2015-07-15 | NRP-11Added · Updated
The Technical Standards for the Comprehensive Risk Management of Entities in Stock Markets establish prudential provisions for financial system members operating in securities and products/services markets, including stock exchanges, brokerages, and investment fund managers. The regulations mandate the implementation of a continuous risk management process involving identification, measurement, control, and monitoring, supported by a segregated organizational structure. Key requirements include the Board of Directors' approval of risk policies and exposure limits, the establishment of an independent Risk Unit, and the formation of a Risk Committee to oversee risk governance and report to the Board.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 30 CNBCR-12/2015 NRP-11 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF ENTITIES IN STOCK MARKETS Approval: 15/07/2015 Validity: 10/08/2015
THE COMMITTEE OF STANDARDS OF THE CENTRAL RESERVE BANK OF EL SALVADOR, CONSIDERING:
I. That Article 2, second paragraph, of the Law on Supervision and Regulation of the Financial System establishes that: the proper functioning of the Financial Supervision and Regulation System requires, from the members of the financial system and other supervised entities, compliance with current regulations and the adoption of the highest standards of conduct in the development of their business, acts, and operations, in accordance with what is established in the aforementioned Law, in other applicable laws, regulations, and technical standards issued for such effect.
II. That in accordance with Article 3, first paragraph, and letter c) of the Law on Supervision and Regulation of the Financial System, it is the responsibility of the Superintendence of the Financial System to proactively monitor the risks of the members of the financial system and the manner in which they manage them, ensuring the prudent maintenance of their solvency and liquidity.
III. That according to Article 3, first paragraph, and letter i) of the Law on Supervision and Regulation of the Financial System, the Superintendence of the Financial System is responsible for supervising the individual and consolidated activity of the members of the financial system and other persons, operations, or entities mandated by laws and, for such purposes, it is incumbent upon it to require that supervised entities and institutions be managed and controlled in accordance with international best practices regarding risk management as well as the technical standards issued.
IV. That Article 7, letters f), q), s), and u) of the Law on Supervision and Regulation of the Financial System, establishes that the following are subject to supervision by the Superintendence of the Financial System: stock exchanges, brokerage houses, securities deposit and custody companies, risk rating agencies, institutions providing auxiliary services to the stock market, agents specialized in securities valuation, general warehouses for deposits, securitization companies, and exchanges for products and services.
V. That Article 35, letter d) of the Law on Supervision and Regulation of the Financial System, stipulates that directors, managers, and other officials holding positions of direction or administration of the members of the financial system must conduct their business, acts, and operations complying with the highest ethical standards of conduct, acting with the due diligence of a good merchant in their own business, being obligated to comply with and ensure that in the institution they direct or work in, the adoption and updating of policies and mechanisms for risk management is fulfilled, being required, among other actions, to identify, evaluate, mitigate, and disclose them in accordance with international best practices.
VI. That according to international standards, it is necessary to have a solid risk management framework to manage risks comprehensively according to the profile, magnitude of activities, business, resources of the entity, and best practices, in such a way as to promote the implementation of prudential measures for the transparent, efficient, and orderly functioning of the market.
THEREFORE, in virtue of the normative powers conferred by Article 99 of the Law on Supervision and Regulation of the Financial System, AGREES to issue the following:
TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF ENTITIES IN STOCK MARKETS
CHAPTER I OBJECT, SUBJECTS, AND TERMS
Object Art. 1.- These Standards have as their object to establish general prudential provisions to strengthen the comprehensive management of risks that must be observed by members of the financial system that make up both the securities market and the products and services market, in accordance with applicable laws and international standards in the matter, in accordance with the nature and scale of their activities.
Subjects Art. 2.- The provisions established in these Standards are applicable to the following entities that are members of the financial system: a) Stock exchanges; b) Exchanges for products and services; c) Brokerage houses; d) Companies specialized in the deposit and custody of securities; e) Risk rating companies; f) Agents specialized in securities valuation; g) General warehouses for deposit; h) Securitization companies and the funds they manage; and i) Investment fund managers and the funds they manage.
Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Senior Management: The Executive President, General Manager, or whoever acts in their place, and the executives who report to them; b) Risk Appetite: The level and types of risks that an entity is willing to assume in relation to its activities, to achieve its strategic objectives and business plans; (2) c) Central Bank: Central Reserve Bank of El Salvador; (2) d) House: Brokerage House; (2) e) Financial Conglomerate: In accordance with Article 113 of the Banks Law, it is the set of companies characterized by the fact that more than fifty percent of their respective share capital is owned by a controlling company, which is also a member of the conglomerate. The controlling company of the conglomerate may be a company with exclusive purpose or a bank constituted in the country; (2) f) Custodian: Company specialized in the deposit and custody of securities, constituted in El Salvador and registered with the Superintendence of the Financial System; (2) g) Entity: Subject obliged to comply with the provisions of these Standards; (2) h) Manager: Investment Fund Management Company; (2) i) Business Group: In accordance with Article 5 of the Securities Market Law, it is that in which a company or set of companies has a common controller, who acting directly or indirectly participates with at least fifty percent in the share capital of each of them or that have common shareholders who, directly or indirectly, are holders of at least fifty percent of the capital of another company, which allows to presume that the economic and financial performance is determined by common interests or subordinate to the group; (2) j) Board of Directors: Collegiate body in charge of the administration of the entity, with supervisory and control functions; (2) k) Risk Profile: Evaluation at a point in time of the exposure to risk; (2) l) Superintendence: Superintendence of the Financial System; (2) m) Securitization Company: Securitization Company; and (2) n) Risk Tolerance: Levels of risk-taking acceptable to achieve a specific objective or manage a category of risk. Risk tolerance represents the practical application of risk appetite and, generally, is aligned with risk categories, such as strategy, finance, people, or reputation. (2)
CHAPTER II ENVIRONMENT FOR COMPREHENSIVE RISK MANAGEMENT
Risk Management Art. 4.- Entities must establish a comprehensive risk management system, which shall be understood as a strategic process carried out by the entire entity, through which they identify, measure, control, monitor, and communicate the different types of risks to which they are exposed. Such management must be in accordance with their risk profile, volume, and complexity of their activities, business, own resources, and third-party resources, in such a way as to promote the implementation of measures in accordance with best practices for the transparent, efficient, and orderly functioning of the market.
