2023-11-14

Added · Updated

Risk Management Framework for Shari’ah Compliant Banking

Domestic banks licensed by SAMA conducting Shari’ah compliant banking activities must maintain a comprehensive risk management framework with active Board and Senior Management oversight, ensuring compliance with Shari’ah rules and risk appetite. These entities must implement sound processes for identifying, measuring, and mitigating credit and market risks, including independent risk functions and adequate management information systems. The framework supersedes the previous version issued on 02-12-2021G.

Saudi Central Bank logo

Saudi Arabia

Saudi Central Bank

Scan of the document's first page
Share

Get SAMA alerts — same-day email on every new publication.

Annotated text · 53 obligations · 1 permission · 0 reporting items
  • Obligation 53
  • Permission 1
  • Definition / condition 44
  • Reporting template 0
  • background, boilerplate

Lineage: In force

Decision No. 3/2149 dated 1985-…Decision No. 3/2149 dated 1985-10-14Law No. M/36 dated 2020-11-26Law No. M/36 dated 2020-11-26Law No. M/5 dated 1966-06-11Law No. M/5 dated 1966-06-11Risk Management Framework for S…2021Risk Management Framework for Shari’ah Compliant Banking (2021-12-02)Risk Management Framework forShari’ah Compliant Banking2023-11-14 · this documentRisk Management Framework for Shari’ah Compliant Banking (2023-11-14)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

What changed in the obligations

Against Risk Management Framework for Shari’ah Compliant Banking (2021-12-02)

18 new obligations · 5 changed obligations · 1 deadline changed · 8 changes of scope · 1 change of who is bound · 35 not carried over

23 obligations are the same in both texts.

