2009-04-02 | Resolución SBS 2116-2009Added
This resolution approves the Regulation for Operational Risk Management, replacing Resolution SBS N° 006-2002 and its amendments, and extends its scope to Private Pension Fund Administrators (AFPs). It substitutes Article 117 of the Compendium of Regulatory Superintendency Norms of the Private Pension Fund Administration System (SPP), detailing specific operational risk management requirements for AFPs regarding investment processes. The resolution also incorporates two new administrative procedures into the Superintendency's Administrative Procedures Text. Entities have until March 31, 2010, to comply, while Private Pension Fund Administrators have until June 30, 2010.
Source: Superintendencia de Banca Seguros y AFP — original document
Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
Lima, April 2, 2009 Resolution S.B.S. N° 2116 -2009 The Superintendent of Banking, Insurance and Private Pension Fund Administrators CONSIDERING: That, by Resolution SBS N° 37-2008 of January 10, 2008, the Regulation for Comprehensive Risk Management was approved, which establishes that supervised entities must have a comprehensive risk management appropriate to their size and the complexity of their operations and services; That, among the risks faced by supervised entities in the development of their activities is operational risk, which can be generated by deficiencies or failures in internal processes, information technology, people, or by the occurrence of external events; That, by Resolution SBS N° 006-2002 of January 4, 2002, and its amendments, the Regulation for the Administration of Operational Risks was approved; That, consequently, it is necessary to make modifications to the Regulation for the administration of operational risks, in order for said norm to be consistent with the provisions of the Regulation for Comprehensive Risk Management, as well as with recent developments on the matter; That, likewise, it is convenient to extend the scope of the regulation referred to operational risk management to Private Pension Fund Administrators; Based on the opinion of the Deputy Superintendencies of Banking and Microfinance, Insurance, Private Pension Fund Administrators, Risks, and Legal Advisory; and, In use of the powers conferred by numerals 7 and 9 of article 349° of the General Law of the Financial System and the Insurance System and Organic Law of the Superintendency of Banking and Insurance, Law N° 26702 and its amendments, and subsection d) of article 57° of the Consolidated Text of the Law of the Private Pension Fund Administration System, approved by Supreme Decree N° 054-97-EF; RESOLVES: Article First.- Approve the Regulation for Operational Risk Management, which forms an integral part of this Resolution. The annexes that form part of the Regulation approved by this Resolution are published on the institutional Portal (http://www.sbs.gob.pe), in accordance with the provisions of Supreme Decree N° 001-2009-JUS. Article Second.- Substitute article 117° of Title VI of the Compendium of Regulatory Superintendency Norms of the Private Pension Fund Administration System (SPP), with the following text: “Article 117°.- Operational Risk. To manage the operational risks associated with the investment process, AFPs shall be subject to the provisions established in the Regulation for Operational Risk Management. Likewise, as part of the measures for the treatment of this risk, entities must do the following: a. Implement procedures so that investment operations have confirmations, either written or by auditory or electronic means, signed by the intermediaries; b. Implement procedures so that investment operations comply with applicable internal and external norms and that they have been carried out under market conditions, having the authorized powers and signatures; c. Implement contingency plans in case of technical failures in information systems or in case of force majeure events that may affect investment management; d. Establish procedures for the operation of adequate audio recording systems for the negotiation of investment operations, and the maintenance of such recordings for a minimum of two (2) years; e. Establish procedures related to the negotiation, registration, settlement, physical safekeeping, and custody of investment operations and the maintenance and control of files; f. Establish policies and procedures that allow for adequate instrumentalization of agreements and contracts in order to define contractual rights and obligations of both the Managed Portfolios and the AFP in aspects related to the investment process; g. Establish adequate dissemination channels among their officials of the legal and administrative provisions applicable to their investment operations; h. Evaluate and monitor the effects that will be produced on the investment acts carried out by the AFP, in accordance with the applicable national or foreign legal regime; i. Evaluate and monitor the legal implications in case of non-payment of an investment made by an issuer or counterparty and the feasibility of executing guarantees; j. Establish conditions and requirements for the diligent action of officials in the investment process in safeguarding the resources of the Managed Portfolios; and, k. Ensure adequate compliance with policies on ethical conduct and policies aimed at avoiding conflicts of interest or other irregularities in the management of investments of the Managed Portfolios' resources.” Article Third.