2020-02-26 | Resolución SBS 877-2020Added · Updated
Resolution SBS No. 877-2020 approves the Business Continuity Management Regulation, establishing mandatory requirements for supervised financial entities to maintain operational capacity during disruptions. The regulation defines a general management system for banks, insurers, and pension administrators, and a simplified system for investment banks and credit companies, detailing obligations for business impact analysis, risk assessment, strategy design, crisis management, and annual testing. It mandates board approval of continuity policies, specifies recovery time objectives, and imposes additional continuity requirements on entities subject to market concentration risk capital buffers.
SBS published 7 documents in the last 30 days — get each new one by email the day it lands.
Lima, February 26, 2020
Resolution S.B.S.
No. 877-2020
The Superintendent of Banks, Insurance, and Private Pension Fund Administrators
CONSIDERING:
That, the Corporate Governance and Integrated Risk Management Regulation, approved by Resolution SBS No. 272-2017, incorporates provisions intended to ensure that supervised companies have adequate risk management and corporate governance;
That, the Operational Risk Management Regulation, approved by Resolution SBS No. 2116-2009, includes provisions that companies must comply with in the effective management of operational risk;
That, through circulars G-139-2009, G-164-2012, and G-180-2015, the minimum criteria for business continuity management, the obligation to report significant operational disruption events, and the use of key indicators for business continuity management were established, respectively;
That, it is necessary to update the regulations on business continuity management by approving a regulation complementary to the Operational Risk Management Regulation, taking into consideration the results of supervision activities and the Sectoral Business Continuity Exercises carried out in 2014 and 2017, as well as international standards and best practices on the matter, including the ISO 22301:2012 standard on business continuity management systems, and the Business Continuity Institute’s Best Practices Guide;
That, to gather public opinion, the draft resolution on this matter was pre-published on the Superintendent’s electronic portal, under the provisions of Supreme Decree No. 001-2009-JUS;
With the approval of the Deputy Superintendencies of Banking and Microfinance, Private Pension Fund Administrators, Insurance, Risk, and Legal Advisory; and,
In exercise of the powers conferred by paragraphs 7 and 9 of Article 349 of the General Law of the Financial System and the Insurance System and the Organic Law of the Superintendency of Banks and Insurance, Law No. 26702 and its amendments, and paragraph d) of Article 57 of the Law of the Private System for the Administration of Pension Funds, whose Unified Text of Regulations is approved by Supreme Decree No. 054-97-EF;
RESOLVES:
Article First.- Approve the Regulation for Business Continuity Management, as indicated below:
“REGULATION FOR BUSINESS CONTINUITY MANAGEMENT
CHAPTER I
GENERAL PROVISIONS
Article 1. Scope
1.1. This Regulation applies to the companies indicated in Articles 16 and 17 of the General Law, as well as to Private Pension Fund Administrators (AFP), hereinafter referred to as companies.
1.2. It also applies to the National Bank, the Agricultural Bank, the Development Financial Corporation (COFIDE), the MIVIVIENDA S.A. Fund, and the Benefit Funds and Benefit Boxes under the supervision of the Superintendency, insofar as they do not conflict with specific regulations governing the operations of said institutions.
Article 2. Definitions
For the application of this Regulation, the following definitions must be considered:
a) Business Impact Analysis: Process by which the effects of a business disruption event are evaluated to determine the priority with which company activities must be recovered.
b) Maximum Acceptable Impact: Maximum level of impact that can be accepted by the company in the event of a business disruption across various aspects, such as financial, regulatory, reputational, public, and compliance with strategic objectives.
c) Business Recovery Objective: Minimum acceptable level of operability of products and services to be recovered after a disruption. It can be defined in terms of one or a combination of the following variables: service channels, volume of operations, volume of clients, amounts for processing operations, and service hours.
d) Maximum Tolerable Period of Disruption (MTPD): Period after which a disruption reaches one of the maximum acceptable impact levels.
e) Single Point of Failure: Unique source or path of a service, activity, and/or process for which there is no alternative and whose loss or failure could cause a disruption.
f) Recovery Point Objective (RPO): Maximum level of information that could be lost as a result of a disruption in information technology services. It is represented in units of time.
g) Recovery Time Objective (RTO): Time established by the company to resume operations in the event of a disruption. It is shorter than the MTPD.
