extending to all their business sectors and units, including internal control functions. It must:
Risks must be maintained within the global internal limits approved by the Board of Directors. These limits must be reviewed as necessary and at least once a year, taking into account, in particular, current regulations and the level of the credit institution's net capital.
Article 33. The monitoring of compliance with the limits referred to in Article 32 must be carried out continuously and result in a report addressed to the management committee and the Board of Directors. This report must include an analysis of the reasons motivating any possible breaches, as well as, if necessary, proposals and/or recommendations relating thereto.
Article 34. Credit institutions put in place and update a risk map taking into account internal factors such as the complexity of the organization, the nature of the activities carried out, and the quality of the systems, as well as external factors such as economic conditions and regulatory developments.
Article 35. Credit institutions must identify, monitor, and manage all climate-related financial risks as well as emerging risks that could harm their financial situation, in particular their capital and liquidity resources. They must ensure that their risk appetite and risk monitoring framework take into account all climate-related financial risks and emerging risks to which they are exposed, and establish a reliable approach to identify, measure, monitor, and manage these risks.
Article 36. : The prospective crisis simulation program must be adapted to the systemic importance, size, and complexity of the credit institution. The crisis simulation program must cover, at a minimum, unless the significance of exposures is justified, credit and concentration risk, market and exchange rate risk, interest rate risk in the banking book, liquidity risk, and operational risk. The crisis simulation program of a credit institution must take into account all significant sources of risk and adopt plausible adverse scenarios. Its results must be integrated into the credit institution's decision-making and risk management processes (including emergency arrangements) and into the assessment of its capital and liquidity levels.
In this regard, credit institutions must have reliable, effective, and comprehensive systems and procedures to assess and permanently maintain the amounts, composition, and internal allocation of capital they deem appropriate, taking into account the nature and level of risks to which they are or could be exposed. In particular, these systems and procedures take into account the results of crisis simulation programs to ensure the credit institution's ability to maintain its solvency above regulatory thresholds in the event of a crisis.
Corrective measures are necessary if significant failures are observed in the crisis simulation program or if the results of crisis simulations are not adequately taken into account in the credit institution's decision-making process.
The crisis simulation program must:
The crisis simulation program must result in a report communicated to the management committee, the risk committee, and the board of directors.
Article 37. : Credit institutions must regularly review the risk monitoring framework to verify its relevance with regard to the evolution of activity, the market environment, and analysis techniques.
Article 38. : The risk monitoring framework is subject to regular internal control, both permanent and periodic, aimed at ensuring that it remains comprehensive and appropriate and that it is correctly implemented.
2- Risk Management Function
Article 39. : Credit institutions must set up a risk management function responsible in particular for:
The risk management function covers all significant risks, has sufficient material and staffing resources, the necessary authority to fulfill its missions, and access to the board of directors.
Article 40. : The appointment or dismissal of the head of the risk management function, as well as any other change related to this position, must be approved by the board of directors after opinion from the risk committee. The credit institution must inform the Central Bank of Mauritania without delay of the resignation or dismissal of the head of the risk management function and indicate the reason in the event of dismissal.
The head of the risk management function must at all times possess the honorability, knowledge, skills, and experience necessary to perform their duties.
Article 41. : The head of the risk management function must have a sufficiently high hierarchical position to allow them to exercise their function independently. They are hierarchically attached to the senior management of the credit institution and functionally attached to the risk committee and the board of directors.
In the event of risk developments that seriously affect or are likely to seriously affect the credit institution, the head of the risk management function may report directly to the risk committee and the board of directors.
The Central Bank of Mauritania may at any time summon the head of the risk management function to examine any subject related to their missions.