- Incorporate procedure N° 122 “Special Authorizations for Operational Risk Management” and procedure N° 123 “Authorization of Principal Processing Abroad” into the Single Text of Administrative Procedures – TUPA of the Superintendency of Banking, Insurance and AFPs approved by Resolution SBS N° 131-2002, whose texts are annexed to this Resolution and are published as provided in Supreme Decree N° 004-2008-PCM, regulation of Law N° 29091. (Institutional Portal: www.sbs.gob.pe). Article Fourth.- This Resolution enters into force the day after its publication in the Official Gazette El Peruano, granting a compliance period until March 31, 2010, from which date Resolution SBS N° 006-2002 and its modifying norms, Circular G-130-2007, as well as all those provisions that totally or partially oppose it, will be without effect. Private Pension Fund Administrators will have a period of adaptation to the Regulation approved by this Resolution until June 30, 2010. Register, communicate and publish, FELIPE TAM FOX Superintendent of Banking, Insurance and Private Pension Fund Administrators REGULATION FOR OPERATIONAL RISK MANAGEMENT CHAPTER I GENERAL PROVISIONS Article 1°.- Scope 1 This Regulation shall apply to the entities indicated in article 16° of the General Law, as well as to Private Pension Fund Administrators (AFP), hereinafter referred to as entities. It also applies to Banco de la Nación, Banco Agropecuario, Corporación Financiera de Desarrollo (COFIDE), Fondo MIVIVIENDA S.A., and the Derramas and Benefit Funds under the control of the Superintendency, as long as they do not contravene the specific regulations that govern the actions of these entities. The complementary and related service entities indicated in article 17° of the General Law are subject, for the management of their operational risk, to the provisions established in specific norms, as well as in article 13 of this Regulation. Article 2°.- Definitions For the purposes of this norm, the following terms must be considered: a. Risk appetite: The level of risk that the entity is willing to assume in its pursuit of profitability and value. b. Board of Directors: Any reference to the board of directors shall also be understood as referring to any equivalent body. c. Event: An occurrence or series of occurrences that may be internal or external to the entity, originated by the same cause, occurring during the same period of time. d. Operational risk loss event: The event that leads to one or more losses, whose origin corresponds to operational risk. e. Information: Any form of electronic, optical, magnetic, or other media record, capable of being processed, distributed, and stored. f. Process: Set of organized and repeatable activities, tasks, and procedures that produce an expected result. g. Comprehensive Risk Management Regulation: Comprehensive Risk Management Regulation approved by Resolution SBS N° 37-2008 of January 10, 2008. h. Legal risk: Possibility of financial losses due to failure in the execution of contracts or agreements, unintentional non-compliance with norms, as well as external factors, such as regulatory changes, judicial processes, among others. i. Outsourcing: Modality by which an entity contracts a provider to deliver goods and/or services that could be developed by it. 2 j. Superintendency: Superintendency of Banking, Insurance and Private Pension Fund Administrators. k. Risk tolerance: The level of variation that the entity is willing to assume in case of deviation from the established business objectives. Article 3°.- Operational risk Operational risk is understood as the possibility of losses due to inadequate processes, personnel failures, information technology failures, or external events. This definition includes legal risk, but excludes strategic and reputational risk. Entities must adequately manage the operational risk they face, for which they will observe the minimum criteria indicated in this Regulation. Article 4° Factors that originate operational risk i) Internal processes Entities must appropriately manage the risks associated with the internal processes implemented for the performance of their operations and services, related to the inappropriate design of processes or inadequate or non-existent policies and procedures that may result in the deficient development of operations and services or their suspension. ii) Personnel Entities must appropriately manage the risks associated with the entity's personnel, related to inadequate training, negligence, human error, sabotage, fraud, theft, stoppages, appropriation of sensitive information, among others. iii) Information technology Entities must manage the risks associated with information technology, related to failures in the security and operational continuity of computer systems, errors in the development and implementation of such systems, and their compatibility and integration, information quality problems, inadequate investment in technology, among other aspects. iv) External events Entities must manage the risks associated with external events beyond the entity's control, related, for example, to failures in public services, the occurrence of natural disasters, attacks, and criminal acts, among other factors. Article 5°.