2025-12-22
Added
Instruction No. 30/2025 establishes minimum standards for internal control systems, compliance functions, and internal audit for all banks and branches of foreign banks licensed in Timor-Leste, as well as Other Deposit Taking Institutions where applicable. The Instruction requires banks to implement comprehensive internal controls covering risk management, segregation of duties, and Basel III capital and liquidity controls, including stress testing frameworks. It mandates the establishment of independent compliance and internal audit functions with defined reporting lines to the Board of Directors, specific responsibilities for monitoring regulatory adherence, and periodic quality assessments. The document also specifies requirements for internal audit scope, such as validating Expected Credit Loss calculations under IFRS 9 and reviewing insurance contract compliance under IFRS 17.
BCTL published 2 documents in the last 30 days — get each new one by email the day it lands.
INSTRUCTION № 30/2025
ON INTERNAL CONTROLS, COMPLIANCE AND INTERNAL AUDIT Considering that Section 23.1 of Regulation 2000/8, dated February 25, on Bank Licensing and Supervision (hereinafter referred as the “Regulation”), determines that banks shall conduct their administration and operations in accordance with sound administrative and accounting procedure, which is reinforced by Sections 27.1.(e) and 31.1 of the Regulation. Considering that Sections 19.1. a, b, and Section 19.3.c of the Regulation require the establishment of appropriate accounting procedures and accounting controls, and compliance with the laws and regulations applicable to banks. Considering Principle 26 of the Core Principles for Effective Banking Supervision (BCBS - Basel Committee on Banking Supervision), which recommends that banks have adequate internal control frameworks to establish and maintain an effectively controlled and tested operating environment for the conduct of their business, considering their risk profile. The Governing Board of Banco Central de Timor-Leste (BCTL), in accordance with Section 46 of Regulation no. 2000/8 of 25 February and Article 31 paragraph 1 of Law no. 5/2011 of 15 June, hereby resolves to approve the following Instruction:
CHAPTER I
GENERAL PROVISIONS
Article 1
Definitions
The following definitions apply to this Instruction:
a) Bank: is defined in accordance with the Regulation. b) BCTL refer to the Banco Central de Timor-Leste; c) Board of Directors: or the Governing Board, is the governing body responsible for overseeing the management of the bank. d) Compliance Function: is an independent function reporting directly to the Board of Directors or a designated Board Committee. It is responsible for identifying, assessing, advising on, monitoring, and reporting compliance risks, including risks of legal or regulatory sanctions, financial loss, or reputational harm arising from non-compliance with applicable laws, regulations, codes of conduct, and established standards.
e) Control Functions: functions that operate independently from business management and are tasked with providing objective assessments, assurance, and reporting. These include, at a minimum, the risk management function, compliance function, and internal audit function. f) Internal Control System: is a coherent framework of policies, procedures, and control mechanisms that ensure effective governance of the bank's organizational and operational structure, including risk management, compliance, and internal audit. g) Internal Audit Function: is an independent, objective assurance and consulting activity designed to add value and improve the bank’s operations. It helps the bank accomplish its objectives by bringing a systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control, and governance processes. h) Risk Limits are the quantitative thresholds that operationalize the bank’s risk appetite, allocated across business units, legal entities, or risk categories to control risk exposures within acceptable bounds. i) Risk Management is a set of processes by which a bank identifies, assesses, monitors, mitigates, and reports material risks and concentrations in a timely and comprehensive manner. j) Senior Management: refers to any officer of the bank, including the Chief Executive Officer, Vice President(s), General Manager, Chief Financial Officer, Chief Lending Officer, Chief Treasury Officer, or any other officer with authority to make binding commitments on behalf of the institution.
Article 2
Purpose
This Instruction establishes the minimum standards and principles that banks must observe in
designing, implementing, and maintaining effective internal control systems to ensure sound risk management, safeguard assets, ensure accurate and reliable financial reporting, and comply with applicable laws and regulations.
The Instruction also sets minimum standards and principles governing the compliance and
internal audit functions of banks, to ensure independent and effective evaluation of internal controls, risk management, governance processes, and the reliability of financial and operational reporting.
Article 3
Scope
This instruction applies to all banks and to all branches of foreign banks licensed to operate in
Timor-Leste.