3- Capital and Liquidity Adequacy
Article 42. : Credit institutions must put in place a framework to assess the adequacy of their capital and liquidity with regard to the permanent compliance with their regulatory obligations. In particular, they must assess the amount of capital required based on their risk profile as well as their strategy and business model, permanently maintain a capital level in compliance by taking into account appropriate capital management buffers, prospectively plan this capital level over a period of three [3] years, and assess the level of high-quality liquid assets or other sources of liquidity or financing necessary to meet their regulatory obligations in all circumstances.
The capital adequacy analysis, provided for in Article 64 of the banking law, must be carried out annually and as necessary when needed, cover all risks to which the credit institution is exposed, be prospective over three [3] years, take into account the results of crisis simulation programs, and result in a capital adequacy report communicated to the management committee, the risk committee, and the board of directors.
The liquidity adequacy analysis must be carried out annually and as necessary when needed, cover all risks to which the credit institution is exposed, be prospective over three [3] years, take into account the results of crisis simulation programs, and result in a liquidity adequacy report communicated to the management committee, the risk committee, and the board of directors.
Article 43. : Credit institutions must determine a capital allocation amount for significant risks, taking into account in particular credit and concentration risks, market risks, general interest rate risk, liquidity and transformation risks, operational and legal risks, and climate risks. Credit institutions must define corrective management actions if necessary to ensure the adequacy of their capital over a period of three [3] years.
4- Credit and Concentration Risks
Article 44. : For the purposes of this instruction, credit risk is the risk of loss incurred in the event of default by a counterparty or counterparties considered as the same group of clients. It results in particular from uncertainty regarding the ability or willingness of counterparties or clients to fulfill their obligations. It materializes by (i) the failure by a client or counterparty to meet its financial obligations or (ii) by the deterioration of the credit quality of this client, counterparty, or group as defined by Instruction No. 11/GR/2012.
Article 45. : Credit institutions must have sufficient resources and an adequate credit and concentration risk management process that takes into account, prospectively, their risk appetite, risk profile, market conditions, and macroeconomic factors. This process includes prudent policies and procedures allowing:
The complete credit lifecycle is covered by the credit risk management framework, including the granting and initial assessment of credit, as well as the continuous management of the credit institution's loan and investment portfolios.
The assessment of default risk, the classification of exposures, and their provisioning are carried out on an individual basis, at least for significant exposures. To this end, institutions set an appropriate threshold for the identification of significant exposures and review it regularly.
In accordance with Article 53 of the banking law, the management committee is assisted by a credit committee in which the head of the risk management function or their representative must participate.
The credit committee must analyze significant commitments and formulate decision proposals to the management committee. It ensures the solvency and good conduct of beneficiaries and ensures that, both in substance and form, the commitments granted respect professional rules. On delegation from the management committee, it may grant credits within the limits approved by the board of directors and report to the management committee.
The head of the risk management function must provide an independent opinion on the commitments studied by the credit committee but does not participate in the granting decision when the credit committee has received a delegation to grant credits. The deliberations and, if applicable, the decisions of the credit committee are recorded in deliberation minutes, and credit institutions maintain an audit trail of commitment decisions available to the Central Bank of Mauritania.
Article 46. : The credit risk management framework must ensure that the risks to which the credit institution may be exposed due to the default of a counterparty are correctly assessed and monitored. It includes a framework for identifying exceptional events and communicating them to the management committee and, if necessary, to the board of directors to initiate remedial actions as soon as possible.
Article 47. : The processes and criteria for assessing credit risk, as well as the responsibilities of persons and bodies authorized to commit the credit institution, must be defined and recorded in writing. They must allow:
These rules must be adapted to the characteristics of the credit institution, in particular its size, the nature, and volume of its activities.
Article 48. : Credit institutions must have a credit risk selection procedure and a risk measurement system allowing them in particular:
Article 49. : Loan or commitment decision processes, including when organized by delegation, must be clearly formalized and adapted to the characteristics of the credit institution, in particular its size, organization, and the nature of its activity.
