Skip to main content

Basel Framework

The Basel Framework is the full set of standards of the Basel Committee on Banking Supervision (BCBS), which is the primary global standard setter for the prudential regulation of banks. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdictions. The background page describes the framework's structure and how to navigate it.

Please provide first name.
Looks good!
Please provide first name.
Looks good!
View the framework as it was / will be on a specific date
BCP40

The Core Principles and assessment criteria

This chapter describes the criteria for assessing compliance with the Core Principles.

  • Effective as of: 25 Apr 2024
  • Last update: 25 Apr 2024
  • Status Current

Introduction

40.1

The Core Principles establish 29 principles that are needed for a supervisory system to be effective and can be categorised into two groups:

  1. Principles 1 to 13 focus on the powers, responsibilities and functions of supervisors;
  2. Principles 14 to 29 focus on prudential regulations and requirements for banks.
40.2

This chapter lists the assessment criteria for each of the 29 Core Principles under two separate headings: "essential criteria" and "additional criteria".

40.3

The individual assessment criteria are based on international standards and sound supervisory practices that are already established, even if they have not yet been fully implemented. Where appropriate, the documents on which the criteria are founded have been cited as "reference documents". These documents include more detailed explanations of supervisory expectations and practices. There is the expectation that guidelines issued by the Committee will be observed by Committee member jurisdictions.

Principle 1 - Responsibilities, objectives and powers

40.4

Principle 1:1 An effective system of banking supervision has clear responsibilities and objectives for each authority involved in the supervision of banks and banking groups. A suitable legal framework for banking supervision is in place to provide each responsible authority with the necessary legal powers to authorise banks, conduct ongoing supervision, address compliance with laws and undertake timely corrective actions to address safety and soundness concerns.

40.5

Essential criteria:

  1. The responsibilities and objectives of each of the authorities involved in banking supervision are clearly defined in legislation and publicly disclosed. Where more than one authority is responsible for supervising the banking system, a credible and publicly available framework is in place to avoid regulatory and supervisory gaps.2
  2. The primary objective of banking supervision is to promote the safety and soundness of banks and the banking system. If the banking supervisor is assigned broader responsibilities, these are subordinate to the primary objective and do not conflict with it.
  3. Laws and regulations provide a framework for the supervisor to set and enforce minimum prudential standards for banks. The supervisor has the power to increase the prudential requirements for individual banks based on their risk profile and systemic importance.
  4. Banking laws, regulations and prudential standards are updated as necessary to ensure that they remain effective and relevant to changing industry and regulatory practices. These are subject to public consultation, as appropriate, and published in a timely manner.
  5. The supervisor has the power to:
    1. have full access3 to a bank's board, management, staff and records (including records that are held by relevant service providers and can be accessed either directly or through the supervised bank);
    2. review the overall activities of a bank (including activities performed by relevant service providers), whether domestic or cross-border; and
    3. supervise the foreign activities of banks incorporated in its jurisdiction.
  6. When, in a supervisor's judgment, a bank is not complying with laws or regulations, or it is engaging or is likely to be engaging in unsafe or unsound practices or actions that have the potential to jeopardise the bank or the banking system, the supervisor has the power to:
    1. take (and/or require a bank to take) timely corrective action;
    2. impose a range of sanctions;
    3. revoke the bank's licence; and
    4. cooperate and collaborate with relevant authorities to achieve an orderly resolution of the bank, including triggering resolution where appropriate.
  7. The supervisor has the power to review the activities of parent companies and of companies affiliated with parent companies to determine their impact on the safety and soundness of the bank. The supervisor has access, whether directly or through the supervised bank, to all necessary information for conducting such a review irrespective of where it is available.
2

If countries have shared or transferred prudential tasks to a supranational supervisor, the roles and responsibilities that have been shared or transferred are clearly set out in law and publicly disclosed. Any residual powers or responsibilities that are retained must be publicly disclosed so that there is clarity on the division of responsibility.

3

For this purpose, “access” includes supervisory access in person to the bank’s premises, and to senior executive staff and the board (both individual members and as a whole) in person or virtually as needed.

Principle 2 - Independence, accountability, resourcing and legal protection for supervisors

40.6

Principle 2:4 The supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy, and adequate resources, and is accountable for the discharge of its duties and use of its resources. The legal framework for banking supervision includes legal protection for the supervisor.

40.7

Essential criteria:

  1. The operational independence, accountability and governance of the supervisor are prescribed in legislation and publicly disclosed. There is no government or industry interference that compromises the operational independence of the supervisor. The supervisor has full discretion to set prudential policy and take any supervisory actions or decisions on banks under its supervision.
  2. The process for the appointment and removal of the head(s) of the supervisory authority and members of its governing body is transparent. The head(s) of the supervisory authority is (are) appointed for a minimum term and is (are) removed from office during their term only for reasons specified in law or if they are not physically or mentally capable of carrying out the role or have been found guilty of misconduct. The reason(s) for removal is (are) publicly disclosed.
  3. The supervisor publishes its objectives and is accountable through a transparent framework for the discharge of its duties in relation to those objectives. The supervisor regularly communicates its supervisory priorities publicly.
  4. The supervisor has effective internal governance and communication processes that enable timely supervisory decisions to be taken at a level appropriate to the significance of the issue and expedited procedures in the case of an emergency. The allocation of responsibilities within the organisation as well as the delegation of authority for particular tasks or decisions are clearly defined. Supervisory processes include internal checks and balances to support effective decision-making and accountability. The governing body is structured to avoid any real or perceived conflicts of interest.
  5. The supervisor and its staff have credibility based on their professionalism and integrity. There are rules on how to avoid conflicts of interest and on the appropriate use of information obtained through work, with sanctions in place if these are not followed.
  6. The supervisor has adequate resources for the conduct of effective supervision and oversight. It is financed in a manner that does not undermine its autonomy or operational independence. This includes:
    1. a budget that provides for staff in sufficient numbers and with skills commensurate with the risk profile and systemic importance of the banks supervised;
    2. salary scales that allow it to attract and retain qualified staff;
    3. the ability to commission external experts with the necessary professional skills and independence to conduct supervisory tasks subject to the necessary confidentiality restrictions;
    4. a budget and programme for the regular training of staff;
    5. a technology budget sufficient to equip its staff with the tools needed to supervise the banking industry and assess individual banks; and
    6. a travel budget that allows appropriate on-site work, effective cross-border cooperation and participation in domestic and international meetings of significant relevance (eg supervisory colleges).
  7. As part of their annual resource planning exercise, supervisors regularly take stock of existing staff skills and projected requirements/needs over the short and medium term, considering relevant emerging risks and practices as well as supervisory developments. Supervisors review and implement measures to bridge any gaps in numbers and/or skillsets identified.
  8. In determining supervisory programmes and allocating resources, supervisors consider the risk profile and systemic importance of individual banks and the different risk mitigation approaches available.
  9. Laws provide protection to the supervisor and its staff against lawsuits for actions taken and/or omissions made while discharging their duties in good faith. The supervisor and its staff are adequately protected against the costs of defending their actions and/or omissions made while discharging their duties in good faith.5
5

The term “supervisor and its staff” is to be understood as covering the head of the authority, the governing body, employees and any professional service providers who carry out tasks for the supervisory authority. As the protection is provided in respect of actions taken and/or omissions made while discharging duties in good faith, it is not removed when the term of appointment, engagement or employment is ended.

Principle 3 - Cooperation and collaboration

40.8

Principle 3: Laws, regulations or other arrangements provide a framework for cooperation and collaboration with relevant domestic authorities and foreign supervisors. These arrangements reflect the need to protect confidential information.6

6

Principle 3 is developed further in Principle 12 BCP40.27, Principle 13 BCP40.30 and Principle 29 BCP40.66.

40.9

Essential criteria:

  1. Arrangements, whether formal or informal, are in place for cooperation, including analysis and sharing of information and undertaking collaborative work, with all domestic authorities with responsibility for the safety and soundness of banks, other financial institutions and/or the stability of the financial system. There is evidence that these arrangements work in practice, where necessary.
  2. Arrangements, whether formal or informal, are in place for the supervisor to coordinate, within its mandate, with relevant authorities with responsibility for macroprudential policy when undertaking actions related to monitoring, identifying and addressing systemic risks that have the potential to affect the stability of the banking system.
  3. Arrangements, whether formal or informal, are in place for cooperation, including analysis and sharing of information and undertaking collaborative work, with relevant foreign supervisors of banks. There is evidence that these arrangements work in practice, where necessary.
  4. The supervisor may provide confidential information to another domestic authority or foreign supervisor but must take reasonable steps to determine that any confidential information so released will be used only for bank-specific or system-wide supervisory purposes and will be treated as confidential by the receiving party.
  5. The supervisor receiving confidential information from other supervisors uses the confidential information for bank-specific or system-wide supervisory purposes only. The supervisor does not disclose to third parties confidential information received without the permission of the supervisor providing the information and is able to deny any demand (other than a court order or mandate from a legislative body) to disclose confidential information in its possession. If the supervisor is legally compelled to disclose confidential information it has received from another supervisor, it promptly notifies the originating supervisor, indicating what information it is compelled to release and the circumstances surrounding the release. Where consent to passing on confidential information is not given, the supervisor uses all reasonable means to resist such a demand or protect the confidentiality of the information.
  6. Processes are in place for the supervisor to support resolution authorities (eg central banks and finance ministries as appropriate) undertaking recovery and resolution planning and actions.

Principle 4 - Permissible activities

40.10

Principle 4: The permissible activities of institutions that are licensed and subject to supervision as banks are clearly defined, and the use of the word "bank" in names is controlled.

40.11

Essential criteria:

  1. The term "bank" is clearly defined in laws or regulations.
  2. The permissible activities of institutions that are licensed and subject to supervision as banks are clearly defined either by supervisors, or in laws or regulations.
  3. The use of the word "bank" and any derivations, such as "banking", in a name, including domain names, is limited to licensed and supervised institutions in all circumstances where the general public might otherwise be misled.
  4. The taking of deposits from the public is reserved for institutions that are licensed and subject to supervision as banks.7
  5. The supervisor or licensing authority publishes or otherwise makes available a current list of licensed banks, including branches of foreign banks, operating within its jurisdiction in a way that is easily accessible to the public.
7

The Committee recognises the existence of non-bank financial institutions that take deposits but may be regulated differently from banks. These institutions should be subject to a form of regulation commensurate to the type and size of their business and, collectively, should not hold a significant proportion of deposits in the financial system.

Principle 5 - Licensing criteria

40.12

Principle 5:8 The licensing authority has the power to set criteria for licensing banks and to reject applications where the criteria are not met. At a minimum, the licensing process consists of an assessment of the ownership structure and governance (including the fitness and propriety of board members and senior management) of the bank and its wider group, its strategic and operating plan, internal controls, risk management and projected financial condition (including capital base). Where the proposed owner or parent organisation is a foreign bank, the prior consent of its home supervisor is obtained.

8

Reference documents: BCBS, Corporate governance principles for banks, July 2015; BCBS, Shell banks and booking offices, January 2003.

40.13

Essential criteria:

  1. The law identifies the authority responsible for granting and withdrawing a banking licence. The licensing authority could be the banking supervisor or another competent authority. If the licensing authority and the supervisor are not the same, the supervisor has the right to have its views on each application considered and its concerns addressed. In addition, the licensing authority provides the supervisor with any information that may be material to the supervision of the licensed bank. The supervisor imposes prudential conditions or limitations on the newly licensed bank, where appropriate.
  2. Laws or regulations give the licensing authority the power to set criteria for licensing banks. If the criteria are not fulfilled or if the information provided is inadequate, the licensing authority has the power to reject an application. If the licensing authority or supervisor determines that the licence was based on false information, the licence can be revoked.
  3. The licensing authority determines that the proposed legal, managerial, operational and ownership structures of the bank and its wider group will not hinder effective:Shell banks must not be licensed.
    1. supervision on both a solo and a consolidated basis; and
    2. implementation of corrective measures in the future.
  4. The licensing authority identifies and determines the suitability of the bank's major shareholders9 (including the beneficial owners) and others that may exert significant influence. It also assesses the transparency of the ownership structure, the sources of initial capital and the ability of shareholders to provide additional financial support, where needed.
  5. A minimum initial capital amount is stipulated for all banks.
  6. At authorisation, the licensing authority evaluates the bank's proposed board members and senior management in terms of their expertise and integrity, availability and time commitment to assume the responsibility, and any potential for conflicts of interest (fit and proper test). The fit and proper criteria include: skills and experience in relevant financial operations commensurate with the intended activities of the bank; and no record of criminal activities or adverse regulatory judgments that make a person unfit to hold important positions in a bank.10 The licensing authority determines whether the bank's board has collective sound knowledge of the material activities the bank intends to pursue, and the associated risks. The supervisor reassesses the suitability of board members in case of significant events (eg change of control or major acquisition) or upon receipt of information that impacts their fitness and propriety.
  7. The licensing authority reviews the proposed strategic and operating plans of the bank. This includes determining that an appropriate system of corporate governance, risk management and internal controls, including those related to the detection and prevention of criminal activities11 as well as the oversight of proposed outsourced functions, will be in place. The operational structure is required to reflect the scope and degree of sophistication of the proposed activities of the bank.
  8. The licensing authority reviews pro forma financial statements and projections of the proposed bank. This includes an assessment of the adequacy of the financial strength to support the proposed strategic plan as well as financial information on the principal shareholders of the bank.
  9. In the case of foreign banks establishing a branch or subsidiary, before issuing a licence, the host supervisor establishes that no objection (or a statement of no objection) from the home supervisor has been received. For cross-border banking operations in its country, the host supervisor determines whether the home supervisor practises global consolidated supervision and uses this information to inform its approach to licensing and supervision.
  10. The licensing authority or supervisor has policies and processes to monitor the progress of new entrants in meeting their business and strategic goals, and to determine that the supervisory requirements outlined in the licence approval are being met.
  11. The criteria for issuing licences are consistent with those applied in ongoing supervision. The supervisor determines that banks continue to comply with the applicable criteria once they are licensed.
9

This includes corporate owners of banks, for those countries which allow corporate ownership of banks.

