2020-07-01 | 11/SEOJK.05/2020Added · Updated
This circular establishes the detailed procedures for assessing the health level of financing companies and Sharia financing companies in Indonesia, implementing provisions from POJK No. 35/2018, POJK No. 10/2019, and POJK No. 28/2020. It mandates a risk-based multifinance rating approach covering corporate governance, risk profile, profitability, and capital adequacy, with specific scoring tables for inherent risks such as strategic, operational, credit, market, liquidity, legal, compliance, and reputational risks. The document defines the general principles of assessment, including risk orientation and proportionality, and outlines the individual evaluation methods for both parent companies and their Sharia Business Units.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA
NUMBER: 11 /SEOJK.05/2020
CONCERNING
ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES AND SHARIA FINANCING COMPANIES
In relation to the mandate of the provisions of Article 109 of Financial Services Authority Regulation Number 35/POJK.05/2018 concerning the Conduct of Business by Financing Companies (State Gazette of the Republic of Indonesia Year 2018 Number 260, Supplement to the State Gazette of the Republic of Indonesia Number 6286), Article 106 of the Financial Services Authority Regulation Number 10/POJK.05/2019 concerning the Conduct of Business by Sharia Financing Companies and Sharia Business Units of Financing Companies (State Gazette of the Republic of Indonesia Year 2019 Number 40, Supplement to the State Gazette of the Republic of Indonesia Number 6320), and Article 7 paragraph (5), Article 8 paragraph (8), Article 9 paragraph (8), Article 10 paragraph (8), Article 12 paragraph (6), and Article 17 paragraph (5) of the Financial Services Authority Regulation Number 28/POJK.05/2020 concerning the Assessment of the Health Level of Non-Bank Financial Service Institutions (State Gazette of the Republic of Indonesia Year 2020 Number 120, Supplement to the State Gazette of the Republic of Indonesia Number 6504), it is necessary to further regulate the assessment of the health level of financing companies, Sharia financing companies, and Sharia business units of financing companies in this Financial Services Authority Circular as follows:
I. GENERAL PROVISIONS
Company means a financing company and a Sharia financing company.
Financing Company means a business entity that conducts financing activities for goods and/or services.
Sharia Financing Company means a Financing Company whose entire business activities conduct Sharia financing.
Sharia Business Unit, hereinafter abbreviated as UUS, is a working unit of the Financing Company's headquarters that conducts Sharia financing and/or functions as the head office of offices conducting Sharia financing.
General Meeting of Shareholders, hereinafter abbreviated as GMS, is the general meeting of shareholders as referred to in the laws concerning limited liability companies for Companies in the form of a limited liability company legal entity or equivalent to the GMS for Companies in the form of a cooperative legal entity.
Board of Directors is the company organ authorized and fully responsible for managing the company for the benefit of the company, in accordance with the purpose and objectives of the company and representing the company, both inside and outside of court, in accordance with the provisions of the articles of association for Companies in the form of a limited liability company legal entity or equivalent to the Board of Directors for Companies in the form of a cooperative legal entity.
Board of Commissioners is the company organ tasked with conducting general and/or specific supervision in accordance with the articles of association and providing advice to the Board of Directors for Companies in the form of a limited liability company legal entity or equivalent to the Board of Commissioners for Companies in the form of a cooperative legal entity.
Sharia Supervisory Board, hereinafter abbreviated as SSB, is a board that has the task and function of supervision and providing advice to the Board of Directors regarding the implementation of the Company's activities to ensure compliance with Sharia principles.
Company Health Level is the result of an assessment of the Company's condition conducted on good corporate governance, risk profile, profitability, and capital adequacy of the Company.
Composite Rating is the final rating result of the Company Health Level assessment.
Subsidiary Company is a company owned and/or controlled by the Company directly or indirectly, both domestically and abroad.
Control is an action aimed at influencing the management and/or policies of a company in any way, whether directly or indirectly.
II. GENERAL PRINCIPLES OF ASSESSING THE HEALTH LEVEL OF THE COMPANY
The general principles in conducting an assessment of the Company's Health Level are as follows:
a. risk-oriented; b. proportionality;
c. materiality and significance; and
d. comprehensive and structured.
The meaning of risk-oriented as referred to in item 1 letter a includes, among others:
a. the assessment of the Company's Health Level is based on the Company's risks and the impact they have on the Company's overall performance; b. the assessment of the Company's Health Level is conducted by identifying internal and external factors that can increase risk or affect the Company's financial performance at present and in the future; and
c. the Company is expected to be able to detect the root causes of the Company's problems earlier and take preventive and corrective measures effectively and efficiently.
The meaning of proportionality as referred to in item 1 letter b includes, among others:
a. the use of parameters or indicators in each factor of the Company's Health Level assessment is conducted by considering the characteristics and complexity of the Company's business; b. the parameters or indicators for assessing the Company's Health Level in this Financial Services Authority Circular are minimum standards that must be used in assessing the Company's Health Level; and
c. in addition to the parameters or indicators as referred to in letter b, the Company may use additional parameters or indicators in accordance with the characteristics and complexity of the business in assessing the Company's Health Level so as to reflect the Company's condition more accurately.
The meaning of materiality and significance as referred to in item 1 letter c includes, among others:
a. the Company needs to pay attention to the materiality and significance of the factors for assessing the Company's Health Level, namely good corporate governance, risk profile, profitability, and capital adequacy, as well as the significance of the parameters or indicators for assessment in each factor in concluding the assessment results and establishing factor ratings; and b. the determination of materiality and significance is based on analysis supported by adequate data and information regarding the Company's risks and financial performance.
The meaning of comprehensive and structured as referred to in item 1 letter d includes, among others:
a. the assessment process is conducted thoroughly and systematically and is focused on the Company's main problems; b. the analysis is conducted in an integrated manner, namely by considering the interrelationships between risks and between factors of the Company's Health Level assessment as well as consolidated Subsidiary Companies; and
c. the analysis must be supported by key facts and relevant ratios to show the level, trends, and degree of problems faced by the Company.
III. PROCEDURES FOR ASSESSING THE HEALTH LEVEL OF THE COMPANY INDIVIDUALLY
The Company is required to conduct an assessment of the Company's Health Level using a risk-based approach (risk-based multifinance rating) individually.
A Financing Company that has a UUS is required to conduct an assessment of the UUS's health level using an individual approach.
The individual assessment of the UUS's health level is an inseparable part of the assessment of the Company's Health Level of the Financing Company that is its parent.
The individual Health Level assessment as referred to in item 1 is conducted with an assessment scope covering the following factors:
a. good corporate governance; b. risk profile;
c. profitability; and
d. capital adequacy.
The individual health level assessment of the UUS as referred to in item 3 covers the assessment of the risk profile factor.
IV. ASSESSMENT OF THE GOOD CORPORATE GOVERNANCE FACTOR
The assessment of the good corporate governance factor is an assessment of the implementation of good corporate governance principles by the Company.
The principles of good corporate governance refer to Financial Services Authority Regulations regarding good corporate governance for financing companies and their implementing regulations, while still considering the characteristics and complexity of the Company's business.
The establishment of the rating for the good corporate governance factor is conducted based on an analysis of:
a. the implementation of good corporate governance principles in the Company; b. the adequacy of governance over the structure, processes, and results of governance implementation in the Company; and
c. other information related to the Company's governance based on relevant data and information.
The Company assesses the good corporate governance factor using its own assessment worksheet as contained in Table I.A Appendix I, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the rating for the good corporate governance factor categorized into 5 (five) ratings, namely:
a. rating 1; b. rating 2;
c. rating 3;
d. rating 4; and e. rating 5, with the order of the good corporate governance factor ratings being smaller reflecting better implementation of the Company's governance.
The establishment of the rating for the good corporate governance factor is conducted in accordance with Table I.B Appendix I, which is an inseparable part of this Financial Services Authority Circular.
V. ASSESSMENT OF THE RISK PROFILE FACTOR
A. General
The assessment of the risk profile factor is an assessment of:
a. inherent risk; and b. the quality of risk management implementation, in the Company's operations.
The risks assessed consist of 8 (eight) types of risks, namely:
a. strategic risk; b. operational risk;
c. credit risk;
d. market risk; e. liquidity risk; f. legal risk; g. compliance risk; and h. reputational risk.
In assessing the risk profile, the Company pays attention to the scope of risk management implementation as regulated in Financial Services Authority Regulations regarding the implementation of risk management for non-bank financial service institutions.
B. Assessment of Inherent Risk
The assessment of inherent risk is an assessment of risks inherent in the Company's business activities, both quantifiable and non-quantifiable, that have the potential to affect the Company's financial position.
The characteristics of the Company's inherent risk are determined by internal and external factors, including:
a. business strategy; b. business characteristics;
c. complexity of the Company's business activities;
d. conditions of the financing industry; and e. macroeconomic conditions.
The assessment of inherent risk is conducted by considering parameters or indicators that are quantitative or qualitative.
The establishment of the inherent risk level for each type of risk refers to the general principles of assessing the Company's Health Level as referred to in Section II.
The establishment of the inherent risk level for each type of risk is categorized into ratings as follows:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high).
C. Assessment of Inherent Risk for Strategic Risk
Strategic risk is the risk resulting from inaccuracies in making and/or implementing strategic decisions and failures in anticipating changes in the business environment.
Sources of strategic risk can be caused by, among others:
a. setting strategies that are not aligned with the Company's vision and mission; b. conducting strategic environment analysis that is not comprehensive;
c. inconsistencies in strategic plans between strategic levels; and
d. failures in anticipating changes in the business environment such as technological changes, macroeconomic condition changes, market competition, and changes in relevant authority policies.
In assessing the inherent risk for strategic risk, the parameters or indicators used are at least:
a. alignment of business strategy with business environment conditions; b. strategy choice: high-risk strategy and low-risk strategy;
c. the Company's strategic position in the industry; and
d. achievement of the Company's business realization.
The Company assesses the inherent risk for strategic risk using the parameters or indicators for assessing inherent risk as contained in Table II.A.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for strategic risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.A.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
D. Assessment of Inherent Risk for Operational Risk
Operational risk is the risk resulting from inadequacies and/or non-functioning internal processes, human error, system failures, and/or the occurrence of external events that affect the Company's operations.
Sources of operational risk can be caused by, among others:
a. weaknesses in human resources; b. weaknesses in internal processes;
c. inadequate systems and infrastructure; and
d. external events that have a negative impact on the Company.
In assessing the inherent risk for operational risk, the parameters or indicators used are at least:
a. organizational complexity and business activities; b. human resources;
c. technology and information systems;
d. fraud risk; e. business and organizational disruption; and f. the level of interaction and dependency of the Company.
The Company assesses the inherent risk for operational risk using the parameters or indicators for assessing inherent risk as contained in Table II.B.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for operational risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.B.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
E. Assessment of Inherent Risk for Credit Risk
Credit risk is the risk resulting from the failure of other parties to fulfill their obligations to the Company.
Credit risks resulting from debtor failure include, among others, credit concentration risk, counterparty credit risk, and settlement risk.
Credit risk is generally present in all Company activities whose performance depends on the performance of debtors, counterparties, and/or issuers.
Credit concentration risk as referred to in item 2 is a risk arising from the concentration of funding provision to one party or a group of parties, industry, sector, and/or specific geographic area that has the potential to cause significant losses that can threaten the continuity of the Company's business.
Counterparty credit risk as referred to in item 2 is a risk arising from the failure of the counterparty to fulfill its obligations and arises from transaction types that have specific characteristics, for example, transactions influenced by fair value or market value movements.
Settlement risk as referred to in item 2 is a risk arising from the failure to deliver cash and/or financial instruments on the agreed settlement date from the sale and/or purchase of financial instruments.
In assessing the inherent risk for credit risk, the parameters or indicators used are at least:
a. financing distribution strategy; b. composition of financing receivables portfolio and concentration level;
c. quality of financing receivables and adequacy of provisions; and
d. external factors.
The Company assesses the inherent risk for credit risk using the parameters or indicators for assessing inherent risk as contained in Table II.C.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for credit risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.C.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
F. Assessment of Inherent Risk for Market Risk
Market risk is the risk on asset, liability, equity, and/or administrative account positions, including derivative transactions, resulting from overall changes in market conditions.
Market risks include, among others, interest rate risk, exchange rate risk, commodity risk, and equity risk.
Risk management implementation for equity risk is applied by Companies that consolidate with Subsidiary Companies.
In assessing the inherent risk for market risk, the parameters or indicators used are at least:
a. business strategy and policies related to market risk; b. volume and composition of asset portfolio exposed to market risk; and
c. volume and composition of liability portfolio exposed to market risk.
The Company assesses the inherent risk for market risk using the parameters or indicators for assessing inherent risk as contained in Table II.D.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for market risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.D.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
G. Assessment of Inherent Risk for Liquidity Risk
Liquidity risk is the risk resulting from the Company's inability to meet maturing liabilities from cash flow funding sources and/or from liquid assets that can be easily converted into cash, without disrupting the Company's activities and financial conditions.
Liquidity risk can also be caused by the Company's inability to liquidate assets without incurring material discounts due to the absence of an active market or severe market disruption, referred to as market liquidity risk.
In assessing the inherent risk for liquidity risk, the parameters or indicators used are at least:
a. composition of short-term assets and liabilities including administrative account transactions; b. cash flow management;
c. vulnerability to funding needs; and
d. access to funding sources.
The Company assesses the inherent risk for liquidity risk using the parameters or indicators for assessing inherent risk as contained in Table II.E.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for liquidity risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.E.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
H. Assessment of Inherent Risk for Legal Risk
Legal risk is the risk resulting from legal claims and/or weaknesses in legal aspects.
Legal risk can arise, among others, due to the absence and/or changes in legislation or weaknesses in agreements, such as the non-fulfillment of contract validity requirements or imperfect collateral binding, causing a transaction already conducted by the Company to be non-compliant with regulations, and litigation processes arising from third-party lawsuits against the Company or the Company's lawsuits against third parties.
In assessing the inherent risk for legal risk, the parameters or indicators used are at least:
a. absence or changes in legislation; b. weaknesses in agreements or cooperation; and
c. dispute resolution processes.
The Company assesses the inherent risk for legal risk using the parameters or indicators for assessing inherent risk as contained in Table II.F.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for legal risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.F.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
I. Assessment of Inherent Risk for Compliance Risk
Compliance risk is the risk resulting from the Company's non-compliance with and/or non-implementation of legislation and regulations.
Sources of compliance risk arise, among others, from legal behavior, namely the Company's behavior or activities that deviate from or violate legislation regulations, and organizational behavior, namely the Company's behavior or activities that deviate from or contradict generally applicable standards.
In assessing the inherent risk for compliance risk, the parameters or indicators used are at least:
a. type and significance of violations committed; b. frequency of violations (including sanctions) or the Company's compliance track record; and
c. violations of legislation regulations or generally applicable business standards; and
d. follow-up on violations.
The Company assesses the inherent risk for compliance risk using the parameters or indicators for assessing inherent risk as contained in Table II.G.1 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
The Company establishes the inherent risk level for compliance risk in 5 (five) ratings, namely:
a. rating 1 (low); b. rating 2 (relatively low);
c. rating 3 (medium);
d. rating 4 (relatively high); and e. rating 5 (high), using the guidelines as contained in Table II.G.2 Appendix II, which is an inseparable part of this Financial Services Authority Circular.
J. Assessment of Inherent Risk for Reputational Risk
Reputational risk is the risk resulting from a decrease in stakeholder trust stemming from negative perceptions of the Company.
Reputational risk arises, among others, due to negative media coverage and/or rumors regarding the Company, as well as the Company's ineffective communication strategy.
In assessing the inherent risk for reputational risk, the parameters or indicators used are at least:
a. influence of the reputation of directors, owners, and groups; b. violations of business ethics;
c. product complexity and business cooperation;
d. frequency, materiality, and exposure of negative reporting; and e. frequency and materiality of complaints from debtors or consumers.
4. The Company assesses the inherent risk for reputation risk using the parameters or risk assessment indicators as listed in Table II.H.1 Appendix II which is an inseparable part of this Financial Services Authority Circular.
5. The Company sets the inherent risk level for reputation risk into 5 (five) rankings, namely:
a. ranking 1 (low); b. ranking 2 (relatively low);
c. ranking 3 (moderate);
d. ranking 4 (relatively high); and e. ranking 5 (high), using the guidelines as listed in Table II.H.2 Appendix II which is an inseparable part of this Financial Services Authority Circular. K. Assessment of the Quality of Risk Management Implementation
The assessment of the quality of risk management implementation reflects the assessment of the adequacy of the risk control system which covers all pillars of risk management implementation as regulated in the Financial Services Authority Regulation regarding the implementation of risk management for non-bank financial service institutions.
The assessment of the quality of risk management implementation aims to evaluate the effectiveness of the Company's risk management implementation in accordance with the principles regulated in the Financial Services Authority Regulation regarding the implementation of risk management for non-bank financial service institutions.
The Company's risk management implementation varies significantly according to size, complexity, and the level of risk that can be tolerated by the Company.
The assessment of the quality of risk management implementation is an assessment of 4 (four) interrelated aspects, namely:
a. active supervision by the Board of Directors, Board of Commissioners, and Sharia Supervisory Board (DPS); b. adequacy of risk management policies and procedures as well as the establishment of risk limits;
c. adequacy of the risk identification, measurement, control, and monitoring processes, as well as the risk management information system; and
d. comprehensive internal control system.
Active supervision by the Board of Directors, Board of Commissioners, and DPS as referred to in item 4 letter a includes evaluation of:
a. the adequacy of active supervision by the Board of Directors, Board of Commissioners, and DPS; and b. the adequacy of the exercise of authority and responsibilities of the Board of Directors, Board of Commissioners, and DPS.
The adequacy of risk management policies and procedures as well as the establishment of risk limits as referred to in item 4 letter b includes evaluation of:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance); b. risk management strategies that are aligned with the level of risk to be taken and risk tolerance;
c. the adequacy of risk management policies and procedures; and
d. the adequacy of the establishment of risk limits.
The adequacy of the risk identification, measurement, control, and monitoring processes, as well as the risk management information system as referred to in item 4 letter c includes evaluation of:
a. the adequacy of the risk identification, measurement, control, and monitoring processes; b. the adequacy of the risk management information system; and
c. the adequacy of the quantity and quality of human resources in supporting the effectiveness of the risk management process.
The comprehensive internal control system as referred to in item 4 letter d includes evaluation of:
a. the adequacy of the internal control system; and b. the adequacy of review by independent parties within the Company, either by the work unit handling risk management or by the work unit handling internal audit.
Review by the work unit handling risk management as referred to in item 8 letter b includes, among others, the methods, assumptions, and variables used to measure and establish risk limits.
Review by the work unit handling internal audit as referred to in item 8 letter b includes, among others, the reliability of the risk management framework and the implementation of risk management by business units and/or support units.
The level of quality of risk management implementation for each type of risk is categorized into 5 (five) rankings,
namely:
a. ranking 1 (strong); b. ranking 2 (fairly strong);
c. ranking 3 (adequate);
d. ranking 4 (fairly weak); and e. ranking 5 (weak).
The establishment of the quality of risk management implementation is done for each type of risk, namely:
a. strategic risk, using the guidelines as listed in Table II.A.3 Appendix II which is an inseparable part of this Financial Services Authority Circular; b. operational risk, using the guidelines as listed in Table II.B.3 Appendix II which is an inseparable part of this Financial Services Authority Circular;
c. credit risk, using the guidelines as listed in Table II.C.3 Appendix II which is an inseparable part of this Financial Services Authority Circular;
d. market risk, using the guidelines as listed in Table II.D.3 Appendix II which is an inseparable part of this Financial Services Authority Circular; e. liquidity risk, using the guidelines as listed in Table II.E.3 Appendix II which is an inseparable part of this Financial Services Authority Circular; f. legal risk, using the guidelines as listed in Table II.F.3 Appendix II which is an inseparable part of this Financial Services Authority Circular; g. compliance risk, using the guidelines as listed in Table II.G.3 Appendix II which is an inseparable part of this Financial Services Authority Circular; and h. reputation risk, using the guidelines as listed in Table II.H.3 Appendix II which is an inseparable part of this Financial Services Authority Circular.
L. Establishment of Risk Profile Factor Rankings
The establishment of risk profile factor rankings is carried out in the following stages:
a. establishment of the risk level for each risk; and b. establishment of the composite inherent risk level and composite quality of risk management implementation; and
c. establishment of the risk profile factor ranking.
The establishment of the risk level as referred to in item 1 letter a is established based on the assessment of the inherent risk level and the quality of risk management implementation for each type of risk as referred to in letters B to K.
After the Company establishes the inherent risk level and the quality of risk management implementation, the Company establishes
the risk level for each type of risk, namely:
a. strategic risk; b. operational risk;
c. credit risk;
d. market risk; e. liquidity risk; f. legal risk; g. compliance risk; and h. reputation risk, using the guidelines as listed in Table II.I Appendix II which is an inseparable part of this Financial Services Authority Circular.
In the event that the Company has Subsidiary Companies, the Company considers the impact of the Subsidiary Company's risks on the Company's risk profile by considering the significance and materiality of the Subsidiary Company and/or the significance of the Subsidiary Company's issues.
The establishment of the composite inherent risk level and composite quality of risk management implementation as referred to in item 1 letter b is done by paying attention to the significance of each risk to the overall risk profile.
The Company establishes the risk profile factor ranking as referred to in item 1 letter c based on a comprehensive and structured analysis of the results of the establishment as referred to in item 1 letter a and letter b by paying attention to the significance of each risk to the overall risk profile.
The risk profile factor ranking is the final conclusion on the Company's risk after considering mitigation carried out through the implementation of risk management.
The establishment of the risk profile ranking as referred to in item 6 and item 7 uses the format as listed in Table II.J Appendix II which is an inseparable part of this Financial Services Authority Circular.
The establishment of the risk profile factor ranking consists of 5 (five) rankings, namely:
a. ranking 1; b. ranking 2;
c. ranking 3;
d. ranking 4; and e. ranking 5, with the order of risk profile factor rankings with smaller numbers reflecting a lower level of risk faced by the Company.
The establishment of the risk profile factor ranking is done in accordance with Table II.K Appendix II which is an inseparable part of this Financial Services Authority Circular.
M. Assessment of Risk Profile Factors for Sharia Business Units (UUS)
Provisions regarding the assessment of risk profile factors for Companies as referred to in letters A to L mutatis mutandis apply to the assessment of risk profile factors for Sharia Business Units (UUS).
Financing Companies that have Sharia Business Units (UUS) must conduct an assessment of risk profile factors for UUS using:
a. inherent risk parameters or indicators, guidelines for establishing inherent risk levels, and guidelines for establishing the quality of risk management implementation with the following formats:
strategic risk, using Tables II.A.1, II.A.2, and II.A.3;
operational risk, using Tables II.B.1, II.B.2, and II.B.3;
credit risk, using Tables II.C.1, II.C.2, and II.C.3;
market risk, using Tables II.D.1, II.D.2, and II.D.3;
liquidity risk, using Tables II.E.1, II.E.2, and II.E.3;
legal risk, using Tables II.F.1, II.F.2, and II.F.3;
compliance risk, using Tables II.G.1, II.G.2, and II.G.3;
reputation risk, using Tables II.H.1, II.H.2, and II.H.3;
b. guidelines for establishing the risk level for each type of risk, using Table II.I;
c. format for establishing composite risk profiles using Table II.J; and
d. guidelines for establishing risk profile factor rankings, using Table II.K, as listed in Appendix II which is an inseparable part of this Financial Services Authority Circular.
VI. ASSESSMENT OF PROFITABILITY FACTORS
The assessment of profitability factors must at least include assessment of:
a. the Company's performance in generating profit (profitability); b. sources supporting profitability;
c. continuity of components supporting profitability;
d. profitability management; and e. the implementation of social functions by the Company, for Sharia Financing Companies and Sharia Business Units (UUS).
The assessment is carried out by considering the level, trend, structure, stability of profitability, and comparison of the Company's performance with the performance of an equivalent peer group through both quantitative and qualitative aspect analysis.
In determining the equivalent peer group, the Company needs to pay attention to the business scale, characteristics, and/or complexity of the Company's business as well as the availability of data and information owned.
The Company assesses profitability factors using parameters or indicators as listed in Table III.A Appendix III which is an inseparable part of this Financial Services Authority Circular.
The establishment of the profitability factor ranking is based on
a comprehensive and structured analysis of the parameters or indicators of profitability as referred to in item 4 by paying attention to the significance of each parameter or indicator and considering other issues that affect the Company's profitability.
The Company establishes the profitability factor ranking in 5 (five)
rankings, namely:
a. ranking 1; b. ranking 2;
c. ranking 3;
d. ranking 4; and e. ranking 5, with the order of profitability factor rankings with smaller numbers reflecting a better profitability condition.
The establishment of the profitability factor ranking is done in accordance with Table III.B Appendix III which is an inseparable part of this Financial Services Authority Circular.