Article 3. Business Continuity Management System
3.1. The business continuity management system is the component of integrated risk management that seeks to ensure the company’s capacity to continue operating at previously established levels in the event of a disruption.
3.2. The business continuity management system implies, at a minimum, the following phases:
i) Understanding the organization; ii) design of the continuity strategy; iii) implementation of the continuity strategy; iv) testing plan; v) training; and, vi) review and update.
Article 4. Proportionality of the Business Continuity Management System
4.1. The company’s business continuity management system must be proportional to the size, nature, and complexity of its operations.
4.2. The provisions regarding the general business continuity management system and operational disruption reports, described in Subchapters I and IV of Chapter II, respectively, are mandatory for the following companies:
a) Banking Company; b) Financial Company; c) Municipal Savings and Credit Cooperative - CMAC; d) Popular Credit Municipal Cooperative - CMCP; e) Rural Savings and Credit Cooperative - CRAC; f) Insurance and/or Reinsurance Company; g) Cash Transportation, Custody, and Administration Company; h) Private Pension Fund Administrator; i) 1 j) Electronic Money Issuing Company; k) The National Bank; l) Credit Company authorized to operate with electronic money, credit cards, or provide interoperable payment services 2.
4.3. The provisions regarding the simplified business continuity management system, described in Subchapter II of Chapter II, are mandatory for the following companies:
a) Investment Bank; b) Credit Company 3; c) Fund Transfer Company; d) Benefit Fund and Benefit Box under the supervision of the Superintendency; e) Development Financial Corporation – COFIDE; f) MIVIVIENDA S.A. Fund; g) Guarantee Fund for Small Industry Loans – FOGAPI; and, h) The Agricultural Bank.
4.4. The companies indicated in Article 1 not listed in paragraphs 4.2 or 4.3 above may establish a business continuity management system in accordance with the provisions of this regulation.
Article 5. Policies for Business Continuity Management
5.1. Policies for business continuity management must be approved by the board of directors and must consider at least the following:
a) Alignment with the company’s strategic objectives; b) Provision of a framework to establish and achieve business continuity management objectives; and, c) Establishment of maximum acceptable impacts in the event of a disruption, which must be considered for the business impact analysis.
5.2. Policies must be reviewed periodically to ensure they remain aligned with the company’s objectives and organizational structure.
1 Literal eliminated by Resolution SBS No. 814-2025 published on 10/03/2025.
2 Literal incorporated by Resolution SBS No. 814-2025 published on 10/03/2025.
3 Literal substituted by Resolution SBS No. 814-2025 published on 10/03/2025.
Article 6. Responsible for Business Continuity Management
6.1. Business continuity management may be performed by a specialized unit or assigned to another unit of the company, depending on the size, nature, and complexity of its operations.
6.2. The unit in charge of business continuity management has the following responsibilities regarding such management:
a) Propose policies; b) Develop appropriate procedures and methodologies; c) Support and assist company units in implementing the developed policies, procedures, and methodology; d) Ensure that management is integrated into the company’s risk management; e) Ensure that the board of directors, general management, and risk committee are aware of relevant aspects of management for timely decision-making; f) Ensure that the development of activities related to management is approved by the corresponding instances; and, g) Identify training and dissemination needs for adequate management.
CHAPTER II
BUSINESS CONTINUITY MANAGEMENT SYSTEMS
SUBCHAPTER I
GENERAL BUSINESS CONTINUITY MANAGEMENT SYSTEM
Article 7. Understanding the Organization
7.1. The company must conduct a business impact analysis and a risk assessment that could cause business disruption, the results of which must be approved by the risk committee and reported to the board of directors.
