This chapter describes the criteria for assessing compliance with the Core Principles.
The Core Principles establish 29 principles that are needed for a supervisory system to be effective and can be categorised into two groups:
This chapter lists the assessment criteria for each of the 29 Core Principles under two separate headings: "essential criteria" and "additional criteria".
The individual assessment criteria are based on international standards and sound supervisory practices that are already established, even if they have not yet been fully implemented. Where appropriate, the documents on which the criteria are founded have been cited as "reference documents". These documents include more detailed explanations of supervisory expectations and practices. There is the expectation that guidelines issued by the Committee will be observed by Committee member jurisdictions.
Principle 1:1 An effective system of banking supervision has clear responsibilities and objectives for each authority involved in the supervision of banks and banking groups. A suitable legal framework for banking supervision is in place to provide each responsible authority with the necessary legal powers to authorise banks, conduct ongoing supervision, address compliance with laws and undertake timely corrective actions to address safety and soundness concerns.
| 1 | Reference documents: BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Report on the impact and accountability of banking supervision, July 2015; BCBS, Principles for the supervision of financial conglomerates, September 2012; SCO40. |
Essential criteria:
| 2 | If countries have shared or transferred prudential tasks to a supranational supervisor, the roles and responsibilities that have been shared or transferred are clearly set out in law and publicly disclosed. Any residual powers or responsibilities that are retained must be publicly disclosed so that there is clarity on the division of responsibility. |
| 3 | For this purpose, “access” includes supervisory access in person to the bank’s premises, and to senior executive staff and the board (both individual members and as a whole) in person or virtually as needed. |
Principle 2:4 The supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy, and adequate resources, and is accountable for the discharge of its duties and use of its resources. The legal framework for banking supervision includes legal protection for the supervisor.
| 4 | Reference document: BCBS, Report on the impact and accountability of banking supervision, July 2015. |
Essential criteria:
| 5 | The term “supervisor and its staff” is to be understood as covering the head of the authority, the governing body, employees and any professional service providers who carry out tasks for the supervisory authority. As the protection is provided in respect of actions taken and/or omissions made while discharging duties in good faith, it is not removed when the term of appointment, engagement or employment is ended. |
Principle 3: Laws, regulations or other arrangements provide a framework for cooperation and collaboration with relevant domestic authorities and foreign supervisors. These arrangements reflect the need to protect confidential information.6
Essential criteria:
Principle 4: The permissible activities of institutions that are licensed and subject to supervision as banks are clearly defined, and the use of the word "bank" in names is controlled.
Essential criteria:
| 7 | The Committee recognises the existence of non-bank financial institutions that take deposits but may be regulated differently from banks. These institutions should be subject to a form of regulation commensurate to the type and size of their business and, collectively, should not hold a significant proportion of deposits in the financial system. |
Principle 5:8 The licensing authority has the power to set criteria for licensing banks and to reject applications where the criteria are not met. At a minimum, the licensing process consists of an assessment of the ownership structure and governance (including the fitness and propriety of board members and senior management) of the bank and its wider group, its strategic and operating plan, internal controls, risk management and projected financial condition (including capital base). Where the proposed owner or parent organisation is a foreign bank, the prior consent of its home supervisor is obtained.
| 8 | Reference documents: BCBS, Corporate governance principles for banks, July 2015; BCBS, Shell banks and booking offices, January 2003. |
Essential criteria:
Principle 6:12 The supervisor13 has the power to review, reject and impose prudential conditions on any proposals to transfer significant ownership or controlling interests held directly or indirectly in existing banks to other parties.
| 12 | Reference documents: BCBS, Parallel-owned banking structures, January 2003; BCBS, Shell banks and booking offices, January 2003. |
| 13 | While the term “supervisor” is used throughout Principle 6, the Committee recognises that in a few countries these issues might be addressed by a separate licensing authority. |
Essential criteria:
Principle 7: The supervisor has the power to: (i) approve or reject (or recommend to the responsible authority the approval or rejection of) and impose prudential conditions on major acquisitions or investments by a bank (including the establishment of cross-border operations), against prescribed criteria; and (ii) determine that corporate affiliations or structures do not expose the bank to undue risks or hinder effective supervision.
Essential criteria:
| 14 | The supervisor may consider whether the acquisition or investment creates obstacles to the orderly resolution of the bank. |
Principle 8:15 An effective system of banking supervision requires the supervisor to develop and maintain a forward-looking assessment of the risk profile of individual banks, proportionate to their systemic importance; identify, assess and address risks emanating from banks and the banking system as a whole; have a framework in place for early intervention; and have plans in place, in partnership with other relevant authorities, to take action to resolve banks in an orderly manner if they become non-viable.
| 15 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Frameworks for early supervisory intervention, March 2018; BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Guidelines for identifying and dealing with weak banks, July 2015; SRP10, SRP20, SCO50. |
Essential criteria:
The methodology and processes address (among other things): banks' group structure (including risks posed by entities in the wider group); risks around banks' business models, including business model sustainability;16 banks' risk profile with a forward-looking view;17 their internal control environment; and their resolvability. The methodology permits relevant comparisons between banks, and the nature, frequency and intensity of supervision reflect the outcome of this analysis.
Principle 9:18 The supervisor uses an appropriate range of techniques and tools to implement the supervisory approach and deploys supervisory resources on a proportionate basis, considering the risk profile and systemic importance of banks.
| 18 | Reference document: BCBS, High-level considerations on proportionality, July 2022. |
Essential criteria:
Additional criterion:
Principle 10:20 The supervisor collects, reviews and analyses prudential reports and statistical returns21 from banks on both a solo and a consolidated basis, and independently verifies these reports through either on-site examinations or use of external experts.
| 20 | Reference documents: BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Principles for effective risk data aggregation and risk reporting, January 2013; BCBS, Principles for the supervision of financial conglomerates, September 2012. |
| 21 | In the context of this principle, “prudential reports and statistical returns” are distinct from and required in addition to mandatory accounting reports. The former are addressed by this principle, and the latter are addressed in Principle 27 BCP40.61. |
Essential criteria:
Principle 11:22 The supervisor acts at an early stage to address unsafe and unsound practices or activities that could pose risks to banks or to the banking system. The supervisor has at its disposal an adequate range of supervisory tools, that it can apply at its discretion, to bring about timely corrective actions. This includes the ability to revoke the banking licence or to recommend its revocation.
| 22 | Reference document: BCBS, Parallel-owned banking structures, January 2003. |
Essential criteria:
Principle 12:24 The supervisor supervises the banking group on a consolidated basis, adequately monitoring and, as appropriate, applying prudential standards to all aspects of the business conducted by the banking group worldwide.
| 24 | Reference documents: BCBS, Principles for the supervision of financial conglomerates, September 2012; BCBS, Home-host information sharing for effective Basel II implementation, June 2006; BCBS, The supervision of cross-border banking, October 1996; BCBS, Principles for the supervision of banks’ foreign establishments, May 1983; BCBS, Consolidated supervision of banks’ international activities, March 1979; SCO10. |
Essential criteria:
Additional criterion:
Principle 13:26 Home and host supervisors of cross-border banking groups share information and cooperate for effective supervision of the group and group entities, and effective handling of crisis situations. Supervisors require the local operations of foreign banks to be conducted to the same standards as those required of domestic banks.
| 26 | Reference documents: Financial Stability Board (FSB), Key attributes of effective resolution regimes for financial institutions, October 2014; BCBS, Principles for effective supervisory colleges, June 2014; BCBS, Home-host information sharing for effective Basel II implementation, June 2006; BCBS, High-level principles for the cross-border implementation of the New Accord, August 2003; BCBS, Shell banks and booking offices, January 2003; BCBS, The supervision of cross-border banking, October 1996; BCBS, Information flows between banking supervisory authorities, April 1990; BCBS, Principles for the supervision of banks’ foreign establishments, May 1983. |
Essential criteria:
Principle 14:27 The supervisor determines that banks have robust corporate governance policies and processes covering, for example, corporate culture and values, strategic direction and oversight, group and organisational structure, the control environment, the suitability assessment process, the responsibilities of the banks' boards and senior management, and compensation practices. These policies and processes are commensurate with the risk profile and systemic importance of the bank.
| 27 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; FSB, Strengthening governance frameworks to mitigate misconduct risk: a toolkit for firms and supervisors, April 2018; FSB, Supplementary Guidance to the FSB Principles and Standards on Sound Compensation Practices, March 2018; BCBS, Corporate governance principles for banks, July 2015; FSB, Guidance on supervisory interaction with financial institutions on risk culture: a framework for assessing risk culture, April 2014; FSB, Principles for Sound Compensation Practices, April 2009. |
Essential criteria:
| 28 | Independent director refers to a non-executive member of the board who does not have any management responsibilities within the bank and is not under any other undue influence, internal or external, political or ownership, that would impede the board member’s exercise of objective judgment. |
| 29 | The Committee defines: (i) “duty of care” as the duty of board members to decide and act on an informed and prudent basis with respect to the bank. This is often interpreted as requiring board members to approach the affairs of the company the same way that a “prudent person” would approach his or her own affairs; and (ii) “duty of loyalty” as the duty of board members to act in good faith in the interest of the company. The duty of loyalty should prevent individual board members from acting in their own interest, or the interest of another individual or group, at the expense of the company and shareholders. |
| 30 | This includes whistleblowing policies and procedures that protect employees from reprisals or other detrimental treatment. |
Principle 15:31 The supervisor determines that banks have a comprehensive risk management process (including effective board and senior management oversight) to identify, measure, evaluate, monitor, report and control or mitigate all material risks32 (which can include risks related to digitalisation, climate-related financial risks and emerging risks) on a timely basis and to assess the adequacy of their capital, their liquidity and the sustainability of their business models in relation to their risk profile and market and macroeconomic conditions. This extends to the development and review of contingency arrangements (including robust and credible recovery plans where warranted) that consider the specific circumstances of the bank. The risk management process is commensurate with the risk profile and systemic importance of the bank.33
Essential criteria:
| 34 | This includes, where relevant, risks not directly addressed in the subsequent principles, such as reputational, step-in and strategic risks. |
| 35 | Banks should include climate-related financial risks assessed as material over relevant time horizons, including in their stress testing programmes where appropriate. |
| 36 | New products include those developed by the bank or by a third party and purchased or distributed by the bank. |
Principle 16:37 The supervisor sets prudent and appropriate capital adequacy requirements for banks that reflect the risks undertaken and presented by a bank in the context of the markets and macroeconomic conditions in which it operates.38 The supervisor defines the components of capital, bearing in mind their ability to absorb losses. At least for internationally active banks, capital requirements are not less stringent than the applicable Basel standards.
| 37 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Guiding principles for the operationalisation of a sectoral countercyclical capital buffer, November 2019; SCO10, SCO30, CAP10, CAP30, CAP50, CAP99, RBC20, RBC30, RBC40, LEV10, LEV20, LEV30, SRP10, SRP20. |
| 38 | Implementation of the Basel Framework is not a prerequisite for compliance with the Core Principles. Compliance with the Basel Framework capital adequacy regimes is only required of those jurisdictions that have declared that they have voluntarily implemented it. |
Essential criteria:
| 39 | Capital adequacy requirements for internationally active banks should be applied on a fully consolidated basis, including any holding company that is the parent entity within a banking group. The framework will apply to all internationally active banks at every tier within a banking group, on a fully consolidated basis. As an alternative to full sub-consolidation, the application of this framework to the standalone bank (ie on a basis that does not consolidate assets and liabilities of subsidiaries) would achieve the same objective, providing the full book value of any investments in subsidiaries and significant minority-owned stakes is deducted from the bank’s capital. Supervisors must also test that individual banks are adequately capitalised on a standalone basis. |
Additional criteria:
Principle 17:41 The supervisor determines that banks have an adequate credit risk management process that considers their risk appetite, risk profile, market conditions, macroeconomic factors and forward-looking information. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate credit risk42 (including counterparty credit risk43) on a timely basis. The full credit life cycle is covered, including credit underwriting, credit evaluation and the ongoing management of the bank's loan and investment portfolios.
| 41 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Guidance on credit risk and accounting for expected credit losses, December 2015; FSB, Principles for sound residential mortgage underwriting practices, April 2012; CRE20, CRE40, CRE45, CRE50, CRE51, CRE54, MGN10, MGN20. |
| 42 | Credit risk may result from: on-balance sheet and off-balance sheet exposures, including loans and advances; investments; interbank lending; derivative transactions; securities financing transactions; and trading activities. |
| 43 | Transactions that give rise to counterparty credit risk include: OTC derivatives, exchange-traded derivatives, long settlement transactions and securities financing transactions that are bilaterally or centrally cleared. Counterparty credit risk may result from (but is not limited to) transactions with banks, non-financial corporates and non-bank financial institutions. |
Essential criteria:
approving new exposures (including prudent underwriting standards), and ensuring a thorough understanding of the risk profile and characteristics of the borrowers (and in the case of securitisation exposures all features of securitisation transactions)44 that would materially impact the performance of these exposures;
renewing and refinancing existing exposures; and
identifying the appropriate approval authority for the size and complexity of the exposures;
| 44 | Securitisation includes both traditional and synthetic securitisations (or similar structures that contain features common to both). Where appropriate, supervisors should provide guidance about whether a given transaction should be considered a securitisation. |
Principle 18:45 The supervisor determines that banks have adequate policies and processes for the early identification and management of problem exposures46 and the maintenance of adequate provisions47 and reserves.48
| 45 | Reference documents: BCBS, Prudential treatment of problem assets – definitions of non-performing exposures and forbearance, April 2017; BCBS, Guidance on credit risk and accounting for expected credit losses, December 2015. |
| 46 | For banks’ internal risk management purposes, a problem exposure is an exposure for which there is reason to believe that all amounts due, including the principal and interest, may not be collected in accordance with the contractual terms of the agreement with the counterparty. |
| 47 | Principle 18 covers all provisioning approaches (eg incurred loss models, expected credit loss models, calendar provisioning) that are used for prudential purposes. In some jurisdictions, cumulative provisions are referred to as loss allowances. |
| 48 | Reserves for the purposes of this principle are “below the line” non-distributable appropriations of profit required by a supervisor in addition to provisions (“above the line” charges to profit). |
Essential criteria:
| 49 | A forborne exposure is an exposure for which a bank’s counterparty is experiencing financial difficulty in meeting its financial commitments and the bank grants a concession that it would not otherwise consider. |
| 50 | Provisions are not limited to problem exposures. Depending on the relevant jurisdiction’s accounting and prudential frameworks, provisions may be required for a wider range of exposures (eg all exposures, including performing exposures, under expected credit loss frameworks). |
Principle 19:51 The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate concentrations of risk on a timely basis. Supervisors set prudential limits to restrict bank exposures to single counterparties or groups of connected counterparties.52 At least for internationally active banks, large exposure requirements are not less stringent than the applicable Basel standard.
| 51 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; Joint Forum, Cross-sectoral review of group-wide identification and management of risk concentrations, April 2008; BCBS, Principles for the management of credit risk, September 2000; LEX10, LEX20, LEX30, LEX40. |
| 52 | Connected counterparties may include natural persons as well as legal persons. Two or more natural or legal persons shall be deemed a group of connected counterparties if at least one of the following criteria is satisfied: (a) control relationship: one of the counterparties, directly or indirectly, has control over the other(s); or (b) economic interdependence: if one of the counterparties were to experience financial problems, the other(s), as a result, would also be likely to encounter financial difficulties. |
Essential criteria:
| 53 | Concentration risk may result from credit, market and other risk where a bank is overly exposed to particular asset classes, products, collateral, currencies or funding sources, and is broader than exposures subject to large exposure requirements. Credit concentrations include exposures to: single counterparties (including collateral credit protection and other commitments provided); groups of connected counterparties; counterparties in the same industry, economic sector or geographic region; and counterparties whose financial performance is dependent on the same activity or commodity. |
| 54 | The measure of credit exposure for large exposures should reflect the maximum possible loss from counterparty failure (ie it should encompass actual and potential exposures as well as contingent liabilities). The risk weighting concept adopted in the Basel Framework should not be used in measuring credit exposure for this purpose, as its use for measuring credit concentrations could significantly underestimate potential losses. |
Additional criterion:
Principle 20:55 To prevent abuses arising in transactions with related parties56 and to address the risk of conflicts of interest, the supervisor requires banks to: enter into any transactions with related parties on an arm's length basis;57 monitor these transactions; take appropriate steps to control or mitigate the risks; and write off exposures to related parties in accordance with standard policies and processes.
| 55 | Reference documents: BCBS, Corporate governance principles for banks, July 2015; BCBS, Principles for the management of credit risk, September 2000. |
| 56 | Related parties should include: (a)the bank’s subsidiaries and affiliates (including their subsidiaries, affiliates and special purpose entities) and any other party that the bank exerts control over or that exerts control over the bank; (b)the bank’s major shareholders, including beneficial owners; (c)the bank’s board members, senior management and key staff, corresponding persons in affiliated companies, and parties that can exert significant influence on board members or senior management; and (d)for the natural persons identified in (a) to (c), their direct and related interests and their close family members. |
| 57 | Related party transactions include on-balance sheet and off-balance sheet credit exposures; dealings such as service contracts, asset purchases and sales, construction contracts and lease agreements; derivative transactions; borrowings; and write-offs. The term “transaction” should be interpreted broadly to incorporate not only transactions that are entered into with related parties but also situations in which an unrelated party (with whom a bank has an existing exposure) subsequently becomes a related party. |
| 58 | Exceptions may be appropriate for certain transactions between entities within a banking group when the supervisor considers this to be consistent with sound group-wide risk management. An exception may also be appropriate for beneficial terms that are part of overall remuneration packages. |
| 59 | For this purpose, exposures should be calculated consistently with Principle 19 BCP40.43. |
| 60 | The supervisor may exclude banks’ exposures to certain entities within the banking group where the supervisor considers this to be consistent with sound group-wide risk management. |
Principle 21:61 The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate country risk62 and transfer risk63 in their international lending and investment activities on a timely basis.
| 61 | Reference documents: IMF, External debt statistics – guide for compilers and users, 2013; BCBS, Management of banks’ international lending: country risk analysis and country exposure measurement and control, March 1982. |
| 62 | Country risk is the risk of exposure to loss caused by events in a foreign country. The concept is broader than sovereign risk as all forms of lending or investment activity involving individuals, corporates, banks or governments are covered. |
| 63 | Transfer risk is the risk that a borrower will not be able to convert local currency into a foreign currency and so will be unable to make debt service payments in a foreign currency. The risk normally arises from exchange restrictions imposed by the government in the borrower’s country. |
Principle 22:64 The supervisor determines that banks have an adequate market risk management process that considers risk appetite, risk profile, market and macroeconomic conditions, and the risk of a significant deterioration in market liquidity. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate market risks on a timely basis.
Essential criteria:
Principle 23:65 The supervisor determines that banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book on a timely basis.66 These systems consider the bank's risk appetite, risk profile and market and macroeconomic conditions.
| 65 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; SRP31. |
| 66 | Wherever “interest rate risk” is used in this principle the term refers to interest rate risk in the banking book. Interest rate risk in the trading book is covered under Principle 22 BCP40.50. |
Essential criteria:
Principle 24:67 The supervisor sets prudent and appropriate liquidity requirements (which can include either quantitative or qualitative requirements or both) that reflect the liquidity needs of banks. The supervisor determines that banks have a strategy that enables prudent management of liquidity risk and compliance with liquidity requirements. The strategy considers the bank's risk profile, market and macroeconomic conditions, and includes prudent policies and processes, consistent with the bank's risk appetite, to identify, measure, evaluate, monitor, report and control or mitigate liquidity risk over an appropriate set of time horizons. At least for internationally active banks, liquidity (including funding) requirements are not lower than the applicable Basel standards.
Essential criteria:
Principle 25:68 The supervisor determines that banks have an adequate operational risk69 management framework and operational resilience70 approach that considers their risk profile, risk appetite, business environment, tolerance for disruption to their critical operations,71 and emerging risks. This includes prudent policies and processes to: (i) identify, assess, evaluate, monitor, report and control or mitigate operational risk on a timely basis; and (ii) identify and protect themselves from threats and potential failures, respond and adapt to, as well as recover and learn from, disruptive events to minimise their impact on delivering critical operations through disruption.
| 68 | Reference documents: FSB, Enhancing third-party risk management and oversight: a toolkit for financial institutions and financial authorities, December 2023; BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Revisions to the principles for the sound management of operational risk, March 2021; BCBS, Principles for operational resilience, March 2021; BCBS, Cyber resilience: range of practices, December 2018; BCBS, Sound practices implications of fintech developments for banks and bank supervisors, February 2018; FSB, Guidance on identification of critical functions and critical shared services, July 2013; BCBS, Recognising the risk-mitigating impact of insurance in operational risk modelling, October 2010; BCBS, High-level principles for business continuity, August 2006; BCBS, Outsourcing in financial services, February 2005. |
| 69 | Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This definition includes legal risk but excludes strategic and reputational risk. |
| 70 | Operational resilience refers to the ability of the bank to deliver critical operations through disruption. Operational resilience is an outcome that benefits from the effective management of operational risk. |
| 71 | Tolerance for disruption is the level of disruption from any type of operational risk a bank is willing to accept given a range of severe but plausible scenarios. The term “critical operations” encompasses critical functions and includes activities, processes, services and their relevant supporting assets, the disruption of which would be material to the continued operation of the bank or its role in the financial system. Whether a particular operation is critical depends on the nature of the bank and its role in the financial system. |
Essential criteria:
| 72 | Including control functions, risk management and internal audit. |
| 73 | Information and communication technology refers to the underlying physical and logical design of information technology and communication systems, the individual hardware and software components, data and the operating environments. |
| 74 | These include cyber security, ICT response and recovery programmes, ICT change management processes, ICT incident management processes and relevant information transmission to users on a timely basis. |
| 75 | In developing their exit strategies, banks should consider both near-term and long-term disorderly and orderly exits, as this could impact exit strategies and assumptions. |
| 76 | A bank’s operational risk exposure evolves when it initiates change, such as engaging in new activities or developing new products or services; entering into unfamiliar markets or jurisdictions; implementing new business processes or technology systems or modifying existing ones; and/or engaging in businesses that are geographically distant from the head office. Change management should assess the evolution of associated risks across time throughout the full life cycle of a product or service. |
Additional criteria:
Principle 26:77 The supervisor determines that banks have adequate internal control frameworks to establish and maintain an effectively controlled and tested operating environment for the conduct of their business, considering their risk profile. These include clear arrangements for delegating authority and responsibility; separation of the functions that involve committing the bank, paying away its funds, and accounting for its assets and liabilities; reconciliation of these processes; safeguarding the bank's assets; and appropriate independent78 internal audit (including those that are outsourced or co-sourced), compliance and other control functions to test adherence to and effectiveness of these controls as well as applicable laws and regulations.
| 77 | Reference documents: BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Corporate governance principles for banks, July 2015; BCBS, The internal audit function in banks, June 2012; BCBS, Compliance and the compliance function in banks, April 2005; BCBS, Framework for internal control systems in banking organisations, September 1998. |
| 78 | In assessing independence, supervisors give due regard to the control systems designed to avoid conflicts of interest in the performance measurement of staff in the compliance, control and internal audit functions. For example, the remuneration of such staff should be determined independently of the business lines that they oversee. |
Essential criteria:
| 79 | The time horizon for establishing a forward-looking view should appropriately reflect climate-related financial risks and emerging risks as needed. |
Principle 27:80 The supervisor determines that banks and banking groups maintain adequate and reliable records, prepare financial statements in accordance with accounting policies and practices that are widely accepted internationally and annually publish information that fairly reflects their financial condition and performance and bears an independent external auditor's opinion. The supervisor also determines that banks and parent companies of banking groups have adequate governance and oversight of the external audit function.
| 80 | Reference documents: BCBS, Supplemental note to external audits of banks – audit of expected credit loss, December 2020; BCBS, External audits of banks, March 2014; BCBS, Supervisory guidance for assessing banks’ financial instrument fair value practices, April 2009. |
| 81 | In this essential criterion, the supervisor is not necessarily limited to the banking supervisor. Responsibility for ensuring that financial statements are prepared in accordance with accounting policies and practices may also be vested with securities and market supervisors. |
Additional criterion:
Principle 28:82 The supervisor determines that banks and banking groups regularly publish information on a consolidated and, where appropriate, solo basis that is easily accessible and fairly reflects their financial condition, performance, risk exposures, risk management strategies and corporate governance policies and processes (including compensation practices). At least for internationally active banks, disclosure requirements are not less stringent than the applicable Basel standards.
| 82 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Corporate governance principles for banks, July 2015; FSB, Enhancing the risk disclosure of banks, October 2012; BCBS, Enhancing bank transparency, September 1998; DIS10, DIS20, DIS21, DIS25, DIS26, DIS30, DIS31, DIS35, DIS40, DIS42, DIS43, DIS45, DIS50, DIS51, DIS60, DIS70, DIS75, DIS80, DIS85, DIS99. |
| 83 | In this essential criterion, the disclosure requirement may be found in applicable accounting, stock exchange listing or other similar rules, instead of or in addition to directives issued by the supervisor. |
Principle 29:84 The supervisor determines that banks have adequate policies and processes, including robust and risk-based85 customer due diligence (CDD) rules and effective compliance functions to promote high ethical and professional standards in the financial sector and prevent the bank from being used intentionally or unintentionally for criminal activities.86
| 84 | Reference documents: FATF Recommendations (February 2012, as amended in November 2023); BCBS, Sound management of risks related to money laundering and financing of terrorism, July 2020; FATF, Guidance on risk-based supervision, March 2021; FATF, Guidance on correspondent banking services, October 2016; FATF, Risk-based approach guidance for the banking sector, October 2014; BCBS, Shell banks and booking offices, January 2003. |
| 85 | Adopting a risk-based approach will enable competent authorities and banks to ensure that measures to prevent or mitigate money laundering and terrorist and proliferation financing are commensurate with the identified risks. |
| 86 | The Committee is aware that, in some jurisdictions, other authorities, such as a financial intelligence unit, may have primary responsibility for assessing compliance with laws and regulations regarding criminal activities in banks, such as fraud, money laundering and terrorist and proliferation financing. Thus, in the context of this principle, “the supervisor” might refer to such other authorities, particularly in essential criteria 7, 8 and 10. In such jurisdictions, the banking supervisor cooperates with such authorities to achieve adherence with the criteria set out in this principle. |
Essential criteria:
| 87 | In accordance with international standards, banks are to report suspicious activities involving cases of potential money laundering, terrorist financing and proliferation financing to the relevant national centre, which is established either as an independent governmental authority or as a department within an existing authority or authorities that serves as a financial intelligence unit. |
This standard describes the scope of application of the Basel Framework.
This standard describes the criteria that bank capital instruments must meet to be eligible to satisfy the Basel capital requirements, as well as necessary regulatory adjustments and transitional arrangements.
This standard describes the framework for risk-based capital requirements.
This standard describes how to calculate capital requirements for credit risk.
This standard describes how to calculate capital requirements for market risk and credit valuation adjustment risk.
This standard describes how to calculate capital requirements for operational risk.
This standard describes the simple, transparent, non-risk-based leverage ratio. This measure intends to restrict the build-up of leverage in the banking sector and reinforce the risk-based requirements with a simple, non-risk-based "backstop" measure.
This standard describes the Liquidity Coverage Ratio, a measure which promotes the short-term resilience of a bank's liquidity risk profile.
The net stable funding ratio requires banks to maintain a stable funding profile in relation to the composition of their assets and off-balance-sheet activities.
Large exposures regulation limits the maximum loss that a bank could face in the event of a sudden counterparty failure to a level that does not endanger the bank's solvency. This standard requires banks to measure their exposures to a single counterparty or a group of connected counterparties and limit the size of large exposures in relation to their capital.
This standard establishes minimum standards for margin requirements for non-centrally cleared derivatives. Such requirements reduce systemic risk with respect to non-standardised derivatives by reducing contagion and spillover risks and promoting central clearing.
The Pillar 2 supervisory review process ensures that banks have adequate capital and liquidity to support all the risks in their business, especially with respect to risks not fully captured by the Pillar 1 process, and encourages good risk management.
This standard sets out disclosure requirements, which aim to encourage market discipline.
The Basel Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector.