2020-02-26 | NRP-20Added · Updated
The Committee of Standards of the Central Reserve Bank of El Salvador issued these standards to establish minimum provisions for the integral risk management of financial entities, including banks, insurance companies, and payment system operators. The document mandates the implementation of a documented risk management process covering identification, measurement, control, and monitoring of credit, market, liquidity, operational, reputational, and technical risks. It requires entities to establish specific organizational structures, including a Risk Committee and an independent Risk Unit, with defined responsibilities for the Board of Directors and Senior Management. Approved on February 26, 2020, with validity starting April 1, 2020, the rules oblige entities to submit approved risk policies to the Superintendence within ten business days and update them at least every two years.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 14 CNBCR-03/2020 NRP-20 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES Approval: 02/26/2020 Validity: 04/01/2020
THE COMMITTEE OF STANDARDS OF THE CENTRAL RESERVE BANK OF EL SALVADOR, CONSIDERING: I. That in accordance with Article 3, letter c) of the Law on Supervision and Regulation of the Financial System, it is the responsibility of the Superintendence of the Financial System to proactively monitor the risks of the members of the financial system and the manner in which they manage them, ensuring the prudent maintenance of their solvency and liquidity. II. That Article 7 of the Law on Supervision and Regulation of the Financial System establishes that members of the financial system include banks incorporated in El Salvador, their offices abroad and their subsidiaries; the branches and offices of foreign banks established in the country; insurance companies, their branches abroad and the branches of foreign insurance companies established in the country; cooperative banks, savings and credit societies and federations regulated by the Law on Cooperative Banks and Savings and Credit Societies; the Social Housing Fund and the National Popular Housing Fund; the Agricultural Development Bank, the Mortgage Bank of El Salvador, S.A., and the Development Bank of El Salvador. III. That in accordance with Article 35, letter d) of the Law on Supervision and Regulation of the Financial System, it is stipulated that directors, managers and other officials holding positions of direction or administration of the members of the financial system must conduct their business, acts and operations complying with the highest ethical standards of conduct, acting with the due diligence of a good merchant in their own business, being obligated to comply with and ensure that in the institution they direct or work for, the adoption and updating of policies and mechanisms for risk management are fulfilled, being required, among other actions, to identify, evaluate, mitigate and disclose them in accordance with international best practices. IV. That Article 99, letter a) of the Law on Supervision and Regulation of the Financial System stipulates that it will be the responsibility of the Committee of Standards to approve technical standards, instructions and provisions that the laws regulating the supervised entities establish must be issued to facilitate their application, including aspects inherent to risk management by the supervised entities. V. That in accordance with international standards, it is necessary to have a solid risk management framework that allows for the integral management of risks according to the profile, magnitude of activities, business, resources of the entity and best practices, in such a way as to promote the implementation of prudential measures for the transparent, efficient and orderly functioning of the
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 14 CNBCR-03/2020 NRP-20 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES Approval: 02/26/2020 Validity: 04/01/2020 market.
THEREFORE, in virtue of the regulatory powers conferred by Article 99 of the Law on Supervision and Regulation of the Financial System,
AGREES to issue the following: TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES
CHAPTER I OBJECT, SUBJECTS AND TERMS
Object Art. 1.- These Standards have as their object to establish the minimum provisions that entities must observe for the integral management of risks in accordance with applicable laws and international standards in the matter, in accordance with the nature and scale of their activities. These Standards complement the general regulatory framework in force, of which the "Technical Standards on Corporate Governance" (NRP-17), approved by the Central Bank through its Committee of Standards, also form part.