10

Refer to Principle 14 BCP40.32.

11

Refer to Principle 29 BCP40.66.

Principle 6 - Transfer of significant ownership

40.14

Principle 6:12 The supervisor13 has the power to review, reject and impose prudential conditions on any proposals to transfer significant ownership or controlling interests held directly or indirectly in existing banks to other parties.

12

Reference documents: BCBS, Parallel-owned banking structures, January 2003; BCBS, Shell banks and booking offices, January 2003.

13

While the term “supervisor” is used throughout Principle 6, the Committee recognises that in a few countries these issues might be addressed by a separate licensing authority.

40.15

Essential criteria:

  1. Laws or regulations contain clear definitions of "significant ownership" and "controlling interest".
  2. There are requirements to obtain supervisory approval or provide immediate notification with respect to proposed changes that would result in a change in ownership (including beneficial ownership), to the exercise of voting rights over a particular threshold or to a change in controlling interest.
  3. The supervisor has the power to reject any proposal for a change in significant ownership (including beneficial ownership) or controlling interest, or prevent the exercise of voting rights in respect of such investments to ensure that any change in significant ownership meets criteria comparable with those used for licensing banks. If the supervisor determines that the change in significant ownership was based on false information, the supervisor has the power to reject, modify or reverse the change in significant ownership.
  4. The supervisor obtains from banks, through periodic reporting or on-site examinations, the names and holdings of all significant shareholders or those that exert controlling influence, including the identities of beneficial owners of shares being held by nominees, custodians and through vehicles that might be used to disguise ownership.
  5. The supervisor has the power to take appropriate action to modify, reverse or otherwise address a change of control that has taken place without the necessary notification to, or approval from, the supervisor.
  6. Laws, regulations or the supervisor require banks to notify the supervisor as soon as they become aware of any material information which may negatively affect the suitability of a major shareholder or a party that has a controlling interest.

Principle 7 - Major acquisitions

40.16

Principle 7: The supervisor has the power to: (i) approve or reject (or recommend to the responsible authority the approval or rejection of) and impose prudential conditions on major acquisitions or investments by a bank (including the establishment of cross-border operations), against prescribed criteria; and (ii) determine that corporate affiliations or structures do not expose the bank to undue risks or hinder effective supervision.

40.17

Essential criteria:

  1. Laws or regulations clearly define:
    1. what types and amounts (absolute and/or in relation to a bank's capital) of acquisitions and investments need prior supervisory approval; and
    2. cases for which notification after the acquisition or investment is sufficient. Such cases are primarily activities closely related to banking and where the investment is small relative to the bank's capital.
  2. Laws or regulations provide criteria by which to judge individual bank proposals for acquisitions and investments.
  3. The supervisor determines that any new acquisitions and investments will not expose the bank to undue risks or hinder effective supervision, and (where appropriate) that they will not hinder effective implementation of corrective measures in the future.14 The supervisor can prohibit banks from making major acquisitions/investments (including the establishment of cross-border banking operations) in countries with laws or regulations prohibiting information flows deemed necessary for adequate consolidated supervision. In making this assessment, the supervisor considers the effectiveness of supervision in the host country and its own ability to exercise supervision on a consolidated basis.
  4. The supervisor determines that the bank has, from the outset, adequate financial, managerial and organisational resources to manage the acquisition/investment.
  5. The supervisor is aware of the risks that non-banking activities can pose to a bank and has the means to take action to mitigate those risks. The supervisor considers the ability of the bank to manage these risks prior to permitting investment in non-banking activities.
  6. The supervisor reviews major acquisitions or investments by other entities in the banking group to determine that these do not expose the bank to any undue risks or hinder effective supervision. The supervisor also determines, where appropriate, that these new acquisitions and investments will not hinder effective implementation of corrective measures in the future. Where necessary, the supervisor is able to effectively address the risks to the bank arising from such acquisitions or investments.
14

The supervisor may consider whether the acquisition or investment creates obstacles to the orderly resolution of the bank.

Principle 8 - Supervisory approach

40.18

Principle 8:15 An effective system of banking supervision requires the supervisor to develop and maintain a forward-looking assessment of the risk profile of individual banks, proportionate to their systemic importance; identify, assess and address risks emanating from banks and the banking system as a whole; have a framework in place for early intervention; and have plans in place, in partnership with other relevant authorities, to take action to resolve banks in an orderly manner if they become non-viable.

40.19

Essential criteria:

  1. The supervisor uses a well defined methodology and processes to determine and assess on an ongoing basis the nature, impact and scope of the risks which banks:
    1. are exposed to; and
    2. present to the safety and soundness of the banking system (including implications for and interlinkages with financial system stability).
  2. The supervisor, in conjunction with relevant authorities where appropriate, uses a process to assess and identify which banks are systemically important in a domestic context. Supervisors publicly disclose information that provides an outline of the process employed to assess and determine systemic importance. The supervisor conducts these assessments sufficiently regularly to ensure they reflect the current state of the domestic financial system.
  3. The supervisor assesses banks' compliance with prudential regulations and other legal requirements.
  4. The supervisor considers the macroeconomic environment, climate-related financial risks and emerging risks in its risk assessment of banks. The supervisor also considers cross-sectoral developments, for example in non-bank financial institutions, through frequent contact with their regulators.
  5. The supervisor, in conjunction with other relevant authorities, identifies, monitors and assesses:The supervisor incorporates this analysis into its assessment of banks and addresses proactively any serious threat to the stability of the banking system. The supervisor communicates any significant trends or emerging risks to other relevant authorities with responsibilities for financial system stability.
    1. the build-up and transmission of risks, trends and concentrations within and across the banking system as a whole;
    2. any emerging or system-wide risks which could impact banks and the banking system as a whole; and
    3. common behaviours by banks (eg procyclical actions), interlinkages and interconnections that may adversely affect the stability of the banking system, including implications for financial system stability.
  6. Drawing on information provided by the bank and other domestic authorities, the supervisor, in conjunction with the resolution authority, assesses the bank's resolvability (where appropriate) having regard to the bank's risk profile and systemic importance. When bank-specific barriers to orderly resolution are identified, the supervisor requires banks to adopt appropriate measures, where necessary, such as changes to business strategies, managerial, operational and ownership structures, and internal procedures. Any such measures consider their effect on the soundness and stability of the bank's ongoing business.
  7. The supervisor has a clear framework or process (eg identification of risk and early intervention) for handling banks in the build-up to and during times of stress, such that any decisions to require or undertake recovery or resolution actions are made in a timely manner.
  8. Where the supervisor becomes aware of banks restructuring their activities to avoid the regulatory perimeter, the supervisor takes appropriate steps to address this. Where the supervisor becomes aware of bank-like activities being performed fully or partially outside the regulatory perimeter, the supervisor takes appropriate steps to draw the matter to the attention of the responsible authority to address regulatory arbitrage.

The methodology and processes address (among other things): banks' group structure (including risks posed by entities in the wider group); risks around banks' business models, including business model sustainability;16 banks' risk profile with a forward-looking view;17 their internal control environment; and their resolvability. The methodology permits relevant comparisons between banks, and the nature, frequency and intensity of supervision reflect the outcome of this analysis.

16

The ultimate responsibility for designing and implementing sustainable business strategies lies with a bank’s board.

17

The time horizon for establishing a forward-looking view should appropriately reflect climate-related financial risks and emerging risks as needed.

Principle 9 - Supervisory techniques and tools

40.20

Principle 9:18 The supervisor uses an appropriate range of techniques and tools to implement the supervisory approach and deploys supervisory resources on a proportionate basis, considering the risk profile and systemic importance of banks.

18

Reference document: BCBS, High-level considerations on proportionality, July 2022.

40.21

Essential criteria:

  1. The supervisor employs an appropriate mix of on-site and off-site supervision to evaluate the condition of banks, their risk profile, their internal control environment and the corrective measures necessary to address supervisory concerns. The specific mix between on-site and off-site supervision may be determined by the particular conditions and circumstances of the country and the bank. The supervisor regularly assesses the quality, effectiveness and integration of its on-site and off-site functions and amends its approach, as needed.
  2. The supervisor has a coherent process for planning and executing on-site and off-site activities. There are policies and processes to ensure that such activities are conducted on a thorough and consistent basis with clear responsibilities, objectives and outputs, and that there is effective coordination and information-sharing between the on-site and off-site functions.
  3. The supervisor uses a range of information to regularly review and assess the safety and soundness of banks and the stability of the banking system, the evaluation of material risks, and the identification of necessary corrective and supervisory actions. This includes information such as prudential reports, statistical returns, information on a bank's related entities and publicly available information. The information received on banks is used by supervisors to form a holistic view and understanding of their risk profile. The supervisor determines that information provided by banks is reliable19 and obtains, as necessary, additional information on banks and their related entities.
  4. The supervisor uses a variety of tools to regularly review and assess the safety and soundness of banks and the stability of the banking system, including:The supervisor uses its analysis to determine follow-up work required, if any.
    1. analysis of financial statements and accounts;
    2. business model analysis;
    3. horizontal peer reviews;
    4. analysis of corporate governance, including risk management and internal control systems;
    5. reviews of the outcome of stress tests undertaken by the banks; and
    6. assessments of the adequacy of banks' capital and liquidity levels under adverse economic scenarios, which may include conducting supervisory stress tests on individual banks or on a system-wide basis.
  5. Based on the information provided by banks and its own analysis, the supervisor communicates its findings to banks as appropriate and requires them to take action to mitigate any particular vulnerabilities that have the potential to affect their safety and soundness or the stability of the banking system (including implications for and interlinkages with financial system stability).
  6. The supervisor evaluates the work of the bank's internal audit function (including those that are outsourced or co-sourced) and determines whether, and to what extent, it may rely on the internal auditors' work to identify areas of potential risk.
  7. The supervisor engages sufficiently frequently with the bank's board, non-executive board members and senior and middle management (including heads of individual business units and control functions) to develop an understanding of and assess matters such as strategy, group structure, corporate governance, performance, capital adequacy, liquidity, asset quality, risk management systems and internal controls. Where necessary, the supervisor challenges the bank's board and senior management on the assumptions made in setting strategies and business models.
  8. The supervisor communicates to the bank the findings of its on- and off-site supervisory analyses in a timely manner by means of written reports or through discussions or meetings with the bank's management. The supervisor meets with the bank's senior management and the board to discuss the results of supervisory examinations and external audits, as appropriate. The supervisor also meets separately with the bank's independent board members and external auditor, as necessary.
  9. The supervisor undertakes appropriate and timely follow-up activities to check that banks have addressed supervisory concerns or implemented requirements communicated to them. This includes early escalation to the appropriate level of the supervisory authority and to the bank's board if action points are not addressed in an adequate or timely manner.
  10. The supervisor requires banks to notify it in advance of any substantive changes in their activities, structure and overall condition, or as soon as they become aware of any material adverse developments, including breaches of legal or prudential requirements.
  11. The supervisor may use independent third parties, including external experts, but it cannot outsource its prudential responsibilities to third parties. Where third parties are used, the supervisor:
    1. clearly defines and documents their roles and responsibilities, including the scope of work where they are appointed to conduct supervisory tasks;
    2. assesses their suitability for the designated task(s), the quality of their work and whether their output can be relied upon to the degree intended;
    3. ensures that they are subject to appropriate confidentiality restrictions;
    4. considers the biases that may influence them; and
    5. requires that they promptly bring to its attention any material shortcomings identified during the course of any work undertaken by them for supervisory purposes.
  12. The supervisor has an adequate information system which facilitates the processing, monitoring and analysis of prudential information. The system aids the identification of areas requiring follow-up action.
19

Refer to Principle 10 BCP40.23.

40.22

Additional criterion:

  1. The supervisor has a framework for periodic independent reviews, for example by an internal audit function, internal risk function or third-party assessor, of the adequacy and effectiveness of the range of its available supervisory tools and the effectiveness of their use, and makes changes as appropriate. The supervisory approach should be reviewed at periodic intervals and improved as necessary to ensure it remains effective and fit for purpose.

Principle 10 - Supervisory reporting

40.23

Principle 10:20 The supervisor collects, reviews and analyses prudential reports and statistical returns21 from banks on both a solo and a consolidated basis, and independently verifies these reports through either on-site examinations or use of external experts.

20

Reference documents: BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Principles for effective risk data aggregation and risk reporting, January 2013; BCBS, Principles for the supervision of financial conglomerates, September 2012.

21

In the context of this principle, “prudential reports and statistical returns” are distinct from and required in addition to mandatory accounting reports. The former are addressed by this principle, and the latter are addressed in Principle 27 BCP40.61.

40.24

Essential criteria:

  1. The supervisor has the power to require banks to submit information, on both a solo and a consolidated basis, on their financial condition, performance and risk exposures, on demand and at regular intervals. These reports provide information such as on- and off-balance sheet assets and liabilities, profit and loss, capital adequacy, liquidity, large exposures, risk concentrations (including by economic sector, geography and currency), asset quality, loan loss provisioning, related party transactions, interest rate risk, market risk and information that allows for the assessment of the materiality of climate-related financial risks and emerging risks to banks.
  2. The supervisor provides reporting instructions that clearly describe the standards to be used in preparing supervisory reports. Such standards are based on accounting principles and rules that are widely accepted internationally.
  3. The supervisor requires banks to have sound governance structures and control processes for methodologies that produce valuations. The measurement of fair values maximises the use of relevant and reliable inputs which are consistently applied for risk management and reporting purposes. The valuation framework and control procedures are subject to adequate independent validation and verification, either internally or by an external expert. The supervisor assesses whether the valuation used for regulatory purposes is reliable and prudent. Where the supervisor determines that valuations are not sufficiently prudent, the supervisor requires the bank to adjust its reporting for capital adequacy or regulatory reporting purposes.
  4. The supervisor collects and analyses information from banks at a frequency commensurate with the nature of the information requested and the risk profile and systemic importance of the bank.
  5. To make meaningful comparisons between banks, the supervisor collects data from all banks and all relevant entities covered by consolidated supervision on a comparable basis and for the same dates (stock data) and periods (flow data).
  6. The supervisor has the power to request and receive any relevant information from banks, as well as any entities in the wider group, irrespective of their activities, where the supervisor believes that it is:This includes, but is not limited to, internal management information, corporate governance information, transactions with the wider group (eg any non-bank entities) and related party transactions.
    1. material to the condition of the bank;
    2. material to the assessment of the risks of the bank; or
    3. needed to support resolution planning.
  7. The supervisor has a means of enforcing compliance with the requirement that the information be submitted on a timely and accurate basis. The supervisor determines the appropriate level of the bank's senior management that is responsible for the accuracy of supervisory returns, imposes sanctions for misreporting and persistent errors, and requires that inaccurate information be amended.
  8. The supervisor utilises policies and procedures to determine the validity and integrity of supervisory information. This includes a programme for the periodic verification of supervisory returns either by the supervisor's own staff or by external experts.
  9. The supervisor has a process in place to periodically review the information collected to determine that it satisfies a supervisory need.

Principle 11 - Corrective and sanctioning powers of supervisors

40.25

Principle 11:22 The supervisor acts at an early stage to address unsafe and unsound practices or activities that could pose risks to banks or to the banking system. The supervisor has at its disposal an adequate range of supervisory tools, that it can apply at its discretion, to bring about timely corrective actions. This includes the ability to revoke the banking licence or to recommend its revocation.

22

Reference document: BCBS, Parallel-owned banking structures, January 2003.

40.26

Essential criteria:

  1. The supervisor raises supervisory concerns with the bank's management or, where appropriate, the bank's board, at an early stage, and requires that these concerns be addressed in a timely manner. Where the supervisor requires the bank to take significant corrective actions, these are addressed in a written document to the bank's board. The supervisor requires the bank to submit regular written progress reports, and it checks that corrective actions are completed satisfactorily. The supervisor follows through conclusively and in a timely manner on matters that are identified.
  2. The supervisor uses an appropriate range of supervisory tools23 in a timely manner when, in the supervisor's judgment, a bank is not complying with laws, regulations or supervisory actions, is engaged in unsafe or unsound practices or in activities that could pose risks to the bank or the banking system, or when the interests of depositors are otherwise threatened.
  3. The supervisor uses its powers to act where a bank falls below established regulatory threshold requirements, including prescribed regulatory ratios or measurements. The supervisor intervenes at an early stage to require a bank to take action to prevent it from breaching its regulatory threshold requirements. Laws or regulations guard against the supervisor unduly delaying appropriate corrective actions, without limiting the supervisor's discretion to act.
  4. The supervisor uses a broad range of possible measures to address, at an early stage, such scenarios as described in BCP40.26(2) above. These measures include the ability to impose sanctions expeditiously or require a bank to take timely corrective action. In practice, the range of measures is applied in accordance with the gravity of a situation. The supervisor provides clear prudential objectives or sets out the actions to be taken, which may include restricting the current activities of the bank, imposing more stringent prudential limits and requirements, withholding approval of new activities or acquisitions, restricting or suspending payments to shareholders or share repurchases, restricting asset transfers, barring individuals from the banking sector, replacing or restricting the powers of managers, board members or controlling owners, facilitating a takeover by or merger with a healthier institution, providing for the interim management of the bank, and revoking or recommending the revocation of the banking licence.
  5. The supervisor applies sanctions not only to the bank but, when and if necessary, also to management and/or the board, or relevant individuals. The supervisor has the power to apply corrective measures and sanctioning measures simultaneously, including financial penalties.
  6. The supervisor exercises its power to take corrective actions, including ring-fencing the bank from the actions of parent companies, subsidiaries, parallel-owned banking structures and other related entities in matters that could impair the safety and soundness of the bank or the banking system.
  7. Laws, regulations or the supervisor establish a clear policy on whether imposed sanctions are made a matter of public knowledge and, in that case, what to disclose and when. The decision to publish sanctions or corrective measures applied to banks and individuals (eg senior managers, board members, directors, officers and other employees) may be subject to confidentiality considerations and it must not jeopardise other supervisory objectives or prejudice another case pending before the supervisor. While transparency of enforcement measures is encouraged, the decision to disclose sanctions can be made on a case by case basis, depending on their seriousness and the frequency of their occurrence, among other considerations.
  8. The supervisor cooperates and collaborates with relevant authorities in deciding when and how to effect the orderly resolution of a problem bank (which could include closure, assisting in restructuring, or merger with a stronger institution).
  9. Where appropriate, when taking formal corrective action in relation to a bank, the supervisor informs the supervisor of related non-bank financial entities of its actions and coordinates its actions with them.
23

Refer to Principle 1, essential criterion 1 BCP40.5.

Principle 12 - Consolidated supervision

40.27

Principle 12:24 The supervisor supervises the banking group on a consolidated basis, adequately monitoring and, as appropriate, applying prudential standards to all aspects of the business conducted by the banking group worldwide.

40.28

Essential criteria:

  1. The supervisor understands the overall structure of the banking group and is familiar with all the material activities (including non-banking activities) conducted by entities in the wider group, whether domestic or cross-border. The supervisor understands and assesses how group-wide risks are managed and takes action when risks arising from the banking group and other entities in the wider group, in particular contagion and reputational risks, may jeopardise the safety and soundness of the bank and the banking system.
  2. The supervisor imposes prudential standards and collects and analyses financial and other information on a consolidated basis for the banking group, covering areas such as capital adequacy, liquidity, large exposures, exposures to related parties, lending limits and group structure.
  3. The supervisor reviews whether the oversight of a bank's foreign operations by management (of the parent bank or head office and, where relevant, the holding company) is adequate having regard to their risk profile and systemic importance. The supervisor determines that parent banks have unimpeded access to all material information from their foreign branches and subsidiaries. The supervisor also determines that banks' policies and processes require the local management of any cross-border operations to have the necessary expertise to manage those operations in a safe and sound manner, and in compliance with supervisory and regulatory requirements. The home supervisor considers the effectiveness of supervision conducted in the host countries in which its banks have material operations.
  4. The home supervisor visits the foreign offices of the bank periodically. The location and frequency of these visits are determined by the risk profile and systemic importance of the bank's foreign operations. The supervisor meets the host supervisors during these visits. The supervisor has a policy for assessing whether it needs to conduct on-site examinations of a bank's foreign operations or require additional reporting, and it has the power and resources to take those actions as and when appropriate.
  5. The supervisor reviews the main activities of parent companies and of companies affiliated with the parent companies that have a material impact on the safety and soundness of the bank and takes appropriate supervisory action.
  6. The supervisor limits the range of activities the consolidated group may conduct and the locations in which activities can be conducted (including the closing of foreign offices) if it determines that:
    1. the safety and soundness of the bank is compromised because the activities expose it to excessive risk and/or are not properly managed;
    2. the supervision by other domestic authorities is not adequate relative to the risks the activities present; and/or
    3. the exercise of effective supervision on a consolidated basis is hindered.
  7. In addition to supervising on a consolidated basis, the responsible supervisor supervises individual banks in the group. The responsible supervisor supervises each bank on a solo basis and understands its relationship with other members of the group.25
25

Refer to Principle 16, additional criterion 2 BCP40.38.

40.29

Additional criterion:

  1. For countries which allow corporate ownership of banks, the supervisor has the power to establish and enforce fit and proper standards for senior management of parent companies.

Principle 13 - Home-host relationships

40.30

Principle 13:26 Home and host supervisors of cross-border banking groups share information and cooperate for effective supervision of the group and group entities, and effective handling of crisis situations. Supervisors require the local operations of foreign banks to be conducted to the same standards as those required of domestic banks.

40.31

Essential criteria:

  1. The home supervisor establishes bank-specific supervisory colleges for banking groups with material cross-border operations to enhance its effective oversight, considering the risk profile and systemic importance of the banking group and the corresponding needs of its supervisors. In its broadest sense, the host supervisor which has a relevant subsidiary or a significant branch in its jurisdiction and a shared interest in the effective supervisory oversight of the banking group is included in the college. The structure of the college reflects: (i) the nature of the banking group, including its scale, structure and complexity, and its significance in host jurisdictions; and (ii) the opportunity to enhance mutual trust and meet the needs and responsibilities of both home and host supervisors.
  2. Home and host supervisors share appropriate information on a timely basis in line with their respective roles and responsibilities, both bilaterally and through colleges. This includes information on:Informal or formal arrangements (such as memoranda of understanding and confidentiality agreements) are in place to enable the timely exchange of confidential information.
    1. the material risks (including those arising from the respective macroeconomic environments) and risk management practices of the banking group; and
    2. the supervisors' assessments of the safety and soundness of the relevant entity under their jurisdiction.
  3. Home and host supervisors coordinate and plan supervisory activities or undertake collaborative work if common areas of interest are identified to improve the effectiveness and efficiency of supervision of cross-border banking groups.
  4. The home supervisor develops an agreed communication strategy with the relevant host supervisors. The scope and nature of the strategy reflects the risk profile and systemic importance of the cross-border operations of the banking group. Home and host supervisors also agree on the communication of views and outcomes of joint activities and college meetings to banks, where appropriate, to ensure the consistency of messages on group-wide issues.
  5. Where appropriate, given the banking group's risk profile and systemic importance, the home supervisor, working with its national resolution authorities, develops a framework for cross-border crisis cooperation and coordination among the relevant home and host authorities. The relevant authorities share information on crisis preparations from an early stage, subject to rules on confidentiality, in a way that does not materially compromise the prospect of a successful resolution.
  6. Where appropriate, given the banking group's risk profile and systemic importance, the home supervisor, working with its national resolution authorities and relevant host authorities, develops a group resolution plan. The relevant authorities share any information necessary for the development and maintenance of a credible resolution plan. Supervisors also notify and consult relevant authorities and supervisors (both home and host) promptly when taking any recovery and resolution measures.
  7. The host supervisor's national laws or regulations require that the cross-border operations of foreign banks are subject to prudential, inspection and regulatory reporting requirements similar to those for domestic banks.
  8. The home supervisor is given on-site access to local offices and subsidiaries of a banking group to facilitate its assessment of the group's safety and soundness and compliance with customer due diligence requirements. The home supervisor informs host supervisors of intended visits to local offices and subsidiaries of banking groups.
  9. The host supervisor supervises booking offices in a manner consistent with internationally agreed standards. The supervisor does not permit shell banks or the continued operation of shell banks.
  10. A supervisor that takes action based on information received from, or that is consequential for the work of, another supervisor consults that supervisor, to the extent possible, before taking such action.

Principle 14 - Corporate governance

40.32

Principle 14:27 The supervisor determines that banks have robust corporate governance policies and processes covering, for example, corporate culture and values, strategic direction and oversight, group and organisational structure, the control environment, the suitability assessment process, the responsibilities of the banks' boards and senior management, and compensation practices. These policies and processes are commensurate with the risk profile and systemic importance of the bank.

40.33

Essential criteria:

  1. Laws, regulations or the supervisor establish the responsibilities of a bank's board and senior management with respect to corporate governance to ensure there is effective control over the bank's entire business. The supervisor provides guidance to banks on expectations for sound corporate governance.
  2. The supervisor regularly conducts comprehensive evaluations of a bank's corporate governance policies and practices, and their implementation, and determines that the bank has robust corporate governance policies and processes commensurate with its risk profile and systemic importance. The supervisor requires banks to correct deficiencies in a timely manner.
  3. The supervisor determines that board membership comprises individuals with a balance of skills, diversity and expertise, who collectively possess the necessary qualifications commensurate with the size, complexity and risk profile of the bank. Board membership includes a sufficient number of experienced independent directors.28 Board members are qualified (individually and collectively) for their positions, effective and exercise their "duty of care" and "duty of loyalty".29
  4. The supervisor determines that governance structures and processes for nominating and appointing board members are appropriate for the bank. Boards regularly assess the performance of the board as a whole, its committees and individual board members (including their ongoing suitability). Board membership is regularly renewed to refresh skills and independence. Commensurate with the bank's risk profile and systemic importance, board structures include audit, risk, compensation and other board committees with experienced, independent directors.
  5. The supervisor determines that the bank's board approves and oversees implementation of the bank's strategic direction, risk appetite and strategy, and related policies, establishes and communicates corporate culture and values (eg through a code of conduct),30 and establishes conflicts of interest policies and a strong control environment.
  6. The supervisor determines that the bank's board, except where required otherwise by laws or regulations:
    1. has established fit and proper standards in selecting senior management and heads of the control functions;
    2. has developed effective processes to allocate authority, responsibility and accountability within the bank;
    3. maintains plans for succession; and
    4. actively and critically oversees senior management's execution of board strategies, including monitoring the performance of senior management and heads of the control functions against the standards established for them.
  7. The supervisor determines that the bank's board actively oversees the design and operation of the bank's compensation system and that it has appropriate incentives, which are aligned with prudent risk-taking and effective in addressing misconduct that potentially results in losses. The compensation system and related performance standards, policies and procedures are non-discriminatory and consistent with the long-term objectives and financial soundness of the bank and are rectified if there are deficiencies.
  8. The supervisor determines that the bank's board and senior management know and understand the bank's operational structure and its risks, including those arising from the use of structures that impede transparency (eg special purpose or related structures). The supervisor determines that risks are effectively managed and mitigated, where appropriate.
  9. Laws, regulations or the supervisor require banks to notify the supervisor or publicly disclose as soon as they become aware of any material and bona fide information that may negatively affect the fitness and propriety of a bank's board member or a member of the senior management.
  10. The supervisor has the power to require changes in the composition of the bank's board if it believes that any individuals are not fulfilling their duties related to the satisfaction of these criteria.
28

Independent director refers to a non-executive member of the board who does not have any management responsibilities within the bank and is not under any other undue influence, internal or external, political or ownership, that would impede the board member’s exercise of objective judgment.

29

The Committee defines: (i) “duty of care” as the duty of board members to decide and act on an informed and prudent basis with respect to the bank. This is often interpreted as requiring board members to approach the affairs of the company the same way that a “prudent person” would approach his or her own affairs; and (ii) “duty of loyalty” as the duty of board members to act in good faith in the interest of the company. The duty of loyalty should prevent individual board members from acting in their own interest, or the interest of another individual or group, at the expense of the company and shareholders.

