2006-05-16 | CD-SIBOIF-421-1-MAY16-2006

Added · Updated

Norm on the Contracting of Service Providers for the Performance of Operations or Services on Behalf of Financial Institutions

Resolution No. CD-SIBOIF-421-1-MAY16-2006 establishes minimum requirements for supervised financial institutions to contract third-party service providers for continuous or temporary operations. The regulation mandates that institutions evaluate associated risks, determine the materiality of agreements, and implement risk management and monitoring programs. It defines the responsibilities of the board of directors and management, requiring clear policies, pre-contractual evaluations, and comprehensive contracts that address service levels, compliance, dispute resolution, and contingency planning for material contracts.

Superintendencia de Bancos y de Otras Instituciones Financieras logo

Nicaragua

Superintendencia de Bancos y de Otras Instituciones Financieras

Click to view thumbnail

1

NORM ON THE CONTRACTING OF SERVICE PROVIDERS FOR THE PERFORMANCE OF OPERATIONS OR SERVICES ON BEHALF OF FINANCIAL INSTITUTIONS

RESOLUTION NO. CD-SIBOIF-421-1-MAY16-2006 of May 16, 2006

The Board of Directors of the Superintendence of Banks and Other Financial Institutions, after deliberations on the matter,

CONSIDERS

I

That Article 130 of Law 561, the General Law of Banks, Non-Bank Financial Institutions and Financial Groups, establishes that financial institutions may subcontract the performance of their internal operations. Internal operations subcontracting is understood as the use by financial institutions of a third party or service provider, whether related or not to the institution, for the continuous performance of activities or operations;

II

That said Article 130 also states that the Board of Directors of the Superintendence is empowered to issue general norms that institutions subject to the supervision of the Superintendence of Banks and Other Financial Institutions must follow for the performance of this type of operations;

III

That Article 10, item 6, of Law 552, "Law of Reforms to Law 316, Law of the Superintendence of Banks and Other Financial Institutions," empowers the Board of Directors of the Superintendence to issue norms on operations, contracts, and transactions with related parties;

IV

That Article 55, item 5, of the General Law of Banks establishes that in any negotiation with related parties, institutions must conduct them under conditions that do not differ from those applicable to any other unrelated party in comparable transactions; this condition is applicable, among others, to contractual services performed by or on behalf of the institution and to any transaction or series of transactions with third parties, natural or legal, in which the related party has a financial interest, or that the related party participates in said transaction or series of transactions.

In exercise of its powers,

HAS ISSUED

The following:

RESOLUTION NO. CD-SIBOIF-421-1-MAY16-2006

NORM ON THE CONTRACTING OF SERVICE PROVIDERS FOR THE PERFORMANCE OF OPERATIONS OR SERVICES ON BEHALF OF FINANCIAL INSTITUTIONS

TITLE I ON THE CONTRACTING OF PROVIDERS FOR THE PERFORMANCE OF OPERATIONS ON BEHALF OF FINANCIAL INSTITUTIONS

CHAPTER I OBJECT, SCOPE, DEFINITIONS AND VERIFICATION

Art. 1. Object.- This norm aims to establish the minimum requirements that supervised financial institutions must comply with for the contracting of third-party service providers for the performance of activities or operations on a continuous or temporary basis.

In order to achieve the aforementioned object, financial institutions must, at least:

  • Evaluate the risks associated with existing and proposed contracting agreements;
  • Develop parameters to help determine the materiality of such agreements;
  • Implement a risk management and monitoring program. This program must be directly related to the materiality of the contracted operation; and,
  • Ensure that the board of directors and the general manager or chief executive receive the necessary and relevant information to allow them to fulfill their responsibilities in accordance with the terms of this norm.

Operations contracted to service providers, performed both internally and externally to the institution, are subject to the supervision and oversight of the Superintendence in accordance with the terms of applicable legal provisions and the provisions of this norm.

