Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
PRO20

Regulation and supervision of institutions relevant to financial inclusion

This chapter addresses the application of selected Basel Core Principles to the regulation and supervision of institutions relevant to financial inclusion.
  • Published: 01 Jan 2026

Guidelines

This chapter addresses the application of selected Basel Core Principles to the regulation and supervision of institutions relevant to financial inclusion.

The contents of this chapter are based on:

Related standards

Other related publications

Foreword

20.1

Financial inclusion can introduce potential benefits to the safety, soundness and integrity of the financial system. However, it can also bring potential risks to providers and customers alike, and entail the transfer of well-known risks to new players. Research suggests that financial inclusion significantly increases macroeconomic growth, although broadening access to credit can compromise macrofinancial stability when combined with poor quality of banking supervision.1

1

See Sahay, R, M Cihak, P N’Diaya, A Barajas, S Mitra, A Kyobe, Y Nian Mooi and R Yousefi, Financial inclusion: can it meet multiple macroeconomic goals, IMF Staff Discussion Notes, no 15/17, September 2015.

20.2

As previously noted by the Committee, “[p]roportionate regulation and supervision calls for a supervisory approach commensurate with the systemic importance and risk profile of supervised institutions. In the financial inclusion context, this requires effective allocation of supervisory resources, as well as specialised understanding of the changing nature – and sometime also level – of risks that accompany progress on financial inclusion”.2 Such allocation of resources is particularly challenging in low-income countries, where supervisors typically have responsibility for multiple institutional types and multiple functions, while facing significant resource and capacity constraints.

Key terms

20.3

The following terms are used throughout this chapter and have the meaning given below:

  1. Deposit-taking institution: is a bank or any other financial institution licensed to take deposits and intermediate such funds, including financial (savings and credit) cooperatives. The term does not include: any institution that engages only in remittances – that is, transferring funds from a payer or transferor to a payee or transferee subject to a limited maximum holding period (eg in the range of two to five days); or any informal savings scheme, such as a rotating savings and credit association comprised of a small group (eg 25–50 people).
  2. E-money issuer: is a bank or non-bank that issues e-money.3 This Guidance does not address closed-loop systems (such as retailer gift cards), where the e-money can only be used to purchase goods and services offered by the e-money issuer.
  3. Financial cooperative: is a member-owned and member-controlled financial institution governed by the “one member, one vote” rule. Financial cooperatives often take deposits or similar repayable funds from, and make loans only to, members, although some also serve non-members. The term includes credit unions, caisses, cajas, cooperative banks, and savings and credit cooperatives.
  4. Microcredit: is a small credit typically provided to unserved and underserved customers, in particular the underemployed, self-employed or informally employed poor and low-income individuals and microenterprises.
  5. Microfinance institution: is a financial institution that provides financial services, including microcredits, to unserved and underserved customers. A microfinance institution is a type of microlender.
  6. Microlender: is a legal entity or an individual engaged primarily in extending microcredits. Examples of microlenders include microfinance institutions, and banks specialised in offering microcredit to unserved and underserved customers.
  7. Non-bank deposit-taking institution: is any deposit-taking institution that is not a bank.
  8. Non-bank financial institution (NBFI): is any licensed or registered financial institution that is not a bank.
  9. Non-financial firm: is any business primarily dedicated to activities other than provision of financial services.
3

The Committee on Payments and Market Infrastructures (CPMI) defines e-money as “a digital equivalent of cash, stored on an electronic device or remotely at a server”. CPMI, Non-banks in retail payments, September 2014.

Guidance on the application of the Core Principles

20.4

This chapter addresses the specific application of selected Core Principles to the regulation and supervision of financial institutions relevant to financial inclusion. In many countries, NBFIs are the primary providers of financial services and strive to serve unserved and underserved customers. This guidance is provided to reinforce the importance of proportionate regulation and supervision of such institutions. As noted in the Core Principles, “[i]n countries where nonbank financial institutions provide deposit and lending services similar to those of banks, many of the Principles [...] would also be appropriate to such nonbank financial institutions”. Consistent with this statement, this guidance may also apply to such NBFIs. However, the Core Principles also acknowledge that “some of these institutions may be regulated differently from banks as long as they do not collectively hold a significant proportion of deposits in a financial system”.4 In some countries, NBFIs, while not systemic based on the value of funds they intermediate, may present a systemic dimension due to the number and type of customers they serve.

4

BCP02.2 (Footnote 2).

20.5

The guidance set out in this chapter may help promote cooperation and collaboration among a range of authorities and be useful for:

  1. prudential supervisors;5
  2. payment overseers and other authorities engaged in the regulation and supervision of NBFIs or specialised financial institutions established by the Government with specific mandate to develop and promote key strategic sectors in driving the socio-economic development objectives of the country;
  3. authorities with oversight of non-financial firms participating in innovative financial services; and
  4. authorities with responsibility for financial integrity, financial consumer protection, national socio-economic development as well as data protection and competition.
5

In many countries, the prudential supervisor is the central bank or a separate banking supervisor. In some countries, the finance ministry, a specialised agency or other department (eg cooperative development agency, microfinance regulatory authority) may supervise one or more types of non-bank deposit-taking institutions.

20.6

Many unserved and underserved customers reside in countries that are not BCBS members. In recognition of this and given the universal applicability of the Core Principles, this chapter is intended to be useful to both BCBS member and non-member countries, which may implement this guidance gradually over time. The guidance also recognises and reflects the significant variation globally in the composition of financial sectors – particularly regarding the relative importance of banks and NBFIs, the size and complexity of the institutions, and the supervisory structure. This guidance can help promote productive and constructive dialogue between supervisors and assessors regarding the regulation and supervision of financial institutions targeting unserved and underserved customers.

20.7

This chapter is not intended to inhibit the entry of new providers or the adoption of new technologies or to increase supervisory burdens. Rather, it outlines a proportionate application of the Core Principles for the regulation and supervision of small and non-complex institutions striving to serve unserved and underserved customers, which typically engage in small transactions, including lending and deposits.

20.8

Of the 29 Core Principles issued by the Committee, this chapter specifically addresses 19 Core Principles by providing additional guidance on their application to the regulation and supervision of financial institutions engaged in reaching the financially unserved and underserved. It does not create new principles and does not exclude applicability of any Core Principle to any market development relevant to financial inclusion. For each of the Core Principles discussed, this chapter addresses those Essential Criteria (ECs) and Additional Criteria (ACs) which have specific relevance to the financial inclusion context.

Principle 1: Responsibilities, objectives and powers (ECs 1, 2, 6 and 7)

20.9

As stated in EC2, the primary objective of banking supervision is to promote the safety and soundness of banks and the banking system. Supervisors with financial inclusion responsibilities may consider the risks that financial exclusion poses to the safety and soundness of the financial system. These include less transparency, financial integrity risks,6 greater macroeconomic volatility,7 and higher social and political instability.

6

Financial Action Task Force (FATF), Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures, June 2025.

7

Dabla-Norris E and N Srivisal, Revisiting the link between finance and macroeconomic volatility, January 2013.