30

This includes whistleblowing policies and procedures that protect employees from reprisals or other detrimental treatment.

Principle 15 - Risk management process

40.34

Principle 15:31 The supervisor determines that banks have a comprehensive risk management process (including effective board and senior management oversight) to identify, measure, evaluate, monitor, report and control or mitigate all material risks32 (which can include risks related to digitalisation, climate-related financial risks and emerging risks) on a timely basis and to assess the adequacy of their capital, their liquidity and the sustainability of their business models in relation to their risk profile and market and macroeconomic conditions. This extends to the development and review of contingency arrangements (including robust and credible recovery plans where warranted) that consider the specific circumstances of the bank. The risk management process is commensurate with the risk profile and systemic importance of the bank.33

31

Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Stress testing principles, October 2018; BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Identification and management of step-in risk, October 2017; BCBS, Corporate governance principles for banks, July 2015; BCBS, Supervisory guidance for managing risks associated with the settlement of foreign exchange transactions, February 2013; BCBS, Principles for effective risk data aggregation and risk reporting, January 2013; BCBS, Principles for the supervision of financial conglomerates, September 2012; FSB, Guidance on supervisory interaction with financial institutions on risk culture: a framework for assessing risk culture, April 2014.

32

To some extent, the precise requirements may vary from risk type to risk type (Principles 15 to 25) as reflected by the underlying reference documents.

33

While in this and other principles the supervisor is required to determine that banks’ risk management policies and processes are being adhered to, the responsibility for ensuring adherence remains with a bank’s board and senior management.

40.35

Essential criteria:

  1. The supervisor determines that banks have appropriate risk management strategies that have been approved by the bank's board, and that the board establishes an effective risk appetite statement and framework to define the level of risk the bank is willing to assume or tolerate. The supervisor also determines that the board ensures that:
    1. a sound risk culture is established throughout the bank, to promote the development and execution of its strategy;
    2. policies and processes are developed for risk-taking that are consistent with the risk management strategy and the established risk appetite;
    3. uncertainties attached to risk measurement are recognised;
    4. appropriate limits are established that are consistent with the bank's risk appetite, risk profile, capital strength and liquidity needs. These limits are understood by, and regularly communicated to, relevant staff; and
    5. senior managers take the steps necessary to monitor and control all material risks consistent with the approved strategies and risk appetite.
  2. The supervisor requires banks to have comprehensive risk management policies and processes to identify, measure, evaluate, monitor, report and control or mitigate all material risks.34 The supervisor determines that these processes are adequate:
    1. to provide a comprehensive bank-wide view of risk across all material risk types;
    2. for the risk profile and systemic importance of the bank;
    3. to assess risks arising from the macroeconomic environment affecting the markets in which the bank operates and to incorporate such assessments into the bank's risk management process; and
    4. to assess risks that could materialise over longer time horizons (including risks related to digitalisation, climate-related financial risks and emerging risks). Where appropriate, banks use scenario analysis as a tool.
  3. The supervisor determines that risk management strategies, policies, processes and limits are properly documented and aligned with the bank's risk appetite statement and framework; regularly reviewed and appropriately adjusted to reflect changing risk appetites, risk profiles and market and macroeconomic conditions; and communicated within the bank. The supervisor determines that adequate procedures are in place for breaches of risk limits and significant deviations from established policies, ensuring they receive prompt attention and authorisation from the appropriate level of management and the bank's board (where necessary) and are adequately followed up with proportionate and timely remedial action.
  4. The supervisor determines that the bank's board and senior management obtain sufficient information on and understand the nature and level of risk being taken by the bank and how this risk relates to adequate levels of capital and liquidity. The supervisor also determines that the board and senior management regularly review and understand the implications and limitations (including the risk measurement uncertainties) of the risk management information that they receive.
  5. The supervisor determines that banks have an appropriate internal process for assessing their overall capital and liquidity adequacy and the sustainability of their business models in relation to their risk appetite, risk profile35 and forward-looking business strategies. The supervisor reviews and evaluates banks' internal capital and liquidity adequacy assessments and strategies.
  6. Where banks use models to measure components of risk, the supervisor determines that the following conditions are met:In addition, the supervisor assesses whether the model outputs appear reasonable as a reflection of the risks assumed.
    1. banks comply with supervisory standards on the use of models;
    2. the banks' boards and senior management understand the limitations and uncertainties relating to the output of the models and the risk inherent in their use; and
    3. banks perform regular and independent validation and testing of the models. In addition, the supervisor assesses whether the model outputs appear reasonable as a reflection of the risks assumed.
  7. The supervisor determines that banks have information systems that are adequate (both under normal circumstances and in periods of stress) for measuring, assessing and reporting on the size, composition and quality of exposures on a bank-wide basis across all risk types, products and counterparties. The supervisor also determines that these reports reflect the bank's risk profile and capital and liquidity needs, and that they are provided on a timely basis to the bank's board and senior management in a form suitable for their use.
  8. The supervisor determines that banks develop and maintain appropriate risk data aggregation and reporting capabilities commensurate with the risk profile and systemic importance of the bank. The supervisor also determines that the board and senior management review and approve the bank's risk data aggregation and risk reporting framework, and that they ensure that adequate resources are deployed to support these efforts.
  9. The supervisor determines that banks have adequate policies and processes to ensure that the banks' boards and senior management understand the risks inherent in new products,36 material modifications to existing products, and major management initiatives (such as changes in systems, processes, business models and major acquisitions). The supervisor determines that the bank's board and senior management monitor and manage these risks on an ongoing basis. The supervisor also determines that the bank's policies and processes require the undertaking of any major activities of this nature to be approved by the board or a specific committee of the board.
  10. The supervisor determines that banks have risk management functions covering all material risks with sufficient resources, independence, authority and access to the banks' boards to perform their duties effectively. The supervisor determines that their duties are clearly segregated from risk-taking functions in the bank and that they report on risk exposures directly to the board and senior management. The supervisor also determines that the risk management function is subject to regular review by the internal audit function.
  11. The supervisor requires larger and more complex banks to have a dedicated risk management unit overseen by a chief risk officer (CRO) or equivalent function. If the CRO of a bank is removed from their position for any reason, this should be done with the prior approval of the board and generally should be disclosed publicly. The bank should also discuss the reasons for such removal with its supervisor.
  12. The supervisor issues standards related to, in particular, credit risk, market risk, liquidity risk, interest rate risk in the banking book, operational risk and large exposures.
  13. The supervisor requires banks to have appropriate contingency arrangements, as an integral part of their risk management process, to address risks that may materialise and actions to be taken in stress conditions (including those that will pose a serious risk to their viability). If warranted by its risk profile and systemic importance, the contingency arrangements include robust and credible recovery plans that consider the specific circumstances of the bank. The supervisor, working with resolution authorities as appropriate, assesses the adequacy of banks' contingency arrangements given their risk profile and systemic importance (including reviewing any recovery plans) and their likely feasibility during periods of stress. The supervisor seeks improvements if deficiencies are identified.
  14. The supervisor requires banks to have forward-looking stress testing programmes covering all material risks commensurate with their risk profile and systemic importance as an integral part of their risk management process. At a minimum, banks' stress testing programmes cover credit risk, market risk, interest rate risk in the banking book, liquidity risk, country and transfer risk, operational risk and significant risk concentrations. The supervisor regularly assesses a bank's stress testing programme and determines that it captures all material sources of risk and adopts plausible adverse scenarios. The supervisor also determines that the bank integrates the results into its decision-making, risk management processes (including contingency arrangements) and the assessment of its capital and liquidity levels. The supervisor requires corrective action if material deficiencies are identified in a bank's stress testing programme or if the results of stress tests are not adequately considered in the bank's decision-making process. Where appropriate, the scope of the supervisor's assessment includes the extent to which the stress testing programme:
    1. promotes risk identification and control on a bank-wide basis;
    2. adopts suitably severe assumptions and seeks to address feedback effects and system-wide interaction between risks;
    3. benefits from the active involvement of the board and senior management; and
    4. is appropriately documented and regularly maintained and updated.
  15. The supervisor assesses whether banks appropriately account for risks (including liquidity impacts) in their internal pricing, performance measurement and new product approval process for all significant business activities.
34

This includes, where relevant, risks not directly addressed in the subsequent principles, such as reputational, step-in and strategic risks.

35

Banks should include climate-related financial risks assessed as material over relevant time horizons, including in their stress testing programmes where appropriate.

36

New products include those developed by the bank or by a third party and purchased or distributed by the bank.

Principle 16 - Capital adequacy

40.36

Principle 16:37 The supervisor sets prudent and appropriate capital adequacy requirements for banks that reflect the risks undertaken and presented by a bank in the context of the markets and macroeconomic conditions in which it operates.38 The supervisor defines the components of capital, bearing in mind their ability to absorb losses. At least for internationally active banks, capital requirements are not less stringent than the applicable Basel standards.

37

Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Guiding principles for the operationalisation of a sectoral countercyclical capital buffer, November 2019; SCO10, SCO30, CAP10, CAP30, CAP50, CAP99, RBC20, RBC30, RBC40, LEV10, LEV20, LEV30, SRP10, SRP20.

38

Implementation of the Basel Framework is not a prerequisite for compliance with the Core Principles. Compliance with the Basel Framework capital adequacy regimes is only required of those jurisdictions that have declared that they have voluntarily implemented it.

40.37

Essential criteria:

  1. Laws, regulations or the supervisor require banks to calculate and consistently observe prescribed capital requirements, including thresholds with reference to which a bank might be subject to supervisory action. Laws, regulations or the supervisor define the qualifying components of capital, ensuring that emphasis is given to those elements of capital permanently available to absorb losses on a going concern basis.
  2. At least for internationally active banks,39 the definition of capital, the risk coverage, the method of calculation and thresholds for the prescribed requirements are not lower than those established in the applicable Basel standards.
  3. The supervisor has the power to impose a specific capital charge and/or limits on all material risk exposures, if warranted, including in respect of risks that the supervisor considers not to have been adequately transferred or mitigated through transactions (eg securitisation transactions) entered into by the bank. Both on-balance sheet and off-balance sheet risks are included in the calculation of prescribed capital requirements.
  4. The prescribed capital requirements reflect the risk profile and systemic importance of banks in the context of the markets and macroeconomic conditions in which they operate, constrain the build-up of leverage in banks and the banking sector, and reduce the risk of contagion. In assessing the adequacy of a bank's capital levels given its risk profile, the supervisor focuses, among other things, on:Consequently, capital requirements may vary from bank to bank to ensure that each bank is operating with the appropriate level of capital to support its risk profile. Laws, regulations or the supervisor in a particular jurisdiction may set higher overall capital adequacy standards than the applicable Basel requirements.
    1. the potential loss absorbency of the instruments included in the bank's capital base;
    2. the appropriateness of risk weights as a proxy for the risk profile of its exposures;
    3. the adequacy of provisions and reserves to cover expected losses; and
    4. the quality of its risk management and controls.
  5. The use of banks' internal assessments of risk as inputs to the calculation of regulatory capital is approved by the supervisor. If the supervisor approves such use:
    1. such assessments adhere to rigorous qualifying standards;
    2. any cessation of such use or any material modification of the bank's processes and models for producing such internal assessments are subject to the approval of the supervisor;
    3. the supervisor has the capacity to evaluate a bank's internal assessment process to determine that the relevant qualifying standards are met and that the bank's internal assessments can be relied upon as a reasonable reflection of the risks undertaken;
    4. the supervisor has the power to impose conditions on its approvals if the supervisor considers it prudent to do so; and
    5. if a bank does not continue to meet the qualifying standards or the conditions imposed by the supervisor on an ongoing basis, the supervisor has the power to revoke its approval.
  6. The supervisor has the power to require banks to adopt a forward-looking approach to capital management (including the conduct of appropriate stress testing). The supervisor has the power to require banks:
    1. to set capital levels and manage available capital and planned capital expenditures in anticipation of possible business cycle effects, market conditions and changes in factors specific to the bank that could have an adverse effect; and
    2. to have in place feasible contingency arrangements to maintain or strengthen capital positions in times of stress, as appropriate given the risk profile and systemic importance of the bank.
  7. Laws or regulations require, or the supervisor has the power to impose a simple, transparent, non-risk-based measure that captures all on- and off-balance sheet exposures to supplement risk-based capital requirements to constrain the build-up of leverage in banks and in the banking sector.
39

Capital adequacy requirements for internationally active banks should be applied on a fully consolidated basis, including any holding company that is the parent entity within a banking group. The framework will apply to all internationally active banks at every tier within a banking group, on a fully consolidated basis. As an alternative to full sub-consolidation, the application of this framework to the standalone bank (ie on a basis that does not consolidate assets and liabilities of subsidiaries) would achieve the same objective, providing the full book value of any investments in subsidiaries and significant minority-owned stakes is deducted from the bank’s capital. Supervisors must also test that individual banks are adequately capitalised on a standalone basis.

40.38

Additional criteria:

  1. For non-internationally active banks, capital requirements, including the definition of capital, the risk coverage, the method of calculation, the scope of application and the capital required, are broadly consistent with the principles of the applicable Basel standards relevant to internationally active banks.
  2. The supervisor requires adequate distribution of capital within different entities of a banking group according to the allocation of risks.40
  3. Laws or regulations permit the supervisor or relevant authorities to require banks to maintain additional capital (which may include sectoral capital requirements) in a form that can be released when system-wide risk crystallises or dissipates.
40

Refer to Principle 12, essential criterion 7 BCP40.28.

Principle 17 - Credit risk

40.39

Principle 17:41 The supervisor determines that banks have an adequate credit risk management process that considers their risk appetite, risk profile, market conditions, macroeconomic factors and forward-looking information. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate credit risk42 (including counterparty credit risk43) on a timely basis. The full credit life cycle is covered, including credit underwriting, credit evaluation and the ongoing management of the bank's loan and investment portfolios.

41

Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Guidance on credit risk and accounting for expected credit losses, December 2015; FSB, Principles for sound residential mortgage underwriting practices, April 2012; CRE20, CRE40, CRE45, CRE50, CRE51, CRE54, MGN10, MGN20.