Art. 2. Definitions.- For the purposes of this Norm, the following are understood:

  1. Financial institution or institution: That subject to the authorization, supervision, surveillance, and oversight of the Superintendence of Banks and Other Financial Institutions.
  2. Contracting of operations; contracting of operations or services; contracting; contracting agreement or any combination of these words in which, by their logical order, the following is understood: Use by financial institutions of a third party or service provider, whether related or not to the institution, for the performance of activities, operations, advice, consulting, or services in general, on a continuous or temporary basis.
  3. Third party or service provider: Refers to the entity contracted by the financial institution for the performance of operations or services on behalf of the latter.

Art. 3. Application and Scope.- The provisions of this norm are applicable to all financial institutions subject to the authorization, supervision, and surveillance of the Superintendence of Banks and Other Financial Institutions, indicated in Article 1 of Law 561, General Law of Banks, Non-Bank Financial Institutions and Financial Groups, published in the Official Gazette, number 232, of November 30, 2005, and in Article 2 of Law 316, Law of the Superintendence of Banks and Other Financial Institutions, published in the Official Gazette, number 196 of October 14, 1999.

This norm is applicable to all contracting of operations or services of a financial institution. Likewise, when applying this norm, the financial institution must consider both the impact that the contracting will have on its own operations and at the consolidated level, including those located outside the country. Likewise, this norm is applicable to all those operations where, as a consequence of this, a contracting of operations or services originates.

The materiality of all contracting agreements must be evaluated following the guidelines established in this norm. The Superintendence recognizes that contracting agreements will present variable degrees of materiality and expects that the degree of management and risk administration exigency of the contracting be directly related to its materiality.

Art. 4. Verification of Compliance.- The Superintendent will verify compliance with the provisions contained in this norm through requests for all supporting documentation of the contracting and reviews of the systems and processes associated with it (determination of materiality, prior evaluations, contracts, risk management and administration, etc.) and/or through on-site inspections. When the Superintendent determines that any of the provisions of this norm have been infringed, without prejudice to the corresponding sanctions, he/she will immediately order the necessary corrective measures.

CHAPTER II RESPONSIBILITIES AND CONTROLS

Art. 5. Responsibilities of the Board of Directors.- The financial institution wishing to contract its operations to third parties must have clear policies to evaluate whether such operations or services can be efficiently provided. The board of directors of financial institutions is responsible for approving and/or re-evaluating the contracting policies of their operations or services, materiality parameters, risk management and administration programs, review of all material contracting agreements signed by the financial institution and related reports, when necessary for subsequent evaluation.

Art. 6. Responsibility for the elaboration and implementation of policies.- The management or the comprehensive risk management instance, in cases where the institution has this instance or when this responsibility corresponds to the latter by law or norm, will be responsible, as the case may be, for the elaboration of the contracting policies to be approved by the board of directors, implementing said policies and ancillary procedures, evaluating their effectiveness regularly, and reporting to the board on significant risks of the contracting.

Art. 7. Contracting Policies.- The contracting policies referred to in the previous article must include at least the following:

  1. Contracting risk philosophy: The risk philosophy of the contracting of operations or services of the financial institution must establish the guiding principles, bases for decision-making, and parameters for risk administration. The risk philosophy of financial institutions must include, at least, the following:
    • Integration of contracting agreements, individually and in their entirety, with the global business and strategic objectives of the institution. This includes the identification of operations or services that, for strategic or internal control reasons, the institution would not consider contracting to third parties.
    • Internal technical importance and capacity, and administrative structures to supervise and administer the contracting of operations or services and the relationship with the service provider.
    • Reasons why an important operation for the institution will be contracted. Such reasons must consider short and medium-term implications, as well as all relevant prudential aspects. When the service provider is in another country or jurisdiction, the financial institution must identify the implications that could result from the discrepancy between the legal requirements of both countries or jurisdictions. The reasons must also consider the global impact of all contracting of operations on the stability and security of the financial institution.
  2. Evaluation of the materiality of the contracting: This evaluation must identify the processes to determine the materiality of individual contracting, taking into consideration the factors indicated in Title II of this Norm.
  3. Risk management and administration plan: Financial institutions must have a risk management and administration plan related to contracting that, at a minimum, must include the aspects contained in Title III of this Norm (when the contracting is material).
  4. Approval authorities and limits for the contracting of operations or services based on materiality: This authority can be individual or shared in a Committee. It must be clearly specified:
    • The approval authority to be delegated,
    • The officials or positions to whom it is delegated,
    • The ability of the authorized persons.

