2023-12-29

Added · Updated

Instruction No. 78/AMF-UMOA/2023 on the Internal Control and Risk Management Framework of the Central Securities Depository / Settlement Bank (CSD/SB)

Instruction No. 78/AMF-UMOA/2023 establishes the internal control and risk management framework for Central Securities Depositories and Settlement Banks (CSD/SBs) within the West African Monetary Union. It mandates the implementation of a three-line defense model, defines the responsibilities of the governing and executive bodies, and requires the establishment of an independent compliance function with specific charter, resource, and reporting obligations. The instruction further stipulates that significant compliance anomalies must be documented and reported to both the CSD/SB's governing body and the AMF-UMOA.

Autorite des Marches Financiers de l'UMOA logo

Senegal

Autorite des Marches Financiers de l'UMOA

Click to view thumbnail

AMF-UMOA WEST AFRICAN MONETARY UNION FINANCIAL MARKETS AUTHORITY The Secretary General

INSTRUCTION NO. 78/AMF-UMOA/2023 ON THE INTERNAL CONTROL AND RISK MANAGEMENT FRAMEWORK OF THE CENTRAL SECURITIES DEPOSITORY / SETTLEMENT BANK (CSD/SB)

The West African Monetary Union Financial Markets Authority,

Having regard to the Revised Treaty of the West African Monetary Union (UMOA) of July 12, 2019, which entered into force on October 1, 2022, modifying the name of the Regional Council for Public Savings and Financial Markets (CREPMF) to the West African Monetary Union Financial Markets Authority (AMF-UMOA);

Having regard to the Convention of July 3, 1996 establishing the Regional Council for Public Savings and Financial Markets, particularly its Annex on the composition, organization, functioning, and powers of the Regional Council for Public Savings and Financial Markets;

Having regard to General Regulation No. 001/97 of November 28, 1997, relating to the organization, functioning, and control of the regional financial market, particularly Articles 10 and 16;

Having regard to Instruction No. 3/97 of November 29, 1997, relating to the authorization of the Central Securities Depository/Settlement Bank;

Having regard to Decision No. 004 of April 29, 2021/CM/UMOA appointing the President of the Regional Council for Public Savings and Financial Markets;

Having regard to the deliberations of the AMF-UMOA at its 50th extraordinary session held on September 24, 2021 via videoconference;

Having regard to the deliberations of the AMF-UMOA at its 98th ordinary session held on December 23, 2023, in Cotonou, Republic of Benin;

HEREBY DECIDES:


2/24 Instruction No. 78/2023/AMF-UMOA

TITLE 1. GENERAL PROVISIONS

Article 1 Definitions For the purposes of this Instruction, the following terms shall mean:

a) Internal Audit: An independent and objective activity that provides an organization with assurance on the degree of control over its operations, offers advice to improve them, and contributes to creating added value. Internal audit must evaluate governance, risk management, and control processes and contribute to their improvement based on a systematic, methodical, and risk-based approach.

b) Risk Appetite: The level and type of risk that the CSD/SB is willing to assume in its exposures and activities to achieve its strategic objectives and obligations.

c) Internal Audit and Compliance Charters: Documents that define the positioning of the internal audit and compliance functions within the approved structure and specify the organization, powers, responsibilities, and operating procedures of said functions.

d) Risk Map: A synthetic and visual representation of the CSD/SB's risks. It thus serves as a tool for highlighting priority risks. The risk map is established based on a rigorous system for identifying and evaluating risks inherent to the CSD/SB from internal factors (business and activities, organizational changes, etc.) and external factors (economic conditions, technological progress, legislative and regulatory changes, etc.).

e) Audit Committee: A committee established by the deliberative body to assist it in exercising its missions, particularly to verify the reliability and transparency of financial information, assess the relevance of accounting methods as well as the quality of the internal control framework and the risk management framework, evaluate the audit strategy, and propose improvement avenues where appropriate.

f) Internal Control: Measures put in place by the executive bodies with the aim of ensuring that:

  • the objectives set by the CSD/SB are realistic and achieved;
  • resources are used economically and efficiently, and risks are adequately controlled;
  • assets are protected;
  • financial and management information is complete and reliable;
  • laws and regulations as well as internal policies, plans, rules, and procedures are respected.

g) Control Cycle: The interval during which all activities and entities of the CSD/SB will have been verified at least once by the internal audit function.