7.2. The business impact analysis must include the following:
a) An inventory of products or services delivered to individuals or legal entities that could be affected by the interruption of the company’s activities, including obligations maintained with said individuals or entities in said inventory; b) An evaluation over time of the financial, regulatory, and reputational impacts, on the public, and on compliance with strategic objectives that could result from interrupting the delivery of products and services, with the objective of determining the MTPD and RTO; c) The definition of prioritized products and services, considering the corresponding MTPD and RTO, as well as the identification of the processes supporting them; and, d) The estimation of own and/or third-party resources necessary for the execution of prioritized products and services, including personnel with technical capabilities, procedures, information, technology, and infrastructure.
7.3. The risk assessment that could cause business disruption must include at least the following:
a) Identification of single points of failure; b) Scenarios in which necessary resources, own and/or provided by third parties, are not available; and, c) Exposure to risks related to the geographic location of its facilities and those of providers whose failure or unavailability could affect the company’s operational continuity.
7.4. Methodologies for developing the business impact analysis and the risk assessment that could cause business disruption must be consistent with those used for operational risk management. It should be noted that risks that could cause a disruption must be considered as part of the company’s operational risk management.
Article 8. Design of Continuity Strategy
8.1. The company must design strategies to ensure continuity in the delivery of prioritized products and services referred to in paragraph c) of Article 7.2.
8.2. Such continuity strategies must be approved by the board of directors and must consider the following:
a) Technical feasibility, RTOs, and resources necessary for implementation; b) A scenario analysis including the failure or unavailability of goods or services provided by third parties; c) Having more than one data processing center with distinct risk profiles, so that possible disruption events do not affect them simultaneously; d) 4 e) Facilities designated for the recovery of processes supporting prioritized products and services must comply with the security policies and protocols established by the company; f) If data processing centers are located in the same city, having an analysis performed by an independent and specialized third party, analyzing whether the data processing centers will or will not be affected by the same disruption event, considering the geographic location, soil, infrastructure, and accessibility of each center; 5 g) The analysis referred to in the previous paragraph f) must be updated periodically or in the event of changes in any of the stated characteristics; and, h) The results of the analysis stipulated in paragraph f) along with proposals for activities required to comply with the indication in the previous paragraph c) must be presented to the board of directors.
Article 9. Implementation of Continuity Strategy
9.1. The company must implement the approved continuity strategies. For this purpose, it must develop crisis management plans, continuity plans for prioritized products and services, information technology service recovery plans, and emergency plans.
9.2. The crisis management plan describes the organizational structure and applicable procedures in a crisis situation, including the following:
a) Activation and deactivation criteria; b) Composition of the strategic-level crisis committee; c) Guidelines for decision-making; d) Roles and responsibilities during the crisis; e) Communication scheme among crisis committee members; and f) Guidelines for communication with individuals or legal entities and legal entities that could be affected by the interruption of the company’s activities.
9.3. The continuity plan for prioritized products and services describes the necessary aspects for deploying strategies to ensure continuity in the delivery of said products and services, and must include the following:
4 Literal eliminated by Resolution SBS No. 3601-2021 published on 29/11/2021.
5 Literal modified by Resolution SBS No. 3601-2021 published on 29/11/2021.
a) Activation and deactivation criteria; b) Roles and responsibilities of those involved; and c) Description of procedures and resources necessary to recover products and services; and, d) Description of procedures and resources necessary to return products and services to normal operation.
9.4. The information technology (IT) service recovery plan describes the necessary aspects for deploying approved strategies to recover IT services. Such plan must contemplate the following aspects:
a) Activation and deactivation criteria; b) Composition of the team in charge of recovering IT services, which must include providers supporting said IT services; c) Roles and responsibilities; d) Description of procedures and resources necessary to recover IT services; and e) Description of procedures and resources necessary to return IT services to normal operation.