The factors used to establish limits must contemplate: * The type of activity to be contracted, * The experience or knowledge of the service provider, * The percentage of the service to be contracted.

Art. 8. Obligations with the Superintendence and its clients.- Financial institutions must ensure that the contracting of operations or services will not prevent or limit the capacity to comply with their legal and regulatory obligations, as well as with their clients, nor restrict or limit the adequate supervision of the institution by the Superintendence.

TITLE II SINGLE CHAPTER MATERIALITY

Art. 9. Determination of materiality.- The financial institution must establish a risk management and administration program applicable to all contracting of operations or services, except for those that are clearly immaterial, and must ensure that the risk mitigants used for said program are appropriate for each particular contracting. Those material contracting must be subject to all and each of the requirements established in Title III of this norm, unless, in a substantiated and reasoned manner, it is concluded that a particular requirement is not appropriate for a specific contracting agreement.

The materiality of a contracting agreement will depend on whether it has the potential to cause a significant impact, whether quantitative or qualitative, on an important business line of the institution or on its operations at the global or consolidated level.

The evaluation of the materiality of a contracting agreement will depend on the particular circumstances of each financial institution.

Art. 10. Aspects to consider to establish the materiality of an operation.- In order to determine the materiality of a contracting agreement, the financial institution must consider, at least, the following aspects:

  • The financial, reputational, and operational impact on the institution in case the service provider does not perform the entrusted operation adequately;
  • Potential losses for the clients of the financial institution and their counterparties in case of failures attributable to the service provider;
  • Possible consequences of the contracting on the ability and capacity of the financial institution to comply with its legal and regulatory obligations;
  • Cost of the contracting;
  • Interrelation of the contracted operation with the rest of the operations of the financial institution;
  • Relationship of the service provider with the financial institution;
  • Regulatory framework of the service provider;
  • Degree of difficulty and time required to select an alternative service provider or to perform the operation internally again, if necessary;
  • Complexity of the contracting.

Annex 1, which becomes an integral part of this norm, presents some additional or complementary aspects that the financial institution may use to determine the materiality of a contracting.

In case of significant changes in the volume or nature of the business, the financial institution must re-evaluate the materiality of its contracting. In cases where the contracting is re-evaluated as material, it must comply with the requirements of this norm immediately.

TITLE III RISK MANAGEMENT AND ADMINISTRATION PROGRAM FOR MATERIAL CONTRACTING. POLICIES AND PROCEDURES

CHAPTER I PRE-CONTRACTUAL ASPECTS

Art. 11. Risk management and administration program.- Financial institutions must design a risk management and administration program applicable to all contracting of operations or services of the institution, except for those that are clearly immaterial, the risk mitigants used must be in concordance with the risks associated with the particular contracting. In the development of a risk management and administration program for contracting, financial institutions must, at a minimum, consider and include the aspects indicated in this Title.

Art. 12. Prior evaluation.- Financial institutions must carry out a comprehensive evaluation of all risks related to a contracting of operations or services, and identify all relevant aspects related to the service provider, including qualitative and quantitative factors. Annex 2, which becomes an integral part of this norm, establishes an enumerative list of factors that must be considered to carry out the evaluation of a service provider.

