2017-01-18 | Resolución SBS 272-2017Added
This resolution approves the Regulation of Corporate Governance and Comprehensive Risk Management, which applies to financial and insurance companies, private pension fund administrators, and other entities supervised by the Superintendence. The regulation establishes new criteria for corporate governance, including requirements for independent directors, board committees, remuneration systems, market conduct, and conflict of interest management. It mandates that companies with five or fewer directors must have at least one independent director, and those with six or more directors must have at least two. Additionally, it revises aspects of comprehensive risk management, such as the compliance function, and requires companies to adopt a Code of Ethics and Conduct.
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 Lima, January 18, 2017
S.B.S. Resolution No. 272 -2017 The Superintendent of Banking and Insurance and Private Pension Fund Administrators
WHEREAS: That, the Regulation of Comprehensive Risk Management, approved by SBS Resolution No. 37-2008 and its amending norms, hereinafter the Regulation, aims to establish that supervised companies included in articles 16° and 17° of the General Law of the Financial System and the Insurance System and Organic Law of the Superintendence of Banking and Insurance, Law No. 26702 and its amending laws, hereinafter General Law, as well as Private Pension Fund Administrators, and other entities subject to the supervision of this Control Body, have a comprehensive risk management appropriate to their nature, size and the complexity of their operations and services, within the framework of the provisions of current regulations; That, by SBS Resolution No. 11699-2008 and its amendments, the Internal Audit Regulation was approved; That, based on the provisions of Law No. 29903, SBS Resolution No. 6422-2015 regulated the appointment of independent directors by Private Pension Fund Administrators, the tasks they are responsible for performing, as well as their link with the corresponding disclosure procedures; That, based on supervision experience and international standards, it is necessary to modify current regulations to promote better risk management and corporate governance in companies under the supervision of the Superintendence; That, in this sense, it is necessary to develop and establish criteria related to corporate governance, such as those referring to independent directors, board committees, the remuneration system, market conduct, and the management of conflicts of interest; That, likewise, it is necessary to review aspects related to comprehensive risk management, such as the regulatory compliance function, in order to strengthen the performance and responsibility of companies;
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 That, in order to gather public opinions regarding the proposed modification of the regulations, the draft resolution was pre-published, under the provisions of Supreme Decree No. 001-2009-JUS; With the approval of the Deputy Superintendencies of Banking and Microfinance, Private Pension Fund Administrators, Insurance, Risks, Legal Advisory, Market Conduct and Financial Inclusion, and Economic Studies; and, In use of the powers conferred by numerals 7 and 9 of article 349° of the General Law, RESOLVES: Article First.- To approve the Regulation of Corporate Governance and Comprehensive Risk Management, which forms part of this Resolution: “REGULATION OF CORPORATE GOVERNANCE AND COMPREHENSIVE RISK MANAGEMENT INDEX Title I General Provisions Title II Corporate Governance Chapter I General Aspects Chapter II Company Governance Bodies Subchapter I Board of Directors Subchapter II Board Committees Subchapter III Management Chapter III Conflicts of Interest and Questionable Practices Chapter IV Remuneration System Chapter V 1 Evaluation of requirements and impediments of shareholders, directors, managers and principal officers Subchapter I General Provisions Subchapter II Requirements and Impediments Subchapter III Evaluation by the company Subchapter I Supervision by the Superintendence Title III Comprehensive Risk Management Chapter I General Aspects Chapter II Risk Unit Chapter III Regulatory Compliance Chapter IV Goods and/or services provided by third parties 2 1 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021 2 Substituted by SBS Resolution No. 504-2021 of 02/22/2021 effective from 07/01/2021.
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 Final and Complementary Provisions
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 REGULATION OF CORPORATE GOVERNANCE AND COMPREHENSIVE RISK MANAGEMENT TITLE I GENERAL PROVISIONS Article 1°.- Scope This Regulation applies to the companies indicated in articles 16° and 17° of the General Law, as well as to Private Pension Fund Administrators (AFPs). Likewise, it applies to Banco de la Nación, Banco Agropecuario, Corporación Financiera de Desarrollo (COFIDE), Fondo MIVIVIENDA S.A., Derramas and Cajas de Beneficios under the control of the Superintendence, the Peruvian Federation of Municipal Savings and Credit Banks (FEPCMAC) and the Fund of Municipal Savings and Credit Banks (FOCMAC). The provisions contained in the Regulation are applicable to the aforementioned entities, hereinafter companies, as long as they do not contravene the specific norms that regulate them. Article 2°.- Definitions and/or references For the application of the Regulation, the following definitions and/or references must be considered: a) Risk appetite.- the level of risk that the company is willing to assume within its risk capacity, to achieve its objectives. b) Ultimate Beneficiary.- in accordance with the Regulation for the acquisition of ownership in the share capital of supervised companies and significant owners, approved by SBS Resolution No. 6420-2015. c) Risk capacity.- the maximum level of risk that a company can assume given its current resources, regulatory requirements and contractual obligations. d) Parent Company.- legal entity or legal entity that exercises control over other legal entities or entities, and which may or may not correspond to a holding company. For this purpose, control is understood in accordance with the special rules on linkage and economic group, approved by SBS Resolution No. 5780-2015. e) Golden parachutes.- contractual agreements between a company and its employees and board members that prevent them from being dismissed if the ownership and/or control of the company passes to another group of shareholders; or, that assure them indemnities, regardless of their performance, if they are dismissed by the new shareholders. f) Market conduct.- practices of companies in their relationship with users, regarding the offer of financial products and services, information transparency and claims management. g) Conflict of interest.- a situation in which a person or governance body of the company faces different behavioral alternatives with incompatible interests due, among other causes, to the lack of alignment between their interests and those of the company. h) Internal control.- a process carried out by the board of directors, management and personnel, designed to provide reasonable assurance in achieving objectives related to the effectiveness and efficiency