20.10

At the same time, EC2 should be applied considering the broader financial sector landscape of a country – for example, by interpreting the reference to “banks and banking system” to include licensed non-bank deposit-taking institutions if they serve a significant number of customers.8

8

In countries where non-bank deposit-taking institutions are numerous, very small, and geographically remote, alternative supervisory approaches may be applied (see guidance on Core Principle 8).

Principle 2: Independence, accountability, resourcing and legal protection for supervisors (ECs 1, 3, 6, 7 and 8)

20.11

As a general rule, supervisors should not have responsibilities to promote or develop a sub-sector of financial institutions that they supervise. If supervisors have such developmental responsibilities or objectives, they should clearly publish these objectives (EC3) and discharge their duties in relation to such objectives in a manner consistent with the long-term sustainability and soundness of the institutions they supervise. This should be supported by institutional arrangements that provide for effective coordination and ensure independence between the developmental function and the regulatory and supervisory functions to reduce conflicts of interest.

20.12

As supervisors are confronted with an evolving landscape – eg new types of institutions that can grow quickly in number, scope and scale, new products and services, and new arrangements among banks and non-banks, including the use of retail agent networks as a primary customer interface – they should regularly evaluate staff skills and projected staff requirements over the short and medium term and implement measures to bridge any gaps in numbers and/or skill sets identified (EC7).

Principle 3: Cooperation and collaboration (ECs 1, 2 and 3)

20.13

Most often, banks are supervised by the central bank or a separate banking supervisor. Prudential responsibilities over one or more types of non-bank deposit-taking institutions may be assumed by the banking supervisor or by other authorities, such as a specialised non-bank regulator, the finance ministry and, in some cases, the cooperative agency. There may also be separate functional supervisors – focusing on such topics as financial integrity, deposit insurance, consumer protection, competition and data protection – and sectoral supervisors that supervise financial institutions offering different types of financial products (eg credit, insurance, securities, payments). The innovative digital financial products and services being offered to unserved and underserved customers may involve all of these authorities as well as regulators and supervisors of non-financial firms providing the delivery channel for such products and service.

20.14

Cooperation and coordination among these regulators and supervisors are key to developing an effective regulatory and supervisory framework for financial institutions targeting unserved and underserved customers, in particular to:

  1. design informed and proportionate rules and requirements for the licensed institutions;
  2. delineate regulatory and supervisory responsibilities as clearly as possible to avoid or minimise overlaps and gaps as well as arbitrage by institutions offering similar products;
  3. avoid or minimise inconsistent or overly burdensome requirements that interfere with implementation of policy objectives, including financial inclusion; and
  4. effectively share information about risk sources or events that may affect the financial system, including risks arising from non-financial sectors (eg telecommunications, retail).
20.15

There should be clear and strong cooperation and coordination mechanisms between the prudential supervisor and the authority with financial consumer protection responsibilities (or between different units if these functions are under the same supervisor). For instance, consumer complaints data provided by the consumer protection authority (or supervisory unit) to the prudential supervisor could be an indicator of potential weaknesses in the institutions involved and thereby contribute to an early warning system. Similarly, the authority or unit with financial consumer protection responsibilities can benefit from data on consumer complaints received by the prudential supervisor and prudential supervisory findings that manifest potential consumer or market conduct risks. There should be an active consultation process among the relevant authorities for the drafting of regulations and guidelines for institutions that fall under the regulatory and supervisory jurisdiction of more than one authority.

20.16

The prudential supervisor may also pursue coordination and cooperation mechanisms with:

  1. the financial intelligence unit, with respect to the detection and monitoring of suspicious transactions;
  2. foreign authorities, to identify and address stability threats arising abroad; and
  3. authorities responsible for the regulation and supervision of NBFIs as well as functional supervisors, where relevant, to expand participation in the financial stability policy arrangements.

Increased supervisory dialogue with the industry may also facilitate earlier identification and better understanding of market developments, innovations, and new risks and risk mitigants.

Principle 4: Permissible activities (ECs 1, 2, 4 and 5)

20.17

NBFIs targeting unserved and underserved customers typically engage in a narrow range of activities. These activities may include, lending, taking deposits, facilitating domestic and international transfers (remittances); issuing payment cards or e-money; using agents to interact with customers; acting as an agent of another financial institution; and distributing basic insurance products.

20.18

Certain activities, such as offering chequing accounts or engaging in foreign trade financing, may be beyond the managerial resources or expertise of smaller or less seasoned non-bank deposit-taking institutions. Permission to engage in sophisticated activities should be substantiated by a thorough supervisory assessment of the financial institution and the capacity of its management to identify, control and mitigate more complex risks.

20.19

NBFIs targeting unserved and underserved customers often offer simpler financial products and services than those offered to middle- and high-income customers. In some cases, the difference is one of size, eg smaller loans, smaller account balances and lower-value transactions, which can translate into more limited risks both to the institution and to the financial system. Insurance products for unserved and underserved customers may also have simpler payout processes than the products targeting other market segments. In addition, such insurance products and microcredit often have simpler documentation. NBFIs engaged in simpler activities and offering simpler products may typically face a different and more limited range of risks.

20.20

Some NBFIs may offer ancillary non-financial services, such as business skills training for micro-entrepreneurs. Supervisors should require that these services be conducted by a separate entity and ring-fenced from financial intermediation to minimise conflicts of interests and undue risk exposures.

20.21

Permitted activities of financial institutions (EC2) should be defined sufficiently broadly to permit innovation. At the same time, the supervisor should monitor the emergence of new products and services (eg through market monitoring, allowing providers to launch and test pilots with real customers in a monitored and controlled environment, or studying similar developments in other countries) and be ready to modify the list of permitted activities, as needed.

20.22

Building on EC4, institutions that offer e-money and other digital stored-value products not defined as deposits may also need to be licensed and subject to supervision as appropriate for the risks involved. In some cases, this may mean that a non-financial firm, such as a mobile network operator (MNO), is required to establish a separate legal entity to offer financial services, such as e-money issuance and digital value storage.

20.23

The public list of registered, licensed and supervised financial institutions (EC5) should be clear and comprehensible and should indicate for each type of institution:

  1. the permitted activities;
  2. the supervisory authority; and
  3. whether deposit insurance is available to the deposits placed with them – and, if so, from whom.

Each such institution should be required to disclose its status prominently – both at branches and through agents or other third parties acting on its behalf.

Principle 5: Licensing criteria (ECs 3, 4, 5, 6 and 7)

20.24

The banking supervisor or central bank may be responsible for licensing non-bank deposit-taking institutions; however, in some countries, the applicable law may designate a different licensing authority (EC1). While some NBFIs are registered but not licensed, this must not be permitted for deposit-taking institutions. A proportionate approach to licensing (eg less stringent licensing criteria and procedures for institutions with a low risk profile) allows authorities to allocate the level of resources appropriate for the range of activities that financial institutions are permitted to carry out and the risk posed to the financial system or depositors.

20.25

While the basic licensing criteria may be similar across different types of institutions, regardless of whether they primarily target unserved and underserved customers, the specific requirements for each criterion can vary. These differences reflect the varying risks posed by the products, services and delivery channels designed for unserved and underserved customers as well as the institutional structure. Non-governmental organisations or other ownerless entities (eg associations, foundations) should not be allowed to operate as deposit-taking institutions given that they lack shareholders with the incentive and capacity to provide new capital if the institution’s solvency is threatened.

20.26

A graduated set of licensing criteria commensurate with the permissible activities of financial institutions may be put in place. This will contribute to ensuring that all deposit-taking institutions aiming to provide financial services to unserved and underserved customers are authorised to do so under a licensing framework that can build such customers' trust in the system.

20.27

A graduated set of criteria could also encourage unregulated microlenders to upgrade the quality of their management, governance and operations, and become regulated and supervised institutions (although formalisation is not a supervisory objective). Supervisors should, to the extent possible, monitor registered but unlicensed NBFIs to identify when certain players, subsectors, products or delivery channels evolve to such an extent that the risks they pose individually or collectively become material, requiring adoption of a licensing approach that is appropriate for such cases. (Similarly, an institution’s migration into the next tier with stricter licensing requirements should be commensurate with its evolving risk profile).

20.28

In many countries, there are examples of non-profit microfinance institutions having “transformed” into for-profit, regulated financial institutions, including deposit-taking institutions.9 Supervisors (and licensing authorities, where applicable) should construct a coherent regime for processing applications from “transformed” microfinance institutions.

9

In the microfinance lexicon, “transformation” typically refers to a transaction in which a non-profit organisation transfers its microfinance business to a new or existing for-profit company in exchange for shares in the new company, cash or other assets of equivalent value. Lauer, K, Transforming NGO MFIs: critical ownership issues to consider, CGAP Occasional Papers, no 13, Washington DC, June 2008.

20.29

Newly organised for-profit microfinance institutions may propose having non-profit investors as well as for-profit investors. Not all investors are alike: for-profit investors may have greater incentives to monitor management decisions, while some specialised microfinance investors may have weaker incentives or capacity to oversee the risk-taking behaviour of management. Requirements on shareholder suitability and diversification and on governance structures should be crafted to reflect acceptable scenarios that may arise when there is a mix of non-profit and for-profit owners. For small institutions with limited, low-risk activities, an ownership structure with less stringent requirements may be appropriate in the short term, on a temporary basis. In the medium term, however, more prudent requirements should be imposed, including the need for owners with substantial financial assets to ensure adequate capitalisation, good governance and a sufficient degree of monitoring of management.

20.30

Determining the appropriate minimum initial capital requirement (EC5) for institutions with similar risk profiles is of particular importance. Lower minimum initial capital requirements for NBFIs with typically narrower scope of activities, smaller size and reduced complexity (compared with banks) are most likely appropriate. However, the threshold should be high enough to:

  1. support the basic infrastructure needed to operate sustainably;
  2. ensure that the capital will be adequate to cover unexpected losses from material activities and risks that will be assumed; and
  3. indicate the minimum financial capacity and commitment of the new entrants.
20.31

In some countries, to encourage uptake, the minimum initial capital for a new type of NBFI has been set too low, leaving the institution with insufficient funds to acquire the requisite operating systems and technology, and to absorb the typical initial losses of a start-up. An excessively low requirement can also result in high numbers of relatively weak institutions or institutions engaged in riskier business models. Start-up requirements for financial cooperatives may also include minimum thresholds such as the number of individuals indicating their commitment or intention to become members, or limited geographical scope. Particular attention should be paid to regulatory or statutory conditions under which withdrawable member shares may be considered for the calculation of minimum initial capital.

20.32

The licensing criteria outlined in EC7 are of particular importance when applied to institutions offering new products, services or delivery channels as well as new arrangements between the applicant and other financial or non-financial firms. To adequately assess the strength of an applicant’s proposed plans, policies and internal controls, the assessor should be familiar with the risks of these new products, services and delivery channels, including the data security risks of new technologies and the operational and other risks of using an agent network to interface with customers unfamiliar with using formal financial products and services.

20.33

In many countries, innovative financial services targeting unserved and underserved customers are being offered by banks or NBFIs in partnership with non-financial firms. Institutions offering digital stored-value products that are not defined as deposits - as opposed to the channel for transmitting payment or transfer instructions - may need to be licensed. In some cases, this may mean that a non-financial firm, such as an MNO, is required to establish a separate legal entity to offer financial services.

Principle 8: Supervisory approach (ECs 4, 6, 7 and 8)

20.34

Supervisory approaches should be based on a good understanding of the institutions’ risk profiles - including their systemic importance, specific risks, dynamics and structure - based on a well-defined methodology. For instance, some jurisdictions have large numbers of small, non-complex and non-systemic individual banks or NBFIs - such as financial cooperatives, rural banks and microfinance institutions - targeting large numbers of unserved and underserved customers. Often, due to resource constraints, supervisors are not able to assess the risk profile of each individual institution on an ongoing basis at the same frequency or with the same intensity as they do with respect to medium-sized and large institutions.

20.35

Some jurisdictions apply different approaches, such as a collective approach or an auxiliary supervision approach. Both approaches focus on off-site monitoring at a subsector level as well as targeted supervision of individual institutions. These approaches do not eliminate individual reporting requirements or risk assessments, but are applied based on the overall view of the subsector and on strong off-site analyses. Industry-wide surveillance helps with the identification of risks of vulnerabilities in individual institutions. Minimum standards are established for the whole subsector, but not all institutions are subject to frequent on-site inspections (as is typically the case for medium-sized and large institutions).

20.36

When financial institutions engaged in financial inclusion assume a significant size (eg in terms of assets, deposits, or number of customers) or risk profile, supervisors should focus on supervision of the individual institutions.

20.37

Regardless of the overall approach taken towards certain types of institutions, the ECs under Principle 8 are highly relevant in a context where innovative institutions, products and channels target unserved and underserved customers.

20.38

In addition, as some sectors catering to the unserved and underserved may be outside the supervisory perimeter, a robust surveillance system for market monitoring will help supervisors comply with EC8, by identifying the emergence of bank-like or illegal activities such as financial pyramids and other non-regulated schemes. Supervisors should have access to quantitative and qualitative information that helps them monitor developments in their jurisdiction, identify emerging risks, assess the systemic relevance of regulated and unregulated financial services providers, products and channels, and evaluate whether or how they should be regulated, or whether they should be considered illegal or too risky to continue operating in the market. This would help minimise potential loss of customer funds and deterioration of confidence in the financial sector and the supervisor's credibility.

Principle 9: Supervisory techniques and tools (ECs 1, 2, 3, 4, 5, 8 and 11 + AC1)

20.39

Initiatives targeting unserved and underserved customers may include numerous small financial institutions, greater diversity of institutions, products and delivery channels, and a greater number of third parties working with such institutions (whether related or contractually engaged as agents, partners or otherwise). Such diversity may require greater reliance on off-site supervision as well as deployment of different supervisory tools from those used for conventional banking. For instance, the quality of a traditional microloan portfolio usually cannot be assessed in the same manner in which it is done for conventional commercial loans (eg with respect to sampling techniques; the checking of client documentation; the analysis of follow-on, restructured and delinquent loans; the quality of customer service and monitoring; and the focus on larger exposures). Other examples are institutions delivering pre-approved loans through mobile phones using alternative credit scoring and credit screening models developed by outsourced parties, as well as institutions using retail agents as a delivery channel for their products and services. The supervisor may conduct an inspection of a third party such as an agent network manager. Supervisors may greatly benefit from the use of technology for the identification, analysis and assessment of risks associated with an increasingly complex financial sector landscape (eg tools to facilitate the gathering, transmitting, checking, processing and analysis of regulatory returns).

20.40

Where the supervisor relies more heavily on off-site supervision, the need to build a robust surveillance system increases, as it enables the development of early warning indicators, which could inform supervisory responses and actions. Such a system should enable the supervisor to identify emerging risks that may be common to other institutions serving similar client segments, delivering similar products or adopting similar strategies (eg partnerships to deliver services through mobile phones).

20.41

Supervisors should have a good level of intra-agency and sometimes inter-agency cooperation, coordination and information-sharing arrangements that are working effectively to produce an array of useful and constant information sources as determined by EC3. For instance, in addition to financial data, a valuable source of information may be consumer complaints, particularly in fast-growing markets. Supervisors may establish a framework for receiving and analysing complaints statistics (directly from both financial institutions and alternative dispute resolution mechanisms, or indirectly from a financial consumer protection authority or unit) as a technique that helps in the identification of main business conduct and corporate governance weaknesses, issues with new products or channels, and regulatory compliance matters that could affect the financial strength of a given institution or a particular sector.

20.42

A good surveillance system relies largely on standardised reporting by supervised institutions. Other sources may include self-assessments conducted by the institutions, publicly available information and market intelligence. Supervisors may coordinate with agencies in charge of collecting, reviewing and publishing additional statistics (eg assets or credit portfolio of NBFIs, national surveys including household debt levels or mobile penetration levels). Coordination may facilitate not only data collection, but also the improvement of the national data infrastructure that could feed the supervisor's analyses and its understanding of new client segments.

20.43

All supervisory tools listed in EC4 could be useful for supervising banks and non-banks targeting unserved and underserved customers, and the extent of reliance on each will depend on the approach chosen for a particular subsector, the range of institutions, the range of products, their delivery channels, and the systemic importance, size, risk profile and complexity of each institution. Peer comparisons are important in a good surveillance system, particularly for alternative supervisory approaches where the supervisor plays a more indirect role. The supervisor may dedicate significant resources to analysing and understanding the business models of a particular subsector and the dynamics among participants to help achieve its supervisory goals.

20.44

Coordination with other authorities may be relevant when supervising certain subsectors, such as those relying on telecommunications services. It is also crucial in jurisdictions where financial institutions are owned by firms regulated by other authorities.

20.45

Timely communication of supervisory findings to supervised institutions (EC8) is even more important if alternative supervisory approaches are adopted, to ensure they remain relevant. The supervisor also communicates concerns raised by the assessment of one or more institutions or from industry-wide surveillance to other institutions or their umbrella organisations. The supervisor may also communicate its risk management expectations to the subsector as a whole. Dialogue and feedback from the industry may be sought, especially in the case of new subsectors and new risks.

20.46

Supervisors may choose to use external auditors (EC11) or other specialised third parties to conduct assessments in areas where in-house knowledge is lacking, such as in the assessment of technological platforms that are the core of many subsectors reaching unserved and underserved customers (eg non-bank e-money issuers).

20.47

Periodic independent reviews of supervisory tools (AC1) are important for the supervision of financial institutions targeting unserved and underserved customers, with respect to both: (i) innovations that may require new and different tools in the future; and (ii) alternative supervisory approaches.

Principle 10: Supervisory reporting (ECs 1, 4, 5, 8, 9 and 11)

20.48

For institutions targeting unserved and underserved customers, supervisors may adjust the reporting requirements to ensure they have the information needed to understand the business models and related risks (EC1), and to carry out effective and proportionate supervision. To avoid unduly burdensome reporting requirements, supervisors should first identify the key risk indicators that need to be monitored. Such key indicators should allow the supervisor to assess portfolio quality, loan loss provisioning, risk concentrations, related-party transactions, capital adequacy, operating costs, funding structure and liquidity position, foreign exchange exposures, and interest rate repricing gaps. Supervisors should have the ability to compare key indicators against performance benchmarks within peer groups. Reports of internal and external auditors may also be used to collect information about particular activities in supervised institutions.

20.49

Adjustments to reporting requirements could capture the risks arising from innovative business models, including those adopted by institutions targeting unserved and underserved customers (EC1). For instance, supervisors may require institutions that use the traditional microlending methodology to provide detailed information on credit risk, such as the ageing of past-due accounts, the distribution of allowance for losses based on the ageing buckets, or the levels of written-off accounts. This will allow them to assess the adequacy of loan loss provisions and the potential impact of the current exposures on capital levels. In the case of e-money issuers, supervisors may require reporting of the volume and type of transactions, as well as value of outstanding e-money issued, to be able to gauge whether supervisory measures are necessary with respect to both the issuers and the deposit-taking institutions holding the funds backing the e-money issuance. Supervisors may also require information on the network of agents used for service delivery and on the profile of a particular client segment. Proportionate reporting requirements may apply to both new institutional types and established institutions offering new products, services or delivery channels.

20.50

Supervisors may also consider collecting standardised statistics on consumer complaints from financial institutions directly when such statistics are not requested by a financial consumer protection authority, and complementing them with statistics on complaints presented to other entities (eg alternative dispute resolution mechanism). This will help supervisors carry out comprehensive and prospective analyses of, and monitor changes in, the risk profile of financial institutions (EC4).

20.51

When enforcing reporting compliance (EC7), supervisors should be mindful of potential challenges faced by some types of financial institutions targeting unserved and underserved customers (eg limited information systems, personnel and skills). Supervisors may provide guidance to such institutions on how to prepare and submit regulatory returns.

20.52

To verify the validity and integrity of supervisory information (EC8), supervisors would ideally have a system that automatically flags unusual data patterns, such as significant changes in the value of specific variables from one reporting period to the next, and/or inconsistencies observed between the value of individual variables and that of aggregate indicators. In the case of subsectors composed of a large number of small financial institutions, supervisors may use external experts not only to verify the validity and integrity of regulatory reports but also to carry out specific supervisory tasks. This may include analysis of detailed quantitative or qualitative information provided by supervised institutions, and examination of specific aspects of their operations.

Principle 11: Corrective and sanctioning powers of supervisors

20.53

The need for an adequate range of supervisory instruments to bring about timely corrective actions applies equally to banks and non-bank deposit-taking institutions engaged in financial inclusion. However, supervisors more often have the authority to use corrective and remedial powers with respect to banks than with respect to NBFIs (including non-bank e-money issuers, which in several countries have greater outreach to unserved and underserved customers).

20.54

The registration or licensing of non-financial firms engaging in deposit-taking activities facilitates supervision by the prudential supervisor and the implementation of prompt corrective actions or sanctions. Without such a registration or licensing requirement, the supervisor’s authority to exercise corrective and remedial powers over such firms may be limited and the supervisor may not be able to intervene in a timely and effective manner to resolve the non-financial firm. The supervisor may not have the tools, skills or power to assess the financial health of an e-money issuer if its core business is non-financial – although this challenge could be mitigated through explicit coordination and cooperation arrangements with the authority directly supervising the non-financial firm.

20.55

As some financial institutions relevant to financial inclusion, including non-bank e-money issuers, may be subject to less intensive supervision than banks or to alternative supervisory approaches, supervisors should ensure that their approach to supervision and their supervisory tools enable them to monitor such institutions more closely. In addition, supervisors should engage with other authorities (eg the telecommunications regulator) to obtain timely information on emerging risks relevant to non-financial firms or third parties and to respond quickly and in a coordinated manner.

20.56

Supervisors need specific knowledge of providers' business models and their risks when designing and using proportionate corrective and sanctioning measures. Some tools typically used for conventional banking may be less effective, inadequate, or applicable only to certain subsectors. Innovative business products and services may, in the initial years of operation, be offered by only one or a few providers. The risk of interrupting or reducing availability of such products and services reinforces the need for well-designed measures.

20.57

Some of the corrective and sanctioning tools that are appropriate for financial institutions engaging in traditional microlending may differ from those typically used for conventional bank lending. For instance, restricting lending can have negative consequences for such microlenders since the implicit promise of follow-on loans to current borrowers is an important incentive for loan repayment. In addition, if the lender is unable to generate new loans to cover the high upfront costs of the labour-intensive traditional microlending methodology, its capital base may deteriorate quickly. Market solutions – eg mergers and loan sales – may be problematic, as traditional microloan portfolios may lose value when sold or transferred.10 If such market solutions result in or send a signal of a change in the close relationship between client and lender, incentives for repayment may be reduced. Supervisors designing corrective or sanctioning measures must therefore have a good understanding of the specific dynamics of traditional microlending, so that the supervisory measures do not lead to unintended and undesirable consequences.

10

See Rozas D, Throwing in the towel: lessons from MFI liquidations, September 2009.

20.58

Financial cooperatives may also require specific corrective and sanctioning actions due to their membership-based structure and, in some countries, their system-based organisation.11 The requirement for a financial cooperative to raise additional capital may be more challenging due to its capital and ownership structure.

11

In some countries, financial cooperatives are organised in structured systems in which individual cooperatives form higher level structures such as federations, associations, central cooperatives and cooperative banks.

20.59

Supervisors may also consider alternative approaches, in which strict corrective or sanctioning measures against one provider may produce the desired behaviour changes or curb undesired behaviour in other providers with similar business models. Challenges in the design of prompt corrective actions and sanctions should not discourage their implementation, since their absence would weaken supervisory effectiveness and negatively affect the safety and soundness of the supervised financial institutions.

Principle 12: Consolidated supervision (ECs 1 and 5 + AC1)

20.60

In many countries non-financial firms with wide distribution networks play a key role in providing physical access to financial services for previously unserved or underserved customers. These firms include both international and domestic retail department stores, as well as telecommunications companies. They may act as the agent of financial institutions, offering financial products and services, or directly provide credit facilities to their customers. These non-financial firms may be parents of a licensed financial institution or affiliated to the parent company of a financial institution.

20.61

Supervisors should pay attention to the establishment, by regulated financial institutions, of special purpose vehicles or group entities that may be outside the supervisor's remit, to undertake activities such as providing credit. Besides gaining operational efficiencies, such decisions may also be motivated by regulatory arbitrage objectives. A group-wide view by the supervisor is essential to identify and act upon risks posed by unregulated activities within the group to the regulated entity or to financial stability.

Principle 14: Corporate governance (ECs 1, 2, 3, 5, 7 and 8)

20.62

Robust corporate governance is important in institutions targeting unserved and underserved customers, as it ensures responsible and sustainable financial inclusion based on a culture that reinforces values such as sound risk management and the fair treatment of customers. Some non-banks may have governance structures and practices that are significantly different from those of banks. Supervisors should develop a good understanding of how such structures work and their impact on the institution's risk profile. In situations where the supervisor might not be able to exercise the same level and intensity of regulation and supervision over such non-banks, the supervisor will tend to rely more on robust corporate governance standards.

20.63

Supervisors should develop some guidance to help institutions conduct self-assessments of their level of compliance with principles and regulatory requirements for sound corporate governance.

20.64

Supervisors should check whether there is effective board oversight and participation when board members live abroad and participate in the board of multiple institutions, a situation that may be commonly found in some types of institutions engaged in financial inclusion. Moreover in many countries, state-owned banks (eg rural banks, postal banks and development banks) may pose specific challenges in terms of governance.12 In such situations, supervisors should require the financial institutions to follow the same principles of good governance required of privately owned banks.

12

See Organisation for Economic Co-operation and Development (OECD), OECD guidelines on corporate governance of state-owned enterprises, October 2024, for further discussion on distinct governance challenges faced by state-owned entities.

20.65

Regular assessment of corporate governance (EC2) may require frequent engagement with an institution, which may be challenging for supervisors with limited resources particularly where the number of institutions providing such financial services is high.

20.66

To the extent that a financial institution’s use of third parties – whether as agents, agent network managers, or partners providing data processing or other services – becomes significant, it will be important for the financial institution to ensure that its culture and values are upheld and that the financial institution has the capability to manage and mitigate the third-party risks.

20.67

Non-financial firms engaged in financial services may pose challenges for supervisors assessing their governance structure or addressing other supervisory concerns, not only because their structure will differ from those of financial institutions more familiar to the supervisor, but also because their main business is not within the remit of the financial supervisor. Supervision may be hindered even inadvertently, by the firm, and attention to the supervisor’s concerns may be limited depending on the importance of the financial business to its overall business. The supervisor’s access to information may not be as effective as it would be if the provider were a separate legal entity. The supervisor may also not be able to ensure that the board of the non-financial firm has enough expertise in the financial business under supervision.

Principle 15: Risk management process (ECs 1, 2, 4, 7, 9 and 10, 12, 13).

20.68

Supervisors should be well informed and have a good understanding of the business models, risk types, risk sources and risk exposures of banks and non-banks catering to unserved and underserved customers. With these inputs, supervisors will be able to set proportionate (not necessarily lower) expectations of risk management strategies, policies and processes commensurate with the varying scale and complexity of operations, risk profile and systemic importance of different institutions, and determine that the supervised institutions are meeting these expectations (ECs 1 and 2). Supervisors can make such determinations primarily during licensing (in the case of small financial institutions), during ongoing supervision (including through meetings with board members or senior management), and when the supervised institution introduces new products or services or delivery channels, according to the supervisory approach adopted. Well informed supervisors will be able to systematically review and adjust their expectations of risk management processes for providers targeting unserved and underserved customers as needed.

20.69

Key risk management challenges faced by financial institutions targeting unserved and underserved customers may include: the lack of a comprehensive view of risks in a fast-changing environment; unavailability of qualified staff; and deficient management information systems. Supervisors should assess financial institutions’ policies and processes to manage risks arising from third parties, as these are highly relevant when targeting unserved and underserved customers, given their prevalence (for example, the use of agents as the main interface with retail customers). Financial institutions should ultimately be responsible for any outsourced activities, and need to have specific mechanisms to ensure regulatory compliance, such as ensuring that agents follow relevant consumer protection and AML/CFT rules.13 Supervisors should require that financial institutions test and validate alternative credit scoring or screening models developed by third parties, and understand the limitations and uncertainties relating to their output. This could be done also at the subsector level, depending on the supervisory approach taken (EC6). Supervisors require and determine that financial institutions have adequate policies and processes to manage consumer protection risks, ensure fair treatment of customers and provide an effective customer care system.

13

The applicable law or regulation should indicate that the financial institution remains liable for all explicitly or implicitly authorised actions of an agent acting on behalf of the institution pursuant to an agency agreement, and that this agreement clearly states the institution’s liability. The regulation may also require that such agreement specify agent responsibilities and the actions that the financial institution can take when responsibilities are not fulfilled or rules are not followed by the agent.

20.70

Information systems in supervised institutions are crucial for proper recording of transactions and management of accounts and secure storage of personal data. In the case of small transaction accounts offered to unserved and underserved customers as well as loans delivered to such customers via mobile phone, the information system should allow the monitoring and management of risks associated with the use of third parties that are often providing agency services for the delivery of such new products (EC8). Information systems should also allow for the timely and reliable creation, processing and transmission of risk management reports to senior management, particularly in the case of fast-changing environments. Information systems should be strengthened in parallel with changes in the types of risks and customer profiles, as well as portfolios of products, services and channels offered by the financial institution.

20.71

Supervisors should monitor the resources available for risk management in financial institutions targeting unserved and underserved customers (EC10), and assess whether there are resource constraints and the reasons behind such constraints. For example, the business model of financial institutions applying the traditional microlending methodology places greater responsibility on loan officers, making it harder to segregate risk management and risk-taking functions – a situation that can still be mitigated through other mechanisms. On the other hand, financial institutions may face rapid increases in exposures and sources of risk due to a combination of high demand and increased offerings of new products, services or delivery channels. This could strain risk management capacities that initially planned for a lower level of business operations. Supervisors should ensure that there is a balance between the financial institution’s risk appetite and its capacity to manage risks.

20.72

When issuing standards (EC12), supervisors should focus on the specific risks arising from the products, services, channels and types of institutions catering to unserved and underserved customers, and set standards commensurate with these characteristics. Such standards may vary from those imposed on institutions catering to other market segments.

20.73

Supervisors should require and carefully review, especially at the licensing stage, the contingency arrangements for ensuring business continuity during disruptions to the operations of financial institutions using digital delivery channels to reach unserved and underserved customers, particularly if they rely on the uninterrupted services provided by third parties (EC13), including agents and telecommunications services.

20.74

Considering the potentially greater contagion risks (eg traditional microlending institutions) and reputational risks (eg state-owned banks) faced by some types of institutions targeting unserved and underserved customers, supervisors should require and determine the adequacy of the policies and processes of the individual institutions to address such risks (EC2).

Principle 16: Capital adequacy (ECs 1, 2, 4 and 6 + AC1)

20.75

Where supervisors choose to apply Basel standards, Basel I or the standardised approach of Basel II may be adequate for less complex and non-systemic banks and non-bank institutions. Compliance with advanced measurement techniques may be beyond the expertise of many institutions (including some banks), and ensuring compliance with them may become costly.

20.76

As an alternative to Basel standards, some respondents do not impose a capital adequacy ratio on institutions other than commercial banks, but impose simpler requirements such as a minimum nominal capital and leverage ratio. For non-bank e-money issuers, supervisors may substitute capital adequacy ratios with requirements to protect client funds. For example, the non-bank e-money issuer is often required to set aside, in an account with a prudentially regulated financial institution, an amount equivalent to the total e-money issued and to take other measures to protect the customers’ ownership of such funds.

20.77

While ECs 1 and 2 emphasise the importance of adequately defining the qualifying components of regulatory capital, this task may be particularly challenging for small financial cooperatives. Some specific measures may be adopted, depending on the structure, size and sophistication of a particular cooperative sector:

  1. restricting redemptions of shares unless the capital adequacy ratio is kept at a minimum level equal to or higher than that specified by regulation;
  2. requiring cooperatives to make liquidity deposits in a second-tier entity or to use another comparable facility; or
  3. applying capital adequacy requirements on a group or system basis (eg at the level of a federation or a central cooperative).

For the last two measures, the liquidity and solvency of the cooperatives will depend on the liquidity and solvency of the second-tier entity. Consequently, these entities must be well regulated and supervised.

20.78

A proportionate approach does not always result in lower capital adequacy ratios. Supervisors may impose higher capital adequacy requirements (sometimes temporarily) to compensate for weaknesses in certain subsectors. For example, small financial cooperatives may face difficulties in raising additional capital in times of stress or may not have adequate contingency plans (EC6 [b]) due to their membership-based operations and decision-making process.

20.79

Several characteristics of traditional microlending might justify: (i) higher capital adequacy ratios for financial institutions engaged in this type of activity relative to those imposed on diversified or other or financial institutions; or (ii) a tailored approach to risk-weighted assets that differentiates traditional microlending from “other retail exposures” – the asset category typically assigned to microloans under the misguided assumption that they exhibit features similar to those of a large pool of small, diversified loans. The following characteristics of traditional microlending are particularly relevant:

  1. the defaults in traditional microloans usually result in loss, with limited recovery through collateral;
  2. borrowers that notice increasing delinquency in the institution may stop paying if they believe that the institution will be less likely to offer follow-on loans due to credit quality problems;
  3. the high operational costs of generating and maintaining high volumes of short-term small loans, which indicates that a relatively low level of delinquency will de-capitalise a specialised traditional microlender more quickly than it would a diversified commercial bank; and
  4. losses in traditional microloan portfolios may be linked more strongly to localised events given the high degree of interdependency of low-income borrowers and the typical regional concentration of microfinance institutions.

In general, selecting an appropriate level of regulatory capital will require a clear regulatory definition of different types of microcredits and a good understanding of the local context with respect to microfinance operations.

Principle 17: Credit risk (ECs 3 and 4)

20.80

To adequately assess banks’ credit risk management practices, supervisors need to distinguish financial institutions using traditional microlending methodologies from those using other less labour-intensive methodologies. In many countries, microlenders (particularly banks) are extending large numbers of very small loans based on credit scoring which uses alternative client information often supplied by third parties, such as bill payment history, non-financial data from social media, mobile phone usage and big data analytics. These loans may be closer to loans in terms of risk management methodologies, although there is not yet enough experience to make a general statement about their performance compared with traditional microlending. Some models also use new delivery channels (eg pre-approved loans delivered through mobile phones and payroll-based loans).

20.81

It is important for supervisors to familiarise themselves with newer, alternative credit scoring and screening techniques, and to be satisfied that the lenders using them adequately test their strength. In addition, given the emergence of business models in which third parties participate in the loan delivery process (for example, digital delivery of credit by mobile phone or payment card) and may supply non-financial data and data analytics, supervisors may also strive to understand whether and how the use of such third parties affects credit risk management and whether the lenders (and their boards) are aware of the assumptions and limitations of outsourced methodologies (in line with EC3[a] and [g]).

20.82

Further, special attention may be paid to financial institutions engaging in riskier business models or products such as those relying on high delinquency rates (eg lending to clients with low credit scores) and offering products with high inherent risks (eg loans in a currency different from that of the borrower’s income). Specifically, inquiry is appropriate into whether lenders are reassessing the borrower’s payment capacity every time a new loan is being extended, in line with EC3[c], or are instead creating debt traps for certain delinquent customers. This is critical for loans to financial consumers with little or no experience in the formal financial sector and low financial capability, and who may more readily take on credit without reflecting on their needs or their capacity to repay. Lending to customers with high risk of over indebtedness is also important vis-à-vis the financial health of the financial institutions if they are underestimating the risks and underpricing the loans.

20.83

The negative consequences of consumer over indebtedness may be significant, not only for financial inclusion but also for financial stability14 – high delinquency levels affecting one financial institution could cause negative spillover effects on others operating in the same market and lead providers to label entire categories of consumers as “unlendable”. Supervisors should require that financial institutions targeting unserved and underserved customers have policies and processes in place to monitor and avoid over indebtedness.15

14

See International Financial Consumer Protection Organisation (FinCoNet), Report on responsible lending: review of supervisory tools for suitable consumer lending practices, July 2014.

15

See policy tools to curb debt stress in Davel, G, Regulatory options to curb debt stress, CGAP Focus Note 83, March 2013.

20.84

The proliferation of formal, informal, regulated and unregulated microlenders with varying business models raises further concerns regarding debt stress and potential systemic consequences of over indebtedness in some jurisdictions. Such concerns have driven efforts to improve credit information (both positive and negative) on a broader set of customers of providers beyond banks. In some jurisdictions, credit information on unserved and underserved customers may not be available, accurate or reliable. An effective credit information system that includes the full range of bank and non-bank lenders serving different market segments, including the unserved and underserved, is critical for avoiding over indebtedness. Public and private sector efforts to raise consumer awareness of the risks of over indebtedness are also important.

Principle 18: Problem assets, provisions and reserves (ECs 4. 5, 7, 8 and 10)

20.85

A tailored approach is required with respect to institutions engaged in traditional microlending, especially regarding asset classification and provisioning (EC7). For example, in traditional microlending, past-due loans should move to riskier categories with higher provisioning and be classified as non-accrual more quickly than other types of loans (EC5). Different approaches may also be considered for certain innovative microcredit products that rely on alternative credit scoring models and delivery channels as supervisors gain knowledge about their performance.

20.86

To build a flexible but appropriate regime for problem assets, supervisors need to understand microlending dynamics and the local market practices. Care may be warranted when using external experts in assessing a lender’s policies and processes for classification and provisioning of microcredits (EC2), ensuring that such experts have adequate knowledge of innovations in microlending. Particular attention should be paid to rescheduled, refinanced, and reclassified microcredits to avoid circumvention of the classification and provisioning standards (EC5). Microcredits that have been granted concessions by the bank should typically be classified in a higher risk category than those with the same number of days or payments past due but without such concessions. The supervisor may also consider the unique features of loans to small farmers, which are often “bullet loans” requiring special treatment separate from other microfinance loans.

20.87

EC4 is relevant for supervisors implementing a problem asset framework for financial institutions targeting unserved and underserved customers, as the performance of their microloan portfolios is linked to the macroeconomic environment,16 and often highly influenced by the specific market conditions and the country’s political situation. These factors, which impact the likelihood and speed of portfolio deterioration, should be accounted for by the supervisor when assessing the classification and provisioning of microloan portfolios. Supervisors may try to reduce the impact of negative macroeconomic conditions by establishing dynamic provisioning that mandates higher provisioning requirements in periods of high economic growth; such provisions could be used to meet provisioning requirements in recession periods.

16

See, for instance, Di Bella, G ,The impact of the global financial crisis in microfinance and policy implications, IMF Working Papers, WP/11/75, July 2011; Wagner C, From boom to bust: how different has microfinance been from traditional banking?, Development Policy Review, vol 30, issue 2, pp 187–210, 2012; Wagner and Winkler, The vulnerability of microfinance to financial turmoil – evidence from the global financial crisis, World Development, vol 51, November, pp 71–90. 2013; and Kruijff D and S Hartenstein, Microfinance and the global financial crisis: a call for Basel, World Bank Working Papers, no 94906, Washington DC, January 2014.

20.88

The generation of accurate and timely data (EC6) will allow the supervisor to run tests tailored to microfinance (EC5), including accuracy tests that will help it spot instances of non-compliance or tampering with the policies and rules.17

17

For useful guidance on microfinance portfolio assessments, see Christen R. and M Flaming, Due diligence guidelines for the review of microcredit loan portfolios: a tiered approach, CGAP Technical Guide, December 2009.

20.89

When setting up requirements on the valuation of risk mitigants (EC8) applicable to traditional microlending, the supervisor should consider that risk mitigants are less often used by microlenders and, when used, they are used differently from conventional banking. When a microlender obtains collateral, it usually does not cover the value of the loan and often the collateral is not expected to be enforced due to the high enforcement costs relative to the loan amount. This is particularly the case in countries with weak judicial and legal systems. Possession of a charge over collateral is expected to promote better repayment behaviour.

20.90

A tailored approach to traditional microlending should be based on clear and appropriate regulatory definitions of microcredit, microloan, microfinance loan or similar terms applicable to banks and NBFIs implementing this particular methodology.

Principle 24: Liquidity risk (ECs 2, 3, 4)

20.91

Implementing Core Principle 24 requires specialised knowledge of the specific dynamics of assets and liabilities in institutions targeting unserved and underserved customers - particularly traditional microlenders - and the nature, structure and behaviour of funding sources, which may differ from those of more complex and large banks.

20.92

As the types of institutions and their products (including those that target unserved and underserved customers) become more diverse and complex, the application of Core Principle 24 becomes more challenging, requiring the supervisor to keep abreast of emerging business models and to develop an understanding of the changes to liquidity risk (for instance, how innovative credit products targeting unserved and underserved customers impact liquidity management).

20.93

The specific assets typical of traditional microlenders introduce liquidity risks that are different from those of conventional, diversified banks and non-banks.18 As the promise of follow-on microloans is an important incentive for borrowers to repay (with the treatment and response of individual borrowers having a potentially significant impact on other borrowers of the same institution), a traditional microloan would usually behave like a long-term asset,19 the proceeds of which may be unavailable in a liquidity shortage. Traditional microlenders also face the potential for rapid deterioration of capital in the case of loan defaults as they usually rely on their loan portfolio as their most important source of revenue.

18

Although not always the case, non-banks engaged in traditional microlending generally hold relatively large amounts of cash or highly liquid assets such as government bonds.

19

See Brom, K, Asset and liability management for deposit-taking MFIs, CGAP Focus Note 55, June 2009. It is important to recognise that microfinance is an evolving business, and the assumption of follow-on loans as a strong (or the main) incentive for loan repayment may vary across providers and across countries. The supervisor should develop specific knowledge of the particular market.

20.94

In many countries, a non-bank e-money issuer is required to place an amount equivalent to the total outstanding e-money it has issued into a restricted account of one or more deposit-taking institutions to guarantee the availability of funds for customer withdrawals. Some jurisdictions may also apply other liquidity requirements to e-money issuers, but the supervisor should be mindful of the costs of liquidity maintenance and the consequent impact on the operational viability of the supervised institutions (for example, e-money issuers).

20.95

There is limited data on the behaviour and stability of low-value deposits maintained by low-income customers in banks and non-banks, and it is not clear whether there are significant differences with mainstream retail bank deposits.20 It is important to note that sources of funding for many institutions reaching unserved and underserved customers (which often differ from those of conventional banks) may have difficulty responding quickly in the event of liquidity shortfalls. In some markets, microfinance institutions borrow heavily from local banks for on-lending, exposing both lenders and borrowers in the event of market-wide deleveraging.21 Finally, non-bank deposit-taking institutions may not have access to central bank liquidity facilities, impacting contingency funding plans (EC6).

20

For studies on deposits in microfinance institutions, see Westley G and X Palomas, Is there a business case for small savers?, CGAP Occasional Papers, no 18, September 2010.

21

For an analysis of microfinance crises, see Chen G, S Rasmussen and X Reille, Growth and vulnerabilities in microfinance, CGAP Focus Note 61, February 2010. The link between microfinance and local and global markets is further explored in Kruijff, D and S Hartenstein, Microfinance and the global financial crisis: a call for Basel, World Bank Working Papers, no 94906, January 2014.

20.96

The above factors may justify supervisors applying a higher liquidity requirement or focusing on high-quality, highly liquid assets, particularly for small institutions, with less expertise and capacity in asset and liability management and in designing and testing contingency funding plans. The supervisor may consider imposing a cushion in the form of a reserve or liquidity ratio, requiring institutions to hold sufficient unencumbered liquid assets (for example, as a percentage of deposits) and limiting concentration of funding sources, which could be introduced in a phased manner for institutions in their first years of operation, subject to stricter supervisory monitoring in the early phases.

20.97

Liquidity risk management should focus on comprehensively measuring and forecasting cash flows and maintaining an adequate minimum liquidity cushion for business-as-usual and stressed situations, considering the likely behavioural responses of relevant actors. The application of ECs 5–7 (eg establishment and regular review of funding strategies, robust contingency funding plans, and stress testing) to institutions targeting unserved and underserved customers should be commensurate with the complexity, scope, size, risk profile and business model for each type of institution and should not be unduly onerous. When setting these requirements, supervisors should be mindful of the potential contagion effects that may manifest in geographically concentrated markets or in microloan portfolios.

Principle 25: Operational risk and operational resilience (ECs 1. 2, 5, 9, AC1)

20.98

Supervisors should determine that financial institutions reaching unserved and underserved customers are cognisant of the distinct operational risks associated with their products and delivery mechanisms as well as the target customers and other characteristics of the market that they serve (ECs 1–2). In evaluating whether operational risk frameworks put in place by the supervised institution are adequate, the supervisor should understand the potentially fast-evolving roles played by third parties involved in the delivery of the financial services, including third-party providers that may access information on payment accounts and provide payment initiation services to users. The supervisory assessment should aim at ensuring that operational risk is managed without stifling innovation.

20.99

Supervisors should be able to ascertain that financial institutions targeting unserved and underserved customers have the necessary internal controls and information systems in place to ensure that risks are appropriately managed (including consumer protection and conduct risks). Examples of operational risk events related to financial inclusion include the following:

  1. Internal fraud: a non-bank e-money issuer can manipulate the books (to steal customer funds) so that it appears that the e-money on its books matches the funds deposited in a trust account or custodial account with a deposit-taking institution.22 Although e-money is a relatively simple financial product, this does not mean that the risks of manipulation are lower or that the controls in managing e-money are simpler than risks and controls involved in managing deposit accounts.
  2. Execution, delivery, and process management; external fraud: the use of agents as the primary customer interface – including to accept deposits and loan repayments, and to enable withdrawals – introduces new operational risks and consumer protection risks in addition to the common third-party risks (EC9). Long distances between a financial institution and its agents can make oversight of agent actions difficult, introducing increased risk of fraud and theft, abusive treatment of customers, and failure to handle customer data confidentially.23 Policies and procedures governing the selection, training and oversight of agents should be designed to address these risks.
  3. Clients, products and business practices: customers new to formal financial services and digital financial transactions may lack familiarity with the technology applications and the complexities of digital interfaces, which may result in them sending funds to the wrong mobile number or forgetting the security measures of the mobile device. Digital financial transactions often rely on electronic (as opposed to paper-based) records and receipts, which can sometimes give rise to availability- and reliability-related issues due to the interruption of service. These issues may undermine customers’ trust in the institution and its products, services and/or channels.
  4. Business disruption and system failures: financial institutions targeting unserved and underserved customers may be operating in areas that lack basic infrastructure or are prone to interruptions in the delivery of basic services. Disruptions in service may impact the provider’s reputation and result in a loss of customer confidence not only in the specific company but also in digital delivery mechanisms. Financial institutions using digital platforms as the sole means of serving customers need business continuity measures to address the risk of disruptions on the platforms used (EC5). Supervisors should understand and consider the practical realities in serving these areas while balancing the need for the supervised entities to put in place mechanisms to address risks resulting from this type of operating environment.
22

A trust account or custodial account may help ensure that the funds of e-money clients are not available to other creditors of the e-money issuer.

23

The data security and fraud problems are further exacerbated by a practice common among customers new to digital financial services of giving their passwords to agents.

20.100

Both on the digital platforms and in the networks of agents, it must be clear to the supervised institutions that they have the final responsibility for the protection of consumers’ personal and financial information. Supervisors should have the authority to look into the implementation of service level agreements if deemed necessary, and take action when there are risks arising from the non-implementation of certain provisions (EC9).

20.101

In some countries, the delivery by both banks and NBFIs of financial services to unserved and underserved customers via mobile phones is concentrated in one or two MNOs. Supervisors should monitor these situations to assess whether such financial institutions become more vulnerable to, or exposed to new sources of, operational risks (eg service unreliability or disruption). Where they are exposed to such risks, supervisors should require institutions to diversify or establish appropriate contingency plans to address stress in the service providers or the unavailability of a service provider (AC1). The supervised institution and the supervisor would benefit from periodic testing of the contingency plