2017-07-07 | 35/SEOJK.03/2017Added · Updated
Financial Services Authority Circular No. 35/SEOJK.03/2017 establishes standard guidelines for internal control systems that conventional and Islamic commercial banks must implement. The regulation mandates that banks adjust their internal control systems to meet five core components: management oversight and control culture, risk identification and assessment, control activities and segregation of duties, accounting and information systems, and monitoring and corrective actions. This circular revokes Bank Indonesia Circular No. 5/22/DPNP and became effective on July 7, 2017.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 35 /SEOJK.03/2017
CONCERNING
STANDARD GUIDELINES FOR INTERNAL CONTROL SYSTEMS FOR COMMERCIAL BANKS
In light of the implementation of Financial Services Authority Regulation Number 18/POJK.03/2016 concerning the Implementation of Risk Management for Commercial Banks (State Gazette of the Republic of Indonesia Year 2016 Number 53, Supplement to the State Gazette of the Republic of Indonesia Number 5861) and Financial Services Authority Regulation Number 65/POJK.03/2016 concerning the Implementation of Risk Management for Islamic Commercial Banks and Sharia Business Units (State Gazette of the Republic of Indonesia Year 2016 Number 298, Supplement to the State Gazette of the Republic of Indonesia Number 5988), as well as in light of the transfer of the functions, duties, and authority for the regulation and supervision of financial services in the banking sector from Bank Indonesia to the Financial Services Authority, it is necessary to regulate again the implementation of standard guidelines for internal control systems for commercial banks in a Financial Services Authority Circular Letter as follows:
Standard Guidelines for Internal Control Systems for Commercial Banks are standard internal control system guidelines that must be fulfilled by Banks so that Banks can expand and deepen according to the Bank's needs.
Banks that already have an internal control system but have not yet met the Standard Guidelines for Internal Control Systems for Commercial Banks must adjust and perfect the Bank's internal control system with reference to the Appendix which is an integral part of this Financial Services Authority Circular Letter.
This copy is in accordance with the original
Director of Law 1
Legal Department signed
Yuliana
In formulating the internal control system, Banks must consider total assets, products and services offered, including new products and services, operational complexity, office network, Risk profile of each business activity, methods used for data processing and Risk measurement, and related regulations.
Standard Guidelines for Internal Control Systems for Commercial Banks must include at least 5 (five) main components, namely:
a. management oversight and control culture; b. risk identification and assessment;
c. control activities and segregation of duties;
d. accounting, information and communication systems; and e. monitoring activities and corrective actions for deviations.
At the time this Financial Services Authority Circular Letter takes effect, Bank Indonesia Circular Letter No. 5/22/DPNP concerning Standard Guidelines for Internal Control Systems for Commercial Banks is revoked and declared invalid.
The provisions in this Financial Services Authority Circular Letter take effect on the date of establishment.
Established in Jakarta on July 7, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 35 /SEOJK.03/2017 CONCERNING STANDARD GUIDELINES FOR INTERNAL CONTROL SYSTEMS FOR COMMERCIAL BANKS
TABLE OF CONTENTS
I. BACKGROUND................................................................................. 2
II. SCOPE OF BANK INTERNAL CONTROL SYSTEM.................... 3
I. BACKGROUND
An effective Internal Control System (ICS) is an important component in Bank management and forms the basis for healthy and safe Bank operational activities. An effective ICS can help the Board of Directors and Board of Commissioners safeguard Bank assets, ensure the availability of reliable financial and managerial reporting, increase the Bank's compliance with laws and regulations, and reduce the Risk of losses, deviations, and violations of prudential aspects.
The implementation of a reliable and effective Bank ICS is the responsibility of the Board of Directors, Board of Commissioners, and Bank officials. In addition, the Board of Directors and Board of Commissioners are also obligated to enhance an effective risk culture within the Bank organization and ensure it is embedded at every level of the organization.