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 of operations, reliability of financial information, and compliance with applicable laws and regulations. i) Days.- calendar days. j) Board of Directors.- all references to the board of directors also refer to any equivalent governance body. k) Independent Director.- is one who is selected for their professional prestige and economic independence and who has not had, in the last three (3) consecutive years prior to their appointment, any link with the company, its management, economic group or its principal shareholders, the latter being understood as those who own five percent (5%) or more of the company's shares. Linkage is defined in the special rules on linkage and economic group, approved by SBS Resolution No. 5780-2015. l) Event.- an event or series of events that may be internal or external to the company, originated by the same cause, occurring during the same period of time. 3 m) Corporate governance.- is the set of processes, policies, norms and practices that determine how a company or a group is directed, managed and controlled. n) Significant events.- those events that may have a significant impact on the financial situation of the company, or on the achievement of its objectives. o) Impact.- qualitative or quantitative measurement of the consequences of an event. It will usually be expressed in monetary terms, such as financial losses. p) General Meeting of Shareholders.- all references to the general meeting of shareholders or similar bodies. Its main powers are included in the General Law and in the General Law of Companies. q) General Law.- General Law of the Financial System and the Insurance System and Organic Law of the Superintendence of Banking and Insurance, Law No. 26702 and its amending norms. r) General Law of Companies.- Law No. 26887 and its amending norms. s) Risk limits.- is the maximum level of risk, based on appetite, preferably expressed in quantitative measures by business lines, types of risk, concentrations, or others appropriate to the complexity of the company's operations and services and the sector to which it belongs. t) Risk management manuals.- documents containing the functions, responsibilities, policies, methodologies and procedures arranged for the identification, evaluation, treatment, control, reporting and monitoring of company risks. u) Organization and functions manuals.- documents detailing the organic structure of companies, the objectives and functions of their units, as well as the obligations and responsibilities of their personnel. v) Policy and procedure manuals.- documents containing responsibilities, policies, methodologies and procedures established by companies for carrying out the activities of each of their units, including those corresponding to risk management. w) New product.- product launched for the first time by the company or a change in an existing product that significantly modifies its risk profile. x) Operations with related parties.- in accordance with the definition established in the special rules on linkage and economic group, approved by SBS Resolution No. 5780-2015. 3 Literal modified by SBS Resolution No. 877-2020 of 02/26/2020 effective from 01/01/2022
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 y) Principal officers.- those included in the Complementary Rules for the election of Directors, Managers and Internal Auditors, approved by SBS Resolution No. 1913-2004, in accordance with the provisions of SBS Circular No. G-0119-2004 4, Rules for the Registration of Directors, Managers and Principal Officers – REDIR. z) Process.- set of organized and repeatable activities, tasks and procedures that produce an expected result. aa) Products.- Operations and/or services provided by the company to its clients and users. 5 bb) Regulation.- Regulation of Corporate Governance and Comprehensive Risk Management. cc) Remuneration.- comprises all forms of benefits paid, payable or provided by the company, or on its behalf, in exchange for services rendered to the company. This remuneration may include monetary or non-monetary benefits. dd) Fixed Remuneration.- that remuneration that the worker receives periodically, weekly, biweekly or monthly, being fixed insofar as its amount and payment period are regular. ee) Variable Remuneration.- is all remuneration other than fixed remuneration. ff) Risk.- the possibility of events occurring that negatively impact the company's objectives or its financial situation. gg) Reasonable assurance.- refers to the level of certainty that a company can have regarding the achievement of its objectives, considering that it is always possible for significant events to occur that are not prevented or detected in a timely manner, given the inherent uncertainty of the future. hh) Risk appetite system.- set of policies, limits, processes, procedures, roles and responsibilities through which risk appetite is established, communicated and monitored. ii) Remuneration system.- set of policies, strategies, procedures and resources used by the company for granting remunerations, which include evaluation criteria, payment periodicity, forms of payment, among others. jj) Subcontracting.- modality by which a company contracts a provider to deliver goods and/or services that could be developed by it. 6 kk) Superintendence.- Superintendence of Banking, Insurance and Private Pension Fund Administrators. ll) User.- natural or legal person who uses or may use the products offered by companies. mm) Authorization Regulation: Regulation for the authorization of companies and representatives of the Financial and Insurance Systems, approved by SBS Resolution No. 211-2021. 7 nn) Moral suitability: In accordance with the definition established in subsection o) of article 2 of the Authorization Regulation. 8 oo) Technical suitability: In accordance with the definition established in subsection p) of article 2 of the Authorization Regulation. Includes the effective performance of the person in the function for which they have been appointed. 9 4 Circular repealed by Circular 213-2021 from November 1, 2021 5 Literal modified by SBS Resolution No. 877-2020 of 02/26/2020 effective from 01/01/2022 6 Modified by SBS Resolution No. 504-2021 of 02/22/2021 effective from 07/01/2021. 7 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021 8 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 pp) Economic solvency: In accordance with the definition established in subsection z) of article 2 of the Authorization Regulation. 10 qq) SPP Law Regulation: Regulation of the Consolidated Text of the Private Pension System Law, approved by Supreme Decree No. 054-97-EF and its amending norms. 11 rr) Provider: third party contracted to provide goods and/or services to a company, including under the subcontracting modality. Companies that are part of the same economic group as the contracting company are also considered as third parties. 12 TITLE II CORPORATE GOVERNANCE CHAPTER I GENERAL ASPECTS Article 3°.- Corporate governance Companies must define general principles and guidelines for the adoption and implementation of corporate governance practices that serve as a guide for the actions of the company's governance bodies. The corporate governance structure specifies the distribution of rights and responsibilities among the different governance bodies and interest groups. Corporate governance also provides the structure through which the company's objectives are established, the means to achieve these objectives, as well as how to monitor its performance. The board of directors and management must reasonably ensure the adoption of best practices related to corporate governance. Companies must have a corporate governance framework that considers, at a minimum, the following guidelines: a) The corporate structure and organization consistent with the nature and size of the company, with the group to which it belongs, and with the complexity of its operations and services. b) The moral suitability and economic solvency of the shareholders and ultimate beneficiaries of the company. 9 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021 10 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021 11 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021 12 Incorporated by SBS Resolution No. 504-2021 of 02/22/2021 effective from 07/01/2021.
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 c) The technical and moral suitability of the directors, managers and principal officers of the company; as well as their qualifications and skills for reasonable and impartial decision-making in business, risk management and control. d) The corporate culture and values, as well as the professional responsibility criteria required of directors, managers, officers and other employees. e) The mechanisms for effective monitoring and control of management by the board of directors; as well as the responsibilities of the board of directors and management to the company, shareholders and the company's interest groups. f) The company's mechanisms for objective, integral and independent management of conflicts of interest. g) General remuneration policies aligned with the company's long-term objectives, as well as prudent risk assumption. h) The framework for comprehensive risk management faced by the company, consistent with the nature, size and complexity of its operations and services. i) Solid internal control; as well as effective performance of internal audit and regulatory compliance functions. j) The establishment of equitable treatment for all shareholders, including minority and foreign shareholders, prohibiting any type of action that could hinder the exercise of their rights. k) Information disclosure policies, mainly those referring to the financial situation, ownership, and governance of the entity. l) General policies to incorporate adequate market conduct into the organizational culture and business strategy. Additionally, companies must have a Code of Ethics and Conduct, with the professional responsibility criteria required of their directors, managers, officers and other employees, and which expressly prohibits illegal activities or conduct that could affect the company's reputation or trust in the system. CHAPTER II COMPANY GOVERNANCE BODIES SUBCHAPTER I BOARD OF DIRECTORS Article 4°.- Composition of the board of directors 13 The board of directors is composed of a number of members sufficient for effective and participatory performance, and that allows for the formation of the board committees established by the Regulation. It is composed of people with specialties and competencies that facilitate a plurality of approaches and opinions, and who have skills and knowledge, such that, as a whole, they ensure a reasonable understanding of the activity carried out by the company, the market and the regulatory environment, in order to fulfill their functions. The number of directors is contained in the bylaws, in accordance with the General Law, the General Law of Companies and the specific norms applicable to each company. The names of the directors, their status as independent or not, must be shown in the regulatory reports required by the Superintendence, in addition to being published in the company's annual report. Article 5°.- Board of Directors Regulation The board of directors must approve the regulation that will contain the policies and guidelines necessary for the fulfillment of its functions, unless the bylaws reserve that power to the general meeting of shareholders. This document will be available to the Superintendence and must contain, at a minimum, the following: a) The functions and responsibilities of the chairman of the board and its members. b) Guidelines for the development of work plans by board members that contribute to the performance of the functions of this governance body. c) Policies and procedures to prevent, detect, manage and disclose conflicts of interest of directors. d) Board succession plan that must contain, at a minimum: i) the causes of vacancy established in the General Law of Companies or those additional ones established in the bylaws; ii) the criteria and procedure for the removal of the director and the appointment of the replacement; and iii) the policy and procedure for communicating the vacancy, removal and/or election to the Superintendence, in accordance with the provisions of the General Law. e) Policies and procedure for informing the board of directors about communications from the Superintendence. f) Procedure for granting leaves of absence to directors, as well as the attendance of the alternate or substitute director. g) Criteria for technical and moral suitability for the selection of management staff. h) If the company's bylaws allow it, policies and guidelines for holding non-presential board meetings through communication means that allow the adoption of agreements and guarantee their authenticity. i) If the board has agreed to a self-evaluation of its performance, the criteria used for said self-evaluation. Article 6°.- Independent director The board of directors of companies must have independent directors. As long as it does not contravene their specific norms, companies must have at least one (1) independent director if they have five (5) or fewer directors, or two (2) independent directors if they have six (6) or more directors. The alternate or substitute director elected for an independent director must comply with the requirements to hold said position, indicated in literal k) of article 2 and this article. The independent director of a company may be an independent director of other companies in its economic group.
13 Modified by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021
Los Laureles No. 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 The independent director holds said position in the company for a maximum period of ten (10) years counted from their first appointment. Each independent director must sign a declaration of compliance with the requirements established in literal k) of Article 2 of the Regulation and in this article, at the time of assuming their position and after each year of permanence in it. Article 7.- General Responsibilities of the Board of Directors The directors are responsible for: a) Establishing the main objectives and goals of the company and approving its strategy. b) Establishing an adequate system for delegation of powers, segregation of duties, and treatment of potential conflicts of interest throughout the company. c) Approving the organization and functions manuals, policy and procedure manuals, and other manuals and internal regulations of the company. d) Selecting a management team with technical and moral suitability, that acts in accordance with the development of the company's businesses and operations, as well as evaluating their performance. e) Approving and overseeing the design and implementation of the remuneration system, and ensuring that it is aligned with the company's business strategy, its risk appetite, its policies, and financial soundness. f) Approving the company's risk appetite system. g) Establishing risk management in accordance with the nature, size, and complexity of the company's operations and services, taking into account the competitive environment, the macroeconomic environment affecting the markets in which the company operates, regulatory requirements, and its long-term objectives. h) Arranging the necessary measures for the company to operate in line with its risk appetite, for which it must know the capital and liquidity needs associated with its strategy. i) Establishing the necessary policies and measures for the company to have appropriate market conduct in its business strategy. j) Approving succession plans for management. k) Establishing the company's corporate culture and values, as well as professional responsibility criteria. l) Approving roles and responsibilities of management, risk management, internal control, and regulatory compliance. Article 8.- Board of Directors' Declaration of Compliance The board of directors is responsible for evaluating compliance with the provisions established in the Regulation. Annually, the board of directors shall sign a declaration of compliance, which must contain, at a minimum, the following: a) That the board of directors is aware of the standards provided in the Regulation, as well as its responsibilities. b) That the company complies with the principles and guidelines established in corporate governance matters. c) That the board of directors understands the nature and level of risk assumed by the company. d) That the company has risk management consistent with the nature, size, and complexity of its operations and services; which complies, at a minimum, with the criteria indicated in the Regulation, with the exception of possible deficiencies identified and communicated in the declaration.
Los Laureles No. 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 e) That the board of directors has required management that the policies, processes, and controls executed by management, including adequate risk management, are consistent with the company's strategy, as well as with risk appetite levels and limits. f) That the board of directors has taken note of the information from management, the agreements and reports of the audit committee, the risk committee, the remuneration committee, internal audit, external audit, the compliance officer, the regulatory compliance officer, the user service officer, and any other information that the board of directors deems relevant, as well as any corrective measures that have been ordered, which must be recorded in the corresponding minutes. g) That the board of directors has established all necessary mechanisms so that if non-presential sessions are held, this does not affect or limit the proper fulfillment of its functions and responsibilities. This declaration shall be signed within a period not exceeding one hundred and twenty (120) days after the close of the annual fiscal year, and must be available to the Superintendency. In case the board of directors has identified deficiencies in accordance with literal d), it must send the declaration to the Superintendency within five (5) business days of signing it, including corrective actions and implementation deadlines. SUBCHAPTER II BOARD COMMITTEES Article 9.- Board Committees The board of directors may constitute the committees it deems necessary to comply with the provisions contained in the Regulation. For multiple operations companies and insurance companies referred to in Article 16 of the General Law, the Banco de la Nación, the Banco Agropecuario, COFIDE, Fondo MIVIVIENDA S.A., as well as for AFPs, the constitution of an audit committee, a risk committee, and a remuneration committee shall be mandatory. In the case of those companies that are not obliged to constitute the committees and, furthermore, decide not to do so, all functions shall be assumed by the board of directors. The Superintendency may require the constitution of other committees when it deems it convenient through a general rule. Article 10.- Committee Regulations The committees constituted by the board of directors must have regulations that will contain the necessary policies and procedures for the fulfillment of their functions. Said regulations shall establish, at a minimum, criteria to avoid conflicts of interest and incompatibility of functions, policies for the rotation of their members, the periodicity of their meetings, programming their activities, submitting information, and reporting to the board of directors at its next session the main topics discussed and agreements adopted in the committee sessions in order to monitor their compliance. The agreements adopted in the committee sessions must be recorded in a book, on loose-leaf pages, or in another form permitted by the General Corporations Law, which shall be available to the Superintendency.
