2023-01-06 | Resolución SBS 0053-2023Added · Updated
The Superintendency of Banking, Insurance and Private Pension Fund Administrators (SBS) approves the Model Risk Management Regulation, establishing minimum requirements for the development, validation, implementation, use, and monitoring of models by supervised entities. The resolution also amends the Internal Audit Regulation to require the Internal Audit Unit to include reviews of the new Model Risk Management provisions in its Annual Work Plan. Supervised companies are mandated to maintain an updated model inventory, categorize models based on risk materiality and complexity, and adhere to specific governance structures, including the establishment or utilization of a Model Risk Committee.
SBS published 7 documents in the last 30 days — get each new one by email the day it lands.
Lima, January 6, 2023
S.B.S. Resolution
No. 00053- 2023
The Superintendent of Banking, Insurance and Private Pension Fund Administrators
CONSIDERING:
That, through Resolution SBS No. 272-2017 and its modifying norms, the Corporate Governance and Integrated Risk Management Regulation was approved, which establishes criteria related to corporate governance and integrated risk management;
That, the use of models for risk management is regulated by specific norms for each risk that address aspects of the risks assumed by the companies under the supervision of the Superintendency;
That, model risk management aims to mitigate the possibility of facing losses caused by weaknesses in the development, validation, implementation, use, and monitoring of models, which can lead to erroneous decisions in the company's business;
That, the use of models for risk management by supervised companies has increased in recent years;
That, in this sense, it is necessary to have a regulatory framework that establishes guidelines and minimum requirements to address the main elements for model risk management such as development, validation, implementation, use, monitoring, and contracting of model providers;
That, through Resolution SBS No. 11699-2008 and its modifying norms, the Internal Audit Regulation was approved, which establishes minimum criteria for its exercise in accordance with international standards and best practices;
That, it is convenient to establish as part of the activities programmed in the Annual Work Plan of the Internal Audit Unit, the review of the provisions established in the Model Risk Management Regulation;
That, for the purpose of collecting public opinions on the proposal, the pre-publication of the draft norm was arranged on the electronic portal of the Superintendency, under the provisions of the Thirty-second Final and Complementary Provision of the General Law of the Financial System and the Insurance System and Organic Law of the Banking and Securities Superintendency - Law No. 26702 and its modifying norms, hereinafter General Law, as well as Supreme Decree No. 001-2009-JUS and its modifications;
With the approval of the Adjunct Superintendencies of Banking and Microfinance, Insurance, Risks, Economic Studies and Legal Advice;
In exercise of the powers conferred in paragraphs 7, 9, 13 and 19 of article 349°, as well as in article 350° of the General Law.
RESOLVES:
Article First.- Approve the Model Risk Management Regulation, as indicated below:
MODEL RISK MANAGEMENT REGULATION
TITLE I
GENERAL PROVISIONS
Article 1°.- Scope
This Regulation applies to companies that employ models for risk management and are included in letters A, C and D of article 16° of the General Law, to the National Bank, to the Agricultural Bank, to the Development Financial Corporation (COFIDE) and to the MIVIVIENDA S.A. Fund, hereinafter companies.
Article 2°.- Definitions and references
For the application of this Regulation, the following definitions must be considered:
a) Risk appetite.- as defined in letter a) of article 2° of the Corporate Governance and Integrated Risk Management Regulation. b) Significant goods and/or services provided by third parties.- as stated in paragraph 35.3 of article 35° of the Corporate Governance and Integrated Risk Management Regulation. c) Categorization of models.- process that allows ordering models, based on the risk they represent for the company. d) Model complexity.- level of difficulty of the model identified from a set of attributes associated mainly with its specification, the technique used for estimation, limitations of the employed technique, ability to interpret results, the use of alternative data and unstructured data, the possibility of bias in data, among others. e) Model development.- process comprising the definition of the model's purpose, design (theoretical framework, mathematical or statistical specification, among others), assumptions, expert judgment criteria, data selection, estimation and consistency tests of the model. f) Overrides.- adjustments made, based on expert judgment, to the results generated by the model. g) Model implementation.- process comprising the integration of the model into the company's management. h) Model quality indicators.- indicators through which the accuracy, discrimination power, robustness, goodness of fit, stability and reliability of the model are evaluated, among others.
