2006-06-29 | Resolução CMN 3380Added
Resolution CMN No. 3380 mandates financial institutions and other entities authorized by the Central Bank of Brazil to implement an operational risk management structure compatible with their nature and complexity. The resolution defines operational risk, outlines required components such as identification, monitoring, reporting, and contingency planning, and requires the designation of a responsible director. Institutions must fully implement this structure by December 31, 2007, following a specific timeline for director appointment, policy definition, and final implementation, while also publishing annual public reports and summaries with semi-annual financial statements.
BCB published 18 documents in the last 30 days — get each new one by email the day it lands.
Provides for the implementation of an operational risk management structure.
The CENTRAL BANK OF BRAZIL, in accordance with Article 9 of Law 4.595 of December 31, 1964, makes public that the MONETARY NATIONAL COUNCIL, in a session held on June 29, 2006, based on Articles 4, item VIII, of the aforementioned law, 2, item VI, 8, and 9 of Law 4.728 of July 14, 1965, and 20 of Law 4.864 of November 29, 1965, in Law 6.099 of September 12, 1974, with the changes introduced by Law 7.132 of October 26, 1983, in Law 10.194 of February 14, 2001, with the changes introduced by Law 11.110 of April 25, 2005, and in Article 6 of Decree-Law 759 of August 12, 1969,
RESOLVES:
Article 1. It is determined that financial institutions and other institutions authorized to operate by the Central Bank of Brazil implement an operational risk management structure.
Sole Paragraph. The structure referred to in the caput must be compatible with the nature and complexity of the institution's products, services, activities, processes, and systems.
Article 2. For the purposes of this resolution, operational risk is defined as the possibility of occurrence of losses resulting from failure, deficiency, or inadequacy of internal processes, people, and systems, or from external events.
§ 1. The definition referred to in the caput includes the legal risk associated with inadequacy or deficiency in contracts entered into by the institution, as well as sanctions due to non-compliance with legal provisions and indemnities for damages to third parties arising from the activities developed by the institution.
§ 2. Among the operational risk events are included:
I - internal frauds;
II - external frauds;
III - labor demands and deficient workplace safety;
IV - inappropriate practices regarding clients, products, and services;
V - damage to physical assets owned or used by the institution;
VI - those that cause the interruption of the institution's activities;
VII - failures in information technology systems;
VIII - failures in execution, compliance with deadlines, and management of activities within the institution.
Article 3. The operational risk management structure must provide for:
I - identification, assessment, monitoring, control, and mitigation of operational risk;
II - documentation and storage of information regarding losses associated with operational risk;
III - preparation, with a minimum annual frequency, of reports that allow for the identification and timely correction of deficiencies in control and operational risk management;
IV - conducting, with a minimum annual frequency, tests to assess the operational risk control systems implemented;
V - preparation and dissemination of the operational risk management policy to the institution's personnel at all levels, establishing roles and responsibilities, as well as those of outsourced service providers;
VI - existence of a contingency plan containing the strategies to be adopted to ensure continuity of activities and to limit serious losses resulting from operational risk;
VII - implementation, maintenance, and dissemination of a structured communication and information process.
§ 1. The operational risk management policy must be approved and reviewed, at least annually, by the board of directors of the institutions referred to in Article 1 and by the board of directors, if there is one.
§ 2. The reports mentioned in item III must be submitted to the board of directors of the institutions referred to in Article 1 and to the board of directors, if there is one, which must expressly manifest themselves regarding the actions to be implemented for the timely correction of the identified deficiencies.
§ 3. Any deficiencies must compose the reports on the quality and adequacy of the internal control system, including electronic data processing systems and risk management systems and non-compliance with legal and regulatory provisions, which have, or may have, relevant impacts on the financial statements or on the operations of the audited entity, prepared by the independent audit, as provided in current regulation.
Article 4. The description of the operational risk management structure must be evidenced in a public access report, with a minimum annual frequency.
§ 1. The board of directors or, in its absence, the board of directors of the institution must state in the report described in the caput its responsibility for the disclosed information.
§ 2. The institutions mentioned in Article 1 must publish, together with the semi-annual financial statements, a summary of the description of their operational risk management structure, indicating the location of the report cited in the caput.
Article 5. The operational risk management structure must be capable of identifying, assessing, monitoring, controlling, and mitigating the risks associated with each institution individually, with the financial conglomerate, according to the Accounting Plan of the Institutions of the National Financial System - Cosif, as well as identifying and monitoring the risks associated with the other companies integrated into the economic-financial consolidation, defined in Resolution 2.723 of May 31, 2000.
Sole Paragraph. The structure, provided for in the caput, must also be capable of identifying and monitoring the operational risk arising from outsourced services relevant to the regular functioning of the institution, providing for the respective contingency plans, as per Article 3, item VI.
Article 6. The operational risk management activity must be executed by a specific unit in the institutions mentioned in Article 1.
Sole Paragraph. The unit referred to in the caput must be segregated from the unit executing the internal audit activity, as provided for in Article 2 of Resolution 2.554 of September 24, 1998, with the wording given by Resolution 3.056 of December 19, 2002.
Article 7. Regarding the risk management structure, the constitution of a single responsible unit is admitted:
I - for the operational risk management of the financial conglomerate and its respective integrated institutions;
II - for the activity of identifying and monitoring the operational risk of the non-financial companies integrated into the economic-financial consolidation.
Article 8. The institutions mentioned in Article 1 must indicate a director responsible for operational risk management.
Sole Paragraph. For the purposes of the responsibility referred to in the caput, it is admitted that the indicated director performs other functions in the institution, except for that related to the administration of third-party resources.
Article 9. The operational risk management structure must be implemented by December 31, 2007, observing the following schedule:
I - by December 31, 2006: indication of the responsible director and definition of the organizational structure that will make its implementation effective;
II - by June 30, 2007: definition of the institutional policy, processes, procedures, and systems necessary for its effective implementation;
III - by December 31, 2007: effective implementation of the operational risk management structure, including the items provided for in Article 3, items III to VII.
Sole Paragraph. The definitions mentioned in items I and II must be approved by the board of directors of the institutions referred to in Article 1 and by the board of directors, if there is one, within the stipulated deadlines.
Article 10. The Central Bank of Brazil may:
I - determine the adoption of additional controls, in cases of inadequacy or insufficiency of the operational risk controls implemented by the institutions mentioned in Article 1;
II - impose more restrictive operational limits on the institution that fails to observe, within the established deadline, the determination referred to in item I.
Article 11. This resolution enters into force on the date of its publication.
Brasília, June 29, 2006.
Henrique de Campos Meirelles
President
Read the rest free
Amended 3 times · last 2017-02-23
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 18 documents in the last 30 days. We email you each new one the day it's published.