2010-01-22 | CD-SIBOIF-611-1-ENE22-2010Added · Updated
This regulation establishes the responsibilities and general guidelines for financial institutions to manage operational risk, requiring the implementation of a formal risk management system, specific manuals, and a dedicated risk management unit (UAIR). It mandates the Board of Directors to approve policies and procedures, while requiring institutions to identify risk events, maintain centralized databases, and implement internal controls and business continuity plans. The rules apply to all financial institutions subject to the supervision of the Superintendence of Banks and Other Financial Institutions.
1 Resolution No. CD-SIBOIF-611-1-ENE22-2010 Dated January 22, 2010
NORM ON OPERATIONAL RISK MANAGEMENT
The Board of Directors of the Superintendence of Banks and Other Financial Institutions,
CONSIDERING
I
That Article 38, numeral 4), of the General Banking Law, regarding the obligations of the board of directors of financial institutions, states that the latter has among its responsibilities "to ensure that policies, systems, and processes necessary for the correct administration, evaluation, and control of the risks inherent to the business are implemented and instructed to be maintained in adequate functioning and execution," establishing in said article the authority of the Board of Directors to issue regulations on this matter.
II
That Article 40, numerals 6) and 10) of Law No. 561, General Banking Law, Non-Banking Financial Institutions and Financial Groups, published in La Gaceta, Official Diary No. 232, of November 30, 2005, in its relevant parts, establishes that the provisions regulating the corporate governance of financial institutions must include, among others, policies on comprehensive processes that include the management of the various risks to which the institution may be exposed, establishment of adequate information systems, as well as written policies on the management of different risks.
III
That in accordance with the above and based on the powers established in Article 3, numeral 13), and Article 10, clauses 1), 2), and 3) of Law No. 316, Law of the Superintendence of Banks and Other Financial Institutions and its reforms.
In exercise of its powers
HAS ISSUED
The following:
CD-SIBOIF-611-1-ENE22-2010
NORM ON OPERATIONAL RISK MANAGEMENT
TITLE I GENERAL PROVISIONS
UNIQUE CHAPTER CONCEPTS, OBJECT, AND SCOPE
2
Article 1. Concepts.- For the purposes of this regulation, the terms indicated in this article, both in uppercase and lowercase, singular or plural, shall have the following meanings:
a) Business Impact Analysis: It is a component of business continuity management. It is the process of identifying and measuring (quantitatively and qualitatively) the impact or loss of business processes in the event of an interruption. It is used to identify priority aspects for recovery, resource requirements for recovery, essential personnel, and to help shape the business continuity plan.
b) Business Continuity: Continuous and uninterrupted state of business operation.
c) Operational Risk Factors: Refers to the sources generating events from which operational risk losses originate at the activity or business line level, among which are: internal processes, people, external events, and information technology.
d) Business Continuity Management: It is the global business approach that includes policies and procedures to ensure that specific operations can be maintained or recovered in a timely manner in the event of an interruption. Its purpose is to minimize operational, financial, legal, reputational, and other impacts arising from an interruption.
e) Risk Management: The set of objectives, policies, procedures, and actions implemented to identify, measure, monitor, limit, control, report, and disclose the different types of risk to which institutions are exposed.
f) Information: Any form of electronic, optical, magnetic, or other medium recording, susceptible of being processed, distributed, and stored.
g) Institution or Financial Institution: Refers to banks and financial societies that, in accordance with the General Banking Law, can capture public deposits. It includes branches of foreign banks and financial societies established in the country.
h) Major Operational Interruption: Significant interruption in the normal operations of the institution, affecting a geographic area and the economically integrated adjacent communities. Major operational interruptions can result from a wide range of events, such as: earthquakes, hurricanes, and other weather-related events, terrorist attacks, riots, computer viruses, epidemics, pandemics, and other biological incidents and other intentional or accidental acts that can cause widespread, direct or indirect, damage to physical infrastructure.