3/24 Instruction No. 78/2023/AMF-UMOA

h) Central Securities Depository / Settlement Bank or CSD/SB: The company authorized, by approval from the AMF-UMOA, to exercise, throughout the territory of the Union States, the following activities: the book-entry conservation and circulation of securities, the management of the settlement/delivery cycle, and the settlement of net balances related to stock exchange transactions.

i) Internal Control Framework (ICF): The set of rules, methods, and control measures governing the organizational and operational structure of the CSD/SB. It includes reporting processes and control functions.

j) Control Functions: The functions independent of operational management, whose role is to provide objective assessments regarding the quality and effectiveness of the ICF, governance frameworks, non-compliance risk management, in order to facilitate the control of activities and risks incurred. They include in particular the internal audit function, the risk management function, and the compliance function.

k) Risk Management: The set of strategies, policies, and procedures put in place so that any significant risk and associated risk concentration are detected, measured, limited, controlled, and mitigated, and reported on in a timely and exhaustive manner.

l) Current Standards: The set of rules governing the exercise of the CSD/SB's activities, including:

  • legal and regulatory provisions;
  • internal codes of conduct and ethics;
  • principles for Market Infrastructures issued by the Basel Committee and the International Organization of Securities Commissions (IOSCO).

m) Deliberative Body: The Board of Directors in joint-stock companies or the collegiate body in companies constituted under another form. It is invested with all powers to act in all circumstances on behalf of the CSD/SB, within the limits of the corporate purpose and powers reserved for the General Meeting.

n) Executive Body: Any committee or structure that contributes to the day-to-day management of the CSD/SB and ensures the effective implementation of the activity orientation defined by the deliberative body.

o) Audit Trail: A set of permanent internal procedures to ensure the traceability of operations, to justify any information with an original document from which it must be possible to trace back, through an uninterrupted path, to the summary document and vice versa, and to explain the evolution of balances from one accounting closing to another, thanks to the retention of movements affecting accounting items.

p) Compliance Risk: The risk of judicial, administrative, or disciplinary sanction, financial loss, or reputational damage that the CSD/SB may suffer due to non-observance of the current standards governing the exercise of its activities.


4/24 Instruction No. 78/2023/AMF-UMOA

q) Operational Risk: The risk of losses resulting from deficiencies or failures attributable to processes, people, internal systems, or external events. This notion includes legal risk but excludes strategic and reputational risks.

r) Strategic Risk: The risk that the CSD/SB's business strategies are ineffective, not well implemented, or not adapted to changes affecting the commercial context.

Article 2 Purpose This Instruction sets out the rules regarding the internal control framework applicable to the CSD/SB, the objective of which is to:

  • verify that the operations carried out, the organization, and internal procedures are in compliance with current legislative and regulatory provisions, professional and ethical standards and practices, as well as the orientations of the deliberative and executive bodies;
  • ensure that the orientations, instructions, and limits set by the deliberative body regarding risks are strictly respected;
  • ensure the reliability of accounting and financial information, particularly regarding the conditions for collecting, evaluating, recording, storing, and making this information available.

It also sets out the rules regarding risk management applicable to the CSD/SB, as defined in Article 1 of said Instruction.

Article 3 Scope of Control The corporate governance of the CSD/SB integrates an ICF on which the sound and prudent management of the entity must be based. This framework includes:

  • the monitoring of the reliability and integrity of financial and operational information and the means used to identify, evaluate, classify, and report this information;
  • the verification of the compliance of operations carried out and the organization with current legislative, regulatory, and prudential provisions, professional and ethical standards and practices, orientations, and decisions of the deliberative and executive bodies, particularly regarding risks, powers, and signatures, as well as internal procedures;
  • the monitoring and evaluation of the effectiveness of the entity's risk management framework.

The organization of internal control must be based on the control environment, risk assessment, control activities, information and communication, and monitoring.


5/24 Instruction No. 78/2023/AMF-UMOA

Article 4 Control Environment The deliberative body must ensure the establishment of an adequate control environment, which constitutes the framework and structure necessary for achieving the objectives of the internal control framework.

An adequate control environment implies:

  • the commitment of governance bodies to promoting integrity and ethical values within the CSD/SB;
  • the establishment of a culture that highlights, at all levels of the organization, the importance of internal control;
  • effective involvement of the deliberative body in monitoring the components of the internal control framework;
  • a clear and coherent definition of missions, functions, and responsibilities, including explicit delegations of powers regarding limits;
  • the existence of competent personnel and a human resources management framework allowing the CSD/SB to attract, develop, and maintain skills linked to its objectives;
  • strong adherence by personnel to the control requirements assigned to them as well as the duty to account for their responsibilities in this matter;
  • supervision by each hierarchical manager of the effective application of internal control procedures by their subordinates;
  • the definition of qualitative criteria by the deliberative and executive bodies of the CSD/SB to measure and evaluate the effectiveness of the Internal Control Framework.