VII. ASSESSMENT OF CAPITAL FACTORS
The assessment of capital factors must at least include assessment of:
a. the level of capital adequacy; and b. capital management.
In carrying out the assessment, the Company needs to consider the level, trend, structure, and stability of capital by paying attention to the performance of an equivalent peer group as well as the adequacy of the Company's capital management.
The assessment is carried out using both quantitative and qualitative parameters or indicators.
In determining the equivalent peer group, the Company needs to pay attention to the business scale, characteristics, and/or complexity of the Company's business as well as the availability of data and information owned.
Parameters or indicators in assessing capital include:
a. capital adequacy; and b. capital management.
The Company assesses capital factors using parameters or indicators as listed in Table IV.A Appendix IV which is an inseparable part of this Financial Services Authority Circular.
Capital factors are established based on a comprehensive and structured analysis of the parameters or indicators of capital as referred to in item 6 by paying attention to the materiality and significance of each parameter or indicator and considering other issues that affect the Company's capital.
The Company establishes the capital factor ranking in 5 (five)
rankings, namely:
a. ranking 1; b. ranking 2;
c. ranking 3;
d. ranking 4; and e. ranking 5, with the order of capital factor rankings with smaller numbers reflecting a better capital condition of the Company.
The establishment of the capital factor ranking is done in accordance with Table IV.B Appendix IV which is an inseparable part of this Financial Services Authority Circular.
VIII. ASSESSMENT OF COMPOSITE HEALTH LEVEL RANKINGS
The Company's Health Level is established based on a comprehensive and structured analysis of the ranking of each factor and by paying attention to the general principles of assessing the Company's Health Level as referred to in Roman II.
In carrying out a comprehensive analysis, the Company needs to consider the ability to face significant changes in external conditions.
The Company establishes Composite Rankings in 5 (five)
composite rankings, namely:
a. Composite Ranking 1 (CR-1); b. Composite Ranking 2 (CR-2);
c. Composite Ranking 3 (CR-3);
d. Composite Ranking 4 (CR-4); and e. Composite Ranking 5 (CR-5), with the order of Composite Rankings with smaller numbers reflecting a healthier Company.
4. The establishment of Composite Rankings is done in accordance with Appendix V which is an inseparable part of this Financial Services Authority Circular.
IX. PROCEDURES FOR ASSESSING THE COMPANY'S HEALTH LEVEL ON A CONSOLIDATED BASIS
a. comparison of the Subsidiary Company's total assets to the Company's total assets on a consolidated basis; or b. the significance of certain positions in the Subsidiary Company that affect the performance of the Company on a consolidated basis such as risk profile, profitability, and capital.
5. The establishment of the significance of the Subsidiary Company's issues as referred to in item 3 letter b, among others, considers issues found in the Subsidiary Company that have a significant impact on the performance or condition of the Company on a consolidated basis, for example:
a. issues related to the Subsidiary Company's business that can impact the reputation risk, credit risk, or liquidity risk of the Company on a consolidated basis; b. issues in risk governance; and/or
c. weaknesses in the implementation of the Subsidiary Company's risk management.
6. For Companies that carry out the Company's Health Level Assessment on a consolidated basis:
a. the mechanism for establishing the ranking of each assessment factor and the establishment of the Composite Health Level Ranking on a consolidated basis; and b. the categorization of the ranking of each assessment factor and Composite Ranking on a consolidated basis, must refer to the mechanism for establishing and categorizing the rankings of the Company individually.
7. Parameters or indicators used in the individual Company's Health Level Assessment can be used by the Company when assessing the Company's Health Level on a consolidated basis.
8. The use of parameters or indicators as referred to in item 7 can be supplemented with other parameters or indicators as long as they are relevant to the business scale, characteristics, and complexity of the Company on a consolidated basis.
9. In assessing the Company's Health Level on a consolidated basis, the mechanism for establishing rankings and ranking categories for each assessment factor and the establishment of the composite ranking of the Company's Health Level on a consolidated basis refers to the procedures for assessing the Company's Health Level individually as referred to in Roman III to Roman VIII.
10. The establishment of the ranking of the good corporate governance factor on a consolidated basis is done by considering:
a. the significance or materiality of the Subsidiary Company's share in the Financing Company and Sharia Financing Company on a consolidated basis; and b. issues related to the implementation of good corporate governance principles in the Subsidiary Company that have a significant impact on the implementation of good corporate governance principles on a consolidated basis.
11. The assessment factors of the Subsidiary Company's governance used for the assessment of the implementation of good corporate governance principles on a consolidated basis are established by considering the business characteristics of the Subsidiary Company and are supported by adequate data and information.
12. The establishment of the Company's governance ranking on a consolidated basis is done by considering the impact of the implementation of the Subsidiary Company's governance.
13. The establishment of the risk profile factor on a consolidated basis is done by considering:
a. the significance or materiality of the Subsidiary Company's share in the Company on a consolidated basis; and b. risk profile issues in the Subsidiary Company that have a significant impact on the risk profile on a consolidated basis.
14. The establishment of the risk profile factor on a consolidated basis is done in the following stages:
a. the establishment of the inherent risk level, the quality of risk management implementation, and the risk level of the Company on a consolidated basis is done by calculating the impact caused by the Subsidiary Company's risks on the risk profile of the Company on a consolidated basis; and b. the establishment of the risk profile ranking of the Company on a consolidated basis is done by calculating the impact of all risks of the Subsidiary Company on the risk profile of the Company on a consolidated basis.
15. The establishment of the profitability factor ranking on a consolidated basis as referred to in Article 11 paragraph (1) letter c, paragraph (2) letter c, and paragraph (3) letter c is based on a comprehensive and structured analysis of specific parameters or indicators of profitability resulting from the Company's consolidated financial statements and other financial information by considering:
a. the significance or materiality of the Subsidiary Company's share in the Company on a consolidated basis; and b. profitability issues in the Subsidiary Company that have a significant impact on profitability on a consolidated basis.
16. The assessment is carried out by referring to specific parameters or indicators applicable to the Company individually as long as they are supported by adequate data or information.
17. In carrying out the assessment, the Company can add parameters or indicators that are relevant to the scale, characteristics, and complexity of the Subsidiary Company.
18. The establishment of the capital factor ranking on a consolidated basis is based on a comprehensive and structured analysis of specific parameters or indicators of capital resulting from the consolidated financial statements of insurance companies and financing companies and other financial information by considering:
a. the significance or materiality of the Subsidiary Company's share in the Company on a consolidated basis; and b. capital issues in the Subsidiary Company that have a significant impact on capital on a consolidated basis.
19. The assessment is carried out by referring to specific parameters or indicators applicable to the Company individually as long as they are supported by adequate data or information.
20. In carrying out the assessment, the Company can add
parameters or indicators relevant to the scale, characteristics, and complexity of Subsidiary Companies.
X. REPORTING
Companies are required to conduct self-assessments of the Company's Health Level.
The self-assessment of the Company's Health Level as referred to in item 1 is conducted at least annually for the position at the end of December.
In addition to conducting self-assessments as referred to in item 1, Companies are required to update the self-assessment of the Company's Health Level when necessary.
Companies update the self-assessment of the Company's Health Level as referred to in item 3, among other things, in the following cases:
a. the Company's financial condition deteriorates; b. there are external and internal factors that can significantly affect the Company's Health Level; or
c. other conditions that, in the opinion of the Financial Services Authority and/or the Company, require an update of the self-assessment of the Company's Health Level.
The results of the self-assessment of the Company's Health Level and UUS (Unit Usaha Syariah / Sharia Business Unit) are submitted using the report format as referred to in Appendix VI, which is an integral part of this Financial Services Authority Circular.
Companies submit the results of the self-assessment of the Company's Health Level to the Financial Services Authority as follows:
a. no later than February 15 for the self-assessment of the Company's Health Level for the position at the end of December; or b. no later than 30 (thirty) working days since the date of updating the self-assessment of the Company's Health Level.
If the submission deadline for the results of the self-assessment of the Company's Health Level as referred to in item 6 letters a and b falls on a holiday, the results of the self-assessment of the Company's Health Level are submitted on the next working day.
Companies must submit the results of the self-assessment of the Company's Health Level to the Financial Services Authority online through the Financial Services Authority's data communication network system.
In the event that the Financial Services Authority's data communication network system as referred to in item 8 is not yet available or experiences technical disturbances, the submission is made to the Financial Services Authority offline by:
a. direct handover; or b. sending through a courier service company.
In the event of technical disturbances as referred to in item 9, the Financial Services Authority announces this through the Financial Services Authority's website.
The submission of reports offline as referred to in item 9 must be submitted in electronic data form using media such as compact discs or other electronic data storage media.
The submission of reports as referred to in item 11 must be accompanied by a printed cover letter signed by the Board of Directors.
Reports of the self-assessment results of the Company's Health Level and/or updates to the self-assessment of the Company's Health Level offline as referred to in item 9 are submitted to:
a. for Financing Companies:
Executive Head of Supervision of Insurance Companies, Pension Funds, Financing Institutions, and Other Financial Service Institutions Financial Services Authority u.p. Director of Financing Institution Supervision Wisma Mulia 2 Building, 15th Floor Jalan Jenderal Gatot Subroto Kav. 40 Jakarta 12710; b. for Shariah Financing Companies and Financing Companies that have UUS (Sharia Business Units):
Executive Head of Supervision of Insurance Companies, Pension Funds, Financing Institutions, and Other Financial Service Institutions Financial Services Authority u.p. Director of Shariah Financial Institution Supervision (IKNB Syariah) Wisma Mulia 2 Building, 15th Floor Jalan Jenderal Gatot Subroto Kav. 40 Jakarta 12710.
In the event of a change in the address of the Financial Services Authority's office for report submission as referred to in item 13, the Financial Services Authority will convey notification regarding the address change via letter or announcement.
Companies are deemed to have submitted reports of the self-assessment results of the Company's Health Level and/or updates to the self-assessment of the Company's Health Level with the following provisions:
a. for submissions online through the Financial Services Authority's data communication network system, evidenced by a receipt from the Financial Services Authority's data communication network system; or b. for submissions offline, evidenced by a receipt from the Financial Services Authority.
XI. CLOSING
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Appendix II of Financial Services Authority Circular Number
15/SEOJK.05/2016 concerning the Report on the Implementation of Corporate Governance of Financing Companies, are repealed and declared invalid.
Established in Jakarta on July 1, 2020
EXECUTIVE HEAD OF SUPERVISION
OF INSURANCE COMPANIES, PENSION FUNDS,
FINANCING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
RISWINANDI
APPENDIX I
FINANCIAL SERVICES AUTHORITY CIRCULAR
REPUBLIC OF INDONESIA
NUMBER 11 /SEOJK.05/2020
CONCERNING
ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES AND SHARIAH FINANCING COMPANIES
ASSESSMENT OF GOOD CORPORATE GOVERNANCE FACTORS HEALTH LEVEL OF FINANCING COMPANIES AND SHARIAH FINANCING COMPANIES
Table I.A : Self-Assessment Worksheet (Self Assessment)
Table I.B : Guidelines for Determining the Rating of Good Corporate Governance Factors
Table I.A: Self-Assessment Worksheet (Self Assessment) Good Corporate Governance Factors
Objectives
The assessment of governance structure aims to evaluate the adequacy of the structure and infrastructure of good corporate governance so that the implementation process of good corporate governance principles produces outcomes that meet the expectations of the Company's stakeholders. Included in the good corporate governance structure are the Board of Directors, Board of Commissioners, committees, and work units within the Company. Included in the good corporate governance infrastructure are, among others, the Company's policies and procedures, management information systems, and the main duties and functions of each organizational structure.
The assessment of governance process aims to evaluate the effectiveness of the implementation process of good corporate governance principles, supported by the adequacy of the structure and infrastructure of good corporate governance, so that it produces outcomes that meet the expectations of the Company's stakeholders.
The assessment of governance outcome aims to evaluate the quality of outcomes that meet the expectations of the Company's stakeholders as a result of the implementation process of good corporate governance principles, supported by the adequacy of the structure and infrastructure of good corporate governance.
Included in the implementation outcomes (outcome) cover qualitative and quantitative aspects, including:
a. adequacy of report transparency; b. compliance with statutory regulations;
c. improvement of human resource quality;
d. consumer protection; e. objectivity in conducting assessments or audits; and/or f. Company performance such as profitability, efficiency, and capitalization.
Filling Instructions:
Companies conduct self-assessments of the implementation of good corporate governance principles in the "analysis" column in Appendix I.
The parameters or indicators for assessing good corporate governance factors in Appendix I are minimum standards that must be used in assessing good corporate governance factors.
Companies may add other parameters or indicators according to the characteristics and complexity of the Company's business.
Assessments are conducted per position and trend over the last 12 (twelve) months for parameters or indicators that are quantitative.
In assessing corporate governance factors on a consolidated basis, Companies may use parameters or indicators for assessing corporate governance factors on an individual basis, adjusted to the scale, characteristics, and complexity of the Subsidiary Companies' business.
In the event of changes to regulations regarding criteria or indicators, Companies must adjust the criteria or indicators to the applicable regulations.
Execution of Board of Directors' duties and responsibilities:
a. Governance structure
1) For Companies with assets exceeding Rp200,000,000,000 (two hundred billion rupiah), the number of Board of Directors members is at least 3 (three) people.
2) For Companies with assets up to Rp200,000,000,000 (two hundred billion rupiah), the number of Board of Directors members is at least 2 (two) people.
3) Companies with foreign ownership, whether direct or indirect, must have at least 50% (fifty percent) of Board of Directors members who are Indonesian citizens.
4) All Board of Directors members must reside in Indonesia.
5) All Board of Directors members must have relevant knowledge for their positions.
6) Board of Directors members do not hold concurrent positions as Board of Directors members in other companies, except:
a. as members of the Board of Commissioners in at most 3 (three) other companies; b. as members of the Board of Commissioners in Subsidiary Companies controlled by the Company, provided that the Board of Directors members responsible for supervision over investments in Subsidiary Companies engaged in financing activities, as long as the concurrent position does not cause the individual to neglect the execution of duties and authorities as a Board of Directors member of the Company.
7) Replacement and/or appointment of Board of Directors members must consider the recommendations of the remuneration and nomination committee.
8) The Board of Directors has work guidelines and procedures that include regulations on work ethics, working hours, and meetings.
9) The Board of Directors does not use individual advisors and/or professional services as consultants except for special projects, which must be based on clear contracts covering scope of work, responsibilities, duration of work, and costs, and the consultant must be an independent party qualified to handle special projects.
10) All Board of Directors members have passed the fit and proper test and have obtained approval letters from the Financial Services Authority.
11) Board of Directors members have adequate and relevant competencies for their positions to execute duties and responsibilities and are able to implement the competencies held in the execution of duties and responsibilities.
12) Board of Directors members conduct continuous learning to increase knowledge about the Company and recent developments in the financial field or other fields supporting the execution of duties and responsibilities.
13) Board of Directors members foster continuous learning to increase knowledge about the Company and recent developments in the financial field or other fields supporting the execution of duties and responsibilities at all levels or organizational tiers.
14) Board of Directors members hold expertise certificates in the financing field from professional certification bodies in the financing field registered with the Financial Services Authority.
15) Board of Directors members overseeing risk management functions must hold expertise certificates in risk management.
b. Governance process
1) Board of Directors members do not grant general powers to other parties that result in the transfer of duties and functions of the Board of Directors.
2) The Board of Directors is fully responsible for the execution of Company management.
3) The Board of Directors manages the Company according to authorities and responsibilities as regulated in the Articles of Association and statutory regulations.
4) The Board of Directors has executed duties and responsibilities independently from shareholders.
5) The Board of Directors has applied good corporate governance principles in every business activity of the Company at all levels or organizational tiers.
6) The Board of Directors has followed up on audit findings and recommendations from work units with internal audit functions, external auditors, and results of supervision by the Financial Services Authority and/or results of supervision by other authorities.
7) The Board of Directors has provided complete, accurate, current, and timely data and information to the Board of Commissioners.
8) Decision-making in Board of Directors meetings has been conducted based on deliberation for consensus or majority vote in the event that consensus is not reached.
9) Every decision taken in Board of Directors meetings can be implemented and is consistent with applicable policies, guidelines, and work procedures.
10) The Board of Directors has established policies and strategic decisions through Board of Directors meetings.
11) The Board of Directors does not utilize the Company for personal, family, and/or other parties' interests that can harm or reduce the Company's profits.
12) The Board of Directors does not take and/or receive personal profits from the Company other than remuneration and other facilities determined by the General Meeting of Shareholders (GMS).
13) The Board of Directors does not conduct transactions with conflicts of interest with the Company's activities.
14) The Board of Directors does not fulfill shareholder requests related to the Company's operational activities other than those established in the GMS.
c. Governance outcome
1) The Board of Directors has accounted for the execution of their duties to shareholders through the GMS.
2) The Board of Directors' accountability for the execution of their duties is accepted by shareholders through the GMS.
3) The Board of Directors has disclosed the Company's strategic policies in the personnel field to employees through media easily accessible to employees.
4) The Board of Directors has communicated to employees regarding the business direction of the Company in achieving the Company's mission and vision.
5) Board of Directors meeting results have been recorded in meeting minutes and documented well, including clear disclosure of dissenting opinions that occurred in the Board of Directors meetings along with the reasons for the differing opinions.
6) In the report on the implementation of good corporate governance, all Board of Directors members have at least disclosed:
a) shareholdings reaching 5% (five percent) or more in the relevant Company or in other companies located domestically and abroad; b) financial relationships and family relationships with other Board of Directors members, other Board of Commissioners members, members of the Supervisory Board (DPS), and/or shareholders of the Company or business group where the Board of Directors and Board of Commissioners members serve; c) remuneration and other facilities; and d) share options held by the Board of Directors.
7) Improvement of knowledge, expertise, and abilities of Board of Directors members in managing the Company, demonstrated by, among others, improved Company performance, resolution of problems faced by the Company, and achievement of results according to stakeholder expectations.
8) Improvement of knowledge, expertise, and abilities of all Company employees at all levels or organizational tiers, demonstrated by, among others, improved individual performance according to duties and responsibilities.
9) Improvement of continuous learning culture to increase knowledge about the Company and recent developments in the financial field or other fields supporting the execution of duties and responsibilities at all levels or organizational tiers, demonstrated by, among others, increased employee participation in Company certifications and/or education or training for individual quality development.
10) Company operational activities are not disrupted and/or the Board of Directors does not provide unfair benefits to shareholders that impact reduced Company profits and/or cause Company losses, due to shareholder intervention in the composition and/or execution of Board of Directors duties.
Execution of Board of Commissioners' duties and responsibilities:
a. Governance structure
1) For Companies with assets exceeding Rp200,000,000,000 (two hundred billion rupiah), there are at least 2 (two) Board of Commissioners members.
2) At least 1 (one) Board of Commissioners member resides in Indonesia.
3) For Companies with assets exceeding Rp200,000,000,000 (two hundred billion rupiah), the Company must have independent commissioners.
4) The Board of Commissioners does not hold concurrent positions as Board of Commissioners members in more than 3 (three) other companies, except:
a) non-independent Board of Commissioners members execute functional tasks from shareholders of the Company in the form of a legal entity within their business group; and/or b) Board of Commissioners members hold positions in organizations or non-profit institutions, as long as the individual does not neglect the execution of duties and responsibilities as a Board of Commissioners member of the Company.
5) The Board of Commissioners has work guidelines and procedures, including regulations on work ethics, working hours, and meetings.
6) Board of Commissioners members are not affiliated with shareholders, Board of Directors members, other Board of Commissioners members, and/or members of the Supervisory Board (DPS), meaning they do not have financial, managerial, shareholding, and/or family relationships with shareholders, Board of Directors members, other Board of Commissioners members, and/or members of the Supervisory Board (DPS) or other relationships that can influence their ability to act independently.
7) All Board of Commissioners members have passed the fit and proper test and have obtained approval letters from the Financial Services Authority.
8) Board of Commissioners members have adequate and relevant competencies for their positions to execute duties and responsibilities and are able to implement the competencies held in the execution of duties and responsibilities.
9) Board of Commissioners members conduct continuous learning to increase knowledge about the Company and recent developments in the financial field or other fields supporting the execution of duties and responsibilities.
10) Board of Commissioners members hold basic-level certificates in the financing field from professional certification bodies in the financing field registered with the Financial Services Authority.
b. Governance process
1) Replacement and/or appointment of Board of Commissioners members must consider the recommendations of the remuneration and nomination committee and obtain approval from the GMS.
2) The Board of Commissioners has executed tasks to ensure the implementation of good corporate governance principles in every business activity of the Company at all levels or organizational tiers.
3) The Board of Commissioners has executed supervision over the execution of duties and responsibilities of the Board of Directors periodically and ad hoc, and has provided advice to the Board of Directors.
4) In carrying out supervisory tasks, the Board of Commissioners has directed, monitored, and evaluated the implementation of the Company's strategic policies.
5) The Board of Commissioners is not involved in decision-making for Company operational activities, except in cases of providing funds to related parties and other matters established in the Company's Articles of Association and/or statutory regulations in carrying out supervisory functions.
6) The Board of Commissioners has ensured that the Board of Directors has followed up on audit findings and recommendations from work units with internal audit functions, external auditors, results of supervision by the Financial Services Authority, and/or results of supervision by other authorities.
7) The Board of Commissioners has followed up on audit findings and recommendations from work units with internal audit functions, external auditors, results of supervision by the Financial Services Authority, and/or results of supervision by other authorities.
8) For Companies required to have Independent Commissioners, notification must be made to the Financial Services Authority no later than 10 (ten) working days since the discovery of violations of statutory regulations in the financial and Company fields, as well as conditions or estimated conditions that can endanger the continuity of the Company's business.
9) The Board of Commissioners has executed duties and responsibilities independently.
10) For Companies required to form audit committees, the Board of Commissioners has formed audit committees, risk monitoring committees, and remuneration and nomination committees.
11) The Board of Commissioners has ensured that the formed committees have executed their tasks effectively.
12) The Board of Commissioners has provided sufficient time to execute duties and responsibilities optimally.
13) Board of Commissioners meetings discuss issues according to the meeting agenda and are held periodically, at least 1 (one) time every 3 (three) months.
14) Decision-making in Board of Commissioners meetings has been conducted based on deliberation for consensus or majority vote in the event that consensus is not reached.
15) The Board of Commissioners does not utilize the Company for personal, family, and/or other parties' interests that can harm or reduce the Company's profits.
16) The Board of Commissioners does not take and/or receive personal profits from the Company other than remuneration and other facilities determined by the GMS.
c. Governance outcome
1) Board of Commissioners meeting results have been recorded in meeting minutes and documented well, including differing opinions (dissenting opinions) that occurred in the meetings, clearly stated along with the reasons for the differing opinions.
2) Board of Commissioners meeting results have been distributed to all Board of Commissioners members and relevant parties.
3) Board of Commissioners meeting results are recommendations and/or directives that can be implemented by the GMS and/or Board of Directors.
4) In the report on the implementation of good corporate governance, Board of Commissioners members have at least disclosed:
a) shareholdings reaching 5% (five percent) or more in the relevant Company or in other companies located domestically and abroad; b) financial relationships and family relationships with other Board of Directors members, other Board of Commissioners members, members of the Supervisory Board (DPS), and/or shareholders of the Company or business group where the Board of Directors and Board of Commissioners members serve;
c) remuneration and other facilities; and
d) share options held by the Board of Commissioners.
Enhancement of the knowledge, skills, and capabilities of Board of Commissioners members in overseeing the Company, demonstrated among other things by improved Company performance, resolution of problems faced by the Company, and achievement of results in line with Stakeholder expectations.
Continuous enhancement of a learning culture to increase knowledge about the Company and recent developments related to the financial field or other fields supporting the execution of duties and responsibilities of Board of Commissioners members.
Company operational activities are not disrupted and/or the Board of Commissioners does not provide unfair benefits to owners that impact reduced Company profits and/or cause Company losses, resulting from shareholder intervention in the composition and/or execution of the Board of Commissioners' duties.
Board of Commissioners members do not utilize the Company for personal, family, and/or third-party interests that can harm or reduce Company profits.
Board of Commissioners members do not take and/or receive personal benefits from the Company other than remuneration and other facilities established by the General Meeting of Shareholders (GMS).
a. Governance structure
The DPS consists of at least 1 (one) Sharia expert or more.
The DPS has received a recommendation from the National Sharia Board of the Indonesian Ulema Council (DSN-MUI).
The DPS does not hold concurrent positions as members of the Board of Directors or Board of Commissioners in the same Company.
The DPS does not hold concurrent positions as members of the Board of Directors, members of the Board of Commissioners, or members of the DPS in more than 4 (four) other Sharia financial institutions.
The DPS has passed the competency and propriety assessment.
Appointment of the DPS is conducted through the GMS in accordance with the term as referred to in the OJK Regulation regarding the competency and propriety assessment of key individuals.
b. Governance process
The DPS executes duties and responsibilities in accordance with Good Corporate Governance principles.
In carrying out duties and responsibilities, the DPS has provided advice and suggestions to the Board of Directors and supervised Company activities to ensure compliance with Sharia principles, including aspects of operational activities, use of contracts, products, and marketing practices.
The DPS has provided sufficient time to execute duties and responsibilities optimally.
The DPS has held meetings regularly with a frequency of at least 6 (six) times in 1 (one) year.
Decision-making in DPS meetings has been conducted based on deliberation and consensus and represents a joint decision of the DPS.
The DPS does not conduct transactions that have Conflicts of Interest with Company activities.
The DPS does not utilize the Company for personal, family, and/or third-party interests that can harm or reduce Company profits.
The DPS does not take and/or receive personal benefits from the Company other than remuneration and other facilities established by the GMS.
c. Governance outcome
DPS meeting results are recorded in meeting minutes and documented well, including disclosure of dissenting opinions clearly accompanied by reasons for the difference of opinion.
The DPS has submitted the DPS Supervision Result Report through the good corporate governance report and other reports in accordance with statutory regulations.
In the good corporate governance implementation report, all DPS members have at least disclosed:
a) concurrent positions as DPS members in other Sharia financial institutions; and
b) remuneration and other facilities.
a. Governance structure
Controlling shareholders or equivalents have adequate integrity and financial feasibility.
Controlling shareholders have been approved in the competency and propriety assessment process by the Financial Services Authority (OJK).
b. Governance process
Shareholders or equivalents have a commitment to undertake necessary efforts if the Company faces financial difficulties.
Shareholders or equivalents have a commitment to the operational development of the Company.
Shareholders or equivalents through the GMS strive to ensure the Company is run based on sound business practices.
c. Governance outcome
Shareholders or equivalents do not interfere in Company operational activities that are the responsibility of the Board of Directors in accordance with the Company's Articles of Association and statutory regulations, except in the context of exercising rights and obligations as the GMS.
Shareholders or equivalents who serve as members of the Board of Directors, members of the Board of Commissioners, or members of the DPS in the same Company must prioritize the Company's interests.
Shareholders or equivalents do not influence or instruct the Board of Directors, Board of Commissioners, DPS, officials, and/or employees of the Company to provide unfair benefits.
Shareholders or equivalents do not influence or instruct the Board of Directors, Board of Commissioners, DPS, officials, and/or employees of the Company to perform acts that violate prudential principles in the financial services sector and/or good corporate management principles.
For Sharia Financing Companies and Financing Companies that have Sharia Business Units (UUS), shareholders or equivalents do not influence or instruct the Board of Directors, Board of Commissioners, DPS, officials, and/or employees of the Company to perform acts that violate Sharia principles in the Sharia financial services sector.
Shareholders or equivalents do not intervene in the execution of duties of the Board of Directors and Board of Commissioners that cause the Company to experience difficulties, endanger the continuity of the Company's business, and/or the financial services industry.
Shareholders or equivalents show seriousness and/or take necessary steps in supporting the Company's strategic plan, among others reflected in the owners' commitment and efforts to strengthen the Company's capital.
a. Governance structure
For Companies with total assets exceeding IDR 200,000,000,000.00 (two hundred billion rupiah), the Company has an audit committee, a risk monitoring committee, and a remuneration and nomination committee in accordance with the size and complexity of the business.
Audit Committee
a) Audit committee members consist of at least one Independent Commissioner and one independent party with expertise in audit, finance, or accounting for Financing Companies, or Sharia accounting for Sharia Financing Companies or Financing Companies with UUS, serving as members.
b) The audit committee is chaired by an Independent Commissioner.
c) Audit committee members have good integrity, ethics, and morals.
a) Risk monitoring committee members consist of at least one Independent Commissioner and one independent party with expertise in finance and/or risk management serving as members.
b) The risk monitoring committee is chaired by an Independent Commissioner.
c) Risk monitoring committee members have good integrity, ethics, and morals.
a) Remuneration and nomination committee members consist of at least one Independent Commissioner, one Commissioner, and one official one (1) level below the Board of Directors specializing in human resource management.
b) The remuneration and nomination committee is chaired by an Independent Commissioner.
Concurrent positions of independent parties in other Companies have considered competence, independence criteria, confidentiality, code of ethics, and execution of duties and responsibilities.
All independent party members of the committees do not have financial, managerial, ownership, and/or family relationships with the Board of Directors, Board of Commissioners, and/or controlling shareholders or relationships with the Company, which could influence the ability to act independently.
b. Governance process
In order to provide recommendations to the Board of Commissioners:
a) The audit committee has monitored and evaluated the planning and execution of audits and monitored follow-up on audit results to assess the adequacy of internal controls, including the adequacy of the financial reporting process.
b) The audit committee has reviewed:
(1) the execution of duties of the unit responsible for internal audit;
(2) the conformity of audit execution by public accounting firms with audit standards;
(3) the conformity of financial reports with financial accounting standards; and
(4) the follow-up execution by the Board of Directors on findings from the unit responsible for internal audit, public accountants, and OJK supervision results.
c) The audit committee has provided recommendations for the appointment of public accountants and public accounting firms in accordance with statutory regulations to the GMS through the Board of Commissioners.
In order to provide recommendations to the Board of Commissioners:
a) The risk monitoring committee evaluates the conformity between risk management policies and the implementation of Company policies.
b) The risk monitoring committee monitors and evaluates the execution of duties of the risk management committee and the unit responsible for risk management.
In order to provide recommendations to the Board of Commissioners:
a) The remuneration and nomination committee has evaluated remuneration policies for:
(1) the Board of Directors and Board of Commissioners, and has submitted them to the GMS.
(2) officials and employees, and has submitted them to the Board of Directors.
b) Regarding nomination policies, the committee has compiled systems and procedures for the selection and/or replacement of Board of Directors and Board of Commissioners members to be submitted to the GMS.
c) The remuneration and nomination committee has provided recommendations for candidates for Board of Directors and/or Board of Commissioners members to be submitted to the GMS.
d) The remuneration and nomination committee has provided recommendations for candidate Independent Parties who can serve as committee members to the Board of Commissioners.
Committee meetings are held according to the Company's needs.
Meeting decisions are taken based on deliberation for consensus or majority vote in the event that deliberation for consensus is not reached.
Committee meeting results are recommendations that can be utilized optimally by the Board of Commissioners.
c. Governance outcome
Preparation of meeting minutes, including disclosure of differences of opinion (dissenting opinions) clearly and documented well.
Each committee has executed functions in accordance with regulations, such as providing recommendations as duties to the Board of Commissioners.
a. Governance structure
The Company has policies, systems, and procedures for resolution regarding:
conflicts of interest binding every shareholder, Board of Directors, Board of Commissioners, DPS, and Company employees.
administration, documentation, and disclosure of conflicts of interest referred to in meeting minutes.
b. Governance process
In the event of a conflict of interest, members of the Board of Directors, members of the Board of Commissioners, and officials one level below the Board of Directors do not take actions that can harm or reduce Company profits.
c. Governance outcome
Conflicts of interest that can harm the Company or reduce Company profits have been disclosed in every decision and documented well.
Company operational activities are free from owner, related party, or third-party intervention that could cause conflicts of interest that can harm the Company or reduce Company profits.
The Company successfully resolves conflicts of interest that occur.
a. Governance structure
The unit responsible for the compliance function is independent from operational units.
The unit or employees responsible report to Board of Directors members who oversee the compliance function.
The Company has provided quality human resources in the compliance unit to complete tasks effectively.
b. Governance process
a) ensuring Company compliance with statutory regulations, by:
(1) establishing necessary steps by considering prudential principles;
(2) monitoring and ensuring that Company business activities do not deviate from regulations; and
(3) monitoring and ensuring Company compliance with all agreements and commitments made by the Company to the Financial Services Authority and competent authorities;
b) submitting periodic reports on the execution of duties and responsibilities to the President Director with copies to the Board of Commissioners or competent parties according to the Company's organizational structure;
c) formulating strategies to encourage the creation of a Company compliance culture;
d) proposing compliance policies or compliance principles to be established by the Board of Directors;
e) establishing systems and procedures for compliance to be used to compile internal Company regulations and guidelines;
f) ensuring that all policies, regulations, systems, procedures, and business activities conducted by the Company are in accordance with statutory regulations;
g) minimizing the Company's compliance risk;
h) taking preventive actions so that policies and/or decisions taken by branch office management do not deviate from OJK regulations and statutory regulations; and
i) performing other tasks related to the compliance function.
The appointment of the Director overseeing the compliance function is in accordance with statutory regulations.
The Board of Directors has:
a) approved the Company's compliance policy in the form of a formal document on the effective compliance function;
b) been responsible for communicating all policies, guidelines, systems, and procedures to all relevant organizational levels; and
c) been responsible for creating an effective and permanent compliance function as part of the Company's overall compliance policy.
a) establishing steps to support the creation of a compliance culture in all Company business activities at every organizational level;
b) identifying, measuring, monitoring, and controlling compliance risks;
c) assessing and evaluating the effectiveness, adequacy, and conformity of policies, regulations, systems, and procedures owned by the Company with statutory regulations;
d) conducting reviews and/or recommending updates and improvements to policies, regulations, systems, and procedures owned by the Company to be in accordance with statutory regulations;
e) making efforts to ensure that policies, regulations, systems, procedures, and Company business activities are in accordance with statutory regulations; and
f) performing other tasks related to the compliance function.
c. Governance outcome
The scope of the report on the execution of duties of the Director overseeing the compliance function is in accordance with internal Company regulations.
The Company successfully reduces the level of violations of regulations.
The Company successfully builds a compliance culture in decision-making and in Company operational activities.
a. Governance structure
The organizational structure of the unit responsible for the Company's internal audit is in accordance with internal Company regulations.
The institutionalization of the unit responsible for internal audit is independent from operational units.
The Company provides quality human resources in the unit responsible for internal audit to complete tasks effectively.
b. Governance process
a) the creation of an internal control structure, and ensuring the execution of the Company's internal audit function at every management level; and
b) follow-up on Company internal audit findings in accordance with Board of Commissioners' policies and directives.
The Company implements the internal audit function effectively on all aspects and elements of activities that can directly be estimated to affect the interests of the Company and the public.
The examination plan of the unit responsible for the Company's internal audit, the adequacy of the examination scope, and the depth of the examination are adequate.
There are no deviations in the realization of the examination plan for the unit responsible for the Company's internal audit.
The Company plans and realizes the periodic and continuous improvement of human resource skills quality.
The unit responsible for internal audit has performed supervision functions independently with adequate task coverage in accordance with the plan, execution, and monitoring of audit results.
The unit responsible for internal audit has executed duties at least including assessment of:
a) the adequacy of the Company's internal control system;
b) the effectiveness of the Company's internal control system; and
c) performance quality.
The unit responsible for internal audit has reported all examination findings in accordance with regulations.
The unit responsible for internal audit has monitored, analyzed, and reported on the development of follow-up improvements made by the auditee.
The unit responsible for internal audit has compiled and updated work guidelines and systems and procedures to execute duties for internal auditors periodically in accordance with statutory regulations.
c. Governance outcome
The Board of Directors is responsible for the availability of reports on the execution of the Company's internal audit function to the GMS.
Findings from the examination of the unit responsible for internal audit have been followed up and there are no recurring findings.
The unit responsible for internal audit acts objectively in conducting audits.
The internal audit function has been executed adequately by considering among other things:
a) audit programs cover all work units, with execution considering the risk level of each work unit;
b) audit programs and audit scope are adequate in accordance with generally accepted internal audit principles, including the fulfillment of independence, objectivity, no restrictions in the scope and coverage of internal audit; and
c) the fulfillment of the number and quality of internal auditors.
a. Governance structure
The assignment of audits to public accountants and public accounting firms must at least meet the aspects:
capacity of the appointed public accounting firm;
legality of the work agreement;
audit scope;
professional standards of public accountants; and
communication between the Financial Services Authority and the appointed public accounting firm.
b. Governance process
In the execution of the Company's financial report audit, the Company appoints public accountants and public accounting firms registered with the Financial Services Authority and not currently subject to administrative sanctions by competent authorities.
The appointment of the same public accountant and public accounting firm by the Company is in accordance with statutory regulations.
The appointment of public accountants and public accounting firms first obtains GMS approval based on recommendations from the audit committee through the Board of Commissioners.
The appointed public accountants and public accounting firms are able to work independently, meet professional standards of public accountants, and adhere to work agreements and audit scopes established.
Public accountants have communicated with the Financial Services Authority regarding the condition of the audited Company in the context of audit preparation and execution.
Public accountants have executed audits independently and professionally.
c. Governance outcome
Audit results and management letters have described significant Company problems.
The scope of audit results is at least in accordance with the audit scope as regulated in statutory regulations.
Auditors act objectively in conducting audits.
a. Governance structure
The Company has an adequate organizational structure to support the implementation of good risk management and internal control, including units responsible for internal audit, units responsible for risk management, and compliance units.
The Company has adequate risk management policies and procedures and the establishment of risk limits.
b. Governance process
a) compiling risk management policies including strategies and risk management frameworks in writing and comprehensively, including the establishment of overall risk limits and per risk type, considering the level of risk taken and risk tolerance against capital adequacy. After receiving approval from the Board of Commissioners, the Board of Directors establishes the aforementioned policies, strategies, and risk management frameworks;
b) compiling, establishing, and updating procedures and tools to identify, measure, monitor, and control risks;
c) compiling and establishing transaction approval mechanisms, including those exceeding limits and authority for every job level;
d) evaluating and/or updating risk management policies, strategies, and frameworks at least 1 (one) time in 1 (one) year or at more frequent intervals in the event of significant changes in factors affecting Company business activities, risk exposure, and/or risk profiles;
e) determine the organizational structure, including clear authorities and responsibilities at every level of position related to the implementation of risk management; f) be responsible for the implementation of policies, strategies, and risk management frameworks approved by the Board of Commissioners, as well as evaluate and provide guidance based on reports submitted by the operational unit specializing in risk management, including reports regarding the risk profile; g) ensure that all material risks and the impacts thereof have been followed up on, and submit periodic accountability reports to the Board of Commissioners. Such reports include, among other things, reports on developments and issues related to material risks, accompanied by improvement steps that have been, are being, and will be taken; h) ensure the effective implementation of improvement steps regarding issues or deviations in the Company's business activities discovered by the internal audit unit; i) develop a risk management culture, including risk awareness at all levels of the organization, including adequate communication to all organizational levels regarding the importance of effective internal controls; j) ensure the adequacy of financial support and infrastructure to manage and control risks; and k) ensure that the risk management function has been implemented independently, reflected, among other things, by the separation of functions between the operational unit specializing in risk management, which identifies, measures, monitors, and controls risks, and the operational unit that conducts and completes transactions.
The Board of Commissioners has clear duties and responsibilities, including:
a) approving risk management policies, including strategies and risk management frameworks, established in accordance with the risk level taken (risk appetite) and risk tolerance; b) evaluating risk management policies and risk management strategies at least once (1) within one (1) year, or at more frequent intervals if there are changes in factors significantly affecting the Company's business activities; and c) evaluating the accountability of the Board of Directors and providing improvement guidance regarding the implementation of risk management policies periodically. The evaluation is conducted to ensure that the Board of Directors manages the Company's activities and risks effectively.
The Company has implemented a comprehensive and reliable internal control system.
c. Governance outcome results
The Company implements risk management effectively, adjusted to the Company's objectives, policies, size, and business complexity, as well as the Company's capabilities.
The Board of Directors and Board of Commissioners are able to conduct active supervision regarding the implementation of risk management policies and strategies.
The Company does not conduct business activities exceeding capital adequacy to absorb loss risks.
a. Governance structure
The Company has policies and procedures regarding the implementation of transparency of financial and non-financial conditions.
The Company prepares reports on the implementation of good corporate governance at the end of each fiscal year, with coverage in accordance with statutory regulations.
Complete, accurate, and timely internal reporting is available, supported by adequate management information systems.
There is a reliable information system supported by competent human resources and adequate information system security (security system) technology.
b. Governance process
The Company has transparently disclosed financial and non-financial conditions to stakeholders, including announcing public financial reports and reporting to the Financial Services Authority (OJK) or stakeholders in accordance with statutory regulations.
The Company discloses product information in accordance with statutory regulations, including:
a) written information regarding the Company's products that meet the minimum requirements as determined; b) Company employees (customer service and marketing) have explained product information to debtors or consumers; c) product information provided corresponds to the actual conditions; d) The Company has informed debtors or consumers if there are changes in product information; e) product information is clearly readable and understandable; f) The Company has product information services that are easily accessible to the public; g) The Company has explained the purpose and consequences of disseminating personal data to debtors or consumers; and h) debtors or consumers whose personal data is disseminated have provided consent for the provision of their personal data.
The Company discloses information regarding debtor or consumer complaint procedures and dispute resolution transparently, in accordance with regulations governing debtor or consumer complaints and the Company's mediation.
The Company prepares and presents reports with procedures, types, and coverage as regulated in statutory regulations.
The Company has prepared reports on the implementation of good corporate governance with content and coverage at least in accordance with statutory regulations.
In the event that the report on the implementation of good corporate governance does not correspond to the Company's actual conditions, the Company immediately submits a complete revision to the Financial Services Authority (OJK).
c. Governance outcome results
Annual financial reports have been submitted by the Company completely and on time to the Financial Services Authority (OJK) and the Company's shareholders.
Reports on the implementation of good corporate governance reflect the Company's actual conditions or correspond to the results of the Company's self-assessment, accompanied by self-assessment results with coverage in accordance with statutory regulations.
Reports on the implementation of good corporate governance have been submitted completely and on time to the Financial Services Authority (OJK) and the Company's shareholders.
Mediation for resolving customer complaints is conducted effectively.
The Company applies transparency regarding product information and the use of personal data of debtors or consumers.
a. Governance structure
The Company's strategic plan has been prepared in the form of a business plan (business plan) in accordance with the Company's vision and mission.
The Company's strategic plan is fully supported by shareholders, reflected, among other things, in the shareholders' commitment and efforts to strengthen the Company's capital.
b. Governance process
The Company has prepared the Company's Business Plan realistically, comprehensively, and measurably (achievable), considering the principle of prudence and being responsive to internal and external changes.
The Company's Business Plan is approved by the Board of Commissioners.
The Board of Directors has communicated the Company's Business Plan to:
a) the Company's shareholders; and b) all organizational levels within the Company.
The Board of Directors has effectively implemented the Company's Business Plan.
In preparing and submitting the Company's Business Plan, the following have been considered:
a) external and internal factors that can affect the Company's business continuity; b) the principle of prudence; c) the implementation of risk management; and d) the principle of a healthy Company.
The Board of Commissioners has conducted supervision regarding the implementation of the Company's Business Plan.
c. Governance outcome results
The corporate plan and the Company's Business Plan are prepared by the Board of Directors and approved by the Board of Commissioners.
The corporate plan and the Company's Business Plan, along with their realization, have been communicated by the Board of Directors to controlling shareholders and all organizational levels within the Company.
The Company's Business Plan describes the Company's sustainable growth.
The Company's Strategic Plan is prepared based on a comprehensive study, considering business opportunities and strengths possessed by the Company, and identifying weaknesses and threats (strength, weakness, opportunity, threat/SWOT Analysis).
The Company's Strategic Plan must be supported by adequate infrastructure preparation, including human resources, information technology, office networks, as well as policies and procedures.
Conclusion:
Based on the analysis of all the above assessment criteria or indicators, it is concluded that:
A. Governance structure
Table II.B: Guidelines for Determining the Rating of Corporate Governance Factors
Rating Definition
1 Reflects that the Company's management has implemented good corporate governance which is generally very good. This is reflected in the very adequate fulfillment of good corporate governance principles. In the event of weaknesses in the implementation of good corporate governance principles, these weaknesses are generally not significant and can be immediately corrected by the Company's management. 2 Reflects that the Company's management has implemented good corporate governance which is generally good. This is reflected in the adequate fulfillment of good corporate governance principles. In the event of weaknesses in the implementation of good corporate governance principles, these weaknesses are generally less significant and can be resolved with normal actions by the Company's management. 3 Reflects that the Company's management has implemented good corporate governance which is generally fairly good. This is reflected in the fairly adequate fulfillment of good corporate governance principles. In the event of weaknesses in the implementation of good corporate governance principles, these weaknesses are generally quite significant and require considerable attention from the Company's management. 4 Reflects that the Company's management has implemented good corporate governance which is generally less good. This is reflected in the less adequate fulfillment of good corporate governance principles. There are weaknesses in the implementation of good corporate governance principles, which are generally significant and require comprehensive improvement by the Company's management. 5 Reflects that the Company's management has implemented good corporate governance which is generally not good. This is reflected in the inadequate fulfillment of good corporate governance principles. There are weaknesses in the implementation of good corporate governance principles, which are generally very significant and difficult to correct by the Company's management.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Determined in Jakarta on July 1, 2020
CHIEF EXECUTIVE OF INSURANCE, PENSION FUND,
FINANCING INSTITUTION, AND
OTHER FINANCIAL SERVICE INSTITUTIONS SUPERVISOR FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed RISWINANDI
APPENDIX II
LETTER OF THE FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA
NUMBER 11 /SEOJK.05/2020
REGARDING
ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES AND SHARIA FINANCING COMPANIES
ASSESSMENT OF RISK PROFILE FACTORS FOR THE HEALTH LEVEL OF FINANCING COMPANIES, SHARIA FINANCING COMPANIES, AND UUS
Risk Assessment
Strategic
Table II.A.1: Parameters or Indicators for Assessing Inherent Risk for Strategic Risk
Table II.A.2: Guidelines for Determining the Level of Inherent Risk for Strategic Risk
Table II.A.3: Guidelines for Determining the Quality of Risk Management Implementation for Strategic Risk
Risk Assessment
Operational
Table II.B.1: Parameters or Indicators for Assessing Inherent Risk for Operational Risk
Table II.B.2: Guidelines for Determining the Level of Inherent Risk for Operational Risk
Table II.B.3: Guidelines for Determining the Quality of Risk Management Implementation for Operational Risk
Risk Assessment
Credit
Table II.C.1: Parameters or Indicators for Assessing Inherent Risk for Credit Risk
Table II.C.2: Guidelines for Determining the Level of Inherent Risk for Credit Risk
Table II.C.3: Guidelines for Determining the Quality of Risk Management Implementation for Credit Risk
Risk Assessment
Market
Table II.D.1: Parameters or Indicators for Assessing Inherent Risk for Market Risk
Table II.D.2: Guidelines for Determining the Level of Inherent Risk for Market Risk
Table II.D.3: Guidelines for Determining the Quality of Risk Management Implementation for Market Risk
Risk Assessment
Liquidity
Table II.E.1: Parameters or Indicators for Assessing Inherent Risk for Liquidity Risk
Table II.E.2: Guidelines for Determining the Level of Inherent Risk for Liquidity Risk
Table II.E.3: Guidelines for Determining the Quality of Risk Management Implementation for Liquidity Risk
Risk Assessment
Legal
Table II.F.1: Parameters or Indicators for Assessing Inherent Risk for Legal Risk
Table II.F.2: Guidelines for Determining the Level of Inherent Risk for Legal Risk
Table II.F.3: Guidelines for Determining the Quality of Risk Management Implementation for Legal Risk
Risk Assessment
Compliance
Table II.G.1: Parameters or Indicators for Assessing Inherent Risk for Compliance Risk
Table II.G.2: Guidelines for Determining the Level of Inherent Risk for Compliance Risk
Table II.G.3: Guidelines for Determining the Quality of Risk Management Implementation for Compliance Risk
Risk Assessment
Reputation
Table II.H.1: Parameters or Indicators for Assessing Inherent Risk for Reputation Risk
Table II.H.2: Guidelines for Determining the Level of Inherent Risk for Reputation Risk
Table II.H.3: Guidelines for Determining the Quality of Risk Management Implementation for Reputation Risk
Table II.I: Guidelines for Determining the Risk Level for Each Type of Risk
Table II.J: Format for Determining Risk Profile Rating 112
Table II.K: Guidelines for Determining the Rating of Risk Profile Factors 113
Filling Instructions:
Table II.A.1: Parameters or Indicators for Assessing Inherent Risk for Strategic Risk
Parameter or Indicator Description
Parameter or Indicator Description
3) organizational capability factors, including human resources, infrastructure, office networks, and management information systems; and
4) risk tolerance level, which is the Company's financial capacity to absorb risks.
External factors, including:
Parameter or Indicator Description industry b. Competitive advantages possessed by the Company compared to competitors Clear enough.
c. Company Reputation
Clear enough. d. The Company's readiness to face macroeconomic changes and their impact on the Company's conditions, including interest rates, inflation, and exchange rates Clear enough. e. The Company's strategy to maintain or increase its strategic position in the market to be carried out by the Company, whether business activities, operational coverage areas, or others Clear enough.
4. Achievement of
Company business realization a. The level of deviation between strategic targets and Company achievement results The assessment objective is to measure the extent of the deviation of business plan realization compared to targets in the business plan. b. Documentation of the causes of business plan deviations Clear enough.
c. Financing to funding ratio a. For Financing Companies:
Net Financing Receivables Balance (Outstanding Principal) Total Outstanding Funding Received Total outstanding funding received refers to funding received from:
Table II.A.2: Guidelines for Determining the Level of Inherent Risk for Strategic Risk
Rating Definition Rating
Rating 1
(Low)
Considering the business activities conducted by the Company, the potential losses faced by the Company from strategic risks are categorized as very low during a certain period in the future. Examples of Company characteristics included in Rating 1 (low) include the following:
a. The Company continues existing strategies in accordance with business environment conditions with a high level of strategy success; b. the Company's strategy is categorized as conservative or very low risk;
c. the Company's products and/or activities are categorized as stable, not complex, and diversified;
d. the Company has stable competitive advantages and no threats from competitors; and e. business plan achievement is very adequate.
Rating 2
(Medium
Low)
Considering the business activities conducted by the Company, the potential losses faced by the Company from strategic risks are categorized as low during a certain period in the future. Examples of Company characteristics included in Rating 2 (medium low) include the following:
a. the Company continues the same strategy or has several new strategies in accordance with business environment conditions but still within the Company's core business and competence; b. the Company's strategy is low risk;
c. the Company's products and/or activities are categorized as not complex and diversified;
d. the Company has competitive advantages and competitor threats are categorized as minor; and e. business plan achievement is adequate.
Rating 3
(Medium)
Considering the business activities conducted by the Company, the potential losses faced by the Company from strategic risks are categorized as quite high during a certain period in the future. Examples of Company characteristics included in Rating 3 (medium) include the following:
a. the Company applies new strategies to enter
New business or market rating based on business environment conditions but still within the core business and competencies of the Company; b. the Company's strategy is classified as quite high risk;
c. the Company's products and/or activities are generally diversified, but some are classified as complex;
d. the Company has moderate competitive advantages and faces threats from competitors; and e. the achievement of the business plan is quite adequate.
Considering the business activities carried out by the Company, the likelihood of losses faced by the Company from strategic risk is classified as high over a certain period in the future. Examples of Company characteristics included in rating 4 (medium-high) include the following:
a. the Company implements strategies to enter new businesses or markets according to business environment conditions with an uncertain level of success; b. the Company's strategy is classified as high risk;
c. some of the Company's products and/or activities are concentrated and classified as complex;
d. the Company lacks competitive advantages, or there are significant threats from competitors; and e. the achievement of the business plan is inadequate.
Considering the business activities carried out by the Company, the likelihood of losses faced by the Company from strategic risk is classified as very high over a certain period in the future. Examples of Company characteristics included in rating 5 (high) include the following:
a. the majority of the Company's strategies shift to areas that are different and not the main business lines and competencies according to the Company's business environment conditions; b. the Company's strategy is classified as very high risk;
c. products and/or business activities are very concentrated and classified as complex;
d. the Company has no competitive advantages and there are very significant threats from competitors; and e. the Company's achievement of the business plan is inadequate.
The quality of risk management implementation for strategic risk is very adequate, with minor weaknesses that are not significant and can be ignored.
Examples of Company characteristics included in rating 1 (strong) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance is very adequate and aligned with strategic objectives and overall business strategy; b. the Board of Directors, Board of Commissioners, and/or Sharia Supervisory Board (DPS) have very good awareness and understanding regarding risk management for strategic risk, sources of strategic risk, and the level of strategic risk at the Company;
c. the risk management culture for strategic risk is very strong and has been internalized very well at all organizational levels;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS as a whole is very adequate; e. the risk management function for strategic risk is independent, has clear duties and responsibilities, and operates very well; f. the delegation of authority is controlled and monitored periodically, and operates very well; g. the management strategy for strategic risk is very aligned with the level of risk to be taken and strategic risk tolerance; h. policies, procedures, and limit setting for strategic risk are very adequate and available for all areas of risk management for strategic risk, aligned with implementation, and well understood by employees;
i. the risk management process for strategic risk is very adequate in identifying, measuring, monitoring, and controlling strategic risk;
j. the strategic risk management information system is very good, producing comprehensive and integrated strategic risk reports to the Board of Directors, Board of Commissioners, and/or DPS; k. human resources are very adequate in terms of quantity and quality in the risk management function for strategic risk;
l. the internal control system is very effective in supporting the implementation of risk management for strategic risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; n. generally, there are no significant weaknesses based on independent review results; and o. follow-up on independent review has been carried out very adequately.
The quality of risk management implementation for strategic risk is adequate, although there are some minor weaknesses that can be resolved in normal business activities.
Examples of Company characteristics included in rating 2 (somewhat strong) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance is adequate and aligned with strategic objectives and overall business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding risk management for strategic risk, sources of strategic risk, and the level of strategic risk at the Company;
c. the risk management culture for strategic risk is strong and has been internalized well at all organizational levels;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, with some weaknesses that are not significant and can be repaired immediately; e. the risk management function for strategic risk has clear duties and responsibilities and operates well, but there are minor weaknesses that can be resolved in normal business activities; f. the delegation of authority is controlled and monitored periodically and operates well; g. the management strategy for strategic risk is aligned with the level of risk to be taken and strategic risk tolerance; h. policies, procedures, and limit setting for strategic risk are adequate and available for all areas of risk management for strategic risk, aligned with implementation, and well understood by employees, although there are minor weaknesses;
i. the risk management process for strategic risk is adequate in identifying, measuring, monitoring, and controlling strategic risk;
j. the information management system for strategic risk is good, including strategic risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily repaired; k. human resources are adequate in terms of quantity and quality in the risk management function for strategic risk;
l. the internal control system is effective in supporting the implementation of risk management for strategic risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; n. there are weaknesses but not significant based on independent review results; and o. follow-up on independent review has been carried out adequately.
The quality of risk management implementation for strategic risk is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Company characteristics included in rating 3 (fair) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance is fairly adequate but not always aligned with strategic objectives and overall business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have fairly good awareness and understanding regarding risk management for strategic risk, sources of strategic risk, and the level of strategic risk at the Company;
c. the risk management culture for strategic risk is fairly strong and has been internalized fairly well but not always implemented consistently;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally fairly adequate, but there are weaknesses in some assessment aspects that need management attention; e. the risk management function for strategic risk is fairly good, but there are some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; f. the delegation of authority is fairly good, but control and monitoring are not always carried out well; g. the management strategy for strategic risk is fairly aligned with the level of risk to be taken and strategic risk tolerance; h. policies, procedures, and limit setting for strategic risk are fairly adequate but not always consistent with implementation;
i. the risk management process for strategic risk is fairly adequate in identifying, measuring, monitoring, and controlling strategic risk;
j. the strategic risk management information system meets minimum expectations but has some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; k. human resources are fairly adequate in terms of quantity and quality in the risk management function for strategic risk;
l. the internal control system is fairly effective in supporting the implementation of risk management for strategic risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is fairly adequate, but there are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; n. there are fairly significant weaknesses based on independent review results that require management attention; and o. follow-up on independent review has been carried out fairly adequately.
The quality of risk management implementation for strategic risk is inadequate, with significant weaknesses in various aspects of risk management for strategic risk that require immediate remediation. Examples of Company characteristics included in rating 4 (somewhat weak) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and not aligned with strategic objectives and overall business strategy; b. there are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for strategic risk, sources of strategic risk, and the level of strategic risk at the Company;
c. the risk management culture for strategic risk is not strong and has not been internalized well at each organizational level;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally inadequate, with weaknesses in various assessment aspects that require immediate improvement; e. there are significant weaknesses in the risk management function for strategic risk that require immediate improvement; f. delegation of authority is weak, not controlled and not monitored well; g. the management strategy for strategic risk is not aligned with the level of risk to be taken and strategic risk tolerance; h. there are significant weaknesses in policies, procedures, and limit setting for strategic risk;
i. the risk management process for strategic risk is inadequate in identifying, measuring, monitoring, and controlling strategic risk;
j. there are significant weaknesses in the information management system for strategic risk including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; k. human resources are inadequate in terms of quantity and quality in the risk management function for strategic risk;
l. the internal control system is not effective in supporting the implementation of risk management for strategic risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; n. there are significant weaknesses based on independent review results that require immediate remedial action; and o. follow-up on independent review is inadequate.
The quality of risk management implementation for strategic risk is inadequate, with significant weaknesses in various aspects of risk management for strategic risk that are beyond management's ability to resolve. Examples of Company characteristics included in rating 5 (weak) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and there is no connection with strategic objectives and overall business strategy; b. the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for strategic risk, sources of strategic risk, and the level of strategic risk at the Company is very weak;
c. the risk management culture for strategic risk is not strong or does not exist at all;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, with significant weaknesses in almost all assessment aspects and remedial actions are beyond the Company's ability; e. there are significant weaknesses in the risk management function for strategic risk that require fundamental improvement; f. delegation of authority is very weak or non-existent; g. the management strategy for strategic risk is not aligned with the level of risk to be taken and strategic risk tolerance; h. there are very significant weaknesses in policies, procedures, and limit setting for strategic risk;
i. the risk management process for strategic risk is inadequate in identifying, measuring, monitoring, and controlling strategic risk;
j. there are fundamental weaknesses in the information management system for strategic risk; k. human resources are inadequate in terms of quantity and quality in the risk management function for strategic risk;
l. the internal control system is not effective in supporting the implementation of risk management for strategic risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is lacking or inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require fundamental improvement; n. there are very significant weaknesses based on independent review results that require remedial action; o. follow-up on independent review is inadequate.
| Parameter or Indicator | Description |
|---|---|
| 1. Organizational and business activity complexity | a. Size, complexity, and organizational structure<br>b. Complexity of business processes and diversity of products/services<br>c. Corporate action<br>d. New business development<br>e. Partial delegation of work execution to third parties (outsourcing)<br>f. Significant changes in work patterns<br>g. History of transaction process failures or management process failures<br><br>High business complexity and the level of product diversity of the Company will cause complexity and variation in work processes, both manual and automated, thus potentially causing operational disruptions or losses. |
| 2. Human resources | a. Implementation of human resource management<br>b. Failure due to human factors (human error)<br><br>Ineffective human resource management can result in the potential for operational disruptions or losses for the Company.<br><br>Assessment can be carried out based on, among others:<br>1) percentage of human resource fulfillment in the organizational structure;<br>2) employee turnover rate; and<br>3) budgeting and realization of education and training costs against the human resource budget. |
| 3. Technology and information systems | a. Complexity of information technology systems<br>b. Changes in information technology systems<br>c. Maturity of information technology systems.<br>d. Reliability of information systems, including supporting infrastructure, against information technology threats and attacks<br>e. Suitability of information technology systems with Company activities, among others prioritizing the use of one gate system and front end system<br>f. Failure of information technology systems<br><br>Inadequate information technology and/or ineffective and inefficient management can cause losses to the Company.<br><br>Assessment can be carried out based on, among others, the number of system disruption incidents for internal and external purposes in 1 (one) year. |
| 4. Fraud risk | a. History of internal fraud<br>b. History of external fraud<br><br>Fraud assessment is carried out against the frequency or materiality of fraud that has occurred in the previous assessment period, including potential fraud that can arise from weaknesses in business aspects, human resources, information technology, and external events. |
| 5. Business and organizational disruption | a. Frequency and materiality of external events<br>b. Company location and geographical conditions<br><br>Such external events include terrorism, crime, pandemics, and natural disasters.<br><br>Company location and geographical conditions include, among others, the number and significance of services in disaster-prone areas, social conflicts, crime, and terrorism. |
| 6. Level of interaction and dependency | a. Level of interaction and dependency of the Company against affiliated companies in main business activities<br>b. Level of interaction and dependency of the Company against non-affiliated companies in main business activities<br>c. Impact of interaction and dependency of the Company against affiliated and non-affiliated companies on financial performance<br><br>Self-explanatory. |
Considering the business activities carried out by the Company, the likelihood of losses faced by the Company from operational risk is classified as very low over a certain period in the future. Examples of Company characteristics included in rating 1 (low) include the following:
a. the Company's business has very simple characteristics: products and activities are not varied, business mechanisms are very simple, transaction volume is low, organizational structure is not complex, there are no significant corporate actions, and outsourcing usage is very minimal; b. human resources are very adequate, both in terms of quantity and quality adequacy of human resources and historical data of losses due to human error is not significant;
c. information technology is very mature and there are no significant changes in information technology systems, vulnerability of information technology to disruptions or attacks is very low, supporting infrastructure is very reliable in supporting the Company's business;
d. the frequency and materiality of internal and external fraud are very low and losses caused are not significant compared to transaction volume or Company revenue; e. the threat of business disruption as a result of external events is very low; and f. dependency and impact of dependency against affiliated and non-affiliated companies in main business activities are very low.
Considering the business activities carried out by the Company, the likelihood of losses faced by the Company from operational risk is low over a certain period in the future. Examples of Company characteristics included in rating 2 (medium-low) include the following:
a. the Company's business has simple characteristics: products and activities are relatively less varied, business mechanisms are simple, transaction volume is relatively low, organizational structure is less complex, corporate actions are less significant, and outsourcing usage is minimal; b. human resources are adequate, both in terms of quantity and quality adequacy of human resources and historical data of losses due to human error is less significant;
c. information technology is relatively mature and there are no significant changes in information technology systems, vulnerability of information technology to disruptions or attacks is low, supporting infrastructure is reliable in supporting the Company's business;
d. the frequency and materiality of internal and external fraud are low and losses caused are less significant compared to transaction volume or Company revenue; e. the threat of business disruption as a result of external events is low; and f. dependency and impact of dependency against affiliated and non-affiliated companies in main business activities are low.
Considering the business activities carried out by the Company, the likelihood of losses faced by the Company from operational risk is classified as fairly high over a certain period in the future. Examples of Company characteristics included in rating 3 (medium) include the following:
a. the Company's business has fairly complex characteristics, products and activities are fairly varied, business mechanisms are fairly complex, transaction volume is fairly high, organizational structure is fairly complex, corporate actions are fairly significant, and outsourcing usage is fairly significant; b. human resources are fairly adequate, both in terms of quantity and quality adequacy of human resources and historical data of losses due to human error is fairly significant;
c. information technology is moving towards maturity and there may be significant changes in information technology systems, information technology is fairly vulnerable to disruptions or attacks, supporting infrastructure is fairly reliable in supporting the Company's business;
d. the frequency and materiality of internal and external fraud are fairly high and losses caused are fairly significant compared to transaction volume or Company revenue; e. the threat of business disruption as a result of external events is fairly high; and f. dependency and impact of dependency against affiliated and non-affiliated companies in main business activities are fairly high.
Rating 4 (High-Medium)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from operational risk is classified as high during a certain period in the future.
Examples of characteristics of Companies included in rating 4 (high-medium) include the following:
a. the Company's business has complex characteristics: products and activities vary, business mechanisms are complex, transaction volume is high, organizational structure is complex, significant corporate actions, and significant use of outsourcing; b. human resources are inadequate, both in terms of quantity and quality sufficiency, with significant historical data on losses due to human error;
c. information technology is immature and there are significant changes in information technology systems, information technology is vulnerable to disruptions or attacks, and supporting infrastructure is less reliable in supporting the Company's business;
d. the frequency and materiality of internal and external fraud are high, and losses caused are significant compared to transaction volume or revenue; e. the threat of business disruption as a result of external events is high; and f. dependence and the impact of dependence on affiliated and unaffiliated companies in main business activities are high.
Rating 5 (High)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from operational risk is classified as very high during a certain period in the future.
Examples of characteristics of Companies included in rating 5 (high) include the following:
a. the Company's business has very complex characteristics: products and activities vary very much, business mechanisms are very complex, transaction volume is very high, organizational structure is very complex, significant corporate actions, and very high use of outsourcing; b. human resources are inadequate, both in terms of quantity and quality sufficiency, with very significant historical data on losses due to human error;
c. information technology is immature and there are very significant changes in information technology systems, information technology is very vulnerable to disruptions or attacks, and supporting infrastructure is unreliable in supporting the Company's business;
d. the frequency and materiality of internal and external fraud are very high, and losses caused are very significant compared to transaction volume or the Company's revenue; e. the threat of business disruption as a result of external events is very high; and f. dependence and the impact of dependence on affiliated and unaffiliated companies in main business activities are very high.
Rating 1 (Strong)
The quality of operational risk management implementation for operational risk is very adequate, with minor weaknesses that are not significant and can be ignored.
Examples of characteristics of Companies included in rating 1 (strong) include the following:
a. the formulation of risk appetite and risk tolerance is very adequate and aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or Sharia Supervisory Board (DPS) have very good awareness and understanding regarding operational risk management, operational risk sources, and the level of operational risk at the Company;
c. the operational risk management culture is very strong and has been internalized very well at all organizational levels;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS as a whole is very adequate; e. the operational risk management function is independent, has clear duties and responsibilities, and operates very well; f. delegation of authority is controlled and monitored periodically, and operates very well; g. the management strategy for operational risk is very aligned with the level of risk to be taken and operational risk tolerance; h. policies, risk management procedures, and the setting of limits for operational risk are very adequate and available for all operational risk management areas, aligned with implementation, and well understood by employees;
i. the operational risk management process is very adequate in identifying, measuring, monitoring, and controlling operational risk;
j. business continuity management is very reliable and very tested; k. the information management system for operational risk is very good, producing comprehensive and integrated operational risk reports to the Board of Directors, Board of Commissioners, and/or DPS;
l. human resources are very adequate in terms of quantity and quality in the operational risk management function;
m. the internal control system is very effective in supporting the implementation of operational risk management; n. the implementation of independent reviews by the internal audit unit and functions conducting independent reviews is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; o. generally, there are no significant weaknesses based on independent review results; and p. follow-up on independent reviews has been carried out very adequately.
Rating 2 (Fairly Strong)
The quality of operational risk management implementation for operational risk is adequate, although there are some minor weaknesses that can be resolved in normal business activities.
Examples of characteristics of Companies included in rating 2 (fairly strong) include the following:
a. the formulation of risk appetite and risk tolerance is adequate and aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding operational risk management, operational risk sources, and the level of operational risk at the Company;
c. the operational risk management culture is strong and has been internalized well at all organizational levels;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, with some weaknesses that are not significant and can be repaired immediately; e. the operational risk management function has clear duties and responsibilities and operates well, but there are minor weaknesses that can be resolved in normal business activities; f. delegation of authority is controlled and monitored periodically and operates well; g. the management strategy for operational risk is aligned with the level of risk to be taken and operational risk tolerance; h. policies, procedures, and the setting of limits for operational risk are adequate and available for all operational risk management areas, aligned with implementation, and well understood by employees, although there are minor weaknesses;
i. the operational risk management process is adequate in identifying, measuring, monitoring, and controlling operational risk;
j. business continuity management is reliable and tested; k. the information management system for operational risk is good, including operational risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily repaired;
l. human resources are adequate in terms of quantity and quality in the operational risk management function;
m. the internal control system is effective in supporting the implementation of operational risk management; n. the implementation of independent reviews by the internal audit unit and functions conducting independent reviews is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; o. there are weaknesses but not significant based on independent review results; and p. follow-up on independent reviews has been carried out adequately.
Rating 3 (Sufficient)
The quality of operational risk management implementation for operational risk is sufficiently adequate. Although minimum requirements are met, there are some weaknesses that require management attention.
Examples of characteristics of Companies included in rating 3 (sufficient) include the following:
a. the formulation of risk appetite and risk tolerance is sufficiently adequate but not always aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have sufficiently good awareness and understanding regarding operational risk management, operational risk sources, and the level of operational risk at the Company;
c. the operational risk management culture is sufficiently strong and has been internalized sufficiently well but not always implemented consistently;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally sufficiently adequate, but there are weaknesses in some assessment aspects that need management attention; e. the operational risk management function is sufficiently good, but there are some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; f. delegation of authority is sufficiently good, but control and monitoring are not always implemented well; g. the management strategy for operational risk is sufficiently aligned with the level of risk to be taken and operational risk tolerance; h. policies, procedures, and the setting of limits for operational risk are sufficiently adequate but not always consistent with implementation;
i. the operational risk management process is sufficiently adequate in identifying, measuring, monitoring, and controlling operational risk;
j. business continuity management is sufficiently reliable; k. the information management system for operational risk meets minimum expectations but there are some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;
l. human resources are sufficiently adequate in terms of quantity and quality in the operational risk management function;
m. the internal control system is sufficiently effective in supporting the implementation of operational risk management; n. the implementation of independent reviews by the internal audit unit and functions conducting independent reviews is sufficiently adequate, but there are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; o. there are weaknesses that are sufficiently significant based on independent review results that require management attention; and p. follow-up on independent reviews has been carried out sufficiently adequately.
Rating 4 (Fairly Weak)
The quality of operational risk management implementation for operational risk is less adequate, with significant weaknesses in various aspects of operational risk management that require immediate improvement.
Examples of characteristics of Companies included in rating 4 (fairly weak) include the following:
a. the formulation of risk appetite and risk tolerance is less adequate and not aligned with overall strategic objectives and business strategy; b. there are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding operational risk management, operational risk sources, and the level of operational risk at the Company;
c. the operational risk management culture is less strong and has not been internalized well at every organizational level;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally less adequate, with weaknesses in various assessment aspects that require immediate improvement; e. there are significant weaknesses in the operational risk management function that require immediate improvement; f. delegation of authority is weak, not controlled and not monitored well; g. the management strategy for operational risk is less aligned with the level of risk to be taken and operational risk tolerance; h. there are significant weaknesses in policies, procedures, and the setting of limits for operational risk;
i. the operational risk management process is less adequate in identifying, measuring, monitoring, and controlling operational risk;
j. business continuity management is less reliable; k. there are significant weaknesses in the information management system for operational risk including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement;
l. human resources are less adequate in terms of quantity and quality in the operational risk management function;
m. the internal control system is less effective in supporting the implementation of operational risk management; n. the implementation of independent reviews by the internal audit unit and functions conducting independent reviews is less adequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; o. there are significant weaknesses based on independent review results that require immediate corrective action; and p. follow-up on independent reviews is less adequate.
Rating 5 (Weak)
The quality of operational risk management implementation for operational risk is inadequate, with significant weaknesses in various aspects of operational risk management whose resolution is beyond management's capability.
Examples of characteristics of Companies included in rating 5 (weak) include the following:
a. the formulation of risk appetite and risk tolerance is inadequate and there is no connection with overall strategic objectives and business strategy; b. the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding operational risk management, operational risk sources, and the level of operational risk at the Company is very weak;
c. the operational risk management culture is not strong or does not exist at all;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, with significant weaknesses in almost all assessment aspects and corrective actions are beyond the Company's capability; e. there are significant weaknesses in the operational risk management function that require fundamental improvement; f. delegation of authority is very weak or non-existent; g. the management strategy for operational risk is not aligned with the level of risk to be taken and operational risk tolerance; h. there are very significant weaknesses in policies, procedures, and the setting of limits for operational risk;
i. the operational risk management process is inadequate in identifying, measuring, monitoring, and controlling operational risk;
j. business continuity management is unreliable; k. there are fundamental weaknesses in the information management system for operational risk;
l. human resources are inadequate in terms of quantity and quality in the operational risk management function;
m. the internal control system is ineffective in supporting the implementation of operational risk management; n. the implementation of independent reviews by the internal audit unit and functions conducting independent reviews is less or inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require fundamental improvement; o. there are very significant weaknesses based on independent review results whose corrective actions are beyond management's capability; and p. follow-up on independent reviews is inadequate.
| Parameter or Indicator | Description |
|---|---|
| 1. Financing Distribution Strategy | |
| a. Financing strategy and products | The term "strategy and products" refers to the current strategy and/or changes in financing distribution strategy and/or product marketing strategy that have the potential to increase credit risk exposure at the Company. |
| b. Financing distribution process, competition level, and asset growth rate | High competition levels and aggressive asset growth generally drive aggressive financing distribution strategies. The more aggressive the financing distribution strategy, the higher the inherent risk level faced by the Company if not accompanied by adequate financing distribution standards. |
| c. Significance of indirect financing distribution by the Company | Indirect financing distribution by the Company, such as financing distribution in cooperation with third parties through channeling schemes or joint financing when the Company acts as the fund owner. The significance of indirect financing distribution by the Company can be assessed through the following calculations: |
| Parameter or Indicator | Description |
|---|
c. Ratio of low-quality financing receivables
Note:
Low-quality financing receivables/productive assets are all assets owned by the Company with the intention of obtaining income in the form of financing that has quality in special attention, poor, doubtful, and non-performing according to statutory regulations.
d. Ratio of net low-quality financing receivables
e. Ratio of restructured financing
Note:
Restructured financing receivables/productive assets are all assets owned by the Company with the intention of obtaining income in the form of financing that has been restructured.
f. Ratio of restructured financing with performing and special attention quality against total financing receivables
g. Ratio of restructured financing with performing and special attention quality against total restructured financing receivables
h. Ratio of non-performing financing receivables per economic sector against total financing receivables per economic sector.
i. Ratio of non-performing financing receivables per economic sector against total non-performing financing receivables.
j. Ratio of financing receivables to other Companies.
k. Ratio of non-performing financing receivables to other Companies.
l. Ratio of Provision for Impairment Losses (CKPN)
m. Ratio of CKPN for non-performing financing receivables
Table II.C.2: Guidelines for Determining Inherent Risk Level for Credit Risk
| Ranking | Definition of Ranking |
|---|---|
| Ranking 1 (Low) | Considering the business activities conducted by the Company, the potential losses faced by the Company from credit risk are classified as very low during a certain period in the future. Example characteristics of Companies included in ranking 1 (low) include the following: |
| a. financing distribution portfolio is dominated by very low credit risk exposure; b. financing distribution exposure is very well diversified; | |
| c. financing distribution has very good quality; | |
| d. the Company's financing distribution strategy or business model is classified as very stable; and e. the financing distribution portfolio is relatively unaffected by changes in external factors. Ranking 2 (Low-Medium) | Considering the business activities conducted by the Company, the potential losses faced by the Company from credit risk are classified as low during a certain period in the future. Example characteristics of Companies included in ranking 2 (low-medium) include the following: |
| a. financing distribution portfolio is dominated by low credit risk exposure; b. financing distribution exposure is well diversified; | |
| c. financing distribution has good quality; | |
| d. the Company's financing distribution strategy or business model is classified as relatively stable; and e. the financing distribution portfolio is less affected by changes in external factors. Ranking 3 (Medium) | Considering the business activities conducted by the Company, the potential losses faced by the Company from credit risk are classified as moderately high during a certain period in the future. Example characteristics of Companies included in ranking 3 (medium) include the following: |
| a. financing distribution portfolio is dominated by moderately high credit risk exposure; b. there is a moderately significant concentration of financing distribution; | |
| c. financing distribution has less good quality; | |
| d. the Company's financing distribution strategy or business model is generally classified as moderately stable; and e. the financing distribution portfolio is moderately affected by changes in external factors. Ranking 4 (Medium-High) | Considering the business activities conducted by the Company, the potential losses faced by the Company from credit risk are classified as high during a certain period in the future. Example characteristics of Companies included in ranking 4 (medium-high) include the following: |
| a. financing distribution portfolio is dominated by high credit risk exposure; b. there is a significant concentration of financing distribution; | |
| c. financing distribution has poor quality; | |
| d. there are significant changes in the Company's financing distribution strategy or business model; and e. the financing distribution portfolio is affected by changes in external factors. Ranking 5 (High) | Considering the business activities conducted by the Company, the potential losses faced by the Company from credit risk are classified as very high during a certain period in the future. Example characteristics of Companies included in ranking 5 (high) include the following: |
| a. financing distribution portfolio is dominated by very high credit risk exposure; b. there is a very significant concentration of financing distribution; | |
| c. financing distribution has very poor quality; | |
| d. there are very significant changes in the Company's financing distribution strategy or business model; and e. the financing distribution portfolio is very affected by changes in external factors. |
Table II.C.3: Guidelines for Determining Risk Management Implementation Quality for Credit Risk
| Ranking | Definition of Ranking |
|---|---|
| Ranking 1 (Strong) | The quality of risk management implementation for credit risk is very adequate, with minor weaknesses that are insignificant and can be ignored. |
| Example characteristics of Companies included in ranking 1 (strong) include the following: | |
| a. the formulation of risk levels to be taken (risk appetite) and risk tolerance (risk tolerance) is very adequate and aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have very good awareness and understanding regarding credit risk management, credit risk sources, and credit risk levels at the Company; | |
| c. the credit risk management culture is very strong and has been internalized very well at all organizational levels; | |
| d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS as a whole is very adequate; e. the credit risk management function is independent, has clear tasks and responsibilities, and has operated very well; f. delegation of authority is controlled and monitored periodically, and has operated very well; g. financing strategy is very good and aligned with the risk levels to be taken (risk appetite) and credit risk tolerance (risk tolerance); h. policies, procedures, and limit setting for credit risk are very adequate and available for all areas of credit risk management, aligned with implementation, and well understood by employees; | |
| i. the credit risk management process is very adequate in identifying, measuring, monitoring, and controlling credit risk; | |
| j. the financing distribution process is generally very adequate from the financing analysis process to handling non-performing assets; k. the credit risk grading system and implementation are very good; | |
| l. there is an independent financing review function that operates well; | |
| m. the management information system for credit risk is very good, producing comprehensive and integrated credit risk reports to the Board of Directors, Board of Commissioners, and/or DPS; n. human resources are very adequate in terms of quantity and quality in the credit risk management function; o. the internal control system is very effective in supporting the implementation of credit risk management; p. the execution of independent reviews by the internal audit work unit and functions performing independent reviews is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; q. generally, there are no significant weaknesses based on independent review results; and r. follow-up on independent reviews has been executed very adequately. Ranking 2 (Fairly Strong) | The quality of risk management implementation for credit risk is adequate despite some minor weaknesses that can be resolved in normal business activities. Example characteristics of Companies included in ranking 2 (fairly strong) include the following: |
| a. the formulation of risk levels to be taken (risk appetite) and risk tolerance (risk tolerance) is adequate and aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding credit risk management, credit risk sources, and credit risk levels at the Company; | |
| c. the credit risk management culture is strong and has been internalized well at all organizational levels; | |
| d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, with some weaknesses that are not significant and can be repaired immediately; e. the credit risk management function has clear tasks and responsibilities and has operated well, but there are minor weaknesses that can be resolved in normal business activities; f. delegation of authority is controlled and monitored periodically and has operated well; g. financing strategy is good and aligned with the risk levels to be taken (risk appetite) and credit risk tolerance (risk tolerance); h. policies, procedures, and limit setting for credit risk are adequate and available for all areas of credit risk management, aligned with implementation, and well understood by employees despite minor weaknesses; | |
| i. the credit risk management process is adequate in identifying, measuring, monitoring, and controlling credit risk; | |
| j. the financing distribution process is good, with minor weaknesses in one or more aspects of fund provision that can be easily repaired; k. the credit risk grading system and implementation are good; | |
| l. there is an independent financing review function, but there are minor weaknesses that do not disrupt the overall process; | |
| m. the management information system for credit risk is good, including credit risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily repaired; n. human resources are adequate in terms of quantity and quality in the credit risk management function; o. the internal control system is effective in supporting the implementation of credit risk management; p. the execution of independent reviews by the internal audit work unit and functions performing independent reviews is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; q. there are weaknesses but not significant based on independent review results; and r. follow-up on independent reviews has been executed adequately. Ranking 3 (Sufficient) | The quality of risk management implementation for credit risk is sufficiently adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Example characteristics of Companies included in ranking 3 (sufficient) include the following: |
| a. the formulation of risk levels to be taken (risk appetite) and risk tolerance (risk tolerance) is sufficiently adequate but not always aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have sufficiently good awareness and understanding regarding credit risk management, credit risk sources, and credit risk levels at the Company; | |
| c. the credit risk management culture is sufficiently strong and has been internalized sufficiently well but not always implemented consistently; | |
| d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally sufficiently adequate, but there are weaknesses in some assessment aspects that need management attention; e. the credit risk management function is sufficiently good, but there are some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; f. delegation of authority is sufficiently good, but control and monitoring are not always executed well; g. financing strategy is sufficiently aligned with the risk levels to be taken (risk appetite) and credit risk tolerance (risk tolerance); h. policies, procedures, and limit setting for credit risk are sufficiently adequate but not always consistent with implementation; | |
| i. the credit risk management process is sufficiently adequate in identifying, measuring, monitoring, and controlling credit risk; | |
| j. the financing distribution process is sufficiently good, with weaknesses in one or more aspects of fund provision that need management attention; k. the credit risk grading system and implementation are sufficiently good; | |
| l. the financing review function is sufficiently good, but there are some weaknesses that need management attention; | |
| m. the management information system for credit risk meets minimum expectations but has some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; n. human resources are sufficiently adequate in terms of quantity and quality in the credit risk management function; o. the internal control system is sufficiently effective in supporting the implementation of credit risk management; p. the execution of independent reviews by the internal audit work unit and functions performing independent reviews is sufficiently adequate, but there are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; q. there are weaknesses that are sufficiently significant based on independent review results that require management attention; and r. follow-up on independent reviews has been executed sufficiently adequately. Ranking 4 (Fairly Weak) | The quality of risk management implementation for credit risk is less adequate, with significant weaknesses in various aspects of credit risk management that require immediate corrective action. Example characteristics of Companies included in ranking 4 (fairly weak) include the following: |
| a. the formulation of risk levels to be taken (risk appetite) and risk tolerance (risk tolerance) is less adequate and not aligned with overall strategic objectives and business strategy; b. there are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding credit risk management, credit risk sources, and credit risk levels at the Company; | |
| c. the credit risk management culture is less strong and has not been internalized well at every organizational level; | |
| d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally less adequate, with weaknesses in various assessment aspects that require immediate improvement; e. there are significant weaknesses in the credit risk management function that require immediate improvement; f. delegation of authority is weak, not controlled and not monitored well; g. financing strategy is less aligned with the risk levels to be taken (risk appetite) and credit risk tolerance (risk tolerance); h. there are significant weaknesses in policies, procedures, and limit setting for credit risk; | |
| i. the credit risk management process is less adequate in identifying, measuring, monitoring, and controlling credit risk; | |
| j. the financing distribution process is less good and has weaknesses in one or more aspects of fund provision that need immediate improvement; k. the credit risk grading system and implementation are less good; | |
| l. financing review is less good and has some weaknesses that need immediate improvement; | |
| m. there are significant weaknesses in the management information system for credit risk including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; n. human resources are less adequate in terms of quantity and quality in the credit risk management function; o. the internal control system is less effective in supporting the implementation of credit risk management; p. the execution of independent reviews by the internal audit work unit and functions performing independent reviews is less adequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; q. there are significant weaknesses based on independent review results that require immediate improvement action; and r. follow-up on independent reviews is less adequate. Ranking 5 (Weak) | The quality of risk management implementation for credit risk is inadequate, with significant weaknesses in various aspects of credit risk management that are beyond management's ability to resolve. Example characteristics of Companies included in ranking 5 (weak) include the following: |
| a. the formulation of risk levels to be taken (risk appetite) and risk tolerance (risk tolerance) is inadequate and there is no connection with strategic objectives and business... |
overall business level; b. the Board of Directors, Board of Commissioners, and/or Sharia Supervisory Board (DPS) have very weak awareness and understanding regarding risk management for credit risk, credit risk sources, and credit risk levels at the Company;
c. the risk management culture for credit risk is weak or does not exist at all;
d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, with significant weaknesses in almost all aspects of assessment, actions, and resolutions beyond the Company's capability; e. there are significant weaknesses in the risk management function for credit risk requiring fundamental improvement; f. delegation of authority is very weak or non-existent; g. financing strategy is misaligned with the risk levels to be taken and credit risk tolerance; h. there are very significant weaknesses in policies, procedures, and limit setting for credit risk;
i. the risk management process for credit risk is inadequate in identifying, measuring, monitoring, and controlling credit risk;
j. the fund disbursement process is poor, with weaknesses in one or more aspects of fund provision that need immediate improvement; k. the credit risk grading system and application are poor;
l. the financing review function is poor, with several weaknesses that need immediate improvement;
m. there are fundamental weaknesses in the management information system for credit risk, including risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, which need immediate improvement; n. human resources are inadequate in both quantity and quality in the risk management function for credit risk; o. the internal control system is ineffective in supporting the implementation of risk management for credit risk; p. the execution of independent review by the internal audit unit and functions performing independent review is insufficient or inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors,
Board of Commissioners, and/or DPS requiring fundamental improvement; q. there are very significant weaknesses based on the results of independent review whose corrective actions r. follow-up on independent review is inadequate
| Parameter or Indicator | Description |
|---|---|
| 1. Business strategy and policies related to market risk | Business strategies and policies related to financing disbursement and funding acquisition sensitive to market risk, including interest rates and foreign exchange.<br><br>Business strategies and policies include among others:<br>a. the use of interest rate risk, yield, and foreign exchange considerations in setting funding acquisition strategies; and<br>b. the use of interest rate and yield risk considerations in setting financing disbursement strategies, including setting financing interest rates or yields. |
| 2. Volume and composition of asset portfolio exposed to market risk | Ratio of financing receivables with floating interest rates<br>1) For Financing Companies:<br>Total Outstanding Financing Receivables with Floating Interest Rates<br>-------------------------------------------------------<br>Total Outstanding Financing Receivables<br><br>2) For Sharia Financing Companies and UUS:<br>This ratio is not used for Sharia Financing Companies and UUS. |
| 3. Volume and composition of liability portfolio exposed to market risk | a. Ratio of loans with floating interest rates<br>1) For Financing Companies:<br>Total Loans with Floating Interest Rates<br>----------------------------------------<br>Total Loans<br><br>2) For Sharia Financing Companies and UUS:<br>This ratio is not used for Sharia Financing Companies.<br><br>b. Ratio of loans in foreign currency<br>1) For Financing Companies:<br>Total Outstanding Loans in Foreign Currency<br>-------------------------------------------<br>Total Outstanding Loans<br><br>2) For Sharia Financing Companies and UUS:<br>Total Outstanding Sharia-Compliant Funding in Foreign Currency<br>--------------------------------------------------------------<br>Total Outstanding Sharia-Compliant Funding<br><br>c. Ratio of issued securities with floating interest rates<br>1) For Financing Companies:<br>Total Outstanding Issued Securities with Floating Interest Rates<br>---------------------------------------------------------------<br>Total Outstanding Issued Securities<br><br>2) For Sharia Financing Companies and UUS:<br>This ratio is not used for Sharia Financing Companies and UUS.<br><br>d. Ratio of issued financing securities in foreign currency.<br>Total Outstanding Issued Securities<br><br>e. Ratio of foreign currency liabilities that have been hedged<br>Total Outstanding Foreign Currency Liabilities that have been Hedged<br>--------------------------------------------------------------------<br>Total Outstanding Foreign Currency Liabilities |
| Rating | Definition | Rating |
|---|---|---|
| Rating 1 (Low) | Considering the business activities conducted by the Company, the potential losses faced by the Company from market risk are classified as very low during a certain period in the future.<br><br>Examples of characteristics of Companies included in rating 1 (low) include the following:<br>a. business strategies and policies related to market risk are classified as conservative or very low risk;<br>b. market risk exposure on assets and liabilities is not significant;<br>c. hedging positions are very effective (completely matched/hedged); and<br>d. asset and liability structure is not sensitive to interest rate changes. | Rating 1 (Low) |
| Rating 2 (Low-Medium) | Considering the business activities conducted by the Company, the potential losses faced by the Company from market risk are classified as low during a certain period in the future.<br><br>Examples of characteristics of Companies included in rating 2 (low-medium) include the following:<br>a. business strategies and policies related to market risk are classified as low risk;<br>b. market risk exposure on assets and liabilities is less significant;<br>c. hedging positions are effective; and<br>d. asset and liability structure is less sensitive to interest rate changes. | Rating 2 (Low-Medium) |
| Rating 3 (Medium) | Considering the business activities conducted by the Company, the potential losses faced by the Company from market risk are quite high during a certain period in the future.<br><br>Examples of characteristics of Companies included in rating 3 (medium) include the following:<br>a. business strategies and policies related to market risk are classified as quite high risk;<br>b. market risk exposure on assets and liabilities is quite significant;<br>c. hedging positions are quite effective; and<br>d. asset and liability structure is quite sensitive to interest rate changes. | Rating 3 (Medium) |
| Rating 4 (Medium-High) | Considering the business activities conducted by the Company, the potential losses faced by the Company from market risk are high during a certain period in the future.<br><br>Examples of characteristics of Companies included in rating 4 (medium-high) include the following:<br>a. business strategies and policies related to market risk are classified as high risk;<br>b. market risk exposure on assets and liabilities is significant;<br>c. hedging positions are less effective; and<br>d. asset and liability structure is sensitive to interest rate changes. | Rating 4 (Medium-High) |
| Rating 5 (High) | Considering the business activities conducted by the Company, the potential losses faced by the Company from market risk are very high during a certain period in the future.<br><br>Examples of characteristics of Companies included in rating 5 (high) include the following:<br>a. business strategies and policies related to market risk are classified as very high risk;<br>b. market risk exposure on assets and liabilities are very significant;<br>c. hedging positions are ineffective; and<br>d. asset and liability structure are very sensitive to interest rate changes. | Rating 5 (High) |
| Rating | Definition | Rating |
|---|---|---|
| Rating 1 (Strong) | The quality of risk management implementation for market risk is very adequate, with minor weaknesses that are not significant and can be ignored.<br><br>Examples of characteristics of Companies included in rating 1 (strong) include the following:<br>a. the formulation of risk appetite and risk tolerance is very adequate and aligned with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or DPS have very good awareness and understanding regarding risk management for market risk, market risk sources, and market risk levels at the Company;<br>c. the risk management culture for market risk is very strong and has been internalized very well at all organizational levels;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is overall very adequate;<br>e. the risk management function for market risk has operated very well;<br>f. delegation of authority is controlled and monitored periodically, and has operated very well;<br>g. management strategy for market risk is very adequate;<br>h. policies, procedures, and limit setting for market risk are very adequate and available for all areas of risk management for market risk, aligned with implementation, and well understood by employees;<br>i. the risk management process for market risk is very adequate in identifying, measuring, monitoring, and controlling market risk;<br>j. the management information system for market risk is very good, producing comprehensive and integrated market risk reports to the Board of Directors, Board of Commissioners, and/or DPS;<br>k. human resources are very adequate in both quantity and quality in the risk management function for market risk;<br>l. the internal control system is very effective in supporting the implementation of risk management for market risk;<br>m. the execution of independent review by the internal audit unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;<br>n. generally, there are no significant weaknesses based on the results of independent review; and<br>o. follow-up on independent review has been executed very adequately. | Rating 1 (Strong) |
| Rating 2 (Fairly Strong) | The quality of risk management implementation for market risk is adequate despite some minor weaknesses that can be resolved in normal business activities.<br><br>Examples of characteristics of Companies included in rating 2 (fairly strong) include the following:<br>a. the formulation of risk appetite and risk tolerance is adequate and aligned with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding risk management for market risk, market risk sources, and market risk levels at the Company;<br>c. the risk management culture for market risk is strong and has been internalized well at all organizational levels;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, with some weaknesses that are not significant and can be improved immediately;<br>e. the risk management function for market risk has operated well;<br>f. delegation of authority is controlled and monitored periodically and has operated well;<br>g. management strategy for market risk is adequate;<br>h. policies, procedures, and limit setting for market risk are adequate and available for all areas of risk management for market risk, aligned with implementation, and well understood by employees despite minor weaknesses;<br>i. the risk management process for market risk is adequate in identifying, measuring, monitoring, and controlling market risk;<br>j. the management information system for market risk is good, including strategic risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, but has minor weaknesses that can be easily improved;<br>k. human resources are adequate in both quantity and quality in the risk management function for market risk;<br>l. the internal control system is effective in supporting the implementation of risk management for market risk;<br>m. the execution of independent review by the internal audit unit and functions performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;<br>n. there are weaknesses but not significant based on the results of independent review; and<br>o. follow-up on independent review has been executed adequately. | Rating 2 (Fairly Strong) |
| Rating 3 (Sufficient) | The quality of risk management implementation for market risk is sufficiently adequate. Although minimum requirements are met, there are some weaknesses that require management attention.<br><br>Examples of characteristics of Companies included in rating 3 (sufficient) include the following:<br>a. the formulation of risk appetite and risk tolerance is sufficiently adequate but not always aligned with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or DPS have sufficiently good awareness and understanding regarding risk management for market risk, market risk sources, and market risk levels at the Company;<br>c. the risk management culture for market risk is sufficiently strong and has been internalized sufficiently well but not always implemented consistently;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally sufficiently adequate, but there are weaknesses in some assessment aspects that need management attention;<br>e. the risk management function for market risk has operated sufficiently well;<br>f. delegation of authority is sufficiently good, but control and monitoring are not always executed well;<br>g. management strategy for market risk is sufficiently adequate;<br>h. policies, procedures, and limit setting for market risk are sufficiently adequate but not always consistent with implementation;<br>i. the risk management process for market risk is sufficiently adequate in identifying, measuring, monitoring, and controlling market risk;<br>j. the management information system for market risk meets minimum expectations but has some weaknesses, including reporting to the Board of Directors, Board of Commissioners, and/or DPS that requires management attention;<br>k. human resources are sufficiently adequate in both quantity and quality in the risk management function for market risk;<br>l. the internal control system is sufficiently effective in supporting the implementation of risk management for market risk;<br>m. the execution of independent review by the internal audit unit and functions performing independent review is sufficiently adequate, but there are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>n. there are weaknesses that are quite significant based on the results of independent review that require management attention; and<br>o. follow-up on independent review has been executed sufficiently adequately. | Rating 3 (Sufficient) |
| Rating 4 (Fairly Weak) | The quality of risk management implementation for market risk is less adequate, with significant weaknesses in various aspects of risk management for market risk requiring immediate corrective action.<br><br>Examples of characteristics of Companies included in rating 4 (fairly weak) include the following:<br>a. the formulation of risk appetite and risk tolerance is less adequate and not aligned with overall strategic objectives and business strategy;<br>b. there are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for market risk, market risk sources, and market risk levels at the Company;<br>c. the risk management culture for market risk is less strong and has not been internalized well at every organizational level;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally less adequate, with weaknesses in various assessment aspects requiring immediate improvement;<br>e. the risk management function for market risk has operated less well;<br>f. delegation of authority is weak, not controlled and not monitored well;<br>g. management strategy for market risk is less adequate;<br>h. there are significant weaknesses in policies, procedures, and limit setting for market risk;<br>i. the risk management process for market risk is less adequate in identifying, measuring, monitoring, and controlling market risk;<br>j. there are significant weaknesses in the market risk management information system, including reporting to the Board of Directors, Board of Commissioners, and/or DPS, requiring immediate improvement;<br>k. human resources are less adequate in terms of quantity and quality in the risk management function for market risk;<br>l. the internal control system is less effective in supporting the implementation of risk management for market risk;<br>m. the execution of independent review by the internal audit unit and functions performing independent review is less adequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS requiring immediate improvement;<br>n. there are significant weaknesses based on the results of independent review requiring immediate corrective action; and<br>o. follow-up on independent review is less adequate. | Rating 4 (Fairly Weak) |
| Rating 5 (Weak) | The quality of risk management implementation for market risk is inadequate, with significant weaknesses in various aspects of risk management for market risk whose resolution is beyond management's capability.<br><br>Examples of characteristics of Companies included in rating 5 (weak) include the following:<br>a. the formulation of risk appetite and risk tolerance is inadequate and<br><br>Rating 5 (Weak) | Rating 5 (Weak) |
| Rating Definition Rating | Rating Definition Rating | Rating Definition Rating |
| there is no connection with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or DPS have very weak awareness and understanding regarding risk management for market risk, market risk sources, and market risk levels at the Company;<br>c. the risk management culture for market risk is not strong or does not exist at all;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, with significant weaknesses in almost all aspects of assessment, actions, and resolutions beyond the Company's capability;<br>e. the risk management function for market risk has operated poorly;<br>f. delegation of authority is very weak or non-existent;<br>g. management strategy for market risk is inadequate;<br>h. there are very significant weaknesses in policies, procedures, and limit setting for market risk;<br>i. the risk management process for market risk is inadequate in identifying, measuring, monitoring, and controlling market risk;<br>j. there are fundamental weaknesses in the management information system for market risk;<br>k. human resources are inadequate in both quantity and quality in the risk management function for market risk;<br>l. the internal control system is ineffective in supporting the implementation of risk management for market risk;<br>m. the execution of independent review by the internal audit unit and functions performing independent review is insufficient or inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS requiring fundamental improvement;<br>n. there are very significant weaknesses based on the results of independent review whose corrective actions<br>o. follow-up on independent review is inadequate |
| Parameter or Indicator | Description |
|---|---|
| 1. Composition of short-term assets and liabilities, including administrative account transactions | a. Cash Ratio<br>Cash + Cash Equivalents<br>-----------------------<br>Current Liabilities<br><br>b. Current Ratio<br>Value of Current Assets<br>-----------------------<br>Value of Current Liabilities<br><br>c. Significance of administrative account transactions<br>Total Administrative Account Transactions<br>------------------------------------------<br>Total Liabilities<br><br>Administrative account transactions include the issuance of bank guarantees, joint financing disbursement (third-party portion), and channeling financing disbursement (third-party portion). |
| 2. Cash flow management | Cash Flow from Operating Activities<br>Cash Inflows from Operating Activities<br>--------------------------------------<br>Cash Outflows from Operating Activities |
| 3. Vulnerability to funding needs | The Company's vulnerability to funding needs and the Company's ability to meet funding needs.<br><br>Indicators for assessing the Company's funding needs in normal and crisis situations and the Company's ability to meet funding needs, including through analysis of:<br>a. asset and liability matching analysis;<br>b. cash flow projections; and<br>c. stress tests. |
| 4. Access to funding sources | a. The Company's ability to obtain funding sources in normal and crisis conditions.<br><br>Assessment focuses on the Company's reputation for maintaining funding sources, credit line conditions, funding source access performance, and support from parent or intra-group companies.<br><br>b. Gearing Ratio<br>a) For Financing Companies:<br>Loans from Banks + Bond Issuance + Subordinated Loans + Medium Term Notes Issuance<br>------------------------------------------------------------------------------------<br>Equity + Subordinated Loans - Investments<br><br>b) For Sharia Financing Companies and UUS:<br>Funding from Banks + Sukuk Issuance via Public Offering + Subordinated Funding + Sukuk Issuance without Public Offering<br>-----------------------------------------------------------------------------------------------------------------------<br>Equity + Subordinated Loans - Investments |
Table II.E.2: Guidelines for Determining Inherent Risk Levels for Liquidity Risk
| Rating | Definition of Rating |
|---|---|
| Rating 1 (Low) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from liquidity risk is classified as very low during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 1 (low) include the following:<br>a. The Company has high-quality liquid assets that are very adequate to cover maturing liabilities;<br>b. the Company's funding source fulfillment is very stable;<br>c. the volume of administrative account transactions is not significant;<br>d. intragroup funding commitments are not significant;<br>e. the Company is very capable of meeting obligations and cash flow needs under normal conditions as well as in crisis scenarios;<br>f. cash flow mismatch arising from operational activities is very low; and<br>g. access to funding sources is very adequate, evidenced by the Company's very good reputation, very adequate stand-by loans, and the existence of liquidity commitments or support from the parent company or intragroup. |
| Rating 2 (Low-Medium) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from liquidity risk is classified as low during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 2 (low-medium) include the following:<br>a. The Company has high-quality liquid assets that are adequate to cover maturing liabilities;<br>b. the Company's funding source fulfillment is stable;<br>c. the volume of administrative account transactions is less significant;<br>d. intragroup funding commitments are less significant;<br>e. the Company is capable of meeting obligations and cash flow needs under normal conditions as well as in crisis scenarios;<br>f. cash flow mismatch arising from operational activities is low; and<br>g. access to funding sources is adequate, evidenced by the Company's good reputation or liquidity support from the parent company or intragroup. |
| Rating 3 (Medium) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from liquidity risk is classified as moderately high during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 3 (medium) include the following:<br>a. The Company has high-quality liquid assets that are moderately adequate to cover maturing liabilities;<br>b. the Company's funding source fulfillment is moderately stable;<br>c. the volume of administrative account transactions is moderately significant;<br>d. intragroup funding commitments are moderately significant;<br>e. the Company is moderately capable of meeting obligations and cash flow needs under normal conditions as well as in crisis scenarios;<br>f. cash flow mismatch arising from operational activities is moderately high; and<br>g. access to funding sources is moderately adequate, evidenced by the Company's moderately good reputation, moderately adequate stand-by loans, and the existence of liquidity commitments or support from the parent company or intragroup. |
| Rating 4 (Medium-High) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from liquidity risk is classified as high during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 4 (medium-high) include the following:<br>a. The Company has high-quality liquid assets that are less adequate to cover maturing liabilities;<br>b. the Company's funding source fulfillment is less stable;<br>c. administrative account transactions are significant; and/or<br>d. intragroup funding commitments are significant;<br>e. the Company is less capable of meeting obligations and cash flow needs under normal conditions as well as in crisis scenarios;<br>f. cash flow mismatch arising from operational activities is high; and<br>g. access to funding sources is less adequate due to the Company's less good reputation, limited stand-by loans, and the absence of liquidity commitments or support from the parent company or intragroup. |
| Rating 5 (High) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from liquidity risk is classified as very high during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 5 (high) include the following:<br>a. The Company does not have high-quality liquid assets to meet maturing liabilities;<br>b. the Company's funding source fulfillment is unstable;<br>c. administrative account transactions are very significant; and/or<br>d. intragroup funding commitments are very significant;<br>e. the Company is unable to meet obligations and cash flow needs under normal conditions as well as in crisis scenarios;<br>f. cash flow mismatch arising from operational activities is very high; and<br>g. access to funding sources is inadequate due to deteriorating Company reputation, unavailable stand-by loans, and the absence of liquidity commitments or support from the parent company or intragroup. |
Table II.E.3: Guidelines for Determining the Quality of Risk Management Implementation for Liquidity Risk
| Rating | Definition of Rating |
|---|---|
| Rating 1 (Strong) | The quality of risk management implementation for liquidity risk is very adequate, with minor weaknesses that are not significant and can be ignored.<br><br>Examples of characteristics of Companies included in Rating 1 (strong) include the following:<br>a. the formulation of risk appetite and risk tolerance is very adequate and aligned with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or Sharia Supervisory Board (DPS) have very good awareness and understanding regarding liquidity risk management, liquidity risk sources, and the level of liquidity risk in the Company;<br>c. the liquidity risk management culture is very strong and has been internalized very well at all organizational levels;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS as a whole is very adequate;<br>e. the liquidity risk management function is independent, has clear duties and responsibilities, and operates very well;<br>f. the delegation of authority is controlled and monitored periodically, and operates very well;<br>g. the liquidity management strategy is very adequate, including among others funding strategy, position and liquidity risk management strategy, intragroup position and liquidity risk management, management of high-quality liquid assets as collateral, and emergency funding plan (Contingency Funding Plan/CFP);<br>h. policies, procedures, and limit setting for liquidity risk are very adequate and available for all liquidity risk management areas, aligned with implementation, and well understood by employees;<br>i. the liquidity risk management process is very adequate in identifying, measuring, monitoring, and controlling liquidity risk;<br>j. the management information system for liquidity risk is very good, producing comprehensive and integrated liquidity risk reports to the Board of Directors, Board of Commissioners, and/or DPS;<br>k. human resources are very adequate in both quantity and quality in the liquidity risk management function;<br>l. the internal control system is very effective in supporting the implementation of liquidity risk management;<br>m. the implementation of independent review by the internal audit unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;<br>n. generally, there are no significant weaknesses based on independent review results; and<br>o. follow-up on independent review has been implemented very adequately. |
| Rating 2 (Fairly Strong) | The quality of risk management implementation for liquidity risk is adequate despite some minor weaknesses that can be resolved in normal business activities.<br><br>Examples of characteristics of Companies included in Rating 2 (fairly strong) include the following:<br>a. the formulation of risk appetite and risk tolerance is adequate and aligned with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding liquidity risk management, liquidity risk sources, and the level of liquidity risk in the Company;<br>c. the liquidity risk management culture is strong and has been internalized well at all organizational levels;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, with some weaknesses that are not significant and can be repaired immediately;<br>e. the liquidity risk management function has clear duties and responsibilities and operates well, but there are minor weaknesses that can be resolved in normal business activities;<br>f. the delegation of authority is controlled and monitored periodically and operates well;<br>g. the liquidity management strategy is adequate, including among others funding strategy, position and liquidity risk management strategy, intragroup position and liquidity risk management, management of high-quality liquid assets as collateral, and emergency funding plan (Contingency Funding Plan/CFP);<br>h. policies, procedures, and limit setting for liquidity risk are adequate and available for all liquidity risk management areas, aligned with implementation, and well understood by employees despite minor weaknesses;<br>i. the liquidity risk management process is adequate in identifying, measuring, monitoring, and controlling liquidity risk;<br>j. the management information system for liquidity risk is good, including strategic risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily repaired;<br>k. human resources are adequate in both quantity and quality in the liquidity risk management function;<br>l. the internal control system is effective in supporting the implementation of liquidity risk management;<br>m. the implementation of independent review by the internal audit unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;<br>n. there are weaknesses but not significant based on independent review results; and<br>o. follow-up on independent review has been implemented adequately. |
| Rating 3 (Sufficient) | The quality of risk management implementation for liquidity risk is sufficiently adequate. Although minimum requirements are met, there are some weaknesses that require management attention.<br><br>Examples of characteristics of Companies included in Rating 3 (sufficient) include the following:<br>a. the formulation of risk appetite and risk tolerance is sufficiently adequate but not always aligned with overall strategic objectives and business strategy;<br>b. the Board of Directors, Board of Commissioners, and/or DPS have sufficiently good awareness and understanding regarding liquidity risk management, liquidity risk sources, and the level of liquidity risk in the Company;<br>c. the liquidity risk management culture is sufficiently strong and has been internalized sufficiently well but not always implemented consistently;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally sufficiently adequate, but there are weaknesses in some assessment aspects that need management attention;<br>e. the liquidity risk management function is sufficiently good, but there are some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>f. the delegation of authority is sufficiently good, but control and monitoring are not always implemented well;<br>g. the liquidity management strategy is sufficiently adequate, with some weaknesses in one or more aspects of liquidity management that need management attention;<br>h. policies, procedures, and limit setting for liquidity risk are sufficiently adequate but not always consistent with implementation;<br>i. the liquidity risk management process is sufficiently adequate in identifying, measuring, monitoring, and controlling liquidity risk;<br>j. the management information system for liquidity risk meets minimum expectations but has some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>k. human resources are sufficiently adequate in both quantity and quality in the liquidity risk management function;<br>l. the internal control system is sufficiently effective in supporting the implementation of liquidity risk management;<br>m. the implementation of independent review by the internal audit unit and functions conducting independent review is sufficiently adequate, but there are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>n. there are weaknesses that are sufficiently significant based on independent review results that require management attention; and<br>o. follow-up on independent review has been implemented sufficiently adequately. |
| Rating 4 (Fairly Weak) | The quality of risk management implementation for liquidity risk is less adequate, with significant weaknesses in various aspects of liquidity risk management.<br><br>Examples of characteristics of Companies included in Rating 4 (fairly weak) include the following:<br>a. the formulation of risk appetite and risk tolerance is less adequate and not aligned with overall strategic objectives and business strategy;<br>b. there are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding liquidity risk management, liquidity risk sources, and the level of liquidity risk in the Company;<br>c. the liquidity risk management culture is not strong and has not been internalized well at each organizational level;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally less adequate, with weaknesses in various assessment aspects that require immediate improvement;<br>e. there are significant weaknesses in the liquidity risk management function that require immediate improvement;<br>f. delegation of authority is weak, not controlled and not monitored well;<br>g. the liquidity management strategy is less adequate, with weaknesses in liquidity management aspects that require immediate improvement;<br>h. there are significant weaknesses in policies, procedures, and limit setting for liquidity risk;<br>i. the liquidity risk management process is less adequate in identifying, measuring, monitoring, and controlling liquidity risk;<br>j. there are significant weaknesses in the management information system for liquidity risk including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement;<br>k. human resources are less adequate in terms of quantity and quality in the liquidity risk management function;<br>l. the internal control system is less effective in supporting the implementation of liquidity risk management;<br>m. the implementation of independent review by the internal audit unit and functions conducting independent review is less adequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement;<br>n. there are significant weaknesses based on independent review results that require immediate corrective action; and<br>o. follow-up on independent review is less adequate. |
| Rating 5 (Weak) | The quality of risk management implementation for liquidity risk is inadequate, with significant weaknesses in various aspects of liquidity risk management whose resolution is beyond management's capability.<br><br>Examples of characteristics of Companies included in Rating 5 (weak) include the following:<br>a. the formulation of risk appetite and risk tolerance is inadequate and there is no connection with overall strategic objectives and business strategy;<br>b. the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding liquidity risk management, liquidity risk sources, and the level of liquidity risk in the Company is very weak;<br>c. the liquidity risk management culture is not strong or does not exist at all;<br>d. the execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, with significant weaknesses in almost all assessment aspects and the corrective actions are beyond the Company's capability;<br>e. there are significant weaknesses in the liquidity risk management function that require fundamental improvement;<br>f. delegation of authority is very weak or non-existent;<br>g. the liquidity management strategy is inadequate, with weaknesses in almost all aspects of liquidity management that require immediate improvement;<br>h. there are very significant weaknesses in policies, procedures, and limit setting for liquidity risk;<br>i. the liquidity risk management process is inadequate in identifying, measuring, monitoring, and controlling liquidity risk;<br>j. there are fundamental weaknesses in the management information system for liquidity risk;<br>k. human resources are inadequate in terms of quantity and quality in the liquidity risk management function;<br>l. the internal control system is ineffective in supporting the implementation of liquidity risk management;<br>m. the implementation of independent review by the internal audit unit and functions conducting independent review is less or inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require fundamental improvement;<br>n. there are very significant weaknesses based on independent review results whose corrective actions are beyond management's capability; and<br>o. follow-up on independent review is inadequate. |
Table II.F.1: Parameters or Indicators for Inherent Risk Assessment for Legal Risk
| Parameter or Indicator | Description |
|---|---|
| 1. Absence or change in legislation | a. Proportion of the Company's products not clearly regulated by statutory regulations and products that tend to have a high level of complexity<br><br>Income from Products Not Regulated by Statutory Regulations / Total Income<br><br>b. Use of contract standards that are not in accordance with statutory regulations or best practice<br><br>Value of Contracts Using Contract Standards Not in Accordance with Statutory Regulations or Best Practice / Total Contract Value |
| 2. Weaknesses in agreements or cooperation | a. Non-fulfillment of the validity requirements of the agreement<br>b. Existence of weaknesses in agreement clauses and/or non-fulfillment of agreed requirements<br>c. Transaction complexity and use of terms that are difficult to understand or unusual for the general public<br>d. Existence of supporting documents related to agreements conducted by the Company with third parties<br><br>Weaknesses in agreements conducted by the Company are a source of problems or disputes in the future that can cause potential legal risks for the Company. |
| 3. Dispute resolution process | a. Inability to execute an agreement either in whole or in part.<br>b. Use of choice of law and legal jurisdiction in dispute resolution.<br>c. History of legal claims against the Company.<br>d. The nominal amount of the lawsuit and the estimated losses that may be experienced by the Company due to legal claims.<br>e. The amount of losses experienced by the Company due to a court decision that has permanent legal force compared to the Company's capital.<br>f. The possibility of similar lawsuits arising due to the same contract standard and the estimated total losses that may arise compared to the Company's capital.<br><br>Clearly stated. |
Table II.F.2: Guidelines for Determining Inherent Risk Levels for Legal Risk
| Rating | Definition of Rating |
|---|---|
| Rating 1 (Low) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from legal risk is classified as very low during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 1 (low) include the following:<br>a. there are no products and/or Company activities that are not regulated by statutory regulations or there are products and/or activities that are not regulated in statutory regulations in insignificant amounts;<br>b. agreements made by the Company are very adequate; and<br>c. there are no litigation processes occurring in the Company or there are litigation processes but the frequency and/or financial impact of the lawsuits do not significantly disturb the Company's financial conditions and do not have a major impact on the Company's reputation. |
| Rating 2 (Low-Medium) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from legal risk is classified as low during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 2 (low-medium) include the following:<br>a. there are products and/or activities that are not regulated in statutory regulations in less significant amounts.<br>b. agreements made by the Company are adequate; and<br>c. there are litigation processes occurring in the Company but the frequency and/or financial impact of the lawsuits are less significant in disturbing the Company's financial conditions and have less major impact on the Company's reputation. |
| Rating 3 (Medium) | Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from legal risk is classified as moderately high during a certain period in the future.<br><br>Examples of characteristics of Companies included in Rating 3 (medium) include the following:<br>a. there are products and/or activities that are not regulated in statutory regulations in moderately significant amounts. |
Rating 4 (Medium-High)
Considering the business activities conducted by the Company, the potential losses faced by the Company from legal risks are classified as high during a certain period in the future. Examples of Company characteristics included in Rating 4 (medium-high) include the following:
a. There are products and/or activities not regulated by statutory regulations in significant quantities. b. Agreements made by the Company are inadequate; and
c. There are litigation processes involving the Company with significant frequency and/or financial impact of the lawsuits, such that if the Company loses, compensation for such lawsuits can disrupt the Company's financial condition and have a major impact on the Company's reputation.
Rating 5 (High)
Considering the business activities conducted by the Company, the potential losses faced by the Company from legal risks are classified as very high during a certain period in the future. Examples of financing company characteristics included in Rating 5 (high) include the following:
a. There are products and/or activities not regulated by statutory regulations in very significant quantities; b. Agreements made by the Company are inadequate; and
c. There are litigation processes against the Company by customers or debtors with very significant frequency and/or financial impact, such that if the financing company loses in a court decision, such conditions can significantly affect the business condition of the Company.
| Rating | Definition of Rating |
|---|---|
| Rating 1 (Strong) | The quality of risk management implementation for legal risk is very adequate, with minor weaknesses that are not significant and can be ignored.<br><br>Examples of Company characteristics included in Rating 1 (strong) include the following:<br>a. Formulation of risk appetite and risk tolerance is very adequate and aligned with overall strategic objectives and business strategy;<br>b. The Board of Directors, Board of Commissioners, and/or Sharia Supervisory Board (DPS) have very good awareness and understanding of legal risk management, legal risk sources, and legal risk levels at the Company;<br>c. Legal risk management culture is very strong and has been internalized very well at all organizational levels;<br>d. The overall execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is very adequate;<br>e. The legal risk management function is independent, has clear duties and responsibilities, and operates very well;<br>f. Authority delegation is controlled and monitored periodically, and operates very well;<br>g. Legal risk management strategy is very aligned with the risk appetite and risk tolerance;<br>h. Policies, procedures, and limits for legal risk are very adequate and available for all legal risk management areas, aligned with implementation, and well understood by employees;<br>i. Legal risk management processes are very adequate in identifying, measuring, monitoring, and controlling legal risk;<br>j. Legal risk management information systems are very good, producing comprehensive and integrated legal risk reports to the Board of Directors, Board of Commissioners, and/or DPS;<br>k. Human resources are very adequate in both quantity and quality for the legal risk management function;<br>l. Internal control systems are very effective in supporting legal risk management implementation;<br>m. Independent review implementation by internal audit units and independent review functions is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;<br>n. Generally, there are no significant weaknesses based on independent review results; and<br>o. Follow-up on independent reviews has been implemented very adequately. |
| Rating 2 (Fairly Strong) | The quality of risk management implementation for legal risk is adequate, although there are some minor weaknesses that can be resolved in normal business activities.<br><br>Examples of Company characteristics included in Rating 2 (fairly strong) include the following:<br>a. Formulation of risk appetite and risk tolerance is adequate and aligned with overall strategic objectives and business strategy;<br>b. The Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding of legal risk management, legal risk sources, and legal risk levels at the Company;<br>c. Legal risk management culture is strong and has been internalized well at all organizational levels;<br>d. The overall execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, with some weaknesses that are not significant and can be repaired immediately;<br>e. The legal risk management function has clear duties and responsibilities and operates well, but there are minor weaknesses that can be resolved in normal business activities;<br>f. Authority delegation is controlled and monitored periodically and operates well;<br>g. Legal risk management strategy is aligned with risk appetite and risk tolerance;<br>h. Policies, procedures, and limits for legal risk are adequate and available for all legal risk management areas, aligned with implementation, and well understood by employees, although there are minor weaknesses;<br>i. Legal risk management processes are adequate in identifying, measuring, monitoring, and controlling legal risk;<br>j. Legal risk management information systems are good, including legal risk reporting to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily repaired;<br>k. Human resources are adequate in both quantity and quality for the legal risk management function;<br>l. Internal control systems are effective in supporting legal risk management implementation;<br>m. Independent review implementation by internal audit units and independent review functions is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;<br>n. There are weaknesses but not significant based on independent review results; and<br>o. Follow-up on independent reviews has been implemented adequately. |
| Rating 3 (Sufficient) | The quality of risk management implementation for legal risk is sufficiently adequate. Although minimum requirements are met, there are some weaknesses that require management attention.<br><br>Examples of Company characteristics included in Rating 3 (sufficient) include the following:<br>a. Formulation of risk appetite and risk tolerance is sufficiently adequate but not always aligned with overall strategic objectives and business strategy;<br>b. The Board of Directors, Board of Commissioners, and/or DPS have sufficiently good awareness and understanding of legal risk management, legal risk sources, and legal risk levels at the Company;<br>c. Legal risk management culture is sufficiently strong and has been internalized sufficiently well but not always implemented consistently;<br>d. The overall execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally sufficiently adequate, but there are weaknesses in some assessment aspects that need management attention;<br>e. The legal risk management function is sufficiently good, but there are some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>f. Authority delegation is sufficiently good, but control and monitoring are not always implemented well;<br>g. Legal risk management strategy is sufficiently aligned with risk appetite and risk tolerance;<br>h. Policies, procedures, and limits for legal risk are sufficiently adequate but not always consistent with implementation;<br>i. Legal risk management processes are sufficiently adequate in identifying, measuring, monitoring, and controlling legal risk;<br>j. Legal risk management information systems meet minimum expectations but have some weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>k. Human resources are sufficiently adequate in both quantity and quality for the legal risk management function;<br>l. Internal control systems are sufficiently effective in supporting legal risk management implementation;<br>m. Independent review implementation by internal audit units and independent review functions is sufficiently adequate, but there are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;<br>n. There are weaknesses that are sufficiently significant based on independent review results that require management attention; and<br>o. Follow-up on independent reviews has been implemented sufficiently adequately. |
| Rating 4 (Fairly Weak) | The quality of risk management implementation for legal risk is inadequate, with significant weaknesses in various aspects of legal risk management that require immediate corrective action.<br><br>Examples of Company characteristics included in Rating 4 (fairly weak) include the following:<br>a. Formulation of risk appetite and risk tolerance is inadequate and not aligned with overall strategic objectives and business strategy;<br>b. There are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding legal risk management, legal risk sources, and legal risk levels at the Company;<br>c. Legal risk management culture is not strong and has not been internalized well at every organizational level;<br>d. The overall execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally inadequate, with weaknesses in various assessment aspects that require immediate improvement;<br>e. There are significant weaknesses in the legal risk management function that require immediate improvement;<br>f. Authority delegation is weak, not controlled, and not monitored well;<br>g. Legal risk management strategy is not aligned with risk appetite and risk tolerance;<br>h. There are significant weaknesses in policies, procedures, and limits for legal risk;<br>i. Legal risk management processes are inadequate in identifying, measuring, monitoring, and controlling legal risk;<br>j. There are significant weaknesses in legal risk management information systems, including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement;<br>k. Human resources are inadequate in terms of both quantity and quality for the legal risk management function;<br>l. Internal control systems are less effective in supporting legal risk management implementation;<br>m. Independent review implementation by internal audit units and independent review functions is inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement;<br>n. There are significant weaknesses based on independent review results that require immediate improvement actions; and<br>o. Follow-up on independent reviews is inadequate. |
| Rating 5 (Weak) | The quality of risk management implementation for legal risk is inadequate, with significant weaknesses in various aspects of legal risk management, the resolution of which is beyond management's capability.<br><br>Examples of Company characteristics included in Rating 5 (weak) include the following:<br>a. Formulation of risk appetite and risk tolerance is inadequate and there is no connection with overall strategic objectives and business strategy;<br>b. The awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding legal risk management, legal risk sources, and legal risk levels at the Company are very weak;<br>c. Legal risk management culture is not strong or does not exist at all;<br>d. The execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, with significant weaknesses in almost all assessment aspects, and resolution actions are beyond the Company's capability;<br>e. There are significant weaknesses in the legal risk management function that require fundamental improvement;<br>f. Authority delegation is very weak or non-existent;<br>g. Legal risk management strategy is not aligned with risk appetite and risk tolerance;<br>h. There are very significant weaknesses in policies, procedures, and limits for legal risk;<br>i. Legal risk management processes are inadequate in identifying, measuring, monitoring, and controlling legal risk;<br>j. There are very significant weaknesses in legal risk management information systems;<br>k. Human resources are inadequate in terms of both quantity and quality for the legal risk management function;<br>l. Internal control systems are ineffective in supporting legal risk management implementation;<br>m. Independent review implementation by internal audit units and independent review functions is less than or inadequate, with weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require fundamental improvement;<br>n. There are very significant weaknesses based on independent review results, the improvement actions of which are beyond management's capability; and<br>o. Follow-up on independent reviews is inadequate. |
| Parameter or Indicator | Description |
|---|---|
| 1. Type and significance of violations committed | a. Type of violation or non-compliance committed by the Company.<br>b. Amount of fines imposed on the Company by authorities.<br>c. Significance of the violation.<br>d. Behavior underlying the violation.<br>e. Type of violation or non-compliance regarding the application of Sharia principles committed by the Company, based on findings from the Sharia Supervisory Board (DPS) or authorities.<br><br>Scope of violation refers to violations of statutory regulations and commitments to the Financial Services Authority (OJK), including sanctions imposed for violations committed by the Company.<br>Violations or non-compliance regarding the application of Sharia principles include violations of fatwas issued by the National Sharia Council (DSN) or other generally applicable standards in the Sharia financial sector. |
| 2. Frequency of violations (including sanctions) or Company compliance track record | a. Type and frequency of the same violations found annually in the last 3 (three) years.<br>b. Significance of the same violations.<br><br>Frequency is more historical, looking at the Company's compliance trends over the last 3 (three) years to determine whether the type of violation is repeated or whether significant improvements have not been made by the Company regarding such errors. |
| 3. Violations of statutory regulations or generally applicable business standards | Frequency of violations of regulations because they do not comply with statutory regulations or generally applicable standards.<br>Examples include violations of, among others: tax regulations, accounting standards, codes of ethics, or other generally applicable standards in the financial services sector. |
| 4. Follow-up on violations | Follow-up on violations of statutory regulations, including fulfillment of follow-up plans (action plans) submitted to OJK and other authorities.<br>Self-explanatory. |
| Rating | Definition of Rating |
|---|---|
| Rating 1 (Low) | Considering the business activities conducted by the Company, the potential losses faced by the Company from compliance risks are classified as very low during a certain period in the future.<br><br>Examples of Company characteristics included in Rating 1 (low) include the following:<br>a. There are no violations of statutory regulations;<br>b. The Company's compliance track record is very good;<br>c. The Company has implemented all applicable business standards and codes of ethics; and<br>d. There are no violations of Sharia principles regarding the operation of Sharia financing distribution and the Company's funding activities. |
| Rating 2 (Medium-Low) | Considering the business activities conducted by the Company, the potential losses faced by financing companies from compliance risks are classified as low during a certain period in the future.<br><br>Examples of Company characteristics included in Rating 2 (medium-low) include the following:<br>a. There are violations of statutory regulations that are relatively minor and can be immediately repaired by the Company (not significant);<br>b. The Company's compliance track record is good;<br>c. The Company has implemented almost all applicable business standards and codes of ethics (there are violations that are not significant); and<br>d. There are relatively minor violations of Sharia principles regarding the operation of Sharia financing distribution and the Company's funding activities (not significant). |
| Rating 3 (Medium) | Considering the business activities conducted by the Company, the potential losses faced by the Company from Compliance Risks are classified as sufficiently high during a certain period in the future.<br><br>Examples of Company characteristics included in Rating 3 (medium) include the following:<br>a. There are violations of statutory regulations that are sufficiently significant and require management attention;<br>b. The Company's compliance track record is less than good;<br>c. There are sufficiently significant violations of applicable business standards and codes of ethics; and<br>d. There are sufficiently significant violations of Sharia principles regarding the operation of Sharia financing distribution and the Company's funding activities. |
| Rating 4 (Medium-High) | Considering the business activities conducted by the Company, the potential losses faced by the Company from compliance risks are classified as high during a certain period in the future.<br><br>Examples of Company characteristics included in Rating 4 (medium-high) include the following:<br>a. There are violations of statutory regulations that are significant and require immediate improvement actions;<br>b. The Company's compliance track record is poor;<br>c. There are significant violations of applicable business standards and codes of ethics; and<br>d. There are significant violations of Sharia principles regarding the operation of Sharia financing distribution and the Company's funding activities. |
| Rating 5 (High) | Considering the business activities conducted by the Company, the potential losses faced by the Company from compliance risks are classified as very high during a certain period in the future.<br><br>Examples of Company characteristics included in Rating 5 (high) include the following:<br>a. There are violations of statutory regulations that are very significant and require immediate improvement;<br>b. The Company's compliance track record is very poor;<br>c. There are very significant violations of applicable business standards and codes of ethics; and<br>d. There are very significant violations of Sharia principles regarding the operation of Sharia financing distribution and the Company's funding activities. |
| Rating | Definition of Rating |
|---|---|
| Rating 1 (Strong) | The quality of risk management implementation for compliance risk is very adequate, with minor weaknesses that are not significant and can be ignored.<br><br>Examples of Company characteristics included in Rating 1 (strong) include the following:<br>a. Formulation of risk appetite and risk tolerance is very adequate and aligned with overall strategic objectives and business strategy;<br>b. The Board of Directors, Board of Commissioners, and/or Sharia Supervisory Board (DPS) have very good awareness and understanding of compliance risk management, compliance risk sources, and compliance risk levels at the Company;<br>c. Compliance risk management culture is very strong and has been internalized very well at all organizational levels;<br>d. The overall execution of duties by the Board of Directors, Board of Commissioners, and/or DPS is very adequate;<br>e. The compliance risk management function is independent, has clear duties and responsibilities, and operates very well;<br>f. Authority delegation is controlled and monitored periodically, and operates very well;<br>g. Compliance risk management strategy is very aligned with risk appetite and risk tolerance;<br>h. Policies, procedures, and limits for compliance risk are very adequate and available for all compliance risk management areas, aligned with implementation, and well understood by employees;<br>i. Compliance risk management processes are very adequate in identifying, measuring, monitoring, and controlling compliance risk;<br>j. Compliance risk management information systems are very good, producing comprehensive and integrated compliance risk reports to the Board of Directors, Board of Commissioners, and/or DPS; |
k. human resources are very adequate in terms of quantity and quality in the risk management function for compliance risk;
l. the internal control system is very effective in supporting the implementation of risk management for compliance risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; n. generally, there are no significant weaknesses based on the results of independent review; and o. follow-up on independent review has been carried out very adequately.