i) General Banking Law: Law 561, General Banking Law, Non-Banking Financial Institutions and Financial Groups, published in the Official Diary No. 232, of November 30, 2005.
j) Applicable Best Practices: Refers to control frameworks, international standards, or other studies that help monitor and improve critical activities, increase business value, and reduce risks, such as; recommendations of the Basel Committee, COSO, COBIT, ITIL, ISO 17799, ISO 9001, CMM, and PRINCE2, among others.
k) Recovery Level: The level of service to be provided regarding specific business operations after an interruption.
l) Recovery Objective: Predefined goal for the recovery of specific business operations and support systems to a certain level of functioning (recovery level) within a defined period of time after an interruption has occurred.
m) Business Continuity Plan: A component of business continuity management. It is a detailed action plan that establishes the procedures and systems necessary by business line to continue or re-establish the operations of an institution in the event of an interruption.
n) Policies: Set of practices established by the institution's board of directors, through which the courses of action to be followed by management are defined.
o) Procedure: Method or structured system to execute instructions. Detailed list of the logical and consistent sequence of activities and courses of action, through which compliance with an operational function is ensured.
p) Process: Set of organized and repeatable activities, tasks, and procedures.
q) Critical Process: Process considered indispensable for the continuity of the institution's operations and services, whose lack or poor execution can have a significant impact on the institution.
r) Recovery: The restoration of specific business operations to a level sufficient to meet the institution's obligations, after an interruption has occurred.
s) Resilience: The capacity of a financial institution to absorb the impact of a major operational interruption and continue providing critical operations and services.
t) Risk: The possibility that an event generating losses affecting the economic value of institutions occurs.
u) Legal Risk: Potential loss due to non-compliance with applicable legal and administrative provisions, impact from unfavorable administrative or judicial resolutions, and application of sanctions, in relation to the operations carried out by institutions.
v) Information Technology Risk: Damage, interruption, alteration, or failures derived from the use of IT that supports the critical processes of the Institution and that entails a potential loss.
3
w) Operational Risk: It is the risk of losses resulting from the lack of adequacy or failures in internal processes, people, or systems, or by external events. This definition includes legal and technological risk, but excludes strategic and reputational risk.
x) Critical services provided by third parties: Services related to critical processes provided by third parties, whose lack or poor execution can have a significant financial impact on the institution.
y) Alternate Site: Place enabled to be used during an interruption, in order to maintain the business continuity of an institution. The term applies to both physical space and technological requirements, located in a place different from the primary business location affected. Institutions may have more than one alternate site. In some cases, an alternate site may consist of the infrastructure used in the institution's normal daily operations but with the capacity to accommodate additional business functions when the primary business location is affected.
z) Superintendence: Superintendence of Banks and Other Financial Institutions.
aa) Superintendent: Superintendent of Banks and Other Financial Institutions.
bb) Information Technology (IT): Set of resources necessary to process information, convert it, store it, manage it, transmit it, and find it, such as: Hardware, Software, Information Systems, Technological Research, Local Networks, Databases, Software Engineering, Telecommunications, Services, and IT Organization.
cc) Recovery Time: It is the period of time in which it is expected to restore a specific business operation. The recovery time has two components: the time between the interruption and the activation of the business continuity plan; and the time between the activation of the business continuity plan and the recovery of a specific business activity.
dd) Business Unit: The risk-originating and risk-taking areas discretionary within institutions.
ee) UAIR: Integrated Risk Management Unit established in the regulations governing the matter on integrated risk management.
Article 2. Object.- The purpose of this regulation is to establish the responsibilities and general guidelines to be followed by financial institutions for the adequate management of operational risk, in order to control or mitigate the possible negative impact of said risk. Likewise, it aims to establish special criteria to be taken into account to maintain effective control of the main operational risk factors to which institutions may be exposed.
