| Guidelines This chapter describes compliance risk and the compliance function in banks. The contents of this chapter are based on:
|
| Related standards |
| Related guidelines |
Compliance starts at the top. It will be most effective in a corporate culture that emphasises standards of honesty and integrity and in which the board and senior management lead by example. Compliance concerns everyone within the bank and should be viewed as an integral part of the bank’s business activities. A bank should hold itself to high standards when conducting business, and always strive to observe the spirit as well as the letter of the law. Failure to consider the impact of its actions on its shareholders, customers, employees and the markets may result in significant adverse publicity and reputational damage, even if no law has been broken.
Compliance should be part of the culture of the organisation; it is not just the responsibility of specialist compliance staff. There are significant differences between banks regarding the organisation of the compliance function. In larger banks, compliance staff may be located within operating business lines, and internationally active banks may also have group and local compliance officers. In smaller banks, compliance function staff may be centralised in one unit. Separate units have been established in some banks for specialist areas such as data protection and the prevention of money laundering and terrorist financing.
The following terms are used throughout this chapter and have the meaning given below:
A bank should organise its compliance function and prioritise the management of its compliance risk in a way that is consistent with its own risk management strategy and structures. Regardless of organisation, the compliance function should be independent and sufficiently resourced, its responsibilities should be clearly specified, and its activities should be subject to periodic and independent review by the internal audit function. An independent compliance function is a key component of the bank’s second line of defence.
These principles are applicable to all banks, although it is for individual banks to determine how best they should be implemented. Implementation will depend on factors such as the bank’s size, the nature, complexity and geographical extent of its business, and the legal and regulatory framework within which it operates.
These principles assume a governance structure composed of a board and senior management. The legislative and regulatory frameworks differ across countries and types of entities as regards the functions of the board and senior management. Therefore, the principles set out in this chapter should be applied in accordance with the corporate governance structure of each country and type of entity.1
Principle 1 – The bank’s board of directors (hereafter, the board) is responsible for overseeing the management of the bank’s compliance risk. The board should approve the bank’s compliance policy, including a formal document establishing a permanent and effective compliance function. At least once a year, the board or a committee of the board should assess the extent to which the bank is managing its compliance risk effectively.
A bank’s compliance policy will not be effective unless the board promotes the values of honesty and integrity throughout the organisation. Compliance with applicable laws, rules and standards should be viewed as an essential means to this end. The board is responsible for ensuring that an appropriate policy is in place to manage the bank’s compliance risk. The board should oversee the implementation of the policy, including ensuring that compliance issues are resolved effectively and expeditiously by senior management with the assistance of the compliance function. The board may delegate these tasks to an appropriate board level committee (eg its audit committee).
Principle 2 – The bank’s senior management is responsible for establishing and communicating a compliance policy, for ensuring that it is observed, and for reporting to the board on the management of the bank’s compliance risk. The bank’s senior management is responsible for establishing a permanent and effective compliance function as part of the bank’s compliance policy.
The bank’s senior management is responsible for establishing a written compliance policy that contains the basic principles to be followed by management and staff, and explains the main processes by which compliance risks are to be identified and managed through all levels of the organisation. Clarity and transparency may be promoted by distinguishing between general standards for all staff members and rules that only apply to specific groups of staff.
Senior management is responsible for ensuring that appropriate remedial or disciplinary action is taken if breaches of the compliance policy are identified.
Senior management should, with the assistance of the compliance function:
Principle 3 – The bank’s compliance function should be independent.
The concept of independence does not mean that the compliance function cannot work closely with management and staff in the various business units. A co-operative working relationship between compliance function and business units should help to identify and manage compliance risks at an early stage. Rather, the various elements described below should be viewed as safeguards to help ensure the effectiveness of the compliance function. The way in which the safeguards are implemented will depend to some extent on the specific responsibilities of individual compliance function staff.
The compliance function should have formal status within the bank to ensure appropriate standing, authority and independence. This may be set out in the bank’s compliance policy or in any other formal document, which should be communicated to all staff.
The compliance policy (or other formal document) should address the following issues with respect to the compliance function:
Each bank should have a head of compliance.
The reporting line for compliance staff will depend on how the bank has organised its compliance function. Compliance function staff in operating business units or in local subsidiaries may report to operating business unit management or local management. This is acceptable provided such staff also report to the head of compliance for their compliance responsibilities. Separate reporting to the head of compliance may not be necessary where compliance function staff are in independent support units (eg legal, financial control, risk management). However, these units should co-operate closely with the head of compliance to ensure that they can perform their responsibilities effectively. However, these units should co-operate closely with the head of compliance to ensure that the latter can perform their responsibilities effectively.
If the head of compliance is a member of senior management, they should not have direct business line responsibilities. If they are not a member of senior management, they should report directly to a member of senior management without direct business line responsibilities.
The bank should inform the supervisor and the board when the head of compliance takes up or leaves that position, including reasons for their departure. For internationally active banks with local compliance officers, the host country supervisor should be similarly informed of the arrival or departure of the local head of compliance.
The independence of the head of compliance and any other staff having compliance responsibilities may be undermined if there is a real or potential conflict between their compliance responsibilities and their other responsibilities. Ideally, compliance function staff should perform only compliance responsibilities. However, that this may not be practicable in smaller banks, smaller business units or in local subsidiaries. In these cases, compliance function staff may perform non-compliance tasks, provided potential conflicts of interest are avoided.
Independence may also be undermined if the remuneration of compliance staff is related to the financial performance of the business line they oversee. However, remuneration related to the financial performance of the bank as a whole should generally be acceptable.