Subjects Art. 2.- The subjects obliged to comply with the provisions established in these Standards are: a) Banks incorporated in El Salvador, their offices abroad and their subsidiaries; b) The branches and offices of foreign banks established in the country, insofar as pertinent; c) Insurance companies, their branches abroad and cooperative insurance associations incorporated in the country, insofar as they do not contradict their creation laws; d) The branches of foreign insurance companies established in the country, insofar as pertinent; e) Cooperative banks, savings and credit societies and federations regulated by the Law on Cooperative Banks and Savings and Credit Societies; f) The Mortgage Bank of El Salvador, S.A.; g) The Social Housing Fund and the National Popular Housing Fund, insofar as they do not contradict their creation laws, nor what is provided by the Court of Accounts; h) The Agricultural Development Bank, insofar as it does not contradict its creation law, nor what is provided by the Court of Accounts;
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 14 CNBCR-03/2020 NRP-20 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES Approval: 02/26/2020 Validity: 04/01/2020 i) The Development Bank of the Republic of El Salvador, insofar as it does not contradict its creation law nor what is provided by the Court of Accounts; (2) j) Legal persons that carry out money sending or receiving operations systematically or substantially, by any means, at the national and international level. It will be understood that money sending or receiving operations are carried out systematically or substantially when such activity is carried out habitually or constitutes an important activity within the business operations of the entity; (2) k) Reciprocal Guarantee Societies and their local reinsurers; (2) l) Administrators or Operators of Payment Systems and Securities Settlement Societies; (2) m) Foreign Currency Exchange Houses; and (2) n) Societies that offer complementary services to the financial services of the members of the financial system, particularly those in which they participate as investors. (2)
Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Senior Management: The President, Executive President, Executive Director, General Manager or whoever acts in their place and the executive positions that report to them. For the case of the Development Bank of El Salvador, the President; b) Risk Appetite: The level and types of risks that an entity is willing to assume in relation to its activities, to achieve its strategic objectives and business plans; c) Central Bank: Central Reserve Bank of El Salvador; d) Client: Natural or legal person who maintains a contractual relationship with the entity for the provision of financial services or products that it offers, which in these Standards may refer to: depositors, investors, insured persons, debtors, co-debtors, beneficiaries, among others; e) Conflict of Interest: Any situation in which it may be perceived that a personal benefit or interest of a third party may influence the judgment or professional decision of a member of the entity regarding the fulfillment of its obligations; f) Financial Conglomerate: In accordance with Article 113 of the Banks Law, it is the set of societies characterized by the fact that more than fifty percent of their respective share capital is owned by a controlling society, which is also a member of the conglomerate. The controlling society of the conglomerate may be a society of exclusive purpose or a bank incorporated in the country; g) Integral risk management culture: Standards, attitudes, knowledge and behavior of an entity related to risk and decisions on the
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 14 CNBCR-03/2020 NRP-20 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES Approval: 02/26/2020 Validity: 04/01/2020 way of managing and controlling them; h) Entity: Subject obliged to comply with the provisions established in these Standards; i) Risk Factors: Represent those variables that entities must consider for adequate identification and mitigation of the risks to which they are exposed; j) Board of Directors: Collegiate body or equivalent body in charge of the administration of the entity, with supervisory, direction and control functions; for the case of Cooperative Associations, it will be the Board of Directors or as defined in its Creation Law; k) Stress Tests: Scenarios used to evaluate and measure the resistance, vulnerability and stability of an entity or financial system against the occurrence of possible adverse extreme events, and their impact on the equity and/or financial results of an entity; l) Superintendence: Superintendence of the Financial System; and m) Risk Tolerance: Levels of risk-taking acceptable to achieve a specific objective or manage a category of risk. Risk tolerance represents the practical application of risk appetite and, generally, is aligned with risk categories, such as strategy, finance, people or reputation.
CHAPTER II ON INTEGRAL RISK MANAGEMENT
Integral Risk Management Art. 4.- Entities must establish an integral risk management system, which must be understood as a strategic process carried out by the entire entity, through which they identify, measure, control, mitigate, monitor and communicate the different types of risks to which they are exposed and the interrelationships that arise between them, for the achievement of their objectives. This management must be in accordance with its nature, risk profile, volume and complexity of its activities, business lines, own and third-party resources, in such a way as to promote the implementation of measures in accordance with best practices for the transparent, efficient and orderly functioning of the market. The integral process for risk management must be duly documented and periodically reviewed based on changes that occur in the entity's risk profile and in the market. The policies, procedures and manuals issued by entities must be in Spanish.
