2012-07-11 | CD-SIBOIF-736-1-JUL11-2012

Added · Updated

Norma sobre Control y Auditoría Interna de Bancos y Sociedades Financieras

This resolution establishes the regulatory framework for internal control and internal audit functions within banks and financial societies supervised by the Superintendence of Banks and Other Financial Institutions. It mandates that financial institutions implement an internal control system and maintain an Internal Audit Unit (UAI) that operates with technical independence under the Board of Directors. The document defines specific responsibilities for the Board of Directors and General Management, outlines the minimum functions and characteristics of the UAI, and sets qualification requirements for the Internal Auditor, including restrictions on recent employment history to prevent conflicts of interest.

Superintendencia de Bancos y de Otras Instituciones Financieras logo

Nicaragua

Superintendencia de Bancos y de Otras Instituciones Financieras

Click to view thumbnail

1 Resolution No. CD-SIBOIF-736-1-JUL11-2012 Dated July 11, 2012

NORMA SOBRE CONTROL Y AUDITORÍA INTERNA DE BANCOS Y SOCIEDADES FINANCIERAS

The Board of Directors of the Superintendence of Banks and Other Financial Institutions,

CONSIDERING

I

That Article 41 of Law No. 561, General Law of Banks, Non-Banking Financial Institutions and Financial Groups, published in La Gaceta, Official Journal No. 232, of November 30, 2005, in its relevant parts establishes that without prejudice to the surveillance and oversight of banks and branches of foreign banks corresponding to the Superintendent of Banks, said banks and branches must have an internal auditor whose responsibilities will include the inspection and oversight of the operations and accounts of the respective bank or branch of a foreign bank. Likewise, that the Board of Directors of the Superintendence may issue general norms that internal auditors of banks must comply with in the performance of their functions.

II

That an effective internal audit function allows the financial institution to permanently evaluate the quality of its internal control system and reduce potential risks of losses and damages; likewise, it constitutes a fundamental mechanism of support for the supervision and control carried out by the Superintendence.

III

That it is necessary to update the minimum criteria required for the exercise of the internal audit function of supervised financial institutions in accordance with international standards and best practices in the matter, as well as to progressively adapt their procedures and work techniques to a risk-based audit approach (RBA).

IV

That in accordance with the foregoing and based on the powers established in Article 10, items 2) and 10), of Law No. 316, Law of the Superintendence of Banks and Other Financial Institutions, and its reforms.

In exercise of its powers,

HAS ISSUED

Resolution CD-SIBOIF-736-1-JUL11-2012

2

The following:

NORMA SOBRE CONTROL Y AUDITORÍA INTERNA DE BANCOS Y SOCIEDADES FINANCIERAS

CHAPTER I CONCEPTS, OBJECT AND SCOPE

Article 1. Concepts.- 1 For the purposes of this norm, the terms indicated in this article, both in uppercase and lowercase, singular or plural, shall have the following meanings:

a) Unplanned activities: Special examinations that are not included in the annual work plan and that are necessary for the evaluation of the functioning of the internal control system and its different components.

b) Planned activities: Activities authorized by the board of directors of the financial institution, which must be executed promptly by the Internal Audit Unit, with the objective of examining, evaluating and monitoring the adequacy and effectiveness of the internal control systems.

c) Information System Audit and Control Association: International association dedicated to developing international standards in the matter of control and audit of information systems, better known by its English acronym as ISACA (Information System Audit and Control Association).

d) Risk-Based Audit (RBA): Set of processes through which the internal audit unit evaluates: i) whether the risk management processes and measures implemented by the financial institution are functioning as expected; ii) whether the risk management processes are appropriate and well designed; and, iii) whether the risk control measures implemented by general management are adequate and effective, and reduce the risk to the level of tolerance accepted by the board of directors.

e) Audit committee or committee: The Audit Committee appointed by the board of directors of the financial institution.

f) Days: Calendar days, unless it is expressly established that it refers to business days.

g) Significant events: These are constituted by those events that may have a material impact on liquidity, solvency, image, among other aspects of the institution. The materiality of an event will depend on whether it has the potential to cause an important impact, whether quantitative or qualitative, on an important business line of the institution or on its operations in general. To this end, the internal auditor must apply their best professional judgment to determine those events that they consider may potentially impact the institution and require reporting due to their significant nature.