9.5. The emergency plan describes the necessary aspects to safeguard the physical integrity of personnel and the general public in the company’s facilities.
Article 10. Testing Plan
10.1. Continuity tests must ensure compliance with business continuity management objectives.
10.2. The company must plan and execute annual tests of crisis management plans, business continuity plans, IT service recovery plans, and emergency plans.
10.3. In the event of having multiple strategies to ensure the continuity of prioritized products and services, the company must test all of them in a period not exceeding three years.
10.4. The company must prepare reports on the execution of tests including the following information: objectives and goals of the test; characteristics, scope, and scenario; results obtained and opportunities for improvement; and, action plans to implement.
10.5. The Superintendency may establish specific scenarios to be considered for tests to be executed in a given period.
Article 11. Training and Organizational Culture
The company must ensure the necessary knowledge and commitment to business continuity management at all levels of the organization. To this end, the company must consider the following aspects:
a) Design and implement training programs directed at different organizational levels, according to the functions and responsibilities assigned within the business continuity management system; and, b) Design and execute activities that integrate business continuity management into the company’s organizational culture.
Article 12. Review and Update
The company must review the business continuity management system periodically or in the event of new products or significant changes in the business, operational, or IT environment. For this purpose, it must establish policies for periodic review and guidelines to identify situations warranting its update.
SUBCHAPTER II
SIMPLIFIED BUSINESS CONTINUITY MANAGEMENT SYSTEM
Article 13. Simplified Business Continuity Management System
The simplified business continuity management system must consider the following:
Understanding the Organization.- The company must prioritize products and services and define RTOs. The results of these activities must be approved by the risk committee and reported to the board of directors.
Design of Continuity Strategy.- The board of directors must approve strategies to ensure continuity in the delivery of prioritized products and services. In the case of IT service recovery, the company must implement an alternative data processing center to support prioritized products and services.
Implementation of Continuity Strategy.- Approved strategies must be documented in plans to allow their deployment. Such plans must consider the following aspects:
a) Formation of a crisis committee, criteria for its activation, and definition of guidelines for decision-making in a crisis situation; b) Procedures and resources to recover the delivery of prioritized products and services; c) Procedures and resources to recover IT services; and d) Procedures to manage emergency situations.
Testing Plan.- The company must execute annual tests of its plans. Such tests must ensure the validation of all business continuity strategies in a period not exceeding two years.
Training and Organizational Culture.- The company must ensure that its personnel has sufficient knowledge to fulfill assigned roles as part of business continuity management.
Review and Update.- The company must periodically review or in the event of new products or significant changes in the business, operational, or IT environment, its business continuity management.
SUBCHAPTER III
ADDITIONAL PROVISIONS APPLICABLE TO COMPANIES WITH MARKET CONCENTRATION
Article 14. Company with Market Concentration 6
14.1. Complementarily to the provisions contained in Subchapters I or II, the company subject to the requirement of effective capital buffer for market concentration risk, according to what is stated in the Regulation for the Requirement of Conservation Buffers, by Economic Cycle and by Market Concentration Risk, must comply with the following provisions as part of its business continuity management:
a) Consider for the design of continuity strategies, the fulfillment of business recovery objectives, RPOs, and RTOs. In the case of passive products, an RTO not exceeding three (3) hours must be ensured in contingency situations affecting the company individually; 7
6 Article modified by Resolution SBS No. 3955-2022, published on 27/12/2022, effective from 01/01/2023.
7 Literal substituted by Resolution SBS No. 814-2025, published on 10/03/2025, effective from 01/06/2025 with the exception of the National Bank. For the National Bank, the effective date is from 01/01/2026.