Changed (15)
  • What must be done
    Before
    The Board of Directors or the related committee of the Board shall approve the risk management objectives, strategies and policies that are consistent with the risk profile, risk appetite and risk tolerance for the Bank. in the old text
    Now
    The Board or the delegated committee of the Board shall approve the risk management objectives, strategies and policies, risk appetite and risk tolerance of the bank, taking into consideration the overall economic and financial conditions. in this text
  • Scope
    Before
    4.4 The Board of Directors or the related committee of Board shall ensure the existence of an effective risk management structure for conducting activities including adequate systems for measuring, monitoring, reporting and controlling risk exposures commensurate with the scope, size and complexity of the Bank's business and operations. in the old text
    Now
    5.3 Board or the delegated committee shall ensure that there is an effective risk management structure and policies and procedures governing the conduct of Shari’ah complaint banking activities, including adequate systems for measuring, monitoring, reporting and controlling risk exposures commensurate with the scope, size and complexity of the bank’s business and operations. in this text
  • Who is bound
    Before
    4.8 Senior Management shall ensure that the risk management function should be separated from risk taking function and is reporting directly to the Chief Executive officer/General Manager. in the old text
    Now
    5.5 Board or the delegated committee must ensure that the risk management function is independent from risk taking functions and is reporting directly to the Chief Executive officer/General Manager. in this text
  • Scope
    Before
    4.7 Senior Management shall execute the strategic direction set by the Board of Directors or the related committee of Board on an ongoing basis and set clear lines of authority and responsibility for managing, monitoring and reporting risks. in the old text
    Now
    5.6 Senior management must ensure that the policies and procedures clearly establish roles and responsibilities, and lines of accountability of various functions within the bank for managing, monitoring and reporting risk arising from Shari’ah compliant banking activities. in this text
  • Scope
    Before
    4.6 The senior management shall develop and implement well defined procedures for identifying, measuring, monitoring and controlling risks in line with the risk management objectives, strategies and policies approved by the Board of Directors or the related committee of Board. in the old text
    Now
    5.7 Senior management must ensure that there are well defined policies and procedures managing risks arising from Shari’ah compliant banking activities, in line with the risk appetite and risk tolerance approved by the Board or the delegated committee, and ensure that these policies and procedures are effectively implemented. in this text
  • Scope
    Before
    4.9 The Bank shall have a sound process for executing all elements of risk management including risk identification, measurement, mitigation, monitoring, reporting and control. in the old text
    Now
    6.1 Banks must have in place sound processes for identification, measurement, mitigation, monitoring and reporting of risks associated with Shari’ah compliant banking activities. in this text
  • Scope
    Before
    4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: ii. Integration of Risk Management: While assessing and managing risk, the management should have an overall view of risks the Bank is exposed to. in the old text
    Now
    Risk management processes for Shari’ah compliant banking activities should be integrated with the overall risk management framework, where relevant, to ensure the bank have an overall view of risk exposures and interlinkages with other activities and functions within the bank. in this text
  • Deadline
    Before
    4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: vi. Management Information System: The Bank should specify control reports to be prepared by the independent risk management department that should be periodically (at least quarterly) submitted to the related committee of Board and the Senior Management. in the old text
    Now
    The state of compliance should be reported to the Risk Management Committee and Senior management periodically or more frequently, when necessary. in this text
  • What must be done
    Before
    This process requires the implementation of appropriate policies, limits, procedures and effective management information systems (MIS) for internal risk reporting and decision making that are commensurate with the scope, complexity and nature of the Banks' activities. in the old text
    Now
    6.3 Banks must ensure that effective management information systems (MIS) are in place to support their risk management activities, decision making, facilitate compliance with internal and SAMA’ prudential and supervisory reporting requirements. in this text
  • Scope
    Before
    6.8 Banks shall ensure that they comply at all times with the Shari'ah rules and principles as approved/instructed by the Banks' Shari'ah Committee with respect to its products and activities. in the old text
    Now
    6.6 Banks must ensure that the structuring of products, underlying transactions and contracts are fully compliant with Shari’ah rules and principles. in this text
  • What must be done
    Before
    5.11 In addition to the above, there should be a middle office or an independent function to perform market risk management function and to independently monitor, measure and analyze risks inherent in the treasury operations of a Shari'ah compliant Banking. in the old text
    Now
    8.3.2 setting a middle office or an independent market risk management function to monitor, measure and analyze risks inherent in the treasury operations of a Shari’ah compliant banking activities and periodically report to senior management market risk exposures and risk mitigation and control measures; in this text
  • Scope
    Before
    5.3 Banks shall establish a sound and comprehensive market risk management process and information system which (among others) comprise: a strong MIS for controlling, monitoring and reporting market risk exposure and performance to appropriate levels of senior management. in the old text
    Now
    8.3.4 effective management information system for monitoring and measuring asset risk exposure and performance, and reporting to senior management and board. in this text
  • What must be done
    Before
    5.4 Banks should be able to quantify market risk exposures and assess exposure to the probability of future losses in their net open asset positions. in the old text
    Now
    8.4 Banks must, at all time, be able to quantify market risk exposures, analyze and report to senior management and board their exposure to potential losses in their net open asset positions both under normal and stressed market conditions. in this text
  • Scope
    Before
    5.9 When Banks are involved in buying assets that are not actively traded with the intention of selling them, it is important to analyze and assess the factors attributable to changes in liquidity of the markets in which the assets are traded and which give rise to greater market risk. in the old text
    Now
    8.5 Banks must assess the market structure including consideration on the level of liquidity giving rise to heightened market risk, and availability of market prices in assets where the bank is exposed to. in this text
  • What must be done
    Before
    5.7 Where available valuation methodologies are deficient, Banks shall assess the need (a) to allocate funds to cover risks resulting from illiquidity, new assets and uncertainty in assumptions underlying valuation and realization; and (b) to establish a contractual agreement with the counterparty specifying the methods to be used in valuing the assets. in the old text
    Now
    8.6 Where valuation methodologies are deficient, banks should establish a contractual agreement with the counterparty specifying the methods to be used in valuing the assets or assess the need to allocate funds to cover risks resulting from illiquidity and uncertainty in assumptions underlying valuation and realization. in this text
New in this text (18)
  • Banks must ensure that compliance practices by their majority owned subsidiary(ies) or branches conducting Shari’ah compliant banking activities outside Saudi Arabia are consistent with the requirements of this framework. in this text
  • Shari’ah compliant banking activities conducted by the bank shall be consistent with the risk appetite and within the risk tolerance level approved by the Board or the delegated committee. in this text
  • 6.4 Banks must be aware and understand the different types of risk inherent in all Shari’ah compliant banking products that they offer. in this text
  • 6.5 Banks that offer profit sharing investment accounts (PSIAs) must establish mechanisms for monitor that funds provided by the account holders were utilized for purposes that are in line with the terms and conditions agreed with account holders. in this text
  • Banks must also comply with the risk management requirements set out in the PSIAs Rules (September 2022) and any subsequent updates. in this text
  • Banks must have in place appropriate functions and structure (e.g. Shari’ah risk administration department or unit either separated or embedded within the risk originating function) to ensure that documentation of transactions required for Shari’ah compliant products are complete and that the sequencing of transactions and contracts, are compliant with Shari’ah rules and principles. in this text
  • Banks should periodically review adequacy of resources, competencies and skills for the operation of Shari’ah compliant banking activities and have in place training programs to address any gaps identified in internal capacity and competencies. in this text
  • 7.1 Principle 2.0: Banks shall have in place appropriate methodologies and adequate systems, infrastructure and resources for identifying, measuring, managing and reporting the credit risk exposures arising from Shari’ah compliant financing products. in this text
  • 7.2 Banks must have well-defined criteria and policies and processes for approving new credit, renewing and refinancing existing Shari’ah compliant financing. in this text
  • These criteria should include the type, nature and amount of credit exposures, including the terms and conditions and other contractual obligations under the Shari’ah compliant contract used that the bank may accept and in line with the approved-risk appetite, risk limits, risk bearing capacity as well as SAMA’s requirements on responsible lending. in this text
  • 7.3 Banks must have in place sound processes for managing credit risk in Shari’ah compliant financing contracts, including processes for: in this text
  • 7.3.1 continued monitoring of counterparty’s ability and willingness to repay under the terms of the financing, performance of the underlying assets; processes for classification of the performance of the credit exposures; in this text
  • 7.3.2 tracking, triggering and reporting credit exposures that require prompt action; in this text
  • 7.3.3 monitoring completeness of documentation, counterparty’s compliance with terms and conditions and other contractual requirements of the Shari’ah compliant contract, collateral and other forms of credit risk mitigation; in this text
  • 7.3.5 assessing and ensuring credit risk mitigating techniques used in each Shari’ah compliant financing are legally enforceable and compliant with Shari’ah rules and principles; in this text
  • 7.3.6 identifying problem credits on a timely basis and implementation of workout, restructuring, rescheduling, recovery, or other appropriate measures, and ensuring compliance with Shari’ah rules and principles. in this text
  • 8.9 Banks must ensure that their exposures to market risk are subject to internally pre-determined market risk limits. in this text
  • Banks must ensure that market risk exposures are reported to senior management when exposures are approaching or has breached pre-determined limits, and implement measures to bring the exposures to compliance as soon as practicable. in this text
Not carried over (35)
  • The process shall take into account appropriate steps to comply with Shari'ah rules and principles. in the old text
  • The Senior Management shall ensure that the financing and investment activities are within the approved appetite and risk tolerance limits. in the old text
  • The risk management function shall define the policies, establish procedures and monitor compliance with the established limits and report to the related committee of the Board and Senior Management on risk matters accordingly. in the old text
  • 4.10 The Bank shall ensure that an adequate system of controls with appropriate checks and balances is set in place. in the old text
  • The controls shall (a) comply with the Shari'ah rules and principles; (b) comply with applicable regulatory and internal policies and procedures; and (c) take into account the integrity of risk management processes. in the old text