Stages of the comprehensive risk management process Art. 5.- Entities must have a continuous and documented process for the comprehensive management of their risks, which must contain at least the following stages: a) Identification: This is the stage in which existing risks in each operation, product, process, and business line developed by the entity and those that arise in new business lines are recognized and understood. In this stage, risk factors are identified, which are variables and whose movements can generate changes in the equity of the entity or in the funds it manages; b) Measurement: This is the stage in which risks must be quantified in order to determine compliance or adequacy of policies, established limits, and measure the possible economic impact on the financial results of the entity. The methodologies and tools to measure risks must be in accordance with their organizational structure, volume, and nature of their operations and the levels of risks assumed; c) Control and mitigation: This is the stage that seeks to ensure that the policies, limits, and procedures established for the treatment and mitigation of risks are appropriately executed; it refers to the actions or mechanisms for coverage and control implemented by the entity with the purpose of preventing or reducing negative effects in case the adverse events of identified and managed risks materialize. An action plan must be established to implement measures that seek to mitigate identified risk events. This plan must detail the actions to be implemented, the estimated execution time, and the direct responsible parties for said execution; and d) Monitoring and communication: This is the stage that provides systematic and permanent follow-up to risk exposures, their evolution, trend, and the results of actions adopted. The systems used must ensure a periodic and objective review of risk positions and the generation of sufficient information to support decision-making processes.
Internal organizational structure Art. 6.- Entities must establish an organizational or functional structure, in accordance with their business model and properly segregated, that delimits their functions and responsibilities, as well as the hierarchical levels, levels of dependence, and interrelation that correspond to each of the operational support, business, and control areas that participate in the risk management process to which they are exposed.
Functions of the Board of Directors Art. 7.- The Board of Directors is responsible for ensuring adequate comprehensive risk management, having among its functions at least the following: a) Know and understand all risks inherent to the business developed by the entity, its evolution, and its effects on equity levels, as well as the methodologies for risk management; b) Approve the policies and manuals for risk management assumed by the entity, ensuring that they are implemented; c) Approve the internal organizational or functional structure in accordance with its business model, with their respective organization manuals and segregation of functions, assigning the necessary resources to implement and maintain adequate risk management, effectively and efficiently, including training programs, as well as ensuring independence between the unit or area responsible for risk management and the business areas of the entity; d) Create the Risk Committee, in accordance with the provisions of these Standards, approving the appointment and removal of its members, when applicable, ensuring its independence, this Committee being of a corporate nature in accordance with what is established in these Standards; e) Approve the exposure limits of each risk in particular in accordance with the profile of the entity; likewise, it must establish the respective controls for exceptions and deviations to said limits, as well as contingency plans to be adopted regarding extreme scenarios; f) Approve the entity's incursion into new business lines, operations, and activities, in accordance with business strategies and risk management policies; and g) Repealed; (1) h) Ensure that Internal Audit verifies the existence and compliance of the entity's risk management scheme. The policies and manuals for risk management approved by the Board of Directors must be sent to the Superintendence for its knowledge within the first ten business days after their approval or respective modification.
The Board of Directors must meet with the necessary frequency to perform its functions effectively, which must be at least quarterly. Meetings may also be held via videoconference; however, the agreements and resolutions taken must be documented in accordance with what is established in the Code of Commerce.
Functions of Senior Management Art. 8.- Senior Management is responsible for the implementation of management for each particular risk applicable to the entity, and must report to the Board of Directors, adopting at least the following measures: a) Implement the policies and manuals for risk management authorized by the Board of Directors; (1) b) Form the Risk Unit, or designate a person to perform said function, ensuring its independence from business and operational areas, as well as providing it with adequate human, material, and technical training resources; c) Establish procedures that ensure the flow, quality, and timeliness of information, between business units and the Risk Unit or whoever acts in their place, so that the latter appropriately develops its function; d) Ensure the establishment of mechanisms for disseminating the culture of comprehensive risk management, at all levels of the organizational structure; e) Maintain permanent follow-up on the compliance of risk management work plans, as well as action plans derived from recommendations made in the risk management process; f) Establish conditions at the level of the entire organization to promote an environment that seeks the development of the comprehensive risk management process; and g) Establish and ensure the execution of training and updating programs for the entity's risk management.
Risk Committee Art. 9.- Entities must have a Risk Committee, responsible for the follow-up of comprehensive risk management. This Committee must have authority over operational areas to support the work performed by the Risk Unit -or the person in charge of exercising the risk function- and will be the link between the latter and the Board of Directors. The Risk Committee must be integrated, at minimum, by: a) A member of the entity's Board of Directors, who will preside over the Committee in all sessions; b) The General Manager of the entity or a managerial official, whom he designates, without this exempting him from his responsibility; and c) The person in charge of the Risk Unit or whoever exercises its functions.