i) Model inventory.- register of all models in use in the company's risk management. j) Materiality.- variable that collects the magnitude of the risk associated with the use of the model. k) Model.- quantitative method or system that applies mathematical theories, statistical, economic and/or financial techniques, and assumptions, to process quantitative or qualitative information in quantitative estimates. A model consists of three components: an input component, which provides assumptions and data for the model (including those of expert judgment); a processing component, which transforms data into estimates; and a results component, which translates estimates into information used for decision-making. l) Calculation engine.- tool that contains the necessary elements for calculating model results. m) Provider.- as defined in letter rr) of article 2° of the Corporate Governance and Integrated Risk Management Regulation. n) Retrospective tests (backtesting).- tests that compare the results estimated by the model with what was actually observed, for a specific period of time, in order to evaluate the performance of the models. o) Regulation.- Model Risk Management Regulation. p) Actuarial Management Regulation.- Actuarial Management Regulation for Insurance Companies, approved by Resolution SBS No. 3863-2016 and its modifying norms. q) AML/CFT Risk Management Regulation.- Anti-Money Laundering and Countering the Financing of Terrorism Risk Management Regulation approved by Resolution SBS No. 2660-2015 and its modifying norms. r) Corporate Governance and Integrated Risk Management Regulation.- Corporate Governance and Integrated Risk Management Regulation, approved by Resolution SBS No. 272-2017 and its modifying norms. s) Credit Risk Management Regulation.- Credit Risk Management Regulation approved by Resolution SBS No. 3780-2011 and its modifying norms. t) Insurance Investments Regulation.- Regulation on the Investments of Insurance Companies approved by Resolution SBS No. 1041-2016 and its modifying norms. u) Regulations for Effective Equity Requirement.- Regulation for the Effective Equity Requirement for Credit Risk approved by Resolution SBS No. 14354-2009 and its modifying norms and Regulation for the Effective Equity Requirement for Market Risk approved by Resolution SBS No. 6328-2009 and its modifying norms. v) Regulation for the Constitution of the Catastrophic Risk Reserve.- Regulation for the Constitution of the Catastrophic Risk Reserve approved by Resolution SBS No. 3661-2021. w) Business Continuity Management Regulation.- Business Continuity Management Regulation approved by Resolution SBS No. 877-2020 and its modifying norms. x) Liquidity Risk Management Regulation.- Liquidity Risk Management Regulation approved by Resolution SBS No. 9075-2012 and its modifying norms. y) Market Risk Management Regulation.- Market Risk Management Regulation approved by Resolution SBS No. 4906-2017 and its modifying norms. z) Operational Risk
Management Regulation.- Operational Risk Management Regulation approved by Resolution SBS No. 2116-2009 and its modifying norms. aa) Model replication.- process consisting of reproducing the model development based on its supporting documentation, considering the three components of the model, indicated in the model definition of the Regulation.
bb) Model monitoring.- process comprising the periodic review of the model's performance. cc) Subcontracting.- as defined in letter jj) of article 2° of the Corporate Governance and Integrated Risk Management Regulation. dd) Superintendency.- Superintendency of Banking, Insurance and Private Pension Fund Administrators. ee) Model use.- process consisting of employing the model results for the company's decision-making. ff) Model validation.- process comprising the independent review of the development, implementation and use of the model.
TITLE II
MODEL RISK MANAGEMENT
CHAPTER I
GENERAL ASPECTS
Article 3°.- Model risks
3.1. Model risk is defined as the possibility of losses or adverse consequences derived from weaknesses in the development, validation, implementation, use and monitoring of models. Model risk may arise from inadequate specifications or methodologies; incorrect estimates; incorrect assumptions; calculation errors; inaccurate, inappropriate or incomplete data; inappropriate, improper or unforeseen use of the model; lack of understanding of the model's limitations; and inadequate monitoring and/or controls, primarily.
3.2. The company's model risk management must be consistent with the size, nature and complexity of its operations, products and services. Companies must comply with the criteria of this Regulation and with what is stated in the Corporate Governance and Integrated Risk Management Regulation, in order to ensure a solid model risk management framework consistent with the materiality, use and complexity of the models.