- Operational risk loss events Operational risk loss events can be grouped as described below: a. Internal fraud.- Losses derived from some type of action aimed at defrauding, unduly appropriating assets, or non-compliance with regulations, laws, or business policies in which at least one member of the entity is involved, and which aims to obtain an illicit benefit. b. External fraud.- Losses derived from some type of action aimed at defrauding, unduly appropriating assets, or non-compliance with legislation, by a third party, in order to obtain an illicit benefit. c. Employment practices and workplace safety.- Losses derived from actions incompatible with labor legislation or agreements, regarding hygiene or safety at work, regarding the payment of personal injury claims, or regarding cases related to diversity or discrimination. d. Clients, products, and business practices.- Losses derived from involuntary or negligent non-compliance with a business obligation to specific clients (including fiduciary and suitability requirements), or from the nature or design of a product. e. Damage to physical assets.- Losses derived from damage or harm to physical assets as a consequence of natural disasters or other events. f. Business disruption and system failures.- Losses derived from business disruptions and system failures. g. Execution, delivery, and process management.- Losses derived from errors in the processing of operations or in process management, as well as from relationships with commercial counterparties and suppliers. Annex N° 1 includes a categorization of loss event types applicable according to the sector to which the entity belongs. CHAPTER II ROLES AND RESPONSIBILITIES Article 6°.- Responsibilities of the Board of Directors The Board of Directors has the following specific responsibilities regarding operational risk management: a) Define the general policy for operational risk management. b) Allocate the necessary resources for adequate operational risk management, in order to have appropriate infrastructure, methodology, and personnel. c) Establish an incentive system that promotes adequate operational risk management and does not favor inappropriate risk-taking. d) Approve the operational risk management manual. e) Be aware of the main operational risks faced by the entity, establishing, when possible, adequate levels of tolerance and risk appetite. f) Establish an adequate system of delegation of powers and segregation of duties throughout the organization. g) Obtain reasonable assurance that the entity has effective operational risk management, and that the main identified risks are under control within the limits they have established. Article 7°.- Responsibilities of Management General management is responsible for implementing operational risk management in accordance with the provisions of the Board of Directors, for which it may arrange for the constitution of the committees it deems pertinent. 3 Managers of business or support organizational units are responsible for managing operational risk within their scope of action, within the established policies, limits, and procedures. Article 8°.- Risk Committee The functions of the Risk Committee indicated in the Comprehensive Risk Management Regulation are applicable to operational risk management as appropriate. Article 9°.- Risk Unit In accordance with the Comprehensive Risk Management Regulation, entities may have a centralized Risk Unit or units specialized in the management of specific risks. In this regard, the entity's Risk Unit or, if applicable, the specialized operational risk management unit must fulfill the following functions: a. Propose policies for operational risk management. b. Participate in the design and permanent updating of the Operational Risk Management Manual. c. Develop the methodology for operational risk management. d. Support and assist other units of the entity in the application of the operational risk management methodology. e. Evaluate operational risks associated with significant changes in the business, operational, or IT environment, and associated with the launch of new products, covering the different stages of their development, from the conception of the idea to the completion of its implementation. 4 f. Consolidation and development of reports and information on operational risk management by process, or business and support units. g. Identification of training and dissemination needs for adequate operational risk management. h. Others necessary for the development of the function. Entities must allocate sufficient resources for operational risk management, allowing them to adequately fulfill the functions indicated in this article and ensure adequate independence between the area that assumes the operational risk management functions indicated in this article and other business or support units. Banks, financial institutions, insurance companies, and AFPs must have a specialized operational risk function. According to the size and complexity of the operations carried out by the entity, the Superintendency may require the creation of a specialized unit. CHAPTER III OPERATIONAL RISK MANAGEMENT Article 10°.