h) Institution or Financial Institution: Banks and financial societies, the latter constituted in accordance with the General Law of Banks and what is established in Decree No. 15-L, published in La Gaceta, Official Journal No. 77 of April 10, 1970, insofar as it is relevant.

i) Institute of Internal Auditors: International association dedicated to the continuous professional development of the internal auditor and the internal audit profession, better known by its English acronym as IIA (The Institute of Internal Auditors).

j) Board of Directors: Main administrative body of financial institutions.

k) General Shareholders' Meeting: Highest decision-making body of the financial institution, whose agreements must be complied with and executed by the administration.

l) General Law of Banks: Law 561, General Law of Banks, Non-Banking Financial Institutions and Financial Groups, published in the Official Journal Gazette No. 232, of November 30, 2005.

m) Manual: Internal Audit Manual containing the policies, procedures and audit techniques to be used to evaluate the functioning of the internal control system of the supervised institution.

n) Accounting Framework: Accounting Framework for Banking and Financial Institutions.

o) International Standards for the Professional Practice of Internal Auditing: Standards issued by the Institute of Internal Auditors that serve as an international reference in the matter.

p) Plan: Annual work plan containing the general guidelines, objectives, scope and planned activities developed by the internal audit unit during each fiscal year.

q) Internal control system: Set of policies, procedures and control techniques established by the financial institution to provide reasonable assurance in the achievement of adequate administrative organization and operational efficiency, reliability of reports flowing from its information systems, appropriate identification and administration of the risks it faces in its operations and activities and compliance with the legal and regulatory provisions applicable to it.

r) Superintendence: Superintendence of Banks and Other Financial Institutions.

s) Superintendent: Superintendent of Banks and Other Financial Institutions.

3

m) Manual: Internal Audit Manual containing the policies, procedures and audit techniques to be used to evaluate the functioning of the internal control system of the supervised institution.

n) Accounting Framework: Accounting Framework for Banking and Financial Institutions.

o) International Standards for the Professional Practice of Internal Auditing: Standards issued by the Institute of Internal Auditors that serve as an international reference in the matter.

p) Plan: Annual work plan containing the general guidelines, objectives, scope and planned activities developed by the internal audit unit during each fiscal year.

q) Internal control system: Set of policies, procedures and control techniques established by the financial institution to provide reasonable assurance in the achievement of adequate administrative organization and operational efficiency, reliability of reports flowing from its information systems, appropriate identification and administration of the risks it faces in its operations and activities and compliance with the legal and regulatory provisions applicable to it.

r) Superintendence: Superintendence of Banks and Other Financial Institutions.

s) Superintendent: Superintendent of Banks and Other Financial Institutions.

t) IAU or Internal Audit Unit: Refers to the internal audit unit under the responsibility of an internal auditor.

Article 2. Object.- The object of this norm is to regulate the scope of internal audits and establish guidelines so that the board of directors of the financial institution, through its IAU, permanently oversees the efficiency of the internal control systems and the compliance with its policies and procedures with the aim of minimizing risks, using the principles established in this norm and in generally accepted audit techniques.

Article 3. Scope.- The provisions of this norm are applicable to supervised financial institutions, insofar as they are relevant.

CHAPTER II INTERNAL CONTROL

Article 4. Mandatory Nature of an Internal Control System.- Financial institutions are obligated to have an internal control system that, at a minimum, contains a set of policies, procedures and control techniques established by the financial institution to provide reasonable assurance in the safeguarding of assets and to achieve adequate administrative organization and operational efficiency, reliability of reports flowing from their information systems, appropriate identification and administration of the risks they face, and compliance with the legal and regulatory provisions applicable to them.

CHAPTER III BOARD OF DIRECTORS AND GENERAL MANAGEMENT

Article 5. Responsibilities of the Board of Directors.- Regarding internal control, the board of directors of the financial institution is responsible for adopting, at a minimum, the following measures:

a) Issue policies oriented towards establishing an adequate internal control system. These measures must include the manner of keeping board members permanently informed.

b) Ensure the effectiveness and efficiency of the internal control system implemented by the institution.

c) Meet at least once a month, without prejudice to extraordinary meetings, to address matters that require prompt attention.

d) Keep a Minutes Book where the topics addressed are recorded, signed as provided in Article 27 of the General Law of Banks, so that the analysis, discussion and decision-making on said topics can be verified, as well as the follow-up exercise on the implementation of decisions and measures adopted.

e) Constitute the audit committee and ratify its rules of procedure.

f) Form an IAU under the responsibility of an internal auditor who complies with what is established in Article 41 of the General Law of Banks and the requirements established in this norm and in the regulations governing the matter on requirements to be a director, general manager and/or chief executive and internal auditor of financial institutions.

g) Ensure that the IAU develops its functions with absolute technical independence in accordance with the provisions established in the law and this norm.

h) Ensure that the segregation of functions between business areas and administration and control bodies is clearly delimited.

i) Ensure that IAU members are effectively separated from administrative and/or operational functions, inappropriate for the independent function of auditing.

j) Ensure the effectiveness of the design and functioning of the internal control structure and environment, to determine if it is functioning according to its objectives, and modify it when necessary.

k) Ensure that the IAU, in the fulfillment of its functions, is guaranteed unrestricted access or reservations of any nature, to all documentation, books, files, or records of any type, whether physical or electronic.

l) Ensure that recommendations derived from internal and external audit reports, as well as instructions from the Superintendent, are implemented.

m) Ensure appropriate conditions for the development of the internal audit function, assigning the resources required by the IAU.

Article 6. Responsibilities of General Management.- Regarding internal control, the general management of the financial institution is responsible for adopting, at a minimum, the following measures:

a) Design, develop and implement an internal control system that allows identifying, measuring, monitoring and controlling the risks inherent to the financial institution.

b) Delimit the functions and responsibilities of business areas and administration and control bodies.

c) Ensure that administration and control bodies implement and execute the provisions established in guidelines and policies emanating from the board of directors.

d) Take immediate action and adopt necessary corrective measures on any significant situation or finding detected that requires its prevention or correction.

e) Implement recommendations derived from internal and external audit reports, as well as instructions from the Superintendent.

f) Guarantee the budget required to ensure that the IAU has the appropriate infrastructure and financial, human, technical, logistical and training resources adequate to the magnitude and complexity of the institution's operations, as well as to the risks it faces or in the face of new emerging risks.

g) Inform the IAU in a timely manner about the development of new initiatives, projects, products, services or operational changes in the pre-launch stage.

CHAPTER IV INTERNAL AUDIT UNIT

Article 7. Characteristics of the Audit Unit.- Financial institutions must have an IAU. In the case of foreign financial institutions established in the country, the functions of the IAU may be assisted by the parent institution of said institution, subject to the provisions established in Article 41 of the General Law of Banks and the provisions established in this norm.

The IAU will have the following characteristics:

a) It will be in charge of an internal auditor appointed in accordance with what is ordered in Article 41 of the General Law of Banks and with the requirements established in this norm and in the regulations governing the matter on requirements to be a director, general manager and/or chief executive and internal auditor of financial institutions.

b) Its members must be effectively separated from the administrative and operational functions of the financial institution.

c) It will depend organically, functionally and administratively on the board of directors of the supervised financial institution, before whom it will periodically present the reports that are necessary, without prejudice to the quarterly report that must be rendered, in accordance with what is established in Article 41 of the General Law of Banks.

d) It will fulfill its functions and objectives in a timely, independent, effective and efficient manner.

e) It will have direct access to all information required for the fulfillment of its functions and the development of its examinations, without any limitation that could affect its conclusions, including that which derives from minutes of partners, the board and its committees, and any other governing body, management or administrative level. Any limitation to the access of the aforementioned information must be communicated to the board of directors of the institution with a copy to the Superintendent.

f) It must have appropriate infrastructure and human, technical and logistical resources adequate to the magnitude and complexity of the institution's operations, as well as to the risks it faces and in the face of new emerging risks.

The internal auditor and other auditors who make up the IAU must receive permanent training in matters related to their functions, for which it corresponds to the internal auditor to present the training needs regarding the members of the IAU, indicating the main areas of training and the number of hours required annually, a request that must be presented and discussed in the audit committee and authorized by the board of directors.

All information obtained by the IAU is subject to banking secrecy, in accordance with what is established in Article 113 of the General Law of Banks.

