2016-12-28 | 65/POJK.03/2016Added
This regulation mandates Islamic commercial banks (BUS) and Islamic business units (UUS) to implement comprehensive risk management frameworks covering credit, market, liquidity, operational, legal, reputational, strategic, compliance, rate of return, and investment risks. It requires active oversight by the Board of Directors, Board of Commissioners, and Sharia Supervisory Board, establishes the formation of Risk Management Committees and dedicated Risk Management units, and imposes strict internal control and reporting obligations. Banks must submit quarterly risk profile reports to the Financial Services Authority (OJK), with specific deadlines for March, June, September, and December positions.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
BY THE GRACE OF THE ALMIGHTY GOD,
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that Islamic banking business activities are inseparable from risks that can disrupt the continuity of the bank; b. that to manage such risks, banks are required to implement risk management individually and on a consolidated basis;
c. that the characteristics of Islamic banking products and services require risk identification, measurement, monitoring, and control functions appropriate to Islamic banking business activities;
d. that the steps taken by Islamic banks to mitigate risks must consider consistency with Sharia Principles; e. that the management of every functional activity of the bank must be integrated into an accurate and comprehensive risk management system and process; f. that since December 31, 2013, the functions, duties, and authorities for regulation and supervision of financial services activities in the Banking sector have transferred from Bank Indonesia to the Financial Services Authority; g. that based on the considerations referred to in letters a through f, it is necessary to establish a Financial Services Authority Regulation concerning the Implementation of Risk Management for Islamic Commercial Banks and Islamic Business Units;
Recalling:
DECIDING:
To establish: FINANCIAL SERVICES AUTHORITY REGULATION CONCERNING THE IMPLEMENTATION OF RISK MANAGEMENT FOR ISLAMIC COMMERCIAL BANKS AND ISLAMIC BUSINESS UNITS.
In this Financial Services Authority Regulation, the following terms are defined as:
(1) Banks are required to implement Risk Management effectively.
(2) The implementation of Risk Management as referred to in paragraph (1) for BUS is conducted individually and on a consolidated basis with Subsidiary Companies. (3) The implementation of Risk Management as referred to in paragraph (1) for UUS is conducted against all UUS business activities, which are an integral part of the implementation of Risk Management in the BUK.
The implementation of Risk Management as referred to in Article 2 paragraph (1) must at least cover:
a. active supervision by the Board of Directors, Board of Commissioners, and Sharia Supervisory Board; b. adequacy of Risk Management policies and procedures as well as the establishment of Risk limits;
c. adequacy of the Risk identification, measurement, monitoring, and control processes and the Risk Management information system; and
d. a comprehensive internal control system.
The implementation of Risk Management as referred to in Article 3 must be adjusted to the objectives, business policies, size, and complexity of the business as well as the Bank's capabilities.
(1) Risks as referred to in Article 3 include:
a. Credit Risk; b. Market Risk;
c. Liquidity Risk;
d. Operational Risk; e. Legal Risk; f. Reputational Risk; g. Strategic Risk; h. Compliance Risk;
i. Rate of Return Risk; and
j. Equity Investment Risk.
(2) Banks are required to implement Risk Management for the types of Risks as referred to in paragraph (1).
General
Banks are required to establish clear authorities and responsibilities at every level of position related to the implementation of Risk Management as referred to in Article 2.
Authorities and Responsibilities of the Board of Directors
(1) The authorities and responsibilities as referred to in Article 6 for the Board of Directors must at least cover:
a. drafting written and comprehensive Risk Management policies and strategies; b. being responsible for the implementation of Risk Management policies and the Risk exposures taken by the Bank as a whole;
c. evaluating and deciding on transactions requiring Board of Directors approval;
d. developing a Risk Management culture at all levels of the organization; e. ensuring the improvement of human resources competence related to Risk Management; f. ensuring that the Risk Management function operates independently; and g. conducting periodic reviews to ensure:
1. the accuracy of Risk assessment methodologies;
2. the adequacy of the implementation of the Risk Management information system; and
3. the appropriateness of Risk Management policies and procedures as well as the establishment of Risk limits.
(2) In carrying out the authorities and responsibilities as referred to in paragraph (1), the Board of Directors must have adequate understanding of the Risks inherent in all functional activities of the Bank and be able to take necessary actions according to the Bank's Risk profile. (3) The authorities and responsibilities of the Board of Directors as referred to in paragraph (1) for UUS are carried out by the Director of the UUS.
Authorities and Responsibilities of the Board of Commissioners
The authorities and responsibilities as referred to in Article 6 for the Board of Commissioners must at least cover:
a. approving and evaluating Risk Management policies; and b. evaluating the Board of Directors' accountability for the implementation of Risk Management policies as referred to in letter a.