Article 4°.- Models
4.1. The models to which this Regulation applies are those used in the management of credit, market, liquidity, operational, and anti-money laundering and counter-terrorism financing risks, defined in article 23° of the Corporate Governance and Integrated Risk Management Regulation. In the Methodological Notes of the "Model Inventory" (Annex A), a non-exhaustive list of the models to which this Regulation applies is provided.
4.2. This Regulation does not apply to actuarial models used for the calculation of technical reserves and for the management of technical risk, which are subject to what is provided in the Actuarial Management Regulation; as well as to the provisions of the Regulation for the Constitution of the Catastrophic Risk Reserve.
4.3. The Superintendency may establish that a method or system that does not fit the definition of model indicated in letter k) of article 2° of this Regulation is subject to compliance with some of the considerations of this Regulation.
Article 5°.- Model inventory
5.1. Companies must have a model inventory, which must be permanently updated and include at least the information from the format indicated in Annex A "Model Inventory" of this Regulation, which is located on the Supervised Portal (https://extranet.sbs.gob.pe/).
5.2. Likewise, companies must present annually, via the Capture and External Validation Submodule (SUCAVE), Annex A "Model Inventory" with the available information updated to the close of the first semester of the current year, within a period that does not exceed thirty-one (31) calendar days after the close of the first semester of the year.
Article 6°.- Categorization of models
6.1. Companies must categorize the models that fall within the scope of this Regulation, including those provided by third parties, according to the level of risk implied by their use. The categorization of models must consider at least the materiality, use and complexity of the model. Likewise, the criteria to define the categorization must be approved by the model risk committee or its equivalent.
6.2. For each category, the scope and depth of monitoring and validation of the models must be established; the frequency of monitoring and periodic validation; as well as the need for full replication. The Superintendency may require a different categorization than that determined by the company for its models.
Article 7°.- Control procedures by companies
7.1. Companies must take actions when weaknesses are identified as a result of model validation or monitoring, when it is identified that adequate model risk management is not exercised, and when weaknesses are identified as a result of evaluations carried out by this Superintendency and/or the Internal Audit Unit.
7.2. Companies must establish temporary mitigation measures for the use of the model if actions cannot be implemented immediately.
Article 8°.- Annual report on model risk management
8.1. According to what is stated in article 27° of the Corporate Governance and Integrated Risk Management Regulation, the risk unit must prepare an annual risk report. In said report, regarding model risk management, the company must include, at least, the following:
a) The status of identified weaknesses, the actions taken regarding them in accordance with what is indicated in article 7° of this Regulation, and the status of said actions. b) The status of models that were planned to be developed or modified in the last twelve (12) months. c) The schedule of activities related to the development, validation, implementation and monitoring of models that will be carried out in the next twelve (12) months.
8.2. The Superintendency may request additional aspects and expand the detail of the content related to model risk management.
CHAPTER II
INTERNAL ENVIRONMENT
Article 9°.- Responsibilities of the Board of Directors
9.1. The Board of Directors is responsible for establishing a model risk management that considers at least:
a) Assigning the necessary resources to have adequate infrastructure and personnel with appropriate levels of experience and training. b) Assigning responsibilities for the development, validation, implementation, use and monitoring of models. c) Approving policies for the development, validation, implementation, use and monitoring of models, as well as procedures to ensure data quality.
9.2. Any exception for the use of models categorized in the highest risk levels that present relevant weaknesses in their development must be approved by the Board of Directors, taking explicit knowledge of the risks inherent in the use of said models.
Article 10°.- Model risk committee
10.1. As provided in article 11° of the Corporate Governance and Integrated Risk Management Regulation, the Board of Directors may constitute specialized risk committees it deems necessary, due to the nature, size and complexity of the company's operations and services. Considering the aspects mentioned above, the Superintendency may require companies to create a model risk committee if it deems it necessary.
10.2. If the company has a model risk committee, it must be composed of at least one member of the Board of Directors, the head of the risk unit and the officials responsible for the development, validation and monitoring of models. The person presiding over it must not preside over any other committee with which it presents a conflict of interest and must have the necessary experience and knowledge to adequately perform its functions.