ICS requires Bank attention, considering that one of the causes of Bank business difficulties is the presence of various weaknesses in the implementation of the Bank's ICS, including:
a. lack of supervision mechanisms, unclear accountability of the Board of Directors and Board of Commissioners, and failure to develop an internal control culture at all levels of the organization; b. inadequate implementation of risk identification and assessment of Bank operational activities;
c. absence or failure of main controls over Bank operational activities, such as segregation of duties, authorization, verification, and review of Risk exposure and Bank performance;
d. lack of communication and information between levels within the Bank organization, particularly information at the decision-making level regarding the deterioration of Risk exposure quality and the implementation of corrective actions; e. inadequate or ineffective internal audit programs and other monitoring activities; and f. lack of Bank management commitment to conduct internal control processes and apply strict sanctions for violations of applicable regulations, as well as Bank-established policies and procedures.
II. SCOPE OF BANK INTERNAL CONTROL SYSTEM
b. Objectives
Compliance with Laws and Regulations or Compliance Objectives
The Compliance Objectives are intended to ensure that all Bank business activities have been carried out in accordance with laws and regulations, both regulations issued by the government, the Financial Services Authority, as well as internal policies, regulations, and procedures established by the Bank.
Availability of Complete, Accurate, Relevant, and Timely Financial and Management Information or Information Objectives
The Information Objectives are intended to ensure the availability of complete, accurate, relevant, and timely reports required for making appropriate and accountable decisions.
Effectiveness and Efficiency in Bank Business Activities or Operational Objectives
The Operational Objectives are intended to increase effectiveness and efficiency in the use of assets and other resources in order to protect the Bank from loss Risks.
Enhancing the Effectiveness of Risk Culture in the Bank Organization as a Whole or Risk Culture Objectives
The Risk Culture Objectives are intended to identify weaknesses and assess deviations early and continuously reassess the reasonableness of existing Bank policies and procedures.
b. Board of Commissioners
The Bank's Board of Commissioners has the responsibility to supervise the implementation of internal controls in general, including the Board of Directors' policies establishing such internal controls.
c. Internal Audit Unit (SKAI)
SKAI must be able to evaluate and play an active role in continuously enhancing the effectiveness of ICS in relation to Bank operational activities that have the potential to cause losses in achieving objectives set by Bank management. In addition, the Bank needs to pay attention to the implementation of independent internal audits through adequate reporting channels, and the expertise of internal auditors, particularly regarding risk assessment practices and implementation.
d. Bank Officials and Employees
Every Bank official and employee must understand and implement the ICS established by Bank management. Effective internal control will increase the accountability of Bank officials and employees, encourage an adequate risk culture, and accelerate the identification of unhealthy banking practices and organizational issues through efficient early detection systems.
e. External Parties
External parties of the Bank include the Financial Services Authority, external auditors, and Bank customers who are interested in the implementation of a reliable and effective Bank ICS.
Consideration Factors in Formulating Bank Internal Control System
Banks must have an ICS that can be applied effectively, considering factors:
a. total assets; b. types of products and activities offered, including new products and activities;
c. operational complexity, including office networks;
d. Risk profile of each business activity; e. methods used for data processing and information technology as well as methodologies applied for Risk measurement, monitoring, and limitation; and f. laws and regulations.
Control Environment
The control environment reflects the overall commitment, behavior, concern, and steps of the Bank's Board of Directors and Board of Commissioners in carrying out Bank operational control activities. Control environment elements include:
a. adequate organizational structure; b. leadership style and Bank management philosophy;
c. integrity, ethical values, and competence of all employees;
d. Bank human resources policies and procedures; e. attention and direction of Bank management and other committees, such as the Risk Management Committee; and f. external factors affecting Bank operations and Risk Management implementation.
III. MAIN COMPONENTS OF BANK INTERNAL CONTROL SYSTEM
Bank internal control consists of five main components that are interrelated, namely Management Oversight and Control Culture, Risk Recognition and Assessment, Control Activities and Segregation of Duties, Accountancy, Information and Communication, and Monitoring Activities and Correcting Deficiencies.