The compliance function should have the authority to communicate with any staff member and access any records or files necessary to enable it to carry out its responsibilities.
The compliance function should be able to carry out its responsibilities in all departments of the bank in which compliance risk exists. It should have the right to conduct investigations of possible breaches of the compliance policy and to request assistance from specialists within the bank (eg legal or internal audit) or engage outside specialists to perform this task if appropriate.
The compliance function should be free to report to senior management any irregularities or possible breaches disclosed by its investigations, without fear of retaliation or disfavour from management or other staff members. Although its normal reporting line should be to senior management, the compliance function should also have direct access to the board or to a board committee, when necessary. It may also be useful for the board or board committee to meet with the head of compliance at least annually, as this will help the board or board committee assess whether the bank is managing its compliance risk effectively.
Principle 4 – The bank’s compliance function should have the resources to carry out its responsibilities effectively.
The resources of the compliance function should be both sufficient and appropriate to ensure that compliance risk within the bank is managed effectively. Compliance function staff should have the necessary qualifications, experience and professional and personal qualities to enable them to carry out their specific duties. They should also have a sound understanding of compliance laws, rules and standards and their practical impact on the bank’s operations. The professional skills of compliance function staff should be maintained through regular and systematic education and training.
Principle 5 – The compliance function’s responsibilities should include assisting senior management in managing effectively the bank’s compliance risks If some of these responsibilities are carried out by staff in different departments, the allocation of responsibilities to each department should be clear.
Compliance responsibilities may not always be centralised within a “compliance department” or “compliance unit”, and may be exercised by staff in different departments. In some banks, for example, legal and compliance may be separate departments; the legal department may be responsible for advising management on the compliance laws, rules and standards and for preparing guidance to staff, while the compliance department may be responsible for monitoring compliance with the policies and procedures and reporting to management. In other banks, parts of the compliance function may be located within the operational risk group or within a more general risk management group. If there is a division of responsibilities between departments, the allocation of responsibilities to each department should be clear. There should also be appropriate mechanisms for co-operation among each department and with the head of compliance (eg with respect to the provision and exchange of relevant advice and information). These mechanisms should be sufficient to ensure that the head of compliance can perform their responsibilities effectively.
The compliance function should advise senior management on compliance laws, rules and standards, including keeping them informed on developments in the area.
The compliance function should assist senior management in:
The compliance function should pro-actively identify, document and assess the compliance risks associated with the bank’s business activities, including the development of new products and business practices, the proposed establishment of new types of business or customer relationships, or material changes in such relationships. If the bank has a new products committee, compliance function staff should be represented on the committee.
The compliance function should consider ways to measure compliance risk (eg by using performance indicators) and use such measurements to enhance compliance risk assessment. Technology can aid in developing performance indicators by aggregating or filtering data that may be indicative of potential compliance problems (eg an increase in customer complaints, irregular trading or payments activity, etc).
The compliance function should assess the appropriateness of the bank’s compliance procedures and guidelines, promptly follow up any identified deficiencies, and, where necessary, formulate proposals for amendments.
The compliance function should monitor and test compliance by performing sufficient and representative compliance testing. The results of this testing should be reported through the compliance function reporting line in accordance with the bank’s internal risk management procedures.
The head of compliance should report on a regular basis to senior management on compliance matters. These reports should:
The compliance function may have specific statutory responsibilities (eg fulfilling the role of anti-money laundering officer). It may also liaise with relevant external bodies, including regulators, standard setters and external experts.
The responsibilities of the compliance function should be carried out under a compliance programme that sets out its planned activities, such as the implementation and review of specific policies and procedures, compliance risk assessment, compliance testing, and educating staff on compliance matters. The compliance programme should be risk- based and subject to oversight by the head of compliance to ensure appropriate coverage across businesses and co-ordination among risk management functions.
Principle 6 – The scope and breadth of the activities of the compliance function should be subject to periodic review by the internal audit function.
Compliance risk should be included in the risk assessment methodology of the internal audit function, and an audit programme that covers the adequacy and effectiveness of the bank’s compliance function should be established, including testing of controls commensurate with the perceived level of risk.
The compliance function and the audit function should be separate, to ensure that the activities of the compliance function are subject to independent review. It is important that there is a clear understanding within the bank as to how risk assessment and testing activities are divided between the two functions, and that this is documented (eg in the bank’s compliance policy or in a related document such as a protocol). The audit function should keep the head of compliance informed of any audit findings relating to compliance.
Principle 7 – Banks should comply with applicable laws and regulations in all jurisdictions in which they conduct business, and the organisation and structure of the compliance function and its responsibilities should be consistent with local legal and regulatory requirements.
Banks that conduct business in a particular jurisdiction should comply with local laws and regulations. For example, banks operating in subsidiary form must satisfy the legal and regulatory requirements of the host jurisdiction. Certain jurisdictions may also have special requirements in the case of foreign bank branches. Local offices must ensure that compliance responsibilities specific to each jurisdiction are carried out by individuals with the appropriate local knowledge and expertise, with oversight from the head of compliance in co-operation with the bank’s other risk management functions.
Procedures should be in place to identify and assess the possible increased reputational risk to a bank if it offers products or carries out activities in certain jurisdictions that would not be permitted in its home jurisdiction.
Principle 8 – Compliance should be regarded as a core risk management activity within the bank. Specific tasks of the compliance function may be outsourced, but they must remain subject to appropriate oversight by the head of compliance.
A bank should ensure that any outsourcing arrangements do not impede effective supervision by its supervisors. Regardless of the extent to which specific tasks of the compliance function are outsourced, the board and senior management remain responsible for compliance by the bank with all applicable laws, rules and standards.2
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.