Article 3. Scope.- The provisions of this regulation are applicable to financial institutions subject to the authorization, supervision, and oversight of the Superintendence.
4
TITLE II OPERATIONAL RISK MANAGEMENT
CHAPTER I RESPONSIBILITIES IN RISK MANAGEMENT
Article 4. Risk management system.- Financial institutions must have a risk management system that allows them to identify, measure, control, mitigate, and monitor their exposure to operational risk in the development of their businesses and operations. Each institution must formally establish its own controls and procedures for the management of said risk, considering, among other elements, its corporate purpose, size, nature, and complexity of operations. The implementation of this system must take into account all stages of risk management, grouping processes by business lines, according to the procedure they have formally established.
Article 5. Responsibilities of the board of directors in risk management.- The board of directors of the financial institution shall be responsible for approving the objectives, guidelines, and policies that allow it to carry out adequate management of the operational risk to which the institution is exposed. Likewise, it shall be their responsibility to ensure compliance with said objectives, guidelines, and policies, which must be implemented by the senior management of the institution.
The aforementioned objectives, guidelines, and policies must be clearly defined in the manuals provided for in the following article, which must be consistent with the size and nature of the institution and with the complexity and volume of its operations and services.
Article 6. Manuals for risk management.- The aforementioned objectives, guidelines, and policies must be recorded in manuals that will serve as functional and operational support for the operational risk management process. Generally, these manuals must be technical documents containing, among others, information flow diagrams, models, and methodologies for the evaluation of this type of risk, as well as the requirements of information processing and risk analysis systems.
The boards of directors must approve, at least, the following manuals:
a) Manual of Policies and Procedures: Contains the policies and procedures established by the institution for the identification, measurement, control, adequacy, monitoring, and management of all risks to which it is exposed; as well as, the corrective actions to be implemented and the monitoring of instructions issued, as appropriate. It contemplates, among others, preventive systems to detect the risks to which the institution might be exposed and surveillance mechanisms to ensure that risk limits are not exceeded for the activities or operations it carries out; as well as, the mechanisms established to prepare and exchange information, both internal and external, and the actions planned for the dissemination of activities corresponding to the different management levels and personnel regarding the control of their tasks.
b) Organization and Job Description Manual: Details the functional organization of the institution, as well as, the functions, positions, and responsibilities of officials at all levels.
c) Operational Risk Control Manual: The manual must contemplate a clear definition of operational risk and establish principles for its identification, evaluation, monitoring, control, and mitigation. Likewise, the risk control manual must contain a special section on operational risk. Without prejudice to what is established in clause a) of this article, said section must contain, at least, the following aspects:
Article 7. Unit responsible for risk management.- The unit responsible for the control and analysis of operational risk in financial institutions is the UAIR referred to in the regulation governing the matter on integrated risk management and shall have the functions and responsibilities established both in this regulation and in the aforementioned regulation.
The UAIR, to comply with the functions indicated in this regulation, may assist itself in the areas or instances it deems convenient, provided that, there is independence between the risk-taking areas and the UAIR.
CHAPTER II GENERAL GUIDELINES FOR MANAGING OPERATIONAL RISK
Article 8. General guidelines.- Financial institutions must take into account the following minimum general guidelines in establishing their objectives, policies, and procedures to manage operational risk:
a) Identification of risk-generating events: Financial institutions must identify, by business line, operational risk events grouped by type and failures, or deficiencies in processes, people, information technology, and external events, among others:
5
b) Implementation of actions: Once operational risk events and failures or deficiencies in relation to the factors of this risk and their incidence for the institution have been identified, the board of directors and senior management must decide whether to accept, share, avoid, or transfer the risk, reducing its consequences and effects, for which they must adopt, among others, the following actions:
c) Database formation: Financial institutions must form a centralized database that allows recording, ordering, classifying, and making available information on operational risk events and factors, failures or deficiencies, classified by business line, determining the frequency with which each event repeats and the quantitative effect of loss produced, as well as any other information considered necessary and timely, so that in the future they can estimate expected and unexpected losses attributable to this risk, according to the regulation governing this matter.
d) Information technology: Each institution must have information technology (IT) that guarantees the capture, processing, storage, and transmission of information in a timely, secure, and reliable manner; mitigate business interruptions and ensure that information, including that under the modality of services provided by third parties, is intact, confidential, and available for appropriate decision-making.
