2018-09-11

Added · Updated

Instruction No. 36 on Business Continuity for Credit Institutions and Microfinance Institutions

Instruction No. 36 establishes prudential rules for credit institutions and microfinance institutions in the Democratic Republic of Congo regarding business continuity management and the development of business continuity plans. It mandates that these entities define policies, strategies, and procedures to manage major operational disruptions, ensuring the protection of depositors and the stability of the financial system. The instruction requires the establishment of crisis management cells, impact analyses, and detailed recovery objectives, while assigning specific responsibilities to governing bodies, executive organs, and designated business continuity officers. It further stipulates that plans must be written, tested, and regularly updated, with immediate reporting obligations to the Central Bank of Congo in the event of a crisis.

Banque Centrale du Congo logo

DR Congo

Banque Centrale du Congo

Click to view thumbnail

INSTRUCTION N° 36 ON BUSINESS CONTINUITY FOR CREDIT INSTITUTIONS AND MICROFINANCE INSTITUTIONS

The Central Bank of Congo,

Having regard to Law No. 005/2002 of May 7, 2002, relating to the constitution, organization, and functioning of the Central Bank of Congo, particularly Article 6 thereof;

Having regard to Law No. 003/2002 of February 2, 2002, relating to the activity and supervision of Credit Institutions, particularly Articles 11, 24, 25, 26, and 27 thereof;

Having regard to the Instructions of the Central Bank of Congo, particularly those Nos. 17, 21, and 22 relating respectively to internal control, governance, and risk management;

Decrees the prudential rules regarding business continuity management and the development of business continuity plans.

TITLE I: GENERAL PRINCIPLES

Chapter 1: Object and Scope

Article 1: The purpose of this Instruction is to clarify the general principles guiding credit institutions in the development of a business continuity plan in the event of major operational disruption.

Article 2: This Instruction applies to the following financial institutions, hereinafter referred to as "subject institutions":

  • Banks;
  • Specialized financial institutions;
  • Finance companies;
  • Savings banks;
  • Savings and credit cooperatives;
  • Microfinance institutions.

Article 3: The terms used in this Instruction are defined in the Instruction relating to the terminology of the prudential regulation of the Central Bank of Congo applicable to Credit Institutions and Microfinance Institutions.

Chapter 2: Responsibilities of Governing Bodies

Article 4: Subject institutions must put in place policies, strategies, and procedures that take into account the technical and human aspects of business continuity management, which is an integral part of risk management.

Article 5: The deliberative body and the executive body are collectively responsible for defining effective and comprehensive approaches to business continuity management. They are responsible for effectively managing business continuity, even in the event of outsourcing certain operations, and for developing and approving the appropriate policy to strengthen the resilience and continuity of the enterprise's activities in the event of major operational disruptions.

Article 6: The executive body must initiate, promote, and monitor business continuity management.

Article 7: Subject institutions must put in place an organization that informs the deliberative and executive bodies on the implementation of business continuity management, observed incidents, test results, and action plans to strengthen the institution's resilience and its ability to resume specific activities.

Article 8: The organization for business continuity management must be regularly re-evaluated by the risk management officer and examined independently by internal audit. The executive body is required to inform the deliberative body at least once a year regarding the assessment of the effectiveness of the measures in place.

Chapter 3: Requirement for a Business Continuity Policy

Article 9: Every subject institution must define a policy and implement strategies for the adequate management of its business continuity in the event of major operational disruption.

Article 10: The choice of business continuity strategy must result from the comparative analysis of different possible scenarios for business continuity management, developed based on the subject institution's strategy, its objectives, the anticipated evolution of its activities, its business relationships, its risk level, its preferred development axes, as well as its place in the financial system and its impact on the proper functioning of the latter.

Article 11: The business continuity management of a subject institution must be adapted to its risk profile and take into account its size, the scale and scope of its operations, as well as the risk it poses to the continuous functioning of the financial system and the security of depositors. The business continuity management policy must take into consideration new risks related to socio-economic evolutions at the national and international levels and cover the requirements inherent to outsourced activities.

Article 12: The strategy, policy, standards, and processes of business continuity management must be taken into account and implemented within the general framework of risk management and the execution of the subject institution's essential operations.

Chapter 4: Management of Major Operational Disruption Risk

Article 13: Subject institutions must integrate the risk of major operational disruption into their business continuity management approaches and determine response modes to major operational disruptions that could affect their operations.

Article 14: The anticipation of appropriate measures to continue or recover activities following a major operational disruption must be based on the specific characteristics and risk profile of the concerned subject institution.

