2016-12-07 | 38/POJK.03/2016Added
Commercial banks must implement effective information technology risk management, including active oversight by the Board of Directors and Board of Commissioners, adequate policies and procedures, and integrated risk identification and control processes. Banks are required to establish an IT Steering Committee, maintain a Disaster Recovery Plan with annual testing and review, and ensure information security through confidentiality, integrity, and availability principles. The regulation mandates internal audit functions for IT, requiring annual audits and a triennial independent review, while holding banks accountable for the risk management practices of their third-party IT service providers.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
NUMBER 38 /POJK.03/2016
ABOUT
IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY COMMERCIAL BANKS
BY THE GRACE OF GOD THE ALMIGHTY
THE COMMISSIONERS OF THE FINANCIAL SERVICES AUTHORITY,
Considering:
a. that the development of information technology can be utilized by banks to increase the efficiency of operational activities and the quality of bank services to customers; b. that the use of information technology in bank operational activities can also increase the risks faced by banks;
c. that with the increasing risks faced, banks need to implement risk management effectively;
d. that information technology is a valuable asset for banks, so its management is not only the responsibility of the information technology organizing unit but also all parties using it; e. that in the implementation of the Basel framework, adequate information technology infrastructure is required; f. that in line with the dynamics of regulations related to the use of information technology and the development of national and international standards, it is necessary to improve regulations regarding the implementation of risk management in the use of information technology by banks; g. that in relation to the considerations as referred to in letters a, b, c, d, e, and f, it is necessary to establish a Financial Services Authority Regulation regarding the Implementation of Risk Management in the Use of Information Technology by Commercial Banks;
Recalling:
DECIDING:
To Establish: A FINANCIAL SERVICES AUTHORITY REGULATION REGARDING THE IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY COMMERCIAL BANKS.
GENERAL PROVISIONS
In this Financial Services Authority Regulation, the following terms are meant:
Bank means Commercial Banks as referred to in Law Number 7 of 1992 concerning Banking as amended by Law Number 10 of 1998, including branches of banks located abroad, and Sharia Commercial Banks and Sharia Business Units as referred to in Law Number 21 of 2008 concerning Sharia Banking.
Information Technology is a technique to collect, prepare, store, process, announce, analyze, and/or disseminate information.
Electronic Banking Services are services for Bank customers to obtain information, communicate, and conduct banking transactions through electronic media.
Information Technology Strategic Plan is a document describing the Bank's Information Technology vision and mission, strategies supporting the Bank's Information Technology vision and mission, and main principles serving as guidelines in the use of Information Technology to meet business needs and support long-term strategic plans.
Electronic System is a series of electronic devices and procedures functioning to prepare, collect, process, analyze, store, display, announce, transmit, and/or disseminate electronic information.
Data Center is a facility used to place the Electronic System and its related components for the purpose of placement, storage, and data processing.
Disaster Recovery Center is a facility used to restore data or information and important functions of the Electronic System that are disturbed or damaged due to disasters caused by nature or humans.
Database is a comprehensive set of data arranged systematically, accessible by users according to their respective authority, and managed by a Database Administrator.
Disaster Recovery Plan is a document containing plans and steps to replace and/or restore access to data, hardware, and software required, so that the Bank can carry out critical business operational activities after disturbances and/or disasters.
Information Technology-Based Transaction Processing is activities involving the addition, change, deletion, and/or authorization of data performed on application systems used to process transactions.
Board of Directors:
a) for Banks in the form of a Limited Liability Company means the Board of Directors as referred to in Law Number 40 of 2007 concerning Limited Liability Companies; b) for Banks in the form of legal entities:
1) Regional Public Enterprises or Regional State-Owned Enterprises means the Board of Directors as referred to in Law Number 23 of 2014 concerning Regional Government as last amended by Law Number 9 of 2015;
2) Regional Enterprises means the Board of Directors for Banks that have not yet changed their form into Regional Public Enterprises or Regional State-Owned Enterprises as referred to in Law Number 23 of 2014 concerning Regional Government as last amended by Law Number 9 of 2015;
c) for Banks in the form of a Cooperative legal entity means the management as referred to in Law Number 25 of 1992 concerning Cooperatives; d) for Banks with the status of a branch of a bank located abroad means the branch head and officials one level below the branch head.
Board of Commissioners:
a) for Banks in the form of a Limited Liability Company means the Board of Commissioners as referred to in Law Number 40 of 2007 concerning Limited Liability Companies; b) for Banks in the form of legal entities:
1) Regional Public Enterprises means the Supervisory Board as referred to in Law Number 23 of 2014 concerning Regional Government as last amended by Law Number 9 of 2015;
2) Regional State-Owned Enterprises means Commissioners as referred to in Law Number 23 of 2014 concerning Regional Government as last amended by Law Number 9 of 2015;
3) Regional Enterprises means Supervisors at Banks that have not yet changed their form into Regional Public Enterprises or Regional State-Owned Enterprises as referred to in Law Number 23 of 2014 concerning Regional Government as last amended by Law Number 9 of 2015;
c) for Banks in the form of a Cooperative legal entity means Supervisors as referred to in Law Number 25 of 1992 concerning Cooperatives; d) for Banks with the status of a branch of a bank located abroad means parties appointed to carry out supervisory functions.
SCOPE OF INFORMATION TECHNOLOGY RISK MANAGEMENT
(1) Banks are required to implement risk management effectively in the use of Information Technology.
(2) The implementation of risk management as referred to in paragraph (1) must at least cover:
a. active supervision by the Board of Directors and Board of Commissioners; b. adequacy of policies, standards, and procedures for the use of Information Technology;
c. adequacy of processes for identifying, measuring, monitoring, and controlling Information Technology usage risks; and
d. an internal control system over the use of Information Technology.
(3) The implementation of risk management must be carried out in an integrated manner at every stage of Information Technology usage from the planning, procurement, development, operation, maintenance stages to the cessation and deletion of Information Technology resources.
The implementation of risk management in the use of Information Technology by Banks as referred to in Article 2 must be adjusted to the Bank's objectives, business policies, size, and complexity of business.
IMPLEMENTATION OF INFORMATION TECHNOLOGY RISK MANAGEMENT
Active Supervision by the Board of Directors and Board of Commissioners
Banks are required to establish clear authority and responsibility of the Board of Directors, Board of Commissioners, and officials at every level of position related to the use of Information Technology.