Level 2
(Somewhat Strong)
The quality of risk management implementation for compliance risk is adequate despite some minor weaknesses that can be resolved in normal business activities.
Examples of characteristics of Companies included in Level 2 (somewhat strong) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance is adequate and has aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding risk management for compliance risk, sources of compliance risk, and the level of compliance risk in the Company;
c. the risk management culture for compliance risk is strong and has been well internalized at all organizational levels;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, there are some weaknesses but not significant and can be repaired immediately; e. the risk management function for compliance risk has clear tasks and responsibilities and has run well, but there are minor weaknesses that can be resolved in normal business activities; f. delegation of authority is controlled and monitored periodically and has run well; g. management strategy for compliance risk aligns with the level of risk to be taken (risk appetite) and
Level Definition Rating risk tolerance (risk tolerance); h. policies, procedures, and limit setting for compliance risk are adequate and available for all areas of risk management for compliance risk, aligned with implementation, and well understood by employees despite minor weaknesses;
i. the risk management process for compliance risk is adequate in identifying, measuring, monitoring, and controlling compliance risk;
j. the management information system for compliance risk is good, including reporting compliance risk to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily repaired; k. human resources are adequate in terms of quantity and quality in the risk management function for compliance risk;
l. the internal control system is effective in supporting the implementation of risk management for compliance risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; n. there are weaknesses but not significant based on the results of independent review; and o. follow-up on independent review has been carried out adequately.
Level 3
(Adequate)
The quality of risk management implementation for compliance risk is adequately sufficient. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of characteristics of Companies included in Level 3 (adequate) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance) is adequately sufficient but not always aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have adequate awareness and understanding regarding risk management for compliance risk, sources of compliance risk, and the level of compliance risk in the Company;
c. the risk management culture for compliance risk is sufficiently strong and has been internalized sufficiently well
Level Definition Rating but not always implemented consistently; d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequately sufficient, but there are weaknesses in some assessment aspects that need management attention; e. the risk management function for compliance risk is quite good, but there are several weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; f. delegation of authority is quite good, but control and monitoring are not always implemented well; g. management strategy for compliance risk is quite aligned with the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance); h. policies, procedures, and limit setting for compliance risk are adequately sufficient but not always consistent with implementation;
i. the risk management process for compliance risk is adequately sufficient in identifying, measuring, monitoring, and controlling compliance risk;
j. the management information system for compliance risk meets minimum expectations but there are several weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; k. human resources are adequately sufficient in terms of quantity and quality in the risk management function for compliance risk;
l. the internal control system is sufficiently effective in supporting the implementation of risk management for compliance risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is adequately sufficient, but there are several weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention; n. there are weaknesses that are quite significant based on the results of independent review that require management attention; and o. follow-up on independent review has been carried out adequately sufficient.
Level 4
(Somewhat Weak)
The quality of risk management implementation for compliance risk is less adequate, there are significant weaknesses in various
Level Definition Rating aspects of risk management for compliance risk Examples of characteristics of Companies included in Level 4 (somewhat weak) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance) is less adequate and not aligned with overall strategic objectives and business strategy; b. there are significant weaknesses in the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for compliance risk, sources of compliance risk, and the level of compliance risk in the Company;
c. the risk management culture for compliance risk is less strong and has not been well internalized at every organizational level;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally less adequate, there are weaknesses in various assessment aspects that require immediate improvement; e. there are significant weaknesses in the risk management function for compliance risk that require immediate improvement; f. delegation of authority is weak, not controlled and not monitored well; g. management strategy for compliance risk is less aligned with the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance); h. there are significant weaknesses in policies, procedures, and limit setting for compliance risk;
i. the risk management process for compliance risk is less adequate in identifying, measuring, monitoring, and controlling compliance risk;
j. there are significant weaknesses in the management information system for compliance risk including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; k. human resources are less adequate in terms of quantity and quality in the risk management function for compliance risk;
l. the internal control system is less effective in supporting the implementation of risk management for compliance risk;
m. the implementation of independent review by the internal audit
Level Definition Rating unit and functions conducting independent review is less adequate, there are weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement; n. there are significant weaknesses based on the results of independent review that require immediate corrective action; and o. follow-up on independent review is less adequate.
Level 5
(Weak)
The quality of risk management implementation for compliance risk is inadequate, there are significant weaknesses in various aspects of risk management for compliance risk whose resolution actions are beyond the capability of management. Examples of characteristics of Companies included in Level 5 (weak) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance) is inadequate and there is no connection with overall strategic objectives and business strategy; b. the awareness and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for compliance risk, sources of compliance risk, and the level of compliance risk in the Company is very weak;
c. the risk management culture for compliance risk is not strong or does not exist at all;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, there are significant weaknesses in almost all assessment aspects and the actions and resolution are beyond the Company's capability; e. there are significant weaknesses in the risk management function for compliance risk that require fundamental improvement; f. delegation of authority is very weak or non-existent; g. management strategy for compliance risk is not aligned with the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance); h. there are very significant weaknesses in policies, procedures, and limit setting for compliance risk;
i. the risk management process for compliance risk is inadequate in identifying, measuring, monitoring, and controlling compliance risk;
j. there are fundamental weaknesses in the management information system for compliance risk;
Level Definition Rating k. human resources are inadequate in terms of quantity and quality in the risk management function for compliance risk;
l. the internal control system is ineffective in supporting the implementation of risk management for compliance risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is less or inadequate, there are weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require fundamental improvement; n. there are very significant weaknesses based on the results of independent review whose corrective actions o. follow-up on independent review is inadequate.
Table II.H.1: Parameters or Indicators for Assessing Inherent Risk for Reputational Risk
| Parameter or Indicator | Description |
|---|---|
| 1. Influence of reputation of managers, owners, and group | a. Credibility of managers, owners, and related companies.<br>b. Reputational events involving managers, owners, and related companies.<br><br>Credibility is assessed, among others, from negative news regarding managers, Company shareholders, and/or related companies with the Company.<br>Reputational events are assessed, among others, from negative events faced by the Company, such as bankruptcy petitions against the Company. |
| 2. Violation of business ethics | Violations of ethics are seen, among others, in:<br>a. financial information transparency; and<br>b. business cooperation with other stakeholders.<br><br>Example:<br>In product and service marketing, ethical violations can include providing misleading information to consumers. |
| 3. Product complexity and business cooperation | a. The number and level of consumer usage of the Company's complex products.<br>b. The number and materiality of the Company's cooperation with business partners.<br><br>Complex products and cooperation with business partners can be exposed to reputational risk in case of misunderstanding of product or service usage or negative reporting on business partners, among others in the marketing of insurance products and mutual funds. |
| 4. Frequency, materiality, and exposure of negative reporting | a. Frequency and materiality of negative reporting about the Company in 1 (one) year.<br>b. Type of media and scope of reporting.<br><br>The frequency, type of media, and materiality of negative reporting on the Company, including the Company's managers. |
| 5. Frequency and materiality of complaints from debtors or consumers | a. Frequency of customer complaints.<br>b. Materiality of customer complaints.<br><br>The frequency of customer complaints can be assessed through calculation as follows:<br>Number of consumer complaints in 1 (one) year<br>Number of customers at year-end position |
Table II.H.2: Guidelines for Determining the Level of Inherent Risk for Reputational Risk
Level 1
(Low)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from reputational risk is classified as very low during a certain period in the future. Examples of characteristics of Companies included in Level 1 (low) include the following:
a. generally, there is no negative reputational influence from managers, Company shareholders, and related companies, even it is expected that managers, Company shareholders, and related companies can provide a very positive influence on the Company's reputation; b. violations or potential violations of business ethics are very minimal (not significant), the Company has a reputation as a Company that highly upholds business ethics;
c. the Company's products are simple and easy for customers to understand;
d. the number and value of business cooperation conducted with business partners are not significant; e. the frequency, nature, and scope of negative reporting are not f. the frequency and substance of customer complaints are not material.
Level 2
(Low Medium)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from reputational risk is classified as low during a certain period in the future. Examples of characteristics of Companies included in Level 2 (low medium) include the following:
a. there is a negative reputational influence from managers, Company shareholders, and related companies but the scale of influence is small (not significant) and can be mitigated well; b. violations or potential violations of business ethics are not significant and the Company has a reputation as a Company that upholds business ethics;
c. the Company's products are not simple but relatively do not require special customer understanding;
d. the number and value of business cooperation conducted with business partners are not significant;
e. the frequency, nature, and scope of negative reporting are not f. the frequency and substance of customer complaints are not significant.
Level 3
(Medium)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from reputational risk is classified as quite high during a certain period in the future. Examples of characteristics of Companies included in Level 3 (medium) include the following:
a. there is a negative reputational influence from managers, Company shareholders, and related companies with a quite significant scale of influence but still controllable; b. violations or potential violations of business ethics occur but the scale of influence is quite significant and requires management attention;
c. the Company's products are quite complex so that at a certain level they require special customer understanding;
d. the number and value of business cooperation conducted with business partners are quite significant; e. the frequency, nature, and scope of negative reporting are quite f. the frequency and substance of complaints are quite material.
Level 4
(Medium High)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from reputational risk is classified as high during a certain period in the future. Examples of characteristics of Companies included in Level 4 (medium high) include the following:
a. there is a negative reputational influence from managers, Company shareholders, and related companies with a significant scale of influence that requires special management attention; b. violations or potential violations of business ethics occur with a significant scale of influence that requires special attention;
c. the Company's products are complex so that they require special customer understanding;
d. the number and value of business cooperation conducted with business partners are significant; e. the frequency, nature, and scope of negative reporting are f. the frequency and substance of customer complaints are material.
Level 5
(High)
Considering the business activities conducted by the Company, the likelihood of losses faced by the Company from reputational risk is classified as very high during a certain period in the future. Examples of characteristics of Companies included in Level 5 (high) include the following:
a. there is a negative reputational influence from managers, Company shareholders, and related companies with a very significant scale of influence that requires immediate follow-up and management; b. violations or potential violations of business ethics occur with a very significant scale of influence that requires immediate follow-up and management;
c. the Company's products are very complex and very much require special customer understanding;
d. the number and value of business cooperation conducted with business partners are very significant; e. the frequency, nature, and scope of negative reporting are very f. the frequency and substance of customer complaints are very material.
Table II.H.3: Guidelines for Determining the Quality of Risk Management Implementation for Reputational Risk
Level 1
(Strong)
The quality of risk management implementation for reputational risk is very adequate, there are minor weaknesses that are not significant so they can be ignored.
Examples of characteristics of Companies included in Level 1 (strong) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance) is very adequate and has aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have very good awareness and understanding regarding risk management for reputational risk, sources of reputational risk, and the level of reputational risk in the Company;
c. the risk management culture for reputational risk is very strong and has been internalized very well at all organizational levels;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is overall very adequate; e. the risk management function for reputational risk is independent, has clear tasks and responsibilities, and has run very well; f. delegation of authority is controlled and monitored periodically, and has run very well; g. management strategy for reputational risk is very aligned with the level of risk to be taken and risk tolerance; h. policies, procedures, and limit setting for reputational risk are very adequate and available for all areas of risk management for reputational risk, aligned with implementation, and well understood by employees;
i. the risk management process for reputational risk is very adequate in identifying, measuring, monitoring, and controlling reputational risk;
j. the management information system for reputational risk is very good so as to produce comprehensive and integrated reputational risk reports to the Board of Directors, Board of Commissioners, and/or DPS; k. human resources are very adequate in terms of quantity and quality in the risk management function for
Level Definition Rating reputational risk;
l. the internal control system is very effective in supporting the implementation of risk management for reputational risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS; n. generally, there are no significant weaknesses based on the results of independent review; and o. follow-up on independent review has been carried out very adequately.
Level 2
(Somewhat Strong)
The quality of risk management implementation for reputational risk is adequate despite some minor weaknesses that can be resolved in normal business activities.
Examples of characteristics of Companies included in Level 2 (somewhat strong) include the following:
a. the formulation of the level of risk to be taken (risk appetite) and risk tolerance (risk tolerance) is adequate and has aligned with overall strategic objectives and business strategy; b. the Board of Directors, Board of Commissioners, and/or DPS have good awareness and understanding regarding risk management for reputational risk, sources of reputational risk, and the level of reputational risk in the Company;
c. the risk management culture for reputational risk is strong and has been internalized well at all organizational levels;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequate, there are some weaknesses but not significant and can be repaired immediately; e. the risk management function for reputational risk has clear tasks and responsibilities and has run well, but there are minor weaknesses that can be resolved in normal business activities; f. delegation of authority is controlled and monitored periodically and has run well; g. management strategy for reputational risk aligns with the level of risk to be taken and risk tolerance; h. policies, procedures, and limit setting for reputational risk are adequate and available for all areas
Risk Rating Definition
Management risk level for reputational risk, aligned with implementation, and well understood by employees despite minor weaknesses;
i. the risk management process for reputational risk is adequate in identifying, measuring, monitoring, and controlling reputational risk;
j. the management information system for reputational risk is good, including reporting of reputational risk to the Board of Directors, Board of Commissioners, and/or DPS, but there are minor weaknesses that can be easily corrected;
k. human resources are adequate both in quantity and quality in the risk management function for reputational risk;
l. the internal control system is effective in supporting the implementation of risk management for reputational risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent reviews is adequate in terms of methodology, frequency, and reporting to the Board of Directors, Board of Commissioners, and/or DPS;
n. there are weaknesses but not significant based on the results of independent review; and
o. follow-up on independent review has been adequately implemented.
Rating 3
(Adequate)
The quality of risk management implementation for reputational risk is adequately sufficient. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of characteristics of Companies included in Rating 3 (adequate) include the following:
a. formulation of the level of risk to be taken (risk appetite) and risk tolerance is adequately sufficient but not always aligned with overall strategic objectives and business strategy;
b. the Board of Directors, Board of Commissioners, and/or DPS have adequate awareness and understanding regarding risk management for reputational risk, sources of reputational risk, and the level of reputational risk in the Company;
c. the culture of risk management for reputational risk is sufficiently strong and has been internalized sufficiently well but is not always implemented consistently;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally adequately sufficient, but there are weaknesses in some aspects of assessment that need
Risk Rating Definition management attention;
e. the risk management function for reputational risk is fairly good, but there are several weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;
f. delegation of authority is fairly good, but control and monitoring are not always implemented well;
g. management strategy for reputational risk is fairly aligned with the level of risk to be taken and risk tolerance;
h. policies, procedures, and limit setting for reputational risk are adequately sufficient but not always consistent with implementation;
i. the risk management process for reputational risk is adequately sufficient in identifying, measuring, monitoring, and controlling reputational risk;
j. the management information system for reputational risk meets minimum expectations but has several weaknesses including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;
k. human resources are adequately sufficient both in quantity and quality in the risk management function for reputational risk;
l. the internal control system is sufficiently effective in supporting the implementation of risk management for reputational risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent reviews is adequately sufficient, but there are several weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require management attention;
n. there are weaknesses that are quite significant based on the results of independent review that require management attention; and
o. follow-up on independent review has been implemented adequately enough.
Rating 4
(Quite Weak)
The quality of risk management implementation for reputational risk is less adequate, there are significant weaknesses in various aspects of risk management for reputational risk which Examples of characteristics of Companies included in
Risk Rating Definition
Rating 4 (quite weak) include the following:
a. formulation of the level of risk to be taken (risk appetite) and risk tolerance is less adequate and not aligned with strategic objectives and overall business strategy;
b. there are significant weaknesses in the awareness (awareness) and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for reputational risk, sources of reputational risk, and the level of reputational risk in the Company;
c. the culture of risk management for reputational risk is weak and has not been well internalized at every level of the organization;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is generally less adequate, there are weaknesses in various aspects of assessment that require immediate improvement;
e. there are significant weaknesses in the risk management function for reputational risk that require immediate improvement;
f. delegation of authority is weak, not controlled and not monitored well;
g. management strategy for reputational risk is less aligned with the level of risk to be taken and risk tolerance;
h. there are significant weaknesses in policies, procedures, and limit setting for reputational risk;
i. the risk management process for reputational risk is less adequate in identifying, measuring, monitoring, and controlling reputational risk;
j. there are significant weaknesses in the management information system for reputational risk including reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement;
k. human resources are less adequate in terms of quantity and quality in the risk management function for reputational risk;
l. the internal control system is less effective in supporting the implementation of risk management for reputational risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent reviews is less adequate, there are weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require immediate improvement
Risk Rating Definition improvement;
n. there are significant weaknesses based on the results of independent review that require immediate corrective action; and
o. follow-up on independent review is inadequate.
Rating 5
(Weak)
The quality of risk management implementation for reputational risk is inadequate, there are significant weaknesses in various aspects of risk management for reputational risk whose resolution actions are beyond the capability of management. Examples of characteristics of Companies included in Rating 5 (weak) include the following:
a. formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and there is no connection with strategic objectives and overall business strategy;
b. awareness (awareness) and understanding of the Board of Directors, Board of Commissioners, and/or DPS regarding risk management for reputational risk, sources of reputational risk, and the level of reputational risk in the Company are very weak;
c. the culture of risk management for reputational risk is not strong or does not exist at all;
d. the implementation of duties by the Board of Directors, Board of Commissioners, and/or DPS is inadequate, there are significant weaknesses in almost all aspects of assessment and resolution actions are beyond the capability of the Company;
e. there are significant weaknesses in the risk management function for reputational risk that require fundamental improvement;
f. delegation of authority is very weak or non-existent;
g. management strategy for reputational risk is not aligned with the level of risk to be taken and risk tolerance;
h. there are very significant weaknesses in policies, procedures, and limit setting for reputational risk;
i. the risk management process for reputational risk is inadequate in identifying, measuring, monitoring, and controlling reputational risk;
j. there are fundamental weaknesses in the management information system for reputational risk;
k. human resources are inadequate in terms of quantity and quality in the risk management function for reputational risk;
l. the internal control system is ineffective in
Risk Rating Definition supporting the implementation of risk management for reputational risk;
m. the implementation of independent review by the internal audit unit and functions conducting independent reviews is lacking or inadequate, there are weaknesses in methodology, frequency, and/or reporting to the Board of Directors, Board of Commissioners, and/or DPS that require fundamental improvement;
n. there are very significant weaknesses based on the results of independent review whose corrective actions
o. follow-up on independent review is inadequate
Table II.I: Guidelines for Determining Risk Levels for Each Type of Risk
Analysis
Risk Rating:
Final conclusion regarding the Company's risk level which includes inherent risk level and the quality of risk management implementation so as to describe the Company's risk level. Inherent Risk:
Description of inherent risk assessment based on analysis of assessment factors using both quantitative indicators and qualitative indicators so as to describe the Company's inherent risk level. Quality of Risk Management Implementation:
Analysis of the quality of risk management implementation consists of risk governance, risk management framework, risk management process, human resources, and management information systems, as well as risk control.
Table II.J: Format for Determining Risk Profile Ratings
Type of Risk
Inherent Risk Level
Level of Quality of Risk Management Implementation Risk Level Strategic Risk Operational Risk Credit Risk Market Risk Liquidity Risk Legal Risk Compliance Risk Reputational Risk Composite Rating Risk Profile Rating
Table II.K: Guidelines for Determining Risk Profile Factor Ratings
Rating Definition
Rating 1 A Company's risk profile included in this rating generally has characteristics as follows:
a. considering the business activities conducted by the Company, the potential losses faced by the Company from composite inherent risk are classified as very low during a certain period in the future; and
b. the quality of risk management implementation is very adequate in the composite, if there are minor weaknesses, those weaknesses can be ignored.