Article 15: Subject institutions must define an organization capable of managing a crisis, from its occurrence to its resolution and return to normal, by setting up a crisis cell composed of decision-makers and intervention teams defined by theme, responsible for crisis management operations.

Article 16: Subject institutions must put in place an available and operational crisis communication strategy.

Article 17: For effective crisis management, subject institutions must anticipate reaction modes to disasters and specify criteria and responsibilities to ensure a return to normal under the best conditions, including:

  • Defining generic crisis management tasks to be performed;
  • Distributing tasks among the actors of the crisis organization;
  • Defining the criteria, conditions, and responsibilities to ensure a return to normal;
  • Drafting and validating crisis management manuals and procedures.

Chapter 5: Definition of Recovery Objectives

Article 18: Recovery objectives must serve as a reference basis for evaluating the effectiveness of business continuity management and allow achieving a sufficient level of resilience.

Article 19: The deliberative and executive bodies are responsible for establishing recovery objectives proportionate to the risk that the concerned subject institution represents for the functioning of the financial system as a whole, as well as for the security of depositors.

Article 20: Recovery objectives must include the continuation of the provision of essential services and, where appropriate, depending on the specific situation of the subject institution, meet requirements higher than those of other participants in the financial system.

TITLE II: METHODOLOGICAL PHASES

Chapter 6: Organization of the Business Continuity Management Framework

Article 21: Subject institutions must have a written, detailed, and tested business continuity plan. They must ensure the coherence and effectiveness of specific business continuity plans within the framework of a global plan that integrates the objectives defined by the executive body and validated by the deliberative body.

Article 22: The measures adopted by subject institutions within the framework of business continuity management must appear in the annual internal control and risk management report, in accordance with the provisions of Instruction No. 17 of the Central Bank of Congo relating to internal control.

Article 23: Subject institutions must define a unified framework for business continuity planning to ensure the overall coherence of the framework and its operational nature for all locations and lines of business.

Article 24: Subject institutions must designate a Business Continuity Officer and inform the Central Bank of Congo thereof. The officer must possess the required competencies to perform this activity. To guarantee the effectiveness of the steering of business continuity management, overall responsibility must be entrusted to a manager of the subject institution, who is a member of the executive body.

Article 25: The Business Continuity Officer is responsible for the administration of the plan under normal operating conditions, the activation of the crisis management process, the updating and monitoring of the execution of envisaged corrective actions, as well as the realization of training and testing campaigns for the plan.

Article 26: The Business Continuity Officer is required to:

  • Participate in the deployment of measures included in the business continuity management framework;
  • Take into account the results of business continuity plan tests;
  • Ensure the conformity of practices with regulatory requirements; and
  • Provide reporting on the progress of business continuity management to the executive body.

Article 27: The executive body must immediately inform the Central Bank of Congo of the triggering of the business continuity plan, the emergency plan, or the crisis management plan. The executive body is required to continuously inform the Central Bank of Congo of the developments of the crisis affecting the subject institution, its impact, the measures taken within the framework of the aforementioned plans to ensure the continuation or resumption of activity, as well as any difficulties encountered in the implementation of the business continuity plan.

Chapter 7: Content of the Business Continuity Policy

Article 28: The business continuity management policy must include impact analyses, a business recovery strategy, and business continuity plans.

Article 29: Impact analyses must allow for the identification of essential activities and services, the main dependency situations regarding internal and external sources to the subject institution, as well as the appropriate levels of resilience. To this end, impact analyses must take into account the risk map, provided for in Instruction No. 22 relating to risk management, which must be updated based on the results of said analyses. These analyses must allow for the evaluation of risks and the consequences of different disaster or major operational disruption scenarios on the bank's or financial institution's activities and its reputation.

Article 30: The recovery strategy must define, based on impact analyses, recovery objectives, and defined priorities, the minimum service level provided by the subject institution in the event of a disaster or major operational disruption, as well as the framework within which it will restore normal operating conditions.

Article 31: The subject institution's needs must be the subject of a functional and technical specification document allowing for the definition of backup technical solutions.

Article 32: The business continuity plan must provide in detail the formalized and documented indications on how to implement the recovery strategy, by establishing roles, defining responsibilities in the management of disasters and operational disruptions, and providing precise indications on succession, substitution, or delegation of powers plans in the event that the disaster or disruption has resulted in a change in the subject institution's chain of command.

Article 33: The business continuity plan must specify the scope of activities covered by the plan, the activities treated as priority in the event of major operational disruption, the residual risks not covered by the plan, the implementation deadlines for this plan, the formalization of procedures, as well as, where appropriate, a synthetic description of backup computer systems and the backup site(s).

