2022-04-04

Added · Updated

Requirements for Information Technology (IT) Management Directive No. SIB/56/2022

The National Bank of Ethiopia requires all insurance companies and Ethiopian reinsurers to fully automate core business processes and implement a comprehensive management information system. These entities must establish IT governance, conduct quarterly IT risk assessments, and maintain a disaster recovery site, with specific compliance deadlines of two years for automation and one year for other provisions. Non-compliance with automation and disaster recovery requirements incurs a monthly fine of Birr 10,000 per requirement and potential suspension of related core business functions.

National Bank of Ethiopia logo

Ethiopia

National Bank of Ethiopia

Click to view thumbnail

የ ኢ ት ዮ ጵ ያ ብ ሔ ራ ዊ ባ ን ክ N A T I O N A L B A N K O F E T H I O P I A አ ዲስ አ በ ባ / A D D I S A B A B A

LICENSING AND SUPERVISION OF INSURANCE BUSINESS

Requirements for Information Technology (IT) Management Directive No. SIB/56/2022

Whereas, a business process supported by information technology improves the efficiency, effectiveness and competitiveness of an insurance company;

Whereas, some insurance companies are running their operations manually or their operations are inadequately supported with information technology;

Whereas, it has become important to require insurance Companies to automate at least their core business processes and their management information system;

Whereas, risks related to the usage of information technology should be adequately and periodically identified and managed to ensure the safety and soundness of individual insurance company and the insurance sector as a whole;

Now, therefore, in accordance with Article 64(2) of the Insurance Business Proclamation No. 746/2012 as amended by Insurance Business (Amendment) Proclamation No.1163/2019, the National Bank of Ethiopia has hereby issued this Directive.

1. Short Title This Directive may be cited as “Requirements for Information Technology (IT) Management Directive No. SIB/56/2022.”

2. Definitions For the purpose of this Directive, unless the context provides otherwise: 2.1 “automate” means fully supporting and enabling a business process with information technology;

2.2 “core business process” means underwriting, claims management, reinsurance, investment, portfolio management, accounting and finance ; 2.3 “cyber security” means preservation of confidentiality, integrity and availability of information systems and ensuring the resilience of an insurance company to a cyber-attack; 2.4 “disaster recovery site” means a place where an insurance company places its backup facility that enables to recovery and restore its IT system and operation when a primary data center become unavailable; 2.5 “information technology (IT)” means an integrated set of computer hardware, software, networks and processes that collects, stores, processes and transmits data to provide information and helps to carry out operations and facilitate interaction with internal and external customers/stakeholders of an insurance company; 2.6 “information technology incident” means an event that jeopardizes the information system processes, storages or transmissions and disrupts operation process of an insurance company; 2.7 “information technology risks” means potential events that result in failure of IT and disrupting business of an insurance company; 2.8 “INSA” means Information Network Security Agency; 2.9 “insurance company” means a company licensed by the National Bank to undertake insurance business or an insurance company owned by the Government; 2.10 “IT vendor” means a person or an organization that offers IT goods or services to an insurance company for sale; 2.11 “management information system” means an automated system consisting of computer hardware & software, processes, people and procedures that gathers data from multiple systems; analyzes the data and generates information or reports that help board and senior management of an insurance company and the National Bank in their decision making, oversight, and risk management roles; 2.12 “National Bank” means National Bank of Ethiopia; 2.13 “senior management” means chief executive officer, senior executive officer and any official, as may be defined by individual insurance company, responsible for the day-to-day running of an insurance company; and

2.14 “third party service provider” means a person or an entity to whom the insurance company outsourced some of its activities and/or who gets access to confidential information through its provision of services to the insurance company.

3. Scope of the Directive This Directive shall apply to all insurance companies and an Ethiopian reinsurer.

4. General Requirements 4.1. An insurance company shall describe and include the role of IT in its business strategy. 4.2. An insurance company shall develop and implement IT strategy. 4.3. IT strategy referred to in sub-article 4.2 hereinabove shall be aligned with the insurance company’s business strategy and shall cover at a minimum: i) the insurance company’s vision, mission, and strategic objectives; ii) assessment of information technology opportunities, threats and internal strengths and weaknesses to manage information technologies; iii) assessment of stock of existing IT and planned ones to be introduced in the future; iv) IT objectives to be pursued; v) key performance indicators in achieving IT objectives; vi) strategies to ensure security in the usage of IT; vii) identified IT initiatives to achieve indicated objectives; and viii) requirements provided by Information Network Security Agency (INSA) or any other competent authority. 4.4. To ensure proper implementation of the IT strategy indicated under 4.2 and 4.3 of this Article, an insurance company shall develop and implement: i) IT governance, including duties and responsibilities of board, senior management, IT department, risk management and internal audit functions and other relevant organs of the insurance company; ii) IT department structure with its duties and responsibilities; iii) IT policies and procedures; and iv) annual IT plans with allocation of duties and responsibilities among all responsible organs of the insurance company. 4.5. An insurance company shall allocate financial and human resources that would enable it to effectively and efficiently implement its IT strategy and IT risk management program. 4.6. To ensure proper implementation of IT related initiatives and projects, an insurance company shall develop and follow effective project and IT vendor management framework. 4.7. Board and senior management of an insurance company shall at least quarterly review progress in implementation of IT related plans and initiative or projects and shall take corrective measure (if required).

5. Requirements for Automation of Core Business Processes 5.1. An insurance company shall fully automate at a minimum its core business processes so as to improve the efficiency and effectiveness of its operations, customer service delivery and risk management, among others. 5.2. The automated core business of an insurance company shall be interoperable with one another to ensure automated data sharing and communication among the IT systems. 5.3. An insurance company shall fully automate and put in place a robust, secure, efficient and comprehensive management information system commensurate with the scale and complexity of the insurance company’s operations that at a minimum supports: i) generation of periodic operational and financial performance reports of the various businesses of the insurance company; ii) senior management in its decision making and risk management process; iii) board of directors and its sub-committees in their oversight functions; iv) proper exercise of shareholders right including getting the necessary and relevant information; and v) generation of periodic supervisory returns or reports as required by the National Bank. 5.4. The automation of core business processes and management information system, as indicated under sub-article 5.1, 5.2 and 5.3 of this Article, shall ensure timely delivery of services and submission of supervisory returns.

6. Management of IT Risks 6.1. An insurance company shall put in place and implement IT risk management program aligned with the institutions’ risk management program. 6.2. The IT risk management program indicated under sub-article 6.1 of this Article shall at least cover: i. types or categories and definitions of IT risks to which the insurance company is exposed; ii. IT risk management culture and objectives; iii. IT risk identification, assessment, measurement, reporting and monitoring mechanisms; iv. duties and responsibilities of board and/or its committees, senior management and/or its committees, risk management function, and operational units in managing the risk; v. IT risk management policies, procedures, and standards; and vi. duties and responsibilities of internal auditor to assess and assure the adequacy of IT risk management processes and the overall program. 6.3. In the course of automating its various businesses and developing program to manage related risks, an insurance company shall take into account cyber security risk management requirements provided by INSA. 6.4. An insurance company shall conduct quarterly IT risk assessment and present the assessment report to the board of directors for its discussion and direction. 6.5. The IT risk assessment report indicated under sub-article 6.4 hereinabove shall be submitted to the Insurance Supervision Directorate of the National Bank within 30 (thirty) calendar days after end of each quarter. 6.6. An insurance company shall maintain and quarterly update IT risk register which facilitates the monitoring and managing of the risks. 6.7. An insurance company shall set up or build a disaster recovery site that is maintained at safe place with adequate detachment from the main site of the IT systems.

7. IT Risks Management Policies 7.1. An insurance company shall develop and implement IT risk management strategies, plans, policies, procedures and standards so as to achieve its risk management objectives. 7.2. The IT risk management strategies, plans, policies, procedures and standards indicated under sub-article 7.1 hereinabove shall at least cover: i) physical access and network securities; ii) business continuity plan; iii) disaster recovery plan; iv) incident response plan; v) hardware, software and network maintenance; vi) database and backup management and access; vii) IT change and patch management system; viii) IT vendor and third party service provider management; ix) customer data privacy; x) password, data transfer security, user right access, antivirus, and firewall security; and xi) managing risk related to system development, integration and acquisition. 7.3. An insurance company shall periodically revise its IT risk management strategies, plans, policies, procedures and standards based on its periodic IT risk assessment findings.

8. Training and Awareness 8.1. An insurance company shall prepare annual IT security awareness plan to enhance awareness of all concerned stakeholders regarding IT strategy, polices, procedures, and IT risk management of the insurance company. 8.2. The awareness program indicated under sub-article 8.1 hereinabove shall be provided to all relevant employees of the insurance company having stake in the implementation of IT strategy and managing of related risks, including board and senior management of the company. 8.3. Based on training need assessment, an insurance company shall develop and implement annual training plan to train all the staffs of IT department of the financial institution on an ongoing and regular basis.

9. IT Audit 9.1. An insurance company shall establish an IT audit function within its internal audit function. 9.2. The IT audit function shall be allocated with human and financial resources which are commensurate with the size and complexity of the insurance company. 9.3. The IT audit function shall prepare and implement annual audit plan that gives assurance on the effectiveness of IT strategy, policies, procedures, plans, governance, and risk management. 9.4. The scope of the IT audit shall at least include: i. evaluating and determining the effectiveness of IT strategy, plans, governance, initiatives, policies & procedures and practices; ii. determining proper implementation of IT strategy, governance, plans, initiatives and compliances with policies and procedures; iii. evaluating the adequacy of IT risk management process and practices; iv. carrying out at least annual cyber threat test or conducting other IT audit activities as provided by INSA or other competent authority; and v. identifying areas of deficiencies, recommending corrective actions and following up the rectification of audit findings to ensure that the senior management effectively implements the required actions. 9.5. IT audit shall be conducted at least on a quarterly basis, and the findings shall be reported to board audit committee and a copy shall be submitted to Insurance Supervision Directorate of the National Bank. 9.6. An insurance company shall make all necessary arrangements for its IT audit staffs for their attainment of information security audit certification from any concerned local Government organ.

10. Reporting 10.1. An insurance company shall notify the Insurance Supervision Directorate of the National Bank within 2 (two) working days any IT incidents that could have significant impact on the insurance company’s ability to provide services to its customers and/or adversely affect the insurance company’s reputation or financial condition as per the format attached to this Directive (Annex-1). 10.2. An insurance company shall quarterly summit to the Insurance Supervision Directorate of the National Bank concerning its ongoing handling of IT incidents as per the format attached to this Directive (Annex-2).

11. Transitional Provisions 11.1 An insurance company shall implement all the requirements of Article 5 and sub-article 6.7 of this Directive within 2 (two) years starting from the effective date of this Directive. 11.2 All provisions of this Directive except Article 5 and sub-article 6.7 shall be effective after the lapse of 1 (one) year starting from the effective date of this Directive.

12. Penalty 12.1. An insurance company that violates sub-article 11.1 of this Directive, or fails to fully automate any of its core businesses and its management information system as set out under Article 5 and set up its disaster recovery site as per sub-article of 6.7 of this Directive within: i) the given period shall be penalized Birr 10,000 per each requirement on monthly basis up until it fully complies with the requirement; and ii) additional 2 (two) years may result in full or partial suspension of related core business in due consideration of the nature of the function. 12.2. An insurance company that violates other provisions of this Directive shall be penalized as per relevant National Bank directive.

13. Effective Date This Directive shall enter into force as of 4th day of April 2022.

Yinager Dessie (PhD) Governor


Annex-1: Name of the Insurance Company : ________________________________________________ Reporting Period: ________________

No.Data and time of the incidentDescription of the incident, its nature, sources ...Impact of the incident

Prepared by: ____________________ Approved by ____________________ Signature: ______________________ Signature: ______________________


Annex-2 Name of the Insurance company: ________________________________________________ Reporting Period: ________________

No.Data and time of the incidentDescription of the incident, its nature, sources ...Impact of the incidentAction taken so far to resolve itCurrent status of the incident (resolved or not)Action taken to mitigate future similar incidents

Prepared by: ____________________ Approved by ____________________ Signature: ______________________ Signature: ______________________