10.3. While the company does not have a model risk committee, its responsibilities must be assumed by the risk committee.
10.4. The model risk committee or its equivalent must meet at least quarterly, and all agreements taken must be recorded in minutes, which will be available to this Superintendency. This frequency could be higher considering the size, nature and complexity of the company's operations and services.
Article 11°.- Responsibilities of the model risk committee
11.1. The model risk committee or its equivalent assumes the following functions:
I. Propose to the Board of Directors, for approval, the policies for the development, validation, implementation, use and monitoring of models; as well as the procedures that ensure data quality.
II. Approve the contracting of providers for the development, validation and implementation of models, if applicable.
III. Approve the criteria and thresholds of model quality indicators.
IV. Approve the periodicity of monitoring and periodic validation of models.
V. Approve the purpose, use and categorization of models; and submit to the Board of Directors for knowledge.
VI. Approve the reports on the validation and monitoring of models, and submit to the Board of Directors for knowledge.
VII. Approve the taking of actions against weaknesses identified in models and monitor their execution.
VIII. Approve the schedule of activities referred to in letter c) of paragraph 8.1 of article 8° of this Regulation and modifications to said schedule, if applicable.
IX. Propose improvements for model risk management.
11.2. Any exception for the use of models categorized in levels other than the highest risks, which present relevant weaknesses in their development, must be approved by the model risk committee or its equivalent, taking explicit knowledge of the risks inherent in the use of said models.
11.3. The functions of paragraphs V, VI, VII and IX of paragraph 11.1 of this article may be assumed by other committees without any director among their members, in the case of models categorized in levels other than the highest risks, in which case, the agreements of these must be brought to the knowledge of the Model Risk Committee or its equivalent, at least quarterly 1.
Article 12°.- Specialized functions in model risk management
12.1. Companies must have officials specialized in model risk management, according to the nature, size and complexity of their operations and services. If the company does not have specialized units, the functions will be assumed by teams from the risk unit. If all functions are assumed by the risk unit, the company must be able to demonstrate the required independence between the officials.
12.2. Officials in charge of model development must not present conflicts of interest and must be independent of business units, investment units or other units that form part of the evaluation and origination process of operations. These officials are responsible for documenting and implementing recommendations derived from model development validation and monitoring processes.
12.3. Officials responsible for model validation must be independent of officials responsible for development, as well as those who use the model results, and those in charge of model implementation.
1 Footnote incorporated by Resolution SBS No. 3421-2023 published on October 19, 2023.
12.4. Officials responsible for the implementation and use of models must provide feedback to other involved parties in model risk management.
12.5. The Superintendency may require companies to create specialized units for model risk management.
Article 13°.- Competent officials and professionals
13.1. Officials and professionals involved in model risk management must have adequate training, knowledge and experience in topics related to the type of use and risks managed by models. The general management must ensure the permanent training of these officials and professionals.
13.2. Officials responsible for the validation and monitoring of models must have at least the same organizational level as the official responsible for the development of models.
Article 14°.- Manuals
14.1. Companies must have manuals related to model risk management, which comprise, at least:
a) Policies for the development, validation, implementation, use and monitoring of models, including measures or actions to be implemented based on the results of model quality indicators. b) Guidelines for the categorization of models. c) Procedures to ensure data quality. d) Policies and procedures for the contracting of providers, according to what is stated in the Regulation for the Management of Operational Risk.
14.2. The manuals must be reviewed periodically, according to the policies and procedures defined by the Board of Directors; and must be available to the Superintendency.
Article 15°.- Supporting documentation
15.1. Supporting documentation comprises, as a minimum, documents related to development, implementation, and validation and monitoring reports of the model as required in articles 16°, 18°, 20° and 22° of this Regulation; as well as committee minutes, databases, data dictionaries, programming codes and reports that evidence the assurance of data quality.
15.2. Companies must update and store the supporting documentation of models. Likewise, companies must maintain a history of modifications made to models, detailing the version number and the update date of the model. The supporting documentation must be available to the Superintendency.
CHAPTER III
DEVELOPMENT, APPROVAL, IMPLEMENTATION AND USE OF MODELS
Article 16°.- Model development
16.1. Companies must, at least:
a) Define the purpose and identify the assumptions and limitations of the model.
b) Ensure data quality and, where applicable, consider that the model is built with data that represents and is comparable to the population to which the model will be applied. c) Ensure that the selected variables present coherent relationships in order to capture relevant risk factors and their interrelationships, reflect the model's purpose and consistency with its use, and present adequate quality indicators at the level of each variable. d) Ensure that models present adequate quality indicators at the model level and are consistent with the company's risk appetite so that the model's performance is as expected. e) Perform sensitivity analysis on the model and/or comparison evaluations of results using alternative models (benchmark), if applicable. Sensitivity analyses may consider variable stress and/or variation of assumptions, among others, in order to identify situations in which the model would generate unreliable information.
16.2. In models built using artificial intelligence techniques, companies must, at a minimum, perform tests or other analyses that allow evaluating the interpretability of the model (understanding the model's decision-making process and results), perform hyperparameter optimization as part of the model's learning process; and perform cross-validations or other techniques of similar impact to avoid model overfitting problems.
Article 17.- Model Approval
17.1. Every new model, modified model, or model whose use has changed requires the approval of the model risk committee or its equivalent, prior to its use. A model is considered modified if its variables, assumptions, and/or parameters have been changed. The aforementioned modifications, as well as changes in the model's use, must be justified.
17.2. To approve the purpose and use of the model, the model risk committee or its equivalent must previously consider, at a minimum, the categorization, the results of the model development validation, the assumptions used for the model's development, as well as the model's limitations and the company's risk appetite.
17.3. The model approval act must indicate, at a minimum, the purpose, specific use, and categorization of the model.
Article 18.- Model Implementation
For adequate model implementation, companies must ensure that:
a) Situations in which the model could provide erroneous results have been identified, as well as circumstances or limitations that could prevent its proper functioning. b) The level of automation and IT support are consistent with the model's scope and use. c) Access to systems corresponds to the profile assigned to the officials responsible for the development, validation, implementation, use, and monitoring of the model. d) The units using the model have timely access and availability to the model's results, and that these are presented clearly and understandably.
Article 19.- Model Use
19.1. Companies must ensure that the use of models is consistent with the purpose and criteria with which they were developed, approved, and implemented.
19.2. Companies must carry out training activities regarding the use of models and ensure that officials using the model understand its results, considering the reasonableness and/or materiality of overrides and exceptions, according to the risk managed.
CHAPTER IV
MODEL VALIDATION
Article 20.- Model Validation
20.1. Model validation includes initial validation and periodic validation.
20.2. Initial validation must be carried out prior to the approval of the model's use. Any model that has been modified, in accordance with Article 17 of this Regulation, requires, prior to its approval and implementation, a new validation. Initial validation includes development and implementation validation.
20.2.1 As part of the model development validation process, companies must:
a) Verify the supporting documents indicated in Article 15 of this Regulation. b) Evaluate whether the model design, variable selection process, and expert judgment criteria are consistent with the theoretical framework, industry practices, the model's purpose, and the company's risk policy. c) Verify that the quality of the data used meets the minimum requirements previously established by the company and, where applicable, evaluate that the model has been built with a representative sample of the population on which the model will be applied. d) Verify that the selected variables present coherent relationships, reflect the model's purpose, and present adequate quality indicators at the variable level. e) Verify that the models record adequate quality indicators. f) Perform sensitivity analysis on the models, stressing variables and/or assumptions, among others, or applying the model to different populations to identify changes in the model's results. g) Compare the model's results with the results of a benchmark model. h) Evaluate the methodology of the backtesting performed on the models. i) Evaluate the selection of hyperparameters or other factors and compare with alternative values, in the case of models built using artificial intelligence techniques. The application of the aforementioned literals depends on the category assigned to the model, the type of model, and the risk managed with said model. In the case of models categorized at the highest risk levels, the validation process must include a complete replication of the model.
20.2.2 The validation of the model's implementation must be carried out prior to the model's use. This must consider tests that demonstrate the proper functioning of the calculation engine and IT support, as well as verification of compliance with Article 18 of this Regulation.