Unless, in the case of low-value operations whose limits are set by the general management and approved by the board of directors, credit institutions ensure, including within the framework of delegation procedures, that loan or commitment decisions are taken by at least two people and that credit files are also analyzed by the risk management function.
Article 50. : Credit applications must result in the creation of files containing all quantitative and qualitative information related to the applicant and necessary for file study and decision-making, including accounting documents, asset statements for the last fiscal year, salary or income certificates, or any other document serving as such.
Information must cover both the credit applicant themselves and the entities with which they form a group of related counterparties considered as the same beneficiary, taking into account the legal and financial links and/or the significant degree of dependence existing between them.
Credit files must be regularly monitored and updated, at least annually. Credit institutions must complete these files at least quarterly for counterparties whose receivables are in arrears or who present significant risks or volumes.
Credit files must be securely stored and archived to prevent any risk of fraud.
Article 51. : Credit institutions must put in place a counterparty rating system allowing for relevant differentiation of default risk, regularly review the related methodology, with regard in particular to the performance of this system, and apply this system at least once a year to each of their counterparties. In particular, this system must allow for differentiating, within healthy receivables, the credit quality of counterparties. For retail client exposures, the rating system may be based on automated data processing.
The assigned ratings must be used in the credit granting process, risk management policy, pricing, and internal capital allocation policy.
Article 52. : The assessment of credit risk takes into account in particular the nature of the activities carried out by the applicant, their financial situation, total indebtedness, the asset base of major shareholders or partners, as well as their repayment capacity.
It also takes into account any other information allowing a more complete assessment of the risk, such as the competence of management, the economic environment in which the credit applicant carries out their activity, potential country risk, and proposed guarantees.
Article 53. : Credit granting decisions must take into account their profitability, ensuring that the forecast analysis of direct and indirect charges and revenues is as comprehensive as possible and covers in particular operational and financing costs, the cost corresponding to the beneficiary's default risk during the credit operation, and the cost of remunerating capital.
The management committee must carry out, at least semi-annually, a post-facto analysis of the profitability of credit operations.
Credits granted to the same counterparty (individual client or group of related natural or legal persons presenting a unique risk for the lending institution) must be listed and centralized monthly. Those incurred by sector must also be monthly.
Article 54. : Credits granted to clients benefiting from facilities greater than or equal to 10% of net own funds must be subject to particular quarterly monitoring by the management committee and the risk committee, both on an individual basis and at the group level as defined by Instruction No. 11/GR/2012.
Article 55. : Facilities granted to natural or legal persons related to the credit institution, as defined by Article 23 of the banking law, and granted in accordance with the law and instructions of the Central Bank of Mauritania must be subject to particular monitoring. The credit committee and internal control must ensure compliance with the aforementioned law and instructions. The composition and evolution of balances of this nature must be subject to specific and permanent monitoring by internal control and be brought to the attention of the internal audit committee, the board of directors, and the statutory auditors.
The board of directors must also be informed of any operation likely to generate a conflict between the interests of the credit institution and those of the aforementioned persons. In application of Article 22 of the banking law, it must in particular give its prior approval to any commitment in favor of the aforementioned persons.
Article 56. : Facilities considered as non-performing loans with regard to current regulations must be recorded in the appropriate accounts of the banking chart of accounts and result in the constitution of required provisions and must be managed according to Instruction No. 05/GR/2014.
Provisioning and write-off methods and levels must be subject to an effective review and validation process, controlled by the risk management function.
Credit institutions have adequate and appropriate policies, procedures, and organizational resources for:
Article 57. : The balances of non-performing loans, as well as the results of amicable or judicial efforts undertaken for their recovery, must be regularly, and at least at the end of each quarter, brought to the attention of the risk committee. The risk committee must also be kept informed of the balances of all restructured receivables and the evolution of their repayment.
Article 58. : Credit institutions must carry out, at least quarterly, an analysis of the evolution of the quality of their commitments. This review must in particular allow determining, for operations of significant importance, any necessary reclassifications within internal categories of credit risk level assessment, as well as allocations to doubtful receivable accounting headings and appropriate provisioning levels. The result of this review, and the accompanying analysis, must be brought to the attention of the risk committee.
Credit institutions must put in place a framework for managing and evaluating collateral and guarantees held against credits. The evaluation of collateral and guarantees reflects their net value, taking into account market conditions and the time necessary for their realization.
The determination of the appropriate provisioning level takes into account guarantees for which credit institutions must ensure effective implementation possibilities, compliance with regulatory conditions provided for by Instruction No. 05/GR/2014 regulating the classification of receivables and the constitution of provisions, as well as the existence of a recent prudent-based evaluation.
The review of commitments results in the preparation of a semi-annual report on credit risks, according to a framework defined by the Central Bank of Mauritania. This report is submitted to the risk committee and the board of directors.
Article 59. : Credit institutions must analyze concentration risks on debtors or groups of debtors, economic and geographical sectors, and put in place appropriate limits.
Article 60. : Credit institutions regularly carry out crisis simulations to assess the vulnerability of their credit portfolio in the event of a downturn or deterioration in the quality of their counterparties, in particular those included in the list of sensitive receivables.
5- Market and Exchange Rate Risks
Article 61. : Market risk is the risk associated with price variations having an impact on assets and liabilities valued at market prices. Exchange rate risk corresponds to the risk incurred by the credit institution in the event of variations in currency exchange rates due to the credit institution's short and long currency positions.
Article 62. : Credit institutions must have systems for monitoring transactions carried out on their own account, including transactions not covered with clients, allowing in particular to:
Article 63. : Credit institutions put in place a system of limits for market and foreign exchange risk, at the global level, and if necessary, at a more detailed level. These limits are consistent with current regulations as well as the credit institution's risk appetite and are validated by the board of directors. The level of limits must be appropriate with regard to the financial footprint and take into account the degrees of exposure to other categories of risk. When market and foreign exchange risk is significant, compliance with limits must be subject to daily monitoring.
Article 64. : Credit institutions must establish and monitor exposure limits for foreign exchange risk relative to their net equity according to Instruction No. 07/GR/2023 on banks' foreign exchange positions. These limits are consistent with the credit institution's risk appetite and are validated by the board of directors.
Article 65. : For the management of market and foreign exchange risk, credit institutions put in place:
6- Global Interest Rate Risk
Article 66. : Credit institutions must assess their exposure to global interest rate risk at least once a year. The measurement system must be adapted to the nature of their operations and activities, allowing them in particular:
Article 67. : Credit institutions set limits for global interest rate risk in line with their risk appetite. The determination of the amount of these limits must take into account different interest rate variation hypotheses, including very unfavorable scenarios with regard to the credit institution's risk profile. For the management of global interest rate risk, credit institutions put in place:
7- Liquidity and Transformation Risks
Article 68. : Credit institutions must have prudent policies and procedures, validated by the board of directors, consistent with the credit institution's risk appetite, in order to identify, measure, monitor, report and control or mitigate liquidity and transformation risk on a permanent and prospective basis. These policies and procedures must be adapted to the credit institution's risk profile, the nature and volume of its operations, as well as its funding channels. The assumptions underlying decisions related to the management of these risks must be reviewed regularly and take into account the macroeconomic and market context.
Article 69. : Credit institutions must monitor their cash situation on a daily basis and put in place forecast cash flow tables, at different time horizons.
Article 70. : Credit institutions set limits for liquidity and transformation risks. The determination of these limits must take into account different hypotheses. Liquidity crisis situations, in particular, must be taken into account to determine the limit amounts.
Article 71. : Emergency funding plans to address any liquidity crisis must be put in place. Credit institutions must maintain cash and other immediately available assets in order to be able to face a liquidity crisis. They must:
More like this from BCM
We email you every new BCM publication the day it's published.