2020-02-26 | NRP-21

Added · Updated

Technical Standards for the Comprehensive Risk Management of Pension Entities

The Committee of Norms of the Central Reserve Bank of El Salvador issued these standards to establish prudential provisions for Pension Fund Administrators and Pension Institutes. The document mandates the implementation of a comprehensive risk management system encompassing identification, measurement, control, mitigation, and monitoring of risks. It requires entities to maintain a segregated organizational structure, a Risk Committee, and an independent Risk Unit, with Board approval of policies due within ten business days.

Superintendencia del Sistema Financiero logo

El Salvador

Superintendencia del Sistema Financiero

Click to view thumbnail

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 29 CNBCR-03/2020 NRP-21 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES Approval: 02/26/2020 Validity: 04/01/2020

THE COMMITTEE OF NORMS OF THE CENTRAL RESERVE BANK OF EL SALVADOR, CONSIDERING:

I. That Article 3, first clause and literal c) of the Law for the Supervision and Regulation of the Financial System, establishes that it is the responsibility of the Superintendency of the Financial System to proactively monitor the risks of the members of the financial system and the manner in which they manage them, ensuring the prudent maintenance of their solvency and liquidity.

II. That Article 7 of the Law for the Supervision and Regulation of the Financial System establishes that the members of the Financial System are the Pension Fund Administrators, the National Institute of Pensions for Public Employees, the Salvadoran Institute of Social Security (with respect to the Public Pension System, the Occupational Risks Regime, and health technical reserves), and the Social Security Institute of the Armed Forces.

III. That through Legislative Decree No. 615, of December 20, 2022, published in the Official Journal No. 241, Volume No. 437 of the 21st of the same month and year, the Law for the Creation of the Salvadoran Institute of Pensions was approved, which is established as a public law institution, which, among other things, will respond for the obligations previously acquired and which currently correspond to the National Institute of Pensions for Public Employees, as well as the competencies and attributes, rights and obligations, assets, liabilities, and equity of the latter. (3)

IV. That Article 2 of the Law for the Creation of the Salvadoran Institute of Pensions establishes in its third clause that the aforementioned Institute shall be governed, among other things, by what is provided in the Law for the Supervision and Regulation of the Financial System, as well as by the regulations issued for such effect by the Committee of Norms of the Central Reserve Bank of El Salvador. (3)

V. That Article 3 of the Law for the Creation of the Salvadoran Institute of Pensions establishes in its second clause that the Central Reserve Bank of El Salvador, through its Committee of Norms, will establish the aspects that the aforementioned Institute must include in its risk management policies. (3)

VI. That Article 48 of the Integral Law of the Pension System establishes that, without prejudice to the regulations and intervention of competent entities, Pension Administrators must elaborate internal prudential control policies that allow them to adequately manage their financial, regulatory, and operational risks, and must submit them for approval to their respective boards of directors, for which they must, in any case, adhere to international prudential control standards and the corresponding regulations. (3)

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 29 CNBCR-03/2020 NRP-21 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES Approval: 02/26/2020 Validity: 04/01/2020

VII. That Article 35, literal d) of the Law for the Supervision and Regulation of the Financial System, stipulates that directors, managers, and other officials holding positions of direction or administration of the members of the financial system, must conduct their business, acts, and operations complying with the highest ethical standards of conduct, acting with the due diligence of a good merchant in their own business, being obligated to comply with and ensure that in the institution they direct or work in, the adoption and updating of policies and mechanisms for risk management are fulfilled, including among other actions, identifying, evaluating, mitigating, and revealing them in accordance with international best practices. (3)

VIII. That Article 99, literal a) of the Law for the Supervision and Regulation of the Financial System, stipulates that it will be the responsibility of the Committee of Norms to approve technical standards, instructions, and provisions that the laws regulating the supervised entities establish must be issued to facilitate their application, including aspects inherent to risk management by the supervised entities. (3)