b) Incorporate as part of the prioritized products and services those whose unavailability would affect other companies in the financial system, the insurance system, or the private pension fund administration system; c) Ensure that alternate data processing centers allow for the recovery of all prioritized products and services, in order to meet business recovery objectives, TORs, and PORs; d) Ensure the recovery of those offices and/or agencies previously identified as priority; e) Identify the maximum operating time in contingency situations following an interruption; f) Justify, through a risk assessment, that at least one of the facilities designated for the recovery of prioritized products and services would be available in the event of an occurrence; g) Implement alternative strategies for customer identification, allowing the delivery of prioritized products and services in force majeure situations that prevent the use of identification documents employed in normal operations; h) Designate main and alternate members for the crisis committee, seeking to maximize the probability of having at least one of them available; i) Implement an alternative communication medium to traditional communication, in order to ensure communication with critical personnel and those who may be affected by the interruption of the company's activities, in case said communication fails; j) Implement protocols for communication through the alternative communication medium, which must contemplate internal communication, as well as with authorities, suppliers, and all those who may be affected by the interruption of the company's activities; k) Conduct periodic training on crisis communication protocols and the use of alternative communication mechanisms; and l) Implement redundant data communication networks, seeking to mitigate single points of failure.
14.2 In the case of companies subject to effective capital requirements for market concentration risk that belong to the same economic group, according to the definition contemplated in the Special Standards on Linkage and Economic Group approved by Resolution SBS No. 5780-2015 or the norm that replaces it, the provisions described in paragraph 14.1 are applicable only to that company in the economic group that has the highest level of assets.
SUBCHAPTER IV
OPERATIONAL INTERRUPTION REPORTS
Article 15. Information on significant operational interruption events 8
15.1 The company must inform the Superintendency of the occurrence of a significant operational interruption event as soon as it becomes aware of it and within a maximum period of one (01) business day. For this purpose, a significant operational interruption event is understood as an event that implies any of the following situations:
a) The suspension in the delivery of prioritized products and services for a time greater than the respective TORs; or,
8 Summarily modified by Resolution SBS No. 814-2025, published on 10/03/2025.
b) The activation of the crisis management plan referred to in paragraph 9.2 of Article 9.
15.2 Additionally, and without prejudice to the foregoing, banking companies, financial companies, CMACs, CMCPs, and CRACs must inform the Superintendency of the occurrence of the following events:
a) The suspension in the delivery of prioritized products and services for a time equal to or greater than four hours. b) The interruption in any of the attention channels that lasts for a period equal to or greater than four hours. In the case of in-person channels, the unavailability of 25% of the attention points at the national level must be considered.
The information regarding these events must be submitted within a maximum period of 5 hours from their start, provided they occur between 07:00 am and 04:00 pm. If the incident occurs outside of this schedule, the report must be made no later than the start of the next business day. 9
15.3 In the case of companies with market concentration, as described in Article 14, they must inform the Superintendency of the occurrence of the following events:
a) The suspension in the delivery of prioritized products and services for a time equal to or greater than 1 hour. b) The interruption in any of the attention channels that lasts for a period equal to or greater than 1 hour. In the case of in-person channels, the unavailability of 25% of the attention points at the national level must be considered.
The information regarding these events must be submitted within a maximum period of 2 hours from their start, provided they occur between 07:00 am and 04:00 pm. If the incident occurs outside of this schedule, the report must be made no later than the start of the next business day. 10
15.4 The information to be submitted must include a general description of the event that occurred and must be sent to the email address: continuidad@sbs.gob.pe or, in case the company does not have access to said email due to the occurrence of the interruption event, alternative means of communication must be sought to the extent possible.
15.5 Within ten (10) business days following the occurrence of the interruption event reported to the Superintendency, the company must submit a detailed report explaining the reasons for the failure, the duration, the business lines, products, and services affected, as applicable, the measures taken to overcome the event, and the situation existing as of the report date.
Article 16. Indicators of business continuity management
16.1 The company must implement indicators to monitor business continuity management.
16.2 The company must report quarterly to the Superintendency the indicators indicated in Annex 1 of this regulation. The reports must be submitted through the "External Capture and Validation Sub-module" (SUCAVE), within fifteen (15) calendar days following the close of the period subject to reporting. The formats of the reports and their methodological notes are published on the institutional portal (www.sbs.gob.pe), in accordance with what is established in Supreme Decree No. 001-2009-JUS.
9 Subparagraph 15.2.b) is modified by Resolution SBS No. 3601-2021, published on 29/11/2021. Subsequently, paragraph 15.2 is replaced by Resolution SBS No. 814-2025, published on 10/3/2025.
10 Paragraph 15.3 is replaced by Resolution SBS No. 814-2025, published on 10/3/2025.
SUBCHAPTER V
OPERATIONAL RESILIENCE PROVISIONS IN DIGITAL CHANNELS OF MULTIPLE OPERATION COMPANIES 11
Article 17. Scope 12
The provisions described in this subchapter apply to the companies indicated in letters a), b), c), d), e), and k) of paragraph 4.2 that have implemented digital channels.
Article 18. Business continuity management in digital channels 13
18.1 As part of the "understanding of the organization" stage described in Article 7, the company must:
a) Identify the prioritized products and services offered through digital channels and establish a TOR for each of them. b) Specifically and in detail manage the risks that may interrupt operations in their digital channels. This assessment must include the identification of technological components whose failure may significantly affect the continuity of the prioritized products and services offered through said channels. c) Expressly establish the characteristics and normal conditions under which prioritized products and services are offered in each digital channel, which must be approved by the Board of Directors or Risk Committee. These characteristics must be defined and monitored for each prioritized product and service offered through digital channels.
18.2 The company must implement strategies and plans to prevent, mitigate the impact, and contain events that interrupt the provision of prioritized products and services through digital channels, as well as to restore said services within the established timeframes and conditions. These strategies must contemplate:
a) Implement a monitoring system to supervise the functioning of digital channels offering prioritized products and services, so that it allows identifying any deviation from the normal levels established for each product or service. b) Implement alternative attention channels or schemes in case of interruption of the digital channels through which prioritized products and/or services are offered. c) As part of the information technology (IT) service recovery plan mentioned in paragraph 9.4, the company must develop protocols to address technological failures and the resulting interruptions in the provision of prioritized products and services in digital channels, so as to ensure their restoration to normal levels in the established TORs. d) As part of the communication guidelines referred to in letter f) of paragraph 9.2, the company must develop provisions that guarantee the timely communication of: i) incidents or significant failures to stakeholder groups, including users; and ii) the alternative channels available to continue carrying out operations.
18.3 As part of the testing plan mentioned in Article 10, the company must conduct annual tests to verify the effectiveness of the strategies established to guarantee the continuity of prioritized products and services through digital channels.
11 Subchapter incorporated by Resolution SBS No. 814-2025, published on 10/3/2025.
12 Article whose validity begins on 01/06/2025 for companies with market concentration, with the exception of the National Bank. For the National Bank and the rest of the companies, the validity begins on 01/01/2026.
13 With validity beginning on 01/01/2026.
18.4 The company must maintain a centralized record of all events that have caused the interruption of the provision of prioritized products and services through digital channels for a period greater than 30 minutes, continuous or intermittent. This record must contain, at a minimum, the following fields:
a) Date and time of the start of the event and of the restoration to normal operations. b) Description of the event, the failure, and its causes. c) Affected products and services. d) Affected channels. e) Involved suppliers, if applicable. f) Person responsible for incident management.
Article 19. Clarifications to ensure operational resilience of main digital channels 14
19.1 The provisions of this article are applicable to companies that have the following digital channels: internet banking, mobile application, or digital wallets; through which they offer services of intra-bank transfers, inter-bank transfers, interoperable payments, corporate payroll payments, or payments to suppliers.
19.2 The company must define the characteristics and conditions under which transfer services, interoperable payments, payroll payments, and supplier payments are offered through the digital channels indicated in the previous paragraph to natural persons and companies, in accordance with the structure of Reports CD-A and CD-B of Annex 2, respectively. The reports contain the names of the digital channels, general information about the normal conditions under which they operate (availability schedule, minimum daily availability, entry latency time, and scheduled interruptions) and under which products and/or services are offered through them (TOR, service schedule, minimum daily availability, operational latency time, scheduled interruptions), and the alternative channels in case of contingency. The formats of the reports indicated in this paragraph are attached to this regulation and published on the institutional portal (www.sbs.gob.pe), in accordance with what is established in Supreme Decree No. 009-2024-JUS and its modifying norms.
19.3 Reports CD-A and CD-B must be approved and managed in accordance with what is established in subparagraph c) of paragraph 18.1. The reports, along with the certificate of their annual approval or ratification, must be sent to the Superintendency through the Virtual Front Desk application located in the Supervised Portal, no later than March 31 of each year. In case of modifications, the reports must be sent within a maximum period of seven (07) days following the change made. The Superintendency may instruct via multiple letter the use of an alternative mechanism to the aforementioned one for the submission of information referred to in this paragraph.
19.4 The services of transfers, interoperable payments, payroll payments, and supplier payments granted through the following digital channels: internet banking, mobile application, and digital wallets, are services that require priority recovery in case of interruption. Therefore, they must consider a TOR no greater than three (03) hours for companies with market concentration and five (05) hours for other companies.
19.5 Companies must execute annual tests to verify compliance with the TORs of transfer services, interoperable payments, payroll payments, and supplier payments from internet banking, mobile application, or digital wallets. The result reports of these tests, which must include the lessons learned resulting from their execution, must be sent to the Superintendency as part of the annual operational risk management report (IG-ROp), mentioned in Article 15 of the Regulation for Operational Risk Management, approved by Resolution SBS No. 2116-2009 and its modifications.
14 With validity beginning on 01/6/2025 for companies with market concentration, with the exception of the National Bank. For the National Bank and the rest of the companies, the validity begins on 01/01/2026.
19.6 The services of intra-bank transfers, inter-bank transfers, interoperable payments, corporate payroll payments, and supplier payments offered through the following digital channels: internet banking, mobile application, and digital wallets, cannot be interrupted, within the schedule comprised between 06:00 am and 10:00 pm for a period greater than three (03) hours for companies with market concentration, and five (05) hours for other companies. This maximum time applies to both continuous and accumulated interruptions within that time range on the same day. This requirement applies to unscheduled interruptions or those derived from operational failures.
19.7 Continuity strategies must contemplate the development of procedures that allow, in case of interruptions, to continue offering transfer services, interoperable payments, payroll payments, and supplier payments; and/or allow users to have access to their deposit funds through other schemes or channels.
FINAL AND COMPLEMENTARY PROVISIONS
First.- Without prejudice to what is stated in Article 4, the Superintendency may require that a company, which complies with what is established in paragraph 4.3 of Article 4, comply with the provisions indicated in paragraph 4.2 of said article. 15
Second.- In the case of the companies indicated in letters a, b, c, d, e, j, k, and l of Article 4.2, the design of continuity strategies must ensure that the information corresponding to the operations of all passive products complies with a POR equal to zero. 16
Third.- Interruption in digital channels is understood as any impediment, whether total or partial, that affects the provision of prioritized products or services through them. The degradation of service levels in said channels, when it generates a significant impact on users, in some economic sector, in the fulfillment of legal or regulatory commitments, or in the company's reputation, is considered a partial impediment for the provision of services. 17
Fourth.- The companies mentioned in paragraph 19.1 of Article 19, which offer interoperable payment services, must submit to the Superintendency, through the Virtual Front Desk application located in the Supervised Portal, the following annexes, which form part of the Regulation on the Quality Levels of Interoperable Payment Services provided by Providers, Payment Agreements, Payment Systems, and Technological Providers, approved by Circular No. 0009-2024-BCRP or the norm that replaces it. These submissions must comply with formats established by the Central Reserve Bank of Peru and with the periodicity determined by this entity, including additional submissions derived from corrections:
a) Annex 14 – Monthly Report of Executed Maintenance. b) Annex 15 – Monthly Incident Report. c) Annex 16 – ANS-RTO Report. d) Annex 17 – Service Quality Indicators Report.
The Superintendency may instruct via multiple letter the use of an alternative mechanism to the aforementioned one for the submission of information referred to in this final and complementary provision. 18
Fifth.- The first submission of Reports CD-A and CD-B of Annex 2 must be carried out by companies with market concentration no later than July 15, 2025. 19
Second Article.- Modify Article 1, first paragraph of Article 7, Article 13, and the first paragraph of Article 15 of the Regulation for Operational Risk Management, approved by Resolution SBS No. 2116-2009, in accordance with the following texts:
“Article 1°.- Scope
This Regulation applies to the companies indicated in Article 16 of the General Law, as well as to Private Pension Fund Administrators (AFP), hereinafter companies.
It also applies to the National Bank, the Agropecuario Bank, the Development Financial Corporation (COFIDE), the MIVIVIENDA S.A. Fund, and the Derramas and Benefit Cash Boxes under the supervision of the Superintendency, insofar as they do not conflict with specific regulations governing the actions of these companies. Complementary and related service companies indicated in Article 17 of the General Law are subject, for the management of their operational risk, to what is established in specific norms, as well as in Article 13 of this Regulation.”
“Article 7°.- Responsibilities of Management
The general management is responsible for implementing operational risk management in accordance with the Board's provisions, for which it may dispose of the constitution of committees it considers pertinent.
(…)”
“Article 13°.- Business Continuity and Information Security Management As part of adequate operational risk management, the company must implement a business continuity management system in accordance with the provisions of the Regulation for Business Continuity Management. Likewise, the company must have an information security management system, oriented to guarantee the integrity, confidentiality, and availability of its information.”
“Article 15°.- Report to the Superintendency
The company must present annual reports to the Superintendency regarding operational risk management, through the IG-ROp application, which is available on the Supervised Portal. Said reports must be submitted no later than March 31 of the year following the report year.
(…)”
Third Article: Modify letters l) and aa) of Article 2 of the Regulation on Corporate Governance and Integrated Risk Management, approved by Resolution SBS No. 272-2017, in accordance with the following texts:
“Article 2°.- Definitions and/or References
(…) l) Event.- An event or series of events that can be internal or external to the company, originating from the same cause, that occurs during the same time period.
(…) aa) Products.- Operations and/or services provided by the company to its clients and users.
(…)”
Fourth Article.- Annex No. 1, which contains the formats for Risk Indicators for Business Continuity Management, forms part of the Regulation for Business Continuity Management approved by Article First of this resolution, and is published on the Institutional Portal (www.sbs.gob.pe), in accordance with what is established in Supreme Decree No. 001-2009-JUS.
Fifth Article.-
20 This resolution enters into force on January 1, 2022, from which date Circular No. G-139-2009, Circular No. G-164-2012, and Circular No. G-180-2015 are repealed, except for the measures approved in subparagraphs 8.2.f, 14.a, and 14.c, and in the Second Final and Complementary Provision of the Regulation for Business Continuity Management approved by Article First, which enter into force on July 1, 2022.
Sixth Article.-
21
20 Article replaced by Resolution SBS No. 1536-2020, published on 08/06/2020 and Resolution SBS No. 3601-2021 published on 29/11/2021 21 Article repealed by Resolution SBS No. 1536-2020 published on 08/06/2020.
Register, communicate, and publish.
SOCORRO HEYSEN ZEGARRA
Superintendent of Banks, Insurance, and
Private Pension Fund Administrators
Read the rest free
Amended 2 times · last 2025-09-17
Source: Superintendencia de Banca Seguros y AFP — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from SBS
SBS published 7 documents in the last 30 days. We email you each new one the day it's published.