2020-01-01

Added · Updated

Notice No. 3/2020

Notice No. 3/2020 consolidates and updates regulations on organizational culture, internal governance, internal control, risk management, remuneration policies, and related matters for supervised financial entities. It establishes the three-lines-of-defense model, mandates direct access for control functions to administrative bodies, requires annual self-assessments of governance and control systems, and sets rules for related-party transactions, auditor selection, and outsourcing. The notice revokes previous notices 5/2008 and 10/2011.

Banco de Portugal logo

Portugal

Banco de Portugal

Click to view thumbnail

Notice from the Bank of Portugal No. 3/2020 .................................................................................................................................................................................................. Published in: DR, 2nd Series, No. 136, Part E, of 15-07-2020 Mod. 99999910/T – 01/14 Index Text of the Notice Annex to the Notice Text of the Notice The exercise of financial activity inevitably involves the assumption of risks of various natures. These risks, if not properly managed, can compromise the viability and sustainability of an institution, with negative consequences for the preservation of financial stability. Thus, the exercise of this activity is subject to a set of prudential regulatory requirements, specifically designed to promote behaviors consistent with the preservation of financial stability and the protection of the interests of depositors and other clients. In this context, the regulation of conduct and culture, and the internal governance and organization of financial entities assumes special relevance. This matter is addressed by European Union law concerning the regulation of credit institutions, which has been transposed into the Portuguese legal order through the General Regime of Credit Institutions and Financial Companies. Additionally, as early as 2008, the Bank of Portugal issued Bank of Portugal Notice No. 5/2008, which regulates the internal control systems of supervised entities, and Bank of Portugal Notice No. 10/2011, which regulates the remuneration policies and practices of these same entities. More than ten years after the entry into force of Bank of Portugal Notice No. 5/2008, it appears necessary to review the solutions contained therein, in light of developments in European and Portuguese legislation on these matters, the guidelines of the European Banking Authority (EBA), international best practices, the reflection and practical supervisory experience accumulated by the Bank of Portugal, as well as issues of legal certainty and security. This revision is used to incorporate into the present Notice the provisions of Bank of Portugal Notice No. 10/2011, with the objective of treating in an integrated manner the various matters of organizational culture and internal governance and control, in order to promote an integrated and holistic vision of them. The provisions of this Notice must be interpreted and applied taking into account the framework provided by European and Portuguese legislation, regulation, and guidelines on the matter. The concepts used in the Notice must be read, unless otherwise stated, taking into account the definitions contained in the General Regime of Credit Institutions and Financial Companies.

Bank of Portugal Notice No. 3/2020 .................................................................................................................................................................................................. Mod. 99999910/T – 01/14 Without prejudice to the requirements defined in this Notice, each entity is responsible for the decision and implementation of the internal organization model it considers most appropriate, taking into account the principle of proportionality and its specific characteristics and circumstances. This Notice, together with the law, and taking into account relevant EBA guidelines, serves as the framework for this choice and implementation, structuring it, and highlighting essential prudential objectives that cannot be neglected by supervised entities. Thus, this Notice deals with (i) conduct and organizational culture, (ii) internal governance, organizational structure and strategic planning, (iii) the internal control system and risk management, (iv) related parties and conflicts of interest, (v) whistleblowing, (vi) the outsourcing of operational tasks of internal control functions and the IT system supporting whistleblowing, (vii) policies for the selection and appointment of external auditors, (viii) remuneration policies and practices, (ix) financial groups, (x) self-assessment by regulated entities of the matters provided for herein, and (xi) documentation, information systematization and public disclosure of information. Each of these matters is particularly relevant for the sound and prudent management of activity by supervised entities, and the regime applicable to each of them is provided for in a separate chapter. The densification in this Notice of the theme of conduct and organizational culture is justified by the decisive influence it has on the way supervised entities manage their activity. In this regard, it is worth highlighting the report “Banking Conduct and Culture – A Permanent Mindset Change”, prepared by the G30 and published in November 2018, which states that conduct and organizational culture result from internal mechanisms that produce the values and behaviors that prevail in the institution and that shape the conduct of its employees, contributing to the creation of trust in institutions in general and to benefiting from a positive reputation among different internal and external stakeholder groups. According to the EBA guidelines on internal governance (EBA/GL/2017/11), disseminated through Bank of Portugal Circular Letter No. CC/2018/00000016, the concept of internal governance includes all criteria and principles related to the way (i) the objectives, strategies and risk management system of an institution are established, (ii) its business is organized, (iii) responsibilities and lines of authority are defined and allocated, (iv) reporting lines are configured, and (v) the internal control system is organized and implemented, including accounting procedures and remuneration policies. It also covers information production systems, outsourcing and business continuity management. In this context, it is emphasized that the selection and assessment of the adequacy of the members of the administrative and supervisory bodies (individually and collectively), and of holders of essential functions, must be initiated in a timely manner and be based on a sustained identification of the concrete needs of the supervised entity, taking into account its specific characteristics and circumstances. These same needs must underlie the decision regarding the number of members of the administrative and supervisory bodies and the creation of committees to support these bodies, thereby fostering sound and prudent management and effective internal supervision in each institution.

Bank of Portugal Notice No. 3/2020 .................................................................................................................................................................................................. Mod. 99999910/T – 01/14 Regarding those responsible for risk management, compliance and internal audit functions, in line with the provisions of the EBA guidelines on the assessment of the adequacy of members of administrative bodies and holders of essential functions (EBA/GL/2017/12), disseminated through Bank of Portugal Circular Letter No. CC/2018/00000018, this Notice establishes that the adequacy to exercise their respective functions is subject to assessment and authorization by the competent supervisory authority, at a time prior to their entry into office, in the case of credit institutions identified by the Bank of Portugal as Other Systemically Important Institutions (O-SII), pursuant to Article 138-Q of the General Regime of Credit Institutions and Financial Companies. In order to strengthen the conditions for external auditors to carry out their work with independence, impartiality and objectivity, the obligation is established for supervised entities to adopt policies for the selection and appointment of statutory auditors or statutory audit firms, with a minimum content which is established in the Notice. It is emphasized, in this regard, the need for institutions to also observe the provisions of the recommendations that may be issued by the Committee of European Auditing Oversight Bodies (CEAOB) on the matter. This topic is treated in this Notice to the extent that the policies adopted in this domain by supervised entities fall within their internal governance, naturally without prejudice to the supervisory competences over the audit activity attributed to the Securities Market Commission. Regarding internal control, and as provided for in the previous Bank of Portugal Notice No. 5/2008, it is important to bear in mind that the control environment of institutions reflects their attitude and actions towards internal control, resulting from (i) the convictions, preferences and value judgments manifested by the administrative body and the other employees of the institution regarding the internal control system, and (ii) the emphasis placed on internal control, the measures taken, the approved policies and procedures and the definition and implementation of the organizational structure. The control environment is influenced, inter alia, (i) by the standard of ethical values followed by the institution, (ii) by the existence of sufficient and adequate material, technical and human resources, (iii) by the degree of transparency of the organizational structure and its adequacy in relation to the complexity, size and nature of the institution's activity, (iv) by the clarity of the hierarchical chain and the responsibilities and competences attributed to each function, (v) by the quality of the strategic planning process, and (vi) by the degree of involvement of the administrative body in the activity developed. In order to ensure sound and prudent management, the analysis and decision-making process in supervised entities must be risk-sensitive, and based on credible, complete and as up-to-date information as possible. This Notice, like the EBA guidelines on internal governance (EBA/GL/2017/11), is based on the three-lines-of-defense model of the Institute of Internal Auditors, recently referred to by the European Systemic Risk Board in the report entitled “Macroprudential approaches to non-performing loans”, published in January 2019 and by the G30 in the report entitled “Banking Conduct and Culture – A Permanent Mindset Change”, published in November 2018. In broad terms, the three-lines-of-defense model is based on the distribution of distinct responsibilities in

Bank of Portugal Notice No. 3/2020 .................................................................................................................................................................................................. Mod. 99999910/T – 01/14 matters of governance and risk management by the different functions that make up each of the lines, which can be characterized, summarily, as follows:

  • First line: the business-generating units and related areas, which generate risk for the institution and are the first responsible for the identification, assessment, monitoring and control of the risks they incur, pursuant to Article 26 of this Notice;
  • Second line: the support and control functions, which include, inter alia, the risk management and compliance functions, which interact with the first-line functions with a view to the adequate identification, assessment, monitoring and control of the risks inherent in the activity developed by the first-line functions, pursuant to Articles 27 and 28 of this Notice;
  • Third line: the internal audit function, which carries out independent and risk-oriented analyses, pursuant to Article 32 of this Notice. Taking into account these three lines of defense, supervised entities must take into account their specificities when developing their internal control systems, and may, for example, split the lines of defense into various functions within the supervised entity. In any case, two fundamental premises must always be safeguarded: the first is that all risk-taking units are responsible for their primary management, for which it is essential to ensure that they establish the necessary and adequate mechanisms for this purpose and interact effectively with the second line of defense for this end. The second is that, regardless of the risk management model adopted, it must always be ensured that the risk management function has an aggregated and holistic view of all risks inherent in the institution's activity. It is worth mentioning that, for the purposes of this Notice, only risk management, compliance and internal audit functions and the function of controlling compliance with the regulatory framework provided for in Article 7 of Bank of Portugal Notice No. 2/2018, whenever it is segregated from the compliance function, correspond to internal control functions. Regarding these, the Notice establishes the requirements necessary to guarantee their organizational independence. In particular, it highlights the rule, with exceptions, that these functions must be established in structural units distinct from the units that develop activities that have the duty to monitor and control and in autonomous and independent structural units. However, although supervised entities must promote the independence of internal control functions from business objectives, they must not prevent virtuous interactions between the various lines of defense. The ultimate objective must always be the efficient and harmonious functioning of the internal control system, based on an adequate control environment, which involves all employees, each of whom is aware of the role they play in the system in question. Still regarding internal control functions, it is worth highlighting that this Notice establishes the obligation to have direct access to the administrative and supervisory bodies and to the committees supporting these bodies when constituted. With this rule, it is intended, on the one hand, that the aforementioned functions can transmit directly and immediately any information to the aforementioned bodies without the prior intervention of third parties and, on the other hand, that these bodies can request directly from the internal control functions. Considering the developments that have occurred, the categories of risks provided for in Bank of Portugal Notice No. 5/2008 have been eliminated, now referring to the provisions of the applicable legislation, regulation and guidelines. However, the same principle prevails that supervised entities adopt categories of risk that, collectively, cover all factors associated with the risk events to which they are or may become exposed. Regarding the process of information production, processing and reporting by institutions, the opportunity was taken to update Article 19 of Bank of Portugal Notice No. 5/2008, in light of the recommendations published in this domain by the Basel Committee on Banking Supervision. By its relevance and in line with the EBA guidelines currently in force on the matter (EBA/GL/2019/02), disseminated through Bank of Portugal Circular Letter No. CC/2019/00000065, this Notice also deals with the possibility of occasional outsourcing of operational tasks of internal control functions, establishing a specific regime to be observed by supervised entities when they resort to it. In parallel, and in line with what was already provided for in Bank of Portugal Notice No. 5/2008, this Notice establishes the possibility for institutions, when they are part of a financial group, to establish common services for the development of the responsibilities attributed to the risk management, compliance and internal audit functions. The specific regime to be observed in cases where this occurs is established in the chapter dedicated to financial groups, and it is now expressly provided that the entity providing the common service cannot be established in a jurisdiction with a legal regime that prevents or limits either the compliance by the institution with the legal and regulatory rules governing its activity, including at the level of the provision and circulation of information, or the exercise of supervision by the competent supervisory authority. One of the relevant sources of risk for supervised entities, and for the financial system, are conflicts of interest, with special emphasis on transactions with related parties and the acceptance of gratuities. The relevance of these matters led to their treatment in this Notice, establishing the obligation for supervised entities to adopt policies on these matters and the specific regimes to be observed regarding them. Regarding remuneration policies and practices, and also in line with the EBA guidelines on sound remuneration policies (EBA/GL/2015/22), disseminated through Bank of Portugal Circular Letter No. CC/2016/00000036, complementary rules to those contained in the General Regime of Credit Institutions and Financial Companies are established in this Notice, which are relevant for their practical implementation by supervised entities. Some of these rules were contained in Bank of Portugal Notice No. 10/2011, which is now revoked. The organization of supervised entities in groups raises a set of specific prudential concerns that justifies their treatment in a more densified manner in this Notice.

Bank of Portugal Notice No. 3/2020 .................................................................................................................................................................................................. Mod. 99999910/T – 01/14 In addition to the possibility of establishing common services for the development of risk management, compliance and internal audit functions, it is now also expressly stated that parent companies must have the necessary information to carry out a complete assessment of the group's risk profile and must know its structure, which must be transparent, so that not only the parent company, but also third parties, with particular emphasis on the supervisor, can fully understand how it is organized. The principle of transparency in the organization of financial groups and the principle of coherence of the internal control systems of financial groups are also expressly established. Pursuant to this Notice, supervised entities are now obliged to carry out a self-assessment of the adequacy and effectiveness of their organizational culture and their internal governance and control systems. This self-assessment is set out in an annual report prepared with reference to November 30 of each year. This report now includes, at a minimum, assessments prepared by the administrative and supervisory bodies of the supervised entities and reports prepared by the internal control functions containing an assessment on the independence of these functions and information on all deficiencies identified regarding them. The minimum content of these assessments is established in the Notice, clarifying the need for them to be comprehensive, conclusive and reasoned, and also identifying the internal and external sources of information that must be used to support the assessments carried out. The objective is to promote regular reflection by institutions on the degree of compliance with the matters treated in the Notice, so that the adoption of necessary measures to overcome any identified deficiencies is considered. Regarding the content of these assessments, it is worth highlighting that the requirements falling on the supervisory body regarding this matter are reviewed and clarified, these assessments now covering organizational culture and internal governance and control systems, in line with their responsibilities arising from national and European legislation. The assessment of the supervisory body thus now covers, inter alia, the entire internal control system. In this context, the role of the statutory auditor or statutory audit firm in this matter is also reviewed and clarified. Contrary to what happened in Bank of Portugal Notice No. 5/2008, this Notice no longer requires an independent opinion from the statutory auditor or statutory audit firm on the part of the internal control system relating to the process of preparation and disclosure of financial information. However, the work carried out by them must continue to serve as the basis for the assessments of the administrative and supervisory bodies, either through the work already provided for in the specific legislation on auditing or through additional work that is specifically contracted by the institution to assist in the assessment of organizational culture and the internal governance and control system. The same rationale is adopted when financial groups are involved, although the self-assessment reports relating to the groups are less comprehensive, focusing on internal control. Finally, the experience acquired also revealed the need to establish rules on document management. In this sense, in this Notice, the obligation is established for supervised entities to maintain, inter alia, an adequate documentary archive, ensuring that the documentation it comprises allows, inter alia, to unequivocally know the reasoning behind the decisions taken and the respective participants. The obligation is also established for supervised entities to systematize, in an integrated and updated manner, the information regarding the matters provided for in the Annex to this Notice. This information includes the descriptive part of the previous internal control report and, when requested, is made available immediately to the competent supervisory authority. The draft of this Notice was subject to public consultation, having heard the Securities Market Commission, the Insurance and Pension Funds Supervisory Authority and the National Data Protection Commission. In these terms, the Bank of Portugal, in the exercise of the competences conferred upon it by Article 17 of its Organic Law, approved by Law No. 5/98, of January 31, and by the provisions of paragraph 12 of Article 30-B, paragraph 2 of Article 99, paragraph 3 of Article 115, paragraph 3 of Article 115-G, paragraph 2 of Article 115-I, paragraph f) of paragraph 1 of Article 116, paragraph 8 of Article 116-AA and paragraph c) of Article 133, all of the General Regime of Credit Institutions and Financial Companies, approved by Dec

More like this from BDP

BDP published 2 documents in the last 30 days. We email you each new one the day it's published.

Share