Internal control must cover at least five main components, namely:
In carrying out these responsibilities, the Board of Directors must take steps, including:
i. assigning managers, officials, and employees responsible for specific activities or functions to formulate internal control policies and procedures for operational activities and organizational adequacy;
ii. conducting effective controls to ensure that managers, officials, and employees have developed and implemented established policies and procedures;
iii. documenting and socializing the organizational structure that clearly describes authority and reporting responsibility lines, and establishing an effective communication system to all levels of the Bank organization;
iv. taking appropriate steps to ensure that internal control function activities have been carried out by managers, officials, and employees with adequate experience and capabilities; and
v. effectively implementing improvement steps or recommendations from internal and/or external auditors, including by assigning responsible employees to implement them.
b. Board of Commissioners
The Board of Commissioners has the responsibility:
In fulfilling these responsibilities, the Board of Commissioners:
i. must be objective, possess knowledge and capabilities, and have curiosity regarding Bank business activities and Risks;
ii. must play an active role to ensure improvements to Bank issues that can reduce ICS effectiveness, such as obstacles in information flow from subordinates to management and weaknesses in the implementation of finance, legal, and internal audit functions;
iii. periodically hold meetings with the Board of Directors and Bank executive officials to discuss ICS effectiveness;
iv. review the results of internal control implementation evaluations made by the Board of Directors, SKAI, and external auditors;
v. periodically make efforts to ensure that the Board of Directors has appropriately followed up on findings and recommendations submitted by the Financial Services Authority, internal auditors, and external auditors; and
vi. periodically review the validity of established Bank strategies.
c. Control Culture
The Board of Directors and Board of Commissioners are responsible for enhancing work ethics and high integrity and creating an organizational culture that emphasizes to all Bank employees the importance of the internal controls applicable at the Bank.
In creating such a control culture, steps that must be considered and taken by the Bank include:
To support this control culture, all policies, standards, and operational procedures must be documented in writing and available to every relevant employee.
In strengthening ethical values, the Bank must avoid policies and practices that can lead to incentives or opportunities for deviations or violations, such as emphasis on short-term target achievement ignoring long-term Risk impacts, compensation systems focusing only on short-term performance, ineffective segregation of duties, and sanctions that are too light or too excessive for violations committed.
b. Risks can arise or change according to Bank conditions, including:
c. An effective ICS requires the Bank to continuously identify and assess Risks that can affect the achievement of objectives. Risk assessment must also be carried out by internal auditors so that the audit scope is broader and more comprehensive.
d. This Risk assessment must be able to identify the types of Risks faced by the Bank, set Risk limits, and apply Risk control techniques. Risk assessment methodology must serve as a benchmark for creating Risk profiles in the form of data documentation, which can be updated periodically. Risk assessment also includes assessment of measurable (quantitative) and immeasurable (qualitative) Risks, as well as controllable and uncontrollable Risks, considering costs and benefits. Subsequently, the Bank must decide whether to take such Risks or not, by reducing certain business activities.
e. The Risk assessment must cover all Risks faced, both individual and aggregate Risks, including Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Reputational Risk, Strategic Risk, and Compliance Risk. Specifically for Islamic Commercial Banks, Yield Risk and Investment Risk are added.
f. Internal control needs to be reviewed appropriately when there are Risks that are not yet controlled, both Risks that existed previously and newly emerging Risks. The implementation of such reviews includes continuous evaluation regarding the influence of every change in environment and conditions, and the impact of target achievement or the effectiveness of internal control in Bank operational and organizational activities.
a. Control Activities
Control activities include policies, procedures, and practices that provide assurance to Bank officials and employees that the directives of the Bank's Board of Directors and Board of Commissioners have been implemented effectively. These control activities will help the Bank's Board of Directors and Board of Commissioners manage and control Risks that can affect performance or cause Bank losses.