Article 5 The Lines of Defense of the ICF The ICF is organized to provide objective assessments of the CSD/SB's situation, risk control, and the compliance of its functioning with current rules and procedures. It includes:

  • permanent first-level control, which corresponds to all controls carried out by operational units and their hierarchy in the context of processing daily operations, constituting the first line of defense;
  • permanent second-level control, which corresponds to controls executed by support functions independent of operational units, forming the second line of defense represented by compliance and risk management functions;
  • periodic control, which corresponds to post-facto controls carried out within the framework of an audit plan developed from a risk map, constituting the last line of defense represented by the internal audit function. The audit plan developed using the risk-based approach must be realistic and flexible to allow for

6/24 Instruction No. 78/2023/AMF-UMOA

respect of the control cycle and the handling of unforeseen activities. It must regularly be updated to respond to changes in the internal and external environment of the CSD/SB.

Article 6 Responsibility of the Deliberative Body The deliberative body is ultimately responsible for the existence of an internal control framework within the CSD/SB as well as the proper application of the ICF to the entire organization of the approved structure. It is required to:

  • define and validate, at an appropriate periodicity, the acceptable level of risk to which the CSD/SB is exposed, particularly by setting acceptable limits for counterparty, liquidity, and market risks, as well as by putting in place appropriate frameworks to manage operational and compliance risks;
  • ensure the establishment and updating of an organization, written internal control policies, and procedures for the sound and prudent management of the CSD/SB's activities;
  • ensure the separation of incompatible tasks, particularly decision-making, asset custody, recording, and control functions;
  • ensure that control functions have appropriate means to execute their missions with full independence.

Article 7 Audit Committee The minimum prerogatives of the Audit Committee consist of:

  • examining the effectiveness of the ICF put in place to identify, evaluate, manage, and control financial and non-financial risks;
  • evaluating the internal audit policy and the control cycle, including the escalation policy upon the materialization of significant risks;
  • participating in the selection of Statutory Auditors and examining the conclusions of their work, in accordance with legal and regulatory provisions;
  • analyzing the compliance with the application of ethical and accounting principles with current professional standards and practices;
  • thoroughly examining annual summary statements before their presentation to the deliberative bodies;
  • providing governance bodies with reasonable assurance regarding the quality and effectiveness of the internal control framework, governance frameworks, and risk management framework to facilitate their control of the CSD/SB's activities and risks incurred.

7/24 Instruction No. 78/2023/AMF-UMOA

It also makes proposals to said bodies to strengthen the effectiveness of these systems and frameworks.

Article 8 Responsibilities of the Executive Body The executive body is required to put in place an ICF in line with best practices and to monitor its adequacy and effectiveness. The ICF must be adapted to the CSD/SB's risk profile.

The executive body ensures that policies and procedures are developed and effectively applied by persons with the necessary competence in this area and that all concerned persons understand and assume their responsibilities in this regard. It defines escalation criteria in response to the materialization of risks and ensures the implementation of appropriate measures.

It must in particular:

  • ensure the proper functioning of internal control and risk management frameworks and take necessary measures to remedy, in a timely manner, any deficiency or insufficiency identified;
  • inform control functions, in a timely manner, of all new developments, initiatives, projects, products, and operational changes as well as related risks;
  • ensure that appropriate measures are taken within the set deadlines to implement all corrective actions arising from recommendations of internal audit, Statutory Auditors, or the AMF-UMOA;
  • promote the independence of control functions and make available the necessary resources to carry out their missions;
  • regularly report to the deliberative body on the effectiveness of the internal control framework.

Article 9 Personnel Obligations Each member of the CSD/SB's personnel must:

  • diligently perform all control activities assigned to them;
  • have access to all necessary information to establish, operate, and monitor the internal control framework.

8/24 Instruction No. 78/2023/AMF-UMOA

TITLE 2. COMPLIANCE MANAGEMENT

Article 10 Characteristics of Compliance Policy The CSD/SB must adopt a compliance policy that, in particular:

  • ensures respect for the fundamental principles set by the deliberative body;
  • establishes the compliance function within the CSD/SB;
  • prescribes the development of a compliance charter;
  • specifies the fundamental aspects of compliance risk;
  • establishes the responsibilities of governance bodies in implementing the compliance risk management framework;
  • institutes a continuous training program for employees and all those responsible for implementing and monitoring the compliance policy.