IX. That among the activities developed by Pension Fund Administrators are the administration of Pension Funds, including individual savings accounts for pensions, investments with the resources of said funds, and the granting of benefits to affiliates of the Pension System, which requires management and control mechanisms that allow establishing that they are carried out in accordance with the Integral Law of the Pension System and the current legal framework. (3)

X. That among the activities developed by Pension Institutes is the granting and control of benefits to affiliates of the Public Pension System, administration of funds for the payment of pensions, which requires management and control mechanisms that allow establishing that they are carried out in accordance with the Integral Law of the Pension System and the current legal framework. (3)

XI. That Pension Entities must know the risks to which Pension Funds are exposed and manage them adequately in the best interest of affiliates and pensioners. In this sense, entities must implement solid risk management mechanisms that allow them to optimize the control of their operations and minimize risks and their impacts, in such a way that a correct administration of the resources of the Funds is achieved. (3)

THEREFORE,

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 29 CNBCR-03/2020 NRP-21 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES Approval: 02/26/2020 Validity: 04/01/2020

by virtue of the regulatory powers conferred by Article 99 of the Law for the Supervision and Regulation of the Financial System, AGREES to issue the following:

TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES

CHAPTER I OBJECTIVE, SUBJECTS, AND TERMS

Objective Art. 1.- These Standards have as their objective to establish prudential provisions of a general nature to strengthen the comprehensive management of risks that obligated subjects must observe in accordance with applicable laws and international standards in the matter, in accordance with the nature and scale of their activities. These Standards complement the current general regulatory framework, of which they form part -17), approved by the Central Bank through its Committee of Norms.

Subjects Art. 2.- The subjects obligated to comply with the provisions established in these Standards are: a) Pension Fund Administrators; (3) b) Social Security Institute of the Armed Forces; c) The Salvadoran Institute of Pensions; and (3) d) The Salvadoran Institute of Social Security, with respect to the Public Pension System, the Occupational Risks Regime, and health technical reserves.

Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Senior Management: The Executive President, Executive Director, General Director, General Manager, or acting equivalent, and executive positions that report to them, as well as the heads of entities that do not have the figure of executive president; b) Risk Appetite: The level and types of risks that an entity is willing to assume in relation to its activities, to achieve its strategic objectives and business plan; c) Business Area: It is a specialization of the business that groups processes aimed at generating products and services to serve a target market segment; d) Central Bank: Central Reserve Bank of El Salvador; e) Client or Users: Natural or legal person who maintains a contractual relationship with the entity for the provision of services or financial products that it offers, which in these Standards may refer to: contributors, affiliates, pensioners, participants, beneficiaries, among others; f) Conflict of Interest: Any situation in which it can be perceived that a personal benefit or interest of a third party can influence the judgment or professional decision of a member of the entity regarding the fulfillment of their obligations; g) Comprehensive Risk Management Culture: Norms, attitudes, and behavior of an entity related to risk and decisions on how to manage and control them; h) Operational Risk Event: It is an event or series of events of internal or external origin, which may or may not result in financial losses for the entity; i) Pension Entities or Entities: For the purposes of these Standards, Pension Fund Administrators, the Social Security Institute of the Armed Forces, the Salvadoran Institute of Pensions, and the Salvadoran Institute of Social Security are considered Pension Entities; (3) j) Fund(s): Pension Funds and Voluntary Pension Savings Fund; k) Risk Factors: They represent those variables that entities must consider for adequate identification and mitigation of the risks to which they are exposed; l) Operational Risk Factor: It is the primary cause or origin of an operational event; m) Pension Institutes: For the purposes of these Standards, the following will be considered Pension Institutes: Social Security Institute of the Armed Forces, Salvadoran Institute of Pensions, and the Salvadoran Institute of Social Security; (3) n) Mitigation Measures: Set of actions implemented by pension entities to technically manage risks, so that potential losses derived from their materialization are minimized; (3) o) Risk Map: It is a tool that allows presenting an overview of the risks to which the entity is exposed; independent of the form of its presentation, in which the areas/activities/assets (processes) that could be affected during the occurrence of an adverse event are identified and located. It allows seeing threats and measuring the magnitude of each risk (probability and economic impact). They are a graphical management instrument of risks that allows comparing risks by their relative importance, as well as collectively, allowing the entity to establish acceptable levels of risk; p) Board of Directors: A collegiate body or equivalent body in charge of the administration of the entity, with functions of supervision, direction, and control;

