2009-09-22 | Resolución SBS 13278-2009Added
Cooperatives must implement integrated risk management, with Level 2 and 3 entities requiring a risk committee and unit if assets exceed 32,200 UIT. The Board must approve policies and sign a compliance declaration within 120 days of the fiscal year-end. The Risk Unit must submit an annual risk report to the Superintendency within 90 days of year-end. Cooperatives must also send an adaptation plan to the Federation within 90 days of publication. This regulation replaces prior internal control rules and enters into force upon publication, with compliance required by June 30, 2010.
SBS published 8 documents in the last 30 days — get each new one by email the day it lands.
1
Lima, September 22, 2009
S.B.S. Resolution
No. 13278-2009
The Superintendent of Banking, Insurance and Private Pension Fund Administrators:
CONSIDERING:
That, item 3 of the Twenty-Fourth Final and Complementary Provision of the General Law of the Financial System and of the Insurance System and Organic Law of the Superintendence of Banking and Insurance - Law No. 26702, establishes that the supervision of savings and credit cooperatives not authorized to operate with third parties is the responsibility of the National Federation of Savings and Credit Cooperatives (FENACREP) or other cooperative federations to which they voluntarily affiliate and that are recognized by this Superintendence;
That, item 6 of the Final and Complementary Provision previously cited indicates that this Superintendence supervises and controls the aforementioned cooperative federations, regulates the operations of savings and credit cooperatives not authorized to operate with public funds, and is empowered to order the adoption of necessary measures to correct patrimonial or administrative deficiencies detected;
That, it is necessary for said cooperatives to have an Integrated Risk Management system appropriate to their size and the complexity of their operations and services;
That, said Integrated Risk Management must be designed to have an appropriate internal environment, develop adequate objective determination, implement timely identification, evaluation, treatment and control of risks, as well as prepare relevant reports and conduct adequate monitoring;
That, it is necessary to review the criteria provided for in the Internal Control System Regulation in order to make it compatible with international best practices for the development of an Integrated Risk Management, taking as reference, among other documents, the Integrated Framework for Corporate Risk Management, published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO); and extending it to cooperatives, considering their particularities;
Being in accordance with the opinion of the Adjunct Superintendencies of Banking and Microfinance, Risks, Legal Advice and Economic Studies; and,
In exercise of the powers established in items 7 and 9 of
2
Article 349º, as well as in the Twenty-Fourth Final and Complementary Provision of the aforementioned General Law;
RESOLVES:
First Article.- Approve the Regulation of Integrated Risk Management for Savings and Credit Cooperatives Not Authorized to Operate with Public Funds, as indicated below, which will be applicable to the aforementioned cooperatives, hereinafter referred to as cooperatives, and, where pertinent, to the central savings and credit cooperatives:
A. GENERALITIES
For the application of this regulation, the following definitions shall be considered:
a) Risk Appetite.- The level of risk that the cooperative is willing to assume in its search for profitability and value.
b) General Assembly: General Assembly of partners or associates and, where applicable, General Assembly of Delegates as stated in article 28° of the General Law of Cooperatives.
c) Internal Control.- A process, carried out by directors, management and staff, designed to provide reasonable assurance in achieving objectives related to the effectiveness and efficiency of operations, reliability of financial information and compliance with applicable laws and regulations.
d) Directors.- The partners or associates who are members of the Board of Directors and Supervisory Board.
e) Event.- An occurrence or series of occurrences that can be internal or external to the cooperative, originating from the same cause, that occur during the same period of time.
f) .
1
g) Impact.- The consequence or consequences of an event, expressed either in qualitative or quantitative terms. It is usually expressed in monetary terms, such as financial losses. It is also called severity.
h) General Law: General Law of the Financial System and of the Insurance System and Organic Law of the Superintendence of Banking and Insurance, Law No. 26702 and amendments.
i) General Law of Cooperatives: Unified Text of the General Law of Cooperatives approved by D.S. No. 074-90-TR and its modifying and complementary norms.
j) Risk management manuals.- Documents containing the functions, responsibilities, policies, methodologies and procedures established for the identification, evaluation, treatment, control, reporting and monitoring of the cooperative's risks.
k) Organization and functions manual.- Document that details the organic structure of the cooperative, the objectives and functions of its units, as well as the obligations and responsibilities of its staff.
l) Policies and procedures manuals.- Documents containing functions, responsibilities, the policies, methodologies and procedures established by the cooperative 1 Literal eliminated by SBS Resolution No. 480-2019 published on February 07, 2019.
3 for the performance of the activities of each of the units it has, including those corresponding to risk management.
m) Probability.- The possibility of the occurrence of an event which is usually approximated by a statistical distribution. In the absence of sufficient information, or where it is not possible to obtain it, it can be approximated by qualitative methods.
n) Process.- Set of organized and repeatable activities, tasks and procedures that produce an expected result.
o) Risk.- The condition in which there is the possibility that an event occurs and negatively impacts the objectives of the cooperative.
p) Reasonable Assurance.- Refers to the level of security that a cooperative can have in achieving its objectives, considering that it is always possible that deviations or significant financial impacts that are not prevented or detected occur, given the inherent uncertainty of the future.
q) 2
r) Superintendence.- Superintendence of Banking, Insurance and Private Pension Fund Administrators.
s) Risk Tolerance.- The level of variation that the cooperative is willing to assume in case of deviation from the established objectives.
t) Internal Control System.- Integrated set of processes, policies, procedures and control techniques established and executed at each level of the organizational structure of the Coopac to achieve adequate administrative organization, operational efficiency, information reliability, appropriate identification and management of the risks it faces and compliance with legal provisions applicable to it 3.
B. INTEGRATED RISK MANAGEMENT
Integrated Risk Management is a process, carried out by the Board of Directors, management and staff applied throughout the cooperative and in the definition of its strategy, designed to identify potential events that may affect it, manage them according to its risk appetite and provide reasonable assurance in achieving its objectives.
Integrated Risk Management considers the following categories of objectives:
a) Strategy.- High-level objectives, linked to the cooperative's vision and mission.
b) Operations.- Objectives linked to the effective and efficient use of resources.
c) Information.- Objectives linked to the reliability of the information provided.
d) Compliance.- Objectives linked to compliance with applicable laws and regulations.
Cooperatives must carry out integrated risk management appropriate to their size and the complexity of their operations and services.
Integrated Risk Management can be broken down into components, which are present to varying degrees, depending on whether the entire cooperative, a line of activity, a process or an organizational unit is analyzed. The cooperative may have its own breakdown, which adapts to its organization, but it must consider the main elements described below:
2
Definition of subcontracting repealed by SBS Resolution No. 2490-2024 published on 15.07.2024 3 Item t) incorporated by SBS Resolution No. 1297-2022 published on 22.04.2022.
4 a) Internal Environment.- Which comprises, among others, ethical values, technical and moral suitability of its directors and officials; the organizational structure; and the conditions for the assignment of authority and responsibilities.
b) Objective Setting.- Process by which the cooperative's objectives are determined, which must be aligned with the cooperative's vision and mission, and be compatible with risk tolerance and the degree of accepted risk exposure.
c) Risk Identification.- Process by which internal and external risks that may have a negative impact on the cooperative's objectives are identified. Among other aspects, it considers the possible interdependence between events, as well as the influencing factors that determine them.
d) Risk Evaluation.- Process by which the risk of a cooperative, activity, set of activities, area, portfolio, product or service is evaluated; through qualitative, quantitative techniques or a combination of both.
e) Treatment.- Process by which it is opted to accept the risk, decrease the probability of occurrence, decrease the impact, transfer it totally or partially, avoid it, or a combination of the above measures, according to the defined risk tolerance level.
f) Control Activities.- Process that seeks to ensure that policies, standards, limits and procedures for risk treatment are appropriately taken and/or executed. Control activities are preferably incorporated into business processes and support activities. It includes general controls as well as those applied to information systems, as well as related information technology. They seek the effectiveness and efficiency of the cooperative's operations, the reliability of financial or operational, internal and external information, as well as compliance with applicable legal provisions.