Article 8. Functions of the Audit Unit. 2 The IAU will have the following minimum functions:

a) Evaluate the design, execution, effectiveness and sufficiency of the internal control system.

b) Evaluate compliance with the legal and regulatory provisions governing the financial institution.

c) Evaluate compliance with the policies, procedures and other internal norms of the financial institution.

d) Evaluate the reliability, confidentiality, availability, effectiveness, integrity and functionality of information technology and the control mechanisms and use established by the financial institution to guarantee its security and protection.

e) Evaluate compliance with the security, availability, functionality, reliability, auditability, efficiency, effectiveness and integrity conditions of information systems.

f) In accordance with audit standards and based on the institution's Audit Risk Matrix, design the annual work plan and submit it to the board of directors through the audit committee for approval, and send it to the Superintendent for their knowledge. Likewise, comply with the planned activities in the annual work plan and prepare the respective reports.

g) Carry out unplanned activities when deemed necessary or at the express request of the board of directors or the Superintendent.

h) Evaluate the sufficiency, effectiveness and compliance of the integral system for the prevention and administration of money laundering, goods or assets risk; terrorism financing and financing of the proliferation of weapons of mass destruction, in accordance with the current legal and regulatory provisions specific to carrying out the independent audit or evaluation of the PLA/FT/FP matter.

i) Verify the organizational structure authorized by the board of directors of the financial institution in relation to the effective segregation of functions and exercise of powers attributed to each of the institution's officials.

j) Carry out regular and independent reviews of the risk management system developed by the financial institution to relate the different risks at the capital level and the method established to monitor compliance with internal capital policies.

k) Evaluate compliance with other aspects determined by the board of directors, the audit committee and the Superintendent.

l) Carry out permanent follow-up on the implementation and compliance with orders, instructions and/or recommendations formulated by the Superintendent, by external auditors and by the IAU itself.

Article 9. Qualities of the Audit Unit.- The persons who make up the IAU must possess the knowledge, technical aptitudes, experience and other qualities required for the fulfillment of their responsibilities in accordance with the specificities, risks, products and services of each institution.

Without prejudice to the foregoing, every IAU must have an information systems audit service that collaborates in the achievement of its functions and objectives. This service must have competent personnel and specific experience in systems auditing, appropriate in competencies to the complexity and size of the operations carried out by the financial institution, which may also be subcontracted.

Article 10. Subcontracting.- Financial institutions may subcontract functions assigned to the IAU in order to access advantages of a technical, resource, methodological nature, among others. This type of subcontracting must comply with what is established in Article 130 of the General Law of Banks, with the requirements indicated in this norm and with what is established in the regulations governing the matter on contracting service providers for the performance of operations or services on behalf of financial institutions.

Regardless of the level of subcontracting, the internal auditor remains responsible for ensuring that internal audit functions properly and effectively, and in accordance with what is foreseen in this norm and according to the service agreement or contract signed with the provider.

The internal auditor is responsible for supervising compliance with the service contract, ensuring the general quality of activities, reporting to the audit committee, as well as carrying out follow-up on the results of the contracted work. This implies direction, administration and follow-up of the activity carried out by the third party, not delegating decision-making regarding the priority of risks to be reviewed.

Likewise, in order to avoid possible conflicts of interest, the internal auditor must ensure that personnel subcontracted by the financial institution does not perform functions other than those of internal audit, such as: accounting services; information system operation; local network administration; operation, supervision, design or implementation of computer systems (hardware and software); valuations, appraisals or estimates; administration; representation and resolution of legal and tax conflicts; personnel recruitment; training or consultancies.

Article 11. Audit Procedures and Techniques.- The audit procedures and techniques used by the IAU must comply with the provisions established in this norm and what is established in the International Standards for the Professional Practice of Internal Auditing and in the Code of Ethics issued by the Institute of Internal Auditors.

In the case of systems auditors, the audit guidelines provided by the Information System Audit and Control Association will be taken into consideration.

Likewise, said audit procedures and techniques must be contained in the respective internal audit manual.

CHAPTER V INTERNAL AUDITOR

Article 12. Appointment of the Internal Auditor.- The IAU will be in charge of the Internal Auditor, a full-time official with exclusive dedication, whose appointment will be made in accordance with Article 41 of the General Law of Banks.

In order to avoid possible conflicts of interest, financial institutions cannot appoint as internal auditor persons who in the last twelve (12) months have held positions in the accounting area or managerial positions in operational areas or business units, in the same institution.

Article 13. Requirements of the Internal Auditor.- The interested party who wishes to provide their services to a financial institution as an internal auditor must comply with the qualification criteria and information requirements established in the regulations governing the matter on requirements to be a director, general manager and/or chief executive and internal auditor of financial institutions; as well as, with the requirements established in this norm. The Superintendent may consider the appointment of an internal auditor who does not meet the minimum requirement of five (5) years of experience at an adequate level of magnitude and complexity of the responsibility to be performed, established in the aforementioned norm, when they meet the following qualities:

2 Arto.8, reformado el 10 de septiembre de 2019 - Resolución N° CD-SIBOIF-1129-1-SEP10-2019

1 Arto.1, reformado el 10 de septiembre de 2019 - Resolución N° CD-SIBOIF-1129-1-SEP10-2019

10

a) Have at least three (3) years of experience in auditing financial institutions; and b) Relevant academic qualifications, such as: postgraduate studies, master's degrees, or doctorates related to the position. To prove compliance with the requirements set forth in the aforementioned letters, the financial institution must present the documentation required by the regulation governing the matter on requirements to be a director, general manager, and/or principal executive and internal auditor of financial institutions.

Article 14. Responsibilities of the Internal Auditor.- The internal auditor is responsible for complying, at a minimum, with the following: a) Report in writing to the Superintendent in the event of a temporary absence from their position of more than thirty (30) days and regarding any other modification in the composition of the Internal Audit Unit (UAI) that significantly affects its functioning and independence. b) Verify that practices favoring the partners, directors, or administrators of the financial institution do not occur, which could constitute a detriment to the interest of the clients. If the existence of any practice of this nature is verified, they must report it in writing, immediately and simultaneously to the Audit Committee and to the Superintendent. c) Communicate the occurrence of significant facts immediately, directly, and simultaneously, to the supervisor elected by the shareholders' general meeting or to the head office when it concerns branches of foreign institutions, to the Superintendent, to the audit committee, and to the board of directors of the financial institution. Such communication must be made no later than within three (3) days following the knowledge of the facts. d) Evaluate at least once a year the performance of the members who make up the UAI. e) Ensure compliance with the provisions established by law and in this Norm.

Article 15. Removal of the Internal Auditor.- The removal of the internal auditor, before the expiration of their term, must be done in accordance with what is established in Article 41 of the General Banking Law. The Superintendent may request a report from the internal auditor, who must present it no later than on the date indicated to them. Once the aforementioned term has passed, the Superintendent, within eight (8) business days thereafter, by reasoned resolution, will determine what they consider pertinent. In this case, the lack of an internal auditor cannot last more than sixty (60) days.

Article 16. Interim Internal Auditor.- With prior authorization from the Superintendent, the UAI may be in charge of an interim internal auditor appointed by the board of directors for a period of up to six (6) months, except in the case of removal of the internal auditor, in which case, the UAI may be in their charge for a period of up to sixty (60) days as provided in Article

11

preceding. The interim auditor must meet the same requirements established in this norm for the case of the internal auditor.

CHAPTER VI ANNUAL WORK PLAN

Article 17. Minimum Content of the Annual Work Plan.- The preparation of the annual work plan is the responsibility of the UAI, which must be based on a risk assessment, in order to determine the priorities of the audit activity and be in accordance with the volume and complexity of the operations of each financial institution. The plan must be presented to the audit committee and approved by the board of directors within the last quarter of the year immediately preceding its execution and a copy must be sent to the Superintendent in the first half of the month of January of the following year, and must contain, at least, the following aspects: a) Annual objectives and scope of the UAI plan. b) Schedule of programmed activities, whose minimum content is that provided in the following article, unless the financial institution obtains authorization from the Superintendent in accordance with what is established in Article 19 of this norm. This schedule must include the dates and deadlines detailed by activity; probable dates for the presentation of reports and updates; and the follow-up to observations formulated by the Superintendent. c) Human, technical, and logistical resources available for the fulfillment of the plan, indicating the administrative structure, the structure of the personnel who make up the UAI, the positions they hold, and their professional training, indicating, if applicable, the need to hire specialized services.

Article 18. Programmed Activities.- The programmed activities of financial institutions must include, at a minimum, the aspects detailed below, without prejudice to the fact that the Superintendent may issue instructions on other activities that must be included in said plan: a) Evaluation of the criteria for allocation and compliance with capital requirements for each risk, the calculation of leverage, and total effective equity. b) Evaluation of credit risk management, which must include the review of the effectiveness of operational and accounting controls in the management of the credit portfolio, evaluating in particular the following:

  1. The organizational structure, to verify that there is a clear definition and delimitation of functions and responsibilities (the functions of authorization, accounting recording, and review or control of risks must be segregated).
  2. The degree of compliance with the policies, provisions, and guidelines issued by the board of directors of the financial institution.
  3. If credit risks are duly authorized and within the limits assigned to each committee. Furthermore, verify their correct accounting classification, quality of operations (valuation), and their adequate protection against losses due to poor instrumentation, dishonesty, etc.
  4. The institution's asset recovery system.
  5. The results and procedures for the evaluation and classification of the credit portfolio.
  6. The identification and classification of related credits and significant linkage.
  7. The criteria for debtor evaluation, such as: payment capacity and indebtedness, quality of guarantees, among others.
  8. The evaluation of the management of credit exchange rate risk. c) Evaluation of the management of financial risks (market and liquidity) and compliance with the procedures used for the administration of said risks. d) Evaluation of operational risk management and compliance with the procedures used for the administration of said risk. e) Evaluation of compliance with the provisions indicated in the regulation governing the matter on concentration limits. f) Evaluation of compliance with the provisions indicated in the regulation governing the matter on financial groups. g) Evaluation of the nature and frequency of claims presented to financial institutions; as well as, the treatment and solution given to them. h) Evaluation of the procedures and controls established for the administration of the existing information technology in the institution. i) Evaluation of the effectiveness and reliability of information systems and internal control procedures.

13

j) Evaluation of the procedures and controls established for the management of risks related to the prevention of money laundering and terrorist financing, in accordance with the laws and regulation governing this matter. k) Evaluation of the compliance with the recommendations formulated by the UAI and external auditors; as well as, the instructions of the Superintendent. l) The other evaluations that financial institutions must perform periodically in accordance with the regulations issued by the Superintendent.

Article 19. Risk-Based Audit Plan (PBR).- Financial institutions that have solid internal audit practices and adequate compliance with the criteria provided in this norm may consider in the formulation of their annual work plan only those programmed activities that are relevant according to their own risk-based audit methodology; in which case, they must include for each programmed activity that was not included in their plan, the reasons supporting the decision not to have considered it in the audit plan for that year. Once the PBR is approved by the board of directors, a copy of it must be sent to the Superintendent no later than in the term established in the first paragraph of Article 17 of this norm, attaching the following documents: a) Description of the risk-based audit approach and associated methodology; and b) Self-assessment performed by the internal auditor on the degree of compliance with the International Standards for the Professional Practice of Internal Auditing issued by the Institute of Internal Auditors, and the measures they will take regarding cases where there is a significant deviation. The Superintendent may at any time instruct the inclusion of certain activities excluded by the institution in its PBR. Without prejudice to the foregoing, financial institutions must always include in their annual work plan the evaluation of the program established by the institution for the management of the prevention of money laundering and terrorist financing risks.

Article 20. Modifications to the Annual Work Plan.- Substantive modifications made to the Annual Work Plan must be communicated to the Superintendent within five (5) days of their approval, accompanied by a copy of the agreement of the respective board of directors session where the reasons that gave rise to them are specified. The Superintendent may object to said modifications by resolution or suggest others.

14

Article 21. Report on the Progress of the Plan.- The internal auditor must present within twenty (20) days following the closing of each quarter, a quarterly progress report of the Annual Work Plan to the board of directors, to the audit committee, to the supervisor, and to the Superintendent. The report consists of a summary of the programmed activities carried out, of the programmed activities not carried out (including the incidents or reasons for non-compliance) and the date on which they will be executed, and of the activities carried out but not programmed according to said plan. Likewise, it will be the responsibility of the internal auditor to indicate in said report that they did not detect any significant fact that should have been communicated to the aforementioned instances, if applicable.

CHAPTER VII AUDIT REPORTS AND ARCHIVES

Article 22. Presentation of Reports.- The internal auditor must present to the audit committee all the reports they prepare in compliance with their functions. Said committee will evaluate the respective final reports and, at least quarterly, present them to the board of directors. The opportunity at which said committee becomes aware of the reports and the decisions adopted regarding them must be recorded in the respective minutes book.

Article 23. Minimum Content of the Reports.- The reports prepared by the UAI must contain, at least, the following aspects: a) Objective and scope of the evaluation. b) Methodology, procedures, and audit techniques employed. c) Evaluation of the situation of the activity or operation as of the date of the report, identifying the risks detected and their impact on the financial institution, as well as, the evaluation of the procedures and controls used by it. d) Corrective measures recommended and/or adopted to remedy the problems or deficiencies identified, as appropriate. e) Name of the officials responsible for the evaluation; and f) Start and end date of the evaluation.

15

Article 24. Archiving and Conservation of Documents.- The UAI must maintain a file containing the reports prepared (programmed and non-programmed) and other communications it maintains with the different units or areas of the financial institution, as well as the working papers and supporting documentation thereof. This information must be available to the Superintendent and to the external audit firm hired for the annual review of the operations of the corresponding period. The UAI must conserve electronically or physically, for a minimum period of five (5) years, counted from the date of delivery of the respective final reports, the working papers and all the documentation that adequately supports the audit reports issued by them.

CHAPTER VIII AUDIT COMMITTEE

Article 25. Audit Committee.- The board of directors of supervised institutions must constitute an audit committee by resolution to assist them in the fulfillment of their oversight responsibilities for the financial information process, risk management, internal control, audit, and the process used by the institution to monitor compliance with laws, regulations, norms, code of conduct, among others. The audit committee must be composed, at a minimum, of three members of the board of directors, who will be presided over by one of them, who will be appointed by said board, and who will have the responsibility to inform the board of directors of the facts, situations, and resolutions that are known, discussed, or agreed upon in their meetings. At least one of the members of this committee must have experience in risk management, financial reporting, accounting, or auditing. The internal auditor may participate permanently in the committee with voice, but without vote. Occasionally, the president, the executive director, the general manager, the external auditor, and any other official they consider pertinent may participate in the audit committee as guests, with voice but without vote. When the principal executive of the financial institution is a member of its board of directors, they cannot in turn be a member of the audit committee. Likewise, they cannot participate in board of directors sessions when said body knows the reports of said committee, without prejudice that they may occasionally be invited to participate with right to voice, but without vote.

Article 26. Conflicts of Interest.- When any member or occasional guest of the audit committee has a personal interest or conflict of interest regarding any matter that is addressed by said committee, they must abstain from knowing the case, not be present during the discussion, nor influence the related topic, which must be recorded in the minutes.

Article 27. Obligations of the Audit Committee.- The members of the audit committee will have the following minimum obligations:

16

a) Meet ordinarily at least every two months, without prejudice to extraordinary meetings to deal with matters that require prompt attention. b) Inform the board of directors, at least every three months, of the results of the final audit reports presented by the internal auditor. c) Keep a Minutes Book where the topics addressed are recorded, signed by each of the members, so that the analysis, discussion, and decision-making on said topics can be verified, as well as, the exercise of follow-up on the implementation of decisions and measures adopted. d) Propose the terms of reference for the hiring of external audits that must be carried out, in accordance with the regulation governing this matter. e) Know and analyze the terms of external audit contracts and the sufficiency of the relevant plans and procedures, in concordance with the regulation governing this matter. f) In addition to the tasks entrusted to it by the board of directors, it must perform the following:

  1. Serve as a means of communication between the board of directors and the UAI and between the board of directors and external audit, regarding matters detailed below: i. Quarterly, semi-annual, and annual financial statements. ii. Scope and results of semi-annual and annual examinations. iii. Accounting and financial practices of the institution. iv. Effectiveness and quality of the internal accounting control system. v. Scope of other services provided by external auditors. vi. Any other matter related to the audit of the institution's accounts and its financial aspects, which the committee deems necessary to consider, at its discretion.
  2. Ensure compliance with the Annual Work Plan of the UAI and propose modifications to it.
  3. Attend to the proposals formulated by the UAI aimed at strengthening the internal control system and resolve situations that prevent its work.
  4. Follow up on the implementation of necessary actions to adequately comply with the recommendations given by the Superintendent, as well as, with the recommendations that have emanated from internal and external audit.
  5. Evaluate the performance of the internal auditor at least once a year.

17

  1. Recommend to the board of directors, within their competence, the removal or re-election of the internal and external auditor.

Article 28. Main Functions of the Audit Committee.- 3 The audit committee will have the following functions: a) Regarding financial statements. Review the financial statements at the close of the period, with the general manager or principal executive and with the external auditors themselves, in order to determine:

  1. If they are presented in accordance with the Accounting Framework.
  2. If all matters and transactions or special events that must be disclosed in notes to the financial statements have been appropriately considered.
  3. If the decisions taken by management are reasonable regarding the significant areas of asset valuation and determination of obligations, when the criterion is an important factor in the determination.
  4. How the most important financial problems found in the preparation of the financial statements were resolved.
  5. The wide exchange of ideas with management and with external auditors on the most important aspects and items of the financial statements and notes thereto. In certain cases, however, it will be necessary a detailed analysis of each of the components of the financial statements, due to the fact that the preparation and content thereof is the responsibility of management. In many cases, however, the committee will probably want, the external auditors to participate in the review. b) Regarding the reports of external auditors: Review the result of the examination of the external auditors with them, considering:
  6. The content of the audit report, especially any limitation to the scope of the work or other matter that could have generated a modified opinion.
  7. Any difference between the scope of the planned work and that which was finally carried out, which had not previously been communicated to the attention of the committee.
  8. The resolution of the most important audit problems treated during previous meetings.
  9. Any difference of criterion between management and external auditors, regarding the Accounting Framework, treatment of specific transactions or events, disclosures in the financial statements, and adjustments resulting from the audit engagement.
  10. The recommendations of the external auditors for the improvement of the institution's accounting procedures and internal accounting control system.
  11. The written comments of the external auditors regarding matters of an irregular nature that may have been noticed during the examination.

3 Art. 28, reformed on September 10, 2019 - Resolution No. CD-SIBOIF-1129-1-SEP10-2019

18

  1. The views of the external auditors regarding the technical competence of the accounting management. c) Regarding internal control: It is convenient that the audit committee carefully informs itself of the internal control conditions of the financial institution and is interested in knowing the result of the studies and efforts the institution makes with the purpose of maintaining optimal controls. Emphasis must be placed on the activities of the UAI of the financial institution, of management, and of external auditors. In this particular, it is the responsibility of the Audit Committee:
  2. Ensure the effectiveness of the design and functioning of the internal control structure and environment, to determine if it is functioning according to its objectives, and modify it when necessary.
  3. Inform directly if internal auditors study and evaluate the efficiency and compliance of the internal control system and its regulations periodically, covering the following: i. The way in which those studies and evaluations are made. ii. If the policies and procedures of the financial institution clearly and appropriately define them and if they are duly communicated to all personnel. iii. If internal auditors have provided effective suggestions to improve those areas of accounting and administration where the policies and procedures of the institution are not being adequately complied with, and if the results of the reviews and the compliance with the institution's policies and controls have been treated with management. iv. Regarding meetings with management, the committee must deal at the appropriate level of management with matters concerning the definition of policies and procedures of the institution, regarding the existing internal controls and compliance with the norms of supervisory and control entities. Special care must be taken that said matters have been appropriately treated by general management. Likewise, the audit committee must obtain the views of management regarding the recommendations of internal and external auditors on internal control policies and the analysis of the cost/benefit relationship in the execution of those recommendations. v. The audit committee must inform, periodically and in writing, of its activities to the board of directors, this will allow each director to inform themselves of matters of a financial and administrative or management nature of the institution, which will serve so that they can better fulfill their responsibilities regarding the quality of the institution. d) Regarding audit and Superintendent recommendations: It is the responsibility of the Audit Committee to ensure that management implements the necessary actions to adequately and timely comply with the recommendations emanating from internal audit, external audit, as well as, the instructions of the Superintendent.

19 Article 29. Term of Office of the Audit Committee.- The board of directors of the institution shall determine the duration of the term of its representatives on said committee, which in no case may exceed three years, or until the end of the term of the board of directors, if it concludes before that period.

CHAPTER IX FINAL PROVISIONS

Article 30. Transitional.- Financial institutions shall have a period of three (3) months, counted from the entry into force of this norm, to adjust to the new requirements established therein. The Superintendent may extend the aforementioned period, upon request by a duly justified party, and must inform the Board of Directors of such extension.

Article 31. Repeal.- The Norm on Internal Control and Audit, contained in Resolution No. CD-SIBOIF-596-1-SEP9-2009, of September 9, 2009, published in La Gaceta, Official Journal No. 203, of October 27, 2009, is repealed.

Article 32. Entry into Force.- This Norm shall enter into force upon its notification, without prejudice to its publication in La Gaceta, Official Journal.

(f) J. Rojas R. (f) V. Urcuyo V. (f) Gabriel Pasos Lacayo (f) Fausto Reyes B. (f) illegible (Silvio Moisés Casco Marenco ) (f) illegible (Freddy José Blandón Argeñal) (f) U. Cerna B. URIEL CERNA BARQUERO SECRETARY OF THE BOARD OF DIRECTORS SIBOIF

More like this from SIBOIF

We email you every new SIBOIF publication the day it's published.

Share