Article 34: An effective business continuity device must rely on the following elements:

  • A crisis management organization with a Business Continuity Officer;
  • A written, detailed, tested, widely disseminated plan within the subject credit institution and regularly updated;
  • A backup strategy established based on the results of impact analyses on the subject institution's activities and the functioning of the financial system, and periodically tested;
  • A remote backup site located in a physical and technical environment distinct from the initial environment;
  • Rationalized human resource management;
  • A tested backup computer technical solution covering continuity needs.

Chapter 8: Impact Studies and Assessments

Article 35: Subject institutions must identify their points of fragility through internal controls and external audits in order to define and implement a plan of measures aimed at preventing or minimizing disasters and major operational disruptions and reducing the extent of residual risks to be covered in the business continuity plan.

Article 36: Subject institutions must establish the map and define disaster scenarios to be taken into account in their business continuity plan. To this end, they must:

  • Identify essential activities for their survival or the proper functioning of the financial system;
  • Identify threats weighing on these activities that could cause discontinuity;
  • Evaluate for each risk the probability of occurrence and potential impact, including the disaster evaluation scale, the disaster impact evaluation grid, the risk typology, and disasters;
  • Define the risk management strategy for each identified and characterized risk;
  • Define the assumptions for the development of their business continuity plan, taking into account the scale of disaster scenarios. The disaster map must take into account the risk map, provided for in Instruction No. 22 relating to risk management. The institution must ensure coherence between the two maps.

Article 37: The disaster map and scenarios must be regularly updated, particularly on the occasion of each significant change occurring in the life of the subject institution or its organization, particularly during the creation of new sites or locations and during the modification of existing infrastructure.

Article 38: Subject institutions must determine the impact of potential disasters on their activities and on the functioning of the financial system and specify a business continuity strategy that takes into account the defined stakes. The impact assessment on activities must be established based on:

  • The identification and classification of essential activities and functions as well as the risks weighing on each essential activity or function;
  • The validation of recovery or continuity objectives for each essential activity or function;
  • The determination of key processes and resources related to essential activities and functions in order to deduce degraded modes of operation;
  • The identification of specific failure points and internal and external dependencies;
  • The evaluation of the impacts of business interruption.

Article 39: The risk analysis on the activities and resources of the subject institution must be guided by the impact assessment and allow for the definition of business interruption risk reduction plans concerning the processes, activities, and resources identified as essential.

Chapter 9: Development of the Business Continuity Plan

Article 40: The development of the business operations plan consists of defining strategies for human resource management, personal and property security, as well as for outsourced services.

Article 41: The implementation of a business continuity management process must consist notably of:

  • Risk and vulnerability analysis;
  • Classification of essential activities and definition of functional needs;
  • Taking into account security stakes and the impacts of potential disasters on the subject institution's activity and on the financial sector;
  • Defining a business continuity strategy consistent with the subject institution's objectives;
  • The possible coverage of certain risks by appropriate insurance policies;
  • Updating, maintenance, testing, and evaluation of provided devices;
  • Pre-defined definition of responsibilities and procedures in case of emergency, notably through the establishment of a crisis cell and the definition of an emergency plan or crisis management plan;
  • The implementation of procedures allowing the subject institution to function in "degraded mode," taking into account regulatory imperatives;
  • Staff awareness and specific training of crisis management actors;
  • Impact assessment on the subject institution's activities.

Article 42: Subject institutions must include in their business continuity plan emergency communication protocols and procedures internally and towards all stakeholders, including international ones, in the event of major operational disruption.

Article 43: Subject institutions must define the modalities for rapid detection and evaluation of the crisis situation, alerting of concerned actors, and potential activation of the business continuity plan.

Article 44: Subject institutions must determine the tasks and their logical sequence, from the occurrence of a disaster to the decision to trigger or not the business continuity plan.

Article 45: Subject institutions must define the mode of alert reporting, the actors of the analysis and decision process, their roles and responsibilities, the disaster evaluation criteria, the steps and responsibilities in the implementation of the decision-making process for activating the business continuity plan, the modes of communication and interaction with public services responsible for handling crisis situations, and internal and external communication actions during the crisis.

BANQUE CENTRALE DU CONGO SUITE, PAGE II Article 46 Regulated establishments must validate and communicate internally and externally the trigger scheme for the business continuity plan.

Article 47 Regulated establishments must draft and validate "degraded mode" functional procedures for all essential processes identified during business impact analyses and essential functions analyses.

Article 48 Regulated establishments must implement the local and/or global business continuity strategy for essential processes.

Article 49 Regulated establishments must keep up to date the results of business impact analyses and essential functions analyses, the list of useful contacts, the contact details of all internal and external stakeholders, the inventory of essential resources, information on data backups, references of validated operational procedures, the damage and impact assessment matrix, initial safety instructions and emergency procedures, and the fact sheets for sites covered by the business continuity plan.