g) Information and Communication.- Process by which appropriate and timely information is generated and transmitted to directors, management, staff, as well as external stakeholders such as clients, suppliers, partners, supervisors and this Superintendence. This information is internal and external, and may include management, financial and operational information. 4
h) Monitoring.- Process consisting of the evaluation of the proper functioning of Integrated Risk Management and the implementation of modifications that are required. Monitoring must be carried out in the normal course of the cooperative's activities, and complemented by independent evaluations or a combination of both. It includes reporting of deficiencies found and their correction.
Risks can arise from various sources, internal or external, and can be grouped into various categories or types. Some risks may be associated with a particular activity, such as the investment process, which is exposed to credit, market, operational risks, among others. Below is a non-exhaustive list of the various types of risks to which a cooperative is exposed:
a) Credit Risk
The possibility of losses due to the impossibility or lack of willingness of debtor partners or counterparties, or third parties obliged to fully comply with their contractual obligations registered inside or outside the balance sheet.
4
Modified by SBS Resolution No. 480-2019 published on February 07, 2019.
5
b) Strategic Risk
The possibility of losses due to high-level decisions associated with the creation of sustainable competitive advantages. It is related to failures or weaknesses in market analysis, trends and environmental uncertainty, the cooperative's key competencies and in the process of value generation and innovation.
c) Liquidity Risk
The possibility of losses due to failure to meet financing requirements and fund application arising from cash flow mismatches, as well as by not being able to quickly close open positions, in sufficient quantity and at a reasonable price.
d) Market Risk
The possibility of losses in positions derived from fluctuations in market prices.
e) Operational Risk
The possibility of losses due to inadequate processes, staff failures, information technology, or external events. This definition includes legal risk, but excludes strategic and reputational risk.
f) Reputational Risk
The possibility of losses due to the decrease in confidence in the integrity of the institution that arises when the cooperative's good name is affected. Reputational risk can arise from other risks inherent in the activities of an organization.
The cooperative shall establish appropriate internal systems that facilitate the timely reporting and investigation of illegal, fraudulent activities, identified by any partner of the cooperative or by any person who interacts with it. Such activities must be reported to the Supervisory Board, for which the cooperative will implement procedures that allow maintaining the confidentiality of the whistleblower. In the event that the facts are significant, the Supervisory Board must inform the Board of Directors, in accordance with what is provided in the General Law of Cooperatives, or to the Superintendence, as the case may be. 5
Integrated Risk Management includes internal control, of which it is an integral part. Integrated Risk Management expands and develops the concepts of internal control in a broader and more solid way, with greater emphasis on risk.
The objective of reliability in financial information of internal control is mainly referred to the reliability of financial statements. In Integrated Risk Management, this objective is expanded to include all reports and reports generated by cooperatives, both internal and external. Among them, those used by directors and Management, those sent to third parties, information delivered to supervisors, as well as to partners and other interest groups. The scope also incorporates non-financial information.
According to what is indicated in item 2, a new category of objectives referred to strategy and the categories of objectives referred to operations, information and compliance must be aligned to the strategy. Integrated Risk Management is also applied in the selection of objectives.
5
Modified by SBS Resolution No. 480-2019 published on February 07, 2019.
6
C. THE BOARD OF DIRECTORS AND MANAGEMENT
The Board of Directors is responsible for establishing an integrated risk management and for fostering an internal environment that facilitates its proper development. Among its specific responsibilities are:
a) Approve the general policies that guide the cooperative's activities in the management of the various risks it faces.
b) Select a management team with technical and moral suitability, which acts prudently and appropriately in the development of its activities and operations, as well as in the fulfillment of its responsibilities.
c) Approve the resources necessary for the proper development of Integrated Risk Management, in order to have the appropriate infrastructure, methodology and personnel.
d) Establish an incentive system that promotes the proper functioning of an integrated risk management and that does not favor the inappropriate taking of risks.