Los Laureles No. 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 Article 11.- Composition of the Risk Committee The risk committee must be composed of at least three (3) members, one of whom must be a board member who does not hold an executive position in the company, who shall chair it and may not chair any other committee with which there is a conflict of interest. The risk committee must be organized as an integral committee, which must cover decisions concerning the significant risks to which the company is exposed. The members of the risk committee must have the necessary knowledge and experience to adequately fulfill their functions. The board of directors may create specialized risk committees as it deems necessary, due to the nature, size, and complexity of the company's operations and services. The Superintendency may request companies to create specialized risk committees if it deems it necessary. Article 12.- Functions of the Risk Committee The risk committee, by delegation of the board of directors and within the limits it sets, may assume the following functions: a) Approving the policies and organization for comprehensive risk management in accordance with the nature, size, and complexity of the company's operations and services. b) Proposing the risk limits that the company is willing to assume in business development. c) Deciding on the necessary actions for the implementation of required corrective measures, in case there are deviations with respect to risk appetite levels and limits and assumed exposure degrees. d) Approving the taking of exposures that involve significant variations in the company's risk profile or of the assets managed under the company's responsibility. e) Evaluating the company's capital and liquidity sufficiency to face its risks and alerting to possible insufficiencies. f) Proposing improvements in comprehensive risk management. g) Approving reports on risks associated with new products and proposed or implemented treatment measures, prior to their launch; including market conduct aspects. h) Approving reports on risks associated with significant changes in the business, operational, or IT environment, prior to their execution; as well as proposed or implemented treatment measures. Article 13.- Composition of the Audit Committee The audit committee must be composed of at least three (3) board members who do not hold an executive position in the company. The members of the audit committee must have the necessary knowledge and experience to adequately fulfill their functions. For multiple operations companies and insurance companies referred to in Article 16 of the General Law, as well as for AFPs, the audit committee must be composed of at least one independent director, who shall chair it and may not chair any other committee. Article 14.- Functions of the Audit Committee
Los Laureles No. 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 The audit committee's main purpose is to ensure that accounting and financial reporting processes are appropriate, as well as to evaluate the activities carried out by internal and external auditors. Among its main functions are: a) Overseeing the proper functioning of internal control. b) Informing the board of directors about the existence of limitations in the reliability of accounting and financial processes. c) Overseeing and keeping the board of directors informed about compliance with internal policies and procedures and about the detection of internal control and administration problems, as well as corrective measures implemented based on evaluations carried out by the internal audit unit, external auditors, and the Superintendency. d) In accordance with the policies and procedures approved by the board of directors or general shareholders' meeting, defining the criteria for the selection and hiring of external auditors, evaluating their performance, as well as determining the complementary reports they require for the better performance of their functions or compliance with legal requirements, except in those cases where the audit committee of the parent company defines the criteria for the selection, hiring, and evaluation of external auditors. e) Defining the criteria for the selection and hiring of the internal auditor and their main collaborators, and evaluating their performance. Article 15.- Composition of the Remuneration Committee The remuneration committee must be composed of at least three (3) members, one of whom must be a board member who does not hold an executive position in the company. The members of the remuneration committee must have the necessary knowledge and experience in business management and the risks to which the company is exposed to adequately fulfill their functions. Article 16.- Functions of the Remuneration Committee The remuneration committee, by delegation of the board of directors and within the limits it sets, may assume the following functions: a) Proposing to the board of directors the remuneration system and its modifications, in accordance with the provisions of Chapter IV of this Title. b) Analyzing proposals for modification of the remuneration system and appointing the personnel responsible for verifying compliance with the application of this system. c) Evaluating potential conflicts of interest in the remuneration system and proposing resolution measures. d) Defining the goals and indicators considered in the remuneration system, in accordance with the provisions of Chapter IV of this Title. SUBCHAPTER III MANAGEMENT Article 17.- Management and its Responsibilities Management must have the necessary academic background, experience, and integrity for the fulfillment of its functions. Management includes the general manager or equivalent (who leads it) and first-level managers, i.e., those direct collaborators of the general manager in the execution of the board of directors' policies and decisions. Management may constitute committees for the fulfillment of its responsibilities. Managers may be removed by the board of directors or by the general shareholders' meeting, regardless of the body from which their appointment originated. Management is responsible for: a) Ensuring that the company's activities are consistent with the business strategy, the risk appetite system, corporate culture and values, appropriate market conduct, and policies approved by the board of directors; as well as periodically informing the board of directors of the results of such assurance. b) Implementing comprehensive risk management in accordance with the board of directors' provisions. c) Informing the board of directors regarding new products and, in general, about relevant management initiatives (changes in systems, processes, business models, substantial investments, etc.), that may have a material impact on the company's risk profile. d) Informing the board of directors, at least quarterly, about the company's economic performance. e) Informing the board of directors about operations with related parties. f) Delegating functions to company personnel and ensuring their compliance. g) Implementing the necessary measures for the company to have appropriate market conduct. h) The veracity of the information provided to the board of directors and the general shareholders' meeting. The managers of organizational units, within their scope of action, are responsible for managing risks related to achieving their units' objectives. Among their specific responsibilities are: a) Ensuring consistency between operations, the defined risk appetite system, and established market conduct policies, applicable to their scope of action. b) Assuming, before the immediate superior manager, the results of the risk management corresponding to their unit; and so on up to the manager who has this responsibility before the board of directors. CHAPTER III CONFLICTS OF INTEREST AND QUESTIONABLE PRACTICES Article 18.- Policies on Conflicts of Interest Companies must identify potential conflicts of interest that arise within the company's own governance and management bodies. Likewise, they must implement policies and procedures for their treatment, monitoring, and control. Article 19.- Questionable Practices Companies must establish appropriate internal systems that facilitate the timely reporting and investigation of unauthorized, illicit, fraudulent activities, and other questionable practices defined by the company, identified by any employee or by any person interacting with it. Such activities must be reported to the internal audit unit or organizational unit responsible for their management, for which the company must implement procedures that allow maintaining the confidentiality of the whistleblower. In the case of significant events, the internal audit unit, under its responsibility, must communicate to this Superintendency, in accordance with the provisions of the Internal Audit Regulation. CHAPTER IV REMUNERATION SYSTEM Article 20.