42

Credit risk may result from: on-balance sheet and off-balance sheet exposures, including loans and advances; investments; interbank lending; derivative transactions; securities financing transactions; and trading activities.

43

Transactions that give rise to counterparty credit risk include: OTC derivatives, exchange-traded derivatives, long settlement transactions and securities financing transactions that are bilaterally or centrally cleared. Counterparty credit risk may result from (but is not limited to) transactions with banks, non-financial corporates and non-bank financial institutions.

40.40

Essential criteria:

  1. Laws, regulations or the supervisor require banks to have sound credit risk management processes that provide a comprehensive bank-wide view of all credit risk exposures, including a robust methodology for the early identification and appropriate measurement of credit losses. The supervisor determines that the processes are consistent with the risk appetite, risk profile, systemic importance and capital strength of the bank, that they consider current and forward-looking market and macroeconomic factors, and that they result in prudent standards of underwriting, evaluation, administration, monitoring, measurement and control of credit risk.
  2. The supervisor determines that a bank's board approves and regularly reviews the credit risk management strategy and significant policies for identifying, measuring, evaluating, monitoring, reporting and controlling or mitigating credit risk (including counterparty credit risk) and that these are consistent with the risk appetite set by the board. The supervisor also determines that the board oversees management in a way that ensures that these policies are implemented effectively and fully integrated into the bank's overall risk management process.
  3. The supervisor requires and regularly determines that such policies and processes establish an appropriate and properly controlled credit risk environment, including:
    1. a well documented and effectively implemented strategy and sound policies and processes for assuming credit risk, without undue reliance on external credit assessments;
    2. well defined criteria and policies and processes for:
      (i)

      approving new exposures (including prudent underwriting standards), and ensuring a thorough understanding of the risk profile and characteristics of the borrowers (and in the case of securitisation exposures all features of securitisation transactions)44 that would materially impact the performance of these exposures;

      (ii)

      renewing and refinancing existing exposures; and

      (iii)

      identifying the appropriate approval authority for the size and complexity of the exposures;

    3. effective credit administration policies and processes, including: continued analysis of a borrower's ability and willingness to make all payments associated with the contractual arrangements (including reviews of the performance of underlying assets, eg for securitisation exposures or project finance); monitoring of documentation, legal covenants, contractual requirements, collateral and other forms of credit risk mitigation; and an appropriate exposure grading or classification system;
    4. effective information systems for accurate and timely identification, aggregation and reporting of credit risk exposures to the bank's board and senior management on an ongoing basis;
    5. prudent and appropriate credit limits consistent with the bank's risk appetite, risk profile and capital strength, which are understood by and regularly communicated to relevant staff;
    6. exception tracking and reporting processes that ensure prompt action at the appropriate level of the bank's senior management or board where necessary; and
    7. effective controls (including in respect of the quality, reliability and relevance of data and in respect of validation procedures) around the use of models to identify and measure credit risk and set limits.
  4. The supervisor determines that banks have policies and processes to monitor the total indebtedness of obligors to which they extend credit and any risk factors that may result in default, including significant unhedged foreign exchange risk.
  5. The supervisor requires that banks make credit decisions free of conflicts of interest and on an arm's length basis.
  6. The supervisor requires that the credit policy prescribes that major credit risk exposures exceeding a certain amount or percentage of the bank's capital must be decided by the bank's board or senior management. The same requirement applies to credit risk exposures that are especially risky or are otherwise not aligned with the bank's core business activities.
  7. The supervisor has full access to information in the credit and investment portfolios and to the bank officers involved in assuming, managing, controlling and reporting on credit risk.
44

Securitisation includes both traditional and synthetic securitisations (or similar structures that contain features common to both). Where appropriate, supervisors should provide guidance about whether a given transaction should be considered a securitisation.

Principle 18 - Problem exposures, provisions and reserves

40.41

Principle 18:45 The supervisor determines that banks have adequate policies and processes for the early identification and management of problem exposures46 and the maintenance of adequate provisions47 and reserves.48

45

Reference documents: BCBS, Prudential treatment of problem assets – definitions of non-performing exposures and forbearance, April 2017; BCBS, Guidance on credit risk and accounting for expected credit losses, December 2015.

46

For banks’ internal risk management purposes, a problem exposure is an exposure for which there is reason to believe that all amounts due, including the principal and interest, may not be collected in accordance with the contractual terms of the agreement with the counterparty.

47

Principle 18 covers all provisioning approaches (eg incurred loss models, expected credit loss models, calendar provisioning) that are used for prudential purposes. In some jurisdictions, cumulative provisions are referred to as loss allowances.

48

Reserves for the purposes of this principle are “below the line” non-distributable appropriations of profit required by a supervisor in addition to provisions (“above the line” charges to profit).

40.42

Essential criteria:

  1. Laws, regulations or the supervisor require banks to formulate policies, processes and methodologies for grading, classifying and monitoring all credit exposures (including off-balance sheet and forborne exposures49) and identifying and managing problem exposures. In addition, laws, regulations or the supervisor require regular reviews by banks of their credit exposures (at an individual level or at a portfolio level for credit exposures with homogeneous characteristics) to ensure appropriate exposure classification, detection of deteriorating exposures and timely identification of problem exposures.
  2. Laws, regulations or the supervisor require banks to formulate policies, processes and methodologies for consistently establishing provisions and ensuring appropriate and robust provisioning levels.50 In addition, laws, regulations or the supervisor require banks to formulate policies and processes for writing off problem exposures where recovery is unlikely or where the exposures have very little recovery value.
  3. The supervisor determines that the bank's board approves and regularly reviews significant policies for classifying exposures, determining provisions and managing problem exposures and write-offs. The supervisor also determines that the board oversees management in a way that ensures that these policies are implemented effectively and fully integrated into the bank's overall risk management process.
  4. The supervisor determines that banks have adequate and appropriate policies, processes, methodologies and organisational resources for establishing provisions and write-offs. The supervisor determines that policies, processes and methodologies for the measurement of provisions are appropriate to ensure that provisions and write-offs are timely and reflect realistic repayment and recovery expectations and, where relevant, include appropriate expectations about future credit losses based on reasonable and supportable information. The supervisor determines that banks' credit loss provisions and write-off methodologies and levels are subject to an effective review and validation process conducted by a function independent of the relevant risk-taking function.
  5. The supervisor determines that banks have adequate and appropriate policies, processes and organisational resources for:
    1. reviewing and classifying exposures;
    2. the early identification of deteriorating exposures;
    3. ongoing oversight of problem exposures; and
    4. collecting past due obligations.
  6. The supervisor obtains information on a regular basis and in relevant detail or has full access to information concerning the classification of exposures, collateral and other risk mitigants, provisions and write-offs. The supervisor requires banks to have adequate documentation to support their classification and provisioning.
  7. The supervisor assesses whether banks' classification of exposures is appropriate and whether their determination of provisioning levels is adequate for prudential purposes. The supervisor evaluates banks' treatment of exposures with a view to identifying any material circumvention of the classification and provisioning standards (eg forbearance). If policies, processes or methodologies are inadequate, or if exposure classifications are inaccurate or provisions are deemed to be inadequate for prudential purposes (eg if the supervisor considers existing or anticipated deterioration in exposure quality to be of concern, or if the provisions do not fully reflect losses expected to be realised), the supervisor has the power to take appropriate action, for example through requiring the bank to:Assessments supporting the supervisor's opinion in relation to this and other essential criteria under this principle may be conducted by external experts, with the supervisor reviewing the work of the external experts, including to determine the adequacy of the bank's policies, processes and methodologies for classifying exposures and determining provisions.
    1. revise its policies, processes or methodologies for classification and provisioning;
    2. adjust its classifications of exposures;
    3. increase its levels of provisioning, reserves or capital; or
    4. if necessary, impose other remedial measures.
  8. The supervisor requires banks to have appropriate mechanisms in place for regularly assessing the value of risk mitigants, including guarantees, credit derivatives and collateral. The valuation of collateral reflects the net realisable value, considering prevailing market conditions and the time required for realisation.
  9. Laws, regulations or the supervisor establish criteria for an exposure to be:
    1. identified as a problem exposure;
    2. identified as non-performing (exposures where full repayment is unlikely or which are 90 days past due for a material amount, or defaulted exposures under either the Basel Framework or the applicable prudential regulation, or credit-impaired exposures according to the applicable accounting framework);
    3. reclassified as performing (the counterparty does not have any material exposure more than 90 days past due, repayments have been made when due over a continuous repayment period, the counterparty's situation has improved so that full repayment of exposure is likely in accordance with the contractual terms, and the exposure is no longer defaulted or impaired); and
    4. classified as a forborne exposure.
  10. The supervisor determines that the bank's board obtains timely and appropriate information on the condition of the bank's credit portfolio, including classification of exposures, the level of provisions and reserves, and major problem exposures. The information includes, at a minimum, summary results of the latest credit exposure review process, comparative trends in the overall quality of problem exposures, and measurements of any existing or anticipated deterioration in exposure quality and losses expected to be realised.
  11. The supervisor requires that valuation, classification and provisioning, at least for significant exposures, are conducted on an individual item basis. For this purpose, supervisors require banks to set an appropriate threshold for the purpose of identifying significant exposures and to regularly review the level of the threshold.
  12. The supervisor regularly assesses any trends and concentrations in risk and risk build-up across the banking sector in relation to banks' problem exposures and considers any observed concentration in the risk mitigation strategies adopted by banks and the potential effect on the efficacy of the mitigant in reducing loss. The supervisor considers the adequacy of provisions and reserves at the bank and banking system level given this assessment.
49

A forborne exposure is an exposure for which a bank’s counterparty is experiencing financial difficulty in meeting its financial commitments and the bank grants a concession that it would not otherwise consider.

50

Provisions are not limited to problem exposures. Depending on the relevant jurisdiction’s accounting and prudential frameworks, provisions may be required for a wider range of exposures (eg all exposures, including performing exposures, under expected credit loss frameworks).

Principle 19 - Concentration risk and large exposure limits

40.43

Principle 19:51 The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate concentrations of risk on a timely basis. Supervisors set prudential limits to restrict bank exposures to single counterparties or groups of connected counterparties.52 At least for internationally active banks, large exposure requirements are not less stringent than the applicable Basel standard.

51

Reference documents: BCBS, High-level considerations on proportionality, July 2022; Joint Forum, Cross-sectoral review of group-wide identification and management of risk concentrations, April 2008; BCBS, Principles for the management of credit risk, September 2000; LEX10, LEX20, LEX30, LEX40.

52

Connected counterparties may include natural persons as well as legal persons. Two or more natural or legal persons shall be deemed a group of connected counterparties if at least one of the following criteria is satisfied: (a) control relationship: one of the counterparties, directly or indirectly, has control over the other(s); or (b) economic interdependence: if one of the counterparties were to experience financial problems, the other(s), as a result, would also be likely to encounter financial difficulties.

40.44

Essential criteria:

  1. Laws, regulations or the supervisor require banks to have policies and processes that provide a comprehensive bank-wide view of significant sources of concentration risk.53 Exposures (including counterparty credit risk exposure) arising from off-balance sheet as well as on-balance sheet items included in both the banking book and trading book are captured. At least for internationally active banks, large exposure requirements are not less stringent than the applicable Basel standard.
  2. The supervisor determines that a bank's information systems identify and aggregate on a timely basis exposures creating risk concentrations and large exposure to single counterparties or groups of connected counterparties and facilitate active management of such exposures.54
  3. The supervisor determines that a bank's risk management policies and processes establish thresholds for acceptable concentrations of risk, reflecting the bank's risk appetite, risk profile and capital strength, which are understood by and regularly communicated to relevant staff. The supervisor also determines that the bank's policies and processes require all material concentrations to be regularly reviewed and reported to the bank's board.
  4. The supervisor regularly obtains information that enables concentrations within a bank's portfolio, including sectoral, geographical and currency exposures, to be reviewed.
  5. For credit exposure to single counterparties or groups of connected counterparties, laws or regulations explicitly define, or the supervisor has the power to define, a group of connected counterparties to reflect actual risk exposure. The supervisor may exercise discretion in applying this definition on a case by case basis.
  6. Laws, regulations or the supervisor set prudent and appropriate requirements to control and constrain large credit exposures to a single counterparty or a group of connected counterparties. "Exposures" for this purpose include all claims and transactions (including those giving rise to counterparty credit risk exposure), whether on-balance sheet or off-balance sheet. The supervisor also determines that banks assess connectedness between counterparties through control relationships and economic interdependence based on objective and qualitative criteria. The supervisor determines that senior management monitors these limits and that they are not exceeded on a solo or consolidated basis.
53

Concentration risk may result from credit, market and other risk where a bank is overly exposed to particular asset classes, products, collateral, currencies or funding sources, and is broader than exposures subject to large exposure requirements. Credit concentrations include exposures to: single counterparties (including collateral credit protection and other commitments provided); groups of connected counterparties; counterparties in the same industry, economic sector or geographic region; and counterparties whose financial performance is dependent on the same activity or commodity.

54

The measure of credit exposure for large exposures should reflect the maximum possible loss from counterparty failure (ie it should encompass actual and potential exposures as well as contingent liabilities). The risk weighting concept adopted in the Basel Framework should not be used in measuring credit exposure for this purpose, as its use for measuring credit concentrations could significantly underestimate potential losses.

40.45

Additional criterion:

  1. In respect of credit exposure to single counterparties or groups of connected counterparties, non-internationally active banks are required to adhere to the limits below:Minor deviations from these limits may be acceptable, especially if they are explicitly temporary or related to very small or specialised banks.
    1. 10% or more of a bank's Tier 1 capital is defined as a large exposure; and
    2. 25% of a bank's Tier 1 capital is the limit for an individual large exposure to a private sector non-bank counterparty or a group of connected counterparties.

Principle 20 - Transactions with related parties

40.46

Principle 20:55 To prevent abuses arising in transactions with related parties56 and to address the risk of conflicts of interest, the supervisor requires banks to: enter into any transactions with related parties on an arm's length basis;57 monitor these transactions; take appropriate steps to control or mitigate the risks; and write off exposures to related parties in accordance with standard policies and processes.

55

Reference documents: BCBS, Corporate governance principles for banks, July 2015; BCBS, Principles for the management of credit risk, September 2000.

56

Related parties should include:

(a)

the bank’s subsidiaries and affiliates (including their subsidiaries, affiliates and special purpose entities) and any other party that the bank exerts control over or that exerts control over the bank;

(b)

the bank’s major shareholders, including beneficial owners;

(c)

the bank’s board members, senior management and key staff, corresponding persons in affiliated companies, and parties that can exert significant influence on board members or senior management; and

(d)

for the natural persons identified in (a) to (c), their direct and related interests and their close family members.

57

Related party transactions include on-balance sheet and off-balance sheet credit exposures; dealings such as service contracts, asset purchases and sales, construction contracts and lease agreements; derivative transactions; borrowings; and write-offs. The term “transaction” should be interpreted broadly to incorporate not only transactions that are entered into with related parties but also situations in which an unrelated party (with whom a bank has an existing exposure) subsequently becomes a related party.

40.47
  1. Laws, regulations or the supervisor set out a comprehensive definition of "related parties" that should at least consider all of the elements detailed in footnote 56. The supervisor may exercise discretion in applying this definition on a case by case basis.
  2. Laws, regulations or the supervisor require that transactions with related parties are not undertaken on more favourable terms (eg in credit assessment, tenor, interest rates, fees, amortisation schedules, requirements for collateral) than corresponding transactions with non-related counterparties.58
  3. The supervisor requires that transactions with related parties and the write-off of related party exposures exceeding specified amounts or otherwise posing special risks are subject to prior approval by the bank's board. The supervisor requires that board members with conflicts of interest are excluded from the approval process for granting and managing related party transactions.
  4. The supervisor determines that banks have policies and processes to prevent persons benefiting from the transaction (and/or persons related to such a person) or who otherwise have a conflict of interest from being part of the process of granting and managing the related party transaction.
  5. Laws or regulations establish, or the supervisor sets on a general or case by case basis, limits for exposures to related parties59 or require such exposures to be collateralised or deducted from capital.60 When limits are only set on aggregate exposures to related parties, those are at least as strict as those for single counterparties or groups of connected counterparties under Principle 19.
  6. The supervisor determines that banks have policies and processes to:The supervisor determines that exceptions to policies, processes and limits are reported to the appropriate level of the bank's senior management and, if necessary, to the board, for timely action. The supervisor also determines that senior management monitors related party transactions on an ongoing basis, and that the board also provides oversight of these transactions.
    1. identify individual exposures to and transactions with related parties as well as the total amount of exposures; and
    2. monitor and report on them through an independent credit review or audit process.
  7. The supervisor obtains and regularly reviews information on aggregate exposures to related parties. Supervisors require banks to report (or the supervisor acquires this information through other means) individual related party transactions that are material (eg those exceeding a specified amount or a percentage of the bank's Tier 1 capital).
58

Exceptions may be appropriate for certain transactions between entities within a banking group when the supervisor considers this to be consistent with sound group-wide risk management. An exception may also be appropriate for beneficial terms that are part of overall remuneration packages.

59

For this purpose, exposures should be calculated consistently with Principle 19 BCP40.43.

60

The supervisor may exclude banks’ exposures to certain entities within the banking group where the supervisor considers this to be consistent with sound group-wide risk management.

Principle 21 - Country and transfer risks

40.48

Principle 21:61 The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate country risk62 and transfer risk63 in their international lending and investment activities on a timely basis.

61

Reference documents: IMF, External debt statistics – guide for compilers and users, 2013; BCBS, Management of banks’ international lending: country risk analysis and country exposure measurement and control, March 1982.

62

Country risk is the risk of exposure to loss caused by events in a foreign country. The concept is broader than sovereign risk as all forms of lending or investment activity involving individuals, corporates, banks or governments are covered.

63

Transfer risk is the risk that a borrower will not be able to convert local currency into a foreign currency and so will be unable to make debt service payments in a foreign currency. The risk normally arises from exchange restrictions imposed by the government in the borrower’s country.

40.49
  1. The supervisor determines that a bank's policies and processes adequately consider the identification, measurement, evaluation, monitoring, reporting and control or mitigation of country risk and transfer risk. The supervisor also determines that the processes are consistent with the risk profile, systemic importance and risk appetite of the bank, consider market and macroeconomic conditions, and provide a comprehensive bank-wide view of country and transfer risk exposure. Exposures (including, where relevant, intragroup exposures) are identified, monitored and managed on a regional and an individual country basis (in addition to the end-borrower/end-counterparty basis). Banks are required to monitor and evaluate developments in country risk and in transfer risk and apply appropriate countermeasures.
  2. The supervisor determines that a bank's strategies and policies for the management of country and transfer risks have been approved and are regularly reviewed by the bank's board. The supervisor also determines that the board oversees management in a way that ensures that these policies are implemented effectively and fully integrated into the bank's overall risk management process.
  3. The supervisor determines that banks have information systems, risk management systems and internal control systems that accurately aggregate, monitor and report country exposures on a timely basis; and ensure adherence to established country exposure limits.
  4. There is supervisory oversight of the setting of appropriate provisions against country risk and transfer risk, which may include the following:
    1. The supervisor (or relevant authority) decides on appropriate minimum provisioning by regularly setting fixed percentages for exposures to each country, considering prevailing conditions. The supervisor reviews minimum provisioning levels where appropriate.
    2. The supervisor (or relevant authority) regularly sets percentage ranges for each country, considering prevailing conditions, and the banks may decide, within these ranges, which provisioning to apply for their individual exposures. The supervisor reviews percentage ranges for provisioning purposes where appropriate.
    3. The bank itself sets percentages or guidelines or even decides on the appropriate provisioning for individual exposures. The adequacy of the provisioning will then be judged by the external auditor and/or by the supervisor.
  5. The supervisor regularly obtains and reviews sufficient and timely information on the country risk and transfer risk of banks. The supervisor has the power to obtain additional information, as needed (eg in crisis situations).

Principle 22 - Market risk

40.50

Principle 22:64 The supervisor determines that banks have an adequate market risk management process that considers risk appetite, risk profile, market and macroeconomic conditions, and the risk of a significant deterioration in market liquidity. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate market risks on a timely basis.

40.51

Essential criteria:

  1. Laws, regulations or the supervisor require banks to have appropriate market risk management processes that provide a comprehensive bank-wide view of market risk exposure. The supervisor determines that the processes are consistent with the risk appetite, risk profile, systemic importance and capital strength of the bank; that they consider market and macroeconomic conditions and the risk of a significant deterioration in market liquidity; and that they clearly articulate the roles and responsibilities for identifying, measuring, monitoring, reporting and controlling market risk.
  2. The supervisor determines that a bank's strategies and policies for the management of market risk have been approved and are regularly reviewed by the bank's board. The supervisor also determines that the board oversees management in a way that ensures that these policies are implemented effectively and fully integrated into the bank's overall risk management process.
  3. The supervisor determines that the bank's policies and processes establish an appropriate and properly controlled market risk environment including:
    1. comprehensive risk measurement systems for the accurate and timely identification, aggregation, monitoring and reporting of market risk exposures to the bank's board and senior management;
    2. appropriate market risk limits, which are consistent with the bank's risk appetite, risk profile, capital strength and management's ability to manage market risk and which are understood by and regularly communicated to relevant staff;
    3. exception tracking and reporting processes that ensure prompt action at the appropriate level of the bank's senior management or board, where necessary;
    4. effective controls around the use of models to identify and measure market risk, and set limits; and
    5. sound policies and processes for the allocation of exposures to the trading book.
  4. The supervisor determines that there are systems and controls to ensure that banks' marked to market positions are revalued frequently. The supervisor also determines that all transactions are captured on a timely basis and that the valuation process uses consistent and prudent practices and reliable market data verified by a function independent of the relevant risk-taking business units (or, in the absence of market prices, internal or industry-accepted models). To the extent that the bank relies on modelling for the purposes of valuation, the bank is required to ensure that the model is validated regularly by a function independent of the relevant risk-taking business units. The supervisor requires banks to establish and maintain policies and processes for considering valuation adjustments for positions that otherwise cannot be prudently valued, including concentrated, less liquid and stale positions.
  5. The supervisor determines that banks hold appropriate levels of capital against unexpected losses and make appropriate valuation adjustments for uncertainties in determining the fair value of assets and liabilities.

Principle 23 - Interest rate risk in the banking book

40.52

Principle 23:65 The supervisor determines that banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book on a timely basis.66 These systems consider the bank's risk appetite, risk profile and market and macroeconomic conditions.

65

Reference documents: BCBS, High-level considerations on proportionality, July 2022; SRP31.

66

Wherever “interest rate risk” is used in this principle the term refers to interest rate risk in the banking book. Interest rate risk in the trading book is covered under Principle 22 BCP40.50.

40.53

Essential criteria: 

  1. Laws, regulations or the supervisor require banks to have an appropriate interest rate risk strategy and interest rate risk management framework that provides a comprehensive bank-wide view of interest rate risk. This includes policies and processes to identify, measure, evaluate, monitor, report and control or mitigate material sources of interest rate risk. The supervisor determines that the bank's strategy, policies and processes are consistent with the risk appetite, risk profile and systemic importance of the bank, that they consider market and macroeconomic conditions, and that they are regularly reviewed and appropriately adjusted, where necessary, in line with the bank's changing risk profile and market developments.
  2. The supervisor determines that a bank's strategies and policies for the management of interest rate risk have been approved and are regularly reviewed by the bank's board. The supervisor also determines that the board oversees management in a way that ensures that these policies are implemented effectively and fully integrated into the bank's overall risk management process.
  3. The supervisor determines that a bank's policies and processes establish an appropriate and properly controlled interest rate risk environment, including:
    1. comprehensive risk measurement systems for the accurate and timely identification, aggregation, monitoring and reporting of interest rate risk exposures to the bank's board and senior management;
    2. a regular review and independent (internal or external) validation of any models used by the functions tasked with managing interest rate risk (including a review of key model assumptions, eg regarding optional elements (whether implicit or explicit) embedded in a bank's assets, liabilities and/or off-balance sheet items, in which the bank or its customer can alter the level and timing of their cash flows);
    3. appropriate limits, approved by the bank's board and senior management, that reflect the bank's risk appetite, risk profile and capital strength and that are understood by and regularly communicated to relevant staff; and
    4. effective exception tracking and reporting processes which ensure prompt action at the appropriate level of the bank's senior management or board, where necessary.
  4. The supervisor obtains from banks the results of their internal interest rate risk measurement systems, expressed in terms of the threat to both economic value and earnings, using standardised interest rate shocks on the banking book.
  5. The supervisor assesses whether the internal capital measurement systems of banks adequately capture interest rate risk in the banking book.

Principle 24 - Liquidity risk

40.54

Principle 24:67 The supervisor sets prudent and appropriate liquidity requirements (which can include either quantitative or qualitative requirements or both) that reflect the liquidity needs of banks. The supervisor determines that banks have a strategy that enables prudent management of liquidity risk and compliance with liquidity requirements. The strategy considers the bank's risk profile, market and macroeconomic conditions, and includes prudent policies and processes, consistent with the bank's risk appetite, to identify, measure, evaluate, monitor, report and control or mitigate liquidity risk over an appropriate set of time horizons. At least for internationally active banks, liquidity (including funding) requirements are not lower than the applicable Basel standards.

40.55

Essential criteria: 

  1. Laws, regulations or the supervisor require banks to consistently observe prescribed liquidity requirements, including thresholds with reference to which a bank is subject to supervisory action. At least for internationally active banks, the prescribed requirements are not lower than those prescribed in the applicable Basel standards, and the supervisor uses a range of liquidity monitoring tools no less extensive than those prescribed in the applicable Basel standards.
  2. The prescribed liquidity requirements reflect the liquidity risk profile of banks (including on- and off-balance sheet risks) in the context of the markets and macroeconomic conditions in which they operate.
  3. The supervisor determines that banks have a robust liquidity management framework that requires them to maintain sufficient liquidity to withstand a range of stress events and that includes appropriate policies for managing liquidity risk, which have been approved by the bank's board. The supervisor also determines that these policies and processes provide a comprehensive bank-wide view of liquidity risk and are consistent with the bank's liquidity risk tolerance, risk profile and systemic importance.
  4. The supervisor determines that a bank's liquidity strategy, policies and processes establish an appropriate and properly controlled liquidity risk environment, including:
    1. clear articulation of an overall liquidity risk appetite that is appropriate for the bank's business and its role in the financial system, and that is approved by the bank's board;
    2. sound day-to-day and intraday liquidity risk management practices;
    3. comprehensive risk measurement systems for the accurate and timely identification, aggregation, monitoring, reporting and control of liquidity risk exposures and funding needs (including active management of collateral positions) bank-wide;
    4. adequate oversight by the bank's board to ensure that management effectively implements policies and processes for the management of liquidity risk in a manner consistent with the bank's liquidity risk appetite; and
    5. regular review by the bank's board (at least annually) and appropriate adjustment of the bank's strategy, policies and processes for the management of liquidity risk given the bank's changing risk profile and external developments in the markets and macroeconomic conditions in which it operates.
  5. The supervisor requires banks to establish, and regularly review, funding strategies, policies and processes for the ongoing measurement and monitoring of funding requirements and the effective management of funding risk. The policies and processes include consideration of how other risks (eg credit, market, operational and reputational risks) may impact the bank's overall liquidity strategy, and include:
    1. an analysis of funding requirements under alternative scenarios;
    2. the maintenance of a cushion of high-quality, unencumbered, liquid assets that can be used, without impediment, to obtain funding in times of stress;
    3. diversification in the sources (including counterparties, instruments, currencies and markets) and tenor of funding, and regular review of concentration limits;
    4. regular efforts to establish and maintain relationships with liability holders; and
    5. regular assessment of the capacity to monetise assets.
  6. The supervisor determines that banks have robust liquidity contingency funding plans to handle liquidity problems. The supervisor determines that the bank's contingency funding plan is formally articulated, adequately documented and sets out the bank's strategy for addressing liquidity shortfalls in a range of stress environments without placing reliance on lender of last resort support. The supervisor also determines that the bank's contingency funding plan establishes clear lines of responsibility, includes clear communication plans (including communication with the supervisor) and is regularly tested and updated to ensure it is operationally robust. The supervisor assesses whether the bank's contingency funding plan is feasible (given its risk profile and systemic importance) and requires the bank to address any deficiencies.
  7. The supervisor requires banks to include a variety of short-term and protracted bank-specific and market-wide liquidity stress scenarios (individually and in combination), using conservative and regularly reviewed assumptions, into their stress testing programmes for risk management purposes. The supervisor determines that the results of the stress tests are used by the bank to adjust its liquidity risk management strategies, policies and positions and to develop effective contingency funding plans.
  8. The supervisor identifies those banks carrying out significant foreign currency liquidity transformation. Where a bank's foreign currency business is significant, or the bank has significant exposure in a given currency, the supervisor requires the bank to undertake separate analysis of its strategy and monitor its liquidity needs separately for each such significant currency. This includes the use of stress testing to determine the appropriateness of mismatches in that currency and, where appropriate, the setting and regular review of limits on the size of its cash flow mismatches for foreign currencies in aggregate and for each significant currency individually. In such cases, the supervisor also monitors the bank's liquidity needs in each significant currency, and evaluates the bank's ability to transfer liquidity from one currency to another across jurisdictions and legal entities.
  9. The supervisor determines that a bank's level of encumbered balance sheet assets is managed within acceptable limits to mitigate the risks in terms of the impact on the bank's cost of funding and the implications for the sustainability of its long-term liquidity position. The supervisor requires banks to commit to adequate disclosure and to set appropriate limits to mitigate identified risks.

Principle 25 - Operational risk and operational resilience

40.56

Principle 25:68 The supervisor determines that banks have an adequate operational risk69 management framework and operational resilience70 approach that considers their risk profile, risk appetite, business environment, tolerance for disruption to their critical operations,71 and emerging risks. This includes prudent policies and processes to: (i) identify, assess, evaluate, monitor, report and control or mitigate operational risk on a timely basis; and (ii) identify and protect themselves from threats and potential failures, respond and adapt to, as well as recover and learn from, disruptive events to minimise their impact on delivering critical operations through disruption.

68

Reference documents: FSB, Enhancing third-party risk management and oversight: a toolkit for financial institutions and financial authorities, December 2023; BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Revisions to the principles for the sound management of operational risk, March 2021; BCBS, Principles for operational resilience, March 2021; BCBS, Cyber resilience: range of practices, December 2018; BCBS, Sound practices implications of fintech developments for banks and bank supervisors, February 2018; FSB, Guidance on identification of critical functions and critical shared services, July 2013; BCBS, Recognising the risk-mitigating impact of insurance in operational risk modelling, October 2010; BCBS, High-level principles for business continuity, August 2006; BCBS, Outsourcing in financial services, February 2005.

69

Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This definition includes legal risk but excludes strategic and reputational risk.

70

Operational resilience refers to the ability of the bank to deliver critical operations through disruption. Operational resilience is an outcome that benefits from the effective management of operational risk.

71

Tolerance for disruption is the level of disruption from any type of operational risk a bank is willing to accept given a range of severe but plausible scenarios. The term “critical operations” encompasses critical functions and includes activities, processes, services and their relevant supporting assets, the disruption of which would be material to the continued operation of the bank or its role in the financial system. Whether a particular operation is critical depends on the nature of the bank and its role in the financial system.

40.57

Essential criteria:

  1. Laws, regulations or the supervisor require banks to have appropriate operational risk management and operational resilience strategies, policies, procedures, systems, controls and processes to:These strategies, policies, procedures, systems and controls are consistent with the bank's risk profile, systemic importance, risk appetite, tolerance for disruption and capital strength, and consider market and macroeconomic conditions and emerging risks.
    1. identify, assess, evaluate, monitor, report and control or mitigate operational risk; and
    2. identify and protect themselves from threats and potential failures, respond and adapt to, as well as recover and learn from, disruptive events to minimise their impact on their delivery of critical operations.
  2. The supervisor determines that a bank's board approves and periodically reviews the strategies and policies for its:The supervisor also requires that the board oversee senior management to ensure that these policies are implemented effectively and fully integrated into the overall framework for managing risks across the bank. The supervisor determines that banks have adequate functions72 for the management of operational risk to identify external and internal threats and potential failures in people, processes and systems on an ongoing basis.
    1. management of operational risk for all material products, activities, processes and systems (including the bank's risk appetite for operational risk); and
    2. operational resilience approach (including tolerance for disruption to critical operations).
  3. The supervisor determines that the bank has identified its critical operations (consistent with its operational resilience approach) and mapped the people, technology, processes, data, facilities, third parties or intragroup entities and the interconnections and interdependencies among them that are necessary for the delivery of critical operations through disruption.
  4. The supervisor determines that banks develop and implement response and recovery plans to manage incidents that could disrupt the delivery of critical operations in line with the bank's risk appetite and tolerance for disruption and that they continuously improve their incident response and recovery plans by incorporating the lessons learnt from previous incidents.
  5. The supervisor requires that banks conduct business continuity exercises under a range of severe but plausible scenarios to test their ability to deliver critical operations through disruption. The supervisor reviews the quality and comprehensiveness of the bank's business continuity and disaster recovery plans to assess their ability to deliver critical operations. In doing so, the supervisor determines that the bank can operate on an ongoing basis and minimise losses and interruptions to service provision in the event of a severe business disruption or failure (including but not limited to disruption at a service provider and disturbances in payment and settlement systems).
  6. Laws, regulations or the supervisor require banks to implement a robust information and communication technology (ICT)73 framework (including cyber security) within their operational risk management framework and operational resilience approach. The supervisor determines that banks have established appropriate policies and processes to identify, assess, mitigate, monitor and manage ICT risks.74 These policies and processes also require the board to regularly oversee the effectiveness of the bank's ICT risk management and senior management to routinely evaluate the design, implementation and effectiveness of the bank's ICT risk management. The supervisor also determines that banks have resilient ICT that is subject to protection, detection, response and recovery processes that are regularly tested, incorporate appropriate situational awareness of vulnerabilities and convey relevant timely information for risk management and decision-making processes to fully support and facilitate the delivery of the bank's critical operations.
  7. The supervisor assesses whether banks have appropriate processes and effective information systems to:
    1. regularly monitor operational risk profiles and material operational exposures;
    2. compile and analyse operational risk event data, which include internal loss data, and, when feasible, external operational loss event data; and
    3. facilitate appropriate reporting mechanisms at the level of the bank's board, senior management, the independent risk function and the business units that support proactive management of operational risk and operational resilience.
  8. The supervisor requires banks to have appropriate reporting mechanisms to keep the supervisor apprised of developments affecting their operational risk, including reporting of incidents that disrupt critical operations, and their severity.
  9. Laws, regulations or the supervisor require the board and senior management to understand the risks associated with bank activities performed by service providers and ensure that effective risk management policies and processes are in place to manage these risks. The supervisor determines that banks have established appropriate policies and processes to assess, manage and monitor bank activities performed by service providers. The supervisor determines that banks' third-party risk management policies cover:
    1. procedures for determining whether and how activities can be provided by service providers, and conducting appropriate due diligence for selecting potential service providers;
    2. sound structuring of the service providers' provision, including ownership and confidentiality of data, as well as termination rights;
    3. managing and monitoring the risks associated with the service provider arrangement, including the financial condition of the service provider;
    4. maintaining an effective control environment at the bank over the service provider, which includes a register of outsourced activities, metrics and reporting to facilitate service provider oversight;
    5. managing dependencies on arrangements, including (but not limited to) those of service providers, for the delivery of critical operations;
    6. maintaining viable contingency planning and developing exit strategies to demonstrate the bank's operational resilience in the event of a failure or disruption at a service provider impacting the provision of critical operations.75 The bank's business continuity plans should assess the substitutability of the service providers that it uses for critical operations and other viable alternatives that may facilitate operational resilience in the event of an outage at a service provider, such as bringing the activity back in-house;
    7. execution of comprehensive contracts and/or service level agreements that ensure a clear allocation of responsibilities between the service provider and the bank; and
    8. the bank's right to inspect the service provider's books and records and ability to request reporting (eg audit reports), and permission for the bank's supervisor to access, directly or via the supervised bank, documentation, data and any other information related to the provision of the activity to the bank.
  10. The supervisor determines that senior management has established a change management process76 that is comprehensive, appropriately resourced, adequately divided up between the risk management and control functions, and conducive to the assessment of potential effects on the delivery of critical operations and on their interconnections and interdependencies.
72

Including control functions, risk management and internal audit.

73

Information and communication technology refers to the underlying physical and logical design of information technology and communication systems, the individual hardware and software components, data and the operating environments.

74

These include cyber security, ICT response and recovery programmes, ICT change management processes, ICT incident management processes and relevant information transmission to users on a timely basis.

75

In developing their exit strategies, banks should consider both near-term and long-term disorderly and orderly exits, as this could impact exit strategies and assumptions.

76

A bank’s operational risk exposure evolves when it initiates change, such as engaging in new activities or developing new products or services; entering into unfamiliar markets or jurisdictions; implementing new business processes or technology systems or modifying existing ones; and/or engaging in businesses that are geographically distant from the head office. Change management should assess the evolution of associated risks across time throughout the full life cycle of a product or service.

40.58

Additional criteria:

  1. The supervisor regularly identifies any common points of exposure across banks to operational risk or potential vulnerability (eg reliance of many banks on a common service provider, disruption to service providers of payment and settlement activities, exposures to losses from physical risks or from geopolitical events).
  2. The supervisor assesses concentration risk-related arrangements, and potential systemic risks arising from the concentration of services provided by specific service providers to banks within its jurisdiction.

Principle 26 - Internal control and audit

40.59

Principle 26:77 The supervisor determines that banks have adequate internal control frameworks to establish and maintain an effectively controlled and tested operating environment for the conduct of their business, considering their risk profile. These include clear arrangements for delegating authority and responsibility; separation of the functions that involve committing the bank, paying away its funds, and accounting for its assets and liabilities; reconciliation of these processes; safeguarding the bank's assets; and appropriate independent78 internal audit (including those that are outsourced or co-sourced), compliance and other control functions to test adherence to and effectiveness of these controls as well as applicable laws and regulations.

77

Reference documents: BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Corporate governance principles for banks, July 2015; BCBS, The internal audit function in banks, June 2012; BCBS, Compliance and the compliance function in banks, April 2005; BCBS, Framework for internal control systems in banking organisations, September 1998.

78

In assessing independence, supervisors give due regard to the control systems designed to avoid conflicts of interest in the performance measurement of staff in the compliance, control and internal audit functions. For example, the remuneration of such staff should be determined independently of the business lines that they oversee.

40.60

Essential criteria:

  1. Laws, regulations or the supervisor require banks to have internal control frameworks that are adequate to establish an effectively controlled and tested operating environment for the conduct of their business, considering their risk profile with a forward-looking view.79 These controls are the responsibility of the bank's board and/or senior management and deal with organisational structure, accounting policies and processes, checks and balances, and the safeguarding of assets and investments (including measures for the prevention and early detection and reporting of misuse, such as fraud, embezzlement, unauthorised trading and computer intrusion). More specifically, these controls address:
    1. organisational structure: definitions of duties and responsibilities, including clear delegation of authority (eg clear loan approval limits), decision-making policies and processes, separation of critical functions (eg business origination, payments, reconciliation, risk management, accounting, audit and compliance);
    2. accounting policies and processes, such as but not limited to: reconciliation of accounts, control lists, information for management;
    3. checks and balances (or "four-eyes principle"): segregation of duties, cross-checking, dual control of assets, double signatures; and
    4. safeguarding assets and investments: including physical control and computer access.
  2. The supervisor determines that there is an appropriate balance in the skills and resources of the back office, control functions and operational management relative to the business origination units. The supervisor also determines that the staff of the back office and control functions have sufficient expertise and authority within the organisation (and, where appropriate, in the case of control functions, sufficient access to the bank's board) to be an effective check and balance to the business origination units.
  3. The supervisor determines that banks have an adequately staffed, permanent and independent compliance function that assists senior management in managing effectively the compliance risks faced by the bank. The supervisor determines that staff within the compliance function are suitably trained, have relevant experience and have sufficient authority within the bank to perform their role effectively. The supervisor determines that the bank's board exercises oversight of the management of the compliance function.
  4. The supervisor determines that banks have an independent, permanent and effective internal audit function (including those that are outsourced or co-sourced) charged with:
    1. assessing whether existing policies, processes and internal controls (including risk management, compliance and corporate governance processes) are effective and appropriate and remain sufficient for the bank's business; and
    2. ensuring that policies and processes are complied with.
  5. The supervisor determines that the internal audit function:
    1. has sufficient resources and that staff are suitably trained and have relevant experience to understand and evaluate the business they are auditing;
    2. has appropriate independence and is accountable to the bank's board or to an audit committee of the board, and its status within the bank ensures that senior management reacts to and acts upon its recommendations;
    3. is kept informed in a timely manner of any material changes made to the bank's risk management strategy, policies or processes;
    4. may communicate with any member of staff and has full access to records, files or data of the bank and its affiliates, whenever relevant to the performance of its duties;
    5. employs a methodology that identifies the material risks run by the bank;
    6. prepares an audit plan, which is reviewed regularly, based on its own risk assessment and allocates its resources accordingly; and
    7. has the authority to assess any outsourced functions.
79

The time horizon for establishing a forward-looking view should appropriately reflect climate-related financial risks and emerging risks as needed.

Principle 27 - Financial reporting and external audit

40.61

Principle 27:80 The supervisor determines that banks and banking groups maintain adequate and reliable records, prepare financial statements in accordance with accounting policies and practices that are widely accepted internationally and annually publish information that fairly reflects their financial condition and performance and bears an independent external auditor's opinion. The supervisor also determines that banks and parent companies of banking groups have adequate governance and oversight of the external audit function.

40.62
  1. The supervisor81 holds the bank's board and management responsible for ensuring that financial statements are prepared in accordance with accounting policies and practices that are widely accepted internationally and for ensuring that these are supported by recordkeeping systems to produce adequate and reliable data.
  2. The supervisor holds the bank's board and management responsible for ensuring that the financial statements issued annually to the public bear an independent external auditor's opinion as a result of an audit conducted in accordance with internationally accepted auditing practices and standards.
  3. The supervisor determines that banks use valuation practices consistent with accounting standards widely accepted internationally. The supervisor also determines that the framework, structure and processes for fair value estimation are subject to independent verification and validation, and that banks document any significant differences between the valuations used for financial reporting purposes and for regulatory purposes.
  4. Laws, regulations or the supervisor set out the scope of external audits of banks and the standards to be followed in performing such audits. These should be aligned with internationally accepted standards and require the use of a risk- and materiality-based approach in planning and performing the external audit.
  5. Supervisory guidelines or local auditing standards determine that audits cover several areas, including but not limited to the loan portfolio, loan loss provisions, non-performing exposures, asset valuations, trading and other securities activities, derivatives, asset securitisations, consolidation of off-balance sheet vehicles and other involvement with such vehicles, and the adequacy of internal controls over financial reporting.
  6. The supervisor has the power to reject and rescind the appointment of an external auditor who is deemed to have inadequate expertise or independence or who is not subject to or does not adhere to established professional standards.
  7. The supervisor determines that banks rotate their external auditors (either the firm or individuals within the firm) from time to time.
  8. The supervisor meets periodically with external audit firms to discuss issues of common interest relating to bank operations.
  9. The supervisor requires the external auditor, directly or through the bank, to report to the supervisor matters of material significance, for example: failure to comply with the licensing criteria or breaches of banking or other laws; significant deficiencies and control weaknesses in the bank's financial reporting process; or any other matters that they believe are likely to be of material significance to the safety and soundness of the bank. Laws or regulations provide that auditors who make any such reports in good faith cannot be held liable for breach of the duty of confidentiality.
81

In this essential criterion, the supervisor is not necessarily limited to the banking supervisor. Responsibility for ensuring that financial statements are prepared in accordance with accounting policies and practices may also be vested with securities and market supervisors.

40.63

Additional criterion:

  1. The supervisor has the power to access external auditors' working papers, where necessary.

Principle 28 - Disclosure and transparency

40.64

Principle 28:82 The supervisor determines that banks and banking groups regularly publish information on a consolidated and, where appropriate, solo basis that is easily accessible and fairly reflects their financial condition, performance, risk exposures, risk management strategies and corporate governance policies and processes (including compensation practices). At least for internationally active banks, disclosure requirements are not less stringent than the applicable Basel standards.

40.65
  1. Laws, regulations or the supervisor require periodic public disclosures83 of information by banks on a consolidated and, where appropriate, solo basis that adequately reflect the bank's true financial condition and performance, and adhere to standards promoting comparability, relevance, reliability and timeliness of the information disclosed.
  2. The supervisor determines that the required disclosures include both qualitative and quantitative information on a bank's financial performance, financial position, risk management strategies and practices, risk exposures (including information that will help in understanding a bank's risk exposures during a financial reporting period), aggregate exposures to related parties, transactions with related parties, accounting policies, business models, management, governance (including major share ownership and voting rights) and compensation practices. The scope and content of the information provided and the level of disaggregation and detail are commensurate with the risk profile and systemic importance of the bank. At least for internationally active banks, disclosure requirements are not less stringent than the applicable Basel standards.
  3. Laws, regulations or the supervisor require banks to disclose all material entities in the group structure.
  4. The supervisor or another authority effectively reviews and enforces compliance with disclosure standards.
  5. The supervisor or other relevant authorities regularly publish information on the banking system in aggregate to facilitate public understanding of the banking system and the exercise of market discipline. Such information includes aggregate data on balance sheet indicators and statistical parameters that reflect the principal aspects of banks' operations (balance sheet structure, capital ratios, income earning capacity and risk profiles).
83

In this essential criterion, the disclosure requirement may be found in applicable accounting, stock exchange listing or other similar rules, instead of or in addition to directives issued by the supervisor.

Principle 29 - Abuse of financial services

40.66

Principle 29:84 The supervisor determines that banks have adequate policies and processes, including robust and risk-based85 customer due diligence (CDD) rules and effective compliance functions to promote high ethical and professional standards in the financial sector and prevent the bank from being used intentionally or unintentionally for criminal activities.86

84

Reference documents: FATF Recommendations (February 2012, as amended in November 2023); BCBS, Sound management of risks related to money laundering and financing of terrorism, July 2020; FATF, Guidance on risk-based supervision, March 2021; FATF, Guidance on correspondent banking services, October 2016; FATF, Risk-based approach guidance for the banking sector, October 2014; BCBS, Shell banks and booking offices, January 2003.

85

Adopting a risk-based approach will enable competent authorities and banks to ensure that measures to prevent or mitigate money laundering and terrorist and proliferation financing are commensurate with the identified risks.

86

The Committee is aware that, in some jurisdictions, other authorities, such as a financial intelligence unit, may have primary responsibility for assessing compliance with laws and regulations regarding criminal activities in banks, such as fraud, money laundering and terrorist and proliferation financing. Thus, in the context of this principle, “the supervisor” might refer to such other authorities, particularly in essential criteria 7, 8 and 10. In such jurisdictions, the banking supervisor cooperates with such authorities to achieve adherence with the criteria set out in this principle.

40.67

Essential criteria:

  1. Laws or regulations establish the duties, responsibilities and powers of the supervisor related to the supervision of banks' internal controls and enforcement of compliance with the relevant laws and regulations regarding criminal activities.
  2. The supervisor determines that banks have adequate policies and processes that promote high ethical and professional standards and prevent the bank from being used intentionally or unintentionally for criminal activities. This includes the monitoring, detection and prevention of criminal activity, and reporting of such suspected activities to the appropriate authorities.
  3. In addition to reporting to the financial intelligence unit or other designated authorities, banks report suspicious activities and incidents of fraud to the banking supervisor if such activities/incidents are material to the safety, soundness or reputation of the bank.87
  4. If the supervisor becomes aware of any additional suspicious transactions, it informs the financial intelligence unit and, if applicable, other designated authorities of such transactions. In addition, the supervisor directly or indirectly shares information related to suspected or actual criminal activities with relevant authorities, in a timely manner.
  5. The supervisor determines that banks establish CDD policies and processes that are well documented and communicated to all relevant staff. The supervisor also determines that such policies and processes are integrated into the bank's overall risk management and include appropriate steps to identify, assess, monitor, manage and mitigate the risks of money laundering, terrorist financing and proliferation financing with respect to customers, countries and regions, as well as to products, services, transactions and delivery channels on an ongoing basis. The CDD management programme, on a group-wide basis, has as its essential elements:
    1. a customer acceptance policy that identifies business relationships that the bank will not accept (or will be terminated) based on identified risks;
    2. an ongoing customer identification, verification and due diligence programme, which encompasses verification of beneficial ownership, understanding the purpose and nature of the business relationship, and risk-based reviews to ensure that CDD information is updated and relevant;
    3. policies and processes to monitor transactions on an ongoing basis and identify unusual or potentially suspicious transactions as well as those individuals or entities subject to the United Nations sanctions related to terrorism and proliferation financing;
    4. enhanced due diligence on high-risk accounts (eg escalation to the bank's senior management of decisions on entering into business relationships with these accounts or maintaining such relationships when an existing relationship becomes high-risk);
    5. enhanced due diligence on politically exposed persons (including their family members and close associates) encompassing, among other things, escalation to the bank's senior management of decisions on entering into business relationships with these persons; and
    6. clear rules on what records must be kept on CDD and individual transactions and their retention period. Such records have at least a five-year retention period.
  6. The supervisor determines that banks have specific policies and processes regarding correspondent banking and other similar relationships, in addition to normal due diligence. Such policies and processes include:
    1. gathering sufficient information about their respondent banks to understand fully the nature of their business and customer base, their reputation, how they are supervised and whether they have been subject to money laundering, terrorism financing or proliferation financing investigations or regulatory actions;
    2. prohibitions on establishing or continuing correspondent banking relationships with those banks that do not have adequate controls to manage the risk of criminal activities, that are not effectively supervised by the relevant authorities, or that are considered to be shell banks; and
    3. senior management approval for entering into new correspondent banking relationships.
  7. The supervisor determines that banks have sufficient controls and systems to prevent, identify and report potential abuses of financial services, including money laundering, terrorism financing and proliferation financing.
  8. The supervisor has adequate powers to take action against a bank that does not comply with relevant laws and regulations regarding criminal activities.
  9. The supervisor determines that banks have:
    1. requirements for internal audit and/or external experts to independently evaluate the relevant risk management policies, processes and controls. The supervisor has access to their reports;
    2. effective policies and processes to designate a compliance officer at the bank's management level to manage the financial crimes compliance programme, and a dedicated officer to whom potential abuses of the bank's financial services (including suspicious transactions) are reported;
    3. a compliance function with adequate powers, reporting independence, staff and other resources;
    4. adequate screening policies and processes to ensure high ethical and professional standards when hiring staff or when entering into an agency or outsourcing relationship;
    5. ongoing training programmes for their staff, including on CDD and methods to monitor and detect criminal and suspicious activities; and
    6. policies and processes to report criminal activities by staff to competent authorities.
  10. The supervisor determines that banks have and follow clear policies and processes for staff to report any issues related to the abuse of the banks' financial services to local management and/or the relevant dedicated officer. The supervisor also determines that banks have and utilise adequate management information systems to provide the banks' boards, management and dedicated officers with timely and appropriate information on such activities.
  11. Laws provide that a member of a bank's staff who reports suspicious activity in good faith either internally or directly to the relevant authority cannot be held liable.
  12. The supervisor, directly or indirectly, cooperates with relevant domestic and foreign financial sector authorities or exchanges information with them regarding suspected or actual criminal activities present in banks, where this information is for supervisory purposes.
  13. Unless another authority is responsible, the supervisor has in-house resources with specialist expertise for addressing criminal activities detected in banks. In this case, the supervisor regularly provides information on the risks of money laundering, terrorism financing and proliferation financing to the banks.
  14. The supervisor determines that banks have in place group-wide programmes to address money laundering, terrorist financing and proliferation financing, including policies and procedures for sharing information within the group for these purposes.
87

In accordance with international standards, banks are to report suspicious activities involving cases of potential money laundering, terrorist financing and proliferation financing to the relevant national centre, which is established either as an independent governmental authority or as a department within an existing authority or authorities that serves as a financial intelligence unit.

Background to the Basel Framework

The Basel Framework is a consolidated version of the full set of standards of the Basel Committee on Banking Supervision (BCBS), which is the primary global standard setter for the prudential regulation of banks. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdictions.

Structure

The framework comprises the 14 standards listed below. Each standard is divided into chapters, and many chapters have multiple versions, eg a chapter may have a version that is applicable now and one that will become applicable after the Basel III reforms have been implemented. The full breakdown of all chapters and versions is available here.

If you would like to explore the source material for the consolidated Basel Framework, there is a mapping table that links each of the paragraphs of the BCBS's original published standards to their locations within the first published version the framework.

Other features of the framework include:

  • Interactive cross-references to make it easier to navigate.
  • A "time traveller" feature, which lets you select a future date and see the framework as it is due to apply at that date.
  • Answers to frequently asked questions displayed directly underneath the paragraphs to which they relate.
  • A section to view all past and future planned changes to the Basel Framework.
  • An improved search function, which makes it easier to find specific content in each standard.

If you have any questions or suggestions regarding the consolidated Basel Framework, please let us know at baselcommittee@bis.org.

This standard describes the scope of application of the Basel Framework.

This standard describes the criteria that bank capital instruments must meet to be eligible to satisfy the Basel capital requirements, as well as necessary regulatory adjustments and transitional arrangements.

This standard describes the framework for risk-based capital requirements.

This standard describes how to calculate capital requirements for credit risk.

This standard describes how to calculate capital requirements for market risk and credit valuation adjustment risk.

This standard describes how to calculate capital requirements for operational risk.

This standard describes the simple, transparent, non-risk-based leverage ratio. This measure intends to restrict the build-up of leverage in the banking sector and reinforce the risk-based requirements with a simple, non-risk-based "backstop" measure.

This standard describes the Liquidity Coverage Ratio, a measure which promotes the short-term resilience of a bank's liquidity risk profile.

The net stable funding ratio requires banks to maintain a stable funding profile in relation to the composition of their assets and off-balance-sheet activities.

Large exposures regulation limits the maximum loss that a bank could face in the event of a sudden counterparty failure to a level that does not endanger the bank's solvency. This standard requires banks to measure their exposures to a single counterparty or a group of connected counterparties and limit the size of large exposures in relation to their capital.

This standard establishes minimum standards for margin requirements for non-centrally cleared derivatives. Such requirements reduce systemic risk with respect to non-standardised derivatives by reducing contagion and spillover risks and promoting central clearing.

The Pillar 2 supervisory review process ensures that banks have adequate capital and liquidity to support all the risks in their business, especially with respect to risks not fully captured by the Pillar 1 process, and encourages good risk management.

This standard sets out disclosure requirements, which aim to encourage market discipline.

The Basel Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector.

The Basel Framework homepage lists all 14 standards together with a short description of their content. The "effective as of" date is the date by which the members of the BCBS have agreed to implement the standards. By default, this date is set to the launch date of the consolidated framework for standards that were already in force at the launch of the framework. For standards that have chapters that are due to change in the future, a "next version" date is shown.

Click on the name of any standard to get the list of chapters that it contains. By default, you will see the current versions of the standards that are in effect as of the day you are using the website. In cases where new chapter versions are due to come into effect in the future, the chapter can be accessed by clicking the "new future version" link shown at the bottom of the chapter description.

Video 9 April 2019
Navigating the Basel Framework
This tutorial explains the features of the Basel Committee's consolidated framework, bringing global standards for bank regulation and supervision together in one place.

You might also be interested in