The prior evaluation processes will vary depending on the financial institution and the nature of the contemplated contracting. For example, in the case of contract renewals, in those relationships where there have been no material changes affecting the viability of the contracting, it may not be necessary to carry out an exhaustive prior evaluation.

A prior evaluation must include at least the following aspects (see also Annex 2):

  • The selection of qualified service providers with adequate resources;
  • The financial institution must ensure that the service provider understands and is capable of fulfilling the objectives of the financial institution regarding the contracting;
  • Analysis of the financial capacity of the service provider to fulfill its obligations.

Any special needs, such as service in geographically distant areas, must be identified and satisfied through the use of service providers with similar scope and capabilities.

A service provider that does not meet the criteria indicated in this article must not be contracted.

CHAPTER II CONTRACT

Art. 13. Contract.- The contracting of operations or services must be governed by contracts in which all relevant aspects of this are clearly established, including the rights, obligations, and expectations of all parties involved. Some of the requirements indicated in the following articles may not be applicable to all possible types of contractual relationships; nevertheless, financial institutions must identify and address all relevant aspects to the administration of risks associated with each of the contracting.

Art. 14. Nature and scope of the service to be provided.- The contract must clearly define the object and scope of the relationship. It must include clauses or provisions in which the frequency, content, and form of the service to be provided are established, as well as the products or results thereof. The contract must specify that it will be the service provider who signs the contract who will effectively provide the services. Minimum service levels must be established, including any auxiliary service to be provided.

Art. 15. Compliance parameters.- The contract must contain measures or compliance parameters that allow the parties to determine if the obligations contained therein are being fulfilled.

Art. 16. Deadlines and form.- In those contractual relationships that aim to deliver products or results of any nature, the contract must stipulate the deadline(s) in which these will be delivered, as well as the form in which they must be presented.

Art. 17. Information requirements.- The contract must specify the type and frequency of the information that the financial institution will receive from the service provider. Information must include reports, products, or results that allow determining the observance of compliance parameters and any other information required by the institution's risk management program. Additionally, the contract must include procedures and requirements to inform the institution about events that could have a material effect on the contracting.

Art. 18. Dispute resolution.- The contract must incorporate clauses pertinent to dispute resolution. The contract must specify if the service provider is obligated to continue providing it during the dispute and its resolution, as well as the jurisdiction and laws under which the dispute must be resolved.

Art. 19. Breach and termination.- The contract must specify and define what constitutes a breach of its terms, identify remedies, give opportunity to cure breaches or terminate the contract. The financial institution must ensure that it is capable of continuing its operations in cases of contract termination or when the service provider is not capable of continuing to provide the service. Notification of the termination of the contract must be required with sufficient time, and the assets of the institution must be returned to it expeditiously. Particularly, records and information related to data processing contracting agreements must be returned to the institution in a format that allows the latter to continue its operations without incurring prohibitive expenses.

Art. 20. Ownership and access.- The identification and ownership of all intellectual and physical assets related to the contract must be clearly established, including those acquired or produced as a consequence of said contract. The contract must establish when and how the service provider may use the assets of the institution, and the rights of the latter to access said assets.

Art. 21. Contingency plans.- The contract must establish the measures that the service provider will take to ensure the continuation of its services in case of problems affecting its operability, such as fortuitous events or force majeure. The financial institution must ensure that the service provider performs periodic tests of its recovery and backup systems, and that the latter notifies the institution about the results of said tests. Additionally, the financial institution must be notified in case the service provider makes significant changes to its contingency plans, or when it presents other circumstances that could have a significant impact on the service.

Art. 22. Audit.- The contract must stipulate, clearly, the audit requirements and rights of both parties. At a minimum, the financial institution must have the faculty to evaluate the service provided or

10

alternatively, allow an independent auditor to evaluate the service provided on its behalf. This evaluation must include an audit of the service provider's internal controls as they relate to the service provided.