The risk evaluation process must lead to a good selection of technology and control of its implementation, and incorporate specific evaluations for functional responsibilities, such as: security, business continuity, supplier management, among others. Likewise, they must evaluate deficiencies in hardware, software, systems, applications, and networks, processing or operational errors, procedure failures, inadequate capabilities, network vulnerabilities, installed controls, security against intentional attacks or intrusion incidents, and fraudulent actions, as well as defects in information recovery. The foregoing in accordance with what is established in the regulation governing the matter on technological risk management.
e) Report generation: Financial institutions must permanently have an organized reporting scheme that allows having sufficient and adequate information to manage operational risk continuously and timely. The reports must contain, at least, the following information:
f) Applicable best practices: Financial institutions must assign responsible persons who are in charge of formally defining and authorizing accesses, functional changes to applications, and monitoring compliance with established controls. Likewise, they must define policies, processes, and procedures under applicable best practices that guarantee the execution of internal control criteria relative to effectiveness, efficiency, and compliance with them, aligned with the objectives and activities of the institution, which must be approved by the board of directors.
g) Prior evaluation of new products, activities, processes, and systems: Financial institutions, before launching or undertaking new products, activities, processes, or systems, must ensure that the operational risk inherent in them is properly managed.
h) Outsourcing of services: When certain functions or processes can be subject to subcontracting or outsourcing, the institution must proceed in accordance with the regulation governing the matter on the contracting of service providers.
i) Effective business continuity management: Effective business continuity management is an important component of operational risk management. It is an approach that frames all business operations of the institution, and includes policies and procedures to ensure that specific operations can be maintained or recovered in a timely manner in the event of an interruption. This management aims to minimize the operational, financial, legal, reputational, and other material consequences arising from a service interruption.
For the implementation of effective business continuity management, financial institutions must take into account the basic elements and principles established in the Annex of this regulation, which is an integral part of it.
CHAPTER III INTERNAL CONTROLS
Article 9. Internal control system.- Financial institutions must have an internal control system that meets the requirements established in this regulation and in the regulation that
6
7
8
9 regulates the matter on internal control and audit. This system must be focused on providing reasonable assurance in the safeguarding of the institution's assets and achieving adequate administrative organization and operational efficiency; reliability of the reports flowing from its information systems; appropriate identification and management of the risks it faces; and compliance with the legal provisions applicable to it.
Any internal control system implemented by financial institutions must be based on the following components: a) Control Environment: Institutions must take into account, among other elements, those related to: integrity, ethical values, employee capability, the institution's philosophy, management style, assignment of authority and its responsibilities, organization and development of employees, and board of directors' guidelines. b) Risk Assessment: Institutions must first identify organizational objectives and subsequently identify and evaluate relevant risks that could affect achieving said objectives. Risks must be managed, taking into account the existence of a changing internal and external environment. c) Control Activities: These are the policies and procedures that help ensure that measures are taken to limit risks that could affect the achievement of organizational objectives. Among other activities are the following: authorizations, verifications, reconciliations, segregation of duties, and reviews of operational profitability. d) Information and Communication: It is necessary to identify, organize, and communicate in a timely manner the information necessary for the institution's employees to fulfill their obligations. This information may be operational or financial, of internal or external origin; and institutions must ensure the existence of adequate communication channels among staff, who must be informed of the importance of their participation in the effort to apply internal control. e) Supervision: Financial institutions must implement processes that involve carrying out continuous supervision activities, periodic evaluations, or a combination of both, to verify that their internal control systems remain functioning properly.