Stages of the integral risk management process Art. 5.- Entities must have a documented continuous process for the integral management of their risks, which must contain at least the following stages: a) Identification: This is the stage in which existing risks in each operation, product, service, process and business line developed by the entity and those that may occur in new business lines are recognized and understood. In this stage, the risk factors that can generate changes in the entity's equity or in the funds or resources it administers are identified, in accordance with the operations that their special laws authorize; b) Measurement: This is the stage in which risks must be quantified in order to determine compliance or adequacy of policies, the established limits and measure the possible economic impact on the financial results of the entity. The methodologies and tools to measure each type of risk must be in accordance with the size, nature of their operations and the levels of risks assumed by the entity; c) Control and mitigation: This is the stage that seeks to ensure that the policies, limits and procedures established for the treatment and mitigation of risks are appropriately taken and executed; and d) Monitoring and communication: This is the stage that provides systematic and permanent follow-up to risk exposures and the results of actions adopted. These information systems must ensure a periodic and objective review of risk positions and the generation of sufficient information to support decision-making processes and allow the results of risk management to be communicated in a timely manner.
Types of risks Art. 6.- For the purposes of these Standards, entities must manage, in accordance with their structures, size, business and resources, at least the following risks: a) Credit Risk: The possibility of loss due to the non-compliance of contractual obligations assumed by a counterparty, understood as a borrower or a debt issuer, a reinsurer or a guarantor. Without prejudice to what is established in the "Standards for the Management of Credit Risk and Credit Concentration" (NPB4-49), the management of this risk must consider, in accordance with the policies of each entity, the observance or not of socio-environmental responsibility principles in the activities and resources to be financed; b) Market Risk: The possibility of loss, resulting from movements in market prices that generate a deterioration in value in positions within and outside the balance sheet or in the financial results of the entity; c) Liquidity Risk: The possibility of incurring losses due to not having sufficient resources to meet assumed obligations, incurring excessive costs and being unable to develop the business under the conditions foreseen; d) Operational Risk: Possibility of incurring losses due to failures in processes, people, information systems and due to external events; it includes legal risk which consists of the possibility of occurrence of losses due to failures in the execution of contracts or agreements, non-compliance with regulations, as well as external factors such as regulatory changes, judicial processes, among others; (3) e) Reputational Risk: The possibility of incurring losses, resulting from the deterioration of the entity's image, due to non-compliance with laws, internal regulations, corporate governance codes, codes of conduct, money laundering, terrorist financing and financing of the proliferation of weapons of mass destruction, among others; and (3) f) Technical Risk: The possibility of losses generated by unexpected increases in claims and expenses, due to inadequate technical or actuarial bases used for: establishing the pure risk rate for each insurance line, determining the commercial rate or premiums, the evaluation and acceptance of insured risks or underwriting policies, reinsurance coverage and the calculation of technical reserves.
With reference to the management of money laundering, terrorist financing and financing of the proliferation of weapons of mass destruction risks, entities must apply what is established in the "Technical Standards for the Management of Money Laundering, Terrorist Financing and Financing of the Proliferation of Weapons of Mass Destruction Risks" (NRP-36) approved by the Central Bank, through its Committee of Standards. (3)
CHAPTER III ENVIRONMENT FOR INTEGRAL RISK MANAGEMENT
Organizational System Art. 7.- Entities must establish an organizational structure that allows for adequate integral risk management, with the appropriate segregation of functions and hierarchical levels of operational support, business and control areas that participate in the process, as well as levels of dependence, in accordance with the risk profile, the size and nature of their operations. Entities will establish and apply the methodologies they consider appropriate for the risk management model, without prejudice to the standards and minimum requirements established by the Central Bank through its Committee of Standards.
Functions of the Board of Directors or Equivalent Management Body Art. 8.- The Board of Directors or equivalent management body is responsible for ensuring adequate integral risk management, having among its functions at least the following: a) Define and approve the entity's risk appetite and tolerance, as well as the exposure limits of each particular risk according to its profile; likewise, it must establish the respective controls for exceptions and deviations to said limits;
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 7 of 14 CNBCR-03/2020 NRP-20 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES Approval: 02/26/2020 Validity: 04/01/2020 b) Approve the internal organizational or functional structure according to its business model, with their respective organization manuals and segregation of functions, assigning the necessary resources to implement and maintain adequate risk management, in an effective and efficient manner; c) Approve the policies and manuals for the management of risks assumed by the entity, ensuring that they are implemented; d) Create the Risk Committee, in accordance with what is established in the "Technical Standards on Corporate Governance" (NRP-17) approved by the Central Bank, through its Committee of Standards, approving the appointment and removal of its members, when applicable and ensuring their independence; e) Create the Risk Unit and appoint the person in charge of it, ensuring its independence from the business and operational areas of the entity in order to avoid conflicts of interest, as well as the separation of functions and corresponding responsibilities, and providing it with the resources, tools, materials and adequate technical training; f) Know and understand all the risks inherent to the businesses developed by the entity and to which it is exposed, their evolution and their effects, especially at the equity levels; as well as the methodologies and tools for risk management; g) Approve the entity's involvement in new products, services, business lines and operations, and ensure that they adhere to its business strategies and policies for risk management; h) Ensure that an organizational culture of risk management is implemented within the entity; and i) Ensure that Internal Audit verifies the existence and compliance of the entity's integral risk management scheme. The policies and manuals for risk management approved by the Board of Directors must be sent to the Superintendence for its knowledge, within the first ten business days following their approval or respective modification. The period between reviews and/or updates on policies or manuals must not exceed two years.
Risk Committee Art. 9.- Entities must have a Risk Committee which will observe what is established in these Standards and in the "Technical Standards on Corporate Governance" (NRP-17) approved by the Central Bank, through its Committee of Standards.
Functions of the Risk Committee Art. 10.- The functions of the Risk Committee will include, at minimum, the following activities: a) Approve the following:
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 8 of 14 CNBCR-03/2020 NRP-20 TECHNICAL STANDARDS FOR THE INTEGRAL RISK MANAGEMENT OF FINANCIAL ENTITIES Approval: 02/26/2020 Validity: 04/01/2020 i. The methodologies for managing the different types of risks to which the entity is exposed, as well as their possible modifications, ensuring that it considers the relevant risks of the activities it carries out; and ii. The corrective actions proposed by the Risk Unit and the involved areas, as well as the mechanisms for their implementation, in the case of deviation with respect to the assumed exposure levels or limits. b) Require and follow up on corrective plans to normalize non-compliance with exposure limits or reported deficiencies; c) Evaluate, endorse and propose for approval by the Board of Directors, at least the following: i. The strategies, policies and manuals for integral risk management, as well as the possible modifications made to them; ii. The tolerance limits for exposure to the different types of risks identified by the entity, in accordance with its risk appetite; and iii. The cases or special circumstances in which exposure limits may be exceeded, as well as the special controls on said circumstances. d) Inform the Board of Directors about the risks assumed by the entity, their evolution, their effects, especially at the equity levels and the additional mitigation needs, as well as their corrective actions; e) Inform the Board of Directors about the exposures, deviations and exceptions of the risks that are managed in the entity; and f) Inform the Board of Directors about the results of the reports prepared by the Risk Unit.
Functions of Senior Management Art. 11.- Senior Management is responsible for the establishment and execution of the structural framework of the risk management system and will report to the Board of Directors, being required to adopt and ensure compliance, at minimum, with the following measures: a) Establish the necessary conditions at the level of the entire organization to promote an environment that seeks the development of the integral risk management process; b) Ensure that there are mechanisms that guarantee adequate flow, quality and timeliness of information, between Business Units, operational support areas and the Risk Unit, so that the latter appropriately develops its function; c) Ensure the establishment of mechanisms for the dissemination of the integral risk management culture, at all levels of the organizational structure; and d) Ensure the execution of training and updating programs for the entity's risk management.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 9 of 14 CNBCR-03/2020