| Guidelines This chapter sets out corporate governance principles for banks that focus on: (i) the responsibilities of the board and senior management; (ii) roles and responsibilities of the risk management and control functions; (iii) compensation and disclosure expectations; and (iv) the role of supervisors. The contents of this chapter are based on:
|
| Related standards |
| Related guidelines |
Effective corporate governance is critical to the proper functioning of the banking sector and the economy as a whole. Governance weaknesses at banks that play a significant role in the financial system can result in the transmission of problems across the banking sector and broader economy.
Corporate governance determines the allocation of authority and responsibilities by which the business and affairs of a bank are carried out by its board and senior management, including how they:
The primary objective of corporate governance should be safeguarding stakeholders’ interest in conformity with public interest on a sustainable basis. Among stakeholders, particularly with respect to retail banks, shareholders’ interest would be secondary to depositors' interest.
Supervisors have a keen interest in sound corporate governance, as it is an essential element in the safe and sound functioning of a bank and may adversely affect the bank’s risk profile if not operating effectively. Well governed banks contribute to the maintenance of an efficient and cost-effective supervisory process.
Sound corporate governance may permit the supervisor to place more reliance on the bank’s internal processes. In this regard, supervisory experience underscores the importance of having the appropriate levels of authority, responsibility, accountability, and checks and balances within each bank, including those of the board of directors but also of senior management and the risk, compliance and internal audit functions.
The following terms are used throughout this chapter and have the meaning given below:1
| 1 | See also FSB, Principles for an effective risk appetite framework, November 2013; FSB, Guidance on supervisory interaction with financial institutions on risk culture, April 2014. |
This chapter is intended to guide the actions of board members, senior managers, control function heads and supervisors of a diverse range of banks in a number of countries with varying legal and regulatory systems, including both Committee member and non-member jurisdictions.2 There are significant differences in the legislative and regulatory frameworks across countries which may restrict the application of certain principles or provisions. Each jurisdiction should apply the provisions as the national authorities see fit. In some cases, this may involve legal change. In other cases, a principle may require slight modification to be implemented.
| 2 | The guidance set out in this chapter draws from the G20/OECD Principles of Corporate Governance, revised in 2023. |
The principles set forth in this document are relevant regardless of whether or not a jurisdiction chooses to implement the Basel Framework. The board and senior management at each bank have an obligation to pursue good governance.3
| 3 | This includes state-owned or state-supported banks, including when such support is temporary. See also OECD, Guidelines on Corporate Governance of State-Owned Enterprises, 2024. |
The implementation of these principles should be commensurate with the size, complexity, structure, economic significance, risk profile and business model of the bank and the group (if any) to which it belongs. This means making reasonable adjustments where appropriate for banks with lower risk profiles, and being alert to the higher risks that may accompany more complex and publicly listed institutions.4,5 Systemically important financial institutions (SIFIs) are expected to implement corporate governance structures and practices commensurate with their role in and potential impact on national and global financial stability.
| 4 | Some countries have governance, accounting and auditing standards which may be more extensive and prescriptive for larger or publicly listed institutions than the principles set forth in this chapter. |
| 5 | Shareholder rights are not the primary focus of this guidance and are addressed in the corporate governance principles issued by the OCED. However, the exercise of shareholder rights is important, particularly when certain shareholders have the right to have a representative on the board. In such cases, the suitability of the appointed board member is as critical as their awareness of the responsibility to look after the interests of the bank as a whole, not just of the shareholders. |
This chapter refers to a governance structure composed of a board of directors and senior management. Some countries use a formal two-tier structure, where the supervisory function of the board is performed by a separate entity known as a supervisory board or audit and supervisory board, which has no executive functions. Other countries use a one-tier structure in which the board of directors has a broader role. Still other countries have moved or are moving to a mixed approach that discourages or prohibits executives from serving on the board of directors or limits their number and/or requires the board and board committees to be chaired only by non-executive or independent board members. Some countries also prohibit the chief executive officer (CEO) from serving as chair of the board of directors or even from being part of the board of directors. Owing to these differences, this chapter does not advocate any specific board or governance structure. The terms “board of directors” and “senior management” are used mainly from the perspective of a one-tier board structure. These terms should be interpreted throughout the chapter in accordance with the applicable law within each jurisdiction.
Recognising that different structural approaches to corporate governance exist across countries and that these structures evolve over time, this chapter encourages legislators, supervisors, banks and others to frequently review their practices to strengthen checks and balances and sound corporate governance under diverse structures. The application of corporate governance standards in any jurisdiction is naturally expected to be pursued in a manner consistent with applicable national laws, regulations and codes (eg considering the existence of oversight boards in some jurisdictions).
Effective implementation of sound corporate governance requires relevant legal, regulatory and institutional foundations. A variety of factors, including the system of business laws, stock exchange rules and accounting standards, can affect market integrity and systemic stability. Such factors, however, are often outside the scope of banking supervision. Supervisors are nevertheless encouraged to be aware of legal and institutional impediments to sound corporate governance, and to take steps to foster effective foundations for corporate governance where it is within their legal authority to do so. Where it is not, supervisors may wish to consider supporting legislative or other reforms that would allow them to have a more direct role in promoting or requiring sound corporate governance.
The board has overall responsibility for the bank, including approving and overseeing management’s implementation of the bank’s strategic objectives, governance framework and corporate culture.
The board has ultimate responsibility for the bank’s business strategy and financial soundness, key personnel decisions, internal organisation and governance structure and practices, and risk management and compliance obligations. The board may delegate some of its functions, though not its responsibilities, to board committees where appropriate.
The board should establish and be satisfied with the bank’s organisational structure. This will enable the board and senior management to carry out their responsibilities and facilitate effective decision-making and good governance. This includes clearly laying out the key responsibilities and authorities of the board itself and of senior management and of those responsible for the risk management and control functions.
The members of the board should exercise their “duty of care” and “duty of loyalty” to the bank under applicable national laws and supervisory standards.
Accordingly, the board should:6
| 6 | In some jurisdictions, standards derived from general corporate law govern these matters and national supervisory authorities take appropriate account of these standards while implementing these principles. |
| 7 | In the context of board responsibilities, the term “oversee” should be understood to mean “oversee and be satisfied with”. |
The board should ensure that transactions with related parties (including internal group transactions) are reviewed to assess risk and are subject to appropriate restrictions (eg by requiring that such transactions be conducted on arm’s length terms) and that corporate or business resources of the bank are not misappropriated or misapplied.
In discharging these responsibilities, the board should consider the legitimate interests of depositors, shareholders and other relevant stakeholders. It should also ensure that the bank maintains an effective relationship with its supervisors.
A fundamental component of good governance is a corporate culture of reinforcing appropriate norms for responsible and ethical behaviour. These norms are especially critical in terms of a bank’s risk awareness, risk-taking behaviour and risk management (ie the bank’s “risk culture”).
To promote a sound corporate culture, the board should reinforce the “tone at the top” by:
A bank’s code of conduct or code of ethics, or comparable policy, should define acceptable and unacceptable behaviours.
The bank’s corporate values should recognise the critical importance of timely and frank discussion, as well as escalation of problems to higher levels within the organisation.
As part of the overall corporate governance framework, the board is responsible for overseeing a strong risk governance framework. An effective risk governance framework includes a strong risk culture, a well developed risk appetite articulated through the RAS, and well defined responsibilities for risk management in particular and control functions in general.
Developing and conveying the bank’s risk appetite is essential to reinforcing a strong risk culture. The risk governance framework should outline actions to be taken when stated risk limits are breached, including disciplinary actions for excessive risk-taking, escalation procedures and board of director notification.
The board should take an active role in defining the risk appetite and ensuring its alignment with the bank’s strategic, capital and financial plans and compensation practices. The bank’s risk appetite should be clearly conveyed through an RAS that can be easily understood by all relevant parties: the board itself, senior management, bank employees and the supervisor.
The bank’s RAS should:
The development of an effective RAS should be driven by both top-down board leadership and bottom-up management involvement. While the definition of risk appetite may be initiated by senior management, successful implementation depends upon effective interactions between the board, senior management, risk management and operating businesses, including the chief financial officer (CFO).
A risk governance framework should include well defined organisational responsibilities for risk management, typically referred to as the three lines of defence:
Depending on the bank’s nature, size and complexity, and the risk profile of its activities, the specifics of how these three lines of defence are structured can vary. Regardless of the structure, responsibilities for each line of defence should be well defined and communicated.
Business units are the first line of defence. They take risks and are responsible and accountable for the ongoing management of such risks. This includes identifying, assessing and reporting such exposures, considering the bank’s risk appetite and its policies, procedures and controls. The way the business line executes its responsibilities should reflect the bank’s existing risk culture. The board should promote a strong culture of adhering to limits and managing risk exposures.
The second line of defence includes an independent risk management function. The risk management function complements the business line’s risk activities through its monitoring and reporting responsibilities. Among other things, it is responsible for overseeing the bank’s risk-taking activities and assessing risks and issues independently from the business line. The function should promote the importance of senior management and business line managers in identifying and assessing risks critically rather than relying only on surveillance conducted by the risk management function. The risk management function typically engages with the finance function, which plays a critical role in ensuring that business performance and profit and loss results are accurately captured and reported to the board, management and business lines that will use such information as a key input to risk and business decisions.
The second line of defence also includes an independent and effective compliance function. The compliance function should, among other things, routinely monitor compliance with laws, corporate governance rules, regulations, codes and policies to which the bank is subject. The board should approve compliance policies that are communicated to all staff. The compliance function should assess the extent to which policies are observed and report to senior management and, as appropriate, to the board on how the bank is managing its compliance risk. The function should also have sufficient authority, stature, independence, resources and access to the board.
The third line of defence consists of an independent and effective internal audit function. Among other things, it provides independent review and objective assurance on the quality and effectiveness of the bank’s internal control system, the first and second lines of defence and the risk governance framework including links to organisational culture, as well as strategic and business planning, compensation and decision-making processes. Internal auditors must be competent and appropriately trained and not involved in developing, implementing or operating the risk management function or other first or second line of defence functions (see Principle 9).
The board should ensure that the risk management, compliance and internal audit functions are properly positioned, staffed and resourced and that they carry out their responsibilities independently, objectively and effectively. In its oversight of the risk governance framework, the board should regularly review key policies and controls with senior management and with the heads of the risk management, compliance and internal audit functions to identify and address significant risks and issues, as well as determine areas that need improvement.
The board should select the CEO and may select other key personnel, including members of senior management.
The board should provide oversight of senior management. It should hold members of senior management accountable for their actions and enumerate the possible consequences (including dismissal) if those actions are not aligned with the board’s performance expectations. This includes adhering to the bank’s values, risk appetite and risk culture, under all circumstances. In doing so, the board should:
Board members should be, and remain, qualified, individually and collectively, for their positions. They should understand their oversight and corporate governance role and be able to exercise sound, objective judgment about the affairs of the bank.
The board must be suitable to carry out its responsibilities and have a composition that facilitates effective oversight. For that purpose, the board should be comprised of a sufficient number of independent directors.
The board should be comprised of individuals with a balance of skills, diversity and expertise, who collectively possess the necessary qualifications commensurate with the size, complexity and risk profile of the bank.
In assessing the collective suitability of the board, the following should be considered:
Boards should have a clear and rigorous process for identifying, assessing and selecting board candidates. Unless required otherwise by law, the board (not management) nominates candidates and promotes appropriate succession planning of board members.8
| 8 | In some jurisdictions, shareholders or other stakeholders have the right to nominate board members and/or to approve their selection. In such cases, the board should still do whatever is within its power to ensure that members selected for the board are qualified. |
The selection process should include reviewing whether board candidates:
Board candidates should not have any conflicts of interest that may impede their ability to perform their duties independently and objectively and subject them to undue influence from:
If a board member ceases to be qualified or is failing to fulfil their responsibilities, the board should take appropriate actions as permitted by law, which may include notifying their banking supervisor.
The bank should have in place a nomination committee or similar body, composed of a sufficient number of independent board members, which identifies and nominates candidates after having considered the criteria described above. Further details about the nomination committee and other board committees are discussed in CGO10.70.
To help board members acquire, maintain and enhance their knowledge and skills, and fulfil their responsibilities, the board should ensure that members participate in induction programmes and have access to ongoing training on relevant issues which may involve internal or external resources. The board should dedicate sufficient time, budget and other resources for this purpose, and draw on external expertise as needed. More extensive efforts should be made to train and keep updated those members with more limited financial, regulatory or risk-related experience.
Where there are shareholders with power to appoint board members, the board should ensure that such individuals understand their duties. Board members have responsibilities to the bank’s overall interests, regardless of who appoints them. In cases where board members are selected by a controlling shareholder, the board may wish to set out specific procedures or conduct periodic reviews to facilitate the appropriate discharge of responsibility by all board members.
The board should define appropriate governance structures and practices for its own work, and put in place the means for such practices to be followed and periodically reviewed for ongoing effectiveness.
The board should structure itself in terms of leadership, size and the use of committees to effectively carry out its oversight role and other responsibilities. This includes ensuring that the board has the time and means to cover all necessary subjects in sufficient depth and have a robust discussion of issues.
The board should maintain and periodically update organisational rules, by-laws, or other similar documents setting out its organisation, rights, responsibilities and key activities.
To support its own performance, the board should carry out regular assessments – alone or with the assistance of external experts – of the board as a whole, its committees and individual board members. The board should:
The board should maintain appropriate records (eg meeting minutes or summaries of matters reviewed, recommendations made. decisions taken and dissenting opinions) of its deliberations and decisions. These should be made available to the supervisor when required.
The chair of the board plays a crucial role in the proper functioning of the board. The chair provides leadership to the board and is responsible for its effective overall functioning, including maintaining a relationship of trust with board members. The chair should possess the requisite experience, competencies and personal qualities to fulfil these responsibilities. The chair should ensure that board decisions are taken on a sound and well informed basis. The chair should encourage and promote critical discussion and ensure that dissenting views can be freely expressed and discussed within the decision-making process. The chair should dedicate sufficient time to the exercise of their responsibilities.
To promote checks and balances, the chair of the board should be an independent or non-executive board member. In jurisdictions where the chair is permitted to assume executive duties, the bank should have measures in place to mitigate any adverse impact on the bank’s checks and balances, eg by designating a lead board member, a senior independent board member or a similar position and having a larger number of non-executives on the board.
To increase efficiency and allow deeper focus in specific areas, a board may establish certain specialised board committees. The committees should be created and mandated by the full board. The number and nature of committees depend on many factors, including the size of the bank and its board, the nature of the business areas of the bank, and its risk profile.
Each committee should have a charter or other instrument that sets out its mandate, scope and working procedures. This includes how the committee will report to the full board, what is expected of committee members and any tenure limits for serving on the committee. The board should consider the occasional rotation of members and of the chair of such committees, as this can help avoid undue concentration of power and promote fresh perspectives.
In the interest of greater transparency and accountability, a board should disclose the committees it has established, their mandates and their composition (including members who are considered to be independent).
Committees should maintain appropriate records of their deliberations and decisions (eg meeting minutes or summaries of matters reviewed, recommendations made and decisions taken). Such records should document the committees’ fulfilment of their responsibilities and help the supervisor or those responsible to assess the effectiveness of these committees.
A committee chair should be an independent, non-executive board member.
The audit committee is responsible for:
| 10 | In some jurisdictions, external auditors are appointed directly by shareholders, with the board only making a recommendation. |
At a minimum, the audit committee as a whole should possess a collective balance of skills and expert knowledge – commensurate with the complexity of the banking organisation and the duties to be performed – and should have relevant experience in financial reporting, accounting and auditing. Where needed, the audit committee has access to external expert advice.
A risk committee should:
The risk committee of the board is responsible for advising the board on the bank’s overall current and future risk appetite, overseeing senior management’s implementation of the RAS, reporting on the state of risk culture in the bank, and interacting with and overseeing the CRO.
The committee’s work includes oversight of the strategies for capital and liquidity management as well as for all relevant risks of the bank, such as credit, market, operational and reputational risks, to ensure they are consistent with the stated risk appetite.
The committee should receive regular reporting and communication from the CRO and other relevant functions about the bank’s current risk profile, current state of the risk culture, utilisation against the established risk appetite, and limits, limit breaches and mitigation plans (see Principle 6).
There should be effective communication and coordination between the audit committee and the risk committee to facilitate the exchange of information and effective coverage of all risks, including emerging risks, and any needed adjustments to the risk governance framework of the bank.
The compensation committee is required for systemically important banks. It should support the board in overseeing the remuneration system’s design and operation and in ensuring that remuneration is appropriate and consistent with the bank’s culture, long-term business and risk appetite, performance and control environment (see Principle 10) as well as with any legal or regulatory requirements. The compensation committee should be constituted in a way that enables it to exercise competent and independent judgment on compensation policies and practices and the incentives they create. The compensation committee works closely with the bank’s risk committee in evaluating the incentives created by the remuneration system. The risk committee should, without prejudice to the tasks of the compensation committee, examine whether incentives provided by the remuneration system take into consideration risk, capital, liquidity and the likelihood and timing of earnings.
Other specialised committees that are recommended include:
The board should appoint members to specialised committees with the goal of achieving an appropriate mix of skills and experience that, in combination, allow the committees to fully understand, objectively evaluate and bring fresh thinking to the relevant issues.
In jurisdictions permitting or requiring executive members on the board, the board of a bank should work to ensure the needed objectivity in each committee, such as by having only non-executives and, to the extent possible, a majority of independent members.
Conflicts of interest may arise as a result of the various activities and roles of the bank (eg where the bank extends loans to a firm while its proprietary trading function buys and sells securities issued by that firm), or between the interests of the bank or its customers and those of the bank’s board members or senior managers (eg where the bank enters into a business relationship with an entity in which one of the bank’s board members has a financial interest).