TITLE III OPERATIONAL RISK FACTORS Article 10. Operational risk factors.- The operational risk factors to which financial institutions are mostly exposed are the following: a) Internal processes; b) People; c) External events; and d) Information technology.
10 It is determinant for an effective control of these factors that financial institutions have an appropriate definition of each of these, for which they must observe the criteria developed in the chapters that make up this present Title.
CHAPTER I INTERNAL PROCESSES Article 11. Management of risks associated with internal processes.- Financial institutions must appropriately manage risks associated with the internal processes implemented for the performance of their operations and services, in such a way that the possibility of losses related to inappropriate process design, or inadequate or non-existent policies and procedures that could result in deficient development of operations and services or their suspension is minimized.
In this sense, among others, the risks associated with failures in processes and/or models used; errors in transactions; inadequate evaluation of contracts or the complexity of products, operations, and services; errors in accounting information; inadequate compensation, settlement, or payment; insufficient resources for the volume of operations; inadequate documentation of transactions; as well as, non-compliance with planned deadlines and costs may be considered.
Article 12. Development of policies.- Financial institutions must have written policies regarding the design, control, update, and monitoring of processes. These policies will refer, at least, to the following aspects: a) Process design, which must be adaptable and dynamic; b) Description in logical and orderly sequence of activities, tasks, and controls; c) Identification of the people responsible for executing the processes for their correct functioning, by establishing measures and setting objectives, guaranteeing that the global goals of the process are met; defining limits and scope; maintaining contact with internal and external customers of the process to ensure that their expectations are satisfied and known, among others; d) Dissemination and communication of processes; and e) Update and continuous improvement through permanent monitoring of their application.
Article 13. Segregation of duties.- Financial institutions must have an adequate segregation of duties that avoid incompatibilities, understood as those tasks whose combination in the competencies of a single person could eventually allow the commission or concealment of fraud, errors, omissions, or other operational risk events.
Article 14. Inventories.- Financial institutions must maintain updated inventories of processes in operation, which will contain, at minimum, the following information: type of process, name of the process, responsible person, products and services generated by the process, internal and external customers, approval date, update date, and it must indicate whether it is a critical process.
11
CHAPTER II PEOPLE Article 15. Management of risks associated with people.- Financial institutions must appropriately manage risks associated with the institution's people, in such a way that the possibility of losses associated with inadequate staff training, negligence, human error, sabotage, fraud, theft, strikes, appropriation of sensitive information, money laundering, and similar events is minimized.
Institutions must evaluate their organization in order to determine if the human resource needs with the appropriate competencies for the performance of each position have been defined, considering not only professional experience and academic training, but also values, attitudes, and personal skills that can serve as a criterion to guarantee institutional excellence.
Likewise, institutions must maintain updated information on human resources, which allows adequate decision-making by management levels and the performance of qualitative and quantitative analyses according to their needs. This information must refer to the personnel existing in the institution; to academic training and experience; to the manner and dates of selection, recruitment, and hiring; to historical information on training events in which they have participated; to the positions they have held in the entity; to the results of evaluations performed; to the dates and causes of separation of personnel who have left; and, to any other information considered pertinent.
CHAPTER III EXTERNAL EVENTS Article 16. Management of risks associated with external events.- Financial institutions must take into account in operational risk management the possibility of losses derived from the occurrence of events beyond the institution's control that could alter the development of their activities, affecting the aspects that give rise to operational risk referred to in the preceding articles. In this sense, among other events, the following may be taken into consideration: a) Legal contingencies; b) Failures in public services; c) The occurrence of natural disasters, attacks, and criminal acts; and d) Failures in critical services provided by third parties.
CHAPTER IV INFORMATION TECHNOLOGY Article 17. Management of risks associated with information technology.- Financial institutions must manage risks associated with IT, complying with the requirements established in this norm, in the regulations governing the matter on integrated risk management, and in the regulations on technological risk management.
