2018-09-11
Added · Updated
Instruction No. 36 establishes prudential rules for credit institutions and microfinance institutions in the Democratic Republic of Congo regarding business continuity management and the development of business continuity plans. It mandates that these entities define policies, strategies, and procedures to manage major operational disruptions, ensuring the protection of depositors and the stability of the financial system. The instruction requires the establishment of crisis management cells, impact analyses, and detailed recovery objectives, while assigning specific responsibilities to governing bodies, executive organs, and designated business continuity officers. It further stipulates that plans must be written, tested, and regularly updated, with immediate reporting obligations to the Central Bank of Congo in the event of a crisis.
The Central Bank of Congo,
Having regard to Law No. 005/2002 of May 7, 2002, relating to the constitution, organization, and functioning of the Central Bank of Congo, particularly Article 6 thereof;
Having regard to Law No. 003/2002 of February 2, 2002, relating to the activity and supervision of Credit Institutions, particularly Articles 11, 24, 25, 26, and 27 thereof;
Having regard to the Instructions of the Central Bank of Congo, particularly those Nos. 17, 21, and 22 relating respectively to internal control, governance, and risk management;
Decrees the prudential rules regarding business continuity management and the development of business continuity plans.
Article 1: The purpose of this Instruction is to clarify the general principles guiding credit institutions in the development of a business continuity plan in the event of major operational disruption.
Article 2: This Instruction applies to the following financial institutions, hereinafter referred to as "subject institutions":
Article 3: The terms used in this Instruction are defined in the Instruction relating to the terminology of the prudential regulation of the Central Bank of Congo applicable to Credit Institutions and Microfinance Institutions.
Article 4: Subject institutions must put in place policies, strategies, and procedures that take into account the technical and human aspects of business continuity management, which is an integral part of risk management.
Article 5: The deliberative body and the executive body are collectively responsible for defining effective and comprehensive approaches to business continuity management. They are responsible for effectively managing business continuity, even in the event of outsourcing certain operations, and for developing and approving the appropriate policy to strengthen the resilience and continuity of the enterprise's activities in the event of major operational disruptions.
Article 6: The executive body must initiate, promote, and monitor business continuity management.
Article 7: Subject institutions must put in place an organization that informs the deliberative and executive bodies on the implementation of business continuity management, observed incidents, test results, and action plans to strengthen the institution's resilience and its ability to resume specific activities.
Article 8: The organization for business continuity management must be regularly re-evaluated by the risk management officer and examined independently by internal audit. The executive body is required to inform the deliberative body at least once a year regarding the assessment of the effectiveness of the measures in place.
Article 9: Every subject institution must define a policy and implement strategies for the adequate management of its business continuity in the event of major operational disruption.
Article 10: The choice of business continuity strategy must result from the comparative analysis of different possible scenarios for business continuity management, developed based on the subject institution's strategy, its objectives, the anticipated evolution of its activities, its business relationships, its risk level, its preferred development axes, as well as its place in the financial system and its impact on the proper functioning of the latter.
Article 11: The business continuity management of a subject institution must be adapted to its risk profile and take into account its size, the scale and scope of its operations, as well as the risk it poses to the continuous functioning of the financial system and the security of depositors. The business continuity management policy must take into consideration new risks related to socio-economic evolutions at the national and international levels and cover the requirements inherent to outsourced activities.
Article 12: The strategy, policy, standards, and processes of business continuity management must be taken into account and implemented within the general framework of risk management and the execution of the subject institution's essential operations.
Article 13: Subject institutions must integrate the risk of major operational disruption into their business continuity management approaches and determine response modes to major operational disruptions that could affect their operations.
Article 14: The anticipation of appropriate measures to continue or recover activities following a major operational disruption must be based on the specific characteristics and risk profile of the concerned subject institution.
Article 15: Subject institutions must define an organization capable of managing a crisis, from its occurrence to its resolution and return to normal, by setting up a crisis cell composed of decision-makers and intervention teams defined by theme, responsible for crisis management operations.
Article 16: Subject institutions must put in place an available and operational crisis communication strategy.
Article 17: For effective crisis management, subject institutions must anticipate reaction modes to disasters and specify criteria and responsibilities to ensure a return to normal under the best conditions, including:
Article 18: Recovery objectives must serve as a reference basis for evaluating the effectiveness of business continuity management and allow achieving a sufficient level of resilience.
Article 19: The deliberative and executive bodies are responsible for establishing recovery objectives proportionate to the risk that the concerned subject institution represents for the functioning of the financial system as a whole, as well as for the security of depositors.
Article 20: Recovery objectives must include the continuation of the provision of essential services and, where appropriate, depending on the specific situation of the subject institution, meet requirements higher than those of other participants in the financial system.
