2022-04-20 | Resolución SBS 1298-2022Added · Updated
Resolution SBS No. 1298-2022 approves the Internal Audit Regulation for Savings and Credit Cooperatives Not Authorized to Capture Public Funds (Coopac) and their central organizations. The regulation mandates that Coopac Level 2 entities with total assets exceeding 32,200 UIT and all Level 3 entities must establish an Internal Audit Unit (UAI), while Level 2 entities with assets of 32,200 UIT or less and Level 1 entities must appoint an internal auditor or assign audit functions to the Supervisory Council. It defines the scope, definitions, responsibilities of governing bodies, independence requirements, and specific audit functions, including compliance with anti-money laundering and counter-terrorist financing prevention systems.
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000
Lima, April 20, 2022 Resolution S.B.S. No. 1298-2022
The Superintendent of Banks, Insurance, and Private Pension Fund Administrators
CONSIDERING:
That, in exercise of the powers established in items 7 and 9 of Article 349, as well as in the Twenty-Fourth Final and Complementary Provision of the General Law of the Financial System and the Insurance System and Organic Law of the Superintendence of Banks and Insurance - Law No. 26702 and its amendments (General Law), through Resolution SBS No. 742-2001 and its amendments, the Internal Audit Regulation for Savings and Credit Cooperatives Not Authorized to Operate with Public Funds was approved;
That, Law No. 30822, Law that modifies the General Law and other concordant norms, regarding the regulation and supervision of savings and credit cooperatives, modified the Twenty-Fourth Final and Complementary Provision of the General Law, establishing new provisions regarding the regulation and supervision of Savings and Credit Cooperatives Not Authorized to Capture Public Funds (Coopac);
That, in item 4-A.1 of the Twenty-Fourth Final and Complementary Provision of the General Law, it is established that in matters of regulation, the Superintendence of Banks, Insurance, and AFP (Superintendence) issues the norms that are necessary for the compliance with what is established in the aforementioned final and complementary provision, as well as the other aspects that are necessary for the supervision and regulation of Coopac, which must be consistent with the modular scheme contemplated in item 2 of the aforementioned final and complementary provision and respect the cooperative and proportionality principles applicable to supervision; likewise, in item 4-A.3 of the cited final and complementary provision, the Superintendence is authorized to issue norms on internal audit;
That, Law No. 27693, Law that creates the Financial Intelligence Unit – Peru, provides that it is the function and power of the Superintendence to regulate, in coordination with the supervisory bodies of obligated subjects, the guidelines, requirements, sanctions, and other aspects related to prevention systems, as well as internal audit being one of the agents for the compliance of the anti-money laundering and counter-terrorist financing prevention system;
That, through Resolution SBS No. 480-2019, the General Regulation of Savings and Credit Cooperatives Not Authorized to Capture Public Funds was approved, which modified Article 4 of Resolution SBS No. 742-2001, by specifying the responsibility for the work of internal audit;
That, given the development of Coopac, it is necessary to establish and identify the bodies of the Coopac that intervene in internal audit functions; the organization, principles, and internal norms that govern their practice; the scopes for the appointment of those in charge of internal audit work, as well as their responsibilities and functions; the aspects to take into account within the framework of supervision, including those related to the prevention of money laundering and terrorist financing, risk management, the assurance and improvement of the quality of internal audit, among other topics; maintaining consistency with the modular scheme established in Law No. 30822, and respecting the cooperative and proportionality principles applicable to supervision;
That, consequently, this Superintendence considers it necessary to issue a new Internal Audit Regulation for Savings and Credit Cooperatives Not Authorized to Operate with Public Funds;
That, in order to collect opinions from the general public regarding the proposal for regulatory modification, the pre-publication of the draft resolution on the matter was ordered on the electronic portal of the Superintendence, under the provisions of the Thirty-Second Final and Complementary Provision of the General Law, item 2 of the Tenth Final Complementary Provision of Law No. 30822, and Supreme Decree No. 001-2009-JUS and its amendments;
Having the previous technical and positive viability report of the norm from the Assistant Superintendent of Cooperatives and the approval of the Assistant Superintendencies of Cooperatives and Legal Advice; and
In exercise of the powers conferred by items 7 and 9 of Article 349 of the General Law, as well as in items 4-A and 9 of the Twenty-Fourth Final and Complementary Provision of the General Law;
RESOLVES:
Article First.- Approve the Internal Audit Regulation for Savings and Credit Cooperatives Not Authorized to Capture Public Funds, which forms an integral part of this Resolution:
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000
“INTERNAL AUDIT REGULATION FOR SAVINGS AND CREDIT COOPERATIVES NOT AUTHORIZED TO CAPTURE PUBLIC FUNDS
CHAPTER I GENERAL PROVISIONS
Article 1. Scope The provisions of this Regulation are applicable to savings and credit cooperatives not authorized to capture public funds and to savings and credit cooperative central organizations.
