2013-07-08 | CD-SIBOIF-781-1-MAY14-2013

Added · Updated

Norm for Integrated Risk Management

The Superintendence of Banks and Other Financial Institutions issued Resolution No. CD-SIBOIF-781-1-MAY14-2013, establishing mandatory integrated risk management guidelines for banks, financial companies, financial groups, and foreign branches. The norm requires these institutions to define risk appetite, tolerance levels, and exposure limits while implementing continuous processes for risk identification, measurement, monitoring, and control. It mandates a two-tier organizational structure comprising a Board of Directors and a Risk Committee, assigning specific approval and supervisory functions to each to ensure segregation of duties and independence from business units.

Superintendencia de Bancos y de Otras Instituciones Financieras logo

Nicaragua

Superintendencia de Bancos y de Otras Instituciones Financieras

Click to view thumbnail

1 Resolution No. CD-SIBOIF-781-1-MAY14-2013 Dated May 14, 2013 NORM FOR INTEGRATED RISK MANAGEMENT

The Board of Directors of the Superintendence of Banks and Other Financial Institutions, after discussions on the matter,

CONSIDERING

I That subsections 1) and 2) of Article 10 of Law 316, the Law of the Superintendence of Banks and Other Financial Institutions, published in La Gaceta, Official Gazette No. 196, of October 14, 1999, and its amendments, establish that it corresponds to the Board of Directors of the Superintendence of Banks and Other Financial Institutions (Board of Directors) to issue general norms to strengthen and preserve public security and confidence in institutions under the supervision, inspection, surveillance, and audit of the Superintendence; as well as to issue general norms that promote adequate, agile, modern, and practical supervision over institutions subject to the supervision, inspection, surveillance, and audit of said entity.

II That Article 40, subsections 6) and 10) of Law No. 561, the General Law of Banks, Non-Banking Financial Institutions and Financial Groups (General Law of Banks), published in La Gaceta, Official Gazette No. 232, of November 30, 2005, establish that the provisions regulating corporate governance of financial institutions must include, among others, "policies on comprehensive processes that include the management of the various risks to which the institution may be exposed, as well as adequate information systems and a Committee for the management of said risks", as well as written policies on the management of different risks.

III That Article 38, subsection 4, of the General Law of Banks, regarding the obligations of the board of directors, states that the latter has among its responsibilities "to ensure that policies, systems, and processes necessary for the correct administration, evaluation, and control of risks inherent to the business are implemented and instructed to be maintained in adequate functioning and execution."

IV That Article 40, subsection 9, of the same Law, establishes that among the policies regulating the corporate governance of financial institutions, aspects regarding adequate information flows, both internal and with the public, must be included.

2

V That in accordance with what is indicated in subsection 11 and in the last paragraph of said Article 38 of the General Law of Banks, the Board of Directors of the Superintendence is empowered to issue norms of general application in which the manner in which the responsibilities indicated in the preceding considerations will be applied and executed is established.

In exercise of its powers,

HAS ISSUED

The following:

CD-SIBOIF-781-1-MAY14-2013 NORM FOR INTEGRATED RISK MANAGEMENT

CHAPTER I GENERAL PROVISIONS

Article 1. Objective.- The purpose of this norm is to establish the minimum guidelines that financial institutions must observe for integrated risk management, which must be consistent with the nature, complexity, volume, and risk profile of their operations.

Article 2. Scope.- The provisions of this norm are applicable to banks, financial companies, financial groups, and branches of foreign banks and financial companies established in the country, which hereinafter will be known as financial institutions, or simply institutions.

Article 3. Concepts.- For the purposes of this norm, the terms indicated in this article, both in uppercase and lowercase, singular or plural, shall have the following meanings:

a) Risk Appetite: The quantity and type of risk that a financial institution is willing to accept or retain. b) Integrated Risk Management: A dynamic and strategic process carried out transversally at all levels of the institution, through which it identifies, measures, monitors, and controls the different types of risks to which it is exposed and the interrelationships that arise among them, to provide reasonable assurance in the achievement of its objectives. c) Risk Exposure Limit: The permissible magnitude of exposure when taking a specific risk position. The risk exposure limit structure may be defined based on a business line, risk factor, cause, or origin, among others.

3

d) Risk Tolerance Level: The magnitude of risk that the institution is prepared to handle after the risk has been managed, in order to achieve its objectives. e) Risk Profile: The nature and magnitude of the institution's risk exposures. f) Business Continuity Plans: Plans referred to in the regulations governing the matter on operational risk management. g) Risk: The probability that an event generating losses affecting the economic value of the institutions occurs. h) Credit Risk: Potential loss due to the failure of a debtor or counterparty to pay in operations conducted by the institutions. i) Financial Group Risk: The possibility of economic losses due to the unexpected transfer of risks resulting from the interdependence between the institution and the rest of the companies forming the group. This risk may manifest in any of the risks defined in this article. j) Money Laundering, Assets, or Goods Laundering, and Terrorism Financing Risk (ML/TF): The inherent risk that institutions permanently face and confront due to their very nature of business; of being used, consciously or unconsciously, for money, assets, or goods laundering; and for terrorism financing. k) Liquidity Risk: Potential loss due to the inability to renew liabilities or to contract others under normal conditions for the institution due to the early or forced sale of assets at unusual discounts to meet its obligations, or due to the fact that a position cannot be timely disposed of, acquired, or covered by establishing an equivalent opposite position. l) Market Risk: Potential loss due to changes in risk factors that affect the valuation of positions from active, passive, or contingent liability-generating operations, such as interest rates, exchange rates, price indices, among others. m) Financial Risk: Refers to market risk and liquidity risk.

4

n) Legal Risk: Potential loss due to non-compliance with applicable legal and administrative provisions, the impact of unfavorable administrative or judicial resolutions, and the application of sanctions, in relation to the operations carried out by the institutions. o) Operational Risk: The risk of loss associated with non-accidental events due to the inadequacy or failure of internal processes, personnel, and systems, or due to external events, and includes, among others, technological risk; money laundering, assets, or goods laundering, and terrorism financing risk; and legal risk. p) Technological Risk: Potential loss due to damage, interruption, alteration, or failures derived from the use or dependence on hardware, software, systems, applications, networks, and any other distribution channel in the provision of financial services to the institution's clients. q) Business Units: Centers generating benefits or profits. r) Operational Support Units: All those units of the operational infrastructure that make viable the activity attended to by financial institutions.

CHAPTER II INTEGRATED RISK MANAGEMENT

Article 4. Basic Elements.- For the purposes of implementing adequate integrated risk management, institutions must consider the following basic elements:

a) Define their objectives regarding risk exposure and develop policies and procedures for the management of the different types of risk to which they are exposed, whether quantifiable or not, as established in Article 5 of this norm. b) Clearly delimit the different functions, activities, and responsibilities in matters of integrated risk management among their various administrative bodies, administrative units, and operational and support staff, in accordance with Chapter III of this norm. c) Identify, measure, monitor, and control the quantifiable risks to which they are exposed, considering, where appropriate, non-quantifiable risks.

d) Group, considering their financial subsidiaries, the different types of risk to which they are exposed, by business unit or by cause or origin thereof. Additionally, they will group them globally, incorporating for this purpose the risks of all business units or by cause or origin thereof.

e) Establish criteria for risk tolerance and risk appetite.

Article 5. Objectives, Guidelines, and Policies.- The objectives, guidelines, and policies of integrated risk management must be consistent with the nature, complexity, and volume of the institution's operations, as well as with its size and risk profile; and must contemplate, at least, the following aspects:

a) The risk profile and the objectives of exposure thereto. b) The organizational structure supporting the integrated risk management process, which must follow the provisions established in this norm, as well as a clear delimitation of functions and job profiles at all its levels. c) The powers and responsibilities of those persons holding positions that imply taking risks for the institution. d) The classification of risks by type of operation and business line. e) General and specific risk exposure limits. f) The manner and periodicity with which the two structures, strategic and operational, referred to in this norm, must be informed about the institution's risk exposure and those inherent to each business unit. g) Internal controls, as well as the corresponding measures to correct deviations observed on tolerance levels and risk exposure limits. h) The process to approve, from an integrated risk management perspective, operations, services, products, and business lines that are new to the institution, as well as integrated risk management strategies and, where applicable, hedging strategies; including modifications or updates to existing operations, services, products, and business lines. i) Business continuity plans to restore minimum levels of operation in case of fortuitous events or force majeure.