Control activities are applied at all functional levels according to the Bank's organizational structure, including at least:
Top Level Reviews
The Bank's Board of Directors periodically requests explanations (information) and operational performance reports from officials and employees, allowing for the review of progress (realization) results compared to targets to be achieved, such as financial reports compared to established budget plans. Based on this review, the Board of Directors immediately detects problems such as control weaknesses, financial reporting errors, or fraud.
Functional Review
This review is carried out by SKAI with higher frequency, whether daily, weekly, or monthly. In operational performance reviews, SKAI:
a) reviews the Risk assessment (Risk profile reports) generated by the Risk Management unit; b) analyzes operational data, both Risk-related data and financial data, namely verifying details and transaction activities compared to outputs (reports) generated by the Risk Management unit; and c) reviews the realization of work plan and budget implementation, in order to:
(1) identify causes of significant deviations; and (2) establish requirements for corrective actions.
Information System Control
a) The Bank implements verification of the accuracy and completeness of transactions and implements authorization procedures, in accordance with internal regulations. b) Information system control activities can be classified into 2 (two) criteria, namely:
(1) general controls, including controls over data center operations, procurement and software maintenance systems, access security, and development and maintenance of existing application systems. These general controls are applied to mainframes, servers, and user workstations, as well as internal-external networks; and (2) application controls, applied to programs used by the Bank to process transactions and to ensure that all transactions are correct, accurate, and properly authorized. In addition, application controls must ensure the availability of effective audit processes and to check the correctness of the intended audit process.
Physical Controls
a) Physical controls are implemented to ensure the physical security of the Bank's assets. b) This activity includes asset security, record-keeping, and limited access to computer programs and data files, as well as comparing the Bank's asset and liability values with those recorded in control records, specifically periodic asset value checks.
Documentation
a) The Bank must at least formally and adequately document policies, procedures, systems, and accounting standards, as well as the audit process. b) These documents must be updated periodically to reflect the Bank's actual operational activities and must be communicated to Bank officials and employees. c) Upon request, documents must always be available for the benefit of internal auditors, public accountants, and supervision by the Financial Services Authority (OJK). d) The accuracy and availability of documents must be assessed by internal auditors when conducting routine and non-routine audits.
b. Functional Segregation
a. Accounting System
b. Information System
c. Communication System
b. Internal Audit Unit (SKAI) Function
c. Weakness Improvement and Corrective Actions for Deviations
IV. OTHERS
In the implementation of internal controls, the Bank must also pay attention to internal control aspects established in other legislative regulations, including those regulating:
Determined in Jakarta on July 7, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, sd
NELSON TAMPUBOLON
APPENDIX
circular letter of the FINANCIAL SERVICES AUTHORITY NUMBER 35 /SEOJK.03/2017 ABOUT GUIDELINES FOR STANDARD INTERNAL CONTROL SYSTEMS FOR COMMERCIAL BANKS
TABLE OF CONTENTS
I. BACKGROUND................................................................................. 2
II. SCOPE OF THE BANK INTERNAL CONTROL SYSTEM.................... 3
I. BACKGROUND
II. SCOPE OF THE BANK INTERNAL CONTROL SYSTEM
Parties Interested in the Bank Internal Control System
The implementation of a reliable and effective SPI is the responsibility of all parties involved in the Bank's organization, including the following:
a. Board of Directors
The Bank's Board of Directors has the responsibility to create and maintain an effective SPI and ensure that the system runs safely and reliably in accordance with the internal control objectives established by the Bank.