Rating 2 A Company's risk profile included in this rating generally has characteristics as follows:
a. considering the business activities conducted by the Company, the potential losses faced by the Company from composite inherent risk are classified as low during a certain period in the future; and
b. the quality of risk management implementation is adequate in the composite, if there are minor weaknesses, those weaknesses need to receive management attention.
Rating 3 A Company's risk profile included in this rating generally has characteristics as follows:
a. considering the business activities conducted by the Company, the potential losses faced by the Company from composite inherent risk are classified as moderately high during a certain period in the future; and
b. the quality of risk management implementation is moderately adequate in the composite, although minimum requirements are met, there are some weaknesses that require management attention and improvement.
Rating 4 A Company's risk profile included in this rating generally has characteristics as follows:
a. considering the business activities conducted by the Company, the potential losses faced by the Company from composite inherent risk are classified as high during a certain period in the future; and
This copy is consistent with the original
Director of Law 1
Legal Department signed
Mufli Asmawidjaja
Rating Definition
b. the quality of risk management implementation is less adequate in the composite, there are significant weaknesses in various aspects of risk management that require immediate corrective action.
Rating 5 A Company's risk profile included in this rating generally has characteristics as follows:
a. considering the business activities conducted by the Company, the potential losses faced by the Company from composite inherent risk are classified as very high during a certain period in the future; and
b. the quality of risk management implementation is inadequate in the composite, there are significant weaknesses in various aspects of risk management whose resolution actions are beyond the capability of management.
Established in Jakarta on July 1, 2020
CHIEF EXECUTIVE OF THE INSPECTORATE FOR INSURANCE, PENSION FUNDS, FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed RISWINANDI
APPENDIX III
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 11 /SEOJK.05/2020 CONCERNING HEALTH LEVEL OF FINANCING COMPANIES AND SHARIAH FINANCING COMPANIES
ASSESSMENT OF PROFITABILITY FACTORS
HEALTH LEVEL OF FINANCING COMPANIES AND
SHARIAH FINANCING COMPANIES
Table III.A : Parameters or Indicators for Assessing Profitability Factors
Table III.B : Guidelines for Determining Profitability Factor Ratings 10
Instructions for Filling Out:
The parameters or indicators for assessing profitability factors in Appendix III are minimum standards that must be used in assessing profitability factors.
Companies may add other parameters or indicators according to the characteristics and complexity of the Company's business.
Assessment is done per position and period for the last 12 (twelve) months for parameters or indicators that are quantitative.
For certain parameters or indicators, assessment can be done by considering trends for at least a period of 3 (three) years.
In assessing the Company's profitability factor on a consolidated basis, parameters or indicators for assessing the Company's profitability factor on an individual basis can be used, adjusted to the scale, characteristics, and complexity of the Child Company's business.
Table III.A: Parameters or Indicators for Assessing Profitability Factors
Parameter or Indicator Description
Parameter or Indicator Description b. Return on equity (RoE). Net Profit After Tax Average Total Equity
c. Operating expenses to operating income ratio (BOPO).
Operating Expenses
Operating Income of the Company
Details of operating income and operating expense accounts in the calculation of the operating expense to operating income ratio refer to Financial Services Authority Circular Letter regarding monthly reports of Financing Companies and Shariah Financing Companies.
d. Net interest margin (NIM). For Financing Companies:
Net Interest Income
Average Financing Receivables
For Shariah Financing Companies:
Net Financing Income
Average Productive Assets
e. Net operating margin. For Financing Companies:
Interest Income - Operating Expenses
Average Financing Receivables
For Shariah Financing Companies:
Financing Income - Operating Expenses
Average Productive Assets
f. Equity ratio to paid-in capital. Equity
Paid-in Capital
g. Performance of actual profit components (profitability) against budget projections.
Actual Profit Component Performance (Profitability) Budget Projection Performance in profit components (profitability) is a comparison between realization and budget projections for income statement accounts, including: operating income, operating expenses, non-operating income, non-operating expenses, and net profit.
b. Ratio of operating income other than interest income (net) to average total assets.
Operating Income other than Interest Income (net) Average Total Assets
c. Ratio of overhead expenses to average total assets.
Overhead Expenses
Average Total Assets
Parameter or Indicator Description
Overhead expenses are all operating expenses that are not interest expenses.
d. Ratio of provisioning expenses to average total assets.
Provisioning Expenses
Average Total Assets
e. Noncore earnings component net to average total assets.
Noncore Earnings Component Net
Average Total Assets
b. Future profitability projections. Future profitability projections are an analysis of projections of profitability components (operating income, operating expenses, net profit) over a period of 5 (five) years ahead accompanied by considerations.
Profitability
Management
The Company's ability to manage profitability.
The Company's ability to manage profitability is an analysis of among other things the ability to:
a. generate income; and b. manage expenses, sustainably.
Implementation
of social functions by the Company, for
Shariah
Financing
Companies
The Company's role in implementing social functions.
For Shariah Financing Companies, to assess the Company's role in implementing its social functions through the receipt and distribution of zakat funds and the receipt and distribution of charity funds.
Table III.B: Guidelines for Determining Profitability Factor Ratings
Rating Definition
Rating 1 Profitability is very adequate, profit exceeds targets, and supports capital growth.
Companies included in Rating 1 meet all or most of the example characteristics as follows:
a. the Company's performance in generating profit (profitability) is very adequate; b. the main source of profitability originating from financing business activities is very dominant;
c. the ability of profit to increase capital and profit prospects in the future are very high; and
d. the Company's ability to manage profitability is very adequate.
Rating 2 Profitability is adequate, profit exceeds targets, and supports capital growth.
Companies included in Rating 2 meet all or most of the example characteristics as follows:
a. the Company's performance in generating profit or profitability is adequate; b. the main source of profitability originating from financing business activities is dominant;
c. the ability of profit to increase capital and profit prospects in the future are high; and
d. the Company's ability to manage profitability is adequate.
Rating 3 Profitability is moderately adequate, profit meets targets, although there is pressure on profit performance that could cause a decrease in profit but still sufficiently supports the Company's capital growth. Companies included in Rating 3 meet all or most of the example characteristics as follows:
a. the Company's performance in generating profit or profitability is moderately adequate; b. the main source of profitability originates from financing business activities moderately dominant
However, there is a considerable influence from activities other than financing and Sharia financing business;
c. the ability to generate profit in increasing capital and the profit outlook in the future is quite good; and
d. the Company's ability to manage profitability is quite adequate.
Profitability is inadequate, profit does not meet targets, and it is estimated that this condition will remain in the future, thus providing insufficient support for capital growth and the continuity of the Company's business.
Companies included in Rating 4 meet all or most of the following example characteristics:
a. the Company's performance in generating profit or profitability is inadequate or the Company incurs losses;
b. the main source of profitability comes from activities other than financing;
c. the ability of profit to increase capital and the profit outlook in the future is poor or may even have a negative impact on the Company's capital; and
d. the Company's ability to manage profitability is inadequate.
Profitability is inadequate, profit does not meet targets and is unreliable, and immediate improvement in profit performance is required to ensure the continuity of the Company's business.
Companies included in Rating 5 meet all or most of the following example characteristics:
a. the Company incurs significant losses;
b. the main source of profitability comes from activities other than financing;
c. the Company's losses significantly affect capital; and
d. the Company's ability to manage profitability is inadequate.
This copy is consistent with the original
Legal Director 1
Legal Department
signed
Mufli Asmawidjaja
Determined in Jakarta on July 1, 2020
EXECUTIVE HEAD OF INSURANCE, PENSION FUND,
FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS SUPERVISOR FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA,
signed
RISWINANDI
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 11 /SEOJK.05/2020
CONCERNING
ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES AND SHARIA FINANCING COMPANIES
OF FINANCING COMPANIES AND SHARIA FINANCING COMPANIES
Table IV.A: Parameters or Indicators for Assessing the Capital Factor
Table IV.B: Guidelines for Determining the Capital Factor Rating
| Parameter or Indicator | Description |
|---|---|
| 1. Capital Adequacy | a. Capital Ratio<br>Adjusted Capital / Adjusted Assets<br><br>Description:<br>1) Adjusted Capital is the sum of the following capital components:<br>a) for Companies in the form of a Limited Liability Company (Perseroan Terbatas), the sum of:<br>(1) Adjusted Equity consisting of:<br>(a) Paid-in capital;<br>(b) Additional paid-in capital, which is the sum of:<br>i. Share premium/discount;<br>ii. Equity issuance costs; and<br>iii. Others in accordance with financial accounting standards principles;<br>(c) Differences in transaction values of entities under common control;<br>(d) Retained earnings/losses;<br>(e) 50% (fifty percent) of current year profit/loss after tax;<br>(f) Treasury stock; and<br>(g) Other equity components, which is the sum of:<br>i. Changes in revaluation surplus;<br>ii. Exchange differences due to translating financial statements into foreign currency;<br>iii. Gains and losses from measuring available-for-sale financial assets;<br>iv. Effective portion of gains and losses of hedging instruments in cash flow hedges; and<br>v. Other equity components in accordance with financial accounting standards principles,<br>considering reduction factors such as:<br>(a) Deferred tax calculations;<br>(b) Goodwill;<br>(c) Other intangible assets; and<br>(d) All equity investments in subsidiary companies;<br>(2) Subordinated loans (qardh) up to a maximum of 50% (fifty percent) of paid-in capital, meeting the following criteria:<br>(a) with a minimum term of 5 (five) years;<br>(b) in the event of liquidation, the claim right applies last among all existing loans; and<br>(c) stipulated in a notarial deed agreement between the Financing Company and the lender.<br>b) for Companies in the form of a Cooperative, the sum of basic deposits, mandatory deposits, reserve funds, grants, and undistributed surplus.<br><br>2) Adjusted Assets are the Company's assets multiplied by the asset risk weights as follows:<br><br>For Financing Companies:<br>a) Financing assets<br><br> |
| --- | --- |
| (1) | (2) |
| 1. Investment Financing in the Current and Special Attention Categories | |
| a. Financial Leasing | 25% |
| b. Sale and Leaseback | 25% |
| c. Factoring with Guarantee from the Seller of Receivables | 25% |
| d. Factoring without Guarantee from the Seller of Receivables | 25% |
| e. Installment Purchase | 25% |
| f. Project Financing | 10% |
| g. Infrastructure Financing | 10% |
| 2. Working Capital Financing in the Current and Special Attention Categories | |
| a. Sale and Leaseback | 25% |
| b. Factoring with Guarantee from the Seller of Receivables | 25% |
| c. Factoring without Guarantee from the Seller of Receivables | 25% |
| d. Business Capital Facilities | 25% |
| 3. Multi-Purpose Financing in the Current and Special Attention Categories | |
| a. Financial Leasing | 37.5% |
| b. Installment Purchase | 37.5% |
| c. Fund Facilities | 37.5% |
| 4. Other Financing in the Current and Special Attention Categories | 50% |
| 5. Overdue Financing | |
| a. Substandard | 50% |
| b. Doubtful | 62.5% |
| c. Loss | 75% |
b) Non-financing assets
| No. Component | Risk Weight | |
|---|---|---|
| (1) | (2) | |
| 1. Cash and Cash Equivalents | 0% | |
| 2. Short-Term Investments in Securities | ||
| a. Securities Issued by the Government or Bank Indonesia | 0% | |
| b. Securities Issued by Parties Other Than the Government or Bank Indonesia | 75% | |
| 3. Equity Investments | ||
| a. Banks | 50% | |
| b. Other Financial Service Companies | 75% | |
| c. Other Companies | 100% | |
| 4. Other Assets | 100% |
For Sharia Financing Companies: a) Sharia financing assets
| No. Component | Asset Risk Weight With Sharia Guarantee | Asset Risk Weight Without Sharia Guarantee |
|---|---|---|
| (1) | (2) | (3) |
| 1. Sales and Purchase Financing in the Current and Special Attention Categories for Productive Sector Purposes)* | ||
| a. Murabahah | 15% | 30% |
| b. Salam | 15% | 30% |
| c. Istishna | 15% | 30% |
| d. Other Sales and Purchase Financing | 15% | 30% |
| 2. Sales and Purchase Financing in the Current and Special Attention Categories for Consumer Purposes | ||
| a. Murabahah | 25% | 50% |
| b. Salam | 25% | 50% |
| c. Istishna | 25% | 50% |
| d. Other Sales and Purchase Financing | 25% | 50% |
| 3. Investment Financing in the Current and Special Attention Categories | ||
| a. Mudharabah | 15% | 30% |
| b. Musyarakah | 15% | 30% |
| c. Mudharabah Musyarakah | 15% | 30% |
| d. Musyarakah Mutanaqishoh | 15% | 30% |
| e. Other Investment Financing | 15% | 30% |
| 4. Service Financing in the Current and Special Attention Categories | ||
| a. IMBT | 15% | 30% |
| b. Ijarah | 25% | 50% |
| c. Qardh | 25% | 50% |
| d. Other Service Financing | 25% | 50% |
| 5. Other Financing in the Current and Special Attention Categories | 25% | 50% |
| 6. Overdue Financing | ||
| a. Substandard | 50% | 100% |
| b. Doubtful | 62.5% | 125% |
| c. Loss | 75% | 150% |
*) The productive sector refers to activities aimed at producing goods or services that add value and increase income, proven by supporting documents.
b) Non-Sharia financing assets
| No. Component | Risk Weight | |
|---|---|---|
| (1) | (3) | |
| 1. Cash and Cash Equivalents | 0% | |
| 2. Short-Term Investments in Securities | 75% | |
| 3. Equity Investments | ||
| a. Banks | 50% | |
| b. Other Financial Service Companies | 75% | |
| c. Other Companies | 100% | |
| 4. Other Assets | 100% |
b. Ratio of Problem Financing Receivables to Paid-in Capital.
c. Ratio of Low-Quality Receivables to Paid-in Capital.
d. Company's Capital Adequacy to Anticipate Potential Losses According to Risk Profile. The assessment of the Company's capital adequacy to anticipate potential losses according to the risk profile is conducted by considering among others:
The assessment of capital adequacy by anticipating potential losses according to the risk profile can be conducted through stress testing analysis.
2. Capital Management
a. Company's Capital Management
This includes the understanding of the Board of Directors and Board of Commissioners, capital management policies and procedures, capital planning, capital adequacy assessment, and independent review.
b. Ability to Access Capital as Seen from Internal and External Sources
| Rating | Definition | ||||
|---|---|---|---|---|---|
| Rating 1 | The Company has very adequate capital quality and adequacy relative to the risk profile, accompanied by very strong capital management in accordance with the Company's characteristics, business scale, and business complexity.<br><br>Companies included in Rating 1 meet all or most of the following example characteristics:<br>a. The Company has a very adequate level of capital, is very capable of anticipating all risks faced, and supports the Company's business expansion in the future;<br>b. the quality of capital components is generally very good, permanent, and able to absorb losses;<br>c. The Company has conducted stress testing with results that can cover all risks faced very adequately;<br>d. The Company has very good capital management and/or has a very good capital adequacy assessment process in accordance with business strategy and objectives as well as business complexity and Company scale; and<br>e. The Company has very good access to capital sources and/or has capital support from the business group or parent company.<br><br>Rating 2 | The Company has adequate capital quality and adequacy relative to the risk profile, accompanied by strong management in accordance with the Company's characteristics, business scale, and business complexity.<br><br>Companies included in Rating 2 meet all or most of the following example characteristics:<br>a. The Company has an adequate level of capital and can anticipate almost all risks faced;<br>b. the quality of capital components is generally good, permanent, and able to absorb losses;<br>c. The Company has conducted stress testing with results that can cover all risks faced adequately;<br>d. The Company has good capital management and/or has a good capital adequacy assessment process in accordance with business strategy and objectives as well as business complexity and Company scale; and<br>e. The Company has good access to capital sources and/or there is capital support from the business group or parent company.<br><br>Rating 3 | The Company has fairly adequate capital quality and adequacy relative to the risk profile, accompanied by fairly strong capital management in accordance with the Company's characteristics, business scale, and business complexity.<br><br>Companies included in Rating 3 meet all or most of the following example characteristics:<br>a. The Company has a fairly adequate level of capital and is fairly capable of anticipating risks faced;<br>b. the quality of capital components is generally fairly good, fairly permanent, and fairly able to absorb losses;<br>c. The Company has conducted stress testing with results that can cover all risks faced fairly adequately;<br>d. The Company has fairly good capital management and/or has a fairly good capital adequacy assessment process in accordance with business strategy and objectives as well as business complexity and Company scale; and<br>e. The Company has fairly good access to capital sources, but support from | ||
| the business group or parent company is not explicit.<br><br>Rating 4 | The Company has inadequate capital quality and adequacy relative to the risk profile, accompanied by weak capital management compared to the Company's characteristics, business scale, and business complexity.<br><br>Companies included in Rating 4 meet all or most of the following example characteristics:<br>a. The Company has an inadequate level of capital and cannot anticipate all risks faced;<br>b. the quality of capital components is generally poor, less permanent, and less able to absorb losses;<br>c. The Company has conducted stress testing with results that are less able to cover all risks faced;<br>d. The Company has poor capital management and/or has a poor capital adequacy assessment process in accordance with business strategy and objectives as well as business complexity and Company scale; and<br>e. The Company is less able to access capital sources, and there is no support from the business group or parent company.<br><br>Rating 5 | The Company has inadequate capital quality and adequacy relative to the risk profile, accompanied by very weak capital management compared to the Company's characteristics, business scale, and business complexity.<br><br>Companies included in Rating 5 meet all or most of the following example characteristics:<br>a. The Company has an inadequate level of capital, so the Company must add capital to anticipate all risks faced under normal conditions and crisis conditions;<br>b. the quality of capital instruments is generally poor, not permanent, and unable to absorb losses;<br>c. The Company has conducted stress testing with results that are unable to cover all risks faced;<br>d. The Company has poor capital management and/or has a poor capital adequacy assessment process in accordance with business strategy and objectives as well as business complexity and Company scale; and<br>e. The Company is unable to access capital sources and there is no support from the business group or parent company. |
This copy is consistent with the original
Legal Director 1
Legal Department
signed
Mufli Asmawidjaja
Determined in Jakarta on July 1, 2020
EXECUTIVE HEAD OF INSURANCE, PENSION FUND,
FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS SUPERVISOR FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA,
signed
RISWINANDI
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 11 /SEOJK.05/2020
CONCERNING
ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES AND SHARIA FINANCING COMPANIES
of Financing Companies and Sharia Financing Companies
| Rating | Explanation |
|---|---|
| PK-1 | Reflects a Company condition that is generally very healthy, thus assessed as very capable of facing significant negative influences from changes in business conditions and other external factors, reflected in assessment factor ratings, such as the implementation of good corporate governance, risk profile, profitability, and capital that are generally very good. In case of weaknesses, they are generally not significant. |
| PK-2 | Reflects a Company condition that is generally healthy, thus assessed as capable of facing significant negative influences from changes in business conditions and other external factors, reflected in assessment factor ratings, such as the implementation of good corporate governance, risk profile, profitability, and capital that are generally good. In case of weaknesses, they are generally less significant. |
| PK-3 | Reflects a Company condition that is generally fairly healthy, thus assessed as fairly capable of facing significant negative influences from changes in business conditions and other external factors, reflected in assessment factor ratings, such as the implementation of good corporate governance, risk profile, profitability, and capital that are generally fairly good. In case of weaknesses, they are generally fairly significant and if not successfully addressed by management, may disrupt the continuity of the Company's business. |
| PK-4 | Reflects a Company condition that is generally less healthy, thus assessed as less capable of facing significant negative influences from changes in business conditions and other external factors, reflected in assessment factor ratings, such as the implementation of good corporate governance, risk profile, profitability, and capital that are generally less good. There are weaknesses that are generally significant and cannot be addressed well by management, disrupting the continuity of the Company's business. |
| PK-5 | Reflects a Company condition that is generally unhealthy, thus assessed as unable to face significant negative influences from changes in business conditions and other external factors, reflected in assessment factor ratings, such as the implementation of good corporate governance, risk profile, profitability, and capital that are generally poor. There are weaknesses that are generally very significant, so to address them, financial support from shareholders or funds from other parties is required to strengthen the Company's financial condition. |
*) Applicable for individual and consolidated Health Level assessments of Companies.
Determined in Jakarta on July 1, 2020
EXECUTIVE HEAD OF INSURANCE, PENSION FUND,
FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS SUPERVISOR FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA,
signed
RISWINANDI
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 11 /SEOJK.05/2020
CONCERNING
ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES AND SHARIA FINANCING COMPANIES
FOR ASSESSMENT OF THE HEALTH LEVEL OF FINANCING COMPANIES, SHARIA FINANCING COMPANIES, AND UUS
Company Name : .................................................
Report Letter Number : .................................................
Report Letter Date : .................................................
Report Responsible Person:
Name : .................................................
Position : .................................................
Telephone : .................................................
Electronic mail (e-mail) : .................................................
| No. Assessment Factor | Rating Individual | Rating Consolidated*) |
|---|---|---|
| 1. Good Corporate Governance | ||
| 2. Risk Profile | ||
| 3. Profitability | ||
| 4. Capital | ||
| Company Health Level Rating |
*) In the event the Company has a Subsidiary Company that is consolidated.
Analysis regarding the Company's overall condition is reflected in the four health level assessment factors as follows:
In the event the Company has a Subsidiary Company that is consolidated, the Company considers:
a. the significance or materiality of the Subsidiary Company's share to the Company on a consolidated basis; and b. Subsidiary Company issues regarding good corporate governance, risk profile, profitability, and capital that have a significant impact on the Company on a consolidated basis.
Date : Date :
Prepared by: Approved by:
| Good Corporate Governance Rating | Individual | Consolidated |
|---|---|---|
| Analysis |
Description regarding the conclusion of the Company's good corporate governance performance, considering the good corporate governance assessment factors comprehensively and structurally, covering both structure, process, and outcome of good corporate governance. In the event the Company has a Subsidiary Company that is consolidated, the Company considers:
a. the significance or materiality of the Subsidiary Company's share to the Company on a consolidated basis; and b. Subsidiary Company issues regarding good corporate governance, risk profile, profitability, and capital that have a significant impact on the Company on a consolidated basis.
C. Assessment of Risk Profile Factors for Companies and Sharia Financing Companies
C.1 Assessment of Risk Profile Factors for Companies
Risk Profile
Individual Consolidated
Risk Rating
Inherent Risk
Risk Management Implementation Quality Rating
Risk Level Rating
Risk Rating
Inherent Risk
Risk Management Implementation Quality Rating
Risk Level Rating
Strategic Risk
Operational Risk
Credit Risk
Market Risk
Liquidity Risk
Legal Risk
Compliance Risk
Reputational Risk
Composite Rating
Risk Profile Rating
Risk Profile Rating
Analysis
The description regarding the overall risk profile conclusion of the Company includes an assessment of inherent risk and the quality of Risk Management implementation, with a focus of analysis on significant risk exposures in the Company. In the event that the Company has Consolidated Subsidiaries, the Company takes into account:
a. the significance or materiality of the Subsidiary's share to the Company on a consolidated basis; and b. issues of the Subsidiary regarding good corporate governance, risk profile, profitability, and capital that have a significant impact on the Company on a consolidated basis.
C.2 Assessment of Risk Profile Factors for Sharia Financing Companies (UUS)
Risk Profile
UUS
Inherent Risk Rating
Risk Management Implementation Quality Rating
Risk Level Rating
Strategic Risk
Operational Risk
Credit Risk
Market Risk
Liquidity Risk
Legal Risk
Compliance Risk
Reputational Risk
Composite Rating
Risk Profile Rating
Analysis
The description regarding the overall risk profile conclusion of the UUS includes an assessment of inherent risk and the quality of Risk Management implementation, with a focus of analysis on significant risk exposures in the UUS.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
D. Assessment of Profitability Factors
Profitability Rating Individual Consolidated
Analysis
The final conclusion regarding the Company's profitability performance by considering profitability assessment factors. In the event that the Company has Consolidated Subsidiaries, the Company considers the impact of the Subsidiary's profitability performance on the Company's overall profitability by considering the significance and materiality of the Subsidiary.
E. Assessment of Capital Adequacy Factors
Capital Adequacy Rating Individual Consolidated Analysis
The final conclusion regarding the Company's capital adequacy performance by considering capital adequacy assessment factors. In the event that the Company has Consolidated Subsidiaries, the Company considers the impact of the Subsidiary's capital adequacy performance on the Company's capital adequacy, overall, by considering the significance and materiality of the Subsidiary.
Established in Jakarta on July 1, 2020
EXECUTIVE HEAD OF SUPERVISOR
OF INSURANCE, PENSION FUNDS,
FINANCING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
RISWINANDI
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.