Based on Article 35, paragraph 1, subparagraph 1.1 of Law no. 03/L-209 on the Central Bank of the Republic of Kosovo (Official Gazette of the Republic of Kosovo, no. 77/16 August 2010), Article 4, paragraph 3, Article 76, paragraph 6 and Article 77, paragraph 6 of Law no. 05/L-045 on Insurance (Official Gazette of the Republic of Kosovo no. 38/24 December 2015), the Board of the Central Bank of the Republic of Kosovo in the meeting held on April 28, 2016, approved the following:
REGULATION
ON INTERNAL CONTROLS AND INTERNAL AUDIT OF INSURERS
Article 1
Purpose and Scope
- The purpose of this Regulation is to define the fundamental principles for the organization and operation of internal controls and the internal audit function of insurers.
- This Regulation applies to all insurers and branches of foreign insurers, licensed by the CBK to operate in the Republic of Kosovo, hereinafter referred to as insurers.
Article 2
Definitions
- All terms used in this Regulation have the same meaning as the terms defined in Article 3 of Law no. 05/L-045 on Insurance (hereinafter the Insurance Law), or according to the following definitions for the purpose of this Regulation:
a) Internal control system is the process controlled by the Board of Directors, senior managers and other personnel of the insurer, established to provide reasonable assurance regarding the achievement of operational efficiency and effectiveness, reliable financial reporting and compliance with applicable laws, regulations and policies.
b) Internal Audit Function is an independent, objective and advisory activity established to add value and improve the insurer's operations. This function helps the insurer achieve its objectives by bringing a systematic disciplined approach to evaluating and improving the effectiveness of risk management, control and governance processes.
c) For the purposes of this Regulation, the term “insurer” means “insurer and/or reinsurer”;
d) Inherent risk means the risk continuously present during the exercise of the insurer's activity, as a result of the lack of functioning of the internal control system.
Article 3
Requirements for Internal Controls
- Insurers must establish a sound internal control system with the aim of preventing losses, maintaining reliable financial and management reporting, expanding their prudent operation and promoting stability in the financial system of the Republic of Kosovo.
- Insurers must have an effective internal control system that is consistent with the nature, complexity and inherent risk in the activities of on-balance sheet and off-balance sheet items and that adapts to changes in their environment and business conditions.
- The objectives of the internal control system must be to reduce fraud, misuse and erroneous actions, as well as to reduce other risks faced by insurers, which will:
a) Promote the efficiency and effectiveness of activities and measures that protect insurers in the use of assets and other resources and in protecting them from losses;
b) Ensure reliability, completeness and accuracy of financial and management information, so that senior managers, directors, shareholders, external parties and supervisors can rely on them for decision-making; and
c) Ensure compliance with applicable laws and regulations and policies.
- An effective internal control system consists of the following interrelated components:
a) Oversight by the board of directors, senior managers and the control culture;
b) Risk identification and assessment;
c) Control activities and segregation of duties;
d) Information and communication; and
e) Monitoring of activities and correction of deficiencies.
Article 4
Oversight by the Board of Directors, Senior Managers and Control Culture
- The Board of Directors and senior managers are responsible for promoting high standards of ethics and integrity and for establishing a culture within the insurer that emphasizes and demonstrates the importance of internal controls for all levels of personnel. Senior managers ensure that all personnel understand their role in the internal control process and that they will be fully involved in this process.
- The Board of Directors is responsible for the direction, leadership and oversight of the insurer and for ensuring that affairs are conducted in its best interest. The Board of Directors has a duty to act diligently in fulfilling the important duty of leading and overseeing the activities of senior managers, ensuring that the insurer's daily operations are in the hands of qualified, honest and competent persons.
- Specific duties of the Board of Directors in the field of internal control are:
a) Approval and review, at least annually, of the comprehensive business strategy and important policies of the insurer;
b) Establishment of the organizational structure, including its operational units, sub-units, functions and supervisory positions of the insurer;
c) Establishment of the audit committee, in accordance with paragraph 3 of Article 30 of the Insurance Law;
d) Identification of the main risks faced by the insurer, to set acceptable levels for these risks and to ensure that senior management is monitoring the effectiveness of the internal control system;
e) Formal review, at least once a year, of the internal control system and the internal audit function;
f) To ensure the establishment and effective functioning of the internal control system.
- Senior managers are responsible for the organizational and procedural controls of the insurer, ensuring the integrity of internal controls and establishing an effective management team, which is characterized by a professional control culture and is responsible for fulfilling its responsibilities;
- Specific duties of senior managers in the field of internal control are:
a) Implementation of the strategy and policies approved by the Board of Directors;
b) Development of processes that identify, measure, monitor and control risks caused by the insurer;
c) Maintenance of an organizational structure that clearly defines responsibilities, authority and reporting relationships;
d) To ensure that delegated responsibilities are effectively fulfilled, to establish appropriate internal control policies and to monitor the adequacy and effectiveness of the internal control system;
e) To ensure that contracted services of any kind are with contractors who have an appropriate internal control system. Contracts for these services must specify that external auditors, internal auditors and CBK examiners will have access to any documentation, source of information or system that may be required in the performance of their respective functions.
Article 5
Risk Identification and Assessment
- All material risks that may have an unfavorable impact on the achievement of the insurer's objectives must be continuously identified and assessed. This assessment must cover all risks faced by the insurer and the consolidated group of which the insurer is a part (including underwriting risk, by forecasting and assessing the maximum possible risk, reserve risk, liquidity risk, operational risk and reputational risk).
- Internal controls must be reviewed at least once a year to properly address any new and previously uncontrolled risks.
- Effective risk assessment must identify and take into account internal factors (such as: complexity of organizational structure, nature of insurer's activities, quality of personnel, organizational changes and staff movements) as well as external factors (such as: changes in economic conditions, changes in industry and technological advancements), which may jeopardize the achievement of the insurer's objectives.
- Risk assessment must be carried out at all levels of individual activities and across the broad spectrum of activities. This assessment must address measurable and non-measurable aspects of risk and must weigh the costs of controls against the benefits they provide.
- The risk assessment process must also include the assessment of risks to determine which of them are controllable and which are uncontrollable by the insurer. For controllable risks, the insurer must assess whether to accept them or the extent to which it wishes to reduce risks through control procedures. For uncontrollable risks, the insurer must decide whether to accept these risks or withdraw from them, or reduce the level of business activities related to these risks.
Article 6
Control Activities and Segregation of Duties
- Control activities must be an integral part of the insurer's daily activities. Senior management must maintain an appropriate control structure, with control activities defined at every level of the business, including: high-level reviews, appropriate control activities for different departments and units, physical controls, control for compliance with exposed limits and monitoring of non-compliance, a system of approvals and authorizations, a system of verifications as well as coordination.
- Control activity must be designed and implemented to address the risks identified by insurers, through the risk assessment process. Control activities are divided into two phases:
a) Establishment of adequate control policies and procedures; and
b) Verification that these policies and procedures are being implemented;
- Control activities must involve all levels of the insurer's personnel, from senior management to front-line personnel.
- Duties must be properly distributed and personnel will not be assigned responsibilities that may result in a conflict of interest. Areas of potential conflicts of interest must be identified, minimized and subject to careful and independent monitoring.
Article 7
Information and Communication
- Management must collect, record and maintain adequate and comprehensive internal financial, operational and compliance data, as well as external market information related to events and conditions that are relevant for decision-making. Information must be reliable, timely and accessible, and maintained in a consistent format.
- Reliable information systems must be established to cover all significant activities of the insurer. These systems, including those that contain and use data in electronic form, must be secured, independently monitored and supported by adequate emergency plans.
- Management must maintain effective lines of communication to ensure that staff fully understand and support the policies and procedures that affect their duties and responsibilities and that other relevant information is communicated to the appropriate personnel.
Article 8
Monitoring of Activities and Correction of Deficiencies
- The overall effectiveness of the insurer's internal controls must be continuously monitored by the Board of Directors and senior managers. Monitoring of key risks must be part of the daily activities of all operational and business areas of the insurer. The minutes of the Board of Directors' meetings must include actions taken regarding deficiencies identified by internal control.
- The insurer's internal policies and procedures must establish clear lines of responsibility for each operational and business area. Periodic and separate reviews must be conducted by operational and business areas and internal control deficiencies reported at specified intervals to the appropriate level of management and addressed accurately. Material deficiencies in internal control must be reported to senior managers, the audit committee and the Board of Directors.
- The insurer's internal control system must be supplemented by an effective internal audit function, which independently assesses the insurer's control system. A comprehensive and effective internal audit of the internal control system must be carried out by independent, competent and properly trained staff.
Article 9
Internal Audit Function
- The internal audit function is part of the continuous monitoring of the insurer's internal control system, which provides an independent assessment of the adequacy and compliance with the insurer's established policies and procedures. As such, the internal audit function assists senior managers and the Board of Directors in the efficient and effective performance of their responsibilities.
- The scope of the internal audit function must include:
a) Examination and assessment of the adequacy and effectiveness of internal control systems;
b) Review of the application and effectiveness of risk management procedures and risk assessment methodologies;
c) Review of management and financial information systems, including the insurer's electronic information system;
d) Review of the accuracy and reliability of accounting records and financial reports;
e) Review of the insurer's system for capital assessment in relation to risk assessment;
f) Assessment of the economy and efficiency of operations;
g) Testing of transactions and the functioning of specific internal control procedures;
h) Review of systems established to ensure compliance with legal and regulatory requirements, the code of conduct and the implementation of policies and procedures;
i) Testing the reliability and accuracy of regulatory reporting; and
j) Performing specific audit tasks.
- Senior management is responsible for ensuring that the internal audit unit is kept fully informed of new developments, initiatives, products and operational changes.
- Each insurer must have an internal audit function in order to fulfill its duties and responsibilities. The Board of Directors must be responsible for ensuring the independence of the audit function and that sufficient material and human resources are available for the adequate performance of its functions and duties.
- The internal audit function must be independent of the audited activities and from the daily internal control processes. The head of the internal audit unit must have the authority to communicate directly and on his/her own initiative with the external auditor, the Board of Directors or through the audit committee. The Board of Directors decides on the compensation of the head of the internal audit unit.
- The decision on the resignation or dismissal of the head of the internal audit unit, as well as the reasons for resignation or dismissal, must be communicated to the CBK within seven working days.
- Each insurer must have a written audit charter that expresses the position and authority of the internal audit function within the insurer. The internal audit charter must define at least:
a) The objectives and scope of the internal audit function;
b) The position of the internal audit unit within the insurer, its powers, responsibilities and relationships with other control functions; and
c) The responsibility of the head of the internal audit unit.
- The audit charter must be drafted and periodically reviewed by the internal audit unit; it must be approved by the audit committee and then confirmed by the Board of Directors, as part of its supervisory role;
- The audit charter must mandate the internal audit unit with the right to initiate control and authorize it to have access and communicate with any member of the insurer's personnel, to examine any activity or unit of the insurer, and to have access to any record, file or data, including management information and minutes of all consultative and decision-making bodies, whenever relevant for the performance of its duties;
- The charter must define the terms and conditions under which the internal audit unit may be called upon to provide consulting or advisory services or perform other specific tasks.
- In addition to the aforementioned audit charter, the Board must also ensure the charter of the audit committee, which regulates the organization and functioning of this committee.
- The professional competence of each internal auditor and of the internal audit function is essential for the adequate functioning of internal audit.
Members of the internal audit unit must meet the following requirements:
i. professional skills needed to implement and monitor procedural standards and audit techniques in the insurer's operating areas;
ii. knowledge and experience related to International Financial Reporting Standards;
iii. knowledge of principles for risk administration and prudential internal audit techniques of financial institutions.
The head of the internal audit unit will be selected as an individual with a high ethical and professional reputation and with adequate experience in the field of insurance and audit.
- The head of the internal audit unit must prepare an audit plan for assigning and performing duties, which will be approved by the Board of Directors. This approval implies that the insurer will provide the necessary resources for the internal audit unit.
a) The annual audit plan must include in detail the duration and frequency of the internal audit, the necessary resources in terms of personnel and must be based on a written assessment of the material risks of internal controls, updated annually;
b) Reports of the internal audit unit must be presented to the audit committee and the Board of Directors, which contain findings and recommendations as well as responses from senior managers;
c) Reports and working papers must be kept for at least five years;
d) The internal audit unit must follow up on its recommendations to verify whether they have been implemented.
- The head of the internal audit unit must prepare and submit an annual performance report regarding the work done for internal control, as follows:
a) The annual report of the head of the internal audit unit must be presented to the audit committee and the Board of Directors, which will include findings and recommendations as well as responses from senior managers.
b) The minutes of the meetings of the audit committee and the Board of Directors must include a copy as well as the acknowledgment of receipt of such report and the actions taken in relation to the deficiencies identified by the internal audit.
Article 10
Implementation, Remedial Measures and Civil Penalties
Violation of the provisions of this Regulation will be subject to administrative measures and fines as defined in Law no. 03/L-209 on the Central Bank and Law 05/L-045 on Insurance.
Article 11
Entry into Force
This Regulation enters into force on May 2, 2016. Upon the entry into force of this Regulation, CBK Rule 26 on internal control approved on March 28, 2002, and any other provision that may be in conflict with this Regulation, are repealed.
Chairman of the Board of the Central Bank of the Republic of Kosovo
Prof. Dr. Bedri Peci