Meanwhile, the director overseeing the compliance function must play an active role in preventing deviations by management in establishing policies related to prudential principles. b. Board of Commissioners The Bank's Board of Commissioners has the responsibility to supervise the implementation of internal controls in general, including the policies of the Board of Directors establishing such internal controls.
c. Internal Audit Unit (SKAI)
The SKAI must be able to evaluate and play an active role in continuously improving the effectiveness of the SPI in relation to Bank operational activities that have the potential to cause losses in achieving objectives established by Bank management. In addition, the Bank needs to pay attention to the implementation of independent internal audits through adequate reporting channels, and the expertise of internal auditors, particularly regarding Risk assessment practices and application. d. Bank Officials and Employees Every Bank official and employee must understand and implement the SPI established by Bank management. Effective internal control will increase the responsibility of Bank officials and employees, encourage an adequate Risk culture (risk culture), and accelerate the identification of unhealthy banking practices and organizational issues through efficient early detection systems. e. External Parties External parties of the Bank include the Financial Services Authority, external auditors, and Bank customers who are interested in the implementation of a reliable and effective Bank SPI.
Considerations in Formulating the Bank Internal Control System
The Bank must have an SPI that can be implemented effectively, considering factors:
a. total assets; b. types of products and activities offered, including new products and activities;
c. operational complexity, including office networks;
d. Risk profile of each business activity; e. methods used for data processing and information technology, as well as methodologies applied for Risk measurement, monitoring, and limitation (limits); and f. regulations and legislation.
Control Environment
The control environment reflects the overall commitment, behavior, concern, and steps of the Bank's Board of Directors and Board of Commissioners in executing Bank operational control activities. Elements of the control environment include:
a. adequate organizational structure; b. leadership style and Bank management philosophy;
c. integrity and ethical values as well as the competence of all employees;
d. Bank's human resources policies and procedures; e. attention and direction from Bank management and other committees, such as the Risk Management Committee; and f. external factors affecting Bank operations and the implementation of Risk Management.
III. MAIN COMPONENTS OF THE BANK'S INTERNAL CONTROL SYSTEM
Bank internal control consists of five main components that are interrelated, namely Management Oversight and Control Culture, Risk Recognition and Assessment, Control Activities and Segregation of Duties, Accountancy, Information and Communication, and Monitoring Activities and Correcting Deficiencies.
Internal control must cover at least five main components, namely:
a. Board of Directors
The Board of Directors has the following responsibilities:
In carrying out these responsibilities, the Board of Directors must take steps, including:
i. assigning managers, officials, and employees responsible for specific activities or functions to formulate internal control policies and procedures for operational activities and organizational adequacy;
ii. conducting effective controls to ensure that managers, officials, and employees have developed and implemented the established policies and procedures;
iii. documenting and socializing the organizational structure that clearly describes the lines of authority and reporting responsibility, and organizing an effective communication system to all levels of the Bank's organization;
iv. taking appropriate steps to ensure that internal control function activities have been carried out by managers, officials, and employees with adequate experience and capabilities; and
v. effectively implementing corrective steps or recommendations from internal and/or external auditors, including by assigning responsible employees to implement them.
b. Board of Commissioners
The Board of Commissioners has the following responsibilities:
In order to fulfill these responsibilities, the Board of Commissioners:
i. must be objective, possess knowledge and capabilities, and have curiosity regarding the Bank's business activities and Risks;
ii. must play an active role to ensure improvements to Bank problems that can reduce SPI effectiveness, such as obstacles in information flow from subordinates to management and weaknesses in the execution of financial, legal, and internal audit functions;
iii. periodically hold meetings with the Board of Directors and Bank executive officials to discuss SPI effectiveness;
iv. conduct reviews of the results of internal control implementation evaluations made by the Board of Directors, the Internal Audit Unit (SKAI), and external auditors;
v. periodically undertake efforts to ensure that the Board of Directors has appropriately followed up on findings and recommendations submitted by the Financial Services Authority (OJK), internal auditors, and external auditors; and
vi. periodically review the validity of the established Bank strategy.
c. Control Culture
The Board of Directors and Board of Commissioners are responsible for enhancing high work ethics and integrity and creating an organizational culture that emphasizes to all Bank employees the importance of the internal controls applicable at the Bank.
In order to create this control culture, the steps that must be considered and carried out by the Bank include:
To support this control culture, all policies, standards, and operational procedures must be documented in writing and available to every relevant employee.
