2020-02-26 | NRP-22Added · Updated
The Central Bank of Reserve of El Salvador mandates that Electronic Money Provider Companies establish an integral risk management system to identify, measure, control, mitigate, and monitor risks. The Standards require the creation of independent Risk Units and Risk Committees, with the Board of Directors approving risk appetite and tolerance limits. Entities must submit approved risk policies and manuals to the Financial System Superintendence within ten business days and conduct annual internal audits.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
THE STANDARDS COMMITTEE OF THE CENTRAL BANK OF RESERVE OF EL SALVADOR,
CONSIDERING:
I. That Article 2, paragraph 3 of the Law for Facilitating Financial Inclusion establishes that Electronic Money Provider Companies are members of the financial system.
II. That in accordance with Article 3, letter c) of the Law for the Supervision and Regulation of the Financial System, it is the responsibility of the Financial System Superintendence to proactively monitor the risks of the members of the financial system and the manner in which they manage them, ensuring the prudent maintenance of their solvency and liquidity.
III. That in accordance with Article 35, letter d) of the Law for the Supervision and Regulation of the Financial System, it is stipulated that directors, managers, and other officials holding positions of direction or administration in the members of the financial system must conduct their business, acts, and operations complying with the highest ethical standards of conduct and acting with the due diligence of a good merchant in their own business, being obligated to comply with and ensure that in the institution they direct or work for, the adoption and updating of policies and mechanisms for risk management are fulfilled, including among other actions, identifying, evaluating, mitigating, and disclosing them in accordance with international best practices.
IV. That Article 99, letter a) of the Law for the Supervision and Regulation of the Financial System stipulates that it will be the responsibility of the Standards Committee to approve technical standards, instructions, and provisions that the laws regulating the supervised entities establish must be issued to facilitate their application, including aspects inherent to risk management by the supervised entities.
V. That in accordance with international standards, it is necessary to have a solid risk management framework that allows for the integral management of risks according to the profile, magnitude of activities, business, resources of the entity, and best practices, in such a way that it promotes the implementation of prudential measures for the transparent, efficient, and orderly functioning of the market.
THEREFORE,
by virtue of the regulatory powers conferred by Article 99 of the Law for the Supervision and Regulation of the Financial System,
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
AGREES to issue the following:
TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
CHAPTER I OBJECTIVE, SUBJECTS, AND TERMS
Objective Art. 1.- These Standards aim to establish the minimum elements that entities must observe for the integral management of risks in accordance with applicable laws and international standards in the matter, consistent with the nature and scale of their activities.
Subjects Art. 2.- The subjects obligated to comply with the provisions established in these Standards are the Electronic Money Provider Companies.
Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning:
a) Senior Management: The Chief Executive President, Executive Director, General Manager, or whoever acts in their stead, and the executive positions that report to them;
b) External Events: Events associated with the nature or caused by third parties, which escape in terms of cause and origin from the control of the entity;
c) Risk Appetite: The level and types of risks that an entity is willing to assume in relation to its activities, to achieve its strategic objectives and business plans;
d) Central Bank: Central Bank of Reserve of El Salvador;
e) Client: Natural person holder of an electronic money registry;
f) Conflict of Interest: Any situation in which it can be perceived that a personal benefit or interest of a third party may influence the professional judgment or decision of a member of the entity regarding the fulfillment of their obligations;
g) Integral risk management culture: Standards, attitudes, knowledge, and behavior of an entity related to risk and decisions on how to manage and control them;
h) Electronic Money: Monetary value registered in favor of a holder or client, which constitutes a payment obligation enforceable against their Electronic Money Provider, which is accepted by other actors who have agreed to receive or provide this service, as a means of payment in an amount equivalent to the cash delivered, and is stored in an electronic medium;
i) Entity: Subject obligated to comply with the provisions established in these Standards;
j) Operational risk event: An event or series of events, of internal or external origin, that may or may not result in financial losses for the entity;
k) Operational risk factor: The primary cause or origin of an operational event;
l) Board of Directors: A collegiate body or equivalent body in charge of the administration of the entity, with functions of supervision, direction, and control;
m) Business Line: A specialization of the business that groups processes aimed at generating products and services to serve a target market segment;
n) Risk Map: A tool that allows presenting an overview of the risks to which the entity is exposed; independent of the form of its presentation, in which the areas/activities/assets (processes) that could be affected during the occurrence of an adverse event are identified and located. It allows seeing the threats and measuring the magnitude of each risk (probability and economic impact). They are a graphical instrument for risk management that allows comparing risks by their relative importance as well as collectively, allowing the entity to establish acceptable levels of risk;
o) Mitigation measures: Set of actions taken by entities to technically manage risks, so that potential losses derived from their materialization are minimized;