5

j) The authorization process to exceed tolerance levels and risk exposure limits exceptionally.

Modifications that may be intended to be made to the objectives, guidelines, and policies for integrated risk management must be proposed by the risk committee and approved by the institution's board of directors.

The institution must have management policies for each of the risks, with mechanisms that allow them to be adapted timely in the face of changes in the environment or in its risk profile.

Article 6. Types of Risks.- For the purposes of this norm, institutions must manage, in accordance with the nature, complexity, and volume of their operations, and their size and risk profile, at a minimum, the following risks: credit, financial (liquidity, market), operational, and financial group risk. Money laundering, assets, or goods laundering, and terrorism financing risks will be evaluated in accordance with the regulations on the matter.

Article 7. Process for Integrated Risk Management.- Institutions must have a continuous documented process for integrated risk management, which must contain, at least, the following processes:

a) Identification: Consists in becoming aware of the different risks to which the business of the institution is exposed; b) Measurement: Consists in determining the size and impact that the materialization of identified risks would have on the institution's equity; c) Monitoring: Consists in following the evolution and trend of identified risks; and d) Control: Consists in the set of activities executed by the institution to keep risks limited to the tolerance and risk exposure levels defined by the organization.

The process for integrated risk management must be reviewed periodically based on changes that occur in the institution's risk profile and in the market.

CHAPTER III ORGANIZATIONAL SYSTEM

6

Article 8. Organizational Structure.- Institutions must establish an organizational structure that allows for adequate integrated risk management, with the appropriate segregation of functions and hierarchical levels of operational support, business, and control areas participating in the process, as well as levels of dependency, in accordance with the nature, complexity, and volume of operations, and the size and risk profile of the institution, which, at a minimum, must consider the guidelines indicated in the following articles.

Article 9. Strategic Structure.- The strategic structure is composed of the institution's board of directors and the risk committee, whose generic function, without prejudice to the specific functions established in this and other regulations governing the matter on risk management, is the definition and approval of the objectives, guidelines, and policies for the integrated risk management of the institution, as well as ensuring the existence of the necessary resources for their correct implementation.

Article 10. Operational Structure.- The operational structure is composed of the other instances of the institution, which must execute the objectives, guidelines, and policies for integrated risk management, defined and approved by the strategic structure, in the development of the functions assigned to each within the institution.

Article 11. Communication Flows.- Between the strategic and operational structures mentioned above, there must be information flows to guarantee the efficiency of integrated risk management within the institution. In this sense, institutions must take into account the following general guidelines:

a) The strategic structure, through the institution's operational structure, must communicate clearly and explicitly to the rest of the organization the objectives, guidelines, and policies they have defined; likewise, it must create and define a corporate culture of integrated risk management that helps internalize at all levels of the institution the importance of this style of management. b) The operational structure must inform the strategic structure about relevant aspects regarding the execution of the objectives, guidelines, and policies of integrated risk management, so that the process can be enriched and adapted to the needs of the institution and the market at each moment.

Article 12. Independence.- In order to avoid possible conflicts of interest that could affect the performance of integrated risk management functions, there must be independence between the bodies in charge of integrated risk management and the general management, as well as with the different business and operational units of the institution.

7

Article 13. Functions of the Board of Directors.- The board of directors is responsible for ensuring that policies, systems, and processes necessary for the correct administration, evaluation, and control of risks inherent to the business are implemented and instructed to be maintained in adequate functioning and execution. To comply with the above, the board of directors must, at a minimum:

a) Approve the objectives, guidelines, policies, tolerance levels, and risk exposure limits for the integrated management of each of the risks assumed by the institution and of the exceptions thereto, as well as contingency plans. Likewise, it must be aware of and resolve on proposals for updates and authorize respective modifications at least once a year; b) Approve and/or adopt corrective measures in case the objectives, guidelines, policies, tolerance levels, and risk exposure limits for integrated risk management are not met, or are met partially or incorrectly; c) Approve, upon proposal of the risk committee, the tools, models, methodologies, and systems in accordance with the institution's risk profile, and review their validity at least once a year; d) Approve the institution's involvement in new products, operations, and activities, in accordance with business strategies and risk management policies; including modifications or updates to existing operations, services, products, and business lines; e) Inform shareholders about the results of the implementation and execution of the integrated risk management process; f) Approve an organizational structure for integrated risk management and assign sufficient resources for its implementation; g) Approve the integrated risk management manual and the respective management manuals for each type of risk, and their corresponding modifications; h) Create the risk committee, designate its members, and guarantee its independence; i) Be aware of all risks inherent to the businesses developed by the institution, their evolution over time, their effects on equity levels, and the methodologies for risk management; and j) Ensure that internal audit verifies the existence and compliance of the institution's integrated risk management scheme.

8

Article 14. Risk Committee.- The board of directors of each institution must constitute a risk committee, whose purpose is the management of the risks to which the institution is exposed and to supervise that the execution of operations complies with the objectives, guidelines, and policies for integrated risk management, as well as with the tolerance levels and risk exposure limits previously approved by the board of directors.

The risk committee depends on the board of directors and must be integrated, at a minimum, by one member of the board of directors with knowledge of the financial business, as well as by officials of the institution or of some of the institutions forming part of the financial group that said board designates. The governance form, the members who integrate it, the capacity in which they act, the frequency of meetings, and the decision-making process will be established by the board of directors.

The sessions and agreements of the committee must be recorded in minutes signed by the attendees who participated in the session.

With respect to the director members of the committee, they may participate in sessions without physical presence, through communication between them and the other members of the committee via email, telephone, fax, or by any other means of communication that evidences the participation, identification, and decision of the participants.

Committee members must be independent of the business units, in order to avoid conflicts of interest and ensure adequate separation of functions and assignment of responsibilities.

The board of directors may create specialized risk committees it deems necessary, due to the nature, complexity, and volume of the institution's operations and services.

Article 15. Functions of the Risk Committee.- The risk committee has, at a minimum, the following functions:

a) Propose to the board of directors the objectives, guidelines, policies, tolerance levels, and exposure limits for each type of risk and contingency plans, as well as any modifications made to them when the conditions and environment of the institution so require. These objectives, guidelines, and policies must consider what is established in Article 5 of this norm. b) Propose to the board of directors corrective measures and mechanisms for their implementation in case the objectives, guidelines, and policies for integrated risk management are not met, or are met partially or incorrectly. The committee must follow up on the plans or corrective measures implemented to normalize non-compliance with risk exposure limits or reported deficiencies and inform the board of directors.

9

c) Analyze the methodologies, models, and risk management systems proposed by the integrated risk management unit, for subsequent presentation to the board of directors, and review their validity at least once a year. d) Analyze and evaluate proposals regarding the institution's involvement in new operations, products, and services, in accordance with business strategies and integrated risk management policies; and inform the board of directors of the results of its analysis of said proposals, as well as the information strategies to disseminate throughout the organization all information on the integrated management of risks inherent to these new operations, products, and services. e) Inform the board of directors about the results of the implementation and execution of the risk management process. f) Propose to the board of directors and ensure that the institution has the adequate organizational structure for integrated risk management, and the resource allocation strategy for its implementation. g) Propose to the board of directors the integrated risk management manual and the respective administration manuals for each type of risk, and their corresponding modifications. h) Propose to the board of directors the designation of the person responsible for the integrated risk management unit. i) Inform the board of directors about the risks assumed by the institution, their evolution, their effects on equity levels, and additional mitigation needs. j) Ensure the correct execution of approved strategies and policies. k) Define the general strategy for the implementation of approved policies, procedures, and systems for integrated risk management, and their adequate compliance. l) Evaluate risk management proposals made by business areas, operations, and other functional areas. m) Analyze the management reports and information issued by the integrated risk management unit and other areas linked to the risk management system. n) Analyze proposals on the update of risk management policies, procedures, and systems and propose to the board of directors, when required, the update of the manuals indicated in subsection g) of this article, given market conditions or particularly those of the institution.

10

o) Ensure that the computer tools, both those developed i