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 29 CNBCR-03/2020 NRP-21 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES Approval: 02/26/2020 Validity: 04/01/2020

q) Risk Profile: Evaluation at a specific moment in time of the exposure to risk; r) Action Plans: Consists of a set of corrective measures proposed by the entity. These action plans contain activities, responsible parties, and completion dates; s) Process: It is the set of activities that transform inputs into products or services with value for the user, whether internal or external; t) Stress Tests: Scenarios used to evaluate and measure the resistance, vulnerability, and stability of an entity or financial system against the occurrence of possible extreme adverse events, and their impact on equity and/or the financial results of an entity; (3) u) Inherent Risk: Level of risk inherent to the activity, without taking into account the effect of controls; v) Residual Risk: Level resulting from risk after applying controls. It is the risk that remains, once the appropriate controls for its treatment have been implemented. In any case, it requires permanent monitoring to observe its evolution; (3) w) Superintendency: Superintendency of the Financial System; and (3) x) Risk Tolerance: Levels of risk-taking acceptable to achieve a specific objective or manage a category of risk. Risk tolerance represents the practical application of risk appetite and, generally, is aligned with categories of risk, such as; strategy, finance, people, or reputation. (3)

CHAPTER II ON COMPREHENSIVE RISK MANAGEMENT

Comprehensive Risk Management Art. 4.- Pension Entities must establish a comprehensive risk management system, which shall be understood as an integral process carried out by the entire entity, through which they identify, measure, control, mitigate, monitor, and communicate the different types of risks to which they are exposed, considering the funds administered and the interrelationships that arise among them for the achievement of their objectives. Such management must be in accordance with their risk profile, volume, and complexity of their activities, business areas, own and third-party resources, as well as the funds administered, so as to promote the implementation of measures in accordance with best practices for the transparent, efficient, and orderly functioning of the market. The integral process for risk management must be duly documented and reviewed periodically, based on changes that occur in the entity's risk profile and in the market. The policies, procedures, and manuals issued by the entities must be in the Spanish language.

Stages of the comprehensive risk management process Art. 5.- Entities must have a continuous and documented process for the comprehensive management of their risks and the funds they administer, which must contain at least the following stages: a) Identification: It is the stage in which existing risks are recognized and understood in each operation, product, service, and process that the entity develops for the administration of funds. In this stage, risk factors are identified that are variables and whose movements can generate changes in the equity of the entity or in that of the funds it administers; b) Measurement: It is the stage in which risks must be measured quantitatively or qualitatively, in order to determine the compliance or adequacy of policies, the established limits, and to measure the possible economic impact on the financial results of the entity, as well as the Funds it administers. The methodologies and tools to measure risks must be in accordance with the size and nature of their operations and the levels of risks assumed; c) Control and Mitigation: This stage refers to the actions or coverage and control mechanisms implemented by the entity that allow permanent follow-up of risk factors with the aim of preventing, transferring, or reducing negative effects on the funds they administer, in case the adverse events that are triggers for the identified and managed risks materialize; and d) Monitoring and Communication: It is the stage in which systematic and permanent follow-up is given to risk exposures and the results of adopted actions. The computer systems or tools used must ensure a periodic and objective review of risk positions and the generation of sufficient information, to support decision-making processes and allow communicating the results of risk management in a timely manner.

Functional and Communication Structure Art. 6.- Entities must establish an organizational structure, in accordance with their business model and duly segregated, that delimits their hierarchical levels, functions and responsibilities, levels of dependence and interrelationship that correspond to each of the business areas, operational support, and control that participate in the risk management process to which they are exposed. All in accordance with the size, nature of their operations, and funds administered; this structure must be designed considering that there are adequate communication channels in the organization, in its functional and transversal form.