p) Action plans: Consist of a set of corrective measures proposed by the entity. These action plans contain the objectives, activities, responsible parties, and completion dates;
q) Risk Profile: Consolidated result of the measurement of the risks to which an entity is exposed;
r) Personnel: The set of collaborators linked directly or indirectly with the execution of the entity's processes;
s) Process: The set of interrelations of activities for the transformation of input elements into products or services, to satisfy a need;
t) Inherent risk: Level of risk inherent to the activity, without taking into account the effect of controls;
u) Residual risk: Level resulting from the risk after applying controls. It is the risk that remains, once the pertinent controls for its treatment have been implemented. In any case, it requires permanent monitoring to observe its evolution;
v) Superintendence: Financial System Superintendence; and
w) Information Technology: The set of technological tools used to support the entity's processes.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
CHAPTER II ON INTEGRAL RISK MANAGEMENT
Integral Risk Management Art. 4.- Electronic Money Provider Companies must establish a system of integral risk management, which shall be understood as a strategic process carried out by the entire entity, through which they identify, measure, control, mitigate, monitor, and communicate the different types of risks to which they are exposed and the interrelations that arise between them, for the achievement of their objectives. Such management must be in accordance with their nature, risk profile, volume, and complexity of their activities, business lines, own and third-party resources, in such a way that it promotes the implementation of measures consistent with best practices for the transparent, efficient, and orderly functioning of the market.
The integral process for risk management must be duly documented and periodically reviewed based on changes that occur in the entities' risk profile and in the market. The policies, procedures, and manuals issued by the entities must be in Spanish.
Stages of the integral risk management process Art. 5.- Entities must have a continuous documented process for the integral management of their risks, which must contain at least the following stages:
a) Identification: This is the stage in which existing risks in each operation, product, service, process, and business line that the entity develops, and those that may occur in new business lines, are recognized and understood. In this stage, the risk factors that can generate changes in the entity's equity are identified;
b) Measurement: This is the stage in which risks must be quantified in order to determine compliance or adequacy of policies, fixed limits, and measure the possible economic impact on the entity's financial results. The methodologies and tools for measuring each type of risk must be in conformity with the size, nature of their operations, and the levels of risks assumed by the entity;
c) Control and mitigation: This is the stage that seeks to ensure that the policies, limits, and procedures established for the treatment and mitigation of risks are appropriately taken and executed; and
d) Monitoring and communication: This is the stage that gives systematic and permanent follow-up to risk exposures and the results of adopted actions. These information systems must ensure a periodic and objective review of risk positions and the generation of sufficient information to support decision-making processes and allow communicating the results of risk management in a timely manner.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
CHAPTER III ENVIRONMENT FOR INTEGRAL RISK MANAGEMENT
Organizational System Art. 6.- Entities must establish an organizational structure that allows for adequate integral risk management, with the proper segregation of functions and hierarchical levels of operational support, business, and control areas that participate in the process, as well as levels of dependency, in accordance with the risk profile, size, and nature of their operations.
Entities will establish and apply the methodologies they consider appropriate for the risk management model, without prejudice to the standards and minimum requirements established by the Central Bank through its Standards Committee.
Functions of the Board of Directors or Equivalent Management Body Art. 7.- The Board of Directors is responsible for ensuring adequate integral risk management, having among its functions at least the following:
a) Define and approve the entity's risk appetite and tolerance, as well as the exposure limits of each particular risk according to its profile; likewise, it must establish the respective controls for exceptions and deviations from said limits;
b) Approve the internal organizational or functional structure according to its business model, with their respective organization manuals and segregation of functions, assigning the necessary resources to implement and maintain adequate risk management, effectively and efficiently;
c) Approve the policies and manuals for the management of risks assumed by the entity, ensuring that they are implemented;
d) Create the Risk Committee, as established in the "Technical Standards of Corporate Governance" (NRP-17) approved by the Central Bank, through its Standards Committee, approving the appointment and removal of its members, when applicable, and ensuring its independence;
e) Create the Risk Unit and appoint the person in charge of it, ensuring its independence from the entity's business and operational areas to avoid conflicts of interest, as well as the separation of functions and corresponding responsibilities, and providing it with adequate material resources and technical training;
f) Know and understand all the risks inherent to the businesses the entity develops and to which it is exposed, their evolution and effects, especially at the equity levels; as well as the methodologies and tools for risk management;
g) Ensure that an organizational culture of risk management is implemented within the entity; and
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 5 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
h) Ensure that Internal Audit verifies the existence and compliance of the entity's integral risk management scheme.