Institutions, licensed under Instruction nº 06/2010, dated 17 December, on the Licensing and
Supervision of Other Deposit Taking Institutions (ODTIs), are subject to the Instruction where applicable.
Those institutions are expected to have relatively basic risk management systems and internal
controls, information systems, and internal audit that are appropriate for the size of the institution and the nature, scope, and risk of its activities.
When the size and complexity of the ODTI do not warrant a full-scale compliance or internal audit
functions, the ODTI may rely on regular reviews of essential compliance and internal controls conducted by other institution personnel, independent of the area under review.
CHAPTER II
PRINCIPLES OF INTERNAL CONTROL
Article 4
Definition of Internal Control
Internal control shall be understood as a comprehensive process established by the bank’s Board of Directors, Senior Management, and all levels of personnel, designed to achieve the following objectives:
a) promote effective and efficient operations; b) ensure reliability, timeliness, and transparency of financial and management information; c) ensure compliance with applicable laws, regulations, and internal policies; d) safeguard assets against loss from unauthorized use or disposition.
Article 5
Core Components of Internal Control
Banks shall structure their internal control systems to include at minimum the following components:
a) Control Environment – A culture that promotes integrity, ethical values, and competence at all levels, supported by robust organizational structure, with clear arrangements for delegating authority and responsibility, sound human resources practices, and appropriate oversight. b) Risk Assessment – Ongoing and systematic identification, evaluation, and management of material risks affecting the bank’s objectives. c) Control Activities – Policies, procedures, and mechanisms established to ensure that risk responses are effectively carried out, including segregation of duties, cross checking, dual control of assets, double signatures, approval and authorization controls, verifications, and reconciliations of these processes. The separation of the functions that involve committing the bank, paying away its funds, and accounting for its assets and liabilities is essential. The safeguarding of the bank's assets is also relevant. d) Information and Communication – Systems that ensure the flow of reliable, timely, and relevant information both internally and externally to support decision-making and control. e) Monitoring and Corrective Actions – Regular review and evaluation of internal controls, to test adherence to and effectiveness of these controls as well as applicable laws and regulations, including by independent internal audit ((including those that are outsourced), compliance and other control functions, with prompt corrective measures as necessary.
CHAPTER III
ROLES AND RESPONSIBILITIES
Article 6
Board of Directors
environment for the conduct of their business, considering their risk profile with a forward-looking view.
2. The Board of Directors is also responsible for:
a) approving and periodically reviewing the overall business strategies and policies of the bank; b) understanding the major risks faced by the bank, setting acceptable levels for these risks, and ensuring that bank managers take the steps necessary to identify, measure, monitor and control these risks; c) approving the organizational structure; and d) ensuring that bank Board members monitor the effectiveness of the internal control system.
3. The Board of Directors shall conduct:
a) periodic discussions with Senior Management concerning the effectiveness of the bank's internal control system; b) a timely review of evaluations of internal controls made by Senior Management, internal auditors, and external auditors; c) periodic efforts to ensure that senior management has promptly followed up on recommendation and concerns expressed by auditors and the BCTL on internal control weaknesses; and d) a periodic review of the appropriateness of the bank's strategy and risk limits.
4. Pursuant to Section 19.1 of the Regulation, the Audit Committee can assist the Board of Directors
in fulfilling these responsibilities; however, pursuant to Section 16.5, the Board of Directors and its members cannot delegate their responsibilities to others.
5. The Board of Directors and Senior Management are responsible for promoting high ethical and
integrity standards, and for establishing a culture within the organization of the bank that emphasizes and demonstrates to all levels of personnel the importance of internal controls. Bank personnel must be informed of, and held responsible for, their role in the internal controls process.
6. The Board of Directors shall also oversee the integrity, independence, and effectiveness of
control functions, including internal audit, risk management, and compliance.
Article 7
Senior Management
h) promoting a culture of control consciousness, integrity, and compliance.
2. All material risks that could adversely affect the achievement of the bank's goals should be
recognized and continually assessed. This assessment should cover all risks facing the bank and the consolidated banking organization (credit risk, country and transfer risk market risk, interest rate risk, liquidity risk, operational risk, legal risk and reputation risk). Internal controls should be revised to appropriately address new or previously uncontrolled risks.
3. Senior Management shall ensure that the bank maintains adequate internal controls over
regulatory reporting, capital adequacy ratios, leverage ratio, and liquidity coverage ratio, as required under Basel III. They shall establish robust stress testing frameworks and scenario analyses for material risks, ensuring results are integrated into decision-making and capital planning.
Article 8
Basel III Capital and Liquidity Controls
Article 9
Control Functions
with such limits and requirements for following up in instances of non-compliance should be established. e) A system of approvals and authorizations. A system of approval and authorization for bank transactions which exceed a certain limit should be established to ensure that a manager at an appropriate level is aware of the transaction or situation, and to establish accountability. f) A system of verification and reconciliation. Verifications of transaction details and activities as well as periodic reconciliations should be performed on a regular basis.
Article 10
Segregation of Duties
Article 11
Responsibilities of the Board of Directors and Senior Management
Article 12
Compliance Policy
Banks shall adopt a comprehensive compliance policy, approved by the Board of Directors,
setting out the bank’s approach to compliance, including the identification, assessment, monitoring, and reporting of compliance risk.
The compliance policy shall be communicated to all employees and reviewed regularly, at least
annually, and whenever there are significant regulatory or business changes.
The compliance policy shall explicitly cover the bank’s obligations in relation to insurance or risk
transfer arrangements, including compliance with IFRS 17, contractual reviews, and associated regulatory reporting requirements.
Article 13
Organization and Responsibility of the Compliance Function
The compliance function shall be independent of operational and business functions and shall
have direct access to the Board of Directors or its Audit/Compliance Committee.
The head of compliance shall not be assigned responsibilities that could compromise the
function’s independence.
The compliance function shall have the authority to access all records, data, and employees
necessary for discharging its duties.
The compliance function has among its responsibilities:
a) Identify and assess the compliance risks associated with the bank’s business activities; b) Advise the Board and Senior Management on compliance laws, regulations, and standards; c) Monitor and report on the bank’s compliance with applicable obligations; d) Promote staff training and awareness on compliance issues; e) Assist in developing policies and procedures to manage compliance risk; and f) Conduct regular and ad hoc compliance reviews.
The compliance function shall also ensure that the bank’s use of insurance or risk transfer
arrangements complies with all applicable legal and regulatory obligations, including those arising under IFRS 17. Where the bank engages insurance companies to cover exposures such as loan risk, the compliance function shall monitor the adequacy and legality of such arrangements, ensure accurate and transparent reporting in line with IFRS requirements, and coordinate with the internal audit function to avoid overlaps while preserving independence.
The compliance function shall be staffed by an adequate number of qualified personnel with the
necessary skills, experience, and integrity to perform their duties effectively.
The compliance function shall provide regular reports, at least annually, and whenever
necessary, to the Board of Directors or its designated committee on compliance matters, including significant breaches, deficiencies, and corrective actions.
The compliance function shall promptly report material compliance issues to Senior
Management and, where appropriate, to the Board.
Compliance risk shall form part of the bank’s overall risk management framework. The
compliance function shall coordinate with other control functions, including risk management and internal audit, while maintaining its independence.
Banks shall periodically review their compliance frameworks to ensure their continued adequacy
and effectiveness in light of evolving regulatory requirements, market conditions, and the bank’s business activities.
CHAPTER VI
PRINCIPLES OF INTERNAL AUDIT
Article 14
Internal Audit Function
The bank shall have an internal audit function, independent of operational management and
with sufficient standing, authority, and resources within the bank to carry out its responsibilities effectively.
The head of internal audit shall report functionally to the Audit Committee of the Board of
Directors.
Internal auditors shall have unrestricted access to all records, personnel, systems, and physical
properties relevant to the performance of their duties.
Internal auditors shall not assume operational responsibilities or be involved in activities that
could compromise their objectivity.
Article 15
Responsibilities of Board of Directors, Audit Committee, and Senior Management
The Board of Directors, and the Audit Committee, shall:
a) Approve and regularly review the internal audit charter and audit plan. b) Ensure the independence, competence, and adequacy of the internal audit function. c) Oversee the performance of the internal audit function and receive its reports directly. d) Approve the appointment, remuneration, and dismissal of the head of internal audit.