e) Approve the organization and functions manuals, policies and procedures manuals and other manuals of the cooperative.
f) Approve general policies for the responsibilities assigned to the cooperative.
g) Establish the objectives of efficient operation of the cooperative, evaluate and approve its activity plans with due consideration to associated risks.
h) Know the main risks faced by the cooperative establishing, when possible, adequate levels of tolerance and risk appetite.
i) Establish an adequate system of delegation of powers and segregation of functions throughout the organization.
j) Reasonably ensure that the cooperative's accounting equity is sufficient to face the risks to which it is exposed, for which it must know the capital needs and establish management policies that support the cooperative's needs, complying with regulatory requirements appropriately.
k) Obtain reasonable assurance that the cooperative has an effective management of the risks to which it is exposed, and that the main risks are under control within the limits that have been established.
The Board of Directors is responsible for evaluating the proper functioning of the criteria defined in this regulation. Annually, the Board of Directors will sign a compliance declaration that will contain at least the following, the Superintendence being able to define additional minimum criteria by general multiple letter:
a) That the Board of Directors knows the standards provided for in this regulation, as well as its responsibilities.
b) That the cooperative has an appropriate management of its risks for its complexity and size, as well as of the criteria indicated in this regulation, with the exception of possible deficiencies identified and communicated in the declaration.
c) That the Board of Directors has taken knowledge of the Management's information, the reports of the Risk Committee and External Audit, where applicable, and also of other information that the Board of Directors considers relevant, and that the corrective measures ordered are recorded in the corresponding minutes.
This declaration will be signed within a period that will not exceed one hundred twenty (120) calendar days
7 after the annual exercise, and must be available to the Superintendence. 6
General management has the responsibility to implement Integrated Risk Management in accordance with the provisions of the Board of Directors, in addition to the responsibilities given by other regulations.
Management may constitute committees to fulfill its responsibilities.
Managers of organizational units of activities or support, within their scope of action, have the responsibility to manage the risks related to the achievement of their units' objectives.
Among their specific responsibilities are:
a) Ensure consistency between operations and the defined risk tolerance levels applicable to their scope of action.
b) Assume, before the immediate superior manager, the results of the risk management corresponding to their unit; and so until reaching the general manager who has this responsibility before the Board of Directors.
D. COMMITTEES OF THE BOARD OF DIRECTORS
The Board of Directors may constitute the committees it deems necessary in order to comply with the provisions contained in this regulation and the responsibilities indicated in item 7 previously cited.
For Coopacs of Level 3 and Level 2 with total assets greater than 32,200 UIT, the constitution of a risk committee is mandatory. In Level 2 Coopacs with total assets equal to or less than 32,200 UIT, the constitution of a risk committee is optional, its functions being able to be assumed by the Board of Directors. The Superintendence may require the creation of a risk committee for Level 2 Coopacs with total assets equal to or less than 32,200 UIT when it observes in the exercise of supervision actions that the management of risks is complex or the criteria provided for in the current regulation are not met. 7
In Level 1 Coopacs all functions attributed to the risk committee are assumed by the Board of Directors. 8
The Committees constituted by the Board of Directors must have a Regulation that will contain the policies and procedures necessary for the fulfillment of their functions. This regulation will establish, among other aspects, the criteria to avoid conflicts of interest, incompatibility of functions, the periodicity of their meetings, their scheduled activities, the information that must be sent, as well as the way in which it will report to the Board of Directors.
The agreements adopted in the meetings must be recorded in a Minutes Book.
6
Modified by SBS Resolution No. 480-2019 published on February 07, 2019.
7
Paragraph replaced in accordance with what is provided in SBS Resolution No. 480-2019 published on February 07, 2019.
8
Paragraph replaced in accordance with what is provided in SBS Resolution No. 480-2019 published on February 07, 2019.
8
The Board of Directors may create specialized risk committees it deems necessary, based on the size and complexity of the cooperative's operations and services.