The policies and manuals for risk management approved by the Board of Directors must be sent to the Superintendence for its knowledge within the first ten business days following their approval or respective modification. The period between reviews and/or updates on the Policies or Manuals must not exceed two years.
Risk Committee Art. 8.- Entities must have a Risk Committee which shall observe what is established in these Standards and in the "Technical Standards of Corporate Governance" (NRP-17) approved by the Central Bank, through its Standards Committee.
Functions of the Risk Committee Art. 9.- The functions of the Risk Committee or its equivalent shall comprise, at minimum, the following activities:
a) Approve the following: i. The methodologies to manage the different types of risks to which the entity is exposed, as well as their eventual modifications, ensuring that the same considers the relevant risks of the activities it performs; ii. The mechanisms for the implementation of corrective actions; and iii. The corrective actions proposed by the Risk Unit and the areas involved in case there is deviation with respect to the assumed exposure levels or limits.
b) Require and follow up on corrective plans to normalize non-compliance with exposure limits or reported deficiencies;
c) Evaluate, endorse, and propose for Board of Directors approval, at least, the following: i. The strategies, policies, and manuals for integral risk management, as well as the eventual modifications made to them; ii. The tolerance limits for the exposure of the different types of risks identified by the entity, consistent with its risk appetite; and iii. The cases or special circumstances in which exposure limits may be exceeded, as well as the special controls on said circumstances.
d) Inform the Board of Directors about the exposures, deviations, and exceptions of the risks that are managed in the entity, their evolution, their effects, especially at the equity levels, and the additional mitigation needs, as well as their corrective actions;
e) Inform the Board of Directors about the execution of the approved policies, according to the periodicity established in each of them, ensuring that the entity's operations adjust to the policies and procedures defined for risk management; and
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 6 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
f) Inform the Board of Directors about the results of the reports prepared by the Risk Unit or whoever acts in their stead.
Risk Committee Meetings and Agreements Art. 10.- The Risk Committee or whoever acts in their stead must meet with the necessary frequency to perform its functions effectively, at least once every three months. The persons in charge of the different areas involved in the operations that generate risks may participate in the sessions, with the right to speak but without the right to vote.
Functions of Senior Management Art. 11.- Senior Management is responsible for the establishment and execution of the structural framework of the risk management system and must report to the Board of Directors, adopting and ensuring compliance with, at minimum, the following measures:
a) Establish the necessary conditions at the organizational level to foster an environment that promotes the development of the integral risk management process;
b) Ensure that mechanisms exist that guarantee adequate flow, quality, and timeliness of information, between the Business Units and the Risk Unit or whoever acts in their stead, so that the latter appropriately develops its function;
c) Ensure the establishment of mechanisms for the dissemination of the integral risk management culture, at all levels of the organizational structure; and
d) Ensure the execution of training and updating programs for the entity's risk management.
Risk Unit Art. 12.- Entities must have a specialized unit to facilitate the evaluation of integral risk management, and may also designate additional units to supervise and manage specific risks. The Board of Directors of each entity shall create said unit and in turn appoint its responsible person; its size and scope must be related to the size, structure, and risk profile of the entity. Its object must be to identify, measure, control, monitor, and inform about the risks they face in the development of their operations, whether these affect assets and liabilities inside or outside the balance sheet.
This unit must be independent of the business units, or any other operational or support area, in order to avoid conflicts of interest and ensure adequate separation of functions and responsibilities, and its hierarchical position must allow it access to the necessary information for the performance of its functions and ensure that its reports are known by the Board of Directors or by the instance it delegates.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 7 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
The Risk Unit or person in charge must prepare an annual work plan, which must be approved by the Risk Committee, for the purposes of adequately fulfilling risk management functions.