20.3. Companies must perform periodic validations of the models; the depth and frequency of such validations will depend on the model's categorization. Such validations must include validation of use (verifying that the model is being used in accordance with what was approved), review of the risk category assigned to the model, among other aspects that the company deems necessary. Likewise, they must include the evaluation of the reasonableness of overrides and their relevance in the model's results, if applicable.
20.4. Companies must prioritize weaknesses identified in the validation considering their importance in the model's results, establish actions to be taken, as well as deadlines for correcting the weaknesses.
20.5. Validation reports must be submitted to the model risk committee, or its equivalent, for approval.
CHAPTER V
MODEL MONITORING
Article 21.- Model Monitoring
21.1. Companies must establish qualitative and/or quantitative model quality indicators and thresholds for these indicators to determine if the models present acceptable levels in said indicators. Quality indicators and their thresholds must be established in accordance with the theoretical framework, good practices, and risk management policies of the companies, the risk appetite, and the types of model use in risk management.
21.2. Companies must establish procedures and alerts, based on quality indicators, for the timely identification of an increase in model risks in order to take action.
21.3. Companies must periodically prepare model monitoring reports, which must be submitted to the model risk committee, or its equivalent, for approval. The frequency of these reports, which must be at least annual, depends on the categorization of the models.
Article 22.- Monitoring Reports
22.1. Monitoring reports must contain:
a) Monitoring of model quality indicators and their deviations from previously defined thresholds and levels obtained in the development stage. b) Monitoring of variables and risk factors that may impact the model's results. c) Monitoring of the validity of the assumptions used in the model. d) The results of backtesting performed on the models, according to the risks managed through them. e) The update of sensitivity analyses on the models, to monitor whether the model's quality indicators are affected. f) Monitoring of overrides, explaining the reasons for resorting to them, and recording the number of overrides performed relative to the total number of cases evaluated with the model. g) Proposals for necessary actions, including modification or limitation of the model's use, among others. h) Monitoring of the implementation of actions taken in response to weaknesses identified in the models, including recommendations from the Superintendency and the Internal Audit Unit. i) Impact assessments of external factors or crisis situations that may affect the models' performance, indicating proposed actions or strategies to mitigate said impact. j) Evaluation of the level of overfitting in models built using artificial intelligence techniques.
22.2. The application of the aforementioned literals must be consistent with the category assigned to the model, the type of model evaluated, and the risk managed with said model.
CHAPTER VI
SERVICES PROVIDED BY THIRD PARTIES IN MODEL RISK MANAGEMENT
Article 23.- Processes Performed by Providers
23.1. The development and validation processes, as well as the IT implementation process, may be performed by providers, while model monitoring must be performed by the company.
23.2. In cases where a third party provides the company only with model results information and/or periodically sends results for a specific sample, such as score levels, income, among others, the service provided in such cases also corresponds to a provider contract.
Article 24.- Company Responsibility in Contracting Model Providers
24.1. Companies assume full responsibility for the use of models developed, validated, and/or implemented by providers, as well as the associated model risk.
24.2. For this purpose, the provider selection process and the management of operational risks associated with their contracting must be carried out according to the policies and procedures established by the company for this purpose, in compliance with the provisions of the Regulation for Operational Risk Management and the Regulation on Corporate Governance and Comprehensive Risk Management.
24.3. If the model developed by a third party is identified as a prioritized service, in compliance with the Regulation for Business Continuity Management, a strategy must be in place to ensure the continuity of the model's use. Such a strategy should foresee, among other aspects, actions that, if necessary, allow the migration of the model to the company or another provider.
Article 25.- Scope of the Regulation for Models Developed by Providers
25.1. In the case of provider models (including parent company models), which are not specifically developed for the company, companies must have knowledge, at a minimum, of the following aspects of the model's development: i) model design, population, and objective for which the model was developed, ii) information sources used, iii) limitations and potential risks of using the model, iv) associated assumptions, and v) quality indicators of the development; and must evaluate that these aspects are consistent with the company's risk management policies. Companies must evaluate the application of the model to their products or target population and determine if the model is appropriate for the company's use.
25.2. In the case of models developed specifically for the company, the guidelines of this Regulation must be complied with, although some processes and/or requirements of the referred Regulation may be modified depending on limitations related to components considered part of the providers' intellectual property.