Additionally, at all times, regardless of whether the activity is performed internally, contracted to a service provider, or provided by third parties, the Superintendence will retain its supervisory powers in accordance with the law. In this regard, it may directly request from the financial institution the information it deems necessary, as well as from the third-party provider regarding the contracted service.

Art. 23. Subcontracting.- The contract must contain rules or limitations on subcontracting by the primary service provider. In this case, the secondary service provider must comply with the provisions of this norm. In particular, confidentiality and security standards must be established for subcontracting by the primary service provider.

Art. 24. Confidentiality, Security, and Segregation of Property.- The contract must contain requirements for the confidentiality and security of information. The service provider's confidentiality and security policies must be in harmony with those of the financial institution and must meet reasonable standards according to the circumstances. The contract must establish which party is responsible for protection mechanisms, the information to be protected, the powers of each party to modify procedures and security requirements, the party that will be responsible in case of losses due to breaches of security mechanisms, and notification requirements when such breaches occur.

The service provider must be capable of segregating, at all times, the particular information of the financial institution from the information of its other clients, including in adverse situations.

Art. 25. Price.- The contracting contract must detail exhaustively the bases for the calculation of fees and compensation related to the service provided, as well as the frequency, place, and method of payment.

Art. 26. Insurance.- The service provider must notify the financial institution of significant changes in the coverage of the insurance policy/policies and must make known the terms and conditions of the insurance policy.

11

CHAPTER III

BUSINESS CONTINUITY PLAN AND MONITORING OF MATERIAL CONTRACTING AGREEMENTS

Art. 27. General Provision.- Every financial institution that is a signatory to material contracts must implement monitoring and control procedures for its risks in accordance with its risk management policies. The sophistication of the processes must be in concordance with the complexity of the contracting agreements. The management or the comprehensive risk management instance, in cases where the institution has this instance or when this responsibility corresponds to the latter by law or norm, must prepare reports on the monitoring and supervision activities of the contracting agreement. These reports must outline the degree of success of the agreement and the effectiveness of the risk management program and must be reflected in the documentation sent to the members of the financial institution's board of directors.

Art. 28. Contracting in Foreign Jurisdictions.- In cases where the material contracting agreement establishes that the service will be provided from a foreign jurisdiction, the financial institution's risk management program must be in accordance with any additional concerns related to the political and economic environment, technological sophistication, and the legal risk profile of the foreign jurisdiction.

Art. 29. Business Continuity Plan.- Financial institutions must prepare a business continuity plan. This plan must establish reasonably predictable situations, whether temporary or permanent, in which the service provider cannot continue providing the service. The plan and backup systems must be in concordance with the risk of service interruption. In particular, the financial institution must ensure that it is in possession of, or can access in a timely manner, all necessary records to continue business operations, comply with legal obligations, and provide the Superintendence with all information it requires to fulfill its supervisory function, in cases where the service provider is unable to continue providing it.

Art. 30. Centralized Registry.- Financial institutions must maintain a centralized registry of all their material operations or service contracting. The holding company, parent company, or responsible company may maintain such registry on behalf of its subsidiaries. Without prejudice to what is indicated in Article 4 of this norm, the registry must contain information regarding the name or corporate name of the service provider, the type of service provided, the place where the service is provided, the expiration or renewal date of the contracting agreement, and its monetary value. The registry must be constantly updated and must form part of the information sent to the members of the financial institution's board of directors and be available for review by the Superintendence when requested.

12

Art. 31. Monitoring of the Contracting Agreement.- The financial institution must monitor all operations contracting to ensure that the service is being provided as expected and in accordance with the terms of the contract. Monitoring may be carried out through periodic formal meetings with the service provider or through periodic reviews of the compliance parameters established in the contracting agreement. The financial institution must notify the Superintendence of any significant negative impact affecting the development of the service.

The financial institution must review all material operations contracting to ensure they are in compliance with its risk control policies and procedures and with the requirements of this norm. The review referred to in the previous paragraph must include the examination of the institution's risk control mechanisms to:

  • Ensure that risk management policies for operations or service contracting are being complied with;
  • Ensure effective control by the management of the financial institution over operations or service contracting activities;
  • Verify the truthfulness and accuracy of the reports prepared by the management of the financial institution; and,
  • Ensure that personnel involved in the risk management process for operations or service contracting know the institution's risk management policies and have the necessary knowledge to make decisions consistent with said policies.

The management or the comprehensive risk management instance of the institution must adjust the scope of the review depending on the contracting operation.

Art. 32. Internal Audit.- The internal audit of the financial institution must periodically review all internal operations contracting, verifying compliance with the provisions contained in this norm.

Art. 33. Monitoring of the Service Provider.- At least once a year, the financial institution must review the service provider's capacity to continue providing the service in the expected manner. This review must include an evaluation of the circumstances surrounding the

13

service provider, including its financial strength, projections, and technical competence.

TITLE IV

FINAL PROVISIONS

SINGLE CHAPTER

Art. 34. Basic Condition.- As established in numeral 5 of Article 55 of Law 561, General Law of Banks, Non-Bank Financial Institutions, and Financial Groups, in any negotiation with related parties, financial institutions must conduct them under conditions that do not differ from those applicable to any other unrelated party in comparable transactions. This condition being applicable, among others, to contractual services performed by or on behalf of the institution and to any transaction or series of transactions with third parties, natural or legal, in which the related party has a financial interest, or that the related party participates in said transaction or series of transactions.

Art. 35. Limitations on the Contracting of Operations or Services.- The Superintendant may, by reasoned resolution, suspend, limit, or prohibit the contracting of certain types of operations or services to third parties, taking into consideration the materiality of the contracting agreement and the protection of the public interest in financial intermediation, either specifically or generally.

Art. 36. Validity.- This Norm will enter into force upon its notification to the supervised financial institutions, without prejudice to its publication in La Gaceta, Official Diary.

ANNEX 1

ASPECTS TO EVALUATE THE MATERIALITY OF CONTRACTING AGREEMENTS

When evaluating the materiality of a specific contracting contract (or agreement), the financial institution must consider, at least, the following aspects:

  • The importance of the activity to be contracted in relation to the main business of the institution. Revenue flow generated by the internal operation to be contracted.
  • Potential impact of the contracting on earnings, solvency, liquidity, capital, reputation, funding, and internal control systems; or its importance in achieving and implementing the institution's objectives, strategies, and business plans.

14

  • Global exposure of the financial institution with respect to the service provider. Number or quantity of operations that the financial institution contracts with the same service provider.
  • In cases where the service provider cannot continue providing the service:
    1. Expected impact on the financial institution's clients;
    2. Possibility of affecting the institution's reputation;
    3. Materiality of the impact on the institution's risk profile;
    4. Possibility of the institution to contract an alternative service provider. Time and cost of this change.

ANNEX 2

PRE-EVALUATION (DUE DILIGENCE) OF SERVICE PROVIDERS

The pre-evaluation required in Article 12 of this Norm must include, at least, the following:

  • Experience and technical competence to implement the proposed operation;
  • Financial strength (audited financial statements and any other relevant information);
  • Commercial reputation, complaints, compliance, and pending litigation;
  • Internal Control;
  • Contingency plans, including technological recovery tests;
  • Dependence and success of the primary service provider with subcontractors;
  • Insurance coverage; and
  • Objectives, human resources policies, service philosophy, business culture, and the concordance of these with those of the financial institution.

(f) M. Flores L. (f) M. Alonso I. (f) V. Urcuyo V. (f) Antenor Rosales B. (f) Roberto Solórzano Ch. (f) Gabriel Pasos L. (f) Alfredo C. G. (f) U. Cerna B.

URIEL CERNA BARQUERO Secretary of the Board of Directors SIBOIF

More like this from SIBOIF

We email you every new SIBOIF publication the day it's published.

Share