2017-03-17 | 14/SEOJK.03/2017Added · Updated
This Circular implements the Risk Based Bank Rating (RBBR) approach for the self-assessment of the health level of conventional commercial banks, covering both individual and consolidated scopes. It mandates the evaluation of four factors: risk profile, governance, earnings, and capital, utilizing specific inherent risk categories and management risk quality metrics. The document establishes general principles such as risk orientation and proportionality, and details the mechanisms for rating inherent risks, management risk application quality, and composite risk levels to determine the bank's health rating.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
The Board of Directors of Conventional Commercial Banks
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 14 /SEOJK.03/2017
CONCERNING
ASSESSMENT OF THE HEALTH LEVEL OF COMMERCIAL BANKS
In connection with the implementation of Financial Services Authority Regulation Number 4/POJK.03/2016 concerning the Assessment of the Health Level of Commercial Banks (State Gazette of the Republic of Indonesia Year 2016 Number 16, Supplement to the State Gazette Number 5840), Financial Services Authority Regulation Number 18/POJK.03/2016 concerning the Implementation of Risk Management for Commercial Banks (State Gazette of the Republic of Indonesia Year 2016 Number 53, Supplement to the State Gazette Number 5861), and provisions regarding the implementation of consolidated risk management for banks that control subsidiaries, among others, it is stipulated that Banks are required to conduct a self-assessment of the Bank's Health Level using the Risk Based Bank Rating (RBBR) approach, both individually and on a consolidated basis. The scope of assessment includes risk profile factors, Governance, earnings, and capital to produce a composite Health Level rating for the Bank.
Therefore, it is necessary to regulate implementation provisions regarding the Assessment of the Health Level of Commercial Banks in a Financial Services Authority Circular Letter as follows:
I. GENERAL PROVISIONS
The global financial crisis that occurred in recent years has provided valuable lessons that innovation in banking products and activities not accompanied by the implementation of adequate Risk Management can cause various fundamental problems for Banks and the financial system as a whole.
Based on the experience from the global financial crisis, Banks need to increase the effectiveness of the implementation of Risk Management and Governance. The increase in the effectiveness of the implementation of Risk Management and Governance aims to enable Banks to identify problems more early, take appropriate and faster corrective actions, and implement better Governance and Risk Management so that Banks are more resilient in facing crises.
The Health Level of the Bank, Bank management, and the continuity of the Bank's business are the full responsibility of the Bank's management. Therefore, the Bank maintains and improves the Bank's Health Level by applying the principle of prudence and Risk Management in carrying out business activities, including conducting periodic self-assessments of the Bank's Health Level and taking effective corrective steps. On the other hand, the Financial Services Authority evaluates, assesses the Health Level of the Bank, and takes necessary supervisory actions in order to maintain financial system stability.
II. GENERAL PRINCIPLES OF ASSESSMENT OF THE HEALTH LEVEL OF COMMERCIAL BANKS
Bank Management needs to pay attention to general principles as a foundation in conducting assessments of the Health Level of the Bank as follows:
Risk-Oriented
The assessment of the Bank's Health Level is based on the Bank's Risk and the impact it has on the Bank's overall performance. This is done by identifying internal and external factors that can increase Risk or affect the Bank's financial performance currently and in the future. Thus, the Bank is expected to be able to detect the root causes of the Bank's problems more early and take effective and efficient preventive and corrective steps.
Proportionality
The use of parameters or indicators in each factor of the assessment of the Bank's Health Level is done by considering the characteristics and complexity of the Bank's business. The parameters or indicators for assessing the Bank's Health Level in this Financial Services Authority Circular Letter are minimum standards that must be used in assessing the Bank's Health Level. In addition, the Bank may use additional parameters or indicators according to the characteristics and complexity of the business in assessing the Bank's Health Level so that it can reflect the Bank's condition better.
Materiality and Significance
The Bank needs to pay attention to the materiality and significance of the factors for assessing the Bank's Health Level, namely risk profile, Governance, earnings, and capital, as well as the significance of parameters or indicators for assessment in each factor in concluding assessment results and establishing factor ratings. The determination of materiality and significance is based on analysis supported by adequate data and information regarding Risk and the Bank's financial performance.
Comprehensive and Structured
The assessment process is conducted thoroughly and systematically and is focused on the Bank's main problems. Analysis is conducted in an integrated manner, by considering the interrelationships between Risks and between factors for assessing the Bank's Health Level and consolidated Subsidiary Companies. Analysis must be supported by key facts and relevant ratios to show the level, trend, and level of problems faced by the Bank.
III. MECHANISM FOR ASSESSMENT OF THE HEALTH LEVEL OF THE BANK
In accordance with the Financial Services Authority Regulations regarding the Assessment of the Health Level of Commercial Banks, the Bank conducts an assessment of the Bank's Health Level using the Risk-Based approach or RBBR. The assessment of the Bank's Health Level is conducted against the Bank both individually and on a consolidated basis, with the following mechanism:
a. Risk Profile Assessment
The assessment of the risk profile factor is an assessment of Inherent Risk and the quality of the implementation of Risk Management in the Bank's operational activities.
The Risks assessed consist of 8 (eight) types of Risk, namely Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Reputational Risk, Strategic Risk, and Compliance Risk.
In assessing the risk profile, the Bank also pays attention to the scope of the implementation of Risk Management as regulated in Financial Services Authority provisions regarding the Implementation of Risk Management for Commercial Banks.
The characteristics of the Bank's Inherent Risk are determined by internal and external factors, among others: business strategy, business characteristics, complexity of the Bank's products and activities, banking industry conditions, and macroeconomic conditions.
Assessment of Inherent Risk is conducted by considering parameters or indicators that are quantitative or qualitative.
The determination of the level of Inherent Risk for each type of Risk refers to the general principles of assessing the Bank's Health Level. The determination of the level of Inherent Risk for each type of Risk is categorized into Rating 1 (low), Rating 2 (low to moderate), Rating 3 (moderate), Rating 4 (moderate to high), and Rating 5 (high).
There are several minimum parameters or indicators that must be used as a reference by the Bank in assessing Inherent Risk. The Bank may add other parameters or indicators that are relevant to the characteristics and complexity of the Bank's business by considering the principle of proportionality.
a) Credit Risk
Credit Risk is the Risk arising from the failure of other parties to fulfill their obligations to the Bank, including Credit Risk arising from debtor failure, credit concentration risk, counterparty credit risk, and settlement risk. Credit Risk is generally present in all Bank activities whose performance depends on the performance of the counterparty, issuer, or borrower. Credit Risk can also be caused by concentrated funding provision, among others, to debtors, geographical areas, products, types of financing, or specific fields of business. This risk is commonly referred to as Credit Concentration Risk and is taken into account in the assessment of Inherent Risk.
In assessing the Inherent Risk of Credit Risk, the parameters or indicators used are:
(i) composition of asset portfolio and concentration level; (ii) quality of funding provision and adequacy of provisioning; (iii) funding provision strategy and sources of funding provision; and (iv) external factors.
In assessing the Inherent Risk of Credit Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.a., which is an integral part of this Financial Services Authority Circular Letter.
b) Market Risk
Market Risk is the Risk on the balance sheet position and administrative accounts, including derivative transactions, due to overall changes in market conditions, including option price change Risk. Market Risk includes among others Interest Rate Risk, Exchange Rate Risk, Equity Risk, and Commodity Risk.
Interest Rate Risk, Exchange Rate Risk, and Commodity Risk can arise from both trading book positions and banking book positions, while Equity Risk arises from trading book positions. The implementation of Risk Management for Equity Risk and Commodity Risk is applied by Banks that consolidate with Subsidiary Companies. The scope of trading book and banking book positions refers to Financial Services Authority provisions regarding Minimum Capital Requirements for Commercial Banks.
In assessing the Inherent Risk of Market Risk, the parameters or indicators used are:
(i) volume and composition of the portfolio;
(ii) potential loss of Interest Rate Risk in the banking book (Interest Rate Risk in Banking Book/IRRBB); and (iii) business strategy and policy.
In assessing the Inherent Risk of Market Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.b., which is an integral part of this Financial Services Authority Circular Letter.
c) Liquidity Risk
Liquidity Risk is the Risk arising from the Bank's inability to meet liabilities that have fallen due from cash flow funding sources, and/or from high-quality liquid assets that can be pledged, without disrupting the Bank's activities and financial condition. This risk is also called funding liquidity risk.
Liquidity Risk can also be caused by the Bank's inability to liquidate assets without incurring material discounts due to the absence of an active market or severe market disruption. This risk is called market liquidity risk.
In assessing the Inherent Risk of Liquidity Risk, the parameters or indicators used are:
(i) composition of assets, liabilities, and administrative account transactions; (ii) concentration of assets and liabilities; (iii) vulnerability to funding needs; and (iv) access to funding sources.
In assessing the Inherent Risk of Liquidity Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.c., which is an integral part of this Financial Services Authority Circular Letter.
d) Operational Risk
Operational Risk is the Risk arising from the inadequacy and/or malfunction of internal processes, human error, system failure, and/or the occurrence of external events that affect the Bank's operations. Sources of Operational Risk can be caused, among others, by human resources, internal processes, systems and infrastructure, and external events.
In assessing the Inherent Risk of Operational Risk, the parameters or indicators used are:
(i) business characteristics and complexity;
(ii) human resources;
(iii) information technology and supporting infrastructure; (iv) fraud, both internal and external; and (v) external events.
In assessing the Inherent Risk of Operational Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.d., which is an integral part of this Financial Services Authority Circular Letter.
e) Legal Risk
Legal Risk is the Risk arising from legal claims and/or weaknesses in legal aspects. This risk can also arise, among others, from the absence and/or changes in legislation or weaknesses in agreements, such as the non-fulfillment of contract validity requirements or imperfect collateral binding, causing a transaction already conducted by the Bank to be inconsistent with regulations, and litigation processes arising from third-party lawsuits against the Bank or the Bank against third parties.
In assessing the Inherent Risk of Legal Risk, the parameters or indicators used are:
(i) litigation factors;
(ii) agreement weakness factors; and
(iii) absence or changes in legislation factors.
In assessing the Inherent Risk of Legal Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.e., which is an integral part of this Financial Services Authority Circular Letter.
f) Reputational Risk
Reputational Risk is the Risk arising from a decrease in the level of trust of stakeholders stemming from negative perceptions of the Bank. Reputational Risk arises, among others, from negative media coverage and/or rumors regarding the Bank, as well as the Bank's ineffective communication strategy. One approach used in categorizing the sources of Reputational Risk is indirect (below the line) and direct (above the line).
In assessing the Inherent Risk of Reputational Risk, the parameters or indicators used are:
(i) negative reputational influence from the Bank's owners and related companies; (ii) violations of business ethics; (iii) complexity of the Bank's products and business cooperation; (iv) frequency, materiality, and exposure of negative Bank reporting; and (v) frequency and materiality of customer complaints.
In assessing the Inherent Risk of Reputational Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.f., which is an integral part of this Financial Services Authority Circular Letter.
g) Strategic Risk
Strategic Risk is the Risk arising from the Bank's inappropriateness in making decisions and/or implementing a strategic decision, as well as failure to anticipate changes in the business environment. Sources of Strategic Risk are caused, among others, by weaknesses in the strategy formulation process and inappropriateness in strategy formulation, inadequate management information systems, inadequate results of internal and external environment analysis, setting strategic objectives that are too aggressive, inappropriateness in strategy implementation, and failure to anticipate changes in the business environment.
In assessing the Inherent Risk of Strategic Risk, the parameters or indicators used are:
(i) alignment of business strategy with the business environment; (ii) high-risk strategies and low-risk strategies; (iii) business position; and (iv) achievement of the Bank's Business Plan (RBB).
In assessing the Inherent Risk of Strategic Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.g., which is an integral part of this Financial Services Authority Circular Letter.
h) Compliance Risk
Compliance Risk is the Risk arising from the Bank's failure to comply with and/or implement legislation and regulations. Sources of Compliance Risk arise, among others, from legal behavior, i.e., the Bank's behavior or activities that deviate from or violate regulations and/or legislation, and organizational behavior, i.e., the Bank's behavior or activities that deviate from or contradict generally applicable standards.
In assessing the Inherent Risk of Compliance Risk, the parameters or indicators used are:
(i) type and significance of violations committed; (ii) frequency of violations committed or the Bank's non-compliance track record; and (iii) violations of regulations or generally applicable business standards for certain financial transactions.
In assessing the Inherent Risk of Compliance Risk, the Bank uses parameters or indicators of Inherent Risk with reference to Appendix I.1.h., which is an integral part of this Financial Services Authority Circular Letter.
The Bank's Risk Management implementation varies greatly according to scale, complexity, and the level of Risk that the Bank can tolerate. Thus, in assessing the quality of Risk Management implementation, the characteristics and complexity of the Bank's business must be considered.
The assessment of the quality of Risk Management implementation is an assessment of 4 (four) interrelated aspects, namely:
a) risk governance; b) Risk Management framework; c) Risk Management process, adequacy of human resources, and adequacy of management information systems; and d) adequacy of the Risk control system, considering the characteristics and complexity of the Bank's business.
The assessment of the quality of Risk Management implementation for these aspects is conducted in an integrated manner, covering the following:
a) Risk Governance
Risk governance includes evaluation of:
(i) formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance); and (ii) adequacy of active supervision by the Board of Directors and Board of Commissioners, including the implementation of the authority and responsibilities of the Board of Directors and Board of Commissioners.
b) Risk Management Framework
The Risk Management framework includes evaluation of:
(i) Risk Management strategy that is aligned with the level of Risk to be taken and Risk tolerance; (ii) adequacy of organizational devices to support the effective implementation of Risk Management, including clarity of authority and responsibility; and (iii) adequacy of policies, procedures, and limit setting.
c) Risk Management Process, Adequacy of Human Resources, and Adequacy of Management Information Systems The Risk Management process, adequacy of human resources, and adequacy of Risk Management Information Systems include evaluation of:
(i) Risk identification, measurement, monitoring, and control processes; (ii) adequacy of Risk Management information systems; and (iii) adequacy of the quantity and quality of human resources in supporting the effectiveness of the Risk Management process.
d) Adequacy of Risk Control Systems
The adequacy of Risk control systems includes evaluation of:
(i) adequacy of the Internal Control System; and (ii) adequacy of review by independent parties within the Bank, either by the Risk Management Work Unit (SKMR) or by the Internal Audit Work Unit (SKAI). Review by SKMR includes, among others, methods, assumptions, and variables used to measure and set Risk limits, while review by SKAI includes, among others, the reliability of the Risk Management framework and the implementation of Risk Management by business units and/or support units.
The assessment of the quality of Risk Management implementation is conducted against 8 (eight) types of Risk, namely Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Reputational Risk, Strategic Risk, and Compliance Risk.
The level of quality of Risk Management implementation for each type of Risk is categorized into 5 (five) ratings, namely Rating 1 (Strong), Rating 2 (Satisfactory), Rating 3 (Fair), Rating 4 (Marginal), and Rating 5 (Unsatisfactory).
Determination of Risk Level
The Risk Level is determined based on the assessment of the level of Inherent Risk and the quality of Risk Management implementation for each type of Risk. The determination of the level of Inherent Risk for each type of Risk refers to Appendix II.2.2a, II.2.3a, II.2.4a, II.2.5a, II.2.6a, II.2.7a, II.2.8a, and II.2.9a., which are integral parts of this Financial Services Authority Circular Letter. The determination of the level of quality of Risk Management implementation for each type of Risk refers to Appendix II.2.2b, II.2.3b, II.2.4b, II.2.5b, II.2.6b, II.2.7b, II.2.8b, and II.2.9b., which are integral parts of this Financial Services Authority Circular Letter. After the level of Inherent Risk and the quality of Risk Management implementation are determined, the Risk Level for each type of Risk is determined with reference to Appendix II.2.1., which is an integral part of this Financial Services Authority Circular Letter.
Determination of Risk Profile Factor Rating
The determination of the risk profile factor rating is conducted in the following steps:
a) Determination of the Risk Level from each Risk, with reference to point 3); b) Determination of the composite Inherent Risk Level and composite Risk Management implementation quality level, considering the significance of each Risk to the overall risk profile; c) Determination of the risk profile factor rating based on the determination of the Risk Level as referred to in letter a) and the composite Inherent Risk Level and composite Risk Management implementation quality level as referred to in letter b), based on comprehensive and structured analysis, considering the significance of each Risk to the overall risk profile.
The determination of the risk profile factor rating consists of 5 (five) ratings, namely Rating 1, Rating 2, Rating 3, Rating 4, and Rating 5. A smaller risk profile factor rating order reflects a lower Risk faced by the Bank. The determination of the risk profile factor rating is conducted with reference to Appendix II.2.b., which is an integral part of this Financial Services Authority Circular Letter.
b. Governance Assessment
considering the characteristics and complexity of the Bank's business.
In assessing the Governance factor, the Bank uses parameters or indicators with reference to Appendix I.2, which is an integral part of this Financial Services Authority Circular.
The determination of the Governance factor rank is based on an analysis of:
a) the application of good Governance principles as referred to in item 1); b) the adequacy of Governance over the structure, processes, and results of Governance application at the Bank; and c) other information related to the Bank's Governance based on relevant data and information.
The Governance factor rank is categorized into 5 (five) Ranks, namely Rank 1, Rank 2, Rank 3, Rank 4, and Rank 5. A smaller Governance factor rank order reflects better Governance application. The determination of the Governance factor rank is conducted with reference to Appendix II.3, which is an integral part of this Financial Services Authority Circular.
c. Profitability Assessment
In determining the peer group, the Bank needs to consider the business scale, characteristics, and/or complexity of the Bank's business, as well as the availability of data and information owned.
In assessing the profitability factor, the Bank uses parameters or indicators with reference to Appendix I.3, which is an integral part of this Financial Services Authority Circular.
The determination of the profitability factor rank is conducted based on a comprehensive and structured analysis of the profitability parameters or indicators as referred to in item 1), considering the significance of each parameter or indicator and taking into account other issues affecting the Bank's profitability.
The determination of the profitability factor is categorized into 5 (five) Ranks, namely Rank 1, Rank 2, Rank 3, Rank 4, and Rank 5. A smaller profitability factor rank order reflects better profitability conditions. The determination of the profitability factor rank is conducted with reference to Appendix II.4, which is an integral part of this Financial Services Authority Circular.
d. Capital Assessment
The assessment of the capital factor includes an evaluation of capital adequacy and capital management adequacy. In calculating capital, including linking capital adequacy with the risk profile, the Bank refers to Financial Services Authority regulations regarding the Minimum Capital Requirement for Commercial Banks. The higher the Bank's Risk, the greater the capital that must be provided to anticipate such Risk.
In conducting the assessment, the Bank needs to consider the level, trend, structure, and stability of capital, taking into account peer group performance and the adequacy of the Bank's capital management. The assessment is conducted using both quantitative and qualitative parameters or indicators. In determining the peer group, the Bank needs to consider the business scale,
characteristics, and/or complexity of the Bank's business, as well as the availability of data and information owned.
In assessing the capital factor, the Bank uses parameters or indicators with reference to Appendix I.4, which is an integral part of this Financial Services Authority Circular.
The capital factor is determined based on a comprehensive and structured analysis of the capital parameters or indicators as referred to in item 3), considering the materiality and significance of each parameter or indicator, and taking into account other issues affecting the Bank's capital.
The determination of the capital factor is categorized into 5 (five) Ranks, namely Rank 1, Rank 2, Rank 3, Rank 4, and Rank 5. A smaller capital factor rank order reflects better Bank capital conditions. The determination of the capital factor rank is conducted with reference to Appendix II.5, which is an integral part of this Financial Services Authority Circular.
e. Composite Health Level Rank Assessment
The Bank's Composite Health Level Rank is determined based on a comprehensive and structured analysis of each factor's rank and by considering the general principles of Bank Health Level assessment. In conducting a comprehensive analysis, the Bank needs to consider the ability to face significant changes in external conditions.
The determination of the Composite Rank is categorized into 5 (five) Composite Ranks, namely Composite Rank 1 (CR-1), Composite Rank 2 (CR-2), Composite Rank 3 (CR-3), Composite Rank 4 (CR-4), and Composite Rank 5 (CR-5). A smaller Composite Rank order reflects a healthier Bank condition. The Composite Rank is determined with reference to Appendix II.1, which is an integral part of this Financial Services Authority Circular.
The Financial Services Authority has the authority to downgrade the Bank's Composite Health Level Rank if significant problems or violations are found that will significantly affect the Bank's operations and/or business continuity. Examples of significant problems or violations include manipulation, including window dressing, and internal management disputes that affect the Bank's operations and/or business continuity.
a. Banks that control Subsidiary Companies apply the Bank's Health Level assessment on a consolidated basis. The consolidated Bank Health Level assessment includes the assessment of the risk profile, Governance application, profitability, and capital.
b. The determination of Subsidiary Companies to be consolidated refers to regulations regarding the application of Consolidated Risk Management for Banks that control Subsidiary Companies.
In conducting consolidated assessment, the Bank considers:
c. The determination of the materiality and significance of the Subsidiary Company's share can be determined through the comparison of the Subsidiary Company's total assets to the consolidated Bank's total assets, or the significance of specific positions in the Subsidiary Company that affect the consolidated Bank's performance, such as Risk-Weighted Assets (RWA), profitability, and capital. The determination of the significance of the Subsidiary Company's issues considers, among others, issues present in the Subsidiary Company and their impact on the consolidated Bank's performance or condition, for example, issues related to the Subsidiary Company's business that can impact the consolidated Bank's Reputation Risk, Credit Risk, or Liquidity Risk, issues in risk governance, or weaknesses in the Subsidiary Company's Risk Management application.
d. Parameters or indicators used in the individual Bank Health Level assessment can be used by the Bank when assessing the Bank's Health Level on a consolidated basis. These parameters or indicators can be supplemented with other parameters or indicators as long as they are relevant to the consolidated Bank's business scale, characteristics, and complexity.
e. The consolidated Bank Health Level assessment for Banks controlling Subsidiary Companies that are insurance companies is conducted by considering relevant qualitative and quantitative factors, including the fulfillment of the insurance company's capital adequacy according to requirements and the impact of Risks considered significant or material that affect the consolidated Bank's risk profile and financial performance.
f. In assessing the Bank's Health Level on a consolidated basis, the mechanism for determining Ranks and Rank categories for each assessment factor and the determination of the consolidated Bank's Composite Health Level Rank refers to the procedures for assessing the Bank's Health Level individually as referred to in item III.1, which is an integral part of this Financial Services Authority Circular.
g. The assessment and determination of the consolidated risk profile factor are conducted by considering the following:
h. The assessment and determination of the consolidated Governance factor rank are conducted by considering the following:
i. The assessment and determination of the consolidated profitability and capital factor ranks are conducted based on a comprehensive and structured analysis of specific profitability and capital parameters or indicators resulting from consolidated financial reports and other financial information, considering the following:
IV. FOLLOW-UP ON BANK HEALTH LEVEL ASSESSMENT
a. The Bank's Health Level factor rank is determined as Rank 4 or Rank 5; b. The Bank's Composite Health Level Rank is determined as CR-4 or CR-5; and/or
c. The Bank's Composite Health Level Rank is determined as CR-3, but there are significant problems that need to be addressed to avoid disrupting the Bank's business continuity.
The Bank reports the follow-up results of the action plan implementation to the Financial Services Authority no later than 10 (ten) working days after the action plan's completion time target and/or 10 (ten) working days after the end of the month, and is conducted monthly if there are significant problems so that the action plan cannot be completed on time. The Financial Services Authority may request the Bank to improve the action plan.
V. REPORTING
The Bank submits the results of its self-assessment of the Bank's Health Level individually to the Financial Services Authority no later than July 31 for the Bank Health Level assessment as of the end of June, and January 31 for the Bank Health Level assessment as of the end of December.
Banks controlling Subsidiary Companies submit the results of their self-assessment of the Bank's Health Level on a consolidated basis to the Financial Services Authority no later than August 15 for the Bank Health Level assessment as of the end of June, and February 15 for the Bank Health Level assessment as of the end of December.
The Bank immediately updates its self-assessment of the Bank's Health Level and submits it to the Financial Services Authority, among others, if the Bank's financial condition deteriorates, the Bank faces issues such as Liquidity Risk or capital issues, or other conditions that the Financial Services Authority considers require an update of the Bank's Health Level assessment.
The self-assessment report on the Bank's Health Level and/or the update of the self-assessment of the Bank's Health Level is submitted to the Financial Services Authority, at the address:
a. The Department of Supervision of the relevant Bank, for Banks with headquarters or branches of banks domiciled outside the country located in the Special Capital Region of Jakarta; or b. The Regional Office of the Financial Services Authority or the local Financial Services Authority Office according to the area where the Bank's headquarters is located.
The self-assessment report on the Bank's Health Level is submitted using the report format as referred to in Appendix III, which is an integral part of this Financial Services Authority Circular.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
VI. CLOSING
Upon this Financial Services Authority Circular taking effect, Bank Indonesia Circular Number 13/24/DPNP dated October 25, 2011 regarding the Assessment of the Health Level of Commercial Banks is repealed and declared invalid.
This Financial Services Authority Circular takes effect on the date of determination.
Determined in Jakarta on March 17, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX I
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 14 /SEOJK.03/2017
REGARDING
ASSESSMENT OF THE HEALTH LEVEL OF COMMERCIAL BANKS
MATRIX OF PARAMETERS OR INDICATORS FOR ASSESSING THE HEALTH LEVEL OF BANKS
APPENDIX I.1: Risk Profile Factor Assessment
APPENDIX I.1.a: Credit Risk Assessment
APPENDIX I.1.b: Market Risk Assessment
APPENDIX I.1.c: Liquidity Risk Assessment
APPENDIX I.1.d: Operational Risk Assessment
APPENDIX I.1.e: Legal Risk Assessment
APPENDIX I.1.f: Reputation Risk Assessment
APPENDIX I.1.g: Strategic Risk Assessment
APPENDIX I.1.h: Compliance Risk Assessment
APPENDIX I.2: Governance Factor Assessment
APPENDIX I.3: Profitability Factor Assessment
APPENDIX I.4: Capital Factor Assessment
APPENDIX
RISK PROFILE FACTOR ASSESSMENT
APPENDIX I.1.a
Matrix of Parameters or Indicators for Credit Risk Assessment A. Inherent Risk *)
A. Inherent Risk *) d. Credit per Portfolio Category Total Credit a) Credit per Portfolio Category is credit to Banks and third parties who are not Banks based on portfolio categories as regulated in regulations regarding monthly reports of commercial banks. b) Total Credit is credit to Banks and third parties who are not Banks.
2. Quality
Fund Provisioning and Provisioning
Adequacy a. Low Quality Assets and TRA
Total Assets and TRA a) Low quality assets are all Bank assets, both productive and non-productive, that have quality in special attention, doubtful, and bad according to regulations regarding the assessment of commercial bank asset quality, including restructured loans of good quality, Foreclosed Collateral (AYDA) of good quality, abandoned property of good quality, and temporary investments of good quality. b) Low quality Administrative Account Transactions (TRA) consist of irrevocable LCs, provided guarantees, and withdrawal allowances (commitments) that have quality in special attention, doubtful, and bad according to regulations regarding the assessment of commercial bank asset quality. b. Problematic Productive Assets and TRA Total Assets and TRA a) Problematic Productive Assets are productive assets that have quality doubtful and bad according to regulations regarding the assessment of commercial bank asset quality. b) Total Assets are net total assets (after inter-office set-off) as stated in the Monthly Report of Commercial Banks. Total TRA is the total of irrevocable LCs, provided guarantees, and withdrawal allowances (commitments).
c. Foreclosed Collateral
Total Assets a) Foreclosed Collateral (AYDA) according to regulations regarding the assessment of commercial bank asset quality. b) Total Assets are net total assets (after inter-office set-off) as stated in the Monthly Report of Commercial Banks. d. Low Quality Credit Total Credit a) Low Quality Credit is all credit to third parties who are not Banks that have quality in special attention, doubtful, and bad, including restructured loans of good quality.
A. Inherent Risk *) b) Total Credit is credit to third parties who are not Banks. e. Problematic Credit Total Credit a) Problematic Credit is credit to third parties who are not Banks classified as doubtful and bad. b) Total Credit is credit to third parties who are not Banks. f. Problematic Credit minus Problematic Credit CKPN Total Credit minus Problematic Credit CKPN a) Problematic Credit is credit to third parties who are not Banks classified as doubtful and bad. b) CKPN for Problematic Credit is Impairment Loss Reserve (CKPN) for loans classified as doubtful and bad. c) CKPN calculation refers to financial accounting standards. d) Total Credit is credit to third parties who are not Banks. g. CKPN over Credit Total Credit Clearly understood.
3. Fund Provisioning
Strategy and Sources of Fund Provisioning a. Fund provisioning process, level of competition, and level of asset growth Clearly understood. b. New strategies and products The term new strategies and products refers to changes in the Bank's fund provisioning strategy or new product marketing that has the potential to increase Credit Risk exposure at the Bank.
c. Significance of fund provisioning
conducted indirectly by the Bank
Fund provisioning conducted indirectly by the Bank, among others, includes fund provisioning in cooperation with third parties or the purchase of credit from Banks or other financial institutions.
A. Inherent Risk *)
4. External Factors
Changes in economic conditions, technology, or regulations that affect interest rates, exchange rates, debtor business cycles, and impact the debtor's ability to repay loans. Quite clear.
B. Quality of Risk Management Implementation
*) These are minimum parameters or indicators, and Banks may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX I.1.b
Matrix of Parameters or Indicators for Market Risk Assessment A. Inherent Risk *)
b. Trading Liabilities, Derivatives, and FVO
Total Liabilities a) Trading Liabilities are checking accounts, savings, deposits, liabilities to Bank Indonesia, liabilities to other Banks, repo liabilities, acceptance liabilities, issued securities, and received loans with a trading category. b) Derivative Liabilities are all spot and derivative transaction liabilities. c) Fair Value Option (FVO) Liabilities are checking accounts, savings, deposits, liabilities to Bank Indonesia, liabilities to other Banks, repo liabilities, acceptance liabilities, issued securities, and received loans with a fair value measurement category (FVO).
c. Total Structured Product
Total Assets a) Total Structured Product is the total nominal structured product owned by the Bank in accordance with the Financial Services Authority Regulation regarding Prudential Principles in Conducting Structured Product Activities for General Banks. b) Total Assets is total net assets (after inter-office offset) according to the Monthly Report of General Banks.
d. Potential Gain or Loss from Trading, Derivative, and FVO Assets Operational Income a) Potential Gain or Loss from Trading, Derivative, and FVO Assets is the total gain or loss (net) from:
e. Total Derivatives
Total Assets a) Total Derivatives are all spot and derivative transactions in Rupiah and foreign currency with Banks or third parties that are not Banks, namely forwards, futures, swaps, options, and spots. b) Total Assets (quite clear).
f. Net Foreign Exchange Position (PDN)
Total Capital a) Net Foreign Exchange Position (PDN) is a figure representing the sum of the absolute values for the sum of:
g. Equity Category AFS
Total Capital a) Equity in the Available for Sale (AFS) category is participation with criteria for measurement method at fair value through equity, participation purpose for restructuring and other purposes, issuer groups other than insurance companies, and participation portions less than 50% (fifty percent). b) Total Capital is total capital as regulated in Financial Services Authority provisions regarding minimum capital adequacy requirements for general banks.
h. Financial Assets with Maturity Remaining Above One Year Financial Liabilities with Maturity Remaining Above One Year a) This ratio is intended to measure Bank assets or Bank liabilities that are more sensitive to interest rate changes (asset sensitive or liability sensitive). b) Financial assets with maturity remaining above 1 (one) year include placements in Banks, acceptance bills, reverse repo securities, and loans, with a maturity remaining above 1 (one) year and fixed interest rate category. c) Financial liabilities with maturity remaining above 1 (one) year include time deposits, repo liabilities, acceptance liabilities, liabilities to other Banks, issued securities, and received loans with fixed interest rates.
b. Unrealized Loss on Securities (AFS)
Capital a) Unrealized Loss on Securities with the Available for Sale (AFS) portfolio category; b) Total Capital is total capital as regulated in Financial Services Authority provisions regarding minimum capital adequacy requirements for general banks.
3.2 Business Strategy Related to Interest Rates in the Banking Book
a. Characteristics of Business Activities Impacting Interest Rate Risk in the Banking Book and Characteristics of Main Bank Customers Analysis of main business, products with option features, funding structure, and significance of interest income sensitive to interest rate changes. b. Bank's Market Position in the Industry Analysis of the Bank's market position, particularly in competition for cheap funds (savings and checking accounts).
c. Customer Characteristics
Analysis of the Bank's main customer characteristics and their sensitivity to interest rate changes.
B. Quality of Risk Management Implementation
*) These are minimum parameters or indicators, and Banks may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX I.1.c
Matrix of Parameters or Indicators for Liquidity Risk Assessment A. Inherent Risk *)
b. Primary Liquid Assets and Secondary Liquid Assets Short-Term Funding Short-Term Funding is all third-party funds that do not have a maturity and/or third-party funds that have a maturity of 1 (one) year or less.
c. Primary Liquid Assets and Secondary Liquid Assets
Non-Core Funding
Non-Core Funding is funding that the Bank considers relatively unstable or tends not to remain in the Bank, both in normal and crisis situations, including:
d. Primary Liquid Assets
Short-Term Non-Core Funding
Short-Term Non-Core Funding is as referred to in letter c but with a short term (less than 1 (one) year).
e. Non-Core Funding
Total Funding
Total funding is all funding sources obtained by the Bank, whether in the form of third-party funds or received loans.
f. Non-Core Funding – Liquid Assets
Total Productive Assets – Liquid Assets
This ratio is used to assess the Bank's dependence on non-core funding.
g. Significance of Administrative Account Transactions (commitment and contingent liabilities) Commitment and contingent liabilities are commitment and contingent liabilities found in Administrative Account Transactions as regulated in provisions governing the monthly report of general banks.
Concentration of Assets and Liabilities
a. Asset Concentration
Concentration on specific assets or providing funds to sectors not controlled by the Bank can disrupt the liquidity position if a default occurs. b. Liability Concentration Concentration on large fund providers who tend to be sensitive to credit ratings (credit sensitive) and interest rates (interest rate sensitive) can cause problems in the Bank's liquidity position if large withdrawals occur.
Vulnerability to Funding Needs
Bank's vulnerability to funding needs and the Bank's ability to meet funding needs.
Assessment of the Bank's funding needs in normal and crisis situations and the Bank's ability to meet funding needs, including through analysis of maturity profile reports, cash flow projections, and stress tests.
Access to Funding Sources
The Bank's ability to obtain funding sources under normal and crisis conditions.
Assessment focuses on the Bank's reputation for maintaining funding sources, credit line conditions, performance of access to funding sources, and support from the parent company or intra-group.
B. Quality of Risk Management Implementation
*) These are minimum parameters or indicators, and Banks may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX I.1.d
Matrix of Parameters or Indicators for Operational Risk Assessment A. Inherent Risk *)
Business Characteristics and Complexity
a. Bank's business scale and organizational structure b. Complexity of business processes and diversity of products/services
c. Corporate actions and new business development
d. Outsourcing of work execution to third parties High business complexity and product diversity will cause complexity and variation in work processes, both manual and automated, potentially causing operational disruptions or losses.
Human Resources
a. Human resource management implementation b. Failure due to human factors (human error) Ineffective human resource management can cause potential operational disruptions or losses for the Bank.
Information Technology and Supporting Infrastructure
a. Information Technology (IT) complexity b. IT system changes
c. IT system vulnerability to IT threats and attacks
d. IT system maturity e. IT system failure f. Reliability of supporting infrastructure Inadequate information technology and/or ineffective and inefficient management can cause losses for the Bank.
Fraud
a. Internal fraud b. External fraud
Fraud assessment is conducted against the frequency or materiality of fraud that has occurred in previous assessment periods, including potential fraud that may arise from weaknesses in business aspects, human resources, IT, and external events.
External Events
Frequency and materiality of external events impacting the Bank's operational activities External events include terrorism, crime, pandemics, natural disasters, location, and the Bank's geographical conditions.
B. Quality of Risk Management Implementation
*) These are minimum parameters or indicators, and Banks may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX I.1.e
Matrix of Parameters or Indicators for Legal Risk Assessment A. Inherent Risk *)
Litigation Factors
a. The magnitude of the claim amount filed or the estimated loss that may be experienced by the Bank due to the claim compared to the Bank's capital. b. The magnitude of the loss experienced by the Bank due to a court decision that has acquired permanent legal force compared to the Bank's capital.
c. The basis of the claim that occurred and the party being sued or suing the Bank in a filed claim, as well as management's actions regarding a filed claim.
d. The possibility of similar claims arising due to the same contract standards and the estimated total loss that may arise compared to the Bank's capital.
Litigation can occur due to claims or demands from third parties against the Bank or claims or demands filed against third parties, either through the court or outside the court. Such claims or demands generally incur costs that can harm the Bank's condition.
Contract Weakness Factors
a. Failure to meet the validity requirements of the agreement. b. Weaknesses in contract clauses and/or failure to meet agreed requirements.
c. Understanding of the parties regarding the agreement, especially regarding Risks in complex transactions and using terms.
Weaknesses in contracts performed by the Bank are a source of problems or disputes that may arise later, potentially causing Legal Risk for the Bank.
difficult to understand or unusual for the general public. d. Inability to execute an agreement, either in whole or in part. e. The existence of supporting documents related to agreements entered into by the Bank with third parties. f. Updating and reviewing the use of standard agreements by the Bank and/or independent parties. g. The use of Indonesian law choice for agreements entered into by the Bank and the use of dispute resolution forums.
B. Quality of Risk Management Implementation
Risk governance includes evaluation of: (i) the formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) and (ii) the adequacy of active supervision by the Board of Directors and Board of Commissioners, including the exercise of authority and responsibilities of the Board of Directors and Board of Commissioners.
The Risk Management framework includes evaluation of: (i) Risk Management strategies aligned with the level of Risk to be taken and Risk tolerance; (ii) the adequacy of organizational devices to support the effective implementation of Risk Management, including clarity of authority and responsibilities; and (iii) the adequacy of Risk Management policies and procedures and the establishment of Risk limits.
Risk Management processes, information systems, and human resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) the adequacy of Risk Management information systems; and (iii) the adequacy of the quantity and quality of human resources to support the effectiveness of the Risk Management process.
Risk Control systems include evaluation of: (i) the adequacy of the internal control system and (ii) the adequacy of review by independent parties within the Bank, either by the Internal Audit Team (SKMR) or the Independent Audit Team (SKAI).
*) Represents minimum parameters or indicators, and the Bank may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators that are quantitative. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX I.1.f
Matrix of Parameters or Indicators for Reputational Risk Assessment A. Inherent Risk *)
Reputational Influence from
Bank Owners and
Related Companies a. Credibility of owners and related companies. b. Reputational events on owners and related companies.
Reputational influence or negative news from the Bank's owners and/or related companies with the Bank is one of the factors that can cause an increase in Reputational Risk at the Bank.
Violation of Business Ethics Violations of ethics are visible, among others,
through:
a. financial information transparency; and b. business cooperation with other stakeholders.
What needs to be noted is when the Bank violates ethics or business norms that are generally applicable.
Complexity of Bank Products and
Business Cooperation a. The number and level of use by customers of complex Bank products. b. The number and materiality of Bank cooperation with business partners.
Complex products and cooperation with business partners can expose Reputational Risk in the event of misunderstandings regarding the use of products or services or negative reporting on business partners, among others, in bancassurance and mutual fund products.
Frequency, Materiality,
and Exposure of
Negative Reporting on the Bank a. Frequency and materiality of reporting. b. Type of media and scope of reporting.
The frequency, type of media, and materiality of negative reporting on the Bank, including Bank officials, are measured during the assessment period.
Frequency and
Materiality of Customer
Complaints a. Frequency of customer complaints. b. Materiality of customer complaints.
Customer complaints are measured during the assessment period.
B. Quality of Risk Management Implementation
APPENDIX I.1.g
Matrix of Parameters or Indicators for Strategic Risk Assessment A. Inherent Risk *)
High-Risk Strategy and
Low-Risk Strategy a. A low-risk strategy is a strategy where the Bank conducts business activities in market segments and customers that have been known previously or providing traditional products so that business growth tends to be stable and predictable. b. A high-risk strategy is a strategy where the Bank plans to enter new business areas, whether market segments, products or services, or new customers. Inherent Risk levels can also be caused by the Bank's choice of strategy.
Business Position Assessment is based, among others, on:
a. markets where the Bank conducts business activities; b. competitors and competitive advantages;
c. efficiency in conducting business activities;
d. diversification of business activities and operational coverage; and e. macroeconomic conditions and their impact on Bank conditions.
The extent of the Bank's success or failure in achieving its goals can be assessed based on the Bank's position in the market and competitive advantages held, both against peer groups and the banking industry as a whole.
Achievement of Bank Business Plan (RBB)
Realization of RBB compared to RBB. The purpose of assessment is, among others, to measure the extent of deviation of RBB realization compared to the Bank's strategic planning.
B. Quality of Risk Management Implementation
Risk governance includes evaluation of: (i) the formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) and (ii) the adequacy of active supervision by the Board of Directors and Board of Commissioners, including the exercise of authority and responsibilities of the Board of Directors and Board of Commissioners.
The Risk Management framework includes evaluation of: (i) Risk Management strategies aligned with the level of Risk to be taken and Risk tolerance; (ii) the adequacy of organizational devices to support the effective implementation of Risk Management, including clarity of authority and responsibilities; and (iii) the adequacy of Risk Management policies and procedures and the establishment of Risk limits.
Risk Management processes, information systems, and human resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) the adequacy of Risk Management information systems; and (iii) the adequacy of the quantity and quality of human resources to support the effectiveness of the Risk Management process.
Risk Control systems include evaluation of: (i) the adequacy of the internal control system and (ii) the adequacy of review by independent parties within the Bank, either by the Internal Audit Team (SKMR) or the Independent Audit Team (SKAI).
*) Represents minimum parameters or indicators, and the Bank may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators that are quantitative. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX I.1.h
Matrix of Parameters or Indicators for Compliance Risk Assessment A. Inherent Risk *)
Type and Significance
of Violations Committed a. Number of sanction fines for payment obligations imposed on the Bank by authorities. b. Type of violation or non-compliance committed by the Bank. Scope of violations includes violations of applicable regulations and commitments to the Financial Services Authority, including sanctions imposed for violations committed by the Bank.
Frequency of Violations
Committed or
Track Record of
Bank Non-Compliance a. Type and frequency of the same violations found each year in the last 3 (three) years. b. Significance of the Bank's follow-up on these findings.
Frequency is more historical, looking at the Bank's compliance trend over the last 3 (three) years to determine whether the type of violation committed is repeated or if no significant improvement was made regarding that error.
Violations of
Regulations or Standards
Generally Applicable for Certain
Financial Transactions
Frequency of violations of regulations in certain financial transactions because they do not comply with generally applicable standards.
An example is violations of, among others,
UCP, ISDA, ICC, or other standards generally applicable in the financial sector.
B. Quality of Risk Management Implementation
Risk governance includes evaluation of: (i) the formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) and (ii) the adequacy of active supervision by the Board of Directors and Board of Commissioners, including the exercise of authority and responsibilities of the Board of Directors and Board of Commissioners.
The Risk Management framework includes evaluation of: (i) Risk Management strategies aligned with the level of Risk to be taken and Risk tolerance; (ii) the adequacy of organizational devices to support the effective implementation of Risk Management, including clarity of authority and responsibilities; and (iii) the adequacy of Risk Management policies and procedures and the establishment of Risk limits.
Risk Management processes, information systems, and human resources include evaluation of: (i) risk identification, measurement, monitoring, and control processes; (ii) the adequacy of Risk Management information systems; and (iii) the adequacy of the quantity and quality of human resources to support the effectiveness of the Risk Management process.
Risk Control systems include evaluation of: (i) the adequacy of the internal control system and (ii) the adequacy of review by independent parties within the Bank, either by the Internal Audit Team (SKMR) or the Independent Audit Team (SKAI).
*) Represents minimum parameters or indicators, and the Bank may add other parameters or indicators according to the Bank's business characteristics and complexity. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators that are quantitative. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX 1.2
Matrix of Parameters or Indicators for Governance Factor Assessment No. Governance Factor Assessment Description
APPENDIX 1.3
Matrix of Parameters or Indicators for Profitability Factor Assessment Parameter or Indicator *) Description Bank's Performance in Generating Profit (Profitability) a. Return on Asset (ROA) Profit Before Tax Average Total Assets a) Profit Before Tax is profit as recorded in the Bank's current year income statement annualized. Example: For the June position, accumulated profit at the June position is calculated by dividing by 6 and multiplying by 12. b) Average Total Assets Example: For the June position, it is calculated by summing the total assets position from January to June divided by 6. b. Net Interest Margin (NIM) Net Interest Income Average Total Productive Assets a) Net Interest Income is interest income minus interest expense (annualized). b) Average Total Productive Assets Example: For the June position, it is calculated by summing the productive assets position from January to June divided by 6. c) Productive Assets considered are assets that generate interest, both on the balance sheet and on the off-balance sheet.
c. Actual Component Profit Performance (Profitability)
against Budget Projection
Performance on profit components (profitability) which include among others operating income, operating expenses, non-operating income, non-operating expenses, and clean profit compared to budget projections. d. Ability of Profit Components (Profitability) to Increase Capital Self-explanatory.
Parameter or Indicator *) Description
Sources Supporting Profitability a. Net Interest Income Average Total Assets Self-explanatory. b. Operating Income other than Interest Income (net) Average Total Assets Operating income other than interest income is annualized. c. Overhead Expenses Average Total Assets Overhead expenses are all operating expenses that are not interest expenses (annualized), including expenses:
Parameter or Indicator *) Description sale of HTM and loans and receivables, Realized gain on sale of FVO assets, Rental Income, and Other Income. c) Non Core Expenses is the sum of losses from the sale of fixed assets, foreign currency translation losses, insurance claim losses, Unrealized loss on Fair Value Option liabilities, Unrealized loss on Trading and FVO loans and other financial assets, Realized loss on sale of HTM and loans and receivables, Realized loss on sale of FVO assets, rental expenses, and other expenses. Stability (sustainability) Components Supporting Profitability a. Core ROA = Primary Core Net Income - Operating Discretionary Items Average Total Assets a) Primary core net income is primary core income minus primary core expenses (annualized). b) Primary core income is net interest income plus fee-based income (annualized). c) Primary core expenses are overhead expenses, namely operating expenses other than interest expenses and impairment losses (annualized). d) Operating discretionary items are impairment losses (annualized). b. Future profitability prospects Self-explanatory. Profitability Management Ability of the Bank to manage profitability Self-explanatory. *) Represents minimum parameters or indicators, and the Bank may add other parameters or indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators that are quantitative. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
APPENDIX 1.4
Matrix of Parameters or Indicators for Capital Factor Assessment No. Parameter or Indicator *) Description
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
No. Parameter or Indicator *) Description
2. Capital Management
a. Bank's capital management. This includes the understanding of the Board of Directors and Board of Commissioners, capital management policies and procedures, capital planning, capital adequacy assessment, and independent review. b. Ability to access capital, viewed from internal sources and external sources. a. Capital access from internal sources, among others, comes from profitability performance supporting capital. b. Capital access from external sources, among others, comes from capital markets (primary market) and parent companies. *) Represents minimum parameters or indicators, and the Bank may add other parameters or indicators according to the characteristics and complexity of the Bank's business. Assessment is conducted per position and trend over the last 12 (twelve) months for parameters or indicators that are quantitative. In assessing the Health Level of the Bank on a consolidated basis, parameters or indicators for assessing the Health Level of the Bank on an individual basis may be used, adjusted to the scale, characteristics, and complexity of the Subsidiary's business.
Issued in Jakarta on 17 March 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX II
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 14 /SEOJK.03/2017 REGARDING ASSESSMENT OF THE HEALTH LEVEL OF GENERAL BANKS
ASSESSMENT OF THE HEALTH LEVEL OF BANKS
APPENDIX II.1 : Matrix of Composite Health Level Rankings
APPENDIX II.2.a. : Risk Profile Factor Assessment Matrix
APPENDIX II.2.b. : Risk Profile Factor Ranking Matrix
APPENDIX II.2.1. : Risk Level Determination Matrix
APPENDIX II.2.2.a. : Inherent Risk Level Determination Matrix for
Credit Risk
APPENDIX II.2.2.b. : Risk Management Implementation Quality Determination
Matrix for Credit Risk
APPENDIX II.2.3.a. : Inherent Risk Level Determination Matrix for
Market Risk
APPENDIX II.2.3.b. : Risk Management Implementation Quality Determination
Matrix for Market Risk
APPENDIX II.2.4.a. : Inherent Risk Level Determination Matrix for
Liquidity Risk
APPENDIX II.2.4.b. : Risk Management Implementation Quality Determination
Matrix for Liquidity Risk
APPENDIX II.2.5.a. : Inherent Risk Level Determination Matrix for
Operational Risk
APPENDIX II.2.5.b : Inherent Risk Level Determination Matrix for
Operational Risk
APPENDIX II.2.6.a : Inherent Risk Level Determination Matrix for
Legal Risk
APPENDIX II.2.6.b : Risk Management Implementation Quality Determination
Matrix for Legal Risk
APPENDIX II.2.7.a : Inherent Risk Level Determination Matrix for
Reputational Risk
APPENDIX II.2.7.b : Risk Management Implementation Quality Determination
Matrix for Reputational Risk
APPENDIX II.2.8.a : Inherent Risk Level Determination Matrix for
Strategic Risk
APPENDIX II.2.8.b : Risk Management Implementation Quality Determination
Matrix for Strategic Risk
APPENDIX II.2.9.a: Matrix for Determining Inherent Risk Level for Compliance Risk
APPENDIX II.2.9.b: Matrix for Determining Risk Management Application Quality for Compliance Risk
APPENDIX II.3: Matrix for Ranking Governance Factors
APPENDIX II.4: Matrix for Ranking Profitability Factors
APPENDIX II.5: Matrix for Ranking Capital Factors
APPENDIX II.1
Composite Health Rating Matrix *)
| Rating | Explanation |
|---|---|
| PK 1 | Reflects a Bank condition that is generally very healthy, thus assessed as very capable of facing significant negative influences from changes in business conditions and other external factors, as reflected in the assessment factor ratings, including risk profile, Governance application, profitability, and capital which are generally very good. In case there are weaknesses, generally these weaknesses are not significant. |
| PK 2 | Reflects a Bank condition that is generally healthy, thus assessed as capable of facing significant negative influences from changes in business conditions and other external factors, as reflected in the assessment factor ratings, including risk profile, Governance application, profitability, and capital which are generally good. In case there are weaknesses, generally these weaknesses are less significant. |
| PK 3 | Reflects a Bank condition that is generally fairly healthy, thus assessed as fairly capable of facing significant negative influences from changes in business conditions and other external factors, as reflected in the assessment factor ratings, including risk profile, Governance application, profitability, and capital which are generally fairly good. In case there are weaknesses, generally these weaknesses are fairly significant and if not successfully addressed by management, they can disrupt the Bank's business continuity. |
| PK 4 | Reflects a Bank condition that is generally less healthy, thus assessed as less capable of facing significant negative influences from changes in business conditions and other external factors, as reflected in the assessment factor ratings, including risk profile, Governance application, profitability, and capital which are generally less good. There are weaknesses that are generally significant and cannot be addressed well by management, disrupting the Bank's business continuity. |
| PK 5 | Reflects a Bank condition that is generally unhealthy, thus assessed as unable to face significant negative influences from changes in business conditions and other external factors, as reflected in the assessment factor ratings, including risk profile, Governance application, profitability, and capital which are generally less good. There are weaknesses that are generally very significant, so that to address them, funding support from shareholders or funding sources from other parties is needed to strengthen the Bank's financial condition. |
*) Applicable for individual and consolidated Bank Health Rating assessments.
APPENDIX II.2.a
Risk Profile Factor Assessment Matrix
The determination of the risk profile rating is based on the assessment results of 8 (eight) types of Risks assessed by the Bank. The Bank considers the significance and materiality of the assessed Risks in determining the risk profile rating. For example, Credit Risk is generally the most dominant Risk in Bank activities, thus having higher significance compared to other Risks. Thus, the Bank's risk profile rating will be more influenced by the Credit Risk rating as the most dominant Risk in the Bank and subsequently by other Risks considered significant, such as Market Risk, Liquidity Risk, and/or Operational Risk.
In the event that the Bank has Subsidiary Companies that are required to be consolidated, the Bank considers the impact of the Subsidiary Company's Risk on the risk profile and financial performance of the Bank by considering the significance and materiality of the Subsidiary Company and/or the significance of the Subsidiary Company's issues.
| Risk Type | Inherent Risk Level | Risk Management Application Quality Level | Risk Level |
|---|---|---|---|
| Credit Risk | |||
| Market Risk | |||
| Liquidity Risk | |||
| Operational Risk | |||
| Legal Risk | |||
| Reputational Risk | |||
| Strategic Risk | |||
| Compliance Risk |
| Composite Rating | Risk Profile Rating |
APPENDIX II.2.b
Risk Profile Factor Ranking Matrix
| Rating | Definition |
|---|---|
| Rating 1 | The Bank's risk profile included in this rating generally has characteristics as follows:<br>a. Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from composite inherent Risk is classified as very low during a certain period in the future.<br>b. The quality of Risk Management application is very adequate in composite. In case there are minor weaknesses, such weaknesses can be ignored. |
| Rating 2 | The Bank's risk profile included in this rating generally has characteristics as follows:<br>a. Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from composite inherent Risk is classified as low during a certain period in the future.<br>b. The quality of Risk Management application is adequate in composite. In case there are minor weaknesses, such weaknesses need management attention. |
| Rating 3 | The Bank's risk profile included in this rating generally has characteristics as follows:<br>a. Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from composite inherent Risk is classified as fairly high during a certain period in the future.<br>b. The quality of Risk Management application is fairly adequate in composite. Although minimum requirements are met, there are some weaknesses that require management attention and improvement. |
| Rating 4 | The Bank's risk profile included in this rating generally has characteristics as follows:<br>a. Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from composite inherent Risk is classified as high during a certain period in the future.<br>b. The quality of Risk Management application is less adequate in composite. There are significant weaknesses in various aspects of Risk Management that require immediate corrective action. |
| Rating 5 | The Bank's risk profile included in this rating generally has characteristics as follows:<br>a. Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from composite inherent Risk is classified as very high during a certain period in the future.<br>b. The quality of Risk Management application is not adequate in composite. There are significant weaknesses in various aspects of Risk Management whose resolution is beyond management's capability. |
APPENDIX II.2.1
Matrix for Determining Risk Level
This matrix essentially maps the Risk level resulting from the combination of inherent Risk and the quality of Risk Management application. The Risk level is the final conclusion on the Bank's Risk after considering mitigation performed through Risk Management application. To determine the Risk level, the Bank can refer to the following Risk level matrix.
| Inherent Risk \ Quality of Risk Management Application | Strong | Satisfactory | Fair | Marginal | Unsatisfactory |
|---|---|---|---|---|---|
| Low | 1 | 1 | 2 | 3 | 3 |
| Low to Moderate | 1 | 2 | 2 | 3 | 4 |
| Moderate | 2 | 2 | 3 | 4 | 4 |
| Moderate to High | 2 | 3 | 4 | 4 | 5 |
| High | 3 | 3 | 4 | 5 | 5 |
APPENDIX II.2.2.a
Matrix for Determining Inherent Risk Level for Credit Risk
| Rating | Definition | Rating |
|---|---|---|
| Low (1) | Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Credit Risk is classified as very low during a certain period in the future.<br>Example characteristics of Banks included in the Low (1) rating include:<br>a. The funding portfolio is dominated by very low credit exposures.<br>b. Funding exposures are very well diversified.<br>c. Funding has very good quality.<br>d. The Bank's funding strategy or business model is classified as stable.<br>e. The funding portfolio is relatively unaffected by changes in external factors. | |
| Low to Moderate (2) | Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Credit Risk is classified as low during a certain period in the future.<br>Example characteristics of Banks included in the Low to Moderate (2) rating include:<br>a. The funding portfolio is dominated by low credit exposures.<br>b. Funding exposures are well diversified.<br>c. Funding has good quality.<br>d. The funding strategy or business model is relatively stable.<br>e. The funding portfolio is less affected by changes in external factors. | |
| Moderate (3) | Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Credit Risk is classified as fairly high during a certain period in the future.<br>Example characteristics of Banks included in the Moderate (3) rating include:<br>a. The funding portfolio is dominated by moderate credit exposures.<br>b. There is a fairly significant concentration of funding.<br>c. Funding has fairly good quality.<br>d. The funding strategy or business model is generally fairly stable.<br>e. The funding portfolio is fairly affected by changes in external factors. | |
| Moderate to High (4) | Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Credit Risk is classified as high during a certain period in the future.<br>Example characteristics of Banks included in the Moderate to High (4) rating include:<br>a. The funding portfolio is dominated by high credit exposures.<br>b. There is a significant concentration of funding.<br>c. Funding has less good quality.<br>d. There are significant changes in the funding strategy or business model.<br>e. The funding portfolio is affected by changes in external factors. | |
| High (5) | Considering the business activities conducted by the Bank, the likelihood of losses faced by the Bank from Credit Risk is classified as very high during a certain period in the future.<br>Example characteristics of Banks included in the High (5) rating include:<br>a. The funding portfolio is dominated by very high credit exposures.<br>b. There is a very significant concentration of funding.<br>c. Funding has poor quality.<br>d. There are very significant changes in the funding strategy or business model.<br>e. The funding portfolio is very affected by changes in external factors. |
APPENDIX II.2.2.b
For Credit Risk
| Rating | Definition | Rating |
|---|---|---|
| Strong (1) | The quality of Risk Management application for Credit Risk is very adequate. Although there are minor weaknesses, such weaknesses are not significant and can be ignored.<br>Example characteristics of Banks included in the Strong (1) rating include:<br>a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) for credit is very adequate and aligned with the Bank's overall strategic objectives and business strategy.<br>b. The Board of Directors and Board of Commissioners have very good awareness and understanding of Risk Management for Credit Risk.<br>c. The Risk Management culture for Credit Risk is very strong and has been internalized very well at all organizational levels.<br>d. The execution of duties by the Board of Directors and Board of Commissioners is overall very adequate.<br>e. The Risk Management function for Credit Risk is independent, has clear duties and responsibilities, and operates very well.<br>f. Delegation of authority is controlled and monitored periodically and operates very well.<br>g. The lending strategy is very good and very aligned with the level of Risk to be taken and Credit Risk tolerance.<br>h. Risk Management policies and procedures and the determination of Credit Risk limits are very adequate and available for all areas of Risk Management for Credit Risk, aligned with application, and well understood by employees.<br>i. The Risk Management process for Credit Risk is very adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>j. The funding process is generally very adequate from the underwriting process to non-performing asset handling.<br>k. The Credit Risk grading system is very good, applied consistently, and well understood by employees. There is an independent loan review function that operates well.<br>l. The Credit Risk Management Information System is very good, producing comprehensive and integrated Credit Risk reporting to the Board of Directors and Board of Commissioners.<br>m. Human resources are generally very adequate in terms of quantity and competence in the Risk Management function for Credit Risk.<br>n. The internal control system is very effective in supporting the implementation of Risk Management for Credit Risk.<br>o. The execution of independent review by the internal audit work unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.<br>p. Generally, there are no significant weaknesses based on independent review results.<br>q. Follow-up on independent reviews has been implemented very adequately. | |
| Satisfactory (2) | The quality of Risk Management application for Credit Risk is adequate. Although there are some minor weaknesses, such weaknesses can be resolved in normal business activities.<br>Example characteristics of Banks included in the Satisfactory (2) rating include:<br>a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and aligned with the Bank's overall strategic objectives and business strategy.<br>b. The Board of Directors and Board of Commissioners have Credit Risk Management awareness.<br>c. The Risk Management culture for Credit Risk is strong and has been internalized very well at all organizational levels.<br>d. The execution of duties by the Board of Directors and Board of Commissioners is overall adequate. There are some weaknesses that are not significant and can be corrected immediately.<br>e. The Risk Management function for Credit Risk is independent, has clear duties and responsibilities, and operates well. There are minor weaknesses, but they can be resolved in normal business activities.<br>f. Delegation of authority is controlled and monitored periodically, and operates well.<br>g. The lending strategy is good and aligned with the level of Risk to be taken (risk appetite) and Credit Risk tolerance (risk tolerance).<br>h. Risk Management policies and procedures and the determination of Credit Risk limits are adequate and available for all areas of Risk Management for Credit Risk, aligned with application, and well understood by employees.<br>i. The Risk Management process for Credit Risk is adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>j. The funding process is good. There are minor weaknesses in one or more aspects of funding that can be easily corrected.<br>k. The Credit Risk grading system is good, applied consistently, and understood by employees. There is an independent loan review function. There are minor weaknesses that do not disrupt the overall process.<br>l. The Credit Risk Management Information System is good, including Credit Risk reporting to the Board of Directors and Board of Commissioners. There are minor weaknesses that can be easily corrected.<br>m. Human resources are adequate, both in terms of quantity and competence in the Risk Management function for Credit Risk.<br>n. The internal control system is effective in supporting the implementation of Risk Management for Credit Risk.<br>o. The execution of independent review by the internal audit work unit and functions performing independent review is adequate, in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.<br>p. There are weaknesses that are not significant based on independent review results.<br>q. Follow-up on independent reviews has been implemented adequately. | |
| Fair (3) | The quality of Risk Management application for Credit Risk is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention.<br>Example characteristics of Banks included in the Fair (3) rating include:<br>a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is fairly adequate but not always aligned with the Bank's overall strategic objectives and business strategy.<br>b. The Board of Directors and Board of Commissioners have fairly good awareness and understanding of Risk Management for Credit Risk.<br>c. The Risk Management culture for Credit Risk is fairly strong and has been internalized fairly well but not always implemented consistently.<br>d. The execution of duties by the Board of Directors and Board of Commissioners is overall fairly adequate. There are some weaknesses in some assessment aspects that need management attention.<br>e. The Risk Management function for Credit Risk has operated fairly well, but there are some fairly significant weaknesses that need to be resolved immediately by management.<br>f. Delegation of authority is fairly good, but control and monitoring are not always implemented well.<br>g. The lending strategy is fairly aligned with the level of Risk to be taken (risk appetite) and Credit Risk tolerance (risk tolerance).<br>h. Risk Management policies and procedures, and the determination of Credit Risk limits are fairly adequate but not always consistent with application and/or not well understood by employees.<br>i. The Risk Management process for Credit Risk is fairly adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>j. The funding process is fairly good. There are weaknesses in one or more aspects of funding that need management attention.<br>k. The Credit Risk grading system and loan review function are fairly good, but there are some weaknesses that need management attention.<br>l. The Credit Risk Management Information System meets minimum expectations but there are some weaknesses, including Credit Risk reporting to the Board of Directors and Board of Commissioners that requires management attention.<br>m. Human resources are fairly adequate in terms of quantity and competence in the Risk Management function for Credit Risk.<br>n. The internal control system is fairly effective in supporting the implementation of Risk Management for Credit Risk.<br>o. The execution of independent review by the internal audit work unit and functions performing independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention.<br>p. There are weaknesses that are fairly significant based on independent review results.<br>q. Follow-up on independent reviews has been implemented fairly adequately. | |
| Marginal (4) | The quality of Risk Management application for Credit Risk is less adequate. There are significant weaknesses in various aspects of Risk Management for Credit Risk that require immediate corrective action.<br>Example characteristics of Banks included in the Marginal (4) rating include:<br>a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with the Bank's overall strategic objectives and business strategy.<br>b. Significant weaknesses in the awareness and understanding of the Board of Directors and Board of Commissioners regarding Risk Management for Credit Risk.<br>c. The Risk Management culture for Credit Risk is less strong and has not been internalized at every work unit level.<br>d. The execution of duties by the Board of Directors and Board of Commissioners is overall less adequate and there are weaknesses in some assessment aspects that need to be corrected immediately.<br>e. Significant weaknesses in the Risk Management function for Credit Risk that need to be corrected immediately.<br>f. Delegation of authority is weak, not controlled, and not monitored well.<br>g. The lending strategy is less aligned with the level of Risk to be taken (risk appetite) and Credit Risk tolerance (risk tolerance).<br>h. Significant weaknesses in Risk Management policies and procedures and the determination of Credit Risk limits.<br>i. The Risk Management process for Credit Risk is less adequate in identifying, measuring, monitoring, and controlling Credit Risk.<br>j. The funding process is less good and there are weaknesses in one or more aspects of funding that need to be corrected immediately.<br>k. The Credit Risk grading system and loan review are less good and there are some weaknesses that need to be corrected immediately.<br>l. Significant weaknesses in the Credit Risk Management Information System, including reporting of Risk to the Board of Directors and Board of Commissioners that need to be corrected immediately.<br>m. Human resources are less adequate in terms of quantity and competence in the Risk Management function for Credit Risk.<br>n. The internal control system is less effective in supporting the implementation of Risk Management for Credit Risk.<br>o. The execution of independent review by the internal audit work unit and functions performing independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that need to be corrected immediately.<br>p. There are weaknesses that are significant based on independent review results that need to be corrected immediately.<br>q. Follow-up on independent reviews is less adequate. | |
| Unsatisfactory (5) | The quality of Risk Management application for Credit Risk is not adequate. There are significant weaknesses in various aspects of Risk Management for Credit Risk whose resolution is beyond management's capability.<br>Example characteristics of Banks included in the Unsatisfactory (5) rating include: |
a. Formulation of the Risk level to be taken (risk appetite) and Risk tolerance is inadequate and not aligned with the Bank's overall strategic objectives and business strategy.
b. Awareness and understanding of the Board of Directors and Board of Commissioners regarding Risk Management for Credit Risk is very weak.
c. Significant weakness in the awareness and understanding of the Board of Directors and Board of Commissioners regarding Risk Management for Credit Risk.
d. Risk Management culture for Credit Risk is weak and has not been internalized at every level of the organization.
e. The overall implementation of duties by the Board of Directors and Board of Commissioners is inadequate. There are weaknesses in several assessment aspects that need to be improved immediately.
f. Significant weakness in the Risk Management function for Credit Risk that needs to be improved immediately.
g. Weak delegation of authority, not controlled, and not monitored well.
h. Lending strategy is not aligned with the Risk level to be taken and Credit Risk tolerance.
i. Significant weakness in Risk Management policies and procedures as well as the setting of Credit Risk limits.
j. The Risk Management process for Credit Risk is inadequate in identifying, measuring, monitoring, and controlling Credit Risk.
k. The funding provision process is poor. There are weaknesses in one or more aspects of funding provision that need to be improved immediately.
l. The Credit Risk grading system and loan review function are poor. There are several weaknesses that need to be improved immediately.
m. Significant weakness in the Credit Risk Management Information System, including reporting of Risk to the Board of Directors and Board of Commissioners, that needs to be improved immediately.
n. Human resources are inadequate in terms of quantity and competence in the Risk Management function for Credit Risk.
o. The internal control system is less effective in supporting the implementation of Risk Management for Credit Risk.
p. The implementation of independent review by the internal audit unit and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that need to be improved immediately.
q. There are significant weaknesses based on the results of independent review that need to be improved immediately.
r. Follow-up on independent review is inadequate.
Matrix for Setting Inherent Risk Level for Market Risk
Low (1)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Market Risk is classified as very low during a certain period in the future.
Examples of Bank characteristics included in the Low (1) rating are as follows:
a. Market Risk exposure from trading is not significant. b. Most trading book positions offset each other with minimal repricing Risk.
c. All exchange rate positions are completely matched/hedged.
d. Derivative transactions are not significant. e. The asset and liability structure is not sensitive to interest rate changes, as reflected in the repricing gap of assets and liabilities having a very minimal impact on interest income or capital. f. The Bank's portfolio is dominated by non-complex financial instruments. g. Trading activities are generally to meet customer needs.
Low to Moderate (2)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Market Risk is classified as low during a certain period in the future.
Examples of Bank characteristics included in the Low to Moderate (2) rating are as follows:
a. Market Risk exposure from trading is less significant. b. There is a mismatch in trading book positions that is less significant.
c. Most exchange rate positions can offset each other or be hedged.
d. Derivative transactions are less significant. e. The asset and liability structure is less sensitive to interest rate changes, as reflected in the repricing gap of assets and liabilities having a minimal impact on interest income or capital. f. The Bank's portfolio is dominated by less complex financial instruments. g. Trading activities are generally to meet customer needs.
Moderate (3)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Market Risk is classified as moderately high during a certain period in the future.
Examples of Bank characteristics included in the Moderate (3) rating are as follows:
a. Market Risk exposure from trading is moderately significant. b. There is a mismatch in trading book positions in a moderately significant amount.
c. There is a moderately significant exchange rate exposure.
d. Derivative transactions are moderately significant. e. The asset and liability structure is moderately sensitive to interest rate changes, as reflected in the repricing gap of assets and liabilities having a moderately significant impact on interest income or capital. f. The Bank's portfolio is dominated by moderately complex financial instruments. g. There are proprietary trading or market making activities that are not significant.
Moderate to High (4)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Market Risk is high during a certain period in the future.
Examples of Bank characteristics included in the Moderate to High (4) rating are as follows:
a. Market Risk exposure from trading is significant. b. There is a mismatch in trading book positions in a significant amount.
c. Exchange rate exposure is significant.
d. Derivative transactions are significant. e. The asset and liability structure is sensitive to interest rate changes, as reflected in the repricing gap of assets and liabilities having a significant impact on interest income or capital. f. The Bank's portfolio is dominated by complex financial instruments. g. There are proprietary trading or market making activities that are quite significant.
High (5)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Market Risk is very high during a certain period in the future.
Examples of Bank characteristics included in the High (5) rating are as follows:
a. Market Risk exposure from trading is very significant. b. Mismatch in trading book positions is very significant.
c. Exchange rate exposure is very significant.
d. Derivative transactions are very significant. e. The asset and liability structure is sensitive to interest rate changes, as reflected in the repricing gap of assets and liabilities being very significant when compared to interest income or capital's ability to absorb potential losses.
f. The Bank's portfolio is dominated by very complex financial instruments. g. The Bank's trading activities are dominated by proprietary trading and market making.
For Market Risk
Strong (1)
The quality of Risk Management implementation for Market Risk is very adequate. Although there are minor weaknesses, they are not significant and can be ignored.
Examples of Bank characteristics included in the Strong (1) rating are as follows:
a. Formulation of the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has been aligned with the Bank's overall strategic and business objectives. b. The Board of Directors and Board of Commissioners have very good awareness and understanding of Risk Management for Market Risk.
c. Risk Management culture for Market Risk is very strong and has been internalized very well at all levels of the organization.
d. The overall implementation of duties by the Board of Directors and Board of Commissioners is very adequate. e. The Risk Management function for Market Risk, including related independent committees, has clear duties and responsibilities and has operated very well. f. Delegation of authority is controlled and monitored periodically and has operated very well. g. Market Risk strategy, including trading strategy and banking book position management, is very adequate. h. Risk Management policies and procedures as well as the setting of Market Risk limits are very adequate and available for all areas of Risk Management for Market Risk, aligned with implementation and well understood by employees.
i. The Risk Management process for Market Risk is very adequate in identifying, measuring, monitoring, and controlling Market Risk.
j. The Market Risk Management Information System is very good, producing comprehensive and integrated Market Risk reports to the Board of Directors and Board of Commissioners. k. Generally, human resources are very adequate in terms of quantity and competence in the Risk Management function for Market Risk.
l. The internal control system is very effective in supporting the implementation of Risk Management for Market Risk.
m. The implementation of independent review by the internal audit unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. Generally, there are no significant weaknesses based on the results of independent review. o. Follow-up on independent review has been carried out very adequately.
Satisfactory (2)
The quality of Risk Management implementation for Market Risk is adequate. There are some minor weaknesses, but they can be resolved in normal business activities.
Examples of Bank characteristics included in the Satisfactory (2) rating are as follows:
a. Formulation of the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has been aligned with the Bank's overall strategic and business objectives. b. The Board of Directors and Board of Commissioners have awareness of Risk Management for Market Risk.
c. Risk Management culture for Market Risk is strong and has been internalized well at all levels of the organization.
d. The overall implementation of duties by the Board of Directors and Board of Commissioners is adequate. There are some insignificant weaknesses that can be improved immediately.
e. The Risk Management function for Market Risk, including related independent committees, has clear duties and responsibilities and has operated well. There are minor weaknesses that can be resolved in normal business activities. f. Delegation of authority is controlled and monitored periodically, and has operated well. g. Market Risk strategy, including trading strategy and banking book position management, is adequate. h. Risk Management policies and procedures as well as the setting of Market Risk limits are adequate and available for all areas of Risk Management for Market Risk, aligned with implementation, and well understood by employees.
i. The Risk Management process for Market Risk is adequate in identifying, measuring, monitoring, and controlling Market Risk.
j. The Market Risk Management Information System is good, producing comprehensive and integrated Market Risk reports to the Board of Directors and Board of Commissioners. k. Generally, human resources are adequate in terms of quantity and competence in the Risk Management function for Market Risk.
l. The internal control system is effective in supporting the implementation of Risk Management for Market Risk.
m. The implementation of independent review by the internal audit unit and functions performing independent review is adequate in terms of methodology, frequency,
n. There are weaknesses but not significant based on the results of independent review. o. Follow-up on independent review has been carried out adequately.
Fair (3)
The quality of Risk Management implementation for Market Risk is moderately adequate. Although minimum requirements are met, there are some weaknesses that require management attention.
Examples of Bank characteristics included in the Fair (3) rating are as follows:
a. Formulation of the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) is moderately adequate and has been aligned with the Bank's overall strategic and business objectives. b. The Board of Directors and Board of Commissioners have moderate awareness and understanding of Risk Management for Market Risk.
c. Risk Management culture for Market Risk is moderately strong and has been internalized well at all levels of the organization.
d. The overall implementation of duties by the Board of Directors and Board of Commissioners is moderately adequate. There are weaknesses in several assessment aspects that need management attention. e. The Risk Management function for Market Risk, including related independent committees, has clear duties and responsibilities and has operated moderately well, but there are some weaknesses that need management attention. f. Delegation of authority is moderately good, but control and monitoring are not always implemented well. g. Market Risk management strategy, including trading strategy and banking book position management, is moderately adequate. h. Risk Management policies and procedures as well as the setting of Market Risk limits are moderately adequate and available for all areas of Risk Management for Market Risk, aligned with implementation, and well understood by employees.
i. The Risk Management process for Market Risk is moderately adequate in identifying, measuring, monitoring, and controlling Risk Management for Market Risk.
j. The Market Risk Management Information System meets minimum expectations but has some weaknesses, including reporting to the Board of Directors and Board of Commissioners that requires management attention. k. Generally, human resources are moderately adequate in terms of quantity and competence in the Risk Management function for Market Risk.
l. The internal control system is moderately effective in supporting the implementation of Risk Management for Market Risk.
m. The implementation of independent review by the internal audit unit and functions performing independent review is moderately adequate. There are some weaknesses in methodology, frequency, or reporting to the Board of Directors and Board of Commissioners that require management attention. n. There are moderately significant weaknesses based on the results of independent review. o. Follow-up on independent review has been carried out moderately adequately.
Marginal (4)
The quality of Risk Management implementation for Market Risk is less adequate. There are significant weaknesses in various aspects of Risk Management for Market Risk that require immediate corrective action.
Examples of Bank characteristics included in the Marginal (4) rating are as follows:
a. Formulation of the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with the Bank's overall strategic and business objectives. b. Significant weakness in the awareness and understanding of the Board of Directors and Board of Commissioners regarding Risk Management for Market Risk.
c. Risk Management culture for Market Risk is weak and has not been internalized well at all levels of the organization.
d. The overall implementation of duties by the Board of Directors and Board of Commissioners is less adequate. There are weaknesses in several assessment aspects that need management attention. e. Significant weakness in the Risk Management function for Market Risk that requires immediate improvement.
f. Delegation of authority is weak and not controlled and not monitored well. g. Market Risk management strategy is less adequate. There are weaknesses in Market Risk management aspects that require immediate improvement. h. Significant weakness in Risk Management policies and procedures as well as the setting of Market Risk limits.
i. The Risk Management process for Market Risk is less adequate in identifying, measuring, monitoring, and controlling Market Risk.
j. Significant weakness in the Market Risk Management Information System, including reporting to the Board of Directors and Board of Commissioners, that requires immediate improvement. k. Human resources are less adequate in terms of quantity and competence in the Risk Management function for Market Risk.
l. The internal control system is less effective in supporting the implementation of Risk Management for Market Risk.
m. The implementation of independent review by the internal audit unit and functions performing independent review is less adequate. There are some weaknesses in methodology, frequency, or reporting to the Board of Directors and Board of Commissioners that require immediate improvement. n. There are significant weaknesses based on the results of independent review that require immediate corrective action. o. Follow-up on independent review is less adequate.
Unsatisfactory (5)
The quality of Risk Management implementation for Market Risk is inadequate. There are significant weaknesses in various aspects of Risk Management for Market Risk that are beyond management's ability to resolve.
Examples of Bank characteristics included in the Unsatisfactory (5) rating are as follows:
a. Formulation of the Risk level to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with the Bank's overall strategic and business objectives. b. Awareness and understanding of the Board of Directors and Board of Commissioners regarding Risk Management for Market Risk is very weak.
c. Risk Management culture for Market Risk is not strong or does not exist at all.
d. The implementation of duties by the Board of Directors and Board of Commissioners is inadequate. There are weaknesses in almost all assessment aspects that are beyond the Bank's ability to resolve. e. Significant weakness in the Risk Management function for Market Risk that requires fundamental improvement. f. Delegation of authority is very weak or non-existent. g. Market Risk management strategy is inadequate. There are weaknesses in almost all aspects of Market Risk management that require immediate improvement. h. Very significant weakness in Risk Management policies and procedures as well as the setting of Market Risk limits.
i. The Risk Management process for Market Risk is inadequate in identifying, measuring, monitoring, and controlling Market Risk.
j. Fundamental weakness in the Market Risk Management Information System. Reporting of Market Risk to the Board of Directors and Board of Commissioners is very inadequate. k. Human resources are inadequate in terms of quantity and competence in the Risk Management function for Market Risk.
l. The internal control system is ineffective in supporting the implementation of Risk Management for Market Risk.
m. The implementation of independent review by the internal audit unit and functions performing independent review is inadequate. There are very significant weaknesses in methodology, frequency, or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement.
n. There are very significant weaknesses based on the results of independent review that are beyond management's ability to correct. o. Follow-up on independent review is inadequate.
Matrix for Setting Inherent Risk Level for Liquidity Risk
Low (1)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Liquidity Risk is classified as very low during a certain period in the future.
Examples of Bank characteristics included in the Low (1) rating are as follows:
a. The Bank has very adequate high-quality liquid assets to cover maturing liabilities. b. Funding sources consisting of unstable (volatile) funding are not significant.
c. The volume of administrative account transactions and/or intragroup funding commitments is not significant.
d. Concentration on unstable (volatile) funding sources is not significant. e. The Bank is very capable of meeting obligations and cash flow needs under normal conditions and in crisis scenarios. f. Cash flows from assets and liabilities can offset each other very well. g. Access to funding sources is very adequate, proven by the Bank's very good reputation, very adequate standby loans, and the existence of liquidity commitments or support from the parent company or intra-group.
Low to Moderate (2)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Liquidity Risk is classified as low during a certain period in the future.
Examples of Bank characteristics included in the Low to Moderate (2) rating are as follows:
a. The Bank has adequate high-quality liquid assets to cover maturing liabilities.
b. Funding sources consisting of unstable (volatile) funding are less significant.
c. The volume of administrative account transactions and/or intragroup funding commitments is less significant.
d. Concentration on unstable (volatile) funding sources is less significant. e. The Bank is capable of meeting obligations and cash flow needs under normal conditions and in crisis scenarios. f. Cash flows from assets and liabilities can offset each other well. g. Access to funding sources is adequate, proven by the Bank's good reputation, adequate standby loans, and the existence of liquidity commitments or support from the parent company or intra-group.
Moderate (3)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Liquidity Risk is classified as moderately high during a certain period in the future.
Examples of Bank characteristics included in the Moderate (3) rating are as follows:
a. The Bank's liquid assets are moderately adequate to cover maturing liabilities. b. Funding sources consisting of unstable (volatile) funding are moderately significant.
c. The volume of administrative account transactions and/or intragroup funding commitments is moderately significant.
d. Concentration on unstable (volatile) funding sources is moderately significant. e. The Bank is moderately capable of meeting obligations and cash flow needs under normal conditions and in crisis scenarios. f. Cash flows from assets and liabilities can offset each other moderately well. g. Access to funding sources is moderately adequate, proven by the Bank's moderately good reputation, moderately adequate standby loans, and the existence of liquidity commitments or support from the parent company or intra-group.
Rating Definition Rating adequate and there is commitment or liquidity support from the parent company or intra-group.
Moderate to High (4)
Considering the business activities conducted by the Bank, the potential losses the Bank faces from Liquidity Risk are considered high over a certain period of time in the future. Examples of Bank characteristics included in the Moderate to High (4) rating are as follows:
a. There are concerns regarding the quality of the Bank's liquid assets and the ability of liquid assets to cover maturing liabilities. b. Funding sources consisting of unstable (volatile) funding are significant.
c. Administrative account transactions and/or significant intra-group funding commitments.
d. Significant concentration on unstable (volatile) funding sources. e. The Bank is less able to meet obligations and cash flow needs under normal conditions as well as crisis scenarios. f. Significant cash flow gaps (mismatch) at various time scales. g. Access to funding sources is less adequate due to the Bank's poor reputation, limited stand-by loans, and no commitment or liquidity support from the parent company or intra-group. High (5) Considering the business activities conducted by the Bank, the potential losses the Bank faces from Liquidity Risk are considered very high over a certain period of time in the future. Examples of Bank characteristics included in the High (5) rating are as follows:
a. Poor quality of liquid assets, and volume of liquid assets is very inadequate to meet maturing liabilities. b. Funding sources consisting of unstable (volatile) funding are very significant.
Rating Definition Rating
c. Administrative account transactions and/or significant intra-group funding commitments.
d. Significant concentration on unstable (volatile) funding sources. e. The Bank is unable to meet obligations and cash flow needs under normal conditions as well as crisis scenarios. f. Cash flows cannot cover each other at almost all times significantly. g. Access to funding sources is less adequate due to deteriorating Bank reputation, stand-by loans unavailable, and no commitment or liquidity support from the parent company or intra-group.
APPENDIX II.2.4.b
For Liquidity Risk
Rating Definition Rating
Strong (1) Quality of implementation of Risk Management for Liquidity Risk is very adequate. Although there are minor weaknesses, these weaknesses are not significant so they can be ignored. Examples of Bank characteristics included in the Strong (1) rating are as follows:
a. Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has aligned with the Bank's overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have very good (awareness) and understanding of Risk Management for Liquidity Risk.
c. Risk Management Culture for Liquidity Risk is very strong and has been internalized very well at all levels of the organization.
d. Execution of duties by the Board of Directors and Board of Commissioners as a whole is very adequate. e. The Risk Management function for Liquidity Risk, including the Assets and Liabilities Management Committee (ALCO) and related committees, is independent, has clear tasks and responsibilities, and has operated very well. f. Delegation of authority is controlled and monitored periodically and has operated very well. g. Liquidity management strategy is very adequate, including among others funding strategy, position management and intra-day Liquidity Risk strategy, intra-group position and Liquidity Risk management, management of high-quality liquid assets as collateral, and Contingency Funding Plan (CFP).
Rating Definition Rating h. Risk Management policies and procedures as well as the establishment of Liquidity Risk limits are very adequate and available for all areas of Risk Management for Liquidity Risk, aligned with implementation, and well understood by employees.
i. The Risk Management process for Liquidity Risk is very adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
j. The Liquidity Risk Management Information System is very good so as to produce comprehensive and integrated Liquidity Risk reports to the Board of Directors and Board of Commissioners. k. Human resources are very adequate in terms of quantity and competence in the Risk Management function for Liquidity Risk.
l. The internal control system is very effective in supporting the implementation of Risk Management for Liquidity Risk.
m. Implementation of independent review by internal audit work units and functions conducting independent review is very adequate in terms of methodology, frequency, as well as reporting to the Board of Directors and Board of Commissioners. n. Generally, there are no significant weaknesses based on the results of independent review. o. Follow-up on independent review has been implemented very adequately. Satisfactory (2) Quality of implementation of Risk Management for Liquidity Risk is adequate. There are several minor weaknesses that can be resolved in normal business activities. Examples of Bank characteristics included in the Satisfactory (2) rating are as follows:
a. Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with the Bank's overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have Liquidity Risk Management awareness.
Rating Definition Rating
c. Risk Management Culture for Liquidity Risk is strong and has been internalized well at all levels of the organization.
d. Execution of duties by the Board of Directors and Board of Commissioners is generally adequate. There are several weaknesses but not significant and can be repaired immediately. e. The Risk Management function for Liquidity Risk, including ALCO and related independent committees, has clear tasks and responsibilities, and has operated well. There are minor weaknesses that can be resolved in normal business activities. f. Delegation of authority is controlled and monitored periodically, and has operated well. g. Liquidity management strategy is adequate, including among others funding strategy, position management and intra-day Liquidity Risk strategy, intra-group position and Liquidity Risk management, management of high-quality liquid assets as collateral, and Contingency Funding Plan (CFP). h. Risk Management policies and procedures as well as the establishment of Liquidity Risk limits are adequate and available for all areas of Risk Management for Liquidity Risk, aligned with implementation, and well understood by employees.
i. The Risk Management process for Liquidity Risk is adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
j. The Liquidity Risk Management Information System is good so as to produce comprehensive and integrated Liquidity Risk reports to the Board of Directors and Board of Commissioners. k. Human resources are adequate in terms of quantity and competence in the Risk Management function for Liquidity Risk.
l. The internal control system is effective in supporting the implementation of Risk Management for Liquidity Risk.
m. Implementation of independent review by internal audit work units and functions conducting independent review is adequate in terms of methodology, frequency,
Rating Definition Rating n. There are weaknesses but not significant based on the results of independent review. o. Follow-up on independent review has been implemented adequately. Fair (3) Quality of implementation of Risk Management for Liquidity Risk is fairly adequate. Although minimum requirements are met, there are several weaknesses that require management attention. Examples of Bank characteristics included in the Fair (3) rating are as follows:
a. Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is fairly adequate and has aligned with the Bank's overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have (awareness) and fairly good understanding of Risk Management for Liquidity Risk.
c. Risk Management Culture for Liquidity Risk is fairly strong and has been internalized fairly well at all levels of the organization.
d. Execution of duties by the Board of Directors and Board of Commissioners is fairly adequate. There are weaknesses in some assessment aspects that need management attention. e. The Risk Management function for Liquidity Risk, including ALCO and related independent committees, has clear tasks and responsibilities, and has operated fairly well, but there are several weaknesses that need management attention. f. Delegation of authority is fairly good, but control and monitoring are not always implemented well. g. Liquidity management strategy is fairly adequate. There are several weaknesses in one or more aspects of liquidity management that need management attention. h. Risk Management policies and procedures as well as the establishment of Liquidity Risk limits are fairly adequate but not always consistent with implementation.
Rating Definition Rating
i. The Risk Management process for Liquidity Risk is fairly adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
j. The Liquidity Risk Management Information System meets minimum expectations but there are several weaknesses including reporting to the Board of Directors and Board of Commissioners that require management attention. k. Human resources are fairly adequate in terms of quantity and competence in the Risk Management function for Liquidity Risk.
l. The internal control system is fairly effective in supporting the implementation of Risk Management for Liquidity Risk.
m. Implementation of independent review by internal audit work units and functions conducting independent review is fairly adequate. There are several weaknesses in methodology, frequency, as well as reporting to the Board of Directors and Board of Commissioners that require management attention. n. There are fairly significant weaknesses based on the results of independent review. o. Follow-up on independent review has been implemented fairly adequately. Marginal (4) Quality of implementation of Risk Management for Liquidity Risk is less adequate. There are significant weaknesses in various aspects of Risk Management for Liquidity Risk that require immediate corrective action. Examples of Bank characteristics included in the Marginal (4) rating are as follows:
a. Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with the Bank's overall strategic objectives and business strategy. b. Significant weaknesses in (awareness) and understanding of the Board of Directors and Board of Commissioners regarding Risk Management for Liquidity Risk.
c. Risk Management Culture for Liquidity Risk is not strong and has not been internalized well at every level of the organization.
Rating Definition Rating d. Execution of duties by the Board of Directors and Board of Commissioners as a whole is less adequate. There are several weaknesses in some assessment aspects that need to be repaired immediately. e. Significant weaknesses in the Risk Management function for Liquidity Risk that require immediate repair. f. Delegation of authority is weak and not controlled and monitored well. g. Liquidity management strategy is less adequate. There are weaknesses in liquidity management aspects that require immediate repair. h. Significant weaknesses in Risk Management policies and procedures as well as the establishment of Liquidity Risk limits.
i. The Risk Management process for Liquidity Risk is less adequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
j. Significant weaknesses in the Liquidity Risk Management Information System including reporting to the Board of Directors and Board of Commissioners that require immediate repair. k. Human resources are less adequate in terms of quantity and competence in the Risk Management function for Liquidity Risk.
l. The internal control system is less effective in supporting the implementation of Risk Management for Liquidity Risk.
m. Implementation of independent review by internal audit work units and functions conducting independent review is less adequate. There are weaknesses in methodology, frequency, as well as reporting to the Board of Directors and Board of Commissioners that require immediate repair. n. There are significant weaknesses based on the results of independent review that require immediate repair action. o. Follow-up on independent review is less adequate.
Rating Definition Rating
Unsatisfactory
(5)
Quality of implementation of Risk Management for Liquidity Risk is inadequate. There are significant weaknesses in various aspects of Risk Management for Liquidity Risk where resolution actions are beyond management's capability. Examples of Bank characteristics included in the Unsatisfactory (5) rating are as follows:
a. Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with the Bank's overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners' (awareness) and understanding of Risk Management for Liquidity Risk is very weak.
c. Risk Management Culture for Liquidity Risk is not strong or does not exist at all.
d. Execution of duties by the Board of Directors and Board of Commissioners is inadequate. There are significant weaknesses in almost all assessment aspects where resolution actions are beyond the Bank's capability. e. Significant weaknesses in the Risk Management function for Liquidity Risk that require fundamental repair. f. Delegation of authority is very weak or non-existent. g. Liquidity management strategy is inadequate. There are weaknesses in almost all aspects of liquidity management that require immediate repair. h. Very significant weaknesses in Risk Management policies and procedures as well as the establishment of Liquidity Risk limits.
i. The Risk Management process for Liquidity Risk is inadequate in identifying, measuring, monitoring, and controlling Liquidity Risk.
j. Fundamental weaknesses in the Liquidity Risk Management Information System. Liquidity Risk reporting to the Board of Directors and Board of Commissioners is very inadequate. k. Human resources are inadequate in terms of quantity and competence in the Risk Management function for Liquidity Risk.
Rating Definition Rating
l. The internal control system is ineffective in supporting the implementation of Risk Management for Liquidity Risk.
m. Implementation of independent review by internal audit work units and functions conducting independent review is inadequate. There are weaknesses in methodology, frequency, as well as reporting to the Board of Directors and Board of Commissioners that require fundamental repair. n. There are very significant weaknesses based on the results of independent review where repair actions are beyond management's capability. o. Follow-up on independent review is inadequate
APPENDIX II.2.5.a
Inherent Risk Level Determination Matrix for Operational Risk Rating Definition Rating Low (1) Considering the business activities conducted by the Bank, the potential losses the Bank faces from Operational Risk are considered very low over a certain period of time in the future. Examples of Bank characteristics included in the Low (1) rating are as follows:
a. The Bank's business has very simple characteristics. Products and activities are not varied, business mechanisms are very simple, transaction volume is low, organizational structure is not complex, there are no significant corporate actions, and outsourcing usage is very minimal. b. Human resources are very adequate, both in terms of quantity sufficiency and quality of human resources. Historical data on losses due to human error is not significant.
c. Information technology is very mature (mature) and there are no significant changes in information technology systems. Information technology vulnerability to disruption or attack is very low. Supporting infrastructure is very reliable in supporting the Bank's business.
d. Frequency and materiality of internal and external fraud are very low and losses caused are not significant compared to transaction volume or revenue. e. Threat of business disruption as a result of external events is very low. Low to Moderate (2) Considering the business activities conducted by the Bank, the potential losses the Bank faces from Operational Risk are low over a certain period of time in the future.
Rating Definition Rating
Examples of Bank characteristics included in the Low to Moderate (2) rating are as follows:
a. The Bank's business has very simple characteristics. Products and activities are relatively less varied, business mechanisms are simple, transaction volume is relatively low, organizational structure is less complex, corporate actions are less significant, and outsourcing usage is minimal. b. Human resources are adequate, both in terms of quantity sufficiency and quality of human resources. Historical data on losses due to human error is less significant.
c. Information technology is relatively mature (mature) and there are no significant changes in information technology systems. Information technology vulnerability to disruption or attack is low. Supporting infrastructure is reliable in supporting the Bank's business.
d. Frequency and materiality of internal and external fraud are low and losses caused are less significant compared to transaction volume or Bank revenue. e. Threat of business disruption as a result of external events is low. Moderate (3) Considering the business activities conducted by the Bank, the potential losses the Bank faces from Operational Risk are considered fairly high over a certain period of time in the future. Examples of Bank characteristics included in the Moderate (3) rating are as follows:
a. The Bank's business has fairly complex characteristics. Products and activities are fairly varied, business mechanisms are fairly complex, transaction volume is fairly high, organizational structure is fairly complex, corporate actions are fairly significant, and outsourcing usage is fairly significant. b. Human resources are fairly adequate, both in terms of quantity sufficiency and quality. Historical data on losses due to human error is fairly significant.
Rating Definition Rating
c. Information technology is moving towards maturity and significant changes may occur in information technology systems. Information technology is fairly vulnerable to disruption or attack. Supporting infrastructure is fairly reliable in supporting the Bank's business.
d. Frequency and materiality of internal and external fraud are fairly high and losses caused are fairly significant compared to transaction volume or revenue. e. Threat of business disruption as a result of external events is fairly high. Moderate to High (4) Considering the business activities conducted by the Bank, the potential losses the Bank faces from Operational Risk are considered high over a certain period of time in the future. Examples of Bank characteristics included in the Moderate to High (4) rating are as follows:
a. The Bank's business has complex characteristics. Products and activities are varied, business mechanisms are complex, transaction volume is high, organizational structure is complex, corporate actions are significant, and outsourcing usage is significant. b. Human resources are adequate, both in terms of quantity sufficiency and quality. Historical data on losses due to human error is significant.
c. Information technology is not mature and significant changes occur in information technology systems. Information technology is vulnerable to disruption or attack. Supporting infrastructure is less reliable in supporting the Bank's business.
d. Frequency and materiality of internal and external fraud are high and losses caused are significant compared to transaction volume or revenue. e. Threat of business disruption as a result of external events is high.
Rating Definition Rating
High (5) Considering the business activities conducted by the Bank, the potential losses the Bank faces from Operational Risk are considered very high over a certain period of time in the future. Examples of Bank characteristics included in the High (5) rating are as follows:
a. The Bank's business has very complex characteristics. Products and activities are very varied, business mechanisms are very complex, transaction volume is very high, organizational structure is very complex, corporate actions are significant, and outsourcing usage is very high. b. Human resources are inadequate, both in terms of quantity sufficiency and quality. Historical data on losses due to human error is very significant.
c. Information technology is not mature and significant changes occur in information technology systems. Information technology is very vulnerable to disruption or attack. Supporting infrastructure is unreliable in supporting the Bank's business.
d. Frequency and materiality of internal and external fraud are very high and losses caused are very significant compared to transaction volume or revenue. e. Threat of business disruption as a result of external events is very high.
APPENDIX II.2.5.b
For Operational Risk
Rating Definition Rating
Strong (1) Quality of implementation of Risk Management for Operational Risk is very adequate. There are minor weaknesses that are not significant so they can be ignored.
Examples of Bank characteristics included in the Strong (1) rating are as follows:
a. Formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has aligned with the overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have very good (awareness) and understanding of Risk Management for Operational Risk.
c. Risk Management Culture for Operational Risk is very strong and has been internalized very well at all levels of the organization.
d. Execution of duties by the Board of Directors and Board of Commissioners as a whole is very adequate. e. The Risk Management function for Operational Risk is independent, has clear tasks and responsibilities, and has operated very well. f. Delegation of authority has operated very well. g. Operational Risk strategy is very aligned with the level of Risk to be taken and Operational Risk tolerance. h. Risk Management policies and procedures as well as the establishment of Operational Risk limits are very adequate and available for all areas of Risk Management for Operational Risk, aligned with implementation, and well understood by employees.
Excellent (1)
The quality of Operational Risk Management application is excellent. There are no significant weaknesses.
Examples of characteristics of Banks included in the Excellent (1) rating include the following:
i. The Risk Management Process for Operational Risk is very adequate in identifying, measuring, monitoring, and controlling Operational Risk.
j. Business continuity management is very reliable and very well-tested. k. The Operational Risk Management Information System is very good, producing comprehensive and integrated Operational Risk Reports to the Board of Directors and Board of Commissioners.
l. Human resources are very adequate in terms of quantity and competence in the Operational Risk Management function.
m. The internal control system is very effective in supporting the implementation of Operational Risk Management. n. The implementation of independent review by the internal audit unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. o. Generally, there are no significant weaknesses based on the results of independent review. p. Follow-up on independent review has been carried out very adequately.
Satisfactory (2)
The quality of Operational Risk Management application is adequate. There are some minor weaknesses that can be resolved in normal business activities.
Examples of characteristics of Banks included in the Satisfactory (2) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with the overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have Operational Risk Management awareness.
c. The Operational Risk Management culture is strong and has been well internalized at all levels of the organization.
d. The implementation of the duties of the Board of Directors and Board of Commissioners is generally adequate. There are some weaknesses but not significant and can be repaired immediately. e. The Operational Risk Management function is independent, has clear duties and responsibilities, and has run well. There are minor weaknesses, but they can be resolved in normal business activities. f. Delegation of authority has run well. g. Operational Risk Strategy aligns with the level of Risk to be taken and Operational Risk tolerance. h. Risk Management policies and procedures and the establishment of Operational Risk limits are adequate and available for all areas of Operational Risk Management, aligned with implementation, and well understood by employees despite minor weaknesses.
i. The Risk Management Process for Operational Risk is adequate in identifying, measuring, monitoring, and controlling Operational Risk.
j. Business continuity management is reliable and tested. k. The Operational Risk Management Information System is good, including Operational Risk reporting to the Board of Directors and Board of Commissioners. There are minor weaknesses that can be easily repaired.
l. Human resources are adequate, both in terms of quantity and competence in the Operational Risk Management function.
m. The internal control system is effective in supporting the implementation of Operational Risk Management. n. The implementation of independent review by the internal audit unit and functions performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. o. There are weaknesses that are not significant based on the results of independent review. p. Follow-up on independent review has been carried out adequately.
Fair (3)
The quality of Operational Risk Management application is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of characteristics of Banks included in the Fair (3) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is fairly adequate but not always aligned with the overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have sufficient (awareness) and understanding regarding Operational Risk Management.
c. The Operational Risk Management culture is fairly strong and has been internalized fairly well but not always implemented consistently.
d. The implementation of the duties of the Board of Directors and Board of Commissioners is generally fairly adequate. e. The Operational Risk Management function is fairly good, but there are some weaknesses that need management attention. f. Delegation of authority has run fairly well. g. Operational Risk Strategy is fairly aligned with the level of Risk to be taken and Operational Risk tolerance. h. Risk Management policies and procedures and the establishment of Operational Risk limits are fairly adequate but not always consistent with implementation.
i. The Risk Management Process for Operational Risk is fairly adequate in identifying, measuring, monitoring, and controlling Operational Risk.
j. Business continuity management is fairly reliable. k. The Operational Risk Management Information System meets minimum expectations but there are some weaknesses including reporting to the Board of Directors and Board of Commissioners that require management attention.
l. Human resources are fairly adequate in terms of quantity and competence in the Operational Risk Management function.
m. The internal control system is fairly effective in supporting the implementation of Operational Risk Management. n. The implementation of independent review by the internal audit unit and functions performing independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention. o. There are weaknesses that are fairly significant based on the results of independent review that require management attention. p. Follow-up on independent review has been carried out fairly adequately.
Marginal (4)
The quality of Operational Risk Management application is less adequate. There are significant weaknesses in various aspects of Operational Risk Management that require immediate corrective action. Examples of characteristics of Banks included in the Marginal (4) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with the overall strategic objectives and business strategy. b. Significant weaknesses in the awareness (awareness) and understanding of the Board of Directors and Board of Commissioners regarding Operational Risk Management.
c. The Operational Risk Management culture is not strong and has not been well internalized at every level of the organization.
d. The implementation of the duties of the Board of Directors and Board of Commissioners is generally less adequate. There are weaknesses in various assessment aspects that require immediate repair. e. Significant weaknesses in the Operational Risk Management function that require immediate repair. f. Delegation of authority is weak. g. Operational Risk Strategy is less aligned with the level of Risk to be taken and Operational Risk tolerance. h. Significant weaknesses in Risk Management policies and procedures and the establishment of Operational Risk limits.
i. The Risk Management Process for Operational Risk is less adequate in identifying, measuring, monitoring, and controlling Operational Risk.
j. Business continuity management is less reliable. k. Significant weaknesses in the Operational Risk Management Information System including reporting to the Board of Directors and Board of Commissioners that require immediate repair.
l. Human resources are less adequate in terms of quantity and competence in the Operational Risk Management function.
m. The internal control system is less effective in supporting the implementation of Operational Risk Management. n. The implementation of independent review by the internal audit unit and functions performing independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate repair. o. There are significant weaknesses based on the results of independent review that require immediate repair. p. Follow-up on independent review is less adequate.
Unsatisfactory (5)
The quality of Operational Risk Management application is inadequate. There are significant weaknesses in various aspects of Operational Risk Management whose resolution is beyond the capability of management. Examples of characteristics of Banks included in the Unsatisfactory (5) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with the overall strategic objectives and business strategy of the Bank. b. Awareness (awareness) and understanding of the Board of Directors and Board of Commissioners regarding Operational Risk Management are very weak.
c. The Operational Risk Management culture is not strong or does not exist at all.
d. The implementation of the duties of the Board of Directors and Board of Commissioners is inadequate. There are significant weaknesses in almost all assessment aspects and the resolution is beyond the Bank's capability. e. Significant weaknesses in the Operational Risk Management function that require fundamental repair. f. Delegation of authority is very weak. g. Operational Risk Strategy is not aligned with the level of Risk to be taken and Operational Risk tolerance. h. Very significant weaknesses in Risk Management policies and procedures and the establishment of Operational Risk limits.
i. The Risk Management Process for Operational Risk is inadequate in identifying, measuring, monitoring, and controlling Operational Risk.
j. Business continuity management is not reliable. k. Fundamental weaknesses in the Operational Risk Management Information System.
l. Human resources are inadequate in terms of quantity and competence in the Operational Risk Management function.
m. The internal control system is ineffective in supporting the implementation of Operational Risk Management. n. The implementation of independent review by the internal audit unit and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental repair. o. There are very significant weaknesses based on the results of independent review that require immediate repair. p. Follow-up on independent review is inadequate.
Matrix for Determining Inherent Risk Level for Legal Risk
Low (1)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Legal Risk is classified as very low during a certain period in the future. Examples of characteristics of Banks included in the Low (1) rating include the following:
a. There are no litigation processes occurring at the Bank or there are litigation processes but the frequency and/or financial impact of insignificant lawsuits do not disturb the Bank's financial condition and do not have a large impact on the Bank's reputation. b. Agreements made by the Bank are very adequate.
c. All Bank products and/or activities are in accordance with legislation.
Low to Moderate (2)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Legal Risk is classified as low during a certain period in the future. Examples of characteristics of Banks included in the Low to Moderate (2) rating include the following:
a. There are litigation processes occurring at the Bank but the frequency and/or financial impact of lawsuits is less significant in disturbing the Bank's financial condition and less impactful on the Bank's reputation. b. Agreements made by the Bank are adequate.
c. There are products and/or activities that are not regulated in legislation in an insignificant amount.
Moderate (3)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Legal Risk is classified as fairly high during a certain period in the future. Examples of characteristics of Banks included in the Moderate (3) rating include the following:
a. There are litigation processes occurring at the Bank with a frequency and/or financial impact of lawsuits that is fairly significant but less disturbing to the Bank's financial condition, although there is a possibility of emerging Reputational Risk for the Bank. b. Agreements made by the Bank are fairly adequate.
c. There are products and/or activities that are not regulated in legislation in a fairly significant amount.
Moderate to High (4)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Legal Risk is classified as high during a certain period in the future. Examples of characteristics of Banks included in the Moderate to High (4) rating include the following:
a. There are litigation processes occurring at the Bank and the frequency and/or financial impact of lawsuits is significant so that if the Bank loses, compensation for such lawsuits can disturb the Bank's financial condition and have a large impact on the Bank's reputation. b. Agreements made by the Bank are less adequate.
c. There are products and/or activities that are not regulated in legislation in a significant amount.
High (5)
Considering the business activities conducted by the Bank, the possibility of losses faced by the Bank from Legal Risk is classified as very high during a certain period in the future. Examples of characteristics of Banks included in the High (5) rating include the following:
a. There are litigation processes against the Bank by Bank customers or debtors in a frequency and/or financial impact that is very significant so that if the Bank loses in a court decision, such conditions can significantly affect the Bank's business condition. b. Agreements made by the Bank are inadequate.
c. There are products and/or activities that are not regulated in legislation in a very significant amount.
For Legal Risk
Strong (1)
The quality of Legal Risk Management application is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored.
Examples of characteristics of Banks included in the Strong (1) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has aligned with the overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have very good awareness (awareness) and understanding regarding Legal Risk Management.
c. The Legal Risk Management culture is very strong and has been internalized very well at all levels of the organization.
d. The implementation of the duties of the Board of Directors and Board of Commissioners overall is very adequate. e. The Legal Risk Management function is independent, has clear duties and responsibilities, and has run very well. f. Delegation of authority is controlled and monitored regularly and has run very well. g. Legal Risk Strategy is very aligned with the level of Risk to be taken and Risk tolerance. h. Risk Management policies and procedures for Legal Risk are very adequate and available for all areas of Legal Risk Management, aligned with implementation, and well understood by employees.
i. The Risk Management Process for Legal Risk is very adequate in identifying, measuring, monitoring, and controlling Legal Risk.
j. The Legal Risk Management Information System is very good, producing comprehensive Legal Risk reports integrated to the Board of Directors and Board of Commissioners. k. Human resources are very adequate in terms of quantity and competence in the Legal Risk Management function.
l. The internal control system is very effective in supporting the implementation of Risk Management.
m. The implementation of independent review by the internal audit unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. Generally, there are no significant weaknesses based on the results of independent review. o. Follow-up on independent review has been carried out very adequately.
Satisfactory (2)
The quality of Legal Risk Management application is adequate although there are some minor weaknesses that can be resolved in normal business activities.
Examples of characteristics of Banks included in the Satisfactory (2) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with the overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have good awareness (awareness) and understanding regarding Legal Risk Management.
c. The Legal Risk Management culture is strong and has been internalized well at all levels of the organization.
d. The implementation of the duties of the Board of Directors and Board of Commissioners is generally adequate. There are some weaknesses that are not significant and can be repaired immediately. e. The Legal Risk Management function has clear duties and responsibilities and has run well. There are minor weaknesses that can be resolved in normal business activities. f. Delegation of authority is controlled and monitored regularly and has run well. g. Legal Risk Strategy aligns with the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance). h. Risk Management policies and procedures for Legal Risk are adequate and available for all areas of Legal Risk Management, aligned with implementation, and well understood by employees despite minor weaknesses.
i. The Risk Management Process for Legal Risk is adequate in identifying, measuring, monitoring, and controlling Legal Risk.
j. The Legal Risk Management Information System is good, including Legal Risk reporting to the Board of Directors and Board of Commissioners. There are minor weaknesses but can be easily repaired. k. Human resources are adequate both in terms of quantity and competence in the Legal Risk Management function.
l. The internal control system is effective in supporting the implementation of Risk Management.
m. The implementation of independent review by the internal audit unit and functions performing independent review is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. There are weaknesses but not significant based on the results of independent review. o. Follow-up on independent review has been carried out adequately.
Fair (3)
The quality of Legal Risk Management application is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention.
Examples of characteristics of Banks included in the Fair (3) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is fairly adequate but not always aligned with the overall strategic objectives and business strategy. b. The Board of Directors and Board of Commissioners have fairly good awareness (awareness) and understanding regarding Legal Risk Management.
c. The Legal Risk Management culture is fairly strong and has been internalized fairly well but not always implemented consistently.
d. The implementation of the duties of the Board of Directors and Board of Commissioners is generally fairly adequate. There are weaknesses in some assessment aspects that need management attention. e. The Legal Risk Management function is fairly good, but there are some weaknesses that need management attention. f. Delegation of authority is fairly good, but control and monitoring are not always carried out well. g. Legal Risk Strategy is fairly aligned with the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance). h. Risk Management policies and procedures for Legal Risk are fairly adequate but not always consistent with implementation.
i. The Risk Management Process for Legal Risk is fairly adequate in identifying, measuring, monitoring, and controlling Legal Risk.
j. The Legal Risk Management Information System meets minimum expectations but there are some weaknesses including reporting to the Board of Directors and Board of Commissioners that require management attention. k. Human resources are fairly adequate both in terms of quantity and competence in the Legal Risk Management function.
l. The internal control system is fairly effective in supporting the implementation of Risk Management.
m. The implementation of independent review by the internal audit unit and functions performing independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention. n. There are weaknesses that are fairly significant based on the results of independent review that require management attention. o. Follow-up on independent review has been carried out fairly adequately.
Marginal (4)
The quality of Legal Risk Management application is less adequate. There are significant weaknesses in various aspects of Legal Risk Management that require immediate corrective action. Examples of characteristics of Banks included in the Marginal (4) rating include the following:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less adequate and not aligned with the overall strategic objectives and business strategy. b. Significant weaknesses in the awareness (awareness) and understanding of the Board of Directors and
Unsatisfactory (5)
The quality of Legal Risk Management application is inadequate. There are significant weaknesses in various aspects of Legal Risk Management where remedial actions are beyond management's capability. Examples of Bank characteristics included in the Unsatisfactory (5) rating include the following:
a. Formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and has no connection with the Bank's strategic objectives and overall business strategy. b. The Board of Directors and Board of Commissioners' awareness and understanding of Legal Risk Management is very weak.
c. Legal Risk Management culture is not strong or does not exist at all.
d. Significant weaknesses in the Legal Risk Management function requiring fundamental improvement. e. Delegation of authority is very weak or non-existent. f. Legal Risk Strategy is not aligned with the level of risk to be taken and risk tolerance. g. Legal Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Legal Risk. h. Fundamental weaknesses in the Legal Risk Management Information System. Reporting of Legal Risk to the Board of Directors and Board of Commissioners is very inadequate.
i. Human resources are inadequate in terms of both quantity and competence in the Legal Risk Management function.
j. Internal control system is ineffective in supporting the implementation of Risk Management. k. Implementation of independent review by the internal audit unit and functions performing independent review is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners requiring fundamental improvement.
l. There are very significant weaknesses based on independent review results where remedial actions are beyond management's capability.
m. Follow-up on independent review is inadequate.
Appendix II.2.7.a
Low (1)
Considering the Bank's business activities, the potential losses the Bank faces from Reputational Risk are classified as very low during a certain period in the future.
Examples of Bank characteristics included in the Low (1) rating include the following:
a. Generally, there is no negative reputational influence from the Bank's owners and related companies; rather, it is expected that the Bank's owners and related companies can provide a very positive influence on the Bank's reputation. b. Violations or potential violations of business ethics are very minimal. The Bank has a reputation as a company that highly upholds business ethics.
c. The Bank's products are not complex and are easy for customers to understand.
d. Business cooperation with business partners is very minimal in number. e. The frequency of negative news coverage about the Bank is very minimal; negative news is very immaterial, and the scope of coverage is limited. f. The frequency of customer complaints is very minimal and very immaterial.
Low to Moderate (2)
Considering the Bank's business activities, the potential losses the Bank faces from Reputational Risk are classified as low during a certain period in the future.
Examples of Bank characteristics included in the Low to Moderate (2) rating include the following:
a. There is a negative reputational influence from the Bank's owners and related companies, but the scale of influence is small and can be well mitigated. b. Violations or potential violations of business ethics are minimal, and the Bank has a reputation as a company that upholds business ethics.
c. The Bank's products are simple, so they relatively do not require special customer understanding.
d. Business cooperation with business partners is minimal in number. e. The frequency of negative news coverage about the Bank is minimal; negative news is immaterial, and the scope of coverage is small relative to the Bank's scale. f. The frequency of customer complaints is minimal and immaterial.
Moderate (3)
Considering the Bank's business activities, the potential losses the Bank faces from Reputational Risk are classified as moderately high during a certain period in the future. Examples of Bank characteristics included in the Moderate (3) rating include the following:
a. There is a negative reputational influence from the Bank's owners and related companies with a fairly large scale of influence but still controllable. b. Violations or potential violations of business ethics occur, but the scale of influence is fairly significant and requires management attention.
c. The Bank's products are fairly complex, so to some extent they require special customer understanding.
d. Business cooperation with business partners is fairly numerous. e. The frequency of negative news coverage about the Bank is fairly high; negative news is fairly material, and the scope of coverage is fairly wide relative to the Bank's scale. f. The frequency of customer complaints is fairly high and fairly material.
Moderate to High (4)
Considering the Bank's business activities, the potential losses the Bank faces from Reputational Risk are classified as high during a certain period in the future.
Examples of Bank characteristics included in the Moderate to High (4) rating include the following:
a. There is a negative reputational influence from the Bank's owners and related companies with a material scale of influence requiring special management attention. b. Violations or potential violations of business ethics occur with a material scale of influence requiring special attention.
c. The Bank's products are complex, requiring special customer understanding.
d. Business cooperation with business partners is material in number. e. The frequency of negative news coverage about the Bank is high; negative news is material, and the scope of coverage is large relative to the Bank's scale. f. The frequency of customer complaints is high and material.
High (5)
Considering the Bank's business activities, the potential losses the Bank faces from Reputational Risk are classified as very high during a certain period in the future.
Examples of Bank characteristics included in the High (5) rating include the following:
a. There is a negative reputational influence from the Bank's owners and related companies with a very material scale of influence requiring immediate follow-up and management. b. Violations or potential violations of business ethics occur with a very material scale of influence requiring immediate follow-up and management.
c. The Bank's products are very complex, requiring very special customer understanding.
d. Business cooperation with business partners is material in number. e. The frequency of negative news coverage about the Bank is very high; negative news is very material, and the scope of coverage is very large relative to the Bank's scale. f. The frequency of customer complaints is very high and very material.
Appendix II.2.7.b
Strong (1)
The quality of Reputational Risk Management application is very adequate. There are minor weaknesses that are not significant and can be ignored.
Examples of Bank characteristics included in the Strong (1) rating include the following:
a. The Board of Directors and Board of Commissioners have very good awareness and understanding of Reputational Risk Management. b. The formulation of the level of risk to be taken (risk appetite) and risk tolerance is very adequate and has been aligned with strategic objectives and overall business strategy.
c. Reputational Risk Management culture is very strong and has been internalized very well at all levels of the organization.
d. The implementation of duties by the Board of Directors and Board of Commissioners is overall very adequate. e. The Reputational Risk Management function is independent, has clear duties and responsibilities, and has operated very well. f. Delegation of authority is controlled and monitored periodically and has operated very well. g. Reputational Risk Strategy is very aligned with the level of risk to be taken and risk tolerance. h. Reputational Risk Management policies and procedures are very adequate and available for all areas of Reputational Risk Management, aligned with implementation, and well understood by employees.
i. The Reputational Risk Management process is very adequate in identifying, measuring, monitoring, and controlling Reputational Risk.
j. The Reputational Risk Management Information System is very good, producing comprehensive and integrated Reputational Risk Reports to the Board of Directors and Board of Commissioners. k. Human resources are very adequate in terms of both quantity and competence in the Reputational Risk Management function.
l. The internal control system is very effective in supporting the implementation of Risk Management for Reputational Risk.
m. Implementation of independent review by the internal audit unit and functions performing independent review is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. Generally, there are no significant weaknesses based on independent review results. o. Follow-up on independent review has been implemented very adequately.
Satisfactory (2)
The quality of Reputational Risk Management application is adequate, although there are some minor weaknesses, but these weaknesses can be resolved in normal business activities. Examples of Bank characteristics included in the Satisfactory (2) rating include the following:
a. The Board of Directors and Board of Commissioners have Reputational Risk Management awareness. b. The formulation of the level of risk to be taken (risk appetite) and risk tolerance is adequate and has been aligned with strategic objectives and overall business strategy.
c. Reputational Risk Management culture is strong and has been internalized well at all levels of the organization.
d. The implementation of duties by the Board of Directors and Board of Commissioners is generally adequate. There are some weaknesses but not significant and can be improved immediately. e. The Reputational Risk Management function has clear duties and responsibilities and has operated well. There are minor weaknesses that can be resolved in normal business activities. f. Delegation of authority is controlled and monitored periodically and has operated well. g. Reputational Risk Strategy is aligned with the level of risk to be taken and risk tolerance. h. Reputational Risk Management policies and procedures are adequate and available for all areas of Reputational Risk Management, aligned with implementation, and well understood by employees, although there are minor weaknesses.
i. The Reputational Risk Management process is adequate in identifying, measuring, monitoring, and controlling Reputational Risk.
j. The Reputational Risk Management Information System is good, including reporting of Reputational Risk to the Board of Directors and Board of Commissioners. There are minor weaknesses that can be easily improved. k. Human resources are adequate in terms of both quantity and competence in the Reputational Risk Management function.
l. The internal control system is effective in supporting the implementation of Risk Management for Reputational Risk.
m. Implementation of independent review by the internal audit unit and functions performing independent review is adequate, both in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. There are weaknesses that are not significant based on independent review results. o. Follow-up on independent review has been implemented adequately.
Fair (3)
The quality of Reputational Risk Management application is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Bank characteristics included in the Fair (3) rating include the following:
a. The Board of Directors and Board of Commissioners have fairly good awareness and understanding of Reputational Risk Management. b. The formulation of the level of risk to be taken (risk appetite) and risk tolerance is fairly adequate but not always aligned with strategic objectives and overall business strategy.
c. Reputational Risk Management culture is fairly strong and has been internalized fairly well but not always implemented consistently.
d. The implementation of duties by the Board of Directors and Board of Commissioners is generally fairly adequate. There are weaknesses in some assessment aspects that need management attention. e. The Reputational Risk Management function is fairly good, but there are some weaknesses that need management attention. f. Delegation of authority is fairly good, but control and monitoring are not always implemented well. g. Reputational Risk Strategy is fairly aligned with the level of risk to be taken and risk tolerance. h. Reputational Risk Management policies and procedures are fairly adequate but not always consistent with implementation.
i. The Reputational Risk Management process is fairly adequate in identifying, measuring, monitoring, and controlling Reputational Risk.
j. The Reputational Risk Management Information System meets minimum expectations but has some weaknesses, including reporting to the Board of Directors and Board of Commissioners that requires management attention. k. Human resources are fairly adequate in terms of both quantity and competence in the Reputational Risk Management function.
l. The internal control system is fairly effective in supporting the implementation of Risk Management for Reputational Risk.
m. Implementation of independent review by the internal audit unit and functions performing independent review is fairly adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention. n. There are fairly significant weaknesses based on independent review results that require management attention. o. Follow-up on independent review has been implemented fairly adequately.
Marginal (4)
The quality of Reputational Risk Management application is less adequate. There are significant weaknesses in various aspects of Reputational Risk Management requiring immediate corrective action. Examples of Bank characteristics included in the Marginal (4) rating include the following:
a. Significant weaknesses in the awareness and understanding of the Board of Directors and Board of Commissioners regarding Reputational Risk Management. b. The formulation of the level of risk to be taken (risk appetite) and risk tolerance is less adequate and not aligned with strategic objectives and overall business strategy.
c. Reputational Risk Management culture is less strong and has not been internalized well at every level of the organization.
d. The implementation of duties by the Board of Directors and Board of Commissioners is generally less adequate. There are weaknesses in various assessment aspects requiring immediate improvement. e. Significant weaknesses in the Reputational Risk Management function requiring immediate improvement. f. Delegation of authority is weak and not controlled and monitored well. g. Reputational Risk Strategy is less aligned with the level of risk to be taken and risk tolerance. h. Significant weaknesses in Reputational Risk Management policies and procedures and the setting of Reputational Risk limits.
i. The Reputational Risk Management process is less adequate in identifying, measuring, monitoring, and controlling Reputational Risk.
j. Significant weaknesses in the Reputational Risk Management Information System, including reporting to the Board of Directors and Board of Commissioners, requiring immediate improvement. k. Human resources are less adequate in terms of both quantity and competence in the Reputational Risk Management function.
l. The internal control system is less effective in supporting the implementation of Risk Management for Reputational Risk.
m. Implementation of independent review by the internal audit unit and functions performing independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners requiring immediate improvement. n. There are significant weaknesses based on independent review results requiring immediate remedial action. o. Follow-up on independent review is less adequate.
Unsatisfactory (5)
The quality of Reputational Risk Management application is inadequate. There are significant weaknesses in various aspects of Reputational Risk Management where remedial actions are beyond management's capability. Examples of Bank characteristics included in the Unsatisfactory (5) rating include the following:
a. The Board of Directors and Board of Commissioners' awareness and understanding of Reputational Risk Management is very weak. b. The formulation of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and has no connection with the Bank's strategic objectives and overall business strategy.
c. Reputational Risk Management culture is not strong or does not exist at all.
d. Significant weaknesses in the Reputational Risk Management function requiring fundamental improvement. e. Delegation of authority is very weak or non-existent. f. Reputational Risk Strategy is not aligned with the level of risk to be taken and risk tolerance. g. The Reputational Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Reputational Risk. h. Fundamental weaknesses in the Reputational Risk Management Information System. Reporting of Reputational Risk to the Board of Directors and Board of Commissioners is very inadequate.
i. Human resources are inadequate in terms of both quantity and competence in the Reputational Risk Management function.
j. The internal control system is ineffective in supporting the implementation of Risk Management for Reputational Risk. k. Implementation of independent review by the internal audit unit and functions performing independent review is less adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners requiring fundamental improvement.
l. There are very significant weaknesses based on independent review results where remedial actions are beyond management's capability.
m. Follow-up on independent review is inadequate.
Appendix II.2.8.a
Low (1)
Considering the Bank's business activities, the potential losses the Bank faces from Strategic Risk are classified as very low during a certain period in the future.
Examples of Bank characteristics included in the Low (1) rating include the following:
a. The Bank's strategy is conservative or low-risk. b. The Bank's products and/or activities are stable, not complex, and diversified.
c. The Bank continues existing strategies with a high level of strategic success.
d. The Bank has stable competitive advantages and no threats from competitors. e. Business plan achievement is very adequate.
Low to Moderate (2)
Considering the Bank's business activities, the potential losses the Bank faces from Strategic Risk are classified as low during a certain period in the future.
Examples of Bank characteristics included in the Low to Moderate (2) rating include the following:
a. The Bank's strategy is low-risk but with an increasing trend. b. The Bank's products and/or activities are not complex and diversified.
c. The Bank continues the same strategy or has some new strategies but still within the Bank's core business and competencies.
d. The Bank has competitive advantages and competitor threats are minor. e. Business plan achievement is adequate.
Considering the Bank's business activities, the potential losses the Bank faces from Strategic Risk are considered moderately high over a certain period in the future.
Examples of Bank characteristics included in the Moderate (3) rating are as follows:
a. The Bank's strategy is considered moderately risky. b. The Bank's products and/or activities are generally diversified, but some are considered complex.
c. The Bank's strategy success rate is considered moderate due to threats from competitors.
d. The Bank has moderate competitive advantages and there are threats from competitors. e. Business plan achievement is quite adequate.
Considering the Bank's business activities, the potential losses the Bank faces from Strategic Risk are considered high over a certain period in the future.
Examples of Bank characteristics included in the Moderate to High (4) rating are as follows:
a. The Bank's strategy is considered moderately risky but with an increasing trend. b. Some of the Bank's products and/or activities are concentrated and considered complex.
c. The Bank implements strategies to enter new businesses or markets with an uncertain success rate.
d. The Bank lacks competitive advantages, or there are significant threats from competitors. e. Business plan achievement is inadequate.
Considering the Bank's business activities, the potential losses the Bank faces from Strategic Risk are considered very high over a certain period in the future.
Examples of Bank characteristics included in the High (5) rating are as follows:
a. The Bank's strategy is considered highly risky. b. The Bank's products and/or business activities are highly concentrated and considered complex.
c. The majority of the Bank's strategies shift to areas different from the main business lines and the Bank's competencies.
d. The Bank has no competitive advantages and there are very significant threats from competitors. e. The Bank's business plan achievement is inadequate.
For Strategic Risk
The quality of Strategic Risk Risk Management implementation is very adequate. There are minor weaknesses that are not significant and can be ignored.
Examples of Bank characteristics included in the Strong (1) rating are as follows:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has aligned with strategic objectives and overall business strategy. b. The Board of Directors and Board of Commissioners have very good awareness (awareness) and understanding of Risk Management for Strategic Risk, sources of Strategic Risk, and the level of Strategic Risk at the Bank.
c. The Strategic Risk Risk Management culture is very strong and has been internalized very well at all levels of the organization.
d. The execution of the duties of the Board of Directors and Board of Commissioners as a whole is very adequate. e. The Strategic Risk Risk Management function is independent, has clear duties and responsibilities, and has operated very well. f. The delegation of authority is controlled and monitored periodically, and has operated very well. g. Policies and procedures for Strategic Risk Risk Management are very adequate and available for all areas of Strategic Risk Risk Management, aligned with implementation, and understood well by employees. h. The Strategic Risk Risk Management process is very adequate in identifying, measuring, monitoring, and controlling Strategic Risk.
i. The Strategic Risk Information System is very good, thereby generating comprehensive and integrated Strategic Risk Reports to the Board of Directors and Board of Commissioners.
j. Human resources are very adequate in terms of quantity and competence in the Strategic Risk Risk Management function. k. The internal control system is very effective in supporting the implementation of Strategic Risk Risk Management.
l. The implementation of independent reviews by internal audit units and functions conducting independent reviews is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.
m. Generally, there are no significant weaknesses based on the results of independent reviews. n. Follow-up on independent reviews has been implemented very adequately.
The quality of Strategic Risk Risk Management implementation is adequate although there are some minor weaknesses that can be resolved in normal business activities.
Examples of Bank characteristics included in the Satisfactory (2) rating are as follows:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with strategic objectives and overall business strategy. b. The Board of Directors and Board of Commissioners have awareness of Strategic Risk Risk Management.
c. The Strategic Risk Risk Management culture is strong and has been internalized well at all levels of the organization.
d. The execution of the duties of the Board of Directors and Board of Commissioners is generally adequate. There are some weaknesses but not significant and can be repaired immediately. e. The Strategic Risk Risk Management function has clear duties and responsibilities and has operated well. There are minor weaknesses that can be resolved in normal business activities. f. The delegation of authority is controlled and monitored periodically and has operated well. g. Policies and procedures for Strategic Risk Risk Management are adequate and available for all areas of Strategic Risk Risk Management, aligned with implementation, and understood well by employees although there are minor weaknesses. h. The Strategic Risk Risk Management process is adequate in identifying, measuring, monitoring, and controlling Strategic Risk.
i. The Strategic Risk Information System is good, including Strategic Risk reporting to the Board of Directors and Board of Commissioners. There are minor weaknesses but can be repaired easily.
j. Human resources are adequate in terms of quantity and competence in the Strategic Risk Risk Management function. k. The internal control system is effective in supporting the implementation of Strategic Risk Risk Management.
l. The implementation of independent reviews by internal audit units and functions conducting independent reviews is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners.
m. There are weaknesses but not significant based on the results of independent reviews. n. Follow-up on independent reviews has been implemented adequately.
The quality of Strategic Risk Risk Management implementation is quite adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Bank characteristics included in the Fair (3) rating are as follows:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is quite adequate but not always aligned with strategic objectives and overall business strategy. b. The Board of Directors and Board of Commissioners have (awareness) and understanding that is quite good regarding Strategic Risk Risk Management.
c. The Strategic Risk Risk Management culture is quite strong and has been internalized quite well but not always implemented consistently.
d. The execution of the duties of the Board of Directors and Board of Commissioners is generally quite adequate. There are weaknesses in some assessment aspects that need management attention. e. The Strategic Risk Risk Management function is quite good, but there are some weaknesses that need management attention. f. The delegation of authority is quite good, but control and monitoring are not always implemented well. g. Policies and procedures for Strategic Risk Risk Management are quite adequate but not always consistent with implementation. h. The Strategic Risk Risk Management process is quite adequate in identifying, measuring, monitoring, and controlling Strategic Risk.
i. The Strategic Risk Information System meets minimum expectations but there are some weaknesses including reporting to the Board of Directors and Board of Commissioners that require management attention.
j. Human resources are quite adequate in terms of quantity and competence in the Strategic Risk Risk Management function. k. The internal control system is quite effective in supporting the implementation of Strategic Risk Risk Management.
l. The implementation of independent reviews by internal audit units and functions conducting independent reviews is quite adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention.
m. There are quite significant weaknesses based on the results of independent reviews that require management attention. n. Follow-up on independent reviews has been implemented quite adequately.
The quality of Strategic Risk Risk Management implementation is less than adequate. There are significant weaknesses in various aspects of Strategic Risk Risk Management that require immediate corrective action. Examples of Bank characteristics included in the Marginal (4) rating are as follows:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is less than adequate and not aligned with strategic objectives and overall business strategy. b. Significant weaknesses in the awareness (awareness) and understanding of the Board of Directors and Board of Commissioners regarding Strategic Risk Risk Management.
c. The Strategic Risk Risk Management culture is not strong and has not been internalized well at each level of the organization.
d. The execution of the duties of the Board of Directors and Board of Commissioners is generally less than adequate. There are weaknesses in various assessment aspects that require immediate improvement. e. Significant weaknesses in the Strategic Risk Risk Management function that require immediate improvement. f. The delegation of authority is weak, not controlled, and not monitored well. g. Significant weaknesses in Risk Management policies and procedures and the setting of Strategic Risk limits. h. The Strategic Risk Risk Management process is less than adequate in identifying, measuring, monitoring, and controlling Strategic Risk.
i. Significant weaknesses in the Strategic Risk Information System including reporting to the Board of Directors and Board of Commissioners that require immediate improvement.
j. Human resources are less than adequate in terms of quantity and competence in the Strategic Risk Risk Management function. k. The internal control system is less effective in supporting Risk Management implementation.
l. The implementation of independent reviews by internal audit units and functions conducting independent reviews is less than adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate improvement.
m. There are significant weaknesses based on the results of independent reviews that require immediate improvement action. n. Follow-up on independent reviews is less than adequate.
The quality of Strategic Risk Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Strategic Risk Risk Management whose resolution actions are beyond management's capability. Examples of Bank characteristics included in the Unsatisfactory (5) rating are as follows:
a. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is inadequate and there is no connection with strategic objectives and overall business strategy. b. The Board of Directors and Board of Commissioners' awareness (awareness) and understanding of Strategic Risk Risk Management is very weak.
c. The Strategic Risk Risk Management culture is not strong or does not exist at all.
d. The execution of the duties of the Board of Directors and Board of Commissioners is inadequate. There are significant weaknesses in almost all assessment aspects and actions and resolutions are beyond the Bank's capability. e. Significant weaknesses in the Strategic Risk Risk Management function that require fundamental improvement. f. The delegation of authority is very weak or non-existent. g. Very significant weaknesses in Risk Management policies and procedures and the setting of Strategic Risk limits. h. The Strategic Risk Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Strategic Risk.
i. Fundamental weaknesses in the Strategic Risk Information System.
j. Human resources are inadequate in terms of quantity and competence in the Strategic Risk Risk Management function. k. The internal control system is not effective in supporting the implementation of Strategic Risk Risk Management.
l. The implementation of independent reviews by internal audit units and functions conducting independent reviews is less than adequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement.
m. There are very significant weaknesses based on the results of independent reviews whose improvement actions are beyond management's capability. n. Follow-up on independent reviews is inadequate.
Inherent Risk Level Determination Matrix for Compliance Risk
Considering the Bank's business activities, the potential losses the Bank faces from Compliance Risk are considered very low over a certain period in the future.
Examples of Bank characteristics included in the Low (1) rating are as follows:
a. There are no regulation violations. b. The Bank's compliance track record is very good.
c. The Bank has implemented almost all applicable financial standards and codes of ethics.
Considering the Bank's business activities, the potential losses the Bank faces from Compliance Risk are considered low over a certain period in the future.
Examples of Bank characteristics included in the Low to Moderate (2) rating are as follows:
a. There are relatively minor regulation violations that can be repaired immediately by the Bank. b. The Bank's compliance track record is good.
c. The Bank has implemented almost all applicable financial standards and codes of ethics.
Considering the Bank's business activities, the potential losses the Bank faces from Compliance Risk are considered moderately high over a certain period in the future.
Examples of Bank characteristics included in the Moderate (3) rating are as follows:
a. There are quite significant regulation violations that require management attention. b. The Bank's compliance track record is quite good.
c. There are minor violations of applicable financial standards and codes of ethics.
Considering the Bank's business activities, the potential losses the Bank faces from Compliance Risk are considered high over a certain period in the future.
Examples of Bank characteristics included in the Moderate to High (4) rating are as follows:
a. There are significant regulation violations that require immediate improvement action. b. The Bank's compliance track record is less than good.
c. There are significant violations of applicable financial standards and codes of ethics.
Considering the Bank's business activities, the potential losses the Bank faces from Compliance Risk are considered very high over a certain period in the future.
Examples of Bank characteristics included in the High (5) rating are as follows:
a. There are very significant regulation violations that require immediate improvement. b. The Bank's compliance track record is not good.
c. There are very significant violations of applicable financial standards and codes of ethics.
For Compliance Risk
The quality of Compliance Risk Risk Management implementation is very adequate. Although there are minor weaknesses but not significant, they can be ignored.
Examples of Bank characteristics included in the Strong (1) rating are as follows:
a. The Board of Directors and Board of Commissioners have very good awareness (awareness) and understanding of Risk Management for Compliance Risk. b. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is very adequate and has aligned with strategic objectives and overall business strategy.
c. The Compliance Risk Risk Management culture is very strong and has been internalized very well at all levels of the organization.
d. The execution of the duties of the Board of Directors and Board of Commissioners as a whole is very adequate. e. The Compliance Risk Risk Management function is independent, has clear duties and responsibilities, and has operated very well. f. The delegation of authority is controlled and monitored periodically and has operated very well. g. Compliance Risk Strategy is very aligned with the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance). h. Policies and procedures for Compliance Risk Risk Management are very adequate and available for all areas of Compliance Risk Risk Management, aligned with implementation, and understood well by employees.
i. The Compliance Risk Risk Management process is very adequate in identifying, measuring, monitoring, and controlling Compliance Risk.
j. The Compliance Risk Information System is very good, thereby generating comprehensive and integrated Compliance Risk Reports to the Board of Directors and Board of Commissioners. k. Human resources are very adequate in terms of quantity and competence in the Compliance Risk Risk Management function.
l. The internal control system is very effective in supporting the implementation of Compliance Risk Risk Management.
m. The implementation of independent reviews by internal audit units and functions conducting independent reviews is very adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. Generally, there are no significant weaknesses based on the results of independent reviews. o. Follow-up on independent reviews has been implemented very adequately.
The quality of Compliance Risk Risk Management implementation is adequate although there are some minor weaknesses that can be resolved in normal business activities.
Examples of Bank characteristics included in the Satisfactory (2) rating are as follows:
a. The Board of Directors and Board of Commissioners have (awareness) and understanding that is good regarding Risk Management for Compliance Risk. b. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is adequate and has aligned with strategic objectives and overall business strategy.
c. The Compliance Risk Risk Management culture is strong and has been internalized well at all levels of the organization.
d. The execution of the duties of the Board of Directors and Board of Commissioners is generally adequate. There are some weaknesses but not significant and can be repaired immediately. e. The Compliance Risk Risk Management function has clear duties and responsibilities and has operated well. There are minor weaknesses that can be resolved in normal business activities. f. The delegation of authority is controlled and monitored periodically and has operated well. g. Compliance Risk Strategy is aligned with the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance). h. Policies and procedures for Compliance Risk Risk Management are adequate and available for all areas of Compliance Risk Risk Management, aligned with implementation, and understood well by employees although there are minor weaknesses.
i. The Compliance Risk Risk Management process is adequate in identifying, measuring, monitoring, and controlling Compliance Risk.
j. The Compliance Risk Information System is good, including Compliance Risk reporting to the Board of Directors and Board of Commissioners. There are minor weaknesses that can be repaired easily. k. Human resources are adequate in terms of quantity and competence in the Compliance Risk Risk Management function.
l. The internal control system is effective in supporting the implementation of Compliance Risk Risk Management.
m. The implementation of independent reviews by internal audit units and functions conducting independent reviews is adequate in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners. n. There are weaknesses but not significant based on the results of independent reviews. o. Follow-up on independent reviews has been implemented adequately.
The quality of Compliance Risk Risk Management implementation is quite adequate. Although minimum requirements are met, there are some weaknesses that require management attention. Examples of Bank characteristics included in the Fair (3) rating are as follows:
a. The Board of Directors and Board of Commissioners have (awareness) and understanding that is quite good regarding Risk Management for Compliance Risk. b. The formulation of the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance) is quite adequate but not always aligned with strategic objectives and overall business strategy.
c. The Compliance Risk Risk Management culture is quite strong and has been internalized quite well but not always implemented consistently.
d. The execution of the duties of the Board of Directors and Board of Commissioners is generally quite adequate. There are weaknesses in some assessment aspects that need management attention. e. The Compliance Risk Risk Management function is quite good, but there are some weaknesses that need management attention. f. The delegation of authority is quite good, but control and monitoring are not always implemented well. g. Compliance Risk Strategy is quite aligned with the level of Risk to be taken (risk appetite) and Risk tolerance (risk tolerance). h. Policies and procedures for Compliance Risk Risk Management are quite adequate but not always consistent with implementation.
i. The Compliance Risk Risk Management process is quite adequate in identifying, measuring, monitoring, and controlling Compliance Risk.
j. The Compliance Risk Information System meets minimum expectations but there are some weaknesses including reporting to the Board of Directors and Board of Commissioners that require management attention.
k. Human resources are sufficiently adequate in terms of both quantity and competence for the Compliance Risk Management function.
l. The internal control system is sufficiently effective in supporting the implementation of Compliance Risk Management.
m. The implementation of independent reviews by the internal audit unit and functions performing independent reviews is sufficiently adequate. There are some weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require management attention.
n. There are significant weaknesses based on the results of independent reviews that require management attention.
o. Follow-up actions on independent reviews have been implemented sufficiently adequately.
Marginal (4) The quality of Compliance Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Compliance Risk Management that require immediate corrective action. Examples of bank characteristics included in the Marginal (4) rating are as follows:
a. Significant weaknesses in the awareness and understanding of the Board of Directors and Board of Commissioners regarding Compliance Risk Management. b. The formulation of risk appetite and risk tolerance is inadequate and not aligned with overall strategic objectives and business strategy.
c. Compliance Risk Management culture is weak and has not been well internalized at every level of the organization.
d. The implementation of duties by the Board of Directors and Board of Commissioners is generally inadequate. There are weaknesses in various aspects of assessment that require immediate improvement. e. Significant weaknesses in the Compliance Risk Management function that require immediate improvement. f. Weak delegation of authority that is not well controlled and monitored. g. Compliance Risk Strategy is not aligned with risk appetite and risk tolerance. h. Significant weaknesses in Risk Management policies and procedures, as well as the establishment of Compliance Risk limits.
i. The Compliance Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Compliance Risk.
j. Significant weaknesses in the Compliance Risk Management Information System, including reporting to the Board of Directors and Board of Commissioners, that require immediate improvement. k. Human resources are inadequate in terms of both quantity and competence for the Compliance Risk Management function.
l. The internal control system is less effective in supporting the implementation of Compliance Risk Management.
m. The implementation of independent reviews by the internal audit unit and functions performing independent reviews is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require immediate improvement. n. There are significant weaknesses based on the results of independent reviews that require immediate corrective action. o. Follow-up actions on independent reviews are inadequate.
Unsatisfactory (5) The quality of Compliance Risk Management implementation is inadequate. There are significant weaknesses in various aspects of Compliance Risk Management, the resolution of which is beyond the capacity of management. Examples of bank characteristics included in the Unsatisfactory (5) rating are as follows:
a. The awareness and understanding of the Board of Directors and Board of Commissioners regarding Compliance Risk Management are very weak. b. The formulation of risk appetite and risk tolerance is inadequate and not linked to overall strategic objectives and business strategy.
c. Compliance Risk Management culture is weak.
d. Significant weaknesses in the Compliance Risk Management function that require fundamental improvement. e. Very weak delegation of authority. f. Compliance Risk Strategy is not aligned with risk appetite and risk tolerance. g. The Compliance Risk Management process is inadequate in identifying, measuring, monitoring, and controlling Compliance Risk. h. Fundamental weaknesses in the Compliance Risk Management Information System. Reporting of Compliance Risk to the Board of Directors and Board of Commissioners is very inadequate.
i. Human resources are inadequate in terms of both quantity and competence for the Compliance Risk Management function.
j. The internal control system is ineffective in supporting the implementation of Compliance Risk Management. k. The implementation of independent reviews by the internal audit unit and functions performing independent reviews is inadequate. There are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners that require fundamental improvement.
l. There are very significant weaknesses based on the results of independent reviews, the corrective actions for which are beyond the capacity of management.
m. Follow-up actions on independent reviews are inadequate or non-existent.
APPENDIX II.3
Governance Factor Rating Matrix
Rating Definition
1 Reflects that the Bank's management has generally applied Governance very well. This is reflected in the very adequate fulfillment of good Governance principles. In case there are weaknesses in the application of good Governance principles, these weaknesses are generally not significant and can be immediately improved by the Bank's management. 2 Reflects that the Bank's management has generally applied Governance well. This is reflected in the adequate fulfillment of good Governance principles. In case there are weaknesses in the application of good Governance principles, these weaknesses are generally less significant and can be resolved with normal actions by the Bank's management. 3 Reflects that the Bank's management has generally applied Governance sufficiently well. This is reflected in the sufficiently adequate fulfillment of good Governance principles. In case there are weaknesses in the application of good Governance principles, these weaknesses are generally sufficiently significant and require sufficient attention from the Bank's management. 4 Reflects that the Bank's management has generally applied Governance less well. This is reflected in the less adequate fulfillment of good Governance principles. There are weaknesses in the application of good Governance principles; generally, these weaknesses are significant and require comprehensive improvement by the Bank's management. 5 Reflects that the Bank's management has generally applied Governance poorly. This is reflected in the inadequate fulfillment of good Governance principles. There are weaknesses in the application of good Governance principles; generally, these weaknesses are very significant and difficult to be improved by the Bank's management.
APPENDIX II.4
Profitability Factor Rating Matrix
Rating Definition
1 Profitability is very adequate, profit exceeds targets, and supports capital growth.
Banks included in Rating 1 meet all or most of the following example characteristics:
a. The Bank's performance in generating profit (profitability) is very adequate. b. The main source of profitability from core earnings is very dominant.
c. Components supporting core earnings are very stable.
d. The ability of profit to increase capital and profit prospects in the future are very high.
2 Profitability is adequate, profit exceeds targets, and supports capital growth.
Banks included in Rating 2 meet all or most of the following example characteristics:
a. The Bank's performance in generating profit or profitability is adequate. b. The main source of profitability from core earnings is dominant.
c. Components supporting core earnings are stable.
d. The ability of profit to increase capital and profit prospects in the future are high.
3 Profitability is sufficiently adequate, profit meets targets, although there is pressure on profit performance that may cause a decrease in profit but still sufficiently supports the Bank's capital growth. Banks included in Rating 3 meet all or most of the following example characteristics:
a. The Bank's performance in generating profit or profitability is sufficiently adequate. b. The main source of profitability from core earnings is sufficiently dominant, although there is a sufficiently large influence from non-core earnings.
c. Components supporting core earnings are sufficiently stable.
d. The ability of profit to increase capital and profit prospects in the future are sufficiently good.
4 Profitability is less adequate, profit does not meet targets, and is estimated to remain in such conditions in the future, thus less supporting capital growth and the Bank's business continuity. Banks included in Rating 4 meet all or most of the following example characteristics:
a. The Bank's performance in generating profit or profitability is inadequate or the Bank incurs losses. b. The main source of profitability comes from non-core earnings.
c. Components supporting core earnings are less stable.
d. The ability of profit to increase capital and profit prospects in the future are less good or may even have a negative impact on the Bank's capital.
5 Profitability is inadequate, profit does not meet targets and is unreliable, and requires immediate improvement in profit performance to ensure the Bank's business continuity. Banks included in Rating 5 meet all or most of the following example characteristics:
a. The Bank incurs significant losses. b. The main source of profitability comes from non-core earnings.
c. Components supporting core earnings are unstable.
d. The Bank's losses significantly affect capital.
APPENDIX II.5
Capital Factor Rating Matrix
Rating Definition
Very adequate relative to the risk profile, accompanied by very strong capital management according to the Bank's characteristics, business scale, and business complexity.
Banks included in Rating 1 meet all or most of the following example characteristics:
a. The Bank has a very adequate level of capital, is very capable of anticipating all Risks faced, and supports the Bank's business expansion in the future. b. The quality of capital components is generally very good, permanent, and able to absorb losses.
c. The Bank has conducted stress testing with results that can cover all Risks faced very adequately.
d. The Bank has very good capital management and/or has a very good capital adequacy assessment process according to strategy and business objectives as well as the Bank's complexity and scale. e. The Bank has very good access to capital sources and/or has capital support from business groups or parent companies.
Adequate relative to the risk profile, accompanied by strong capital management according to the Bank's characteristics, business scale, and business complexity.
Banks included in Rating 2 meet all or most of the following example characteristics:
a. The Bank has an adequate level of capital and can anticipate almost all Risks faced. b. The quality of capital components is generally good, permanent, and able to absorb losses.
c. The Bank has conducted stress testing with results that can cover all Risks faced adequately.
d. The Bank has good capital management and/or has a good capital adequacy assessment process. e. The Bank has good access to capital sources and/or there is capital support from business groups or parent companies.
Sufficiently adequate relative to the risk profile, accompanied by sufficiently strong capital management according to the Bank's characteristics, business scale, and business complexity. Banks included in Rating 3 meet all or most of the following example characteristics:
a. The Bank has a sufficiently adequate level of capital and is sufficiently capable of anticipating Risks faced. b. The quality of capital components is generally sufficiently good, sufficiently permanent, and sufficiently able to absorb losses.
c. The Bank has conducted stress testing with results that can cover all Risks faced sufficiently adequately.
d. The Bank has sufficiently good capital management and/or has a sufficiently good capital adequacy assessment process. e. The Bank has sufficiently good access to capital sources, although support from business groups or parent companies is not explicit.
Less adequate relative to the risk profile, accompanied by weak capital management compared to the Bank's characteristics, business scale, and business complexity.
Banks included in Rating 4 meet all or most of the following example characteristics:
a. The Bank has a less adequate level of capital and cannot anticipate all Risks faced. b. The quality of capital components is generally less good, less permanent, and less able to absorb losses.
c. The Bank has conducted stress testing with results that less cover all Risks faced.
d. The Bank has less good capital management and/or has a less good capital adequacy assessment process. e. The Bank is less able to access capital sources, and there is no support from business groups or parent companies.
Inadequate relative to the risk profile, accompanied by very weak capital management compared to the Bank's characteristics, business scale, and business complexity.
Banks included in Rating 5 meet all or most of the following example characteristics:
a. The Bank has an inadequate level of capital, so the Bank must increase capital to anticipate all Risks faced under normal conditions and crisis conditions. b. The quality of capital instruments is generally not good, not permanent, and unable to absorb losses.
c. The Bank has conducted stress testing with results that cannot cover all Risks faced.
d. The Bank has poor capital management and/or has a poor capital adequacy assessment process. e. The Bank is unable to access capital sources and has no support from business groups or parent companies.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Established in Jakarta on 17 March 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX III
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 14 /SEOJK.03/2017 REGARDING THE ASSESSMENT OF THE HEALTH LEVEL OF COMMERCIAL BANKS
REPORTS AND WORKING PAPERS
Appendix III.1 : Report on the Results of the Assessment of the Health Level of Banks
Appendix III.2 : Risk Profile Factor Assessment
Appendix III.3 : Risk Analysis Assessment
Appendix III.4 : Governance Factor Assessment
Appendix III.5 : Profitability Factor Assessment
Appendix III.6 : Capital Factor Assessment
APPENDIX III.1
REPORT
RESULTS OF THE ASSESSMENT OF THE HEALTH LEVEL OF BANKS (RISK BASED BANK RATING) Bank Name :
Position :
No. Assessment Factor Rating
Individual Consolidated *)
1 Risk Profile
2 Governance
3 Profitability
4 Capital
Health Level Rating of the Bank
*) In the event that the Bank has Consolidated Subsidiaries Analysis The analysis of the Bank's overall condition is reflected in the four assessment factors of the Health Level of the Bank as follows:
APPENDIX III.2
RISK PROFILE FACTOR ASSESSMENT
Bank Name :
Position :
Risk Profile
INDIVIDUAL CONSOLIDATED
Rating
Inherent Risk Rating
Rating
Quality of Risk Management Implementation
Rating
Risk Level Rating
Rating
Inherent Risk Rating
Rating
Quality of Risk Management Implementation
Rating
Risk Level Rating
Credit Risk
Market Risk
Liquidity Risk
Operational Risk
Legal Risk
Reputational Risk
Strategic Risk
Compliance Risk
Composite Rating
Risk Profile Rating
Risk Profile Rating
Analysis
A description of the conclusions regarding the Bank's overall risk profile includes the assessment of inherent Risk and the quality of Risk Management implementation, with a focus on analysis of significant Risk exposures in the Bank. In the event that the Bank has Consolidated Subsidiaries, the Bank considers the impact of the Subsidiary's Risk on the Bank's risk profile by considering the significance and materiality of the Subsidiary's share in the consolidated Bank's share or performance, and/or the significance of the Subsidiary's issues.
APPENDIX III.3
RISK ANALYSIS ASSESSMENT …………. *)
Bank Name :
Position :
Analysis
Risk Rating:
The final conclusion regarding the Bank's risk level, covering the level of inherent Risk and the quality of Risk Management implementation, thereby describing the Bank's risk level. Inherent Risk:
A description of the assessment of inherent Risk based on the analysis of assessment factors using both quantitative and qualitative indicators, thereby describing the Bank's inherent risk level. Quality of Risk Management Implementation:
Analysis of the quality of Risk Management implementation consists of risk governance; Risk Management framework; Risk Management process, human resources, and management information systems; and Risk control. *) This working paper is used to support the analysis of Risk in the Bank, including Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Reputational Risk, Strategic Risk, and Compliance Risk.
APPENDIX III.4
GOVERNANCE FACTOR ASSESSMENT
Bank Name :
Position :
No. Governance Assessment Factor Rating
Parameters or indicators for assessing the Governance factor, which is an assessment of the Bank's management's implementation of good Governance principles, refer to the Financial Services Authority regulations on the Implementation of Governance for Commercial Banks, considering the Bank's characteristics and business complexity. Composite Rating Analysis A description of the conclusions regarding the Bank's Governance performance, considering the Governance assessment factors comprehensively and structured, covering both structure, process, and outcome of Governance. In the event that the Bank has Consolidated Subsidiaries, the Bank considers the impact of the Subsidiary's Governance on the Bank's Governance performance by considering the significance and materiality of the Subsidiary and/or the significance of the Subsidiary's Governance weaknesses.
APPENDIX III.5
PROFITABILITY FACTOR ASSESSMENT
Bank Name :
Position :
Profitability Rating Individual Consolidated
Analysis
The final conclusion regarding the Bank's profitability performance, considering the profitability assessment factors. In the event that the Bank has Consolidated Subsidiaries, the Bank considers the impact of the Subsidiary's profitability performance on the Bank's overall profitability by considering the significance and materiality of the Subsidiary.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
APPENDIX III.6
CAPITAL FACTOR ASSESSMENT
Bank Name :
Position :
Capital Rating Individual Consolidated
Analysis
The final conclusion regarding the Bank's capital performance, considering the capital assessment factors. In the event that the Bank has Consolidated Subsidiaries, the Bank considers the impact of the Subsidiary's capital performance on the Bank's overall capital by considering the significance and materiality of the Subsidiary.
Established in Jakarta on 17 March 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.