Article 2. Definitions For the application of this Regulation, the following definitions must be considered: a) Scheduled activities: Those that are included in the Annual Audit Work Plan, some of which are mandatory due to regulatory requirements. b) Unscheduled activities: Special examinations not established in the Plan and carried out when deemed necessary for the evaluation of the functioning of the internal control system. c) General Assembly: General Assembly composed of partners or delegates when applicable, according to what is stated in Article 28 of the General Law of Cooperatives. d) Central: Central of savings and credit cooperatives not authorized to capture public funds, which are those composed exclusively of savings and credit cooperatives and correspond to the homogeneous type indicated in item 1.1 of Article 59 of the General Law of Cooperatives. e) Coopac: Savings and Credit Cooperative Not Authorized to Capture Public Funds. f) Days: Calendar days. g) Business continuity management: Component of comprehensive risk management that seeks to ensure the Coopac's capacity to continue operating at previously established levels in the event of an interruption. The Coopac's business continuity management system must be proportional to the size, nature, and complexity of its operations. h) Information security management: The information security management system is the set of policies, processes, procedures, roles, and responsibilities, designed to identify and protect information assets, detect security events, as well as anticipate response and recovery to cybersecurity incidents. The information security management system implies, at least, the objectives of confidentiality, availability, and integrity. Likewise, it must be proportional to the size, nature, and complexity of its operations. i) Comprehensive risk management: A process, carried out by the Board of Directors and staff applied throughout the Coopac and in the definition of its strategy, designed to identify potential events that may affect it, manage them according to its risk appetite, and provide reasonable assurance in the achievement of its objectives. j) Significant events: Those events that may have a significant impact on the financial situation of the Coopac, or on the achievement of its objectives. k) IAI: Internal Audit Report. l) Head or person in charge of the FIU: The manager or managerial-level official, regardless of their title, responsible for the internal audit unit or service. Defined as “principal official” by the General Regulation, when they do not have the rank of manager.
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000
m) AML/CFT: Money laundering and/or terrorist financing. n) General Law of Cooperatives: Unified Text of the General Law of Cooperatives, approved by Supreme Decree No. 074-90-TR and its modifying norms. o) General Law: General Law of the Financial System and the Insurance System and Organic Law of the Superintendence of Banks and Insurance, Law No. 26702 and its modifying norms. p) Internal audit manual: Document containing the standards, policies, methodologies, procedures, and techniques that guide the internal audit activity of the Coopac, which is approved by the Supervisory Council and is available to the Superintendence. q) Plan: Annual Internal Audit Work Plan containing the general guidelines, objectives, and scope, schedule, and activities to be developed during each fiscal year. r) General Regulation: General Regulation of Savings and Credit Cooperatives Not Authorized to Capture Public Funds, approved by Resolution SBS No. 480-2019 and its modifying norms. s) AML/CFT Regulation: Regulation for the Prevention of Money Laundering and Terrorist Financing applicable to Savings and Credit Cooperatives Not Authorized to Operate with Public Funds, approved by Resolution SBS No. 5060-2018. t) Coopac Registration Regulation: Regulation of the National Registry of Savings and Credit Cooperatives Not Authorized to Capture Public Funds and of the Centrals, approved by Resolution SBS No. 4977-2018 and its amendments. u) Internal control system: Integrated set of processes, policies, procedures, and control techniques established and executed at each level of the Coopac's organizational structure to achieve adequate administrative organization, operational efficiency, reliability of information, appropriate identification and management of the risks it faces, and compliance with the legal provisions applicable to it. v) Audit firms: External Audit Firms. w) Superintendence: Superintendence of Banks, Insurance, and Private Pension Fund Administrators. x) IA Unit: Internal Audit Unit. y) UIT: Tax Unit.