  • 4.11 The Bank shall make appropriate and timely disclosure of information to depositors having deposits on Profit and Loss Sharing basis (also known as Profit-sharing Investment Accounts, PSIAs) so that they are able to assess the potential risks and rewards of their deposits and protect their own interests in their decision making process. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: i. Application of Emergency and Contingency Plan: The Senior Management shall draw up an emergency and contingency plan, approved by the Business Continuity Committee as required under the Business Continuity Management Framework issued by SAMA in February 2017 or the updated version a… in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: This requires having a structure in place to look at risk interrelationships across the Bank. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: Such a setup could be in the form of a separate department or Bank's Risk Management Committee could perform such a function. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: The structure should be such that ensures effective monitoring and control over risks being taken. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: iii. Risk Measurement: For each category of risk, the Bank is encouraged to establish systems/models that quantify its risk profile. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: iv. Utilization: The Bank should develop a mechanism which should, to the highest possible extent, monitor that funds provided by the depositors and investors were utilized for the purpose these were advanced. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: v. Role of Risk Administration Department: It should be separated from the department originating the risk. in the old text
  • 4.12 In addition to the above, the following general requirements shall also be taken into account by Banks: It should be among the responsibilities of Risk Administration Department to monitor that the documents are obtained according to the requirements as specified in the product. in the old text
  • Given that all the required measures are in place (e.g. pricing, valuation and income recognition frameworks, strong MIS for managing exposures etc.), the applicability of any market risk management framework that has been developed should be assessed taking into account of consequential business and reputation risks. in the old text
  • In addition, the unit should also prepare control reports indicating deviations for the information of senior management. in the old text
  • 6.4 Banks shall consider the full range of material operational risks affecting their operations, including the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. in the old text
  • Banks shall also incorporate possible causes of loss resulting from Shari'ah non-compliance and the failure in their fiduciary responsibilities. in the old text
  • 6.5 Principle 4.0: Banks shall ensure that the policies and related procedures shall be in place to measure, mitigate and monitor the Shari'ah non-compliance risk. in the old text
  • In this regard, the Bank must consider Shari'ah compliance as falling within a higher priority category in relation to other identified risks. in the old text
  • This means that Shari'ah compliance considerations are taken into account whenever the Banks accept deposits and investment funds, provide finance and carry out investment services for their customers. in the old text
  • 6.10 Banks shall undertake a Shari'ah compliance review at least annually, performed either by a separate Shari'ah audit department or as part of the existing internal audit function by persons having the required knowledge and expertise for the purpose. in the old text
  • The objective is to ensure that (a) the nature of the Banks' financing and equity investment and (b) the operations relating to all Shari'ah compliant and services are executed in adherence to the applicable Shari'ah rules and principles, policies and procedures approved by the Bank's Shari'ah Committee. in the old text
  • 6.11 Banks shall keep track of income not recognized arising out of Shari'ah non-compliance and assess the probability of similar cases arising in the future. in the old text
  • Based on historical reviews and potential areas of Shari'ah non-compliance, Banks may assess potential profits that cannot be recognized as eligible Banks' profits. in the old text
  • The Bank shall seek its Shari'ah Committee ruling and direction with regard to the appropriate cleansing and disposal of Non-*Shari'ah* Compliant income. in the old text
  • 6.12 Principle 5.0: Banks shall have in place appropriate mechanisms to safeguard the interests of all fund providers. in the old text
  • Where Profit & Loss Sharing depositors' funds are comingled with the Banks' own funds, Banks shall ensure that the bases for the asset, revenue, expenses and profit allocations are established, applied and reported in a manner consistent with the Banks' fiduciary responsibilities. in the old text
  • 6.14 Banks shall establish and implement a clear and formal policy for undertaking their different and potentially conflicting roles in respect to managing different types of investment accounts. in the old text
  • The policy relating to safeguarding the interests of their Profit & Loss Sharing deposit holders may include the following: i. Identification of investing activities that contribute to investment returns and taking reasonable steps to carry on those activities in accordance with the Banks' fiduciary and agency duties and to treat all their fund providers appropriately and in accordance with the t… in the old text
  • The policy relating to safeguarding the interests of their Profit & Loss Sharing deposit holders may include the following: ii. Allocation of assets and profits between Banks and their Profit and Loss Sharing deposit holders will be managed and applied appropriately to Profit & Loss Sharing deposit holders having funds invested over different investment periods; and in the old text
  • The policy relating to safeguarding the interests of their Profit & Loss Sharing deposit holders may include the following: iii. Limiting the risk transmission between current and investment accounts. in the old text
  • 6.15 A reliable IT system is necessary for profit & loss sharing mechanism, failure of which may lead to Shari'ah non-compliance risk. in the old text
  • The Bank should identify key risk indicators and should place key control activities like Code of Conduct, Delegation of authority, segregation of duties, succession planning, mandatory leave, staff compensation, recruitment and training, dealing with customers, compliant handling, record keeping, MIS, physical controls etc. in the old text
  • 6.16 Banks shall adequately disclose information on a timely basis to their Profit & Loss Sharing deposit holders and markets in order to provide a reliable basis for assessing their risk profiles and investment performance. in the old text

“Not carried over” means the sentence has no counterpart in this text; the rule can still be in force in another text.

Similar documents from other regulators

Source: Saudi Central Bank — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from SAMA

We email you every new SAMA publication the day it's published.

Topics
islamic-finance
capital
governance