- Operational risk management manual Entities must have an operational risk management manual, which must include at least the following aspects: a. Policies for operational risk management. b. Functions and responsibilities associated with operational risk management of the Board of Directors, General Management, the Risk Committee, the Risk Unit (or the specialized unit, if applicable), and the business and support units. c. Description of the methodology applied for operational risk management. d. The manner and periodicity with which the Board of Directors and General Management, among others, must be informed about the entity's exposure to operational risk and that of each business unit. e. The process for approving proposals for new operations, products, and services, which must include, among other aspects, a general description of the new operation, product, or service in question, the identified risks, and the actions to be taken for their control. Article 11°.- Methodology for operational risk management The methodology defined by the entity for operational risk management, when taken as a whole, must consider the components indicated in article 4° of the Comprehensive Risk Management Regulation. Likewise, the following criteria must be met: a. The methodology must be implemented consistently throughout the entity. b. The entity must allocate sufficient resources to apply its methodology in the main business lines, and in the control and support processes. c. The application of the methodology must be integrated into the entity's risk management processes. d. Incentives must be established to allow for continuous improvement of operational risk management. e. The application of the operational risk management methodology must be adequately documented. f. Procedures must be established to ensure compliance with its operational risk management methodology. Article 12°.- Loss event database Entities must have a database of operational risk loss events. It should be noted that an event can result in one or more losses, so entities must be able to group losses by event. The database must meet the following criteria: a. Loss events originating throughout the entity must be recorded, for which policies, capture procedures, and training for personnel involved in the process will be designed. b. At a minimum, the following information related to the event and associated losses must be recorded: 1 Article modified by Resolution SBS N° 877-2020 of 02/26/2020 effective from 01/01/2022 2 Substituted by Resolution SBS N° 504-2021 of 02/22/2021 effective from 07/01/2021. 3 Paragraph modified by Resolution SBS N° 877-2020 of 02/26/2020 effective from 01/01/2022 4 Subsection modified by Resolution SBS N°2429-2021, effective from 08/21/2021
9 • Event identification code. • Loss event type (according to event types indicated in Annex 1 of this Regulation). • Associated business line, according to lines indicated in Annex 2 of this Regulation for companies in the financial system, Annex 3 for insurance companies, and Annex 4 for AFPs. Levels 1 and 2 of the tables indicated in the annexes must be considered. These tables may be updated by the Superintendency through Circular. • Short description of the event. • Long description of the event. • Date of occurrence or start of the event. • Date of discovery of the event. • Date of accounting registration of the event. • Gross amount(s) of the loss(es), currency, and exchange rate. • Amount(s) recovered through existing coverages prior to the event, currency, exchange rate, and type of coverage applied. • Total recovered amount, currency, and exchange rate. • Associated accounting account(s). • Identification if the event is associated with credit risk (for companies in the financial system) or insurance risk (for companies in the insurance system). In the case of events with multiple losses, companies may register the minimum information required for each loss, and establish a way to group this information by the event that originated it. On the other hand, partial information of an event may be registered, as long as the other required data are obtained. For example, the loss amount may be registered first, to subsequently add the associated recoveries. c. Objective criteria must be defined and documented to assign loss events to the event types indicated in Annex 1 of this Regulation, as well as to the business lines indicated in Annexes 2, 3, and 4. Likewise, specific criteria must be defined for those cases where an event is associated with more than one business line. d. A minimum loss amount must be defined from which an event will be registered in the database. Regarding this, a minimum amount of 3,000 new soles is fixed for banks, financial institutions, insurance companies, and AFPs, and of 1,000 new soles for the rest of companies. Companies may establish a lower minimum amount, taking into account their volume of operations and associated complexity. The Superintendency may update the defined minimum amount through Circular. e. A minimum loss amount must be defined from which a physical or electronic file containing information additional to that requested in letter b. must be available, which allows knowing the manner in which the event occurred, special characteristics, and other relevant information, as well as the actions the company would have taken, including among others the improvements or changes required in its policies or procedures. This minimum amount must be approved by the Risk Committee. The Superintendency may subsequently establish a general minimum amount.