When the number of operations or the organizational structure of the entity does not allow the creation of the Risk Committee, the corresponding functions may be developed by the entity's Board of Directors or by a Corporate Risk Committee, provided that it complies with what is established in the applicable legal framework and with the provisions established in these Standards, ensuring objectivity, adequate handling of conflicts of interest, independence of criterion, confidentiality, and access to information. In these cases, the entity will be responsible for having the minutes, reports, and supporting documentation of the topics reviewed. The entity's Board of Directors will maintain responsibility for the execution of the functions defined in these Standards.
Functions of the Risk Committee Art. 10.- The functions of the Risk Committee will include, at minimum, the following activities: a) Ensure that the entity has the adequate organizational structure, policies, manuals, and resources for comprehensive risk management; b) Propose for approval by the Board of Directors, at least the following: i. The policies and manuals for comprehensive risk management, as well as any modifications made to them; ii. The exposure limits to the different types of risks identified by the entity; iii. The mechanisms for the implementation of corrective actions; and (1) iv. The cases or special circumstances in which exposure limits may be exceeded, as well as special controls on said circumstances; c) Validate: i. The methodology to identify, measure, control, mitigate, monitor, and communicate the different types of risks to which the entity is exposed, as well as any eventual modifications, ensuring that it considers the critical risks of the activities performed by the entity; and ii. The corrective actions proposed by the Risk Unit in case of deviation with respect to the assumed exposure levels or limits; d) Inform the Board of Directors about the risks assumed by the entity, their evolution, their effects on equity levels, and additional mitigation needs, as well as their corrective actions; e) Inform the Board of Directors about the execution of approved policies, ensuring that the entity's operations comply with the policies and procedures defined for risk management; f) Require and follow up on corrective plans to normalize non-compliance with exposure limits or reported deficiencies; and g) Inform the Board of Directors about the results of the reports prepared by the Risk Unit or whoever acts in their place.
The Risk Committee will review, at least once a year, what is stated in letters a), b), and c) of this article.
Meetings and agreements of the Risk Committee Art. 11.- The Risk Committee must meet with the necessary frequency to perform its functions effectively, at least once every three months. The persons in charge of the different areas involved in the operations that generate risks may participate in the sessions, with the right to speak but not to vote.
Risk Unit Art. 12.- The entity's Board of Directors, to facilitate the evaluation of comprehensive risk management, must create a specialized Risk Unit or designate a person from the entity, and provide it with sufficient resources to perform its function in accordance with the size, structure, and risk profile of the entity; in any case, it must ensure that there is independence of this with the business and operational areas, in order to avoid conflicts of interest and ensure adequate separation of functions and responsibilities. The object of said Unit must be to identify, measure, control, monitor, and communicate the risks that the entity faces in the development of its operations, whether they affect assets and liabilities within or outside the balance sheet, including, where applicable, the associated risks of the operations it carries out with the member companies of the financial conglomerate or business group. The foregoing does not limit the role of the different operational units in the identification, measurement, control, monitoring, and communication of the risks that the entity faces. The person in charge of the Risk Unit must have a profile in accordance with the functions to be performed, for which the entity must consider their academic training, experience, and training in stock markets and risk management.
Corporate Risk Unit Art. 13.- The functions of the Risk Unit may be performed by another unit of the same type, provided that it complies with what is established in the applicable legal framework and with the provisions established in these Standards and the adequate management of the risks of each of the entities under the respective Unit's charge is guaranteed, objectivity, adequate handling of conflicts of interest, independence of criterion, confidentiality, and access to information. In case the functions are performed by a Corporate Risk Unit, it must
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 9 of 30 CNBCR-12/2015 NRP-11 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ENTITIES IN STOCK MARKETS Approval: 15/07/2015 Validity: 10/08/2015 draft a minutes document containing the topics reviewed in said Committee. The Board of Directors of the entity subject to these Standards must have an original minutes point on the topics treated corresponding only to the entity and the supporting documents that the Corporate Risk Unit used to perform the identification, measurement, control, monitoring, and communication of the risks associated with the entity subject to these Standards. In addition to the global risk management analysis that the Risk Unit may perform, said Unit must explicitly pronounce itself on the analysis of the risk management of the entity subject to these Standards. In these cases, the Board of Directors of the entity will maintain responsibility for the execution of the functions defined in these Standards.
Functions and responsibilities of the Risk Unit Art. 14.- The Risk Unit must comply with at least the following functions: a) Identify, measure, control, monitor, and communicate the risks incurred by the entity within its various business units, in accordance with approved policies and methodologies; b) Design and propose to the Risk Committee the strategies, policies, procedures, and manuals necessary for the integral and specific management of identified risks, as well as their modifications for respective approval; c) Propose for approval the methodologies, models, and parameters for the management of the different types of risks to which the entity is exposed; d) Periodically inform the Risk Committee about the evolution of the main risks assumed by the entity, including details of changes in the applicable risk factors and the historical evolution of the risks assumed by the entity; e) Opine on the possible risks involved in the establishment of new products, operations, and activities as well as significant changes in the entity's business environment; f) Follow up on compliance with risk exposure limits, their tolerance levels by quantifiable risk type, and propose mitigation mechanisms for exposures and inform the Risk Committee; g) Periodically follow up on corrective actions presented by units for improvement in risk management, which must be made known to the Risk Committee and Senior Management; and h) Repealed; (1) i) Draft and propose to the Risk Committee the performance of stress tests in accordance with what is established in these Standards.