TITLE IV FINAL PROVISIONS
12
UNIQUE CHAPTER TRANSITORY, SUPERINTENDENT'S AUTHORITY, AND VALIDITY Article 18. Transitory provisions.- The following transitory provisions are established: a) Financial institutions will have until July 31, 2010 to adapt to the requirements established in this norm. b) Financial institutions must submit to the Superintendent no later than within sixty (60) days following the entry into force of this norm, an adaptation plan to the provisions contained therein. This plan must include a preliminary diagnosis of the institution's current situation reflecting its degree of progress in meeting the requirements established in the norm, the actions planned for total adaptation and their schedule; as well as, the officials responsible for compliance with said plan.
Article 19. Superintendent's Authority.- The Superintendent is authorized to individually extend the deadlines established in the previous article, based on a duly justified and supported request by the interested financial institution.
Article 20. Validity.- This norm will enter into force upon its notification, without prejudice to its subsequent publication in La Gaceta, Official Diary.
ANNEX ELEMENTS AND BASIC PRINCIPLES FOR EFFECTIVE BUSINESS CONTINUITY MANAGEMENT I. ELEMENTS: a) Impact Analysis: It is the starting point of effective business continuity management. It is the dynamic process of identifying critical operations and services, key internal and external dependencies, and appropriate levels of resilience. It evaluates the risks and potential impacts of various interruption scenarios on the institution's operations and reputation. b) Recovery Strategy: Establishes recovery objectives and priorities based on the business impact analysis. Among other aspects, it establishes the objectives for the level of services the institution would seek to provide in case of interruption and the infrastructure necessary for the total restoration of business operations. c) Business Continuity Plans: Provide a detailed guide for the implementation of the maintenance and recovery strategy. They establish roles and delegate responsibilities for handling operational interruptions and provide clear guidelines regarding the succession of authority in cases of interruptions that affect key personnel. They also clearly establish the authority for decision-making and set the circumstances or events that activate the institution's business continuity plan. Personnel safety must be the primary consideration of the business continuity plan.
13
II. PRINCIPLES: a) Board of Directors and Senior Management Responsibilities: The board of directors and senior management are jointly responsible for the continuity of the institution's operations.
Business continuity management must be a key component of the institution's integrated risk management. Business continuity management policies and processes must be implemented at the global level of the institution or, at minimum, at its critical operations.
Effective business continuity management deals not only with technical aspects, but also with human resources. In this way, it recognizes that employees and possibly their families may be affected by the same event that caused the interruption, and as a consequence, not all employees will be available to the institution during or immediately after the occurrence of the event.
The board of directors and senior management of the institution are responsible for the effective management of their business continuity policies and for the development and implementation of policies that promote resilience to, and continuity in the event of, operational interruptions. They must recognize that outsourcing operations does not transfer the responsibilities they have regarding business continuity management to the service provider. The board of directors and senior management must create and promote an organizational culture that has business continuity as one of its priorities. The board of directors and senior management must provide the financial and human resources to develop and implement the institution's approach to business continuity management.
Systems must be established that allow reporting to the board of directors and senior management on matters related to business continuity, including the degree of implementation, incident notification, test results, and actions related to strengthening the institution's resilience or ability to resume specific operations. The business continuity management of an institution must be subject to review by auditors, both external and internal, and significant findings must be brought to the attention of the board of directors and senior management in a timely manner.
Confusion can be a serious obstacle to carrying out an effective response to an interruption. Consequently, responsibilities, as well as succession plans, must be clearly defined in an institution's business continuity management policies.
b) Major Operational Interruptions: Major operational interruptions present a substantial risk to the continuity of the financial system's operations. For this reason, financial institutions in particular must include the risk of a major operational interruption in their business continuity plans. The degree to which a particular institution prepares for recovery in the event of a major interruption must be in accordance with its own characteristics and risk profile. Because access to the resources necessary for total recovery may be limited during a major interruption, the institution must identify, through an impact analysis, those business functions and operations that must be recovered prioritarily, establishing appropriate recovery objectives for said operations.