- Design of the Remuneration System Companies must have a remuneration system for their employees and board members, consistent with their business strategy and policies, and that avoids potential conflicts of interest. This system must correspond to the nature, size, and complexity of the company's operations and services. The remuneration system must include policies and procedures that define the criteria and indicators for determining the variable remuneration of company employees and board members, if applicable. Such criteria and indicators must be consistent with the specific objectives of their functions, the frequency, and method of payment. Employees and board members must have access to these policies. Article 21.- Link to Company Performance The criteria used for calculating the variable remuneration of employees and board members must take into account the company's overall performance and long-term management. The associated time horizon must consider the inherent risks of the company's operations. The remuneration system must define the assumptions under which the application of golden parachute clauses and agreements guaranteeing the payment of variable remuneration, if applicable, is disabled. These criteria must be included in the contracts signed by the company with its employees and in the document of acceptance of office by board members. CHAPTER V 14 EVALUATION OF REQUIREMENTS AND IMPEDIMENTS FOR SHAREHOLDERS, DIRECTORS, MANAGERS, AND PRINCIPAL OFFICERS SUBCHAPTER I GENERAL PROVISIONS Article 21-A.- Evaluation of Requirements and Impediments 14 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021 Companies must implement policies and procedures for compliance with the requirements of moral suitability, technical suitability, and economic solvency of their shareholders, ultimate beneficial owners, directors, managers, and principal officers, as applicable, as well as their non-incurrence in the impediments established in the Law. Said policies and procedures must allow companies to monitor compliance with the foregoing paragraph for an updated evaluation of information on requirements and impediments and for the adoption of corresponding decisions when non-compliance is identified or presumed. Article 21-B.- Responsibilities of the Board of Directors The board of directors is responsible for: a) Approving policies, manuals, and procedures for the evaluation and monitoring of compliance with the requirements of moral suitability, technical suitability, and economic solvency, and of the non-incurrence in the impediments established in the Law, of its shareholders, ultimate beneficial owners, directors, managers, and principal officers, as applicable. b) Approving and overseeing the implementation and operation of the system for the evaluation and monitoring of compliance with the requirements of moral suitability, technical suitability, and economic solvency, and of the non-incurrence in the impediments established in the Law, of its shareholders, ultimate beneficial owners, directors, managers, and principal officers, as applicable. c) Implementing corrective actions in those cases where, as a result of the evaluation of the moral suitability, technical suitability, and economic solvency of shareholders, ultimate beneficial owners, directors, managers, and principal officers, as applicable, it is determined that they may negatively affect the company. SUBCHAPTER II REQUIREMENTS AND IMPEDIMENTS Article 21-C.- Requirements and Impediments for Shareholders Shareholders and their ultimate beneficial owners must permanently comply with the requirements of moral suitability and economic solvency, and not incur in the impediments established in Articles 20, 52, 53, 54, and 55 of the General Law and Article 5 of the Regulation of the Consolidated Text of the Private Pension System Law, as applicable. Article 21-D.- Requirements and Impediments for Directors Company directors must permanently comply with the requirements of technical and moral suitability, and must not be subject to the impediments provided in Article 81 of the General Law and Article 25 of the Regulation of the Consolidated Text of the Private Pension System Law, as applicable, as well as in other cases established in special norms regarding this matter. Directors of Municipal Savings and Credit Banks must additionally comply with the requirements established in the Regulation for the election of representatives to the board of directors of Municipal Savings and Credit Banks, approved by SBS Resolution No. 5788-2015.
Los Laureles No. 214 - Lima 27 - Peru Tel.: (511)6309000 Fax: (511) 6309239 In the case of independent directors, in addition to the provisions of the preceding paragraphs, they must comply with the requirements established in subsection k) of Article 2 and Article 6 of these Regulations, as well as with the provisions contained in Title III of the Compendium of Superintendency Regulatory Standards of the Private Pension Fund Administration System, approved by Resolution No. 053-98-EF/SAFP and its amending regulations. Article 21-E.- Requirements and impediments for managers and principal officers Managers and principal officers must permanently comply with the requirements of technical and moral suitability, in addition to the provisions established in Article 92 of the General Law and 32 of the Regulations of the Consolidated Text of the Private Pension System Law, in accordance with Article 6 of Law No. 27328, Law that incorporates Private Pension Fund Administrators under the control and supervision of the Superintendency of Banking and Insurance, as applicable. SUBCHAPTER III EVALUATION BY THE COMPANY Article 21-F.- Evaluation report of new shareholders The evaluation of the moral suitability and economic solvency requirements of potential shareholders, as well as their non-incurrence in the impediments established in the General Law and in the Regulations of the Consolidated Text of the Private Pension System Law indicated in Article 21-C, is carried out in accordance with the provisions established in the General Law and the Authorization Regulations. In the case of potential significant owners and ultimate beneficiaries seeking to acquire ownership of more than ten percent (10%) of the company's share capital directly or through third parties, the evaluation mentioned in the preceding paragraph is carried out by the Superintendency and is governed, in addition to the rules indicated in the preceding paragraph, by the Regulations for the acquisition of ownership in the share capital of supervised companies and significant owners, approved by SBS Resolution No. 6420-2015. For the acquisition of a percentage less than ten percent (10%) of the company's share capital directly or through third parties, the company must submit to the Superintendency an evaluation report on compliance with the moral suitability and economic solvency requirements, as well as non-incurrence in impediments, within the first ten (10) business days of the month following the acquisition. In the case of the acquisition of shares registered in the Public Registry of the Securities Market, through centralized negotiation mechanisms, the company must submit to the Superintendency an evaluation report on compliance with the requirements and non-incurrence in impediments, when the acquired participation, directly or indirectly, is greater than three percent (3%) of the company's share capital and is maintained for a period longer than thirty (30) days, within the first ten (10) business days of the following month. Companies must prepare the evaluation reports indicated in the preceding paragraphs, in accordance with the policies, manuals, and procedures approved by the board of directors. In the aforementioned cases where there is an obligation to submit a report to the Superintendency and provided that the acquired participation, directly or indirectly, is greater than three percent (3%) of the companies' share capital, they must attach to said report, through the means provided by the Superintendency: a) Annex III of the Authorization Regulations, in the case of natural person shareholders, or the last 2 financial statements, considering the provisions of numeral iv of subsection c of paragraph 6.2 of Article 6 of the Authorization Regulations, in the case of legal entities, and b) Annex I of the Authorization Regulations Article 21-G.- Evaluation report of new directors, managers, and principal officers Prior to the election of new directors, as well as the designation and/or appointment of new managers and principal officers, the company must carry out an evaluation of compliance with the requirements and non-incurrence in impediments in accordance with the provisions established in the General Law and the Authorization Regulations. The company must submit to the Superintendency an evaluation report on compliance with the aforementioned requirements and non-incurrence in impediments, within a period not exceeding five (5) business days after the election of the director, or designation and/or appointment of managers and principal officers. Companies must prepare the evaluation reports indicated in the preceding paragraphs, in accordance with the policies, manuals, and procedures approved by the board of directors. Companies must attach Annexes I and II of the Authorization Regulations to said report through the means provided by the Superintendency. Article 21-H.- Evaluation reports Companies must have evaluation reports for shareholders, ultimate beneficiaries, directors, managers, and principal officers; these must be prepared in accordance with the policies, manuals, and procedures approved by the board of directors and must be kept updated and available to the Superintendency. Article 21-I.