Conflicts of interest may also arise when a bank is part of a broader group. For example, where the bank is part of a group, reporting lines and information flows between the bank, its parent company and/or other subsidiaries can lead to the emergence of conflicts of interest (eg sharing of potential proprietary, confidential or otherwise sensitive information from different entities or pressure to conduct business on a non-arm’s length basis).
The board should oversee the implementation and operation of policies to identify potential conflicts of interest. Where these conflicts cannot be prevented, they should be properly managed (based on the permissibility of relationships or transactions under sound corporate policies consistent with national law and supervisory standards).
The board should have a formal written conflicts-of-interest policy and an objective compliance process for implementing the policy. The policy should include:
| 11 | For example, one done by at least two members of the board or by a committee of the board, or done with the involvement of one member of the risk management, compliance or internal audit functions or with the help of an independent external expert. |
The board should oversee and be satisfied with the process by which appropriate public disclosure is made, and/or information is provided to supervisors, relating to the bank’s policies on conflicts of interest and potential material conflicts of interest.
This should include information on the bank’s approach to disclosing and managing material conflicts of interest that are not consistent with such policies, and conflicts that could arise because of the bank’s affiliation or transactions with other entities within the group.
There is a potential conflict of interest where a bank is both owned by the state and subject to banking supervision of the state. If such conflicts of interest do exist, there should be full administrative separation of the ownership and banking supervision functions to minimise political interference in the supervision of the bank.
Under the direction and oversight of the board, senior management should carry out and manage the bank’s activities in a manner consistent with the business strategy, risk appetite, remuneration and other policies approved by the board.
Senior management consists of a core group of individuals responsible and accountable to the board for the sound and prudent day-to-day management of the bank.
The organisation and procedures and decision-making of senior management should be clear and transparent and designed to promote effective management of the bank. This includes clarity on the role, authority and responsibility of the various positions within senior management, including that of the CEO.
Members of senior management should have the necessary experience, competencies and integrity to manage the businesses and people under their supervision. They should receive access to regular training to maintain and enhance their competencies and stay up to date on developments relevant to their areas of responsibility.
Members of senior management should be selected through an appropriate promotion or recruitment process which considers the qualifications required for the position in question. For those senior management positions for which the board of directors is required to review or select candidates through an interview process, senior management should provide sufficient information to the board.
Senior management contributes substantially to a bank’s sound corporate governance through personal conduct (eg by helping to establish the “tone at the top” along with the board). Members of senior management should provide adequate oversight of those they manage, and ensure that the bank’s activities are consistent with the business strategy, risk appetite and the policies approved by the board.
Senior management is responsible for delegating duties to staff and should establish a management structure that promotes accountability and transparency throughout the bank.
Consistent with the direction given by the board, senior management should implement business strategies, risk management systems, risk culture, processes and controls for managing the risks – both financial and non-financial – to which the bank is exposed and concerning which it is responsible for complying with laws, regulations and internal policies. This includes comprehensive and independent risk management, compliance and audit functions as well as an effective overall system of internal controls. Senior management should recognise and respect the independent duties of the risk management, compliance and internal audit functions and should not interfere in their exercise of such duties.
Senior management should provide the board with the information it needs to carry out its responsibilities, supervise senior management and assess the quality of senior management’s performance. In this regard, senior management should keep the board regularly and adequately informed of material matters, including:
In a group structure, the board of the parent company has the overall responsibility for the group and for ensuring the establishment and operation of a clear governance framework appropriate to the structure, business and risks of the group and its entities.12 The board and senior management should know and understand the bank group’s organisational structure and the risks that it poses.
In operating within a group structure, the board of the parent company should be aware of the material risks and issues that might affect both the bank as a whole and its subsidiaries. It should exercise adequate oversight over subsidiaries while respecting the independent legal and governance responsibilities that might apply to subsidiary boards.
To fulfil its responsibilities, the board of the parent company should:
Subsidiary and senior management remain responsible for developing effective risk management processes for their entities. The methods and procedures applied by subsidiaries should support the effectiveness of risk management at a group level. While parent companies should conduct strategic, group-wide risk management and prescribe corporate risk policies, subsidiary management and boards should have appropriate input to their local or regional application and to the assessment of local risks. Parent companies should ensure that adequate tools and authorities are available to the subsidiary and that the subsidiary understands the reporting obligations it has to the head office. It is the responsibility of subsidiary boards to assess the compatibility of group policy with local legal and regulatory requirements and, where appropriate, amend those policies.
While the strategic objectives, risk governance framework, corporate values and corporate governance principles of the subsidiary should align with that of the parent company (referred to here as “group policies”), the subsidiary board should make necessary adjustments where a group policy conflicts with an applicable legal or regulatory provision or prudential rule, or would be detrimental to the sound and prudent management of the subsidiary.
The board of a significant regulated subsidiary (due to its risk profile or systemic importance or due to its size relative to the parent company) should take further steps as needed to ensure the subsidiary meets its own corporate governance responsibilities and complies with legal and regulatory requirements.
Banks create structures such as units, branches, subsidiaries, or other legal entities for legal, regulatory and tax purposes. Such structures can considerably increase the complexity of the organisation. A large number of legal entities, especially with interconnections and intragroup transactions, can lead to challenges in identifying and managing the risks of the organisation as a whole.
Operating through complex or non-transparent structures may pose financial, legal, reputational and other risks to the bank. It may impede the ability of the board and senior management to conduct appropriate business oversight and could hinder effective banking supervision.15
| 15 | Banks may also be indirectly exposed to risks when they perform certain services or establish structures on behalf of customers. Examples include acting as a company or partnership formation agent, providing a range of trustee services and developing complex structured finance transactions for customers. While these activities are often profitable and can serve the legitimate business purposes of customers, customers may in some cases use products and activities provided by banks to engage in illegal or inappropriate activities |
Senior management – and the board, as appropriate – should be aware of these challenges and take action to avoid or mitigate them by:
The board of the parent company can enhance the effectiveness of the above efforts by requiring a periodic independent formal review of the structures, their controls and activities as well as of their consistency with board-approved strategy.
The board should be prepared to discuss with, and as necessary report to, the bank’s supervisor and the host country supervisors the policies and strategies adopted regarding the establishment and maintenance of these structures and activities.
Banks should have an effective independent risk management function, under the direction of a chief risk officer (CRO), with sufficient stature, independence, resources and access to the board.
The independent risk management function is a key component of the bank’s second line of defence. This function is responsible for overseeing risk-taking activities across the enterprise and should have authority within the organisation to do so. Key activities of the risk management function should include:
While it is common for risk managers to work closely with individual business units, the risk management function should be sufficiently independent of the business units and should not be involved in revenue generation. Such independence is an essential component of an effective risk management function, as is having access to all business lines that have the potential to generate material risk to the bank as well as to relevant risk-bearing subsidiaries and affiliates.
The risk management function should have sufficient staffing with the necessary experience and qualifications, including market and product knowledge as well as command of risk disciplines16. Staff should be able and willing to effectively challenge business operations on all risk-related matters. They should also have access to regular training.
| 16 | Some banks encourage or require staff to rotate between business line and risk management roles. This approach can benefit banks by raising risk management stature, fostering bank-wide dialogue regarding risk, and helping business lines to appreciate the importance of risk management, while risk managers gain a better understanding of business lines. However, to avoid conflicts of interest, risk managers should not oversee activities for which they previously held line responsibility or participated in business decision-making or the approval process. |
Large, complex and internationally active banks, and other banks, based on their risk profile and local governance requirements, should have a senior manager (CRO or equivalent) with overall responsibility for the bank’s risk management function. In banking groups, there should be a group CRO in addition to subsidiary-level risk officers. Because some banks may have an officer who fulfils the function of a CRO under a different title, reference in this document to the CRO is intended to incorporate equivalent positions, provided they meet the independence and other requirements set out herein.
The CRO has primary responsibility for overseeing the development and implementation of the bank’s risk management function. This includes the ongoing strengthening of staff skills and enhancements to risk management systems, policies, processes, quantitative models and reports as necessary to ensure that the bank’s risk management capabilities are sufficiently robust and effective to fully support its strategic objectives and all of its risk-taking activities. The CRO is responsible for supporting the board in its engagement with and oversight of the development of the bank’s risk appetite and RAS and translates the risk appetite into a structure of risk limits. Along with management, the CRO should be actively engaged in monitoring performance against risk-taking and adherence to risk limit. The CRO’s responsibilities also include managing and participating in key decision-making processes (eg strategic planning, capital and liquidity planning, new products and services, compensation design and operation).
The CRO should have the organisational stature, authority and necessary skills to oversee the bank’s risk management activities. The CRO should be independent and have duties distinct from other executive functions. The CRO must have access to all necessary information but should not manage or have financial responsibility for operational business lines or revenue-generating functions. There should be no “dual hatting” (ie the chief operating officer, CFO, chief auditor or other senior manager should in principle not also serve as the CRO).17 The CRO should report directly to the board or its risk committee and have unrestricted access to them. The CRO should have the ability to interpret and articulate risk in a clear and understandable manner and to effectively engage the board and management in constructive dialogue on key risk issues. The CRO should interact regularly with the board and/or risk committee, and the CRO should have the ability to meet with the board or risk committee without executive directors being present.18
| 17 | Where “dual hatting” is unavoidable (eg in smaller banks where resource constraints may make overlapping responsibilities necessary), these roles should be compatible and should not weaken checks and balances within the bank. For example, the CRO may also have lead responsibility for a particular risk area. |
| 18 | In some cases, the CRO may sit on the bank’s credit committee, which is responsible for approving credit exposures. While CRO participation may benefit the decision-making process and also benefit the CRO by providing information on potential exposures (and underwriting practices) which should be captured in the credit monitoring process, it can place the CRO in a conflicted position if he or she is faced with flagging or criticising the exposure in the future. Some banks have found it a better practice to provide the CRO with veto authority only (as opposed to approval authority) in such situations. |
Appointment, dismissal and other changes to the CRO position should be approved by the board or its risk committee. If the CRO is removed from their position, this should be disclosed publicly, and the reasons should also be discussed with the bank’s supervisor. The risk committee or the board should review and approve the CRO’s performance, compensation and budget.
Risks should be identified, monitored and controlled on an ongoing bank-wide and individual entity basis. The sophistication of the bank’s risk management and internal control infrastructure should keep pace with changes to the bank’s risk profile, to the external risk landscape and in industry practice.
The bank’s risk governance framework should include policies, supported by appropriate control procedures and processes, designed to ensure that the bank’s risk identification, aggregation, mitigation and monitoring capabilities are commensurate with the bank’s size, complexity and risk profile.
Risk identification should encompass all material risks to the bank, on- and off-balance sheet and on a group-wide, portfolio-wise and business-line level. To perform effective risk assessments, the board and senior management, including the CRO, should, regularly and on an ad hoc basis, evaluate the risks faced by the bank and its overall risk profile. The risk assessment process should include ongoing analysis of existing risks as well as the identification of new or emerging risks. Risks should be captured from all organisational units. Concentrations associated with material risks should likewise be factored into the risk assessment.
Risk identification and measurement should include both quantitative and qualitative elements. Risk measurements should also include qualitative, bank-wide views of risk relative to the bank’s external operating environment. Banks should also consider and evaluate harder-to-quantify risks, such as reputation risk.
Internal controls are designed, among other things, to ensure that each key risk has a policy, process or other measure, as well as a control to ensure that such policy, process or other measure is being applied and works as intended. As such, internal controls help ensure process integrity, compliance and effectiveness. Internal controls provide reasonable assurance that financial and management information is reliable, timely and complete and that the bank is complying with its various policies and applicable laws and regulations.
To avoid actions beyond the authority of the individual or even fraud, internal controls also place reasonable checks on managerial and employee discretion. Even in smaller banks, for example, key management decisions should be taken by more than one person. Internal reviews should also determine the extent of a bank’s compliance with company policies and procedures as well as with legal and regulatory policies. Adequate escalation procedures are a key element of the internal control system.
An effective internal control system requires appropriate segregation of duties and that personnel are not assigned conflicting responsibilities. Areas of potential conflicts of interest should be identified, minimised, and subject to careful, independent monitoring.
Segregation of duties is not limited to situations involving simultaneous front and back office control by one individual. It can also result in serious problems when there are not appropriate controls in those instances where an individual has responsibility for:
The degree of sophistication of the bank’s risk management infrastructure – including, in particular, a sufficiently robust data infrastructure, data architecture and information technology infrastructure – should keep pace with developments such as balance sheet and revenue growth; increasing complexity of the bank’s business, risk configuration or operating structure; geographical expansion; mergers and acquisitions; or the introduction of new products or business lines.
Banks should have accurate internal and external data to be able to identify, assess and mitigate risk, make strategic business decisions and determine capital and liquidity adequacy. The board and senior management should give special attention to the quality, completeness and accuracy of the data used to make risk decisions.19 While tools such as external credit ratings or externally purchased risk models and data can be useful as inputs into a more comprehensive assessment, banks are ultimately responsible for the assessment of their risks.
Risk measurement and modelling techniques should be used in addition to, but should not replace, qualitative risk analysis and monitoring. The risk management function should keep the board and senior management apprised of the assumptions used in and potential shortcomings of the bank’s risk models and analyses. This would ensure better understanding of risks and exposures and may allow quicker action to address and mitigate risks.
As part of its quantitative and qualitative analysis, the bank should utilise stress tests and scenario analyses to better understand potential risk exposures under a variety of adverse circumstances:20
Banks should regularly compare actual performance against risk estimates (ie backtesting) to assist in judging the accuracy and effectiveness of the risk management process and making necessary adjustments.
The risk management function should not only identify and measure risk exposures but also evaluate possible ways to mitigate these exposures. In some cases, tit may direct that risk be reduced or hedged to limit exposure. In other cases, such as when there is a decision to accept or take risk that is beyond risk limits (ie on a temporary basis) or take risk that cannot be hedged or mitigated, the risk management function should report these material exemptions to the board and monitor the positions to ensure that they remain within the bank’s framework of limits and controls or within exception approval. Either approach may be appropriate depending on the issue at hand, provided that the independence of the risk management function is not compromised.
Banks should have risk management and approval processes for new or expanded products or services, lines of business and markets, as well as for large and complex transactions that require significant use of resources or have hard-to-quantify risks. Banks should also have review and approval processes for outsourcing bank functions.21 The risk management function should provide input on risks as part of such processes and on the outsourcer’s ability to manage risks and comply with legal and regulatory obligations. Such processes should entail the following:
Effective risk identification and measurement approaches are likewise necessary in subsidiary banks and affiliates.22 Material risk-bearing affiliates and subsidiaries should be captured by the bank-wide risk management system and should be a part of the overall risk governance framework.23
| 22 | There may be national laws that exempt subsidiaries from some supervisory requirements on a standalone basis if these subsidiaries are well integrated in a group and certain preconditions are met. The considerations set out in this paragraph apply in circumstances where no such exception is available. |
| 23 | The risk governance framework should also cover the relevant risk-bearing affiliates of the group to ensure that the policies, business strategies, processes and controls of the affiliates are in broad alignment with the group’s objectives. |
Mergers and acquisitions, divestitures and other changes to a bank’s organisational structure can pose special risk management challenges to the bank. In particular, risks can arise from conducting due diligence that fails to identify post-merger risks or activities conflicting with the bank’s strategic objectives or risk appetite. The risk management function should be actively involved in assessing risks that could arise from mergers and acquisitions and inform the board and senior management of its findings
An effective risk governance framework requires robust communication within the bank about risk, both across the organisation and through reporting to the board and senior management.
Ongoing communication about risk issues, including the bank’s risk strategy, throughout the bank is a key tenet of a strong risk culture. A strong risk culture should promote risk awareness and encourage open communication and challenge about risk-taking across the organisation as well as vertically to and from the board and senior management. Senior management should actively communicate and consult with the control functions on management’s major plans and activities to enable those functions to carry out their responsibilities.
Information should be communicated to the board and senior management in a timely, accurate and understandable manner so that they are equipped to take informed decisions. To avoid overwhelming them with excessive details, risk information should be prioritised, concise, and fully contextualised. The board should assess the relevance and the process for maintaining the accuracy of the information it receives and determine if additional or less information is needed.
Material risk-related ad hoc information that requires immediate decisions or reactions should be promptly presented to senior management and, as appropriate, the board, the responsible officers and, where applicable, the heads of control functions to facilitate timely action.
Risk reporting to the board should be carefully designed to present bank-wide, individual portfolio and other risks in a concise and meaningful manner. Reporting should accurately communicate risk exposures, results of stress tests or scenario analyses and encourage discussion on topics such as the bank’s current and prospective exposures (particularly under stressed scenarios), risk/return relationships and risk appetite and limits. Reporting should also include information about the external environment to identify market conditions and trends that may have an impact on the bank’s current or future risk profile.
Risk reporting systems should be dynamic, comprehensive and accurate, using a variety of underlying assumptions. Risk monitoring and reporting should not only occur at the disaggregated level (including material risk residing in subsidiaries) but should also be aggregated to allow for a bank-wide or integrated perspective of risk exposures. Risk reporting systems should highlight any deficiencies or limitations in risk estimates, as well as any significant embedded assumptions (eg regarding risk dependencies or correlations).
Banks should avoid organisational “silos” that can impede effective sharing of information across an organisation and can result in decisions being taken in isolation from the rest of the bank.24 Overcoming these information-sharing obstacles may require the board, senior management and control functions to re-evaluate established practices to encourage greater communication.
| 24 | Organisational silos can be characterised by business lines, legal entities and/or geographical units being run in isolation from each other, with limited information shared and, in some cases, competition across silos. |
The bank’s board of directors is responsible for overseeing the management of the bank’s compliance risk. The board should establish a compliance function and approve the bank’s policies and processes for identifying, assessing, monitoring and reporting and advising on compliance risk.
Senior management is responsible for establishing a compliance policy that contains the basic principles to be approved by the board and explains how compliance risks will be identified and managed through all levels of the organisation.
While the board and management are accountable for the bank’s compliance, the compliance function has an important role in supporting corporate values, policies and processes that help ensure that the bank acts responsibly and fulfils all applicable obligations.
The compliance function should advise the board and senior management on the bank’s compliance with applicable laws, rules and standards and keep them informed of developments in the area. It should also help educate staff about compliance issues, act as a contact point within the bank for compliance queries from staff members, and provide guidance to staff on the appropriate implementation of applicable laws, rules and standards in the form of policies and procedures and other documents such as compliance manuals, internal codes of conduct and practice guidelines.
The compliance function is independent from management to avoid undue influence or obstacles in the performance of its duties. The compliance function should directly report to the board, as appropriate, on how the bank is managing its compliance risk. As previously noted, there should be no “dual hatting” by the head of the compliance function.
To be effective, the compliance function must have sufficient authority, stature, independence, resources and access to the board. Management should respect the independent duties of the compliance function and not interfere with their fulfilment.
The internal audit function should provide independent assurance to the board and should support board and senior management in promoting an effective governance process and the long-term soundness of the bank.
An effective and efficient internal audit function constitutes the third line of defence in the system of internal control. It provides an independent assurance to the board of directors and senior management on the quality and effectiveness of a bank’s internal control, risk management and governance systems and processes, thereby helping the board and senior management protect their organisation and its reputation.26
The internal audit function should have a clear mandate, be accountable to the board and be independent of the audited activities. It should have sufficient standing, skills, resources and authority within the bank to enable the auditors to carry out their assignments effectively and objectively. To ensure independence, the head of the internal audit function should not take on other roles (“dual hatting”).
The board and senior management contribute to the effectiveness of the internal audit function by:
To safeguard the independence of the internal audit function, the board and senior management should ensure that:
The bank’s remuneration structure should support sound corporate governance and risk management.
Remuneration systems form a key component of the governance and incentive structure through which the board and senior management promote good performance, convey acceptable risk- taking behaviour and reinforce the bank’s operating and risk culture. The board (or, by delegation, its compensation committee) is responsible for the overall oversight of management’s implementation of the remuneration system for the entire bank. In addition, the board or its committee should regularly monitor and review outcomes to assess whether the bank-wide remuneration system is creating the desired incentives for managing risk, capital and liquidity.27 The board or subcommittee should review the remuneration plans, processes and outcomes at least annually.
| 27 | See FSB, Principles for Sound Compensation Practices, 2009. |
Systemically important financial institutions should have a board compensation committee as an integral part of their governance structure and organisation to oversee the compensation system’s design and operation.
The board, together with its compensation committee, if applicable, should approve the compensation of senior executives, including the CEO, CRO and head of internal audit, and should oversee development and operation of compensation policies, systems and related control processes.
For employees in control functions (eg risk, compliance and internal audit), remuneration should be determined independently of any business line overseen, and performance measures should be based principally on the achievement of their own objectives to maintain independence.
The remuneration structure should align with the business and risk strategy, objectives, values and long-term interests of the bank. It should also incorporate measures to prevent conflicts of interest. Remuneration programmes should encourage a sound risk culture in which risk-taking behaviour is appropriate and which encourages employees to act in the interest of the bank as a whole (also considering client interests) rather than prioritising personal or business line gains. Incentives embedded within remuneration structures should not incentivise staff to take excessive risk.
Remuneration should reflect risk-taking and risk outcomes. Practices by which remuneration is paid for potential future revenues whose timing and likelihood remain uncertain should be carefully evaluated by means of both qualitative and quantitative key indicators. The remuneration framework should provide for variable remuneration to be adjusted to take into account the full range of risks, including breaches of risk appetite limits, internal procedures or legal requirements.
Banks must set specific provisions for employees with significant influence on the overall risk profile, so-called material risk-takers. For these employees, remuneration payout schedules should be sensitive to risk outcomes over a multi-year horizon. This often involves deferring a significant part of the compensation until risk outcomes become better known. This includes “malus/forfeiture” provisions, where compensation can be reduced or reversed based on realised risks or conduct events before compensation vests, and/or “clawback” provisions, under which compensation can be reduced or reversed after compensation vests if new facts emerge showing that the compensation paid was based on erroneous assumptions, such as misreporting, or if it is discovered that the employee has failed to comply with internal policies or legal requirements. In such cases, banks should take action as soon as practicable to recover forfeitable or recoupable amounts to improve the likelihood of successful recovery. “Golden hellos” or “golden parachutes”, under which new or terminated executives or staff receive large payouts irrespective of performance, are generally not consistent with sound compensation practice.
The governance of the bank should be adequately transparent to its shareholders, depositors, other relevant stakeholders and market participants.
Transparency is consistent with sound and effective corporate governance. As emphasised in DIS Disclosure requirements, it is difficult for shareholders, depositors, other relevant stakeholders and market participants to effectively monitor and properly hold the board and senior management accountable when there is insufficient transparency. The objective of transparency in corporate governance is to provide these parties with the information necessary to enable them to assess the effectiveness of the board and senior management in governing the bank.
Although disclosure may be less detailed for non-listed banks, especially those that are wholly owned, these banks can nevertheless pose the same types of risk to the financial system as publicly traded banks through various activities, including their participation in payment systems and acceptance of retail deposits.
All banks, even those for whom disclosure requirements may differ because they are non-listed, should disclose relevant and useful information that supports the key areas of corporate governance identified by the Committee. Such disclosure should be proportionate to the size, complexity, structure, economic significance and risk profile of the bank. At a minimum, banks should disclose annually the following information:
In general, banks should apply the disclosure and transparency section of the OECD principles.28 Disclosure should include, but not be limited to, material information on the bank’s objectives, organisational and governance structures and policies (in particular, the content of any corporate governance or remuneration code or policy and the process by which it is implemented), major share ownership and voting rights, and related party transactions.29 An annual report on compensation should be disclosed to the public, which includes:
Measures that reflect the longer-term performance of the bank should also be presented.
| 28 | Section IV of the OECD principles states: “The corporate governance framework should ensure that timely and accurate disclosure is made on all material matters regarding the corporation, including the financial situation, performance, sustainability, ownership, and governance of the company.” See OECD (2023). |
| 29 | Relevant banks should also appropriately disclose their incentive and compensation policy following the FSB, Principles for Sound Compensation Practices, 2009. |
The bank should also disclose key points concerning its risk exposures and risk management strategies without breaching necessary confidentiality. When involved in material and complex or non- transparent activities, the bank should disclose adequate information on their purpose, strategies, structures, and related risks and controls.
Disclosure should be accurate, clear and presented in a manner that allows shareholders, depositors, other relevant stakeholders and market participants to consult the information easily. Timely public disclosure is recommended, whether on a bank’s public website, in its annual and periodic financial reports, or by other appropriate means. It is good practice to have an annual corporate governance-specific and comprehensive statement in a clearly identifiable section of the annual report depending on the applicable financial reporting framework. Any material developments that arise between regular reports should be disclosed to the bank supervisor and relevant stakeholders as required by law without undue delay.
Supervisors should provide guidance for and supervise corporate governance at banks (including through comprehensive evaluations and regular interaction with boards and senior management), require improvement and remedial action as necessary, and share information on corporate governance with other supervisors.
The board and senior management are primarily responsible for the governance of the bank, and supervisors should assess their performance in this regard. This section sets forth several principles that can assist supervisors in assessing corporate governance and foster good corporate governance in banks.
Supervisors should establish guidance or rules requiring banks to have robust corporate governance policies and practices. Such guidance is especially important where national laws, regulations, codes or listing requirements regarding corporate governance are not sufficiently robust to address the unique corporate governance needs of banks. Regulatory guidance should address, among other things, expectations for checks and balances and a clear allocation of responsibilities, accountability and transparency among the members of the board and senior management and within the bank. In addition to guidance or rules, where appropriate, supervisors should also share industry best practices regarding corporate governance with the banks they supervise.
Supervisors should have processes in place to fully evaluate a bank’s corporate governance. This may include regular reviews of written materials and reports, interviews with board members and bank personnel, examinations, self-assessments by the bank, and other types of on- and off-site monitoring. Supervisors should maintain regular communication with a bank’s board, senior management, risk management, compliance and internal audit functions, and external auditors.30
Supervisors should evaluate whether the bank has implemented effective mechanisms through which the board and senior management execute their respective oversight responsibilities. Supervisors should evaluate whether the board and senior management have implemented processes for the oversight of the bank’s strategic objectives, including risk appetite, financial performance, capital adequacy, capital planning, liquidity, risk profile and risk culture, controls, compensation practices, and the selection and evaluation of management. Supervisors should focus particular attention on the oversight of the risk management, compliance and internal audit functions. This should include assessing the extent to which the board interacts with and meets with representatives of these functions. Supervisors should determine whether internal controls are being adequately assessed and contribute to sound governance throughout the bank.
Supervisors should evaluate the processes and criteria used by banks to select board members and senior management and, as they judge necessary, obtain information about the expertise and character of board members and senior management. The fit and proper criteria should include those detailed in Principle 2 of this chapter. The individual and collective suitability of board members and senior management should be subject to ongoing attention by supervisors.
Governance evaluations should also include an assessment of how effectively the board and senior management contribute to good governance and promote risk culture within a bank. Supervisors should consider factors such as how the “tone at the top” and the cultural values of the bank are communicated and put into practice, how information flows to and from the board and senior management, and how serious problems are identified and addressed. This may include reviewing board and management assessments, surveys and other tools used by banks in assessing their internal culture, as well as conducting interviews and making qualitative judgments. In arriving at such judgments, supervisors should be mindful of the consistency of treatment across supervised banks. Supervisory staff should have the necessary skills to evaluate and assess governance effectiveness.
When reviewing corporate governance for groups, supervisors should consider the governance responsibilities of both the parent company and subsidiaries, in accordance with Principle 5 of this chapter.
Supervisors should interact regularly with the board, individual board members, senior managers and those responsible for the risk management, compliance and internal audit functions. This should include scheduled meetings and ad hoc exchanges through various communication channels (eg e-mail, telephone, in-person meetings). The purpose of these interactions is to support timely and open dialogue between the bank and supervisors on a range of issues, including:
The frequency of interactions may vary according to the size, complexity, structure, economic significance and risk profile of the bank. For example, supervisors may meet with the full board of directors annually, but more frequently with key individuals, such as the chairperson or board committee chairs. For systemically important banks, interaction should occur more frequently, particularly with members of the board and senior management, and those responsible for the risk management, compliance and internal audit functions.
Supervisors should have a range of tools to address governance weaknesses or failures at banks. They should be able to require improvements and remedial actions, and ensure accountability for the corporate governance of a bank. These tools may include the ability to compel changes in the bank’s policies and practices, the composition of the board of directors or senior management, or other corrective actions. They should also include, where necessary, the authority to impose sanctions or other punitive measures. The choice of tool and the time frame for any remedial action should be proportionate to the level of risk the deficiency poses to the safety and soundness of the bank or the relevant financial system(s).
If remedial action is required, the supervisor should set a timetable for completion. Supervisors should also implement escalation procedures to enforce more stringent or faster remedial action if a bank fails to address the deficiencies identified or the supervisor deems that further action is warranted.
Supervisors should cooperate and share information on corporate governance matters with relevant public authorities, including between bank supervisors and conduct authorities, and between home and host supervisors of internationally active banks. Such communication can help supervisors improve their assessment of the overall governance of a bank and the risks it faces, particularly in a group context, and help other authorities assess the risks posed to the broader financial system.31
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.