25.3. For the validation of models developed by providers that are categorized at the highest risk levels, a complete replication must be performed as part of the model validation, prior to its approval. If such replication cannot be performed due to limitations in accessing model information due to the provider's intellectual property issues, companies must evidence such limitation and use alternative techniques such as benchmarking or others.
25.4. Companies must be able to monitor models applied to their portfolio, even when development and/or validation are performed by providers.
COMPLEMENTARY FINAL PROVISIONS
First.- Relationship with other regulations
Where applicable, the criteria indicated in the Credit Risk, AML/CFT, Liquidity, Market, Operational, and Insurance Investment Risk Management Regulation apply. Likewise, regarding information technology infrastructure, application and data architecture, and data management, the criteria indicated in the format (sections 305 to 321 of the “Compliance Report”) published by the Superintendency on the Supervised Portal, which is used to send the report required in Article 60 of the Regulation for the Effective Capital Requirement for Credit Risk, for Internal Ratings Based (IRB) Methods, apply. Second.- Internal Models for Capital Requirements of Financial System Companies Financial system companies that apply for internal models for capital requirements for credit or market risk must comply with the provisions of this Regulation, in addition to what is established in the corresponding Regulations for Effective Capital Requirement. Third.- Models for the management of money laundering and terrorist financing risks Literal a) of Article 2 and the use of these definitions in Articles 16, 17, and 21 of this Regulation do not apply to models that manage money laundering and terrorist financing risks. Fourth.- Additional Requirements from the Superintendency The Superintendency, if deemed necessary, may require companies to conduct external studies, which may be prepared by specialized consultants, to evaluate partial or total compliance with the aspects contemplated in this Regulation.
Article Second.- Modify the Internal Audit Regulation, approved by SBS Resolution N° 11699-2008 and its amending norms, in accordance with the following text:
Table 2: Insurance System Companies
| Risk Type | Models categorized at the highest risk levels | Models at other risk levels |
|---|---|---|
| Credit, Market, and Liquidity Risks | As of January 1, 2025 | As of November 30, 2025 |
| Operational and AML/CFT Risk |
Article Sixth.- In order to comply with the provisions of articles third, fourth, and fifth of this Resolution, companies must submit an action plan to the Superintendency by March 31, 2023. The plan must be approved by the Board of Directors, and must contain the planned actions and timeline for full adaptation, and the officials responsible for the compliance of said plan.
Register, communicate, and publish.
3 Article substituted by SBS Resolution N° 3421-2023 published on October 19, 2023.
4 Article substituted by SBS Resolution N° 3421-2023 published on October 19, 2023.
5 Table substituted by SBS Resolution N° 3884-2024 published on November 18, 2024.
MARIA DEL SOCORRO HEYSEN ZEGARRA
Superintendent of Banking, Insurance, and AFPs
ANNEX A
MODEL INVENTORY
Month/Year
Company:………………………………………
| Model Name 1/ | Model Categorization 2/ | Provider Contract or Internal Development 3/ | Responsible Development Unit or Provider Name | Associated Risks 4/ | Model Type 5/ | Products 6/ | Types of Use 7/ | Associated Exposure 8/ | Type of Associated Exposure 9/ | Responsible Validation Unit or Provider Name | Date of Last Validation Report | Date of Last Monitoring Report | Specification 10/ | Dependent Variable 11/ | Number of Independent Variables | Main Model Quality Indicator | Main Model Quality Indicator Threshold | Main Model Quality Indicator Level at Development Stage | Main Model Quality Indicator Level at Last Monitoring |
|---|
Los Laureles Nº 214 - Lima 27 - Peru Tel.: (511)6309000 METHODOLOGICAL NOTES OF THE 'MODEL INVENTORY' These methodological notes provide the detail of the fields that companies must include in relation to all models they use in the management of risks covered in Article 4 of the Model Risk Management Regulation. General provisions:
a. This inventory must include the detail of all models in use by the company in the management of risks covered in Article 4 of the Model Risk Management Regulation. b. Include a row considering the model type and use type.
General aspects of the model
Read the rest free
Source: Superintendencia de Banca Seguros y AFP — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from SBS
SBS published 7 documents in the last 30 days. We email you each new one the day it's published.