10 Article 13°.- Business Continuity and Information Security Management As part of adequate operational risk management, the company must implement a business continuity management system in accordance with the provisions of the Regulation for Business Continuity Management. Likewise, the company must have an information security management system, oriented to guarantee the integrity, confidentiality, and availability of its information. Article 14°.- Goods and/or services provided by third parties The company must have appropriate policies and procedures to manage risks associated with services provided by third parties, and have a register of these. The company must implement a procedure for the identification of those significant providers, specifying the cases in which they are under the subcontracting modality. In the cases of significant services, whether or not under the subcontracting modality, and of subcontracted services, the company must consider the following aspects: a) Implement a provider selection process for the service. b) Have a contract, which must include service level agreements; clearly establish the responsibilities of the provider and the company; establish the prevailing jurisdiction in case of conflict between the parties; and incorporate the required information security levels. c) Manage and monitor risks associated with these services. d) Maintain a register that must contain at minimum: i) Provider name ii) Main business activity of the provider iii) Description or list of services provided iv) Countries, regions, and/or geographic zones from where the service to be contracted is provided v) Agreed service levels for its provision vi) Whether subcontracting is or is not considered significant by the company vii) Service start date viii) Last renewal date, if applicable ix) Service expiration date or next contract renewal date, as applicable
CHAPTER IV INFORMATION REQUIREMENTS Article 15°.- Report to the Superintendency The company must present annual reports to the Superintendency regarding operational risk management, through the IG-ROp application, which is available on the Supervised Entity Portal. Such reports must be sent no later than March 31 of the year following the reporting year. 7
5 Article modified by Resolution SBS No. 877-2020 of 02/26/2020 effective from 01/01/2022 6 Substituted by Resolution SBS No. 504-2021 of 02/22/2021 effective from 07/01/2021. 7 Paragraph modified by Resolution SBS No. 877-2020 of 02/26/2020 effective from 01/01/2022
11 The minimum content of said report, as well as the operational aspects of IG-ROp, related to instructions, responsible parties, and other necessary aspects for its adequate functioning, are established in the “IG-ROp Manual”, which will be published on the SBS “Supervised Entity Portal”. Likewise, additional instructions for the adequate use of the system will be published on the Portal. Supervised companies must designate an official responsible for the information to be reported through IG-ROp, and take the necessary measures to ensure the veracity of said information. The responsible official must correspond to any of the following classifications: Director, Manager, or Principal Official, according to the provisions of Circular G-119-2004 8, referred to the norms for the registration of Directors, Managers, and Principal Officials – REDIR. Article 16°.- Additional Information The Superintendency may require the company any other information it considers necessary for adequate supervision of the company's operational risk management. Likewise, the company must have available to the Superintendency all documents mentioned by this Regulation, as well as audit reports or reviews performed by the parent company if applicable.
CHAPTER V EXTERNAL COLLABORATORS Article 17º.- Internal Audit The Internal Audit Unit must evaluate compliance with the procedures used for operational risk management, as well as what is established in this Regulation, in accordance with what is established in the Internal Audit Regulation. Article 18º.- External Audit External audit firms must include in their report on the internal control system comments directed to indicate whether the entity has policies and procedures for operational risk management, considering compliance with what is established in this Regulation. Article 19º.- Risk Rating Companies Risk rating companies must take into account the policies and procedures established by the company for operational risk management in the process of classifying supervised companies.
FINAL AND TRANSITORY PROVISIONS First.- Special Authorizations Companies may request the Superintendency for specific exemption from any of the regulatory requirements indicated in this Regulation, attaching the corresponding supporting documentation, for which the requirements indicated in the First Final and Transitory Provision of the Regulation of Integrated Risk Management will apply, insofar as it is applicable to operational risk management.
12 Second.- Simplified Regime for SMEs SMEs are not obligated to implement the loss event database required in Article 12° of this Regulation. Nevertheless, the Superintendency may require the application of said article to those SMEs it considers appropriate, taking into consideration their size, complexity, and volume of operations. Third.- Sanctions In case of non-compliance with the provisions contained in this Regulation, the Superintendency will apply the corresponding sanctions in accordance with what is established in the Sanctions Regulation. Fourth.- Transparency As part of the information that must be revealed in the Annual Report of companies, in accordance with what is indicated in the Regulation of Integrated Risk Management, the main characteristics of the operational risk management implemented by the company must be included. Fifth.- Adequacy of Private Pension Fund Administrators Within a period not exceeding ninety (90) calendar days from the publication of this Regulation, AFPs must send to the Superintendency an adequacy plan to the provisions contained in this norm. Said plan must include a diagnosis of the existing situation in the AFP regarding compliance with each of the articles of this Regulation, the actions foreseen for total adequacy and the schedule for them, as well as the officials responsible for compliance with said plan.
13 ANNEX N° 1 LOSS EVENT TYPES BY OPERATIONAL RISK Event Type (Level 1) Definition Event Type (Level 2) Examples Internal Fraud Losses derived from any type of action aimed at defrauding, improperly appropriating goods, or circumventing regulations, laws, or corporate policies (excluding diversity/discrimination events) in which at least one member of the company is involved. Unauthorized Activities Unrevealed operations (intentional), unauthorized operations (with financial losses), erroneous valuation of positions (intentional). Theft and Fraud Theft, embezzlement, forgery, bribery, account appropriation, smuggling, tax evasion (intentional). External Fraud Losses derived from any type of action aimed at defrauding, improperly appropriating goods, or circumventing legislation, by a third party. Theft and Fraud Theft, forgery. System Security Damages from cyberattacks, information theft. Labor Relations and Workplace Safety Losses derived from actions incompatible with legislation or labor agreements, regarding hygiene or workplace safety, regarding payment of claims for personal damages, or regarding cases related to diversity or discrimination. Labor Relations Issues regarding remuneration, social benefits, contract termination. Hygiene and Workplace Safety Cases related to hygiene and workplace safety standards; compensation to workers. Diversity and Discrimination Any type of discrimination. Clients, Products and Business Practices Losses derived from the involuntary or negligent non-compliance of a corporate obligation towards specific clients (including fiduciary and suitability requirements), or from the nature or design of a product. Suitability, Information Disclosure and Trust Breach of trust / non-compliance with guidelines, suitability/information disclosure aspects (customer knowledge, etc.), breach of privacy of retail customer information, breach of privacy, aggressive sales, abuse of confidential information. Improper Business or Market Practices Restrictive competition practices, improper commercial/market practices, market manipulation, abuse of privileged information (in favor of the company), money laundering. Defective Products Product defects (unauthorized, etc.), model errors. Selection, Sponsorship and Risks Absence of client investigation according to guidelines, excess of risk limits towards clients. Advisory Activities Litigation regarding results of advisory activities. Damage to Physical Assets Losses derived from damages or harm to physical assets as a consequence of natural disasters or other events Disasters and Other Events Losses from natural disasters, human losses from external causes (terrorism, vandalism). Business Interruption and System Failures Losses derived from business interruptions and system failures Systems Losses from hardware, software, or telecommunications equipment failures; electrical power failure. Execution, Delivery and Process Management Losses derived from errors in the processing of operations or in process management, as well as from relationships with commercial counterparties and suppliers Receipt, Execution and Maintenance of Operations Data entry errors, maintenance or download, non-compliance with deadlines or responsibilities, erroneous execution of models/systems, accounting errors. Errors in the securities clearing and cash settlement process (e.g., in Delivery vs. Payment). Tracking and Reporting Non-compliance with the obligation to report, inaccuracy of external reports (generating losses). Client Acceptance and Documentation Non-existence of authorizations / client rejections, non-existent / incomplete legal documents. Client Account Management Unauthorized access to accounts, incorrect client records (generating losses), loss or damage to client assets due to negligence. Commercial Counterparties Failures of counterparties other than clients, other litigations with counterparties other than clients. Distributors and Suppliers Subcontracting, litigations with suppliers.
14 ANNEX N° 2 GENERIC BUSINESS LINES FOR FINANCIAL SYSTEM COMPANIES Level 1 Level 2 Definition Corporate Finance Corporate Finance Realization of structured financing operations and participation in securitization processes; underwriting; financial advisory to corporate companies, large and medium-sized enterprises, as well as to the central government and public sector entities; among other activities of similar nature. Public Administration Finance Investment Banking Advisory Services Trading and Sales Sales Treasury operations; purchase and sale of securities, currencies, and commodities for own account; among other activities of similar nature. Market Making Own Positions Treasury Retail Banking Retail Banking Financing to retail clients including credit cards, auto loans, among others. Commercial Banking Commercial Banking Financing to non-retail clients, including: factoring, discounting, financial leasing, among others. Clearing and Payments External Clients Activities related to payments and collections, interbank fund transfer, clearing and settlement, among other activities of similar nature. Other Services Custody Custody services, trusts, fiduciary commissions, and other services. Trusts Other Services
15 ANNEX N° 3 GENERIC BUSINESS LINES FOR INSURANCE COMPANIES LEVEL 1 LEVEL 2 Definition General Lines Fire and Home Refers to policies issued against the following risks:
16
17 ANNEX N° 4 GENERIC BUSINESS LINES FOR AFP Level 1 Level 2 Definition Fund Administration Administration of mandatory contributions In the manner established in the SPP Law Administration of voluntary contributions In the manner established in the SPP Law
18
More like this from SBS
SBS published 4 documents in the last 30 days. We email you each new one the day it's published.