Authorities and Responsibilities of the Sharia Supervisory Board
The authorities and responsibilities as referred to in Article 6 for the Sharia Supervisory Board must at least cover:
a. evaluating Risk Management policies related to the fulfillment of Sharia Principles; and b. evaluating the Board of Directors' accountability for the implementation of Risk Management policies related to the fulfillment of Sharia Principles as referred to in letter a.
Risk Management Policies
Risk Management policies as referred to in Article 3 letter b must at least contain:
a. the establishment of Risks related to banking products and transactions; b. the establishment of the use of measurement methods and Risk Management information systems;
c. the determination of limits and the establishment of Risk tolerance;
d. the establishment of Risk rating assessments; e. the drafting of contingency plans in worst-case scenarios; and f. the establishment of an internal control system in the implementation of Risk Management.
Risk Management Procedures and Establishment of Risk Limits
(1) Risk Management procedures and the establishment of Risk limits as referred to in Article 3 letter b must be adjusted to the level of Risk to be taken (risk appetite) regarding the Bank's Risks. (2) Risk Management procedures and the establishment of Risk limits as referred to in paragraph (1) must at least contain:
a. clear accountability and levels of delegation of authority; b. periodic review of Risk Management procedures and the establishment of Risk limits; and
c. adequate documentation of Risk Management procedures and the establishment of Risk limits.
(3) The establishment of Risk limits as referred to in paragraph (2) must cover:
a. overall limits; b. limits per type of Risk; and
c. limits per specific functional activities with Risk exposure.
General
(1) Banks are required to carry out the Risk identification, measurement, monitoring, and control processes as referred to in Article 3 letter c against material Risk factors. (2) The implementation of the Risk identification, measurement, monitoring, and control processes as referred to in paragraph (1) must be supported by:
a. timely management information systems; and b. accurate and informative reports regarding the Bank's financial condition, functional activity performance, and Risk exposure.
Risk Identification, Measurement, Monitoring, and Control Processes
(1) In carrying out the Risk identification process, Banks are required to conduct analysis at least on:
a. the characteristics of Risks inherent in the Bank; and b. Risks from the Bank's products and business activities.
(2) In carrying out the Risk measurement process, Banks are required to at least:
a. periodically evaluate the suitability of assumptions, data sources, and procedures used to measure Risks; and b. improve the Risk measurement system in the event of changes in the Bank's business activities, products, transactions, and material Risk factors that can affect the Bank's financial condition. (3) In carrying out the Risk monitoring process, Banks are required to at least:
a. evaluate Risk exposure; and b. improve the reporting process in the event of changes in business activities, products, transactions, Risk factors, information technology, and the Bank's Risk Management information systems that are material. (4) Banks are required to carry out Risk control processes to manage specific Risks that can endanger the continuity of the Bank's business. (5) The implementation of the Risk control process as referred to in paragraph (4) must be in accordance with Sharia Principles.
Risk Management Information Systems
(1) The Risk Management information system as referred to in Article 3 letter b must at least include reports or information regarding:
a. Risk exposure; b. compliance with Risk Management policies and procedures as well as the establishment of Risk limits as referred to in Article 10 and Article 11; and
c. the realization of Risk Management implementation compared to established targets.
(2) Reports or information generated from the Risk Management information system as referred to in paragraph (1) must be submitted regularly to the Board of Directors. (3) The Risk Management information system as referred to in paragraph (1) for UUS may use the information system technology used in the BUK's Risk Management information system.
General
(1) Banks are required to implement an internal control system effectively against the implementation of business activities and operations at all levels of the Bank's organization. (2) The implementation of the internal control system for UUS may be combined with the internal control system of the BUK.
(1) The implementation of the internal control system as referred to in Article 15 must at least be able to detect weaknesses and deviations that occur in a timely manner. (2) The internal control system as referred to in paragraph (1) must ensure:
a. compliance with applicable laws and regulations as well as Bank policies or internal regulations; b. the availability of complete, accurate, useful, and timely financial and management information;
c. effectiveness and efficiency in operational activities; and
d. the effectiveness of Risk culture within the Bank's organization as a whole.
Internal Control System in the Implementation of Risk Management
(1) The internal control system in the implementation of Risk Management as referred to in Article 3 letter d must at least cover:
a. the suitability of the internal control system with the type and level of Risks inherent in the Bank's business activities; b. the establishment of authorities and responsibilities for monitoring compliance with Risk Management policies and procedures, as well as the establishment of Risk limits as referred to in Article 10 and Article 11;
c. the establishment of clear reporting lines and separation of functions between operational work units and work units carrying out control functions;
d. an organizational structure that clearly depicts the Bank's business activities; e. accurate and timely financial and operational reporting; f. adequate procedures to ensure the Bank's compliance with applicable laws and regulations; g. effective, independent, and objective review of procedures for assessing the Bank's operational activities; h. adequate testing and review of the Risk Management information system;
i. complete and adequate documentation of operational procedures, audit scope and findings, and management responses based on audit results; and
j. periodic and continuous verification and review of the handling of material Bank weaknesses and management actions to correct deviations that occur. (2) The assessment of the internal control system in the implementation of Risk Management as referred to in paragraph (1) must be conducted by the internal audit work unit.