Training programs Art. 15.- Because integral risk management is a dynamic process, Senior Management must guarantee that employees and executives directly involved in risk management are trained in these topics, developing for this purpose an annual training plan, in which personnel to be trained, topics to be developed, and their scheduling are incorporated. Likewise, since this management involves the entire organization, a dissemination program must be established that generates an organizational risk culture among all employees and levels of the organization.
CHAPTER III RISK MANAGEMENT FRAMEWORK
Policies for risk management Art. 16.- Entities must develop policies to define the management framework for the different types of risks to which they are exposed as well as for third-party funds they administer, which allow them to reduce their vulnerability and losses from such risks and promote at the level of the entire organization a culture of prevention and risk control, ensuring compliance with internal and external norms related thereto. Risk management policies must consider, among other aspects, the functions and responsibilities in risk management, criteria, information systems, as well as mechanisms for identification, measurement, control, and mitigation of the risks presented by the entity. The entity's policies and procedures must be consistent with its structure, nature, size, complexity of its activities, operations, business lines, type of clients it serves, and with the duties applicable to its activity. These policies and procedures must also be in accordance with the operations authorized according to its object and applicable legal regime.
Risk management manual Art. 17.- Entities must have a risk management manual that, based on policies, groups for the management of each risk: the associated processes, the functions and responsibilities of the involved areas, indicating the segregation of functions of key positions susceptible to risks, the methodology for measuring risk detailing variables, criteria, tools used, and the periodicity with which information must be reported on exposure to each of the types of risks to the Risk Committee or whoever acts in its place, to the Board of Directors, or to Senior Management. The integral risk management manual must be a technical document that contains, in addition to the aspects mentioned in the previous paragraph, at minimum the following: information flow diagrams, risk matrix, categorization of loss events, models, methodologies, and calculations for the valuation of the different types of risks, stress tests, as well as the requirements for information processing systems and risk analysis.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 10 of 30 CNBCR-12/2015 NRP-11 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ENTITIES IN STOCK MARKETS Approval: 15/07/2015 Validity: 10/08/2015 For the development of the risk management manual, entities must consider the implementation of prudential measures and best practices referred to risk management. The Superintendence will know these documents and may request explanations and expansions, being able to recommend modifications when it deems pertinent, in attention to best practices.
For the case of entities that administer third-party funds or securitization funds, the aforementioned manual must include the management of risks associated with said funds.
CHAPTER IV MANAGEMENT BY TYPE OF RISK
Types of risks Art. 18.- For the purposes of these Standards, entities must manage the risks they assume according to their structure, size, business, and resources, as well as those assumed by the third-party funds they administer. Considering, when applicable, credit risk, counterparty risk, custody risk, liquidity risk, market risk, operational risk, and reputational risk. In the case of Risk Rating Agencies and General Warehouses, they must manage especially what corresponds to operational risk and reputational risk.
Credit Risk Art. 19.- Credit risk is understood as the possibility of loss due to the default of contractual obligations assumed by the issuer of a security or because the credit rating of the security, or in its absence, the issuer, has deteriorated. The management of this risk must consider, when applicable, the following aspects: a) Identify the factors or variables whose movements may originate an increase in credit risk; b) Establish limits or thresholds of credit concentration, charged to an issuer or group of issuers that must be considered as a single source of risk due to their patrimonial or liability links; c) Have mechanisms to monitor identified risk factors, performing an analysis of concentration of its investment portfolio as well as estimates of the trends they present, considering for this: individual exposures against the same issuer, linked issuers and related groups, issuers in the same economic sector or geographic region; d) Monitor and control the nature, characteristics, diversification, correlation, and quality of risk exposure, considering the type of investment or instrument related to the operations; e) Analyze the recovery value, as well as mitigation mechanisms and estimate the expected loss in the operation; and f) Establish measures to mitigate exposure to this risk.
Counterparty Risk Art. 20.- Counterparty risk is understood as the possibility of loss that may occur due to the default of contractual obligations assumed by a party for the settlement of an operation due to illiquidity, insolvency, operational capacity, or improper actions. The management of this risk must consider, when applicable, the following aspects: a) Identify and evaluate risk factors that may originate an increase in counterparty risk assumed by the entity; b) Establish limits or thresholds of concentration charged to one or a group of counterparties, which must be considered as a single source of risk due to their patrimonial or liability links; c) Analyze payment means; d) Analyze guarantees associated with operations carried out with counterparties, classifying assets as acceptable according to the entity's policies and risk profile; e) Establish valuation methods for guarantees taking into consideration existing market conditions; and f) Establish measures to mitigate exposure to this risk. In the case of product and services exchanges, mechanisms and procedures must be foreseen to verify the transfer of ownership of products and services, as well as to manage the settlement risk of operations carried out therein, considering the default of contracts and associated guarantees.