The authority and responsibility of the Board of Directors as referred to in Article 4 must at least cover:
a. establishing the Information Technology Strategic Plan and Bank policies related to the use of Information Technology; b. establishing adequate policies, standards, and procedures related to Information Technology organization and communicating them effectively, both to the organizing units and users of Information Technology;
c. ensuring:
1. the Information Technology used by the Bank can support the Bank's business development, achievement of the Bank's business objectives, and continuity of service to Bank customers;
2. there are activities to improve the competence of human resources related to the organization and use of Information Technology;
3. the availability of an effective information security management system communicated to user and organizing units of Information Technology;
4. the implementation of risk management processes in the use of Information Technology is carried out adequately and effectively;
5. Information Technology policies, standards, and procedures are implemented effectively in user and organizing units of Information Technology;
6. there is a system for measuring the performance of the Information Technology organization process that can at least:
a) support the monitoring process of strategy implementation; b) support the completion of Information Technology development projects; c) optimize the utilization of human resources and investment in infrastructure; and d) improve the performance of the Information Technology organization process and the quality of service delivery of process results to Information Technology users.
The authority and responsibility of the Board of Commissioners as referred to in Article 4 must at least cover:
a. evaluating, directing, and monitoring the Information Technology Strategic Plan and Bank policies related to the use of Information Technology; and b. evaluating the Board of Directors' accountability regarding the implementation of risk management in the use of Information Technology.
(1) Banks are required to have an Information Technology Steering Committee.
(2) The Information Technology Steering Committee as referred to in paragraph (1) is responsible for providing recommendations to the Board of Directors at least regarding:
a. the Information Technology Strategic Plan that aligns with the Bank's business activity strategic plan; b. the formulation of main Information Technology policies, standards, and procedures;
c. the conformity between approved Information Technology projects and the Information Technology Strategic Plan;
d. the conformity between the implementation of Information Technology projects and the agreed project plan (project charter); e. the conformity between Information Technology and management information system needs as well as Bank business activity needs; f. the effectiveness of steps to minimize risks over the Bank's investment in the Information Technology sector so that the Bank's investment in the Information Technology sector contributes to the achievement of the Bank's business objectives; g. monitoring Information Technology performance and efforts to improve Information Technology performance; h. efforts to resolve various Information Technology-related problems that cannot be resolved effectively, efficiently, and on time by user and organizing units of Information Technology; and
i. the adequacy and allocation of resources owned by the Bank.
(3) The Information Technology Steering Committee as referred to in paragraph (1) must at least consist of:
a. a director overseeing the Information Technology unit; b. a director overseeing the risk management unit;
c. the highest official leading the Information Technology unit; and
d. the highest official leading the Information Technology user unit.
(4) The Information Technology Steering Committee as referred to in paragraph (3) is chaired by one of the Bank's directors who also serves as a member.
Adequacy of Policies, Standards, and Procedures for the Use of Information Technology at Banks
(1) Banks are required to have policies, standards, and procedures for the use of Information Technology as referred to in Article 2 paragraph (2) letter b and are required to implement policies, standards, and procedures for the use of Information Technology consistently and continuously. (2) Policies, standards, and procedures for the use of Information Technology must at least cover aspects:
a. management; b. development and procurement;
c. Information Technology operations;
d. communication networks; e. information security; f. Disaster Recovery Plan; g. Electronic Banking Services; h. use of third-party Information Technology service providers; and
i. provision of Information Technology services by the Bank.
(3) Banks are required to establish risk limits that can be tolerated to ensure that aspects related to Information Technology as referred to in paragraph (2) can run optimally. (4) Banks are required to conduct periodic reviews and updates of policies, standards, and procedures as referred to in paragraph (2). (5) Banks are required to establish the review and update period for policies, standards, and procedures as referred to in paragraph (4) in written policy.
(1) Banks are required to have an Information Technology Strategic Plan that supports the Bank's business activity strategic plan.
(2) The Information Technology Strategic Plan as referred to in paragraph (1) must be included in the Bank's business plan.
Risk Management Processes Related to Information Technology
(1) Banks are required to have policies, standards, and procedures for the Information Technology risk management process.
(2) Banks are required to conduct risk management processes related to the use of Information Technology.
(3) The risk management process as referred to in paragraph (2) is conducted at least on aspects related to Information Technology as referred to in Article 8 paragraph (2). (4) In the event that Banks use third-party Information Technology service providers, Banks are required to ensure that third-party Information Technology service providers implement risk management as regulated in this Financial Services Authority Regulation.
In conducting Information Technology development and procurement, Banks are required to take control steps to produce systems and data that maintain confidentiality and integrity and support the achievement of the Bank's objectives, including:
a. establishing and implementing Information Technology development and procurement procedures and methodologies consistently; b. applying project management in system development;
c. conducting adequate testing during the development and procurement of a system, including joint testing with user units, to ensure system accuracy and functionality according to user needs and conformity between systems;
d. documenting system development and maintenance; e. having application system change management; f. ensuring the Bank's Information Technology systems are capable of displaying information completely; and g. measuring the urgency of creating a written escrow agreement for software considered important for the Bank's operational continuity in the event the software is made by third parties and source code is not provided to the Bank.
Banks are required to ensure the continuity and stability of Information Technology operations and mitigate risks that have the potential to disrupt the Bank's operational activities.
Banks are required to provide communication networks that meet the principles of confidentiality, integrity, and availability.
For conventional commercial banks that have Sharia business units, they are required to have a system that can generate separate reports for Sharia business unit activities.
(1) Banks are required to have a Disaster Recovery Plan.
(2) Banks are required to ensure that the Disaster Recovery Plan as referred to in paragraph (1) can be implemented effectively so that the Bank's operational continuity remains running during disasters and/or disturbances to the Information Technology facilities used by the Bank. (3) Banks are required to conduct tests on the Disaster Recovery Plan for all critical applications and infrastructure according to the results of the business impact analysis, at least 1 (one) time in 1 (one) year by involving Information Technology users. (4) Banks are required to review the Disaster Recovery Plan at least 1 (one) time in 1 (one) year.