Article 3. Responsibility of the General Assembly and the Board of Directors 3.1. The General Assembly, as the supreme authority of the Coopac and primarily responsible for its control, is responsible for adopting the necessary actions so that the Supervisory Council carries out both the oversight functions indicated in Article 31 of the General Law of Cooperatives and the control functions established in item 2 of the Twenty-Fourth Final and Complementary Provision of the General Law, as well as adequate follow-up on the compliance with the provisions of this Regulation. 3.2. The Board of Directors is responsible for providing the resources and other facilities that are necessary for the development of these functions.
Article 4. Adaptation due to change in modular level The Coopac, within a period not exceeding 90 days from being notified of the change in modular level, must adapt to the provisions of this Regulation that are applicable to its new modular level. The Boards of Directors and Supervisory Councils are responsible for executing the necessary actions to guarantee the adaptation provided for in this article.
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000
CHAPTER II ON THE WORK OF INTERNAL AUDIT
Article 5. Internal audit Internal audit is an independent and objective assurance and consulting activity, conceived to add value and improve an organization's operations, by helping them achieve their objectives by providing a systematic and disciplined approach to the evaluation and improvement of the effectiveness of risk management and corporate governance.
Article 6. Responsibility for internal audit work The Supervisory Council is responsible for carrying out the minimum internal audit work indicated in Articles 18 and 19 of this Regulation, through an IA Unit or an Internal Auditor, in the following cases: a) Coopac of level 2 that register total assets for amounts greater than 32,200 UIT and Coopac of level 3 must have an IA Unit, whose main function is the permanent evaluation of the functioning of the internal control system. This unit depends organically and functionally on the Supervisory Council and communicates its reports, as well as any situation that puts the Coopac at risk, periodically to said body. b) Coopac of level 2 that register total assets less than or equal to 32,200 UIT must have a full-time or part-time internal auditor according to what is established in Article 12 of this Regulation. The internal auditor depends organically and functionally on the Supervisory Council and reports periodically to said body. c) Coopac of level 1 must have an internal auditor according to what is established in Article 12 of this Regulation or may assign the internal audit functions to the members of the Supervisory Council, choosing one of them as responsible for the audit work.
Article 7. Independence of the personnel in charge of internal audit work 7.1. Those in charge of carrying out the internal audit work according to what is indicated in the previous article, must have sufficient independence to carry out their functions effectively, efficiently, and timely, having for this purpose all the necessary powers to achieve their objectives. All of them must be effectively separated from operational and administrative functions within the Coopac. 7.2. The person in charge of the internal audit work and the members of the IA Unit must have access to the information required for the fulfillment of their functions and the development of their examinations, without limitation that could affect their conclusions, including those derived from minutes of the Councils and Committees, management, and any other administrative-level body. 7.3. The Supervisory Council must guarantee the existence of an environment free of conditions that threaten the capacity of the person in charge to carry out the internal audit work to carry out their activities in a neutral manner.
