2020-04-14 | NRP-24

Added · Updated

Technical Standards for the Business Continuity Management System

The Committee of Standards of the Central Reserve Bank of El Salvador issues technical standards requiring supervised financial entities to establish a Business Continuity Management System. The document mandates that entities, including banks, insurance companies, and investment fund managers, implement specific roles for the Board of Directors, Risk Committee, and Senior Management to oversee continuity planning. It requires the execution of business impact analyses, threat assessments, and regular testing of continuity plans to ensure operational resilience.

Superintendencia del Sistema Financiero logo

El Salvador

Superintendencia del Sistema Financiero

Click to view thumbnail

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 14 CNBCR-07/2020 NRP-24 TECHNICAL STANDARDS FOR THE BUSINESS CONTINUITY MANAGEMENT SYSTEM Approval: 14/04/2020 Validity: 01/07/2020

THE COMMITTEE OF STANDARDS OF THE CENTRAL RESERVE BANK OF EL SALVADOR,

CONSIDERING:

I. That in accordance with Article 2, second paragraph of the Law for the Supervision and Regulation of the Financial System, for the proper functioning of the Financial Supervision and Regulation System, it is required that the members of the financial system and other supervised entities comply with current regulations and adopt the highest standards of conduct in the development of their businesses, acts, and operations, in accordance with what is established in the aforementioned Law, in other applicable laws, in regulations, and in the technical standards issued for such effect.

II. That Article 7 of the Law for the Supervision and Regulation of the Financial System establishes the entities subject to the supervision of the Superintendence of the Financial System.

III. That in accordance with Article 35, first paragraph and letter d) of the Law for the Supervision and Regulation of the Financial System, directors, managers, and other officials holding positions of direction or administration in the members of the financial system must conduct their businesses, acts, and operations complying with the highest ethical standards of conduct and acting with the due diligence of a good merchant in their own business, being obligated to comply with and ensure that in the institution they direct or work in, the adoption and updating of policies and mechanisms for risk management are fulfilled, including among other actions, identifying, evaluating, mitigating, and disclosing them in accordance with international best practices.

IV. That in accordance with Article 99, letters a) and g) of the Law for the Supervision and Regulation of the Financial System, the Central Reserve Bank of El Salvador is the institution responsible for the approval of technical standards related to risk management by supervised entities, as well as those in which the minimum physical conditions that premises must meet, their security measures, and matters related to the conservation and archiving of documentation of the members of the financial system are defined.

V. That international standards suggest, among other good practice activities, broad guidelines in the matter of business continuity, with the description of the methods, techniques, and approaches used worldwide to develop, implement, and maintain an effective business continuity management system.

VI. That it is convenient for entities to adequately manage the risks to which the different processes and activities they carry out are exposed, in order to guarantee business continuity, ensuring efficient operational risk management.

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 14 CNBCR-07/2020 NRP-24 TECHNICAL STANDARDS FOR THE BUSINESS CONTINUITY MANAGEMENT SYSTEM Approval: 14/04/2020 Validity: 01/07/2020

THEREFORE, by virtue of the regulatory powers conferred upon it by Article 99 of the Law for the Supervision and Regulation of the Financial System, AGREES to issue the following:

TECHNICAL STANDARDS FOR THE BUSINESS CONTINUITY MANAGEMENT SYSTEM

CHAPTER I OBJECT, SUBJECTS, AND TERMS

Object Art. 1.- These Standards aim to establish the minimum provisions that entities must consider to establish a Business Continuity Management System and criteria for the adoption of policies, plans, methodologies, and procedures in accordance with international best practices, the size, nature of their operations, business segmentation, and the organizational complexity of each entity, and in this way, strengthen their operational risk management.