Article 21: Subject institutions must have a written, detailed, and tested business continuity plan. They must ensure the coherence and effectiveness of specific business continuity plans within the framework of a global plan that integrates the objectives defined by the executive body and validated by the deliberative body.
Article 22: The measures adopted by subject institutions within the framework of business continuity management must appear in the annual internal control and risk management report, in accordance with the provisions of Instruction No. 17 of the Central Bank of Congo relating to internal control.
Article 23: Subject institutions must define a unified framework for business continuity planning to ensure the overall coherence of the framework and its operational nature for all locations and lines of business.
Article 24: Subject institutions must designate a Business Continuity Officer and inform the Central Bank of Congo thereof. The officer must possess the required competencies to perform this activity. To guarantee the effectiveness of the steering of business continuity management, overall responsibility must be entrusted to a manager of the subject institution, who is a member of the executive body.
Article 25: The Business Continuity Officer is responsible for the administration of the plan under normal operating conditions, the activation of the crisis management process, the updating and monitoring of the execution of envisaged corrective actions, as well as the realization of training and testing campaigns for the plan.
Article 26: The Business Continuity Officer is required to:
Article 27: The executive body must immediately inform the Central Bank of Congo of the triggering of the business continuity plan, the emergency plan, or the crisis management plan. The executive body is required to continuously inform the Central Bank of Congo of the developments of the crisis affecting the subject institution, its impact, the measures taken within the framework of the aforementioned plans to ensure the continuation or resumption of activity, as well as any difficulties encountered in the implementation of the business continuity plan.
Article 28: The business continuity management policy must include impact analyses, a business recovery strategy, and business continuity plans.
Article 29: Impact analyses must allow for the identification of essential activities and services, the main dependency situations regarding internal and external sources to the subject institution, as well as the appropriate levels of resilience. To this end, impact analyses must take into account the risk map, provided for in Instruction No. 22 relating to risk management, which must be updated based on the results of said analyses. These analyses must allow for the evaluation of risks and the consequences of different disaster or major operational disruption scenarios on the bank's or financial institution's activities and its reputation.
Article 30: The recovery strategy must define, based on impact analyses, recovery objectives, and defined priorities, the minimum service level provided by the subject institution in the event of a disaster or major operational disruption, as well as the framework within which it will restore normal operating conditions.
Article 31: The subject institution's needs must be the subject of a functional and technical specification document allowing for the definition of backup technical solutions.
Article 32: The business continuity plan must provide in detail the formalized and documented indications on how to implement the recovery strategy, by establishing roles, defining responsibilities in the management of disasters and operational disruptions, and providing precise indications on succession, substitution, or delegation of powers plans in the event that the disaster or disruption has resulted in a change in the subject institution's chain of command.
Article 33: The business continuity plan must specify the scope of activities covered by the plan, the activities treated as priority in the event of major operational disruption, the residual risks not covered by the plan, the implementation deadlines for this plan, the formalization of procedures, as well as, where appropriate, a synthetic description of backup computer systems and the backup site(s).
Article 34: An effective business continuity device must rely on the following elements:
Article 35: Subject institutions must identify their points of fragility through internal controls and external audits in order to define and implement a plan of measures aimed at preventing or minimizing disasters and major operational disruptions and reducing the extent of residual risks to be covered in the business continuity plan.
Article 36: Subject institutions must establish the map and define disaster scenarios to be taken into account in their business continuity plan. To this end, they must:
Article 37: The disaster map and scenarios must be regularly updated, particularly on the occasion of each significant change occurring in the life of the subject institution or its organization, particularly during the creation of new sites or locations and during the modification of existing infrastructure.
Article 38: Subject institutions must determine the impact of potential disasters on their activities and on the functioning of the financial system and specify a business continuity strategy that takes into account the defined stakes. The impact assessment on activities must be established based on:
Article 39: The risk analysis on the activities and resources of the subject institution must be guided by the impact assessment and allow for the definition of business interruption risk reduction plans concerning the processes, activities, and resources identified as essential.
Article 40: The development of the business operations plan consists of defining strategies for human resource management, personal and property security, as well as for outsourced services.
Article 41: The implementation of a business continuity management process must consist notably of:
Article 42: Subject institutions must include in their business continuity plan emergency communication protocols and procedures internally and towards all stakeholders, including international ones, in the event of major operational disruption.
Article 43: Subject institutions must define the modalities for rapid detection and evaluation of the crisis situation, alerting of concerned actors, and potential activation of the business continuity plan.
Article 44: Subject institutions must determine the tasks and their logical sequence, from the occurrence of a disaster to the decision to trigger or not the business continuity plan.
Article 45: Subject institutions must define the mode of alert reporting, the actors of the analysis and decision process, their roles and responsibilities, the disaster evaluation criteria, the steps and responsibilities in the implementation of the decision-making process for activating the business continuity plan, the modes of communication and interaction with public services responsible for handling crisis situations, and internal and external communication actions during the crisis.