Custody Risk Art. 21.- Custody risk is understood as the possibility of loss affecting values held in custody due to insolvency, negligence, fraud, poor administration, or inadequate maintenance of records by a custodian. The management of this risk must consider, when applicable, the following aspects: a) Identify and evaluate risk factors; b) Establish necessary measures to safeguard assets and minimize the risk of loss; c) Establish measures that allow the entity to have the capacity to safeguard its own or third-party assets; and d) Establish measures to mitigate exposure to this risk. In the case of Custodians, they must have rules and procedures to safeguard the integrity of securities issuances and of securities holders, to avoid the unauthorized creation or elimination of securities; likewise, they must have safeguard procedures and internal controls that fully protect assets.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 11 of 30 CNBCR-12/2015 NRP-11 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ENTITIES IN STOCK MARKETS Approval: 15/07/2015 Validity: 10/08/2015
Liquidity Risk Art. 22.- Liquidity risk is understood as the possibility of incurring losses due to not having sufficient resources to meet assumed obligations. The management of this risk applies only for the administration of third-party funds carried out by entities subject to these norms and must consider, when applicable, the following aspects: a) Identify and evaluate risk factors; b) Establish minimum liquidity levels based on business and investment objectives, assumed risk profile, and redemption conditions of participation shares; c) Perform stress tests under a stress scenario based on the operations they carry out in accordance with assumptions or premises established individually according to the nature, complexity, vulnerability, and volume of operations performed by the entity; d) Elaborate contingency plans that incorporate actions to be taken in case of unexpected liquidity requirements, said plan must have roles and responsibilities of involved areas and events that activate the plan; e) Ensure that established liquidity levels are sufficient in relation to assumed obligations; f) Establish methodologies that quantify liquidity risk, which must relate to the level and risk profile, size, nature, complexity, and other characteristics of the entity's operations, as well as its liquidity indicators; g) Establish early warning indicators that allow identifying exposure to liquidity risk; h) Establish strategies to manage a potential lack of liquidity at the entity or systemic level; i) Establish a level of liquid assets free of any encumbrance, to be used in front of a series of liquidity stresses; and j) Establish measures to mitigate exposure to this risk.
Market Risk Art. 23.- Market risk is understood as the possibility of loss, resulting from movements in market prices that generate a deterioration in value in the entity's positions or the funds it administers. The management of this risk must consider, when applicable, the following aspects: a) Identify risk factors; b) Have a market analysis that allows monitoring identified risk factors; c) Evaluate significant variations in product and service prices, due to operations in product and services exchanges; d) Evaluate positions subject to market risk, using for this purpose models, tools, and limits that allow measuring potential loss in said positions associated with price movements, interest rates, or exchange rates; e) Evaluate the concentration, volatility, and correlation of positions subject to market risk; f) Establish a methodology to be used for the valuation of financial instruments classified for trading, defining in its case, the respective price sources; g) Monitor movements in interest rates and foreign currency of active and passive positions, when applicable; h) Establish measures to mitigate exchange rate risk; and i) Establish measures to mitigate exposure to this risk. In the case of entities that administer third-party funds, they must carry out a sensitivity analysis especially in extreme situations and simulation of scenarios. Likewise, they must evaluate the impact of interest rate risk on services provided by the entity and the launch of new products.
Operational Risk Art. 24.- Operational risk is understood as the possibility of incurring losses due to failures in processes, people, information systems, and due to external events; operational risk includes the management of information security, business continuity, and legal risk. Legal risk is understood as the possibility of occurrence of losses due to failures in the execution of contracts or agreements, non-compliance with norms, as well as external factors such as regulatory changes, judicial processes, among others. The management of operational risk must consider, when applicable, the following aspects: a) Identify operational risk events grouping them according to Annex No. 1 of these Standards, in such a way as to allow establishing its operational risk map; b) In the case of stock exchanges, product and services exchanges, houses, custodians, general warehouses, securitizers, and investment fund managers, the identification of events can be grouped additionally, according to the business lines the entity maintains, as expanded in Annex No. 2 of these Standards; c) Document processes that describe the functions of each organizational unit; d) Establish tolerance levels for each identified type of risk, defining their causes, origins, or risk factors; e) Analyze and order identified risks by priority, classifying them according to impact and probability on institutional objectives; f) Analyze exposure to potential losses due to various activities carried out by people participating in the administration business, processing errors, transactions, among others; g) Entities must form a centralized database that allows registering, ordering, classifying, and having information on operational risk events. These must be classified by factors, determining the frequency of the event and the effect produced, containing as minimum the fields detailed in Annex No. 3 of these Standards; h) Give systematic and timely follow-up to operational risk events; i) Manage risks adequately through action plans to treat the risk; and j) Regarding legal risk management, entities must consider at minimum the following: i. Establish specific policies and controls so that, prior to the celebration of legal acts, their validity is analyzed and adequate legal verification is sought. Likewise, these policies and procedures must contain aspects related to the orderly, complete, integral, and timely conservation of information and documentation supporting the entity's operations, establishing mechanisms that allow adequate control and follow-up of their legal and regulatory obligations, as well as follow-up and compliance with observations made by their supervisors; ii. Estimate the amount of potential losses derived from unfavorable judicial or administrative resolutions, as well as the possible application of sanctions, in relation to operations carried out. In said estimation, judicial litigations in which the entity is plaintiff or defendant, administrative procedures in which it participates, as well as litigations derived from the application of alternative means of conflict resolution must be included; iii. Analyze acts carried out by the entity when governed by a legal system different from the national one and evaluate the differences existing between the system in question and the national one, including what relates to the judicial procedure; iv. Ensure compliance with legal, regulatory, and contractual provisions to which the entity is subject and disseminate them to employees and Board of Directors members;
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 12 of 30 CNBCR-12/2015 NRP-11 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ENTITIES IN STOCK MARKETS Approval: 15/07/2015 Validity: 10/08/2015 v. Make applicable legal and administrative provisions known to its directors and employees; and vi. Maintain control of judicial and administrative resolutions, their causes, and costs.
Reputational Risk Art. 25.- Reputational risk shall be understood as the possibility of incurring losses due to the deterioration of the entity's image resulting from non-compliance with laws, internal norms, corporate governance codes, codes of conduct, money laundering regulations, service provision, technological failures, among others. The management of this risk must consider, where applicable, the following aspects: a) Identify and evaluate internal and external risk factors or events; b) Establish mechanisms to mitigate risks; c) Evaluate potential contagion risks that could affect the entity's reputation, impacting the entity's security and solvency levels; and d) Establish measures to mitigate exposure to this risk.
Business Continuity Management System (2) Art. 26.- Entities must implement a business continuity management system in the event of interruptions, which must include contingency plans, business impact analysis, disaster recovery plans, and incident management plans, ensuring normal business operations in the occurrence of adverse events. Business continuity plans must consider at a minimum the following: a) The identification of events that put business continuity at risk, the activities to be carried out to overcome them, operational alternatives, and the return to normal activities; b) The definition of roles and responsibilities for their implementation; c) The carrying out of necessary tests to confirm their effectiveness and efficiency, at least once a year; and d) The disclosure of the plan to all members of the entity.
Provision of Services by Third Parties Art. 27.- Entities must establish appropriate policies and procedures to evaluate, supervise, and monitor the performance of critical services provided by third parties, that is, those that could interrupt the normal development of operations defined in each entity's policies. The provision of services must be formalized through signed contracts, which include the scope of the service and clearly define the responsibilities of the provider and the entity, establishing the liaison person between the entity and the provider. Likewise, they must include a clause that obliges the provider to document the services provided, guaranteeing the adequate use of confidential information and the establishment of contingency and service continuity plans. Furthermore, clauses must be included that facilitate an adequate review of the respective service provision by the entities themselves or potentially by the Superintendence and other supervisory bodies. Likewise, entities must guarantee the continuity of activities provided by the provider in the event of problems such as non-compliance or revocation of the contract, among others. Entities must have a centralized control of all services provided by third parties, and as a minimum requirement, it must contain the name of the provider, the type of service, the contract amount, the counterparty within the entity, and its validity. This control must be available to the Superintendence whenever it is required. Regardless of whether certain services are performed by third parties, the entity is responsible for ensuring compliance with the provisions applicable to it.
CHAPTER V INFORMATION AND CONTROL SYSTEMS
Managerial Information Systems Art. 28.- The entity must have managerial information and statistical databases that enable the generation of timely, reliable, consistent, and homogeneous information that allows for the preparation of periodic reports for the Board of Directors, the Risk Committee, and Senior Management, as well as for other interested parties responsible for decision-making in risk management. Entities must send to the Superintendence, annually and no later than the thirtieth day of the year two thousand seventeen, sending it by electronic means or in the form determined by the Superintendence. Likewise, entities must remit operational risk events to the next business day after they occur; sending them by electronic means or in the form determined by the Superintendence.
Internal Control System Art. 29.- Integral risk management includes the internal control system that allows verifying compliance with the policies, limits, processes, and procedures established for the entity's risk management. For this purpose, entities must establish the administrative, financial, accounting, and technological controls necessary in accordance with international standards on the matter.
Role of Internal Audit Art. 30.- The Internal Audit Unit must include within its annual work plan, examinations of the work developed by the Risk Unit. In the case of entities not linked to financial conglomerates, they may subcontract this service.
CHAPTER VI INFORMATION TRANSPARENCY
Annual Report Art. 31.- Entities must submit to the Superintendence, within the first one hundred twenty days following the end of the reported accounting year, the Report of the Board of Directors, which must contain at a minimum the following: a) The organizational structure for integral risk management; b) Detail of the main risks assumed as well as those to which the entity is exposed due to its activities; c) Updated policies for integral risk management; d) Description of the methodologies, systems, and tools used for each of the risks; e) Results of the evaluations carried out on integral risk management and actions taken; f) Projects associated with risk management to be developed in the exercise following the reported one; g) Execution of the training plan related to integral risk management established in article 15 of these Norms; and h) General conclusions on the entity's risk management. For letters b) and e), entities must include statistics that allow for an analysis of the evolution of the entity's integral risk management, in those cases where these are quantifiable. Notwithstanding the above, the entity must inform the Superintendence within a maximum period of three business days upon becoming aware of any aspect related to risk exposure that could impact the entity qualitatively or quantitatively.
Disclosure on Integral Risk Management Art. 32.- Entities must disclose in a summarized manner in a section of their Website, which may in any case use the Website of the financial conglomerate or business group to which they belong, within the first ninety calendar days of each year, the information relating to the policies, methodologies, and other relevant measures adopted for the management of each type of risk. Entities must disclose in a summarized manner in the notes to the annual closing financial statements the way in which they manage risks and compliance with their policies.
CHAPTER VII OTHER PROVISIONS AND VALIDITY
Additional Information Art. 33.- The Superintendence may require entities to provide any additional information it considers necessary for the adequate supervision of integral risk management and of each of the specific risks to which the entity in question is exposed. Entities must have at all times available to the Superintendence all documents, records, and files, in physical, electronic, or any other medium, referred to in these Norms, as well as the information from audits or reviews conducted by their parent companies, in the case of entities whose parent company is located outside the country. Likewise, the Superintendence must have access to the documentation referred to in the previous paragraph, in cases where entities assign functions defined in these Norms to Committees or Risk Units.
Sanctions Art. 34.- Non-compliance with the provisions contained in these Norms will be sanctioned in accordance with what is established in the Law on Supervision and Regulation of the Financial System.
Unforeseen Aspects Art. 35.- Aspects not provided for in regulatory matters in these Norms will be resolved by the Standards Committee of the Central Bank.
Transitory Art. 36.- Subjects obliged to comply with these Norms, from the date of their validity, will have a maximum period of six months to submit to the Superintendence an Adaptation Plan to comply with the provisions established in these Norms. Once presented, entities must initiate and complete its execution within a period of twelve months, counted from the presentation thereof.
Validity Art. 37.- These Norms will enter into force as of August 10, two thousand fifteen.
MODIFICATIONS:
(1) Modifications to articles 7, 8, 10, and 14 approved by the Standards Committee of the Central Reserve Bank of El Salvador in Session No. CN-17/2020 dated October 21, two thousand twenty, with validity as of November 5, two thousand twenty. In order to maintain consistency with new regulations approved by the Standards Committee. (2) Modifications to articles 3 and 26 approved by the Standards Committee of the Central Reserve Bank of El Salvador in Session No. CN-04/2023 of June 28, two thousand twenty-three, with validity as of July 14, two thousand twenty-three.
Annex No. 1
TYPES OF EVENTS FOR OPERATIONAL RISK
| Type of Event (Level 1) | Definition | Type of Event (Level 2) | Examples |
|---|---|---|---|
| Internal Fraud. | Losses derived from any type of action aimed at defrauding, improperly appropriating goods, or evading regulations, laws, or corporate policies in which at least one member of the entity is involved. | Unauthorized Activities. | Unrevealed operations (intentional), unauthorized operations (with economic losses), erroneous valuation of positions (intentional). |
| Theft and Fraud. | Theft, embezzlement, forgery, bribery, misappropriation, smuggling, tax evasion (intentional). | ||
| External Fraud. | Losses derived from any type of action aimed at defrauding, improperly appropriating goods, or evading legislation, by a third party. | Theft and Fraud. | Theft, forgery. |
| System Security. | Damages from computer attacks, information theft. | ||
| Labor Relations and Workplace Safety. | Losses derived from actions incompatible with labor legislation or agreements, regarding hygiene or safety at work, regarding payment of claims for personal damages, or regarding cases related to diversity or discrimination. | Labor Relations. | Issues regarding remuneration, social benefits, termination of contracts. |
| Hygiene and Safety at Work. | Cases related to hygiene and safety standards at work; compensation to workers. | ||
| Diversity and Discrimination. | Any type of discrimination. | ||
| Clients, Products, and Business Practices. | Losses derived from the involuntary or negligent non-compliance with a corporate obligation towards specific clients (including fiduciary and suitability requirements), or of the nature of an obligation. | Suitability, Disclosure of Information, and Trust. | Breaches of trust/non-compliance with guidelines, suitability/disclosure aspects (reserved information, stock market information, customer knowledge, etc.), infringing on client information privacy, abuse of confidential information. |
| Improper Business or Market Practices in the Stock Market Industry. | Restrictive practices of competition, improper commercial/market practices, unauthorized securities intermediation, carrying out fictitious transactions, executing transactions to artificially fix or vary prices, market manipulation, abuse of insider information (in favor of the entity), money laundering. | ||
| Defective Products. | Product defects (unauthorized, etc.), error in contract models. | ||
| Selection, Sponsorship, and Risks. | Absence of client investigation according to guidelines, excess of risk limits towards clients. | ||
| Advisory Activities. | Litigation regarding results of advisory activities. | ||
| Damage to Physical Assets. | Losses derived from damage or harm to physical assets as a consequence of natural disasters or other events. | Disasters and Other Events. | Natural disasters, losses caused by external persons (terrorism, vandalism). |
| Business Interruption and System Failures. | Losses derived from interruptions in business or trading sessions and system failures. | ||
| Systems. | Deficiencies in information systems, hardware or telecommunications equipment; electrical power failures. | ||
| Execution, Delivery, and Process Management. | Losses derived from errors in the processing of operations or in process management, as well as relations with different counterparties. | Receipt, Execution, and Maintenance of Operations. | Data entry errors, errors in establishing asset or quota values, in receiving orders issued by the client, in handling guarantees, maintenance or download, non-compliance with deadlines or responsibilities, erroneous execution of trading models or systems, accounting errors. |
| Errors in the Process of Transfers of Securities, Clearing of Securities, and Cash Settlement. | |||
| Follow-up and Reporting. | Non-compliance with the obligation to inform, inaccuracy of external reports (with generation of losses). | ||
| Client Acceptance and Documentation. | Lack of authorizations or client rejections, non-existent or incomplete legal documents. | ||
| Client Account Management. | Unauthorized access to accounts, incorrect client records (with generation of losses), loss or damage of client assets due to negligence. | ||
| Commercial Counterparties. | Failures of counterparties other than clients, other litigations with counterparties other than clients. | ||
| Provision of Services by Third Parties, Distributors, and Suppliers. | Subcontracting, non-compliance with stipulated obligations (with generation of losses), litigations with suppliers. |
Annex No. 2
DETAIL OF BUSINESS LINES
| Level 1 | Level 2 | Activity Groups |
|---|---|---|
| STOCK EXCHANGES | ||
| Registration of Securities. | Authorization of Issuances. | Review of compliance with the legal and regulatory framework, authorization of the issuance by the Board of Directors, submission to the Superintendence, etc. |
| Registration of the Issuance. | Enablement of issuances in electronic trading systems. | |