Subjects Art. 2.- The subjects obliged to comply with the provisions established in these Standards are: a) Banks incorporated in El Salvador, their offices abroad, and their subsidiaries; branches and offices of foreign banks established in the country; b) Companies that, in accordance with the Law, integrate financial conglomerates, or that the Superintendence of the Financial System declares as such, which includes both their holding companies and their member companies; c) Pension fund management institutions and the funds they manage; d) Insurance companies incorporated in the country, their branches abroad, the branches of foreign insurance companies established in the country, and Cooperative Insurance Associations incorporated in the country, insofar as it does not contradict their respective Law; e) Stock exchanges, brokerage houses, companies specialized in the deposit and custody of securities, risk classifiers, and agents specialized in the valuation of securities; f) Cooperative banks, savings and credit companies, and federations regulated by the Law of Cooperative Banks and Savings and Credit Companies; g) Mutual guarantee companies and their local reinsurance providers; h) Companies that offer complementary services to the financial services of the members of the financial system, particularly those in which they participate as investors; i) Management or operating companies of payment systems and securities settlement systems; j) The Social Housing Fund and the National Popular Housing Fund, insofar as it does not contradict their creation laws nor what is provided by the Court of Accounts; k) The National Institute of Pensions for Public Employees and the Salvadoran Social Security Institute, the latter with respect to the Professional Risks Regime and technical health reserves; l) The Social Prevision Institute of the Armed Forces; m) The Agricultural Development Bank, the Mortgage Bank of El Salvador, S.A., and the Development Bank of El Salvador; n) Securitization companies and the funds they manage; o) Exchanges of products and services; p) Investment fund managers and the funds they manage; q) Electronic Money Provider Companies; r) Data Information Agencies. (2) s) The Pension Unit of the Salvadoran Social Security Institute; and (2) t) Investment banks, their offices abroad, and their subsidiaries. (2)

Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Senior Management: the Executive President, Executive Director, General Manager, or whoever acts in their place, and the executive positions that report to them. For the case of the Development Bank of El Salvador and the National Institute of Pensions for Public Employees, the President; b) Threat: the potential cause of an unwanted event, which can affect business continuity; c) Business Impact Analysis (BIA): process in which the business processes, functions, and activities are analyzed, and the consequences of an interruption on them; d) Central Bank: Central Reserve Bank of El Salvador; e) Business Continuity: is the capacity of an entity to continue offering its products or services at previously defined acceptable levels after an interruption incident; f) Organizational Culture: is the set of attitudes, beliefs, behaviors, norms, and values accepted and applied daily by the members of an entity in their interaction among themselves and in their interaction with the outside; g) Entity: subject obliged to comply with the provisions of these Standards, described in Article 2 of the same; h) Event: occurrence or change of a particular set of circumstances; i) Business Continuity Management: comprehensive management process that identifies threats potential to an entity and the impact they could cause to business operations, if materialized. This process provides a framework to build the organizational capacity to overcome an interruption incident and offer an effective response, in such a way as to safeguard corporate objectives, reputation, brand, and value-creation activities; j) Crisis Management: process by which an entity faces one or more events of considerable magnitude that threaten to affect the entity and stakeholders financially, economically, and reputationally, in front of its clients, users, or the general public. Such events might not imply the disruption of the entity's operations, such as the dissemination or publication of information that could damage its reputation; k) Stakeholders: people or organizations that are impacted by the operations of an entity. Examples: employees, clients, debtors, business partners, suppliers, shareholders, government institutions, among others; l) Interruption Incident: an event that has the capacity to generate an interruption in the products or services offered by an entity, which, if not managed appropriately, can cause an emergency, crisis, or disaster. It is also known as a disruptive incident; m) Board of Directors: collegial body in charge of the administration of the entity, with supervisory, directional, and control functions, or equivalent body; for the case of Cooperative Associations, it will be the Board of Directors or as defined in its Creation Law; n) Maximum Tolerable Period of Disruption (MTPD): is the time it would take for adverse impacts to become unacceptable for the entity; o) Minimum Business Continuity Objective (MBCO): is the minimum acceptable level of products or services that an entity must offer to achieve its objectives during an interruption incident; p) Business Continuity Plan (BCP): documented procedures that guide entities to respond, recover, and continue business at a predefined acceptable level of operation, after an interruption incident and within predefined recovery times; q) Process: refers to the set of interrelated and repeatable procedures and activities that produce an expected result; r) Product and service: beneficial results provided by the entity to critical services, clients, debtors, recipients, and other stakeholders; s) Full Tests: execution of all recovery plans and procedures of the entire organization. Evaluation of alternative operational capabilities in a highly stressed environment, without this putting at risk the provision of products and services by the entity. Eventually, competent public sector entities could be involved; t) Test(s): simulation of an interruption of processes or operations to evaluate the components of a plan (for example, tasks, teams, personnel, procedures, among others) with the objective of verifying if it is viable and functional. Such tests can be as follows:

i. Desktop: Method of exercise to practice plans, in which participants review and discuss action plans and procedures without executing them, in a safe and stress-free environment. It can be carried out with one or several teams or departments. It generally requires the guidance of a facilitator; ii. Simulations: its process involves using a created situation to validate the plan's information, generating a theoretical response to the incident; and iii. Functional: execution of the recovery plans and procedures of an area or business line; u) Recovery Point Objective (RPO): represents the maximum data loss admissible for it to remain feasible to resume an operation and is expressed in units of time of lost information; v) Critical services: are the priority services and activities whose unavailability compromises the existence of the entity; w) Business Continuity Management System (BCMS): is part of the general management system that establishes, implements, operates, monitors, reviews, maintains, and improves business continuity. That is, it provides a formal method to launch Business Continuity Management and verify that it is effective and consistent with the defined continuity levels and organizational culture; x) Superintendence: Superintendence of the Financial System; y) Outsourcing of services: occurs when the entity entrusts the performance of a process to a third party, that is, to a natural or legal person distinct from the entity; and z) Recovery Time Objective (RTO): is the time established by the entity to resume the delivery of a product or service after an interruption incident. The RTO of each product, service, process, or activity is less than the respective Maximum Tolerable Period of Disruption.

CHAPTER II ROLES AND RESPONSIBILITIES

Business Continuity Management Art. 4.- The Board of Directors, Senior Management, and personnel must permanently manage the business continuity of the entities. The business continuity management of the entities must be adequate to the nature, size, and complexity of the operations, products, and services they offer. In this sense, entities must have an organizational or functional structure that clearly delimits the specific functions, roles, and responsibilities associated with business continuity, as well as the levels of dependence and interrelation that correspond with each of the other areas of the entity. Likewise, when the size and complexity of the entity's operations and services so warrant, the business continuity function may be performed by a unit, specialized area, or person designated by the Board of Directors and who guarantees its reporting to the same.

Responsibilities of the Board of Directors Art. 5.- The Board of Directors will be responsible for establishing and maintaining a System for the Management of Business Continuity, which allows the entity to protect its personnel, assets, maintain operation at the minimum acceptable level when interruption incidents occur, and recover the normal level of operations once the emergency phases are overcome, so it must perform, at a minimum, the following: a) Approve the strategies, policies, and manuals of the System for the Management of Business Continuity of the entity, and ensure that Senior Management implements them effectively; b) Approve the allocation of necessary resources to establish, implement, and improve business continuity management in accordance with the defined recovery and continuity strategy; and c) Ensure that the System to Manage Business Continuity is implemented and maintained adequate to meet its objectives, for which it must, at a minimum, perform the following: i. Periodically know the results of tests and evaluations of the System, ensuring that identified recommendations and improvement opportunities are incorporated; ii. Ensure that Internal Audit verifies the existence and compliance of business continuity management; and iii. Know the results of the activation of continuity plans after the response to interruption incidents, the adjustments, and improvement opportunities that must be implemented to strengthen the effectiveness of the BCMS.

Responsibilities of the Risk Committee Art. 6.- The Risk Committee is in charge of ensuring sound business continuity management of the entity, so it must perform, at a minimum, the following: a) Evaluate, review, and propose for approval by the Board of Directors the entity's business continuity strategies, policies, and manuals; b) Approve business continuity plans; c) Supervise that business continuity management is effective and that the business impact analysis is carried out, identifying and prioritizing the critical processes of the entity; d) Approve the business continuity testing program proposed by the unit, area, or person responsible for business continuity management, recommending additional actions or mechanisms for the planning and execution of the same; likewise, carry out a follow-up on the execution of this and the action or improvement plans that result; e) Support the work of whoever holds the business continuity function in the implementation of business continuity management; and f) Carry out the follow-up of business continuity management.

Responsibilities of Senior Management Art. 7.- Senior Management will be responsible for implementing the BCMS, for which it must perform at least the following activities: a) Implement the entity's business continuity strategies, policies, manuals, and plans, in accordance with what is authorized by the Board of Directors and Risk Committee; b) Ensure that a business continuity testing program is carried out and formulated; c) Ensure the fostering of a business continuity culture, motivating the active participation and commitment of all employees; d) Activate continuity plans in response to the occurrence of interruption incidents; and e) Promote continuous improvement in the entity's business continuity management.

Responsibility of the Risk Unit Art. 8.- In matters of business continuity management, the Risk Unit must carry out, at a minimum, the following: a) Support in the design and submit for approval by the Board of Directors, through the Risk Committee, the business continuity strategies, policies, and manuals; b) Support in the design and submit for approval by the Risk Committee, the business continuity plans; c) Ensure that the business continuity management carried out by the entity is consistent with the policies, methodologies, and procedures applied for risk management; and d) Propose to the Risk Committee or whoever acts in their place, the creation of specialized Committees, areas, or positions for the fulfillment of responsibilities related to business continuity management.

CHAPTER III OF THE BUSINESS CONTINUITY MANAGEMENT SYSTEM

Business Continuity Management System Art. 9.- The minimum elements to develop to implement a BCMS will be the following: a) A business continuity policy; b) Roles and responsibilities of participants in business continuity management; c) The business impact analysis (BIA); d) Analysis of threats to business continuity; e) Design and selection of business continuity strategies and tactics; f) Development and implementation of the selected business continuity strategy(ies); f) Business continuity plans for processes that allow the delivery of critical products and services that the entity offers, including internal and external support services that become critical or enablers of business processes; g) Tests on business continuity plans; h) Integration of business continuity management into organizational culture through training, dissemination, and awareness of personnel, at least once a year; i) Crisis management strategy; and j) Periodic reviews of the BCMS.

Functions of the specialized unit or area in Business Continuity Art. 10.- The business continuity function will comprise at least the following aspects: a) Design the entity's business continuity strategies, policies, manuals, and plans, with the support of the Risk Unit, to submit for approval by the Board of Directors; b) Design the entity's business continuity plans, with the support of the Risk Unit, to submit for approval by the Risk Committee; c) Elaborate roles and establish responsibilities of participants in business continuity management; d) Carry out the business impact analysis and the continuity threat analysis with the support of the Risk Unit and inform Senior Management, the Risk Committee, and the Board of Directors, about the results obtained; e) Design and execute a business continuity testing program with the support of the Risk Unit, for approval by the Risk Committee; which allow verifying its applicability, subsequently informing Senior Management, the Risk Committee, and the Board of Directors, about the result of said tests carried out; f) Establish training and awareness programs for personnel, directly related to business continuity management, so that they know their role when facing a disruptive event; g) Define a primary and alternate responsible person to communicate to the Superintendence the following: i. The results of the tests; ii. The activation of the business continuity plan when an interruption incident occurs; said communication must include; a description of each interruption that affects financial services at the moment it has knowledge of the interruption incident, the plan or measures necessary to guarantee the continuity