- Communication of facts to the Board of Directors and the Superintendency Companies must establish in their internal procedures and policies that they must inform the board of directors and the Superintendency of the occurrence of any event that could presumably negatively affect the moral suitability, technical suitability, or economic solvency of shareholders, ultimate beneficiaries, directors, managers, and principal officers, as applicable. Notification to the Superintendency must be made within five (5) business days of becoming aware of the event. SUBCHAPTER IV SUPERVISION BY THE SUPERINTENDENCY Article 21-J.- Supervision The Superintendency supervises compliance with the provisions of the Law and these Regulations, making use of the powers assigned by current regulations. For these purposes, the Superintendency may require the following information: a) The supporting documents that allow accreditation of the evaluation carried out by the company. b) Information on shareholders, ultimate beneficiaries, directors, managers, and principal officers, in accordance with the questionnaires of the Authorization Regulations, which may be requested directly or through the company. c) Documentation signed by shareholders, ultimate beneficiaries, directors, managers, and principal officers. d) Documentary and other supporting evidence that allows accreditation of the veracity of the information in the sworn declarations. Article 21-K.- Nature of sworn declaration All information provided to the Superintendency by the company has the nature of a sworn declaration. Article 21-L.- Meetings with the Superintendency The Superintendency may convene, when deemed appropriate, shareholders, directors, managers, and principal officers for meetings related to compliance with the requirements defined in the Authorization Regulations. Article 21-M.- Evaluation by the Superintendency The Superintendency analyzes the information received from companies and that which may be obtained from other sources and, taking into account the impact that the evaluated criteria may have on the trust, reputation, and integrity of the supervised systems, determines cases of non-compliance with the requirements of moral suitability, technical suitability, or economic solvency, as well as the incurrence in any of the impediments of the law, and communicates this to the company and/or the evaluated person. The evaluation of the requirements and non-incurrence in impediments is carried out in accordance with the provisions established in the General Law and the Authorization Regulations. If the Superintendency determines that a shareholder, ultimate beneficiary, director, manager, or principal officer fails to comply with any requirement or is subject to any of the impediments of the law, it communicates this to the company, so that the board of directors, within a maximum period of fifteen (15) business days from the date of receipt of the Superintendency's communication, reports on the implementation of corrective actions applied to the shareholder, ultimate beneficiary, director, manager, or principal officer, as applicable. The Superintendency may require the application of the measures established in Article 59 and literal b) of subsection 1 of Article 381 of the General Law, as well as the last paragraph of Article 13-A of the Consolidated Text of the Private Pension System Law. Article 21-N.- Infractions and sanctions The Superintendency establishes the classification of infractions and sanctions applicable to non-compliance with the provisions contained in these Regulations and initiates a sanctioning procedure, when applicable. TITLE III COMPREHENSIVE RISK MANAGEMENT CHAPTER I Los Laureles No. 214 - Lima 27 - Peru Tel.: (511)6309000 Fax: (511) 6309239 GENERAL ASPECTS Article 22.- Comprehensive Risk Management Comprehensive Risk Management is a process carried out by the board of directors, management, and personnel applied to the entire company and in the definition of its strategy, designed to identify potential events that may affect it, manage them according to its risk appetite, and provide reasonable assurance in achieving its objectives. Comprehensive Risk Management includes the entire company, its business lines, processes, and organizational units, across all its relevant risks. Companies must design and apply comprehensive risk management, appropriate to their nature, size, and the complexity of their operations and services, as well as to the macroeconomic environment affecting the markets in which the company operates. Companies must have a risk management framework that adapts to their organization and needs, which must consider the elements described below, which may be regrouped in the manner deemed most appropriate to the particular characteristics of the company and its methodology: a) Internal environment.- which includes, among others, corporate culture and values, the technical and moral suitability of its officers; the organizational structure; and the conditions for delegation of powers and assignment of responsibilities. b) Objective setting.- process by which objectives are determined, which must be in accordance with the risk appetite and within its risk capacity. c) Risk identification.- process by which internal and external risks are identified, and which considers, as appropriate, possible associated events and scenarios. d) Risk assessment.- process by which the risk of a company, business line, portfolio, or product is evaluated; using qualitative or quantitative techniques. e) Risk response.- process by which one chooses to accept the risk, decrease the probability of occurrence, decrease the impact, transfer it totally or partially, avoid it, or a combination of the above measures, in accordance with the defined risk appetite level and limits. f) Control.- process that seeks to ensure that risk response measures are met as planned. g) Information and communication.- process by which the board of directors, management, risk committee, and other involved parties are informed, as appropriate. h) Monitoring.- process consisting of the periodic evaluation of the proper functioning of comprehensive risk management. Article 23.- Types of risks Risks can arise from various sources, internal or external, and can be grouped into various categories or types. Below is a non-exhaustive list of the various types of risks to which a company is exposed: a) Credit risk The possibility of losses due to the inability or unwillingness of debtors, issuers, counterparties, or third parties obligated to fulfill their contractual obligations. b) Money laundering and terrorist financing risks The possibility that the company may be used for money laundering and terrorist financing purposes. This definition excludes reputational risk and operational risk. c) Liquidity risk The possibility of losses due to the early or forced sale of assets at unusual discounts to meet obligations, as well as the inability to quickly close open positions or cover positions in sufficient quantity and at a reasonable price. d) Market risk The possibility of losses arising from fluctuations in interest rates, exchange rates, prices of equity instruments, and other market prices, which affect the valuation of positions in financial instruments. e) Reputational risk The possibility of losses due to a decrease in confidence in the integrity of the institution that arises when the good name of the company is affected. Reputational risk can arise from other inherent risks in an organization's activities. f) Technical risk 15 The possibility of losses or adverse modification of the value of commitments undertaken under insurance, reinsurance, and co-insurance contracts. In the case of non-life insurance, fluctuations related to the frequency, severity, and settlement of claims are considered. For life insurance, this may include the possibility of losses due to variations in the level, trend, or volatility of mortality rates, longevity, disability, morbidity, renewal, or surrender of insurance contracts, among other parameters and assumptions, as well as the execution costs of such obligations. This definition includes underwriting risk. g) Reinsurance risk 16 The possibility of losses in case of insufficient reinsurance coverage contracted by the ceding insurance company, when reinsurance needs were not adequately identified, determined, or specified in the contracts; or when the reinsurer is unable to fulfill its payment commitments, or is unwilling to pay them due to discrepancies in the application of the conditions of the insurance and/or reinsurance contract; as well as delays in payments by the reinsurer that may affect the ceding company's cash flows, generating liquidity risk. It also includes risks assumed by the company when participating as a reinsurer in accepted reinsurance operations. h) Strategic risk The possibility of losses due to high-level decisions associated with the creation of sustainable competitive advantages. It is related to failures or weaknesses in market analysis, environmental trends and uncertainty, key company competencies, and the process of value generation and innovation. i) Operational risk The possibility of losses due to inadequate processes, personnel failures, information technology failures, or external events. This definition includes legal risk but excludes strategic and reputational risk. CHAPTER II Los Laureles No. 214 - Lima 27 - Peru Tel.: (511)6309000 Fax: (511) 6309239 15 Subsection modified by SBS Resolution No. 1660-2025 of 05/06/2025, effective from 05/10/2025. 