Major operational interruptions vary in scope and duration. In evaluating whether its business continuity management is sufficient to respond to a major interruption, institutions must review the adequacy of their recovery mechanisms in the following three areas:
c) Recovery Objectives: Financial institutions must establish recovery objectives that reflect the risks they represent for the stability of the financial system.
The institution suffering a major operational interruption could affect the ability of other members to continue with their normal business operations. Consequently, financial institutions must take this risk into account and improve their business continuity management in cases where they determine that an interruption of their operations would affect the stability of the financial system.
Recovery objectives must identify both expected levels of recovery and the time it would take to reach them.
d) Communications: Financial institutions must include in their business continuity plans the mechanisms and procedures to communicate both within the organization and with external stakeholders in the event of a major operational interruption.
Financial institutions must be able to communicate effectively with relevant stakeholders both inside and outside the institution, in the event of a major operational interruption. Particularly in the early stages of the interruption, where effective communication is necessary to estimate the impact of this on the institution's personnel and operations and on the financial system in general, and to decide whether or not to implement the business continuity plan. As time passes, the ability to communicate the most important available information to stakeholders in a timely manner is a critical factor for the recovery of the institution's operations and for the return of the financial system to normal functioning. Maintaining public confidence in the financial institution requires the ability to communicate clearly and regularly during the time the interruption lasts.
Likewise, the communication procedures and systems of financial institutions must include, at minimum, the following aspects:
Identification of the people responsible for communicating with personnel and other external stakeholders. This group may include senior management, public relations staff, legal advisors, and personnel responsible for the institution's business continuity procedures. This group must be able to communicate with personnel located in remote places, dispersed across multiple locations, or who are simply far from the institution's main offices; and
Resolve related aspects that could arise as a result of a major operational interruption, such as the response to be given to failures in primary communication systems. This may include, for example, developing systems and contact information for key personnel that would facilitate multiple methods of communication (landline, digital, or analog telephone lines; cell phones, satellite phones, text messages, Internet pages, among others).
e) Testing: Financial institutions must conduct tests of their business continuity plans, evaluate their effectiveness, and update their business continuity management as necessary.
Testing the capacity to recover critical operations as planned is an essential component of effective business continuity management. Such tests must be carried out periodically, taking into account the nature, scope, and frequency, as determined by the importance of business applications and functions, the institution's role in the market, and material changes in the environment, both external and internal to the institution. Additionally, such tests must identify the need to modify the business continuity plan and its related aspects. In some cases, this need for change may be the result of modifications in its business, systems, software, hardware, personnel, facilities, or the external environment. Both internal and external audit must evaluate the effectiveness of the institution's testing program, review the test results, and report their findings to the audit committee, senior management, and the board of directors. The board of directors and senior management must ensure that any deficiency found is remedied in a timely manner.
Additionally, to the verification that business continuity plans are evaluated and updated as necessary, tests are also essential to promote understanding and familiarity among key personnel of their roles and responsibilities in the event of a major interruption. It is therefore important that testing programs include personnel who are likely to be involved in major operational interruptions.
Senior management must instruct functional areas and they in turn the personnel under their supervision, on the steps to follow in the event of an interruption, in such a way that these are known to all personnel, as well as prepare the continuity plans for critical services that are under their responsibility.
(f) A. Rosales B. (f) V. Urcuyo V. (f) Fausto Reyes B. (f) illegible (Silvio Moisés Casco Marenco) (f) U. Cerna B. URIEL CERNA BARQUERO Secretary of the Board of Directors SIBOIF
More like this from SIBOIF
We email you every new SIBOIF publication the day it's published.