Article 8. Functions of the internal audit unit 8.1. The internal audit functions that, as a minimum, the Supervisory Council must perform, through the member responsible for audit work, the internal auditor, and the head or person in charge of the IA Unit, are the following: a) Evaluate the design, scope, and functioning of the internal control system; b) Prepare the Plan to be approved by the Supervisory Council and make it known to the General Assembly in its next session, as well as comply with scheduled activities and prepare the reports derived from them; c) Evaluate compliance with the legal provisions governing Coopac, during their examinations, in the compliance with the provisions contained in the Twenty-Fourth Final and Complementary Provision of the General Law, the regulatory norms issued by the Superintendence, the General Law of Cooperatives, the Statute, among others; d) Continuously evaluate the quality and adequacy of the computer systems and the mechanisms established by the Coopac to guarantee information security; e) Evaluate the effectiveness of the business continuity management implemented by the Coopac; f) Continuously evaluate compliance with the policy and procedure manuals and other internal norms implemented by the Coopac, as well as propose, if applicable, modifications to them; g) Evaluate the timely and adequate implementation of recommendations and measures to overcome observations made by the Superintendence, external auditors, as well as those made by the IA Unit itself, internal auditor, or member of the Supervisory Council in charge of audit work; h) Maintain a physical and digital, updated archive of all manuals and other internal norms of the Coopac, as well as those documents determined by the Superintendence; i) Communicate to the Supervisory Council, the Board of Directors, and the Superintendence, immediately and simultaneously, the occurrence of significant events, once the corresponding investigations are concluded. The reports on the matter, and the decisions adopted regarding it, must be recorded in the corresponding minute books; j) Verify compliance with the anti-money laundering and counter-terrorist financing prevention system. k) Verify compliance with the Moral and Technical Suitability of directors, managers, and principal officials, as applicable. l) Evaluate compliance with those aspects determined by the Superintendence; and, m) Others that are of interest to the Coopac. 8.2. The Supervisory Council must ensure that the Board of Directors includes a summary of the significant events, reports, and decisions indicated in the previous paragraph, in the report to the Assembly referred to in letter t) of Article 12 of the General Regulation. This information must be recorded in minutes with agreement of knowledge. 8.3. All functions corresponding to internal audit work performed by the respective persons in charge, must be contained in the Coopac's internal audit manual, which must be approved by the Supervisory Council and be available to the Superintendence. These functions must also be contained in the Coopac's Organization and Functions Manual.
Article 9. Adequate infrastructure and other resources 9.1. Those in charge of the internal audit work must have adequate infrastructure, as well as human, technical, and logistical resources, adequate to the magnitude and complexity of the Coopac's operations, as well as to the risks it faces. 9.2. Those in charge of the internal audit work and its collaborators, according to Article 6 of this Regulation, must receive as a minimum one annual training in matters related to their functions. 9.3. The resources necessary for the fulfillment of the functions of the person in charge of the internal audit work must be considered in the formulation of the annual budget assigned to the Supervisory Council.
Article 10. Norms and standards for the practice of internal audit 1 The internal audit activity must comply with the provisions established by this Superintendence and, insofar as they do not oppose such provisions, the norms issued by The Institute of Internal Auditors (IIA) will apply. In the case of system auditors, the audit guidelines provided by ISACA will be taken into consideration.
Article 11. Coordination with audit firms and the Superintendence The Supervisory Council must establish the necessary coordinations with the corresponding audit firm and the Superintendence, as applicable, through the person in charge of the internal audit work, with the aim of permanently evaluating the functioning of the internal control system.
CHAPTER III PERSON IN CHARGE OF INTERNAL AUDIT WORK
Article 12. Selection/Appointment 12.1. In Coopac of level 2 that register total assets greater than 32,200 UIT and in Coopac of level 3, where the constitution of the IA Unit is mandatory, it must be in charge of an internal auditor, who serves as head or person in charge of the IA Unit, performs their work full-time and exclusively, their selection and appointment being the exclusive responsibility and attribution of the Supervisory Council. 12.2. In the case of Coopac of level 2 that register total assets less than or equal to 32,200 UIT, and Coopac of level 1, the internal auditor appointed by the Supervisory Council may be part-time when allowed by the magnitude, complexity of operations, and structure of the Coopac, and this condition does not affect the adequate development of the functions assigned in this Regulation, an aspect that is evaluated by the Superintendence. In its absence, the Coopac's internal auditor performs their work full-time. 12.3. In Coopac of level 1, where the internal audit functions have been assigned to the Supervisory Council, a person in charge of the audit work is designated among its members. 12.4. Coopac must make known to the Superintendence the appointment of the member of the Supervisory Council responsible for internal audit work, the internal auditor, and the head or person in charge of the IA Unit, within a period not exceeding fifteen (15) days from the occurrence of
1 Article modified by Resolution SBS No. 1132-2025 published on 26.03.2025.
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000 designation, attaching a copy of the Board of Supervisors' meeting minutes, duly certified by the secretary or their proxy, as well as the corresponding documented curriculum vitae, through the means established by the Superintendency.