Article 11 Compliance Charter The compliance charter must in particular:

  • state the objectives of the compliance function, establish its independence, and define its responsibilities and competencies;
  • clearly describe the relationships between the compliance function and other control functions and services of the CSD/SB that perform tasks related to its responsibilities;
  • grant the compliance function the right to communicate with any member of personnel and to access any physical or electronic file necessary for the exercise of its responsibilities;
  • confer upon the compliance function the power to initiate investigations;
  • formalize the tasks and obligations of the compliance function that can be delegated to other services and functions of the CSD/SB or outsourced to external providers;
  • define the conditions under which the compliance function may resort, if necessary, to external experts.

The compliance charter must reflect developments in current standards. The CSD/SB is required to update it as soon as possible to take these changes into account.

Any project to outsource the compliance function must be approved by the deliberative body and submitted for authorization to the AMF-UMOA before implementation.


9/24 Instruction No. 78/2023/AMF-UMOA

Article 12 Independence The compliance function must be independent of the units it controls. To ensure the independence of this function, the executive body must ensure the establishment of an organizational framework free from conflicts of tasks and functions. Furthermore, the resources dedicated to it must not be in a situation of conflict of interest.

The compliance function must have access to the deliberative and executive bodies to report any irregularity observed or potential breach.

Article 13 Resources The compliance function must have the human resources necessary to carry out its missions. It must be adapted to the size of the CSD/SB, the nature and complexity of its activities, as well as its risk profile.

The CSD/SB must designate a head of the function responsible for coordinating the organization-wide management of compliance risk as well as supervising the function's activities. The head of the compliance function must have proven experience in audit and compliance.

Article 14 Competence The human resources assigned to the compliance function must possess a high level of knowledge of the CSD/SB's activities and the standards applicable to it.

The CSD/SB must take provisions to ensure that these human resources keep their knowledge of said standards up to date.

Article 15 General Responsibilities The compliance function is responsible for assisting the executive body in identifying and diligently managing any risk of non-compliance by the CSD/SB with the obligations imposed by current standards governing the exercise of its activities.

Article 16 Specific Responsibilities The specific responsibilities of the compliance function consist in particular of:

  • identifying and communicating to all concerned personnel the current standards governing the exercise of the CSD/SB's activities;
  • proactively identifying, evaluating, and managing compliance risks, including during the development of new products or markets, activities, or issuer and member relations with the CSD/SB's services.

Furthermore, if the CSD/SB has a New Products or Markets Committee, the compliance function must be represented there.


10/24 Instruction No. 78/2023/AMF-UMOA

The compliance function must also:

  • centralize and analyze all breaches of current standards and the compliance policy;
  • recommend corrective measures to remedy identified breaches and insufficiencies;
  • monitor the implementation of all its recommendations;
  • evaluate the adequacy of the compliance policy, with regard to developments in the CSD/SB's activities, current standards, and based on identified insufficiencies. It must, where appropriate, formulate amendment proposals;
  • ensure diligent implementation of the compliance policy. The compliance function must ensure that the rules established in the compliance policy are translated into procedures, compliance manuals, and internal controls for areas directly falling under the compliance function. Areas of intervention directly falling under the compliance function concern in particular the fight against money laundering and terrorist financing as well as the protection of the interests of issuers and investors.

Furthermore, other prerogatives compatible with its missions may be entrusted to it, including ensuring liaison with external regulatory and standardization bodies.

The compliance function must be involved and consulted prior to the establishment of internal control procedures.

It must permanently ensure that the CSD/SB's compliance policy is respected at all levels of the organization, including:

  • Raising Awareness and Training Personnel: The compliance function must initiate actions to raise awareness and train personnel on the importance of adopting current standards and respecting the compliance policy. It establishes and implements, for this purpose, a training program for personnel.
  • Documenting its Work: The compliance function is required to document all its work to guarantee the traceability of its interventions and conclusions.

Article 17 Detection of Compliance Anomalies All significant compliance anomalies and deficiencies that would constitute a breach of AMF-UMOA regulatory provisions must be documented and reported in a specific detailed report addressed to the CSD/SB's deliberative body and to the AMF-UMOA.

Reports from the compliance function containing findings implicating management cannot be modified by the latter.


11/24 Instruction No. 78/2023/AMF-UMOA

However, the persons implicated may formulate observations on the findings recorded. The observations form


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 58,032-character original (41% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from AMF-UMOA

We email you every new AMF-UMOA publication the day it's published.

Share