Chapter 10: Maintenance of the business continuity plan

Article 50 Regulated establishments must regularly assess their organization and the availability of human, real estate, technical, and financial resources in light of risks related to business continuity.

Article 51 Regulated establishments must ensure the proper deployment of the business continuity plan and its maintenance in operational condition.

Article 52 Regulated establishments must ensure the transfer and adoption, within their organization and among their personnel, of information, knowledge, and skills related to business continuity management through awareness, training, and communication actions.

563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd

BANQUE CENTRALE DU CONGO SUITE, PAGE 12

Article 53 Regulated establishments must design and implement an internal and external communication plan on business continuity management. When designing this program and these awareness, training, and communication actions, they must define:

  • the scope, objectives, and stakes;
  • the means necessary to achieve the set objectives;
  • the targets and modalities of the awareness program, including the frequency, type, and duration of actions.

Article 54 Regulated establishments must ensure that their business continuity plan remains operational and adapted to internal changes and the evolution of their environment.

Article 55 Regulated establishments must define the conditions for updating the business continuity plan and carry out the necessary operations to maintain it in operational condition.

Article 56 Regulated establishments must, on the one hand, detect inconsistencies and shortcomings in the established system and, on the other hand, complete and improve existing procedures, ensure that business continuity actors are trained and familiar with their roles and responsibilities in the development and implementation of the business continuity plan, and are capable of implementing it quickly and effectively.

Article 57 Regulated establishments must validate the conformity of business continuity management practices with the requirements defined by this Instruction and expressed needs. They are required to identify deviations from current reference frameworks, propose improvements to business continuity management, and develop an annual audit program for the business continuity plan.

563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd

BANQUE CENTRALE DU CONGO SUITE, PAGE 13

Chapter 11: Tests for evaluating business continuity management

Article 58 Regulated establishments must, at a periodicity appropriate to the risks and consequences of different major operational disruption scenarios, conduct an evaluation of their business continuity management systems regarding their capacity to withstand major operational disruptions.

Article 59 The scope and frequency of tests must be determined based on the essential nature of applications and functions for the regulated establishment concerned, as well as regarding its position in the banking or financial system and based on significant changes that have occurred in the national, regional, and international environment.

Article 60 Regulated establishments must, during tests of the business continuity plan, ensure in particular that:

  • the fallback site is located in a geographic area distinct from the primary location and does not use the same components as the primary site at the physical infrastructure level;
  • the alternative site has sufficient updated data, up-to-date equipment, and necessary systems to recover and maintain essential operations and services for a sufficient period of time;
  • the business continuity plan defines the transportation means and modalities for replacing personnel sufficient in terms of headcount and expertise to resume critical operations and services compatible with recovery objectives.

Article 61 The results of business continuity plan tests must be analyzed, and significant findings must be submitted to the deliberative body and the executive body within a reasonable time frame so that necessary corrective measures are implemented and the business continuity management system is updated.

563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd

BANQUE CENTRALE DU CONGO SUITE, PAGE 14

Chapter 12: Implementation of an IT disaster recovery plan

Article 62 Regulated establishments must define an organization and reaction mode capable of ensuring the operational status of the technical IT backup solution in the event of activation of the business continuity plan.

Article 63 Regulated establishments must clarify roles and responsibilities in the implementation of the IT disaster recovery plan and determine substitution or replacement personnel solutions with a definition and planning of their tasks.

Article 64 Regulated establishments are required to periodically test technical solutions and the IT disaster recovery plan to allow for their validation from a technical and organizational perspective, verify their ability to meet defined needs, and assess recovery time objectives. Regulated establishments must beforehand define the scope, extent, objectives, and conditions for carrying out the test.

Article 65 Regulated establishments must, in the absence of validation of the IT technical solution, gather all possible information to implement corrective measures that will render the backup solution operational.

TITLE III: FINAL PROVISIONS

Chapter 13: Miscellaneous Provisions

Article 66 Regulated establishments are required to ensure strict observance of the provisions of this Instruction.

563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd

BANQUE CENTRALE DU CONGO SUITE, PAGE 15

Article 67 Non-compliance with the provisions of this Instruction exposes offenders to sanctions provided for by legal and regulatory texts.

Article 68 Regulated establishments have a period of twelve months from the entry into force of this Instruction to comply with it.

Article 69 This Instruction enters into force on the date of its signature.

Done in Kinshasa, on 11 SEPT 2018

DEOGRAIS OMBIMWANA NYEMBO Governor

563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd

More like this from BCC

We email you every new BCC publication the day it's published.

Share