The Senior Management of the bank has the following responsibilities:
a) Facilitate the implementation of an effective internal audit function; b) Ensure timely and adequate responses to internal audit findings and recommendations; and c) Avoid actions that could compromise the independence of internal audit.
Article 16
Scope of Internal Audit
The internal audit function shall cover at least the following:
a) The adequacy and effectiveness of the internal control system, including financial, operational, compliance, and IT controls. b) The effectiveness of risk management and governance processes. c) The reliability and integrity of financial and management information. d) The safeguarding of assets and prevention/detection of fraud. e) The adequacy of compliance with laws, regulations, and internal policies. f) The evaluation of significant outsourcing arrangements and third-party service providers.
The internal audit function shall also cover validation of models and methodologies used for
the calculation of Expected Credit Losses (ECL) under IFRS 9, including periodic back-testing and independent review. It shall assess the adequacy of internal controls over financial instrument disclosures required under IFRS 7, including credit, market, and liquidity risk disclosures.
It shall evaluate processes for fair value measurement in accordance with IFRS 13, including
the appropriateness of inputs, assumptions, and hierarchy classifications.
For insurance activities, the internal audit shall review compliance with IFRS 17 requirements
on insurance contract recognition, measurement, and disclosure.
Article 17
Audit Methodology and Planning
The internal audit function shall maintain a comprehensive audit universe and a risk-based audit
plan, reviewed at least annually and approved by the Board of Directors or its Audit Committee.
Audit activities shall be conducted in accordance with internationally recognized internal
auditing standards.
The audit plan shall be flexible to respond to emerging risks, regulatory changes, or significant
incidents.
Article 18
Reporting and Follow-up
Internal audit shall issue written reports on its findings, conclusions, and recommendations
addressed to Senior Management and the Board of Directors or Audit Committee.
The internal audit function shall monitor the implementation of its recommendations and report
on outstanding issues.
All significant audit findings should be reported without delay to the Board of Directors or its
Audit Committee, especially where they concern material deficiencies or breaches.
Article 19
Internal Audit Competence and Staffing
The internal audit function shall have staff with the necessary qualifications, experience, and
technical knowledge, including expertise in risk management, accounting, Information Technology, and other relevant fields.
The bank should ensure sufficient staffing and budget for the internal audit function to carry out
its duties effectively.
Banks shall provide ongoing training and development opportunities to internal audit staff to
ensure that their knowledge and skills remain up to date with industry practices, regulatory requirements, and emerging risks.
Article 20
Quality Assurance and Improvement Program
Article 21
Outsourcing Internal Audit
Article 22
Documentation and Record Keeping
include the use of an alternate off-site facility and the recovery of critical systems supported by an external service provider.
5. Banks shall ensure that their information systems and reporting frameworks are consistent with
the Basel Committee Principles for Effective Risk Data Aggregation and Risk Reporting (BCBS 239), enabling timely, accurate, and comprehensive risk data consolidation across legal entities and business lines. Internal controls shall cover the preparation and disclosure of financial statements in compliance with International Financial Reporting Standards (IFRS), including but not limited to IFRS 7, IFRS 9, and IFRS 13.
6. The bank should establish effective channels of communication to ensure that all staff fully
understand and adhere to policies and procedures affecting their duties and responsibilities and to ensure that other relevant information is reaching the appropriate personnel.
7. Banks shall document their internal control framework, policies, procedures, and changes
thereto, and retain records sufficient to demonstrate compliance with this Instruction. Documentation shall be available for supervisory review.
8. Banks shall maintain comprehensive records of the internal audit charter, policies, audit plans,
reports, follow-up actions, quality assurance reviews, and related Board and committee minutes.
Article 23
Monitoring and Review
CHAPTER VIII
FINAL PROVISIONS
Article 24
Supervisory Oversight
Article 25
Repeal
The Instruction №. 2001/5, dated April 11, of the Central Payments Office is hereby revoked.
Article 26
Entry in Force
Read the rest free
Source: Banco Central de Timor-Leste — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCTL
BCTL published 2 documents in the last 30 days. We email you each new one the day it's published.