General
(1) In order to carry out effective Risk Management processes and systems as referred to in Article 2, Banks are required to form:
a. a Risk Management Committee; and b. a Risk Management work unit.
(2) The Risk Management Committee and Risk Management work unit as referred to in paragraph (1) for UUS may be formed separately or combined with the BUK according to the size and complexity of the UUS business and the Risks inherent in the UUS.
Risk Management Committee
(1) The Risk Management Committee as referred to in Article 18 paragraph (1) letter a for BUS must at least consist of:
a. a majority of Board of Directors members, one of whom is the director overseeing the compliance function; and b. relevant executive officials. (2) In the event that the Risk Management Committee for UUS as referred to in Article 18 paragraph (2) is formed separately, the membership of the UUS Risk Management Committee must at least consist of:
a. the Director of the UUS; b. the director overseeing the compliance function of the BUK; and
c. relevant executive officials.
(3) In the event that the Risk Management Committee for UUS as referred to in Article 18 paragraph (2) is combined with the BUK's Risk Management Committee, the Director of the UUS must be included as one of the members of the BUK's Risk Management Committee in discussions related to UUS Risk Management. (4) The Risk Management Committee as referred to in paragraph (1) has the authority and responsibility to provide recommendations to the President Director, which must at least include:
a. the drafting of policies, strategies, and guidelines for the implementation of Risk Management; b. improvements or refinements to the implementation of Risk Management based on the results of Risk Management implementation evaluations; and
c. the establishment of matters related to business decisions that do not comply with normal procedures.
Risk Management Work Unit
(1) The organizational structure of the Bank's Risk Management work unit as referred to in Article 18 paragraph (1) letter b is adjusted to the size and complexity of the Bank's business and the Risks inherent in the Bank. (2) The Risk Management work unit as referred to in paragraph (1) must be independent from operational work units (risk-taking units) and from work units carrying out internal control functions. (3) The Risk Management work unit as referred to in paragraph (2) is directly responsible to the President Director or to a director specifically assigned. (4) The authorities and responsibilities of the Risk Management work unit include:
a. monitoring the implementation of Risk Management strategies approved by the Board of Directors; b. monitoring overall (composite) Risk positions, per type of Risk and/or per type of functional activity, and conducting stress testing;
c. periodic review of Risk Management processes;
d. assessing proposals for new activities and/or products; e. evaluating the accuracy of models and validity of data used to measure Risks, for Banks using models for internal purposes (internal models); f. providing recommendations to operational work units (risk-taking units) and/or to the Risk Management Committee; and g. drafting and submitting Risk profile or composition reports periodically to:
1. the President Director or a director specifically assigned; and
2. the Risk Management Committee.
Relationship Between Operational Work Units and Risk Management Work Units
Operational work units (risk-taking units) as referred to in Article 20 paragraph (2) are required to inform the Risk Management work unit of the Risks inherent in the respective work unit on a periodic basis.
Risk Profile Reports
(1) Banks are required to submit Risk profile reports both individually and on a consolidated basis to the Financial Services Authority.
(2) The Risk profile reports as referred to in paragraph (1) must contain the same substance as the Risk profile reports submitted by the Risk Management work unit to the President Director or to a director specifically assigned and the Risk Management Committee. (3) The Risk profile reports as referred to in paragraph (1) are submitted quarterly for the positions of March, June, September, and December. (4) If necessary, the Financial Services Authority may request Banks to submit Risk profile reports as referred to in paragraph (1) outside the established timeframes as referred to in paragraph (3). (5) The Risk profile reports as referred to in paragraph (1) for the positions of March and September shall refer to the Appendix which is an integral part of this Financial Services Authority Regulation. (6) The Risk profile assessment in the preparation of Risk profile reports as referred to in paragraph (5) refers to the Financial Services Authority regulations concerning the assessment of the health level of Islamic commercial banks and Islamic business units. (7) The Risk profile reports as referred to in paragraph (1) for the positions of June and December are submitted as part of the self-assessment results regarding the Bank's health level.
(1) Individual Risk profile reports as referred to in Article 22 paragraph (1) for the positions of March and September must be submitted at the latest 15 (fifteen) working days after the end of the reporting month. (2) In the event that the deadline for submitting individual Risk profile reports as referred to in paragraph (1) falls on a holiday, the Risk profile reports must be submitted on the next working day. (3) The deadline for submitting individual Risk profile reports for the positions of June and December refers to the Financial Services Authority regulations concerning the assessment of the health level of Islamic commercial banks and Islamic business units. (4) A Bank is considered to have submitted individual reports late if the reports are submitted beyond the submission deadlines as referred to in paragraph (1) and paragraph (3) but do not exceed 1 (one) month from the final submission deadline. (5) A Bank is considered to have not submitted individual reports as referred to in Article 22 paragraph (1) if the reports are not submitted within the established deadlines.
if the Bank has not submitted the report for more than 1 (one) month since the deadline for report submission as referred to in paragraph (1) and paragraph (3).