Banks are required to ensure that information security is implemented effectively by considering at least:
a. information security aimed at ensuring that managed information maintains confidentiality, integrity, and availability effectively and efficiently by considering compliance with regulations; b. information security conducted on technology, human resources, and process aspects in the use of Information Technology;
c. information security applied based on the results of risk assessment on information owned by the Bank; and
d. the availability of incident management management in information security.
Internal Control and Audit System over Information Technology Organization
(1) Banks are required to implement an internal control system effectively on all aspects of Information Technology usage.
(2) The internal control system as referred to in paragraph (1) must at least cover:
a. supervision by management and the existence of a control culture; b. risk identification and assessment;
c. control activities and segregation of functions;
d. information systems, accounting systems, and communication systems; and e. monitoring activities and correction of deviations, carried out by operational units, internal audit units, or other parties. (3) Information systems, accounting systems, and communication systems as referred to in paragraph (2) letter d must be supported by adequate technology, human resources, and the Bank's organizational structure. (4) Monitoring activities and corrective actions for deviations as referred to in paragraph (2) letter d must at least cover:
a. continuous monitoring activities; b. the implementation of effective and comprehensive internal audit functions; and
c. improvements to deviations identified by operational units, internal audit units, and/or other parties.
(1) The implementation of the Information Technology internal audit function as referred to in Article 17 paragraph (4) letter b considers compliance with regulations regarding standards for the implementation of the internal audit function. (2) In order to ensure the implementation of Information Technology internal audit as referred to in Article 17 paragraph (4) letter b, Banks are required to ensure the availability of audit trails for all Information Technology organization activities for the purposes of supervision, law enforcement, dispute resolution, verification, testing, and other examinations. (3) In the event of limitations in the internal audit unit's capabilities, the implementation of the Information Technology internal audit function as referred to in paragraph (1) can be conducted by external auditors. (4) Banks are required to conduct internal audits on all aspects in the organization and use of Information Technology according to needs, priorities, and the results of Information Technology risk analysis at least 1 (one) time in 1 (one) year.
(1) Banks are required to have internal audit guidelines for the use of Information Technology organized by the Bank itself and/or by third-party Information Technology service providers. (2) Banks are required to review the internal audit function for the use of Information Technology at least 1 (one) time in 3 (three) years. (3) The review as referred to in paragraph (2) must use the services of independent external parties. (4) Banks are required to submit to the Financial Services Authority:
a. the results of the review as referred to in paragraph (3) accompanied by improvement recommendations as part of the review report; and b. the results of internal audits on Information Technology as part of the report on the implementation and main points of internal audit results, as regulated in regulations regarding the implementation of standards for the internal audit function.
INFORMATION TECHNOLOGY ORGANIZATION BY BANKS AND/OR THIRD-PARTY INFORMATION TECHNOLOGY SERVICE PROVIDERS
General
(1) Banks organize Information Technology.
(2) The organization of Information Technology as referred to in paragraph (1) can be conducted by the Bank itself and/or third-party Information Technology service providers. (3) In the event that the Bank's Information Technology organization is conducted by third-party Information Technology service providers as referred to in paragraph (2), Banks are required to:
a. be responsible for the implementation of risk management; b. have an Information Technology unit;
c. have the highest official leading the Information Technology unit;
d. be capable of supervising the implementation of Bank activities organized by third-party providers; e. select third-party Information Technology service providers based on cost and benefit analysis by involving the Bank's Information Technology unit; f. monitor and evaluate the reliability of third-party Information Technology service providers periodically regarding performance, provider reputation, and continuity of service provision; g. provide access to internal auditors, external auditors, and the Financial Services Authority to obtain data and information whenever needed; h. provide the Financial Services Authority with timely access to the Database, both for current data and past data; and
i. ensure that third-party Information Technology service providers:
1. have reliable experts supported by academic and/or professional expertise certificates according to the needs of Information Technology organization;
2. apply adequate Information Technology control principles proven by audit results conducted by independent parties;
3. provide access for the Bank's internal auditors, external auditors appointed by the Bank, the Financial Services Authority, and/or other parties in accordance with applicable regulations;
legislation competent to conduct examinations in order to obtain data and information that are needed accurately and in a timely manner whenever required;
4. state no objection in the event that the Financial Services Authority and/or other parties authorized by law conduct examinations, will conduct examinations against the provision of services provided;
5. as an affiliated party, maintain the security of all information including Bank secrets and customer personal data;
6. may only transfer part of its activities (subcontracting) based on Bank approval evidenced by written documents;
7. report to the Bank every critical incident that could result in significant financial losses and/or disrupt the Bank's operational smoothness;
8. submit the results of Information Technology audits conducted by independent auditors periodically regarding the management of Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Transaction Processing, to the Financial Services Authority through the relevant Bank;
9. provide a tested and adequate Disaster Recovery Plan;
10. be willing to the possibility of early termination of the agreement before the agreement period ends; and
as referred to in paragraph (6) is known by the Bank; b. decide on follow-up actions to be taken to address problems including stopping the use of services if necessary; and
c. report to the Financial Services Authority immediately after the Bank stops using services before the end of the agreement period.
(8) In the event that the use of Information Technology service providers or the plan to use Information Technology service providers causes or is indicated to cause supervisory difficulties for the Financial Services Authority, the Financial Services Authority may:
a. order the Bank to stop using Information Technology services before the end of the agreement period; or b. reject the plan to use Information Technology service providers submitted by the Bank. Second Section Placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers
Article 21
(1) Banks must place Electronic Systems in Data Centers and Disaster Recovery Centers within the territory of Indonesia.
(2) Banks may only place Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia provided they obtain approval from the Financial Services Authority. (3) Electronic Systems that can be placed in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in paragraph (2) are:
a. Electronic Systems used to support integrated analysis in order to meet global home regulatory requirements, including cross-border, as long as they are not directly related to individual customer data and transaction data of each customer, unless otherwise regulated by home regulatory. b. Electronic Systems used for integrated risk management with the head office or parent office/main entity office outside the territory of Indonesia, provided they use:
Article 22
(1) Data Centers and Disaster Recovery Centers as referred to in Article 21 must guarantee the continuity of the Bank's business.
(2) The management of Data Centers and Disaster Recovery Centers as referred to in paragraph (1) is further regulated in a Circular Letter of the Financial Services Authority. Third Section Management of Information Technology-Based Transaction Processing by Service Providers
Article 23
(1) Banks must manage Information Technology-Based Transaction Processing within the territory of Indonesia.
(2) Information Technology-Based Transaction Processing may be carried out by service providers within the territory of Indonesia.
(3) The management of Information Technology-Based Transaction Processing by service providers as referred to in paragraph (2) may be carried out provided that:
a. it meets the prudential principle; b. it meets the requirements as referred to in Article 20 paragraph (3), paragraph (4), and paragraph (5); and
c. it pays attention to customer protection aspects.
(4) Information Technology-Based Transaction Processing by Information Technology service providers may be carried out outside the territory of Indonesia provided that:
a. it meets the requirements as referred to in paragraph (3); b. supporting administrative financial documents for transactions conducted at the Bank's office in Indonesia must be accounted for at the Bank's office in Indonesia;
c. the Bank's business plan shows efforts to increase the Bank's role for the development of the Indonesian economy; and
d. prior approval is obtained from the Financial Services Authority.
Article 24
(1) Banks must include plans to use Information Technology service providers in the management of Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Transaction Processing in the Information Technology Strategic Plan and the Bank's business plan. (2) Banks must report plans to use Information Technology service providers in the management of Data Centers, Disaster Recovery Centers and/or Information Technology-Based Transaction Processing within the territory of Indonesia to the Financial Services Authority no later than 2 (two) months before the activities by the service provider are effectively operated. (3) In the event there is a plan to manage Electronic Systems outside the territory of Indonesia, Banks must submit an application for approval to the Financial Services Authority no later than 3 (three) months before the activities by the Information Technology service provider are effectively operated. (4) The realization of plans to manage Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Processing by Information Technology service providers must be reported no later than 1 (one) month since the activities were effectively operated. (5) Approval or rejection of applications as referred to in paragraph (3) is given by the Financial Services Authority no later than 3 (three) months after the application documents are received completely and adequately.
(6) The procedure for submitting plans and realization of plans as referred to in paragraph (2), paragraph (3), and paragraph (4) is carried out using the Information Technology usage report format which is further regulated in a Circular Letter of the Financial Services Authority. Fourth Section Provision of Information Technology Services by Banks
Article 25
(1) Banks may provide Information Technology services to other financial service institutions:
a. which are supervised by the Financial Services Authority, and/or b. outside the territory of Indonesia.
(2) Banks must obtain approval from the Financial Services Authority in providing Information Technology services to financial service institutions as referred to in paragraph (1). (3) Approval from the Financial Services Authority as referred to in paragraph (2) may be granted provided that the Bank:
a. meets the requirements that the provision of Information Technology services does not become one of the Bank's main activities; b. meets the prudential principle;
c. pays attention to cost and benefit analysis;
d. meets the provisions of legislation; and e. meets the arm's length principle.
(4) The provision of Information Technology services as referred to in paragraph (1) is limited only to the management of Data Centers and/or Disaster Recovery Centers.
(5) Banks may provide Information Technology services in the form of applications with the approval of the Financial Services Authority, provided that:
a. it still meets the requirements in paragraph (3) and the financial service institution using the Information Technology services is a Bank; and b. the provision of Information Technology services supports financial inclusion programs; and/or
c. the users of Information Technology services are in the same conglomerate.
Article 26
The provision of Information Technology services in the context of developing Bank product services and/or activities is excluded from the regulations as referred to in Article 25.
CHAPTER V
ELECTRONIC BANKING SERVICES
Article 27
(1) Banks managing Electronic Banking Services must meet the regulations of the Financial Services Authority and/or other relevant authorities.
(2) Banks managing advanced Electronic Banking Service products categorized as digital banking services must meet the regulations of the Financial Services Authority.
(3) Further regulations regarding digital banking services are regulated in the regulations of the Financial Services Authority.
Article 28
(1) Banks must include plans for issuing Electronic Banking Service products in the Bank's business plan.
(2) Banks that will issue Electronic Banking Service products that are transactional in nature must submit an application for approval of the Electronic Banking Service product and obtain approval from the Financial Services Authority. (3) The application for approval of Electronic Banking Service products as referred to in paragraph (2) must be accompanied by the following matters:
a. evidence of readiness to manage Electronic Banking Services which must at least contain:
(4) Submission of applications as referred to in paragraph (2) must be accompanied by the results of examinations from independent parties to provide opinions on the characteristics of the product and the adequacy of security of the related Information Technology systems as well as compliance with applicable regulations and/or international practices. (5) The management of Information Technology for Electronic Banking Service activities carried out by Information Technology service providers is subject to the regulations as regulated in Chapter IV regarding the management of Information Technology by Banks and/or Information Technology service providers.
Article 29
Banks must apply the principle of data security control for customer data and Electronic Banking Service transactions on every Electronic System used by the Bank.
CHAPTER VI
REPORTING
First Section
Information Technology Reports
Article 30
(1) Banks must report the current condition of Information Technology usage no later than 1 (one) month since the end of the reporting year.
(2) Banks must report plans for Information Technology development to be implemented in the next 1 (one) year no later than October 31 of the previous year.
(3) Plans for Information Technology development as referred to in paragraph (2) may be changed 1 (one) time.
(4) Changes to Information Technology development plans as referred to in paragraph (3) must be submitted no later than June 30 of the current year.
(5) Banks may apply for changes to Information Technology development plans outside the timeframes as referred to in paragraph (4) provided they meet certain considerations and obtain approval from the Financial Services Authority. (6) The Financial Services Authority is competent to request Banks to make adjustments to changes in Information Technology development plans as referred to in paragraph (2). (7) Banks must report the results of Information Technology audits no later than 2 (two) months after the audit is completed. Second Section Incidental Reports
Article 31
(1) Banks must report critical incidents, misuse, and/or crimes in the management of Information Technology that can and/or have resulted in significant financial losses and/or disrupted the Bank's operational smoothness. (2) Reports as referred to in paragraph (1) must be submitted immediately to the Financial Services Authority via electronic mail or telephone followed by a written report no later than 7 (seven) working days after the critical incident and/or misuse or crime is known. (3) Written reports as referred to in paragraph (2) are part of the condition reports that have the potential to cause significant losses to the Bank's financial condition as referred to in the Financial Services Authority Regulation on the Implementation of Risk Management for Commercial Banks. Third Section Applications for Approval and Realization Reports
Article 32
(1) Banks that have plans for activities as Information Technology service providers as referred to in Article 25 and/or issuing Electronic Banking Service products as referred to in Article 28, must submit applications for approval to the Financial Services Authority no later than 2 (two) months before implementation. (2) Banks must submit realization reports of activities as Information Technology service providers as referred to in Article 25 and/or issuing Electronic Banking Service products as referred to in Article 28 to the Financial Services Authority no later than 3 (three) months after implementation. (3) Banks that:
a. manage Electronic Systems placed in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in Article 21; and/or b. entrust the management of Information Technology-Based Transaction Processing to service providers outside the territory of Indonesia as referred to in Article 23, must submit applications for approval to the Financial Services Authority no later than 3 (three) months before the implementation plan.
(4) Banks that:
a. manage Electronic Systems placed in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in Article 21; and/or b. entrust the management of Information Technology-Based Transaction Processing to service providers outside the territory of Indonesia as referred to in Article 23, must submit realization reports to the Financial Services Authority no later than 3 (three) months after implementation. (5) Banks must implement activity plans as referred to in paragraph (1) and/or paragraph (3) no later than 6 (six) months since approval was given by the Financial Services Authority. (6) In the event that Banks do not implement activity plans as referred to in paragraph (1) and/or paragraph (3) within the 6 (six) month period since approval was given by the Financial Services Authority as referred to in paragraph (5), the Financial Services Authority's approval becomes invalid. (7) In the event that the Financial Services Authority's approval has become invalid as referred to in paragraph (6), and Banks still intend to implement the Bank's activity plans as referred to in paragraph (1) and/or paragraph (3), Banks must submit applications for approval to the Financial Services Authority again.
Fourth Section
Report Format and Submission Address
Article 33
The format and instructions for compiling reports as referred to in Article 30, Article 31, and Article 32 are regulated in a Circular Letter of the Financial Services Authority.
Article 34
Applications for approval to use Information Technology service providers outside the territory of Indonesia as referred to in Article 21 and Article 23, applications for approval to issue Electronic Banking Service products as referred to in Article 28, as well as the submission of reports as referred to in Article 30, Article 31, and Article 32 are submitted to the Financial Services Authority at the address:
a. The Department of Supervision of the relevant Bank, Department of Sharia Banking or Regional Office of the Financial Services Authority in Jakarta, for Banks with headquarters or branch offices of banks located outside the country that are in the Special Capital Region of Jakarta Province; or b. Regional Office of the Financial Services Authority or Local Office of the Financial Services Authority, according to the area where the Bank's headquarters is located.
CHAPTER VII
OTHERS
Article 35
(1) The Financial Services Authority may conduct examinations or request Banks to conduct examinations on all aspects related to the use of Information Technology.
(2) Banks must provide access to the Financial Services Authority to conduct examinations on all aspects related to the management of Information Technology managed by itself and/or by other parties.
CHAPTER VIII
SANCTIONS
Article 36
(1) Banks that do not implement regulations as stipulated in Article 2 paragraph (1), Article 3, Article 4, Article 7 paragraph (1), Article 8 paragraph (1), Article 8 paragraph (3), Article 8 paragraph (4), Article 8 paragraph (5), Article 9, Article 10 paragraph (1), Article 10 paragraph (2), Article 10 paragraph (4), Article 11, Article 12, Article 13, Article 14,
Article 15, Article 16, Article 17 paragraph (1), Article 18 paragraph (2), Article 18 paragraph (4), Article 19, Article 20 paragraph (3), Article 20 paragraph (4), Article 20 paragraph (5), Article 20 paragraph (6), Article 21 paragraph (1), Article 23 paragraph (1), Article 23 paragraph (4), Article 24 paragraph (1), Article 24 paragraph (2), Article 24 paragraph (3), Article 24 paragraph (4), Article 25 paragraph (2), Article 27 paragraph (1), Article 27 paragraph (2), Article 28 paragraph (1), Article 28 paragraph (2), Article 28 paragraph (3), Article 29, and/or Article 35 paragraph (2) of this Financial Services Authority Regulation, may be subject to administrative sanctions in the form of:
a. written reprimand; b. reduction in health level by reducing the governance factor rating in the Bank's health level assessment;
c. prohibition on issuing products or carrying out new activities;
d. suspension of certain business activities; and/or e. inclusion of Board of Directors members, Board of Commissioners members, and executive officials in the list of unqualified through the competency and propriety assessment mechanism.
(2) Sanctions as referred to in paragraph (1) letter b, letter c, letter d or letter e may be imposed with or without prior imposition of written reprimand sanctions as referred to in paragraph (1) letter a.
Article 37
(1) Banks that do not meet reporting regulations as referred to in Article 30 paragraph (1), Article 30 paragraph (2), Article 30 paragraph (7), Article 31 paragraph (1), Article 31 paragraph (2), Article 32 paragraph (2), and/or Article 32 paragraph (4) of this Financial Services Authority Regulation are subject to administrative sanctions in the form of:
a. fines of Rp1,000,000.00 (one million rupiah) per day of delay per report; or b. fines of Rp50,000,000.00 (fifty million rupiah) per report, for Banks that have not submitted reports after 1 (one) month since the final deadline for report submission. (2) The imposition of fine sanctions as referred to in paragraph (1) does not eliminate the obligation to submit reports.
Article 38
(1) Banks that submit reports as referred to in Article 30 paragraph (1), Article 30 paragraph (2), Article 30 paragraph (7), Article 31 paragraph (1), Article 31 paragraph (2), Article 32 paragraph (2), and/or Article 32 paragraph (4), but not in accordance with the Bank's actual conditions, are subject to administrative sanctions in the form of fines of Rp50,000,000.00 (fifty million rupiah). (2) Banks are subject to sanctions as referred to in paragraph (1) after:
a. Banks are given 2 (two) written reprimands by the Financial Services Authority with a grace period of 7 (seven) working days for each reprimand; and
b. The Bank fails to correct the report within 7 (seven) working days after the final written warning.
CHAPTER IX
TRANSITIONAL PROVISIONS
Article 39
Banks that have already established policies, standards, and procedures in the use of Information Technology and guidelines for risk management in the use of Information Technology must adjust to the provisions in this Financial Services Authority Regulation no later than 12 (twelve) months from the effective date of this Financial Services Authority Regulation.
Article 40
Banks that have used Information Technology service providers prior to the effective date of this Financial Services Authority Regulation must adjust the agreements already made in accordance with the provisions in this Financial Services Authority Regulation.
Article 41
(1) Banks that have placed Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia prior to the effective date of this Financial Services Authority Regulation must relocate the Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Transaction Processing that operate Electronic Systems for public services to Indonesia no later than October 15, 2017. (2) In the context of relocating the location of Data Centers, Disaster Recovery Centers, and/or Information Technology-Based Transaction Processing from outside the territory of Indonesia to Indonesia, Banks must submit an action plan report to the Financial Services Authority no later than December 30, 2016.
CHAPTER X
FINAL PROVISIONS
Article 42
Further provisions regarding the Implementation of Risk Management in the Use of Information Technology by Commercial Banks shall be regulated in a Circular Letter of the Financial Services Authority.
Article 43
(1) Upon the effective date of this Financial Services Authority Regulation, Bank Indonesia Regulation Number 9/15/PBI/2007 regarding the Implementation of Risk Management in the Use of Information Technology by Commercial Banks (State Gazette of the Republic of Indonesia Year 2007 Number 144, Supplement to the State Gazette of the Republic of Indonesia Number 4785) is repealed and declared invalid. (2) Implementation regulations of Bank Indonesia Regulation Number 9/15/PBI/2007 regarding the Implementation of Risk Management in the Use of Information Technology by Commercial Banks (State Gazette of the Republic of Indonesia Year 2007 Number 144, Supplement to the State Gazette of the Republic of Indonesia Number 4785) remain valid insofar as they do not conflict with the provisions in this Financial Services Authority Regulation.
Article 44
This Financial Services Authority Regulation shall come into force on the date of its promulgation and establishment.
In order for everyone to know it, it is ordered to promulgate this Financial Services Authority Regulation by placing it in the State Gazette of the Republic of Indonesia.
Established in Jakarta on December 1, 2016
CHAIRMAN OF THE COMMISSIONERS BOARD
FINANCIAL SERVICES AUTHORITY, signed
MULIAMAN D. HADAD
Promulgated in Jakarta on December 7, 2016
MINISTER OF LAW AND HUMAN RIGHTS
REPUBLIC OF INDONESIA, signed
YASONNA H. LAOLY
STATE GAZETTE OF THE REPUBLIC OF INDONESIA YEAR 2016 NUMBER 267
A copy consistent with the original
Director of Legal Affairs 1
Department of Law signed
Yuliana
EXPLANATION
OF
FINANCIAL SERVICES AUTHORITY REGULATION
NUMBER 38 /POJK.03/2016
REGARDING
THE IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY COMMERCIAL BANKS
I. GENERAL
In order to improve the efficiency of operational activities and the quality of Bank services to its customers, Banks are required to develop their Bank business strategies more optimally by utilizing Information Technology advancements to enhance Bank competitiveness.
The implementation of Information Technology brings changes in operational activities and Bank data management so that they can be carried out more efficiently and effectively, as well as providing information more accurately and quickly. The development of technology-based banking products, including Electronic Banking Services and digital banking services, makes it easier for customers to conduct non-cash banking transactions at any time via electronic networks. In addition, the use of third-party services in the provision of Bank systems and services has also increased.
Along with the various benefits and advantages obtained from the use of Information Technology in carrying out Bank operational activities, there are also risks that can harm Banks and customers, such as operational risk, legal risk, and reputational risk, in addition to other banking risks such as liquidity risk and credit risk.
Therefore, in order to protect the interests of Banks and also customers, Banks are required to implement risk management effectively so that Banks can control the possibility of increased risk occurrence.
Considering that Information Technology is an important asset in operations that can increase added value and Bank competitiveness, while its implementation involves various risks, Banks need to implement information technology governance. The successful implementation of information technology governance depends heavily on the commitment of all work units in the Bank, both organizers and users of Information Technology. The implementation of information technology governance is carried out through the alignment of the Information Technology Strategic Plan with the Bank's business strategy, optimization of resource management, utilization of Information Technology (Information Technology value delivery), performance measurement, and the implementation of effective risk management.
To be able to implement effective risk management, the involvement and supervision of the Board of Directors and Board of Commissioners are required, the formulation and implementation of policies, standards, and procedures related to Information Technology, as well as a continuous process of risk identification, measurement, monitoring, and control.
In addition, in the future, Banks are also required to anticipate the need for adequate Information Technology infrastructure in order to face the implementation of the Basel framework.
Along with developments at both the national and international levels, up to now several regulatory provisions related to Information Technology have been issued, including Laws regarding Electronic Information and Transactions and its implementing regulations in the form of Government Regulations regarding the Organization of Electronic Systems and Transactions and relevant Ministerial Regulations. In addition, reference standards for assessment related to Information Technology, such as National Standards of Indonesia (SNI), International Organization for Standardization (ISO), Control Objective for Information and Related Technology (COBIT), and International Electrotechnical Commission (IEC), have also been updated to become more comprehensive in supporting the development and implementation of Information Technology.
With these provisions, Banks are expected to be able to manage the risks faced effectively in all operational activities supported by the utilization of Information Technology.
II. ARTICLE BY ARTICLE
Article 1
Sufficiently clear.
Article 2
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Information Technology resources include, among others, hardware, software, networks, human resources, data, and information.
Hardware is one (1) or a series of devices connected in an Electronic System.
Software is one (1) or a collection of computer programs, procedures, and/or documentation related to the operation of an Electronic System.
Article 3
Business complexity includes, among others, diversity in the types of transactions, products, services, office networks, and/or supporting technologies used.
Article 4
In establishing authority and responsibility, Banks need to pay attention to, among others, the principle of segregation of duties, for example, the party performing data input is different from the party performing data validation.
Article 5
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Number 1
Sufficiently clear.
Number 2
Enhancement of human resource competence includes, among others, through continuous education and training programs regarding the organization and use of Information Technology.
Number 3
Sufficiently clear.
Number 4
Sufficiently clear.
Number 5
Sufficiently clear.
Number 6
Sufficiently clear.
Article 6
Sufficiently clear.
Article 7
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
The structure of the Information Technology Steering Committee can be adjusted to the size and complexity of Bank activities as well as the Bank's ownership structure or legal entity.
Paragraph (4)
Sufficiently clear.
Article 8
Paragraph (1)
Sufficiently clear.
Paragraph (2)
The depth of policies, standards, and procedures for the use of Information Technology is adjusted to the business policy objectives, the size and complexity of the Bank's business, and pays attention to the Bank's risk profile.
Letter a
The term "management" includes, among others, the Board of Directors, Board of Commissioners, and the Information Technology Steering Committee.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Letter f
Sufficiently clear.
Letter g
Sufficiently clear.
Letter h
Sufficiently clear.
Letter i
Sufficiently clear.
Paragraph (3)
The term "risk limit" refers to the level of error that can still be tolerated by the system (risk tolerance) or security standards established or approved not to be exceeded. The security standards referred to above are adjusted to the risk appetite held by the Bank.
Paragraph (4)
Review and updating are conducted so that policies, standards, and procedures remain in line with Bank operational and Information Technology developments.
Paragraph (5)
Sufficiently clear.
Article 9
Sufficiently clear.
Article 10
Paragraph (1)
The term "risk management process" refers to identifying, measuring, monitoring, and controlling risk.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Paragraph (4)
Sufficiently clear.
Article 11
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Letter f
Information displayed again regarding systems that are no longer used in Bank operations, proprietary systems, or systems that are still used in Bank operations but are experiencing disturbances. The term "in full" means information that is displayed completely and accurately.
Letter g
The term "source code" refers to a series of commands, statements, and/or declarations written in a computer programming language that can be read and understood.
Source code is placed with an independent party based on an agreement between the Bank and the source code creator.
Article 12
Sufficiently clear.
Article 13
Sufficiently clear.
Article 14
The term "having a system that can generate separate reports" refers to a system that can identify input, process, and output of transactions based on Shariah principles.
Article 15
Paragraph (1)
Sufficiently clear.
Paragraph (2)
The Disaster Recovery Plan includes recovery plans at various levels of disasters and disturbances, such as:
a. minor disasters that have a small impact and do not require large costs and can be resolved in a short period; b. major disasters that have a large impact and can become worse if not addressed immediately; and/or
c. catastrophic events that result in permanent damage requiring relocation or replacement at a large cost.
Paragraph (3)
Sufficiently clear.
Paragraph (4)
Sufficiently clear.
Article 16
Sufficiently clear.
Article 17
Paragraph (1)
In implementing the Information Technology internal control system, Banks refer to general principles as regulated in provisions regarding guidelines for internal control system standards.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
The term "adequate" includes, among others, technology suitable for Bank operational activities, competent human resources, and an organizational structure that does not provide opportunities to commit and/or conceal errors or deviations.
Paragraph (4)
Sufficiently clear.
Article 18
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
The use of external auditors to perform internal audit functions for Information Technology does not reduce the responsibility of the internal audit unit leadership. Furthermore, the use of external auditors must consider the size and complexity of the Bank's business and pay attention to relevant statutory provisions regarding external auditors.
In the event that a Bank uses external auditors to perform internal audit functions for Information Technology, the Enterprise Data Management process must still be carried out by the internal audit unit.
Paragraph (4)
Sufficiently clear.
Article 19
Sufficiently clear.
Article 20
Paragraph (1)
The organization of Information Technology includes, among others, the placement of Electronic Systems in Data Centers and Disaster Recovery Centers.
Paragraph (2)
The term "using Information Technology service providers" refers to the use of third-party services in the organization of Bank Information Technology on a continuous basis and/or for a specific period. The term "third party" for:
a. branch offices of banks domiciled abroad, including headquarters and other banks abroad as well as the Bank's business group; or b. banks owned by foreign parties, including parent offices and the Bank's business group. Furthermore, even if the Bank entrusts the organization of Information Technology to a service provider, the Bank is still referred to as the organizer of the Electronic System for every Electronic System used by the Bank in carrying out its business activities.
Paragraph (3)
Letter a
The term Bank's responsibility in implementing risk management includes, among others, ensuring that Information Technology service providers implement adequate risk management in Bank activities organized by the Information Technology service provider as required in this Financial Services Authority Regulation.
Letter b
Sufficiently clear.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Letter f
The term "periodically" refers to the monitoring and evaluation of the reliability of Information Technology service providers in accordance with the Bank's risk appetite regarding the services provided by the Information Technology service provider.
Letter g
Access to obtain data and information is intended so that examinations can be carried out effectively.
Letter h
Access to the Database includes, but is not limited to, the provision of terminals, user IDs for querying, and downloading data.
Letter i
Number 1
Sufficiently clear.
Number 2
This requirement is intended to ensure that the Data Centers, Disaster Recovery Centers, and/or Information Technology services used by the Banks have adequate Information Technology controls at least covering physical security and logical security.
Number 3
Access as referred to in this number is needed to obtain the necessary data and information accurately and timely whenever needed for Information Technology audits, audits and/or other examinations. Financial Services Authority auditors, including external auditors appointed by the Financial Services Authority, are included.
Number 4
Sufficiently clear.
Number 5
Information, including systems and devices used to process, store, and send information, is an asset that must be guaranteed secure by the service provider by being protected from enemies and threats that can interfere with the principles of confidentiality, integrity, and availability.
Number 6
Sufficiently clear.
Number 7
Sufficiently clear.
Number 8
The term "periodically" refers to the implementation of audits in accordance with the Bank's risk appetite regarding the services provided by the Information Technology service provider. The scope of audits conducted by independent auditors includes application systems used to process Bank data.
Number 9
Sufficiently clear.
Number 10
Sufficiently clear.
Number 11
Service level fulfillment is carried out, among others, by ensuring that the organization of Information Technology can support the Bank to operate as it should.
Paragraph (4)
Sufficiently clear.
Paragraph (5)
The term "arm's length principle" refers to a condition where transactions between parties are independent as if they were unrelated parties, including having equality and being based on fair market prices so as to minimize the occurrence of conflicts of interest. The term "related parties with the Bank" refers to related parties as regulated in provisions regarding the maximum limit for granting credit by commercial banks.
Paragraph (6)
Letter a
Sufficiently clear.
Letter b
The term "insolvent" means not having sufficient funds to pay off debts.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Paragraph (7)
Sufficiently clear.
Paragraph (8)
Indications of supervisory difficulties include, among others:
a. difficulties for the supervisory authority in accessing data and information; b. difficulties in conducting examinations of Information Technology service providers; and/or
c. Information Technology service providers being used as a medium to manipulate Bank data and/or Bank financials.
Article 21
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Letter a
The term "home regulatory" refers to regulations issued by the country of origin authority of the bank.
In this case, the home regulatory for branch offices is in accordance with the location of the bank's headquarters abroad, while for subsidiary offices, it is in accordance with the location of the parent office/main entity office, which is a bank abroad. The term "other regulations" in this context refers to regulations for the sake of public interest or the state, law enforcement, or the application of prudential principles.
Letter b
The term "customers who are one group" refers to other customers who have a controlling relationship with the customer, in accordance with provisions regarding the maximum limit for granting credit or the maximum limit for fund disbursement. The term "same banking group" refers to parent offices or main entity offices, subsidiaries, or related companies, which are banks.
Letter c
Sufficiently clear.
Letter d
Sufficiently clear.
Letter e
Sufficiently clear.
Paragraph (4)
Letter a
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
The term "does not reduce the effectiveness of Financial Services Authority supervision" means not causing supervisory difficulties in obtaining necessary data and information, such as having access to the Database and having a Database structure for each application used.
Letter d
Applicable Indonesian legislation includes, among others, Financial Services Authority provisions regarding requirements and procedures for issuing written orders or permits to open Bank secrets.
Letter e
Sufficiently clear.
Letter f
A letter of statement is submitted if the Information Technology service provider has supervisory authority.
Letter g
The term "bank offices outside the territory of Indonesia" refers to:
Letter h
Expected benefits include, among others, improved service quality for customers and the implementation of anti-money laundering and counter-terrorism financing programs.
Letter i
Sufficiently clear.
Article 22
Paragraph (1)
The term "ensuring business continuity" means ensuring that business continuity can continue to run properly when disasters or disturbances occur, including ensuring the readiness of Electronic Systems contained in Data Centers and Disaster Recovery Centers.
Paragraph (2)
Sufficiently clear.
Article 23
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Letter a
The term prudential principle in this paragraph includes, among others, the management of risks for new products and activities as regulated in provisions regarding risk management. The term new products and activities includes, among others, products and activities that add to or increase risk to the Bank, including the development of services such as credit marketing.
Letter b
Sufficiently clear.
Letter c
The relationship between the Bank and customers is based on clear agreements and pays attention to provisions regarding product information transparency and the use of customer personal data, as well as provisions regarding the resolution of customer complaints. The Bank remains responsible for every transaction whose processing is entrusted to a service provider.
Paragraph (4)
The organization of Information Technology-Based Transaction Processing abroad in this paragraph includes that carried out at the headquarters or other offices for foreign bank branches or parent offices for banks owned by foreign financial institutions.
Letter a
Sufficiently clear.
Letter b
The term "supporting financial administrative documents" refers to data that serves as evidence of rights and obligations and business activities of a company and is used to support the preparation of financial reports. Examples: credit agreements and credit disbursement documents, deal slips, and deal confirmations of treasury transactions as well as data transfer order documents via Society for Worldwide Interbank Financial Telecommunication (SWIFT).
Letter c
Efforts to increase the Bank's role in the development of the Indonesian economy are reflected, among others, in plans to increase credit granting and increase export-import financing.
Letter d
Sufficiently clear.
Article 24
Paragraph (1)
Sufficiently clear.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Paragraph (4)
The report includes post-implementation review.
Paragraph (5)
The term "application documents received completely" refers to the receipt of documents required in this Financial Services Authority Regulation as well as the receipt of additional data if necessary.
Paragraph (6)
Sufficiently clear.
Article 25
Paragraph (1)
The provision of Information Technology services by a Bank is the provision of services in the form of utilizing the Bank's Information Technology infrastructure to Financial Service Institutions, based on a cooperation agreement and/or lease agreement between both parties.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Paragraph (4)
Data Centers and/or Disaster Recovery Centers, including communication networks used jointly by Information Technology service providers and users, are included, but the provision of special applications for service users is not included.
Paragraph (5)
Sufficiently clear.
Article 26
Sufficiently clear.
Article 27
Paragraph (1)
Examples of Electronic Banking Services include Automated Teller Machine (ATM), Cash Deposit Machine (CDM), phone banking, Short Message Services (SMS) banking, Electronic Data Capture (EDC), Point Of Sales (POS), internet banking, and mobile banking. Financial Services Authority provisions include, among others, Financial Services Authority Regulations regarding Business Activities and Office Networks of Banks Based on Core Capital, Financial Services Authority provisions regarding the implementation of anti-money laundering and counter-terrorism financing programs for Banks, Financial Services Authority provisions regarding the implementation of risk management, and Financial Services Authority provisions regarding prudential principles in Bank business activities. Other relevant authority provisions include, among others, provisions regarding the organization of card payment instrument activities.
Paragraph (2)
Sufficiently clear.
Paragraph (3)
Sufficiently clear.
Article 28
Paragraph (1)
Sufficiently clear.
Paragraph (2)
The term "Electronic Banking Service products" refers to new products that have characteristics different from existing products in the Bank and/or add to or increase certain risk exposures to the Bank.
Paragraph (3)
Letter a
Number 1
The term "management" includes among others:
the Board of Directors, the Board of Commissioners, and the Information Technology Steering Committee.
Number 2
Sufficiently clear.
Number 3
Sufficiently clear.
Number 4
Sufficiently clear.
Number 5
Sufficiently clear.
Number 6
Sufficiently clear.
Number 7
Sufficiently clear.
Number 8
Sufficiently clear.
Letter b
Sufficiently clear.
Letter c
Examples of other supporting documents include documents required by other relevant authorities, such as:
Article 44
Sufficiently clear.
SUPPLEMENT TO THE STATE GAZETTE OF THE REPUBLIC OF INDONESIA NUMBER 5963 ---
Read the rest free
Amended 3 times · last 2022-07-07
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.