In order to strengthen ethical values, the Bank must avoid policies and practices that can result in incentives or opportunities for deviations or violations, such as emphasis on achieving short-term targets while ignoring long-term Risk impacts, compensation systems that focus only on short-term performance, ineffective segregation of duties, and sanctions that are too light or too severe for violations committed.
a. Risk Assessment is a series of actions carried out by the Board of Directors in order to identify, analyze, and assess the Risks faced by the Bank in order to achieve established targets.
b. Risks can arise or change according to Bank conditions, including:
c. An effective SPI requires the Bank to continuously identify and assess Risks that can affect the achievement of objectives. Risk assessment must also be carried out by internal auditors so that the scope of audit conducted is broader and more comprehensive.
d. This Risk Assessment must be able to identify the types of Risks faced by the Bank, set Risk limits, and determine Risk control techniques. The Risk assessment methodology must serve as a benchmark for creating a Risk profile in the form of data documentation, which can be updated periodically. Risk assessment also includes assessment of Risks that can be measured (quantitative) and cannot be measured (qualitative), as well as Risks that can be controlled and cannot be controlled, considering costs and benefits. Subsequently, the Bank must decide whether to take such Risks or not, by reducing certain business activities.
e. The Risk Assessment must cover all Risks faced, both individual Risks and aggregate Risks, including Credit Risk, Market Risk, Liquidity Risk, Operational Risk, Legal Risk, Reputational Risk, Strategic Risk, and Compliance Risk. Specifically for Sharia Commercial Banks, Yield Risk and Investment Risk are added.
f. Internal control needs to be reviewed appropriately when there are Risks that have not been controlled, both Risks that existed previously and newly emerging Risks. The implementation of such reviews includes conducting continuous evaluations regarding the influence of every change in environment and conditions, and the impact of target achievement or the effectiveness of internal control in the Bank's operational and organizational activities.
Control activities must involve all Bank employees, including the Board of Directors. Therefore, control activities will run effectively if planned and implemented to control identified Risks. Control activities also include the establishment of control policies and procedures and early verification processes to ensure that such policies and procedures are consistently complied with, and are inseparable from every function or daily Bank activity.
a. Control Activities
Control activities include policies, procedures, and practices that provide assurance to Bank officials and employees that the directives of the Bank's Board of Directors and Board of Commissioners have been implemented effectively. These control activities will help the Bank's Board of Directors and Board of Commissioners in managing and controlling Risks that can affect performance or cause Bank losses.
Control activities are applied at all functional levels according to the Bank's organizational structure, which must include at least:
Top Level Reviews
The Bank's Board of Directors periodically requests explanations (information) and operational performance reports from officials and employees, allowing for the review of progress (realization) results compared to targets to be achieved, such as financial reports compared to established budget plans. Based on this review, the Board of Directors immediately detects problems such as control weaknesses, financial reporting errors, or fraud.
Functional Review
This review is carried out by the Internal Audit Unit (SKAI) with higher frequency, whether daily, weekly, or monthly. In the operational performance review, SKAI:
a) conducts a review of the Risk assessment (Risk profile report) generated by the Risk Management work unit; b) analyzes operational data, both Risk-related data and financial data, namely by verifying details and transaction activities compared to the output (reports) generated by the Risk Management work unit; and c) conducts a review of the realization of work plan and budget implementation, in order to:
(1) identify causes of significant deviations; and (2) establish requirements for corrective actions.
Information System Controls
a) The Bank carries out verification of the accuracy and completeness of transactions and implements authorization procedures, in accordance with internal regulations. b) Information system control activities can be classified into 2 (two) criteria, namely:
(1) general controls, including controls over data center operations, procurement and software maintenance systems, access security, and development and maintenance of existing application systems. These general controls are applied to mainframes, servers, and user workstations, as well as internal-external networks; and (2) application controls, applied to programs used by the Bank to process transactions and to ensure that all transactions are correct, accurate, and properly authorized. In addition, application controls must ensure the availability of effective audit processes and to check the correctness of the intended audit process.