Article 13. Suitability Requirements 13.1. The member of the Board of Supervisors responsible for internal audit activities, the internal auditor, and the head or person in charge of the AML Unit (UAI) must meet the appropriate moral and technical suitability requirements for the corresponding function. 13.2. In Level 2 Coopacs registering total assets greater than 32,200 UIT and in Level 3 Coopacs, the head or person in charge of the AML Unit must meet the following minimum requirements: a) Have obtained a professional title or academic degree of Master in subjects related to the functions of the AML Unit. Likewise, have experience in managerial or executive positions in internal audit or related activities, greater than three (3) years in the case of Level 3 Coopacs, or two (2) years in the case of Level 2 Coopacs with total assets greater than 32,200 UIT, in the last eight (8) years, in financial institutions or cooperatives of the same level or higher; or, b) Have experience in managerial or executive positions related to the functions of the AML Unit, greater than five (5) years in the case of Level 3 Coopacs, or three (3) years in the case of Level 2 Coopacs with total assets greater than 32,200 UIT, in the last eight (8) years, in cooperatives of the same level or higher, companies of the financial system, or in companies or institutions linked to the financial system as established in the General Regulation. The aforementioned years of experience can be accredited in positions of responsibility in the Coopac itself, related to the functions of the AML Unit. 13.3. In Level 1 Coopacs and in Level 2 Coopacs with total assets equal to or less than 32,200 UIT, it is the responsibility of the Board of Supervisors to establish the technical suitability requirements that those in charge of internal audit work must meet, in order to guarantee their adequate performance.
Article 14. Impediments and Prohibition 14.1 The member of the Board of Supervisors responsible for internal audit activities, the internal auditor, the head or person in charge of the AML Unit and its members, are subject to the following impediments: a) Not being subject to, nor having a pending observation for any of the impediments indicated in paragraphs 6.1 and 6.2 of article 6 of the Coopac Registration Regulation; b) Not having been sanctioned by the Superintendency, nor by another public or private body, in the last ten (10) years; c) Not holding a position of manager or principal official, simultaneously with that of internal auditor, head or person in charge of the AML Unit, in different areas of the Coopac and in other Coopacs; d) Not being in situations that limit their independence for the exercise of their functions; 14.2. It is a prohibition applicable to the member of the Board of Supervisors responsible for internal audit activities, the internal auditor, the head or person in charge of the AML Unit and its members, to have, directly or indirectly, in the financial and/or cooperative system, overdue debts for more than
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000 one hundred twenty (120) days or in judicial collection.
Article 15. Responsibilities 15.1 Those in charge of performing internal audit work are responsible for fulfilling the functions and responsibilities assigned to them in this Regulation, as well as for informing the Board of Supervisors and the Superintendency immediately, directly, and simultaneously about any situation that significantly affects the development of their functions and independence. 15.2. Likewise, they must inform the Superintendency, the Board of Administration, and the Board of Supervisors immediately, directly, and simultaneously about significant facts detected during their internal audit work. The timing with which the aforementioned Councils receive such reports and the decisions adopted regarding them must be recorded in the corresponding minutes books.
Article 16. Removal 16.1. The removal of the internal auditor, head or person in charge of the AML Unit, or the member of the Board of Supervisors responsible for internal audit activities must be communicated to the Superintendency within a period of fifteen (15) days from when the decision was adopted, attaching the justification of the reasons that justify such measure and a copy of the certified minutes of the Board of Supervisors' meeting, in which the agreement for removal resulting in the change of responsible person is recorded. 16.2. If it considers it convenient, the Superintendency may summon the person in charge of the internal audit functions subject to removal and take the measures it deems necessary.
Article 17. Vacancy 17.1. The situation of vacancy of the internal auditor and the head or person in charge of the AML Unit, as applicable, cannot last more than thirty (30) days, from the date it occurs, except for reasons of force majeure duly justified, which must be reported to the Superintendency within five (05) days prior to the expiration of the deadline. 17.2. During the period that the vacancy lasts, Coopacs may appoint an interim responsible person for internal audit activities, for a period of up to six (6) months, which must not be subject to the impediments and prohibitions established in article 14, and must meet the moral and technical suitability requirements corresponding to the modular level of the Coopac in accordance with article 13 of this Regulation, with the exception of those requirements related to experience, which can be accredited considering, for the case of Level 1 Coopacs and Level 2 Coopacs with total assets equal to or less than 32,200 UIT, at least six (6) months of experience in audit activities; and for Level 2 Coopacs that register total assets greater than 32,200 UIT and Level 3 Coopacs, experience of at least one (1) year in audit activities or in the performance of managerial positions related to audit activity in said entities.