E. RISK UNIT
For Level 2 and 3 Coopacs, the establishment of a risk unit is mandatory. In Level 1 Coopacs, all functions attributed to the risk unit are assumed by the General Management. Level 2 Coopacs with total assets equal to or less than 32,200 UIT may opt to attribute the functions of the risk unit to the General Management. 9
The members of the Risk Unit must possess the experience and knowledge that allow them to properly fulfill their functions, for which a training plan must be established that will be presented to the Board of Directors annually.
The Risk Unit is responsible for supporting and assisting the other units of the cooperative to carry out good risk management in their areas of responsibility, and for this it must be independent of the operational units.
The main responsibilities of the risk unit are as follows:
a) Propose the appropriate policies, procedures, and methodologies for Integral Risk Management in the cooperative, including roles and responsibilities; b) Ensure competent Integral Risk Management, promoting the alignment of the cooperative's risk treatment measures with the risk tolerance levels and the development of appropriate controls; c) Guide the integration between risk management, business plans, and the cooperative's management activities; d) Establish a common risk management language based on the definitions of this regulation and other applicable regulations; e) Estimate the equity requirements that allow covering the risks faced by the cooperative, as well as regulatory requirements, if applicable. Additionally, alert about possible insufficiencies of effective equity to cover identified risks; and, f) Inform the general management and the risk committee of the relevant aspects of risk management for timely decision-making.
Furthermore, he/she is responsible for informing the Board of Directors, respective committees, and decision-making areas about the risks, the degree of accepted risk exposure, and the management thereof, in accordance with the policies and procedures established by the cooperative.
The aforementioned criteria apply to the heads of specialized risk units, in case there is no centralized unit.
The Head of the Risk Unit, in case the Risk Unit is centralized, must have managerial level.
Subsequently, through a Multiple Office, the Superintendency may define the minimum structure of the annual risk report, partial reports by risk, periodic status reports, as well as 10
their presentation by electronic means.
F. 12
G. ROLE OF INTERNAL AND EXTERNAL AUDIT 13
Internal Audit
The Surveillance Board, responsible for the Internal Audit work of the cooperative and performing a role independent of management, monitors the adequacy of Integral Risk Management, and must adhere to the specific provisions regulating its activity in the Internal Audit Regulation.
External Auditors
External Audit is independent of the cooperative and its main function is the evaluation of the reliability of financial information, and must adhere to the specific provisions regulating its activity in the External Audit Regulation.
14
Second Article.- The cooperative must disclose in its Annual Report, at least a general description of the main characteristics of Integral Risk Management.
Third Article.- Within a period not exceeding ninety (90) calendar days from the publication of this Regulation, cooperatives must send to the Federation an adaptation plan to the provisions contained in this regulation.
This plan must include a preliminary diagnosis of the existing situation in the cooperative, the actions planned for total adaptation and their schedule, as well as the officials responsible for compliance with said plan.
Fourth Article.- The first declaration referred to in numeral 8 of Article One of this Resolution will be enforceable for the fiscal year corresponding to 2010.
Fifth Article.- This Resolution will enter into force from the day following its publication in the Official Gazette El Peruano, granting an adaptation period for compliance until June 30, 2010, from which date the Regulation on the Internal Control System for Savings and Credit Cooperatives Not Authorized to Operate with Public Funds, approved by SBS Resolution No. 743-2001, will cease to be in effect.
Register, communicate, and publish,
12 Modified by SBS Resolution No. 480-2019 published on 07.02.2019. Subsequently repealed by SBS Resolution No. 2490-2024 published on 15.07.2024.
13 Modified by SBS Resolution No. 480-2019 published on 07.02.2019.
14 Numeral eliminated by SBS Resolution No. 480-2019 published on 07.02.2019.
11
FELIPE TAM FOX
Superintendent of Banks, Insurance and Private Pension Fund Administrators
Read the rest free
Amended 1 time · last 2022-04-20
Source: Superintendencia de Banca Seguros y AFP — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from SBS
SBS published 8 documents in the last 30 days. We email you each new one the day it's published.