| Trading and Custody of Securities. | Trading Systems and Platforms. | Administration of electronic trading and information transfer systems. |
| Information Systems. | Administration of information systems related to dissemination. | |
| Guarantees Received from Intermediaries. | Formalization of the receipt of guarantees, custody and administration of received guarantees, etc. | |
| Clearing and Monetary Settlement. | Monetary Settlement Systems for Operations. | Administration of the electronic settlement system, use of banking settlement mechanisms, etc. |
| Contingency Management. | Contingency plans for events that could affect the clearing and settlement process. | |
| DEPOSITARIES | ||
| Electronic Registration of Securities Issuances. | Creation of Authorized Issuances in the Registry. | Documentation of authorization of the issuance by the stock exchange and the Superintendence, prospectus, etc. |
| Legal Formalization. | Preparation of contracts. | |
| Maintenance of Issuances. | Update of interest rates, receipt and delivery of funds for the payment of equity rights. | |
| Registration in the Electronic System. | Creation of Securities Accounts. Necessary documentation for identification of holders and formation of files, etc. | |
| Securities Accounts. | Legal Formalization. | Preparation of contracts, etc. |
| Account Maintenance. | Periodic reviews, update of information, etc. | |
| Deposit, Custody, and Administration of Securities. | Deposits, Withdrawals, and Transfers. | Of local and foreign operations, authorizations, etc. |
| Exercise of Equity Rights. | Control of coupon maturity, Receipt and payment of periodic interest, etc. | |
| Clearing and Settlement of Securities. | Local Operations. | Receipt of electronic information, clearing and settlement, etc. |
| Foreign Operations. | Submission of electronic information to the Sub-Custodian, clearing and settlement, control of balance in bank accounts, etc. | |
| Electronic Shareholder Registry. | Creation of the Registry. | Necessary documentation for the identification of holders. |
| BROKERAGE FIRMS | ||
| Structuring of Issuances. | Structuring and Advisory. | Drafting of issuance contracts, analysis, prospectus, etc. |
| Preparation of Legal Documents. | Granting of contracts, processing of issuance authorization. | |
| Securities Intermediation and Stock Advisory. | Primary Market Placement. | Contract, deposit of securities, settlement and clearing, accounting registration, etc. |
| Local Stock Market Brokerage. | Contract, operation orders, trading, clearing and settlement, documentation of the advisory service, accounting registration, etc. | |
| International Stock Market Brokerage. | Contract, operation orders, trading, clearing and settlement, documentation of the advisory service, accounting registration, etc. | |
| Custody of Securities. | Custody of Securities. | Withdrawal, deposit, and transfer of securities, documentation, etc. |
Level 1 Level 2 Activity Groups Exercise of property rights. Receipt and payment of cash, periodic interest on issuances, redemption and maturity of securities, etc. Individual Portfolio Management Asset Management. Investment registration, investment strategy or policy according to what is established by the client, portfolio analysis, registration and custody of securities, asset valuation methodology, etc. Securities Brokerage in local market. Contract, operation orders, negotiation, clearing and settlement, accounting registration, etc. Securities Brokerage in international market. Contract, operation orders, negotiation, clearing and settlement, accounting registration, etc. ASSET SECURITIZERS Issuance Structuring. Structuring and Advisory. Securitization contracts, purchase and sale of assets, assignment of cash flows, etc. Training and Financial Analysis. Feasibility analysis for securitization, training for originator personnel. Administration of Securitization Funds. Administration of Assets. Control and administration of securitized assets, prepayments, etc. Administration of Securities Issuance. Control and administration of the issuance of securitized securities, payment of property rights, maturity and redemption of securities, etc. Treasury. Management and control of funds generated by assets. PRODUCT AND SERVICE EXCHANGES Product and Service Transactions. Authorizations. Authorization of exchange positions, stock agents, licensees, etc. Contract Registration. Registration of contracts for contracts and services, guarantees, advisory services, etc. Contracting Systems. Contracting platforms and systems, surveillance of settlement, etc. GENERAL WAREHOUSES
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 28 of 30 CNBCR-12/2015 NRP-11 TECHNICAL STANDARDS FOR THE INTEGRAL MANAGEMENT OF RISKS OF ENTITIES IN STOCK MARKETS Approval: 15/07/2015 Validity: 10/08/2015 Annex No. 2 DETAIL OF BUSINESS LINES
Level 1 Level 2 Activity Groups Custody and Storage of Goods. Storage in Own Warehouse. Issuance of certificates and bonds, file formation, commissions, insurance, etc. Storage in Fiscal Warehouse. Issuance of certificates and bonds, authorization and validity of Customs, requirements, file formation, commissions, guarantee letters, insurance, etc. Storage in Licensed Warehouse. Lease contracts, issuance of certificates and bonds, file formation, commissions, etc. Unconsolidation of Goods. Unconsolidation of goods. Unconsolidation, loading and unloading of goods, etc. MANAGEMENT COMPANIES
Investment Fund Management.
Asset Management.
Investment registration, investment strategies according to the internal regulations of the fund to be managed, portfolio analysis, divestment processes, registration and custody of assets, etc.
Accounting Systems of Managed Funds. Accounting systems, asset valuation methodology and share value calculation, presentation of the performance of the managed fund, preparation of information directed at participants. Marketing of Participation Shares. Subscription and Redemption of Participation Shares. Offer of participation shares, request for contribution and redemption, registration of participants, calculation of number of shares and information provided to participants.
n
More like this from SSF
We email you every new SSF publication the day it's published.