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000 CHAPTER IV ON THE ANNUAL WORK PLAN
Article 18. Minimum content of the plan 18.1. The Plan must include all activities to be developed. The Plan and the Meeting Minutes of approval by the Board of Supervisors must be sent to the Superintendency before December 31 of the previous year. Said Plan must consider, at least, the following aspects: a) Diagnosis of the functioning and adequacy to Integrated Risk Management, as applicable; b) Diagnosis of the functioning of the Internal Control System; c) Annual objectives and scope of the Plan; d) Audit procedures and techniques to be used; e) Schedule of activities, examinations, and reports, in accordance with what is provided in article 19; and, f) Human, technical, and logistical resources available for the fulfillment of the Plan, indicating the list of professionals forming the AML Unit, the position they hold and their professional training, the programming of specialized training minimum per year, by modular level, and, if applicable, the contracting of specialized services and the additional resources required for the fulfillment of the Plan. In the case where the constitution of the AML Unit is not required, the aforementioned information must be related, as applicable, to the internal auditor or to the members of the Board of Supervisors in charge of internal audit work. 18.2. Regardless of the cited deadline, the Superintendency may request additional activities and require complementary information regarding the content of the Plan. Likewise, it may make observations on its content, within thirty (30) days following its presentation.
Article 19. Scheduled activities 19.1. The Plan must consider, as a minimum, the scheduled activities, detailed in the following annexes: a) Annex No. 1 Scheduled Activities: Level 3 Coopacs and Level 2 Coopacs with total assets greater than 32,200 UIT b) Annex No. 2 Scheduled Activities: Level 2 Coopacs with total assets equal to or less than 32,200 UIT and Level 1 Coopacs. 19.2. The Annexes are developed based on the modular level established by the regulation and contain the detail of the activities to be performed, review periodicity, and the report delivery date, when applicable.
Article 20. Modifications to the Plan Any modification to the Plan must be approved by the Board of Supervisors and reported to the Superintendency as part of the plan progress report referred to in the following article.
Article 21. Report on the progress of the Plan 21.1. The Board of Supervisors will present to the Superintendency a quarterly report on the progress of the Plan, within thirty (30) days following the close of each quarter; information that will be presented in accordance with what is indicated in Annex No. 3 "Quarterly Report on the progress of the fulfillment of the Annual Plan", which forms part of this Regulation, indicating the degree of fulfillment of the objectives and activities carried out and other aspects considered relevant, among others. The last quarterly report will account for the activities planned and carried out during the year. 21.2. A list of all reports prepared by those in charge of internal audit work during the respective period will be included in said report, indicating whether they derive from scheduled or unscheduled activities, date, brief summary of the content, detailing the main observations found, their impact, and the recommendations formulated. 21.3. The report must be brought to the attention of the Board of Supervisors in a timely manner for the taking of pertinent actions.
CHAPTER V ON THE REPORTS
Article 22. Minimum content of the reports The reports carried out by those in charge of internal audit work, in accordance with article 19 of this Regulation, must contain, at least, the following information: a) Objective and scope of the evaluation; b) Date, scope, and summary of main risks detected in previous evaluation related to the same process or operation; c) Reason for the preparation of the report, indicating as applicable the reference to the scheduled or unscheduled activity and, if applicable, referring to the existence of significant facts; d) Audit procedures and techniques employed; e) Evaluation of the situation of the reviewed process or operation as of the date of the report, identifying the risks detected and their impact on the Coopac, as well as the evaluation of the efficiency and effectiveness of the procedures and controls used by the Coopac for the administration of said risks; f) Observations and recommendations formulated, regardless of whether they are remediated or not at the closing of the report, indicating the status in which they are, as well as the corrective measures adopted by the Coopac to remediate the identified deficiencies, as applicable. g) Personnel in charge of the examination; h) Start and end date of the examination; and i) Name and signature of the person in charge of the examination and the internal auditor or person responsible for internal audit work, as applicable.