Article 24
(1) Consolidated Risk Profile reports as referred to in Article 22 paragraph (1) for the March position and the September position must be submitted at the latest 1 (one) month after the end of the reporting month. (2) In the event that the deadline for submitting the consolidated Risk Profile report as referred to in paragraph (1) falls on a holiday, the Risk Profile report must be submitted on the next working day. (3) The deadline for submitting the consolidated Risk Profile report for the June position and the December position refers to the regulations of the Financial Services Authority regarding the assessment of the health level of Islamic commercial banks and Islamic business units. (4) A Bank is considered to have submitted the consolidated report late if the report is submitted beyond the submission deadline as referred to in paragraph (1) and paragraph (3) but does not exceed 14 (fourteen) working days since the final deadline for report submission. (5) A Bank is considered to have not submitted the consolidated report as referred to in Article 22 paragraph (1) if the Bank has not submitted the report for more than 14 (fourteen) working days since the final deadline for report submission as referred to in paragraph (1) and paragraph (3).
Second Section
Other Reports
Article 25
(1) Banks must submit other reports to the Financial Services Authority besides those referred to in Article 22, in the event there are conditions that have the potential to cause significant losses to the Bank's financial condition. (2) Banks are required to submit to the Financial Services Authority other reports related to the implementation of Risk Management periodically or at any time when necessary. (3) The format, reporting procedures, and imposition of sanctions for reports as referred to in paragraph (2) refer to regulations governing bank reporting.
Third Section
Submission Address
Article 26
Reports as referred to in Article 22 and Article 25 are submitted to the Financial Services Authority at the address:
a. Islamic Banking Department, for Banks headquartered in the Special Capital Region of Jakarta Province; or b. Regional Office of the Financial Services Authority or Local Office of the Financial Services Authority for Banks headquartered outside the Special Capital Region of Jakarta Province.
CHAPTER IX
OTHER PROVISIONS
First Section
Assessment of Risk Management Implementation
Article 27
The Financial Services Authority may conduct assessments of the implementation of Risk Management at Banks.
Article 28
Banks are required to provide data and information related to the implementation of Risk Management to the Financial Services Authority.
Second Section
Aspects of Performance Disclosure and Risk Management Policy
Article 29
(1) Risk Management disclosure in the Bank's annual publication report as regulated in the Financial Services Authority Regulation on Transparency and Publication of Bank Reports must be adjusted to this Financial Services Authority Regulation. (2) Disclosure as referred to in paragraph (1) must at least cover Risk Management performance and the direction of Risk Management policy. (3) Risk Management disclosure in the annual publication report as referred to in paragraph (1) for Islamic Business Units (UUS) is combined in the annual report of the Islamic Commercial Bank (BUK).
CHAPTER X
SANCTIONS
Article 30
(1) Banks that are late in submitting reports as referred to in Article 22 are subject to administrative sanctions in the form of a fine of Rp1,000,000.00 (one million rupiah) per day of delay per report. (2) Banks that do not submit reports as referred to in Article 22 are subject to administrative sanctions in the form of a fine of Rp50,000,000.00 (fifty million rupiah) per report. (3) Banks that do not submit reports as referred to in Article 22 and have been subject to sanctions as referred to in paragraph (2) remain required to submit reports to the Financial Services Authority. (4) Banks that submit reports as referred to in Article 22, but:
a. are assessed as significantly incomplete; and/or b. are not accompanied by material documents and information, according to the specified format, are subject to administrative sanctions in the form of a fine of Rp50,000,000.00 (fifty million rupiah). (5) Banks are subject to sanctions as referred to in paragraph (4) after:
a. The Bank is given 2 (two) warning letters by the Financial Services Authority with a grace period of 7 (seven) working days for each warning letter; and b. The Bank does not correct the report within a period of 7 (seven) working days after the last warning letter.
Article 31
Banks that do not implement the provisions as established in Article 2 paragraph (1), Article 4, Article 5 paragraph (2), Article 6, Article 11 paragraph (1), Article 11 paragraph (3), Article 12, Article 13 paragraph (1), Article 13 paragraph (2), Article 13 paragraph (3), Article 13 paragraph (4), Article 14 paragraph (2), Article 15 paragraph (1), Article 16 paragraph (2), Article 17 paragraph (2), Article 18 paragraph (1), Article 21, Article 28, and/or Article 29 paragraph (1) are subject to administrative sanctions including:
a. written warnings; b. suspension of certain business activities; and/or
c. inclusion of board members, Bank employees, and/or shareholders in the list of parties receiving a "fail" rating in the ability and propriety test/assessment or in the Financial Services Authority's administrative records as regulated in applicable Financial Services Authority regulations.
CHAPTER XI
CLOSING PROVISIONS
Article 32
Further provisions regarding the implementation of Risk Management for Banks are regulated in Financial Services Authority Circular Letters.
Article 33
(1) Upon the commencement of this Financial Services Authority Regulation, Bank Indonesia Regulation Number 13/23/PBI/2011 on the Implementation of Risk Management for Islamic Commercial Banks and Islamic Business Units is repealed and declared invalid. (2) With the implementation of this Financial Services Authority Regulation, regulations for Banks that previously referred to regulations regarding the implementation of risk management for commercial banks now refer to this Financial Services Authority Regulation.
Article 34
(1) Bank Indonesia Regulation Number 8/6/PBI/2006 on the Implementation of Consolidated Risk Management for Banks That Control Subsidiary Companies remains in force insofar as it does not conflict with these provisions. (2) Implementation provisions of Bank Indonesia Regulation Number 5/8/PBI/2003 on the Implementation of Risk Management for Commercial Banks as amended by Bank Indonesia Regulation Number 11/25/PBI/2009 remain in force for Islamic Commercial Banks (BUS) and Islamic Business Units (UUS) insofar as they do not conflict with this Financial Services Authority Regulation. (3) Provisions in item 9 of Bank Indonesia Circular Letter Number 5/21/DPNP regarding the Implementation of Risk Management for Commercial Banks are declared invalid.
Article 35
This Financial Services Authority Regulation takes effect on the date of its promulgation.
To ensure that everyone knows it, order the promulgation of this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Determined in Jakarta on December 23, 2016
CHAIRMAN OF THE COMMISSIONERS BOARD
FINANCIAL SERVICES AUTHORITY, signed
MULIAMAN D. HADAD
Promulgated in Jakarta on December 28, 2016
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2016 NUMBER 298 Copy in accordance with the original Legal Director 1 Legal Department signed Yuliana
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 65 /POJK.03/2016
ON
THE IMPLEMENTATION OF RISK MANAGEMENT FOR ISLAMIC COMMERCIAL BANKS AND ISLAMIC BUSINESS UNITS
I. GENERAL
Bank business activities are always faced with risks closely related to their function as financial intermediation institutions. The rapid development of the external and internal environment of Islamic banking results in Islamic banking business risks becoming increasingly complex. To face these conditions, Banks must pay attention to all risks, whether directly or indirectly, that can affect the continuity of the Bank's business, including those arising from Subsidiary Companies, by implementing Risk Management on a consolidated basis. Banks are required to be able to adapt to the environment through the implementation of Risk Management in accordance with Sharia Principles. The Risk Management principles applied in Islamic banking in Indonesia are directed in line with standard rules issued by the Islamic Financial Services Board (IFSB). The implementation of Risk Management in Islamic banking is adjusted to the size and complexity of the business and the Bank's capabilities. The Financial Services Authority establishes this Risk Management regulation as a minimum standard that must be met by BUS and UUS so that Islamic banking can develop according to needs and challenges faced, yet still conducted in a healthy, consistent, and Sharia-compliant manner.
II. ARTICLE BY ARTICLE
Article 1
Clear enough.
Article 2
Paragraph (1)
Included in the scope of Risk Management implementation is the implementation of Anti-Money Laundering and Counter-Terrorism Financing programs. Paragraph (2) Clear enough. Paragraph (3) Clear enough.
Article 3
Clear enough.
Article 4
Business complexity includes, among others, diversity in transaction types, products or services, and business networks. Bank capabilities include, among others, financial capabilities, supporting infrastructure, and human resource capabilities.
Article 5
Paragraph (1)
Letter a
Included in the Credit Risk group are financing concentration risk, counterparty credit risk, and settlement risk.
Financing concentration risk is a Risk arising from the concentration of fund provision to 1 (one) party or a group of parties, industries, sectors, and/or specific geographic areas that has the potential to cause considerable losses that can threaten the continuity of the Bank's business. Counterparty credit risk is a Risk arising from the failure of the counterparty to fulfill its obligations and arises from transaction types with specific characteristics, for example, transactions influenced by fair value or market value movements. Settlement risk is a Risk arising from the failure to deliver cash and/or financial instruments on the agreed settlement date from the sale and/or purchase of financial instruments. Letter b Market Risk includes, among others, benchmark interest rate risk, exchange rate risk, commodity risk, and equity risk. The implementation of Risk Management for commodity risk and equity risk must be applied by Banks that consolidate with Subsidiary Companies. Commodity risk is a Risk due to changes in the price of financial instruments from the trading book and banking book positions caused by changes in commodity prices. Equity risk is a Risk due to changes in the price of financial instruments from the trading book position caused by changes in stock prices. Letter c Clear enough. Letter d Clear enough. Letter e Legal Risk arises, among others, from the absence of supporting legislation or weaknesses in agreements, such as the non-fulfillment of contract validity conditions or imperfect collateral binding. Letter f Reputational Risk arises, among others, from negative media coverage and/or rumors regarding the bank, as well as ineffective bank communication strategies. Letter g Strategic Risk arises, among others, from the bank setting strategies that are less aligned with the bank's vision and mission, conducting non-comprehensive strategic environment analysis, and/or having inconsistencies in strategic plans between strategic levels. Additionally, Strategic Risk arises from failures in anticipating changes in the business environment, including failures in anticipating technological changes, macroeconomic condition changes, market competition dynamics, and changes in relevant authority policies. Letter h Clear enough. Letter i Rate of Return Risk arises, among others, from changes in the behavior of third-party fund customers caused by changes in the expected rate of return received from the Bank. Changes in expectations can be caused by internal factors such as a decrease in the Bank's asset value and/or external factors such as an increase in returns/interest offered by other banks. Changes in the expected rate of return can trigger the transfer of customer funds from the Bank to other banks. Letter j Investment Risk (Equity Investment Risk) arises when the Bank provides profit-sharing based financing to customers with the Bank sharing the risk of business losses of the financed customer (profit and loss sharing method).
In this case, profit-sharing calculations are not only based on the revenue or sales obtained by the customer but calculated from the business profit generated by the customer. If the customer's business goes bankrupt, the principal financing amount provided by the Bank to the customer will not be recovered. Meanwhile, profit-sharing calculations can also use the net revenue sharing method, namely profit-sharing calculated from revenue after deducting capital. Paragraph (2) Clear enough.
Article 6
Clear enough.
Article 7
Paragraph (1)
Letter a
Included in Risk Management policy and strategy is the establishment and approval of Risk limits, both overall (composite) risk, per type of Risk, and per functional activity. Risk Management policy and strategy are prepared at least 1 (one) time or more in 1 (one) year in the event of changes in factors significantly affecting BUS business activities. Letter b Included in the responsibility for implementing Risk Management policy are:
Article 8
Letter a
The evaluation of Risk Management policy is conducted by the Board of Commissioners at least 1 (one) time or more in 1 (one) year in the event of changes in factors significantly affecting the Bank's business activities. Letter b The evaluation of the Board of Directors' accountability for the implementation of Risk Management policy is conducted by the Board of Commissioners at least quarterly.
Article 9
Letter a
The evaluation of Risk Management policy related to the fulfillment of Sharia Principles is conducted by the Sharia Supervisory Board at least 1 (one) time in 1 (one) year. Letter b The evaluation of the Board of Directors' accountability for the implementation of Risk Management policy related to the fulfillment of Sharia Principles is conducted by the Sharia Supervisory Board at least quarterly.
Article 10
Risk Management policy is established, among others, by formulating Risk Management strategy to ensure that:
Article 11
Paragraph (1)
The level of Risk to be taken (risk appetite) considers the experience the Bank has in managing Risk.
Paragraph (2)
Letter a
Clear enough.
Letter b
The term "periodically" means at least 1 (one) time or more in 1 (one) year, depending on the type of Risk, needs, and Bank development.
Letter c
The term "adequate documentation" means written, complete documentation that facilitates audit trails for the Bank's internal control purposes.
Paragraph (3)
Clear enough.
Article 12
Paragraph (1)
The term "Risk factors" refers to various parameters that affect Risk exposure. The term "material Risk factors" refers to Risk factors, both quantitative and qualitative, that significantly affect the Bank's financial condition. Paragraph (2) Clear enough.
Article 13
Paragraph (1)
The Risk identification process is based, among others, on the Bank's past loss experience.
Paragraph (2)
To measure Risk, the Bank can use qualitative or quantitative approaches adjusted to business objectives, business complexity, and Bank capabilities. Letter a The term "periodically" means at least quarterly or more in accordance with the Bank's business development and external conditions that directly affect the Bank's condition. Letter b Clear enough. Paragraph (3) Letter a The evaluation of Risk exposure is conducted through monitoring and reporting of material Risks or those impacting the Bank's capital condition, which is based, among others, on the assessment of potential Risk using historical trends. Letter b Clear enough. Paragraph (4) Risk control can be conducted, among others, through hedging, Risk mitigation methods, and capital addition to absorb potential losses. Furthermore, in performing the function of controlling benchmark interest rate risk, exchange rate risk, and Liquidity risk, the Bank must apply Assets and Liabilities Management (ALMA) at a minimum. Paragraph (5) Clear enough.
Article 14
Paragraph (1)
Letter a
Reports or Risk exposure information include quantitative and qualitative exposure, overall (composite) as well as details per type of Risk and per type of functional activity. Letter b Clear enough. Letter c Clear enough. Paragraph (2) The frequency of reports or information submitted to the Board of Directors can be increased according to the needs of the BUS. Paragraph (3) Clear enough.
Article 15
Clear enough.
Article 16
Paragraph (1)
Clear enough.
Paragraph (2)
Letter a
Clear enough.
Letter b
Complete, accurate, relevant, and timely financial and management information is needed for appropriate and accountable decision-making, and communicated to interested parties. Letter c Effectiveness and efficiency in operational activities are needed, among others, to protect the Bank's assets and other resources from related Risks. Letter d The effectiveness of Risk culture is intended to identify weaknesses and deviations earlier and to continuously reassess the fairness of existing Bank policies and procedures.
Article 17
Clear enough.
Article 18
Paragraph (1)
Letter a
The Risk Management Committee must be non-structural.
Letter b
The Risk Management work unit is part of the Bank's organizational structure (structural).
Paragraph (2)
This regulation is intended so that the UUS can determine the appropriate organizational structure in accordance with the BUK's condition, including financial and human resource capabilities.
Article 19
Paragraph (1)
Membership of the Risk Management Committee can be permanent and non-permanent, depending on the Bank's needs.
Letter a
Clear enough.
Letter b
The term "relevant executive officials" refers to Bank officials one level below the Board of Directors who lead operational work units and Risk Management work units. The membership of executive officials in the Risk Management Committee is adjusted to the Bank's problems and needs. Paragraph (2) Membership of the Risk Management Committee can be permanent and non-permanent, depending on the UUS's needs. Letter a Clear enough. Letter b Clear enough. Letter c The term "relevant executive officials" refers to UUS and BUK officials one level below the Board of Directors who lead operational work units and Risk Management work units. The membership of executive officials in the Risk Management Committee is adjusted to the UUS's problems and needs. Paragraph (3) Clear enough. Paragraph (4) Letter a Clear enough. Letter b Clear enough. Letter c Decisions on business that do not follow normal procedures include, among others, significant business expansion exceeding the Bank's business plan and taking positions or Risk exposure that do not conform to established limits.
Article 20
Paragraph (1)
This regulation is intended so that the Bank can determine the appropriate organizational structure in accordance with the Bank's condition, including financial and human resource capabilities. Paragraph (2) The term "independent" is reflected, among others, in:
among others, financing units, treasury, and funding.
Paragraph (3)
What is meant by "director assigned specifically" is a director who oversees the compliance function or the Risk Management Director. The term Chief Director can be equated with President Director.
Paragraph (4)
The authority and responsibility of the Risk Management work unit are adjusted to the business objectives, business complexity, and the Bank's capabilities.
Letter a
Clear enough.
Letter b
Stress testing is conducted to determine the impact of the implementation of Risk Management policies and strategies on the performance and income of each operational work unit or functional activity of the Bank.
Letter c
Reviews are conducted, among others, based on findings from internal audits and/or developments in internationally applicable Risk Management practices.
Letter d
Assessments include the Bank's ability to conduct new activities and/or products, and reviews of proposed changes to systems and procedures as well as compliance with Sharia Principles.
Letter e
Clear enough.
Letter f
Recommendations include recommendations related to the size or maximum exposure of Risks that must be maintained by the Bank.
Letter g
The Risk Profile is a comprehensive overview of the magnitude of potential Risks inherent in the Bank's entire portfolio or exposures. The frequency of report submission is increased when market conditions change rapidly. For risk exposures that change relatively slowly, such as Credit Risk, reports are submitted at least once (one) per month (one).
Article 21
The frequency of submitting risk exposure information is adjusted to the characteristics of the type of Risk.
Article 22
Paragraph (1)
Clear enough.
Paragraph (2)
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Clear enough.
Paragraph (5)
The Risk Profile report is presented comparatively with the previous quarter's position.
Paragraph (6)
Clear enough.
Paragraph (7)
Clear enough.
Article 23
Paragraph (1)
Example:
For the individual Risk Profile report as of September 2016, the Bank must submit the said report to the Financial Services Authority no later than October 21, 2016.
Paragraph (2)
Clear enough.
Paragraph (3)
Clear enough.
Paragraph (4)
Example:
If the Bank submits the individual Risk Profile report as of September 2016 on October 22, 2016, through November 21, 2016, the Bank is considered to have submitted the report late.
Paragraph (5)
Example:
If the Bank submits the individual Risk Profile report as of September 2016 after November 21, 2016, the Bank is considered not to have submitted the said report.
Article 24
Paragraph (1)
Clear enough.
Paragraph (2)
Example:
For the consolidated Risk Profile report as of September 2016, the Bank must submit the said report to the Financial Services Authority no later than October 30, 2016. Since October 30, 2016, is a holiday, the Risk Profile report must be submitted no later than October 31, 2016.
Paragraph (3)
Clear enough.
Paragraph (4)
Example:
If the Bank submits the consolidated Risk Profile report as of September 2016 on November 1, 2016, through November 17, 2016, the Bank is considered to have submitted the report late.
Paragraph (5)
Example:
If the Bank submits the consolidated Risk Profile report as of September 2016 after November 17, 2016, the Bank is considered not to have submitted the said report.
Article 25
Paragraph (1)
Clear enough.
Paragraph (2)
Other reports related to the implementation of Risk Management include, among others, the Cash Flow Projection Report and the Maturity Profile Report in the context of Risk Management Implementation for Liquidity Risk.
Paragraph (3)
Regulations governing bank reporting include, among others, regulations regarding the Periodic Report of General Banks and the Headquarters Report of General Banks.
Article 26
Clear enough.
Article 27
Assessment of the implementation of Risk Management at the Bank includes the assessment of inherent risk and the adequacy of the risk control system.
Article 28
Clear enough.
Article 29
Paragraph (1)
Clear enough.
Paragraph (2)
Risk Management performance is the result of the implementation of Risk Management for the initial period of the year (January) through the end of the year (December), including the Risk Profile, while the direction of Risk Management policy is the direction and strategy of Risk Management for the next 1 (one) year period.
Paragraph (3)
Clear enough.
Article 30
Paragraph (1)
What is meant by "day" is a working day.
Paragraph (2)
Banks that have been subjected to administrative sanctions in the form of fines in this paragraph are not subject to late submission sanctions as referred to in paragraph (1).
Paragraph (3)
Clear enough.
Paragraph (4)
Banks that have been subjected to administrative sanctions in the form of fines in this paragraph are not subject to late submission sanctions as referred to in paragraph (1).
Paragraph (5)
Clear enough.
Article 31
Clear enough.
Article 32
Clear enough.
Article 33
Clear enough.
Article 34
Clear enough.
Article 35
Clear enough.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 5988
APPENDIX
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 65/POJK.03/2016
REGARDING
RISK MANAGEMENT IMPLEMENTATION FOR
ISLAMIC GENERAL BANKS AND ISLAMIC BUSINESS UNITS
I. Risk Profile Report Format for Banks Individually
RISK PROFILE
FOR BANKS INDIVIDUALLY
Bank Name :
Position : March 31/September 30, 20…
Risk Profile
Assessment per Position Assessment Previous Position Risk Rating Inherent Rating Quality Risk Management Implementation Risk Rating Risk Rating Inherent Rating Quality Risk Management Implementation Risk Rating Credit Risk Market Risk Liquidity Risk Operational Risk Legal Risk Strategic Risk Compliance Risk Reputational Risk Yield Risk Investment Risk Composite Rating Risk Profile Rating Risk Profile Rating Analysis Description of the Bank's overall Risk profile includes assessment of inherent Risk and quality of Risk Management implementation, with a focus on significant Risk exposures at the Bank.
II. Risk Profile Report Format for Banks Consolidated
RISK PROFILE
FOR BANKS CONSOLIDATED*)
Bank Name :
Position : March 31/September 30, 20…
Risk Profile
Assessment per Position Assessment Previous Position Risk Rating Inherent Rating Quality Risk Management Implementation Risk Rating Risk Rating Inherent Rating Quality Risk Management Implementation Risk Rating Credit Risk Market Risk Liquidity Risk Operational Risk Legal Risk Strategic Risk Compliance Risk Reputational Risk Yield Risk Investment Risk Composite Rating Risk Profile Rating Risk Profile Rating *) Only to be filled by Banks having Subsidiary Companies Analysis Description of the Bank's overall Risk profile includes assessment of inherent Risk and quality of Risk Management implementation, with a focus on significant Risk exposures at the Bank. In the event the Bank has subsidiary companies that must be consolidated, the Bank calculates the impact of the subsidiary companies' Risks on the Bank's Risk profile by considering the significance and materiality of the subsidiary companies and/or the significance of the subsidiary companies' issues.
III. Risk Analysis Report Format
RISK ANALYSIS …………. *)
Bank Name :
Position :
Analysis
Risk Rating:
Final conclusion regarding the Bank's Risk level covering inherent Risk level and quality of Risk Management implementation so as to describe the Bank's Risk level. Inherent Risk:
Description of the assessment of inherent Risk based on analysis of assessment factors using both quantitative and qualitative indicators so as to describe the Bank's inherent Risk level. Quality of Risk Management Implementation:
Analysis of the Quality of Risk Management Implementation consists of Risk governance; Risk management framework; Risk Management process, HR, and MIS; and Risk control. *) This working paper is used to support the analysis of Risks at the Bank, including Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Strategic Risk, Compliance Risk, Reputational Risk, Yield Risk, and Investment Risk.
Determined in Jakarta on December 23, 2016
CHAIRMAN OF THE COMMISSIONERS COUNCIL
FINANCIAL SERVICES AUTHORITY, sign
MULIAMAN D. HADAD
Copy matches the original
Director of Law 1
Department of Law sign
Yuliana
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.