The person in charge of the Risk Unit must have a profile consistent with the functions to be performed; for this, the entity must consider their academic background, experience, and training in risk management.
Functions and Responsibilities of the Risk Unit Art. 13.- The Risk Unit or the corresponding person in charge must fulfill at least the following functions:
a) Identify, measure, control, monitor, and communicate the risks in which the entity incurs within its various business units and their effects on the entity's solvency;
b) Prepare the annual work plan of the Unit and submit it for approval to the Risk Committee;
c) Design and propose to the Risk Committee for Board of Directors approval the strategies, policies, procedures, and respective manuals for the integral management of risks and of each of the specific risks identified, as well as their modifications;
d) Propose for approval the methodologies, models, and parameters for the management of the different types of risks to which the entity is exposed;
e) Periodically inform the Risk Committee or whoever acts in their stead, as well as Senior Management, about the evolution of the main risks assumed by the entity, including the detail of changes in applicable risk factors and the historical evolution of the risks assumed by it;
f) Periodically follow up on the corrective actions presented by the units for the improvement in integral risk management, which must be made known to the Risk Committee and Senior Management;
g) Follow up on the compliance of risk exposure limits, their quantifiable tolerance levels by type of risk, and propose mitigation mechanisms for exposures and inform the Risk Committee; and
h) Perform periodic monitoring of the results of the application of methodologies, tools, models, and compliance with tolerance limits.
Training Programs Art. 14.- Due to the fact that integral risk management is a dynamic process, Senior Management must guarantee that the Board of Directors, employees, and executives directly involved in risk management are trained in these subjects, developing for this purpose an annual training plan, which may be incorporated into the entity's general annual training plan, in which personnel to be trained, topics to be developed, and their scheduling are included. Likewise, since this management involves the entire organization, a dissemination program must be established that generates and
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 8 of 20 CNBCR-03/2020 NRP-22 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF ELECTRONIC MONEY PROVIDER COMPANIES
Approval: 02/26/2020 Validity: 04/01/2020
promotes a culture of risk management within the entity, ensuring that all personnel are aware of their responsibilities in this regard.
The dissemination program must include, at minimum, the following elements:
a) Identification of the target audience for the dissemination activities;
b) Definition of the key messages to be conveyed regarding the entity's risk management policy and culture;
c) Selection of appropriate channels and media for dissemination, such as intranet, emails, workshops, or manuals;
d) Schedule of dissemination activities;
e) Assignment of responsibilities for the execution of the dissemination program;
f) Mechanisms for evaluating the effectiveness of the dissemination program.
Internal Audit Art. 15.- Internal Audit must periodically evaluate the adequacy and effectiveness of the entity's integral risk management system, verifying compliance with the policies, procedures, and limits established in these Standards and in the entity's own risk management framework.
The Internal Audit function must be independent of the risk management and business areas. The Internal Audit reports must be submitted to the Board of Directors and the Risk Committee, highlighting any deficiencies found and the recommendations for improvement.
The frequency of Internal Audit reviews must be determined based on the risk profile of the entity, but must be at least once a year.
Reporting to the Superintendence Art. 16.- Entities must report to the Financial System Superintendence the information related to their integral risk management system as required by the applicable regulations and these Standards.
Specifically, entities must report:
a) The policies and manuals for risk management, within the first ten business days following their approval or modification;
b) The annual work plan of the Risk Unit, upon its approval by the Risk Committee;
c) Periodic reports on the status of risk management, including risk exposures, deviations from limits, and corrective actions taken, with the frequency established by the Superintendence;
d) Any significant events or incidents that may have a material impact on the entity's risk profile or financial condition, without delay;
e) The results of the Internal Audit reviews related to risk management.
The reports must be submitted in the format and through the channels established by the Superintendence.
Transitory Provisions First.- The entities subject to these Standards must comply with the provisions herein within ninety (90) calendar days from the date of entry into force of these Standards.
Second.- The provisions of these Standards are without prejudice to the general powers of the Central Bank of Reserve of El Salvador and the Financial System Superintendence to issue additional regulations or interpretations necessary for the proper application of the legal framework governing the financial system.
Third.- These Standards will enter into force on April 1, 2020.
San Salvador, February 26, 2020.
STANDARDS COMMITTEE
[Signatures]
President of the Standards Committee
Members of the Standards Committee