Article 23. Minimum content of the Reports on the Evaluation of the AML/CFT Prevention System and Moral and Technical Suitability The reports that derive from a supervision of the AML/CFT Prevention System and Moral and Technical Suitability, carried out by those in charge of performing internal audit work, must contain, at least, the following information:
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000 a) Reason for the preparation of the examination, indicating as applicable the reference to the scheduled or unscheduled activity and, if applicable, referring to the existence of relevant information or significant facts; b) Objective, scope, and limitations (if applicable); c) Legal regulations; d) Evaluation of the implementation of the AML/CFT prevention system, and its components of compliance and AML/CFT risk management, in accordance with what is provided in the AML/CFT Regulation, must evaluate as a minimum the information detailed in Annex No. 5; e) Evaluation of the Technical, Moral Suitability and non-incurrence of impediments of the directors, managers, and principal officials of the Coopac or of the Central, in accordance with what is provided in the General Regulation, and in the Coopac Registration Regulation, as applicable, must evaluate as a minimum the information detailed in Annex No. 6; f) Observations detected and corrective measures recommended to remediate the identified deficiencies; g) Personnel in charge of the examination; h) Start and end date of the examination; and, i) Signature of the person in charge of the examination and the internal auditor, as applicable.
Article 24. Presentation of reports 24.1. The member of the Board of Supervisors responsible for internal audit activities, the internal auditor, or the head or person in charge of the AML Unit must substantiate their reports prepared in compliance with their functions before the Board of Supervisors, who will evaluate the respective reports no later than in the immediate following session to their presentation. The Board of Supervisors will bring said reports to the attention of the Board of Administration so that it takes immediate actions regarding the implementation of the recommendations formulated by the person responsible for internal audit work. 24.2. The timing with which these bodies take knowledge of the reports and the decisions adopted regarding them must be recorded in the respective Minutes Book. 24.3. Regarding the periodicity and presentation of the Reports referred to in article 19, what is provided in Annexes 1 and 2 must be taken into account. 24.4. Regarding the presentation of the Reports on the evaluation of the AML/CFT Prevention System and Moral and Technical Suitability, the following must be taken into account: a) The AML/CFT Prevention System Evaluation Report, prior to the evaluation of the Board of Supervisors, is brought to the attention of the Board of Administration of the Coopac, within thirty (30) days following the expiration of the respective annual period. The Coopac sends the AML/CFT Prevention System Evaluation Report through the compliance officer, no later than February 15 of the year following the respective annual period, to the supervisory body through the Portal for the Prevention of Money Laundering and Financing of Terrorism (plaft.sbs.gob.pe) or another means established by the Superintendency, as an annex of the second semiannual report for Level 3 modular Coopacs and as an annex of the annual report, for Level 2 and 1 modular Coopacs.
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000 b) The Moral and Technical Suitability Reports, prior to the evaluation of the Board of Supervisors, are brought to the attention of the Board of Administration of the Coopac, within thirty (30) days following the expiration of each semester. Subsequently, the Coopac sends the Suitability Reports no later than fifteen (15) days following their presentation to the Board of Administration and to the supervisory body through the means established by the latter.
Article 25. Follow-up on the implementation of recommendations formulated in the Reports 25.1. The Board of Supervisors presents quarterly to the Board of Administration and to the Superintendency, within thirty (30) days following the close of each quarter, a report on the follow-up of the implementation of the recommendations formulated by the Superintendency, external auditors, as well as those made by the AML Unit itself or the person responsible for internal audit work. The referred follow-up of reports will be presented in accordance with what is required in Annex No. 4 "Evaluation of the Fulfillment of Recommendations formulated by the AML Unit or the person responsible for internal audit work, the Superintendency and External Auditors", which forms part of this Regulation. 25.2. The follow-up report must also indicate the degree of fulfillment of the recommendations formulated, disaggregated by year and by unit or area responsible for implementation, among other aspects considered relevant. 25.3. The Board of Administration, in attention to the fulfillment of its general responsibilities established in the General Regulation, must dispose of the necessary measures to guarantee the timely performance of the work recommended in the Reports of the AML Unit or person responsible for internal audit work, external audits, and inspection visits of the Superintendency, as applicable.