Entities will establish and apply the methodologies they consider appropriate for the risk management model, without prejudice to the norms and minimum requirements established by the Central Bank through its Committee of Norms.

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 5 of 29 CNBCR-03/2020 NRP-21 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES Approval: 02/26/2020 Validity: 04/01/2020

Functions of the Board of Directors or Equivalent Management Body Art. 7.- The Board of Directors or equivalent management body is responsible for ensuring adequate comprehensive management of the entity's risks and the funds administered by it, having among its functions at least the following: a) Define and approve the entity's risk appetite and tolerance, approve the exposure limits of each risk in particular according to its profile, and must establish the respective controls for exceptions and deviations to said limits; b) Approve the internal organizational or functional structure according to its business model, with their respective organization manuals and segregation of functions, assigning the necessary resources to implement and maintain adequate risk management, effectively and efficiently, including training programs; c) Approve the policies and manuals for the management of risks assumed by the entity, ensuring that they are implemented; d) Create the Risk Committee in accordance with what is established in the -17) approved by the Central Bank, through its Committee of Norms, establishing the designation and removal of its members, when applicable, and ensuring their independence; e) Create the Risk Unit and appoint the person in charge of it, ensuring its independence from business and operational areas to avoid conflicts of interest and ensure adequate separation of functions and responsibilities, as well as providing it with the resources, tools, materials, and adequate technical training; f) Know and understand all the risks inherent to the business developed by the entity and to which the entity is exposed, its evolution and its effects, especially at the equity levels; as well as the methodologies and tools for risk management; g) Approve the entity's involvement in new products, services, operations, and activities; and ensure that these adhere to its business strategies and management policies; h) Ensure that an organizational culture of risk management is implemented within the entity; i) Ensure that internal audit verifies the existence and compliance of the entity's risk management scheme. The policies and manuals for risk management approved by the Board of Directors must be sent to the Superintendency for its knowledge within the first ten business days following their approval or respective modification. The period between reviews and/or updates on Policies or Manuals must not exceed two years.

In no case can the functions established in this article contradict the obligations contained in the applicable legal framework for pension institutes.

Risk Committee Art. 8.- Entities must have a Risk Committee which shall observe what is established in these Standards and in the -17) approved by the Central Bank, through its Committee of Norms.

Functions of the Risk Committee Art. 9.- The functions of the Risk Committee will include, at minimum, the following activities: a) Approve the following: i. The methodologies to manage the different types of risks to which the entity is exposed and the funds it administers, as well as any eventual modifications, ensuring that it considers the critical risks of the activities it performs; ii. The mechanisms for the implementation of corrective actions; and iii. The corrective actions proposed by the Risk Unit and the areas involved in case there is deviation with respect to the assumed exposure levels or limits. b) Evaluate, endorse, and propose for approval by the Board of Directors, at least the following: i. The strategies, policies, manuals, and methodologies for comprehensive risk management, as well as any eventual modifications made to them; ii. The tolerance limits for the exposure of the different types of risks identified by the entity; in accordance with its risk appetite; and iii. The cases or special circumstances in which exposure limits may be exceeded, as well as the special controls on said circumstances. c) Require and follow up on action plans to normalize non-compliance with exposure limits or reported deficiencies; d) Inform the Board of Directors about the exposures, deviations, and exceptions of the risks managed in the entity; e) Inform the Board of Directors about the risks assumed by the entity, its evolution, its effects, especially at the equity levels, and the additional mitigation needs, as well as its associated action plans; f) Inform the Board of Directors of the execution of approved policies, according to the periodicity established in each of them, ensuring that the entity's operations comply with the policies and procedures defined for comprehensive risk management; and g) Inform the Board of Directors about the results of the reports prepared by the

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 6 of 29 CNBCR-03/2020 NRP-21 TECHNICAL STANDARDS FOR THE COMPREHENSIVE RISK MANAGEMENT OF PENSION ENTITIES Approval: 02/26/2020 Validity: 04/01/2020

[Text ends abruptly in source]