BANQUE CENTRALE DU CONGO SUITE, PAGE II Article 46 Regulated establishments must validate and communicate internally and externally the trigger scheme for the business continuity plan.
Article 47 Regulated establishments must draft and validate "degraded mode" functional procedures for all essential processes identified during business impact analyses and essential functions analyses.
Article 48 Regulated establishments must implement the local and/or global business continuity strategy for essential processes.
Article 49 Regulated establishments must keep up to date the results of business impact analyses and essential functions analyses, the list of useful contacts, the contact details of all internal and external stakeholders, the inventory of essential resources, information on data backups, references of validated operational procedures, the damage and impact assessment matrix, initial safety instructions and emergency procedures, and the fact sheets for sites covered by the business continuity plan.
Chapter 10: Maintenance of the business continuity plan
Article 50 Regulated establishments must regularly assess their organization and the availability of human, real estate, technical, and financial resources in light of risks related to business continuity.
Article 51 Regulated establishments must ensure the proper deployment of the business continuity plan and its maintenance in operational condition.
Article 52 Regulated establishments must ensure the transfer and adoption, within their organization and among their personnel, of information, knowledge, and skills related to business continuity management through awareness, training, and communication actions.
563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO SUITE, PAGE 12
Article 53 Regulated establishments must design and implement an internal and external communication plan on business continuity management. When designing this program and these awareness, training, and communication actions, they must define:
Article 54 Regulated establishments must ensure that their business continuity plan remains operational and adapted to internal changes and the evolution of their environment.
Article 55 Regulated establishments must define the conditions for updating the business continuity plan and carry out the necessary operations to maintain it in operational condition.
Article 56 Regulated establishments must, on the one hand, detect inconsistencies and shortcomings in the established system and, on the other hand, complete and improve existing procedures, ensure that business continuity actors are trained and familiar with their roles and responsibilities in the development and implementation of the business continuity plan, and are capable of implementing it quickly and effectively.
Article 57 Regulated establishments must validate the conformity of business continuity management practices with the requirements defined by this Instruction and expressed needs. They are required to identify deviations from current reference frameworks, propose improvements to business continuity management, and develop an annual audit program for the business continuity plan.
563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO SUITE, PAGE 13
Chapter 11: Tests for evaluating business continuity management
Article 58 Regulated establishments must, at a periodicity appropriate to the risks and consequences of different major operational disruption scenarios, conduct an evaluation of their business continuity management systems regarding their capacity to withstand major operational disruptions.
Article 59 The scope and frequency of tests must be determined based on the essential nature of applications and functions for the regulated establishment concerned, as well as regarding its position in the banking or financial system and based on significant changes that have occurred in the national, regional, and international environment.
Article 60 Regulated establishments must, during tests of the business continuity plan, ensure in particular that:
Article 61 The results of business continuity plan tests must be analyzed, and significant findings must be submitted to the deliberative body and the executive body within a reasonable time frame so that necessary corrective measures are implemented and the business continuity management system is updated.
563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO SUITE, PAGE 14
Chapter 12: Implementation of an IT disaster recovery plan
Article 62 Regulated establishments must define an organization and reaction mode capable of ensuring the operational status of the technical IT backup solution in the event of activation of the business continuity plan.
Article 63 Regulated establishments must clarify roles and responsibilities in the implementation of the IT disaster recovery plan and determine substitution or replacement personnel solutions with a definition and planning of their tasks.
Article 64 Regulated establishments are required to periodically test technical solutions and the IT disaster recovery plan to allow for their validation from a technical and organizational perspective, verify their ability to meet defined needs, and assess recovery time objectives. Regulated establishments must beforehand define the scope, extent, objectives, and conditions for carrying out the test.
Article 65 Regulated establishments must, in the absence of validation of the IT technical solution, gather all possible information to implement corrective measures that will render the backup solution operational.
TITLE III: FINAL PROVISIONS
Chapter 13: Miscellaneous Provisions
Article 66 Regulated establishments are required to ensure strict observance of the provisions of this Instruction.
563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO SUITE, PAGE 15
Article 67 Non-compliance with the provisions of this Instruction exposes offenders to sanctions provided for by legal and regulatory texts.
Article 68 Regulated establishments have a period of twelve months from the entry into force of this Instruction to comply with it.
Article 69 This Instruction enters into force on the date of its signature.
Done in Kinshasa, on 11 SEPT 2018
DEOGRAIS OMBIMWANA NYEMBO Governor
563, Boulevard Colonel Tshatshl - Kinshasa - Gombe Email: sgouvemeur@bcc.cd/svicegouve@bcc.cd/cabgouv@bcc.cd - Website: http://www.bcc.cd
More like this from BCC
We email you every new BCC publication the day it's published.