Article 26. Working papers 26.1. Those in charge of performing internal audit work must identify, analyze, evaluate, and document information that is sufficient, reliable, relevant, and useful, in such a way that it allows fulfilling the objectives of each activity. In this sense, working papers must guarantee a backup of sufficient and necessary evidence on each of the objectives of internal audit work. Such evidence must be linked and/or referenced in the working papers, as a guarantee that it was carried out with the aptitude and professional diligence corresponding to the work of the internal auditor. 26.2. Those in charge of internal audit work must ensure that working papers are drafted clearly, concisely, precisely, and explicitly, in such a way that it facilitates reaching accurate conclusions by any other professional of internal audit work. Each working paper must include a description of the nature, timing, and extent of the procedures performed in the audit, its results, and the evidence of the audit obtained.
Article 27. Conservation and availability of working papers supporting internal audit activities 27.1. The Board of Supervisors must ensure adequate ordering, control, and conservation of documents generated by internal audit work, whether in physical and/or electronic files; must include in the Audit Manual the policies and/or procedures on the custody and retention of records of the work performed, and on the possibility of disclosing them to third parties unrelated to internal audit work, internal or external. Such policies and/or procedures must be consistent with the guidelines, organization and functions manual, or other applicable regulation applicable to the Coopac. 27.2. The person responsible for internal audit work is responsible for controlling restricted access only to members of the audit team, avoiding unauthorized access by unauthorized third parties.
Article 28. Archive of reports 28.1. Those in charge of audit work must maintain an archive in physical and electronic media, for a period of no less than ten (10) years, containing the reports prepared, working papers, and communications, informing the results of their examinations to the different units of the Coopac, as well as the supporting documentation thereof. Such information must be available to the Superintendency, external auditors, and, if applicable, to risk rating agencies, when so required. 28.2. In order to maintain dual control of the results of internal audit work, the Board of Supervisors must replicate and maintain electronic archives of the audit reports and working papers, must maintain digitized the supporting information it considers pertinent, which must be kept in secure places in accordance with the Coopac's information security procedures and policies.
TRANSITIONAL COMPLEMENTARY PROVISIONS FIRST.- Adaptation and compliance with technical suitability requirements for internal auditors, heads or persons in charge of the AML Unit, in exercise Internal auditors and heads or persons in charge of the AML Unit of Level 2 Coopacs with total assets greater than 32,200 UIT and Level 3 Coopacs, who are designated and in exercise of functions at the publication of this Regulation, have a period of one (1) calendar year, computed from January 1, 2023, to adapt and comply with the technical suitability requirements established in article 13 of this Regulation, as applicable to the modular level of the Coopac.
SECOND.- Application of the prohibition in auditors and heads of internal audit unit Auditors and heads of internal audit unit who are in exercise of their functions at the publication of this Regulation, have a period of six (6) months, computed from the day following the entry into force of the Regulation, to adapt to the compliance of what is established in paragraph 14.2 of article 14 of this Regulation. After the aforementioned period has elapsed, said provision will be applicable to them.
Second Article.- Annexes 1, 2, 3, 4, 5, and 6 approved in the first article of this Resolution are published on the Institutional Portal (www.sbs.gob.pe), in accordance with what is provided in Supreme Decree No. 001-2009-JUS and its amendments.
Third Article.- This regulation enters into force ninety (90) days after its publication in the Official Newspaper El Peruano, from which date
Los Laureles Nº 214 - Lima 27 - Perú Telf.: (511) 6309000 the Internal Audit Regulation for Savings and Credit Cooperatives Not Authorized to Operate with Public Funds approved by Resolution SBS No. 742-2001 and its amendments is repealed.
Fourth Article.- The preparation, presentation, and implementation of the Annual Work Plan of Internal Audit and its respective reports, corresponding to the 2023 exercise, will be subject to the provisions of the Regulation approved by the first article of this Resolution.
Register, communicate, and publish.
MARIA DEL SOCORRO HEYSEN ZEGARRA Superintendent of Banks, Insurance, and AFP
More like this from SBS
SBS published 5 documents in the last 30 days. We email you each new one the day it's published.