2007-06-10
Added · Updated
The Central Bank of Jordan mandates that banks implement minimum internal control measures across ten specific areas, including Board and Executive Management duties, organizational structure, internal audit, risk management, financial systems, information technology, and physical security. Banks are required to establish independent risk and audit functions, maintain accurate financial records compliant with International Financial Reporting Standards, and ensure the confidentiality and integrity of information systems. The instructions further require banks to adopt specific physical security protocols, such as dual control for vaults and continuous video surveillance with one-year retention periods.
1 10/1/6066 24/5/1428 H 10/6/2007 G INSTRUCTIONS OF INTERNAL CONTROL SYSTEMS NO (35/2007) ISSUED BY THE CENTRAL BANK OF JORDAN PURSUANT TO THE STIPULATIONS OF ARTICLE (45/a) OF THE CENTRAL BANK’S LAW AND ARTICLE (99/b) OF THE BANKING LAW Listed here below are the minimum control measures required to ascertain that the Bank’s Management carries out the proper control over the Bank’s activities. FIRST: The following words mentioned in these instructions shall have the following meanings:
2 SECOND: Duties of the Board of Directors In addition to what the relative legislation provided for, the Bank’s Board of Directors must ensure the existence of adequate and effective internal controls, supervision regulations and must continuously follow it up through, as a minimum, pursuing and observing the following controls:
3 2. To prepare and develop the work procedures in a manner that ensures defining, measuring, controlling and supervising the risks that the bank encounters and to implement such procedures. 3. To prepare the financial statements and the closing accounts. 4. To prepare an organizational structure in accordance with Item (Four) and to ensure adherence to it after it is approved by the Board of Directors. 5. To prepare an annual budget to be approved by the Board of Directors and to report performance periodically to the Board of Directors illustrating the actual performance deviation from the projection. 6. To set-up adequate internal control policies and to implement them after they are approved by the Board of Directors. 7. To execute the duties according to the authorized powers. 8. To accomplish the effectiveness of the internal control systems and to report, at least annually, to the Board of Directors about the implementation and effectiveness of the systems 9. To set-up the procedures that guarantee the assessment of the capital adequacy and to report periodically to the Board of Directors in that regard. 10.To provide the external and internal control entities, such as the supervisory authorities, internal and external auditors and any other relevant entities, at the time specified by such entities, with the information and statements so required which are necessary to carry out its tasks in an optimal manner. 11.The annual report must include a statement about the executive management’s responsibility for providing internal control systems that guarantees the quality and transparency of the published information and data. 12. To articulate a bank’s Code of Conduct, get it approved by the Board of Directors and circulate it among all administrative levels at the bank. 13. To develop the skills and professional behavior of the bank’s employees up to par with the latest benchmarks and requirements
4 FOURTH: The Organizational Structure and Job Description At a minimum, the bank’s management must prepare a detailed, clear and flexible organizational structure that can be implemented and a comprehensive job description comprising of the following::
5 FIFTH: Internal Audit Administration The bank must abide by creating an independent internal audit administration that reports directly to the Audit Committee (constituted in accordance with the stipulations of Article (32) of the Banking Law) (or its equivalent in respect of the foreign banks branches) to whom periodical reports shall be made. The audit administration’s tasks shall be as follows, at a minimum.
6 SIXTH: Risk Management Assessment and risk management are deemed to be the responsibility of each of the bank’s units according to the unit’s positions and objectives , the bank must, as a minimum, abide by the following:
7 3. To ascertain, before introducing any new (product/operation/system) that it is compatible with the overall policy of strategic development; that all risks involved including the operational risks have been determined; that the new controlling measures and the procedures or the amendments that it has undergone have been done in conformity with the risk limits acceptable to the bank. 4. To form an independent committee for risk management emanating from the Board of Directors whose membership may include some of the higher executive management members and shall be charged, at the least, with the following: a- To review the risk management strategy being approved by the Board of Directors and to continuously assess its effectiveness to ascertain its conformity with the variables. b- To ascertain the availability of policies, framework, programs, and the tools necessary for risk management, to review it at least annually to ascertain its effectiveness and to amend it if necessary. c- To report periodically to the Board of Directors showing the compatibility extent of the existing risks with the adopted policies and the acceptable levels of risks specified therein in a manner that enables the Board to make the proper decisions. d- To supervise the development of the database necessary for risk management. e- To discuss the risk management reports. f- To ascertain the existence of a business continuity plan and to examine it periodically. 5. The imperativeness of using modern information systems for risk management that guarantee the availability of quality information about the risks that the bank encounters. SEVENTH: The Bank’s relationship with the External Auditor. In addition to the Stipulations of the Banking Law and any other stipulations provided for under any relevant legislation, the bank must abide by the following, as a minimum:
8 a- To provide the Board of Directors with a detailed report showing all weaknesses in the accounting systems, internal supervision and any other issues of a negative effect that the auditor became cognizant of during the audit process. b- To verify the accuracy and integrity of the data presented to the auditor during the audit process. c- To provide the Central Bank with copies of any reports that the external auditor presents to the bank within the audit mandate that the auditor was assigned for. 2. To obtain the prior approval of the Audit Committee before entering into an agreement with the external auditor to offer any non audit services in conformity with the Audit Profession Practice Law and the instructions issued in its pursuance provided such services are declared. EIGHTH: Financial and Accounting Systems Requirements The bank must have the following:
9 8. Proper supervisory systems that encompass the entire bank’s systems to guarantee that each of the bank’s transactions has been duly carried out whereby: a- It is consistent with legislation and it is accurate. b- It is executed pursuant to the concerned unit’s work guide. c- It is executed by the authorized person. d- It is documented and kept in the proper registers in accordance with the legislation in force. NINTH: Information Management and the related Technology At a minimum, the internal control systems must guarantee the effectiveness and integrity of information management and the related technology at the bank of the following issues, at a minimum:
10 6. To create the required principles and standards including the “Code of Conduct of Information Security and Protection” and to constantly engage in educating and augmenting the awareness of the bank’s staff within such framework. 7. To create the proper administrative organization and mechanism that endeavor to determine, measure, control and supervise the information risks and the related technology within the strategic planning framework and the medium and short-term planning for risks. 8. To create the proper mechanisms that enable the continuous supervision and measurement of performance of the information management and the related technology to ascertain the quality of services presented (whether presented by the internal units or by external parties) to the various bank’s units and to ascertain that such services are at the required level to realize the bank’s objectives efficiently and effectively. 9. To obtain assessment reports (risk – control) of the information and the related technology from independent supervisory entities, such as, the internal audit, external audit and the Central Bank and to be committed to remedy the points of weakness and to obtain feedbacks in that regard for the purpose of enhancing and development, including the supervisors’ authorities inspection reports in that regard. 10.To set-up the proper controls to ensure, at the least, the following: a- That developing/purchasing the application programs is done competently and effectively where such programs satisfy the objectives and work requirements of the bank’s units. b- That purchasing and operating the information technology infra-structure is competently and effectively done where it supports such structure and satisfies the objectives and work requirements of the bank’s units. c- The examination of the programs and infra-structure before operating same, to ascertain the extent of its adequacy, reliability, and integrity that leads to the required purpose thereof and which realizes the bank’s objectives. d- The integrity of the programs and infra-structure upon conducting any alteration thereon, where the alterations are accepted by its proprietary by virtue of duly documented acceptances. e- The quality of the services presented by external parties and the mechanism of presentation from the aspect of maintaining the confidentiality, accuracy, availability, and integrity conditions where such conditions are controlled through duly documented agreements. f- The security conditions of the various systems and the data related thereto from the aspect of protecting same from illegal alteration (unauthorized).
11 g- The treatment of problems and events that affect the information and the related technology negatively from the aspect of creating the mechanisms that guarantee the discovery, recording, and the making of the proper decision to overcome such events. h- The adequacy, accuracy, and validity of the entered, treated, and extracted data from the various programs and systems; to ascertain the continuity of up-dating the data; to have backup thereof; to check its reliability and maintaining the same in a manner that minimizes the risks that may negatively impact it. TENTH: Banks’ Security and Safety Requirements The bank must abide by the necessary security and safety requirements where it shall comprise, at the least, of the following:
12 8. To insure all the bank’s assets against any risk such assets may be subjected to. ELEVENTH: The bank must provide the Central Bank with the following:
13 8. Detailed report clarifying the circumstances of any embezzlement, forgery, theft, fraud or major shortage in the assets with an illustration of the procedures that the bank is taking to recover its rights and to guarantee the non-recurrence of such issues in the future. TWELVETH: The following instructions shall be deemed to be an integral part of these instructions:
14 FOURTEENTH: These instructions shall be operational with effect from their respective dates and the following memoranda and circulars shall be considered as repeal. Serial No. Memorandum / Circular Date Subject 1 Memorandum (22/75) 13/2/1975 Notification about embezzlement incidents 2 Memorandum (105/79) 13/5/1979 Debts write-off 3 Memorandum (88/80) 21/6/1980 Branches Internal Auditors 4 Memorandum (30/81) 4/2/1981 Security Procedures (Night guards, Alarm Devices…) 5 Memorandum (205/82) 7/11/1982 Judicial Disputes 6 Circular (7030/7424) 26/3/1988 Internal Audit Departments and its Staff 7 Circular (7030/6591) 18/3/1989 Presenting Inspection Reports to the Board of Directors 8 Circular (7030/3293) 10/2/1991 Augmentation of Internal Controlling Means 9 Circular (7030/14883) 29/7/1991 Provision of Board of Directors Minutes of Meetings to the Central Bank 10 Circular (7100/16779) 19/8/1991 Budgets 11 Circular (7136/23890) 17/11/1991 Shareholders Data 12 Memorandum (3/92) 4/1/1992 Consultation with the Central Bank upon appointing a General Manager or Deputy General Manager 13 Circular (7030/11146) 9/5/1993 Provision of Information about employees in the Inspection / Internal Audit Department to the Central Bank 14 Circular (7136/17828) 27/7/1994 Shareholders Data 15 Circular (7030/22563) 22/9/1994 Notification about embezzlement incidents 16 Circular (7030/23287) 12/9/1995 Rectification of Violations and Comments mentioned in Inspection Reports 17 Circular (10/4/2/14151) 18/6/1996 Provision of Information about the employees of the Treasury Department to the Central Bank 18 Circular (10/12617) 20/7/1998 Security Procedures (Cameras…) 19 Circular (10/2/3/3/19906) 15/11/1999 Security Procedures (Cameras, Alarm Devices…) 20 Circular (10/1751) 7/2/2000 Budgets 21 Circular (10/2/3/3/5939) 13/4/2000 Security Procedures (Transportation of Money) 22 Circular (10/1912) 29/1/2001 Nomination of Liaison Officer
15 23 Circular (10/3940) 27/2/2001 Names of the Audit Committee 24 Circular (10/4794) 27/3/2002 Directives of Control and Supervision Systems 25 Circular (10/13556) 25/5/2002 Data about the Board of Directors and Executive Management 26 Circular (10/2/4/2935) 21/3/2006 Security Procedures (Cameras…) 27 Memorandum (36/2006) 18/4/2006 Security Procedures (Transportation of Money) 28 Circular (10/2/4/6393) 2/7/2006 Security Procedures (Cameras…) 29 Circular (10/2/4/1106) 31/1/2007 Notification about embezzlement incidents Enclosures: 3 Specimens The Governor Dr. Umayya Toukan
16 Specimen No. (1) Chairman and Members of the Board of …………………………………….. Bank on / / 200 Serial No. Chairman and Members of the Board (Name of four sections for the natural person and as per the Commercial Registration for the corporate person) Name of Representative of the Corporate Person (from four sections) No. of Shares owned by the Director in the Bank’s Capital No. of Shares owned by the Representative Date of Birth Date of Joining the Board Educational Qualifications Practical Experience Membership in Committees emanating from the Board Remarks Bank’s Seal and Signature Specimen No. (2) Corporate Persons who are members in the Board of Directors / ……….………………………… Bank on / / 200 Serial No. Name of Corporate Person Type Its Paid-up Capital Nature of Activities and Objectives Address Names of Chairman and Board Members of the Corporate Person Remarks Bank’s Seal and Signature Specimen No. (3) The Executive Management / …………………………………….. Bank on / 200 Serial No. Position: General Manager, Regional Manager, Deputy General Manager, Assistant General Manager, Administrative Consultant or Banker Name (from four sections) Date of Birth Educational Qualifications Practical Experience Date of Joining the Bank Date of Commencement of work in the current position No. of shares owned in the Bank’s Capital (if any) His Membership in Companies Boards of Directors as a representative of the Bank Remarks The Branches of Foreign Banks shall submit Specimen No(3) only Bank’s Seal and Signature