Physical Controls
a) Physical asset controls are implemented to ensure the implementation of physical security for Bank assets. b) This activity includes asset security, records, and limited access to computer programs and data files, as well as comparing the value of Bank assets and liabilities with the values stated in control records, specifically periodic checks of asset values.
Documentation
a) The Bank must at least formalize and adequately document policies, procedures, systems, and accounting standards, as well as audit processes. b) Such documents must be updated periodically to reflect the Bank's actual operational activities, and must be communicated to Bank officials and employees. c) Upon request, documents must always be available for the interests of internal auditors, public accountants, and Bank supervision by the Financial Services Authority (OJK). d) The accuracy and availability of documents must be assessed by internal auditors when conducting routine and non-routine audits.
b. Segregation of Duties
Segregation of duties is intended so that every person in their position does not have the opportunity to commit and hide errors or deviations in the execution of tasks at all levels of the organization and all steps of operational activities. The Bank must comply with this principle of segregation of duties, known as the "Four-Eyes Principle".
In cases where it is necessary due to changes in the characteristics of business activities and transactions as well as the Bank's organization, the Bank's Board of Directors must establish procedures (authority), including the establishment of a list of officers who can access high-risk transactions or business activities.
An effective SPI requires segregation of duties and avoids granting authority and responsibilities that can give rise to various conflicts of interest. All aspects that can give rise to conflicts of interest must be identified, minimized, and carefully monitored by other independent parties, such as public accountants.
In the implementation of segregation of duties, the Bank must take steps, including:
a) establishing specific functions or tasks at the Bank that must be separated or allocated to several people in order to reduce the Risk of financial data manipulation or misuse of Bank assets; b) segregation of duties is not limited to front and back office activities, but also for the purpose of controlling:
(1) approval of fund disbursements and realization of expenditures; (2) customer accounts and Bank owner accounts; (3) transactions in Bank bookkeeping; (4) provision of information to Bank customers; (5) assessment of the adequacy of credit or financing documentation and monitoring of debtors after credit or financing disbursement; (6) other business activities that can give rise to significant conflicts of interest; and (7) independence of the Risk management function at the Bank.
Adequate accounting, information, and communication systems are intended to be able to identify potential problems and serve as a means of exchanging information in the implementation of tasks according to respective responsibilities.
a. Accounting System
The accounting system includes methods and records for the purpose of identifying, grouping, analyzing, classifying, recording or booking, and reporting Bank transactions.
To ensure accurate accounting data consistent with data available based on system processing results, reconciliation processes between accounting data and management information systems must be carried out periodically or at least every month. Any deviations that occur must be immediately investigated and resolved. The reconciliation process must also be documented as part of the overall audit trail requirements.
b. Information System
The information system must be able to generate reports regarding business activities, financial conditions, Risk Management implementation, and compliance with regulations that support the implementation of the Board of Directors' and Board of Commissioners' tasks.
An effective SPI must at least provide sufficient and comprehensive internal data or information regarding finances, Bank compliance with laws and regulations, market information (external conditions), and every event and condition required for appropriate and accountable decision-making.
SPI must at least provide a reliable information system regarding all functional activities of the Bank, especially significant functional activities and those with high Risk potential. Such information systems, including electronic data storage and usage systems, must be guaranteed security, monitored by independent parties (internal auditors), and supported by adequate contingency programs.
The Bank must at least organize an emergency recovery plan and a backup system to prevent high-risk business failures. To ensure that all emergency recovery plans and backup systems have worked effectively, the implementation of procedures, processes, and backup systems must be documented and their effectiveness tested periodically. The Bank must document the implementation of periodic testing, and the Board of Directors must give full attention to findings of weaknesses in procedures, processes, and systems based on test results, and subsequently take necessary corrective steps.
The Bank must at least have and maintain a management information system organized, both in electronic and non-electronic forms. Given that electronic information systems and the use of information technology have Risk impacts, the Bank must control them effectively to avoid business disruptions and the possibility of significant Bank losses.
In order to control the implementation of information systems and technology, the Bank must pay attention to the following:
a) Availability of adequate evidence and documents to support the audit trail process. The audit trail must be implemented effectively and documented to ensure that the automation process has worked effectively and accurately. SKAI must assess the effectiveness and accuracy of the audit trail process when evaluating the implementation of the Bank's internal control. b) Implementation of controls over computer systems and their security (general controls) as well as controls over software applications and other manual procedures (application controls). c) Anticipation of occurrence of Risk of disruption or loss caused by factors outside the Bank's routine control scope, so that the Bank must organize a recovery system and contingency plan, as well as periodic checks for possibilities of previously unpredictable events (disaster and recovery plan). d) The information system must provide relevant, accurate, timely data and information, accessible to interested parties, and presented in a consistent format. e) As part of the recording or bookkeeping process, the information system must be supported by a good accounting system, including the establishment of procedures and schedules for transaction record retention.
c. Communication System
The communication system must be able to provide information to all parties, both internal and external, such as the Financial Services Authority (OJK), external auditors, shareholders, and Bank customers.
The Bank's SPI must ensure the existence of effective communication channels so that all Bank officials and employees fully understand and comply with policies and procedures in carrying out tasks and responsibilities.
The Bank's Board of Directors must organize effective communication channels so that necessary information is accessible to interested parties. This requirement applies to all information, whether regarding established policies and procedures, Risk exposure, and actual transactions, or regarding the Bank's operational performance.
The Bank's organizational structure must allow for adequate information flow, namely upward, downward, and cross-unit or cross-work unit information, as follows:
a) Upward information to ensure that the Board of Directors, Board of Commissioners, and Bank executive officials know the Risks and operational performance of the Bank.
Information channels must be able to respond well so as to generate the implementation of corrective steps and be known by the management ranks. b) Downward information to ensure that the Bank's goals, strategies, and expectations, as well as policies and procedures, have been communicated to lower-level managers and implementers. c) Cross-unit or cross-work unit information to ensure that information known by a specific work unit can be conveyed to other related work units, specifically to prevent conflicts of interest in decision-making and to create adequate coordination.
a. Monitoring Activities
The Bank must conduct continuous monitoring of the overall effectiveness of internal control implementation. Monitoring of the Bank's main Risks must be prioritized and function as part of the Bank's daily activities, including periodic evaluation, both by operational work units (risk-taking units) and by SKAI.
The Bank must monitor and evaluate the adequacy of SPI continuously in relation to changes in internal and external conditions, and must enhance SPI capacity so that its effectiveness can be improved.
Steps that must be taken by the Bank in order to implement effective monitoring activities, at least:
a) ensuring that the monitoring function has been clearly and well-structuredly established in the Bank's organization;
b) determine the work units or employees assigned to monitor the effectiveness of internal controls; c) determine the appropriate frequency for monitoring activities based on the Inherent Risk of the Bank and the nature or frequency of changes occurring in operational activities; d) integrate the Internal Control System (SPI) into operational activities and provide routine reports such as accounting journals, management reviews, and reports regarding approval of exceptions or deviations from established policies and procedures (justification for irregularities) which are subsequently reviewed; e) conduct reviews of the documentation and evaluation results from work units or employees assigned to perform monitoring; and f) determine information or feedback in an appropriate format and frequency.
b. Functions of the Internal Audit Unit (SKAI)
c. Correction of Weaknesses and Corrective Actions for Deviations
IV. OTHERS
In the implementation of internal controls, the Bank must also pay attention to internal control aspects established in other regulatory provisions, including those regulating:
Determined in Jakarta on July 7, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signature
NELSON TAMPUBOLON
This copy is consistent with the original
Legal Director 1
Legal Department signature
Yuliana
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.