16 Subsection modified by SBS Resolution No. 4706-2017 of 12/06/2017 RISK UNIT Article 24.- Risk unit Comprehensive risk management requires companies to organize themselves according to their complexity and business lines in which they operate. In this regard, companies must have a centralized unit or specialized units for specific risk management, in accordance with the nature, size, complexity of the company's operations and services, provided that, when taken as a whole, they allow the implementation of the criteria provided in the Regulations. The Superintendency may require the creation of a comprehensive risk unit in companies that it deems complex, and when it is observed during supervisory actions that the criteria provided in current regulations are not met. Likewise, the Superintendency may require companies to create specialized risk units, if deemed necessary. The members of the risk unit must possess the experience and knowledge that allow them to properly fulfill their functions, for which a training plan must be established and presented to the board of directors annually. Companies included in Article 17 of the General Law, Derramas and Benefit Funds under the control of the Superintendency, as well as FEPCMAC and FOCMAC may assign the functions of the risk unit to management, unless the Superintendency requires such a unit. Article 25.- Functions of the risk unit The risk unit is responsible for supporting and assisting the other units of the company in carrying out good risk management in their areas of responsibility, and for this purpose, it must be independent of the business units. The functions of the risk unit are: a) Propose appropriate policies, procedures, and methodologies for comprehensive risk management in the company, including roles and responsibilities. b) Participate in the design and continuous improvement and adaptation of risk management manuals. c) Ensure adequate comprehensive risk management, promoting the alignment of the company's decision-making with the risk appetite system. d) Guide the integration between risk management, business plans, and business management activities. e) Establish a common risk management language based on the definitions of this standard and other applicable regulations. f) Estimate the capital needs to cover the risks faced by the company and alert management and the risk committee or board of directors, as the case may be, about possible effective capital shortfalls. g) Inform management and the risk committee or board of directors, as the case may be, about relevant aspects of risk management for timely decision-making. h) Inform the risk committee or board of directors, as the case may be, about the risks associated with the launch of new products, and significant changes in the business environment, operational or IT environment, prior to their launch or execution; as well as proposed or implemented treatment measures. Article 26.- Head of the risk unit The head of the risk unit must have academic training and experience associated with the fulfillment of their functions, and must permanently coordinate with management, the risk committee, the audit committee, specialized committees, business units, and support units, regarding the comprehensive risk management carried out by the company. The head of the risk unit must have a managerial level and report directly to the board of directors or to management or to the company's risk committee, as the case may be. In addition, they are responsible for informing the board of directors, the respective committees, and the corresponding decision-making areas about risks, assumed exposure levels, and their management, in accordance with the policies and procedures established by the company. The foregoing is equally applicable to the heads of specialized risk units, in case there is no centralized risk unit. Article 27.- Annual Risk Report The risk unit must prepare an annual risk report at the end of each fiscal year, which must include the activity plan for the following fiscal year. The said report must be submitted to the Superintendency within ninety (90) days after the close of each year. Through a multiple official letter, the Superintendency may define the minimum structure of the annual risk report, or require partial risk reports, periodic situation reports, as well as their submission by electronic means. CHAPTER III REGULATORY COMPLIANCE Article 28.- Regulatory compliance function The regulatory compliance function incorporates the evaluation and monitoring of compliance with all applicable regulations for the supervised company. Its objective is to identify and timely inform the responsible areas of companies about external regulations that have a direct impact on the functions they perform, as well as related internal regulations, so that the necessary measures are taken to comply with these provisions. Companies must determine the most appropriate and efficient way to implement the regulatory compliance function according to their own needs and internal organization, ensuring that said function has sufficient resources to perform effective work. This does not necessarily imply the formation of an organizational unit but rather the existence of the function and the appointment of a person in charge of said work called the Regulatory Compliance Officer, who must have a managerial level and will be designated by the company's board of directors, to whom they will report directly.
Los Laureles No. 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 The Superintendency may require companies to establish organizational units exclusively dedicated to the compliance function, considering their nature, size, and the complexity of their operations and services. Compliance officers must be independent of the activities of the risk and business units and possess solid knowledge of the regulations applicable to the company, as well as their impact on the operations it performs. Activities carried out within the framework of the compliance function must be subject to periodic review by the Internal Audit Unit, which is not subject to the monitoring and evaluation of the compliance function. Article 29.- Responsibilities and functions of the Compliance Officer The responsibilities and functions of the compliance officer, among others contemplated in the Regulation, are the following: a) Propose to the board of directors appropriate policies, procedures, and methodologies for the company's compliance with regulatory requirements. b) Propose an annual compliance program to the board of directors. c) Continuously and timely inform the board of directors and management regarding the necessary actions for good regulatory compliance and potential existing gaps, as well as major changes in the regulatory environment that may impact the company's operations. d) Report semi-annually to the board of directors and management on the progress of implementing regulatory adaptation measures. e) Guide and train company personnel regarding the importance of regulatory compliance and the responsibilities arising from non-compliance. f) Provide reasonable assurance to the board of directors and management that policies and procedures related to regulatory compliance ensure the company meets regulatory requirements. g) Propose corrective measures to the board of directors in case of failures in the application of the compliance function. Article 30.- Compliance policies and procedures The company's board of directors must approve compliance policies and procedures in a formal document establishing a permanent and effective compliance function within the company. This document must contain the criteria to be followed by management and personnel, and explain the main processes that will prevent, identify, and mitigate the possibility of regulatory non-compliance at all organizational levels. The aforementioned document must be available to the Superintendency. Article 31.- Annual compliance program The board of directors must approve the annual compliance program before December 31 of each year. This program must outline the scheduled activities, their implementation, and be available to this Superintendency. The companies' annual compliance program must indicate, in addition to activities related to the responsibility of the compliance function, the following: Los Laureles No. 214 - Lima 27 - Peru Tel. : (511)6309000 Fax: (511) 6309239 a) Prepare self-assessment reports on compliance with external regulations, as well as internal regulations linked to those that have a direct impact on the company, in accordance with the methodology established by it. b) Establish the duration of scheduled activities (start and end), as well as determine the areas involved and the deliverables for each proposed activity. Subsequently, the Superintendency may require additional guidelines to be included in the annual compliance program through a multiple official letter. Article 32.- Relationship of the compliance function with anti-money laundering and terrorism financing risk management, as well as with the user service system function The Superintendency, due to the nature, size, and complexity of the company's operations and services, may authorize that compliance functions can be shared with anti-money laundering and terrorism financing risk management functions, or with user service functions, for which special regulations on these matters must be considered. The Superintendency will specify, through general regulations, the minimum information requirements associated with such authorization request. Article 33.- Corporate compliance officer Companies that are part of an economic group may designate a corporate compliance officer; such designation must have prior authorization from this Superintendency. This officer cannot be the corporate compliance officer for the prevention and management of money laundering and terrorism financing risks. For the authorization of the corporate compliance officer position, companies must submit an authorization request, signed by each of the representatives of the economic group members, attaching a technical report that supports the viability of having a corporate compliance officer. The request must be accompanied by the following information: a) List of entities belonging to the economic group that will have a corporate compliance officer; b) List of personnel in charge of the corporate compliance officer and the coordinators designated by each group member; c) Report supporting how current regulatory compliance provisions will be met for each member of the economic group that would fall within the scope of the corporate function; d) In cases where the corporate compliance function is shared with other functions, a report supporting how these shared functions will be fulfilled; e) Curriculum vitae of the corporate compliance officer; f) Reasons for requesting the designation of a corporate compliance officer; and, g) Other documentation at the request of the Superintendency. If, in the exercise of its supervisory powers, it is determined that the practical exercise of the corporate compliance officer's functions does not allow for adequate compliance with the provisions contemplated in the Regulation by the companies belonging to the economic group, the Superintendency may require the compliance function to be performed individually. Article 34.- Corporate Compliance Coordinator Companies belonging to an economic group that have a corporate compliance officer must designate a coordinator in each member company of the economic group, who will be responsible for directly coordinating all matters related to the compliance function. CHAPTER IV 17 GOODS AND/OR SERVICES PROVIDED BY THIRD PARTIES Article 35.- General aspects 35.1. Goods and/or services provided by third parties are those delivered to the company by a provider. 35.2. In the case of a good and/or service that could be developed by the company but it decides to request it through a third party, the subcontracting modality is configured. 35.3. Significant goods and/or services provided by third parties are those that, in case of failure or suspension, can significantly jeopardize the company by affecting its income, solvency, operational continuity, or reputation. If any significant good and/or service is provided by a third party under the subcontracting modality, the subcontracting is considered significant. 35.4. A provider is considered significant when it provides significant services, whether or not under the subcontracting modality. Article 36.- Goods and/or services provided by third parties 36.1 The risks associated with the delivery of goods and/or services provided by third parties must be managed as part of the company's comprehensive risk management framework. 36.2 The company is responsible for the results of goods and/or services provided by third parties under the subcontracting modality. 36.3 The company must conduct an evaluation of the risks associated with significant services provided by third parties, whether or not they are under the subcontracting modality. This evaluation must be submitted to the board of directors for approval. 36.4 In the case of significant subcontracting, clauses must be included to facilitate an adequate review of the respective service by the companies, the internal audit unit, the external audit firm, as well as by the Superintendency or persons designated by it, in the contracts signed with providers. 36.5 The subcontracting of risk management functions is considered significant for the purposes of this Regulation. 36.6 This Superintendency may define additional requirements for some specific goods and/or services provided by third parties. Article 37.- Authorization for the contracting of significant goods and/or services provided by third parties The contracting of the following significant goods and/or services requires prior authorization from this Superintendency and must comply with the provisions of specific regulatory standards: a) Significant subcontracting of internal audit, in accordance with the provisions of the Internal Audit Regulation or the rule that replaces it; b) Others indicated by the Superintendency through a general rule.” FINAL AND COMPLEMENTARY PROVISIONS First.- Information Availability All information related to the implementation of the provisions and requirements referred to in the Regulation must be available to this Superintendency. Second.- Prudential Measures The Superintendency may require companies to adopt additional prudential measures to those provided in the Regulation, with the purpose of mitigating exposure to the risks they face and/or allowing effective supervision. Third.- Authorization for Corporate Committees Express authorization from the Superintendency is required for a Corporate Committee of the Parent Company to perform functions of any of the Board of Directors' committees. For this, companies must request authorization indicating how the provisions outlined in this Regulation and the following aspects will be met, obligations that remain in force while the authorization is valid: a) It must be evaluated that the management system, taken as a whole, substantially complies with the minimum criteria indicated in the present regulations. b) When the organization receives various services from its parent company, it must ensure that, taken as a whole, they equal or exceed the criteria provided in the Regulation. c) When required for purposes of standardization and common language with its parent company, in order to take advantage of methodological benefits, such as demonstrated knowledge and experience in risk management design and implementation in accordance with good practices, infrastructure, and methods and procedures, a clear understanding and management of the risks to which they are exposed must be demonstrated. This Superintendency may suspend at any time the authorizations referred to in this rule, when in the exercise of its supervisory function it observes that circumstances warrant it, that the company has failed to comply with the stipulated obligations, or that the granted authorization has not contributed to an improvement in its risk management practice, which it will communicate to the company by official letter. Special authorizations granted during the validity of the Comprehensive Risk Management Regulation, approved by SBS Resolution No. 037-2008 and its modifying rules, must be adapted to this Regulation. Fourth.- Evaluation reports of shareholders, ultimate beneficial owners, directors, managers, and principal officers 18 For the application of the provisions of Article 21-H, evaluation reports of shareholders, ultimate beneficial owners, directors, managers, and principal officers must be prepared and made available to this Superintendency within one year from the effective date of said article, without prejudice to the Superintendency being able to request these reports at any time for supervisory purposes. Article Second.- Modify Annex “Scheduled Activities” of the Internal Audit Regulation, approved by SBS Resolution No. 11699-2008 and its modifying rules, as follows: Incorporate as numerals 16 of section I “Companies indicated in literals A and B of Article 16 of the General Law (except bonding and guarantee companies), Banco de la Nación, Banco Agropecuario, Fondo Mivivienda and Corporación Financiera de Desarrollo (COFIDE)”, 20 of section II “Insurance and/or Reinsurance Companies”, 9 of section III “Complementary and Related Services Companies”, 11 of section IV “Bonding and Guarantee Companies”, 9 of section V “Pension Funds and Pension Boxes” and 10 of section VI “Private Pension Fund Administrators (AFPs)”, the following text: “Evaluation of the remuneration system for employees and board members, which must include at least:
17 Substituted by SBS Resolution No. 504-2021 of 02/22/2021 effective from 07/01/2021. 18 Incorporated by SBS Resolution No. 211-2021, effective from February 1, 2021, adaptation November 1, 2021
More like this from SBS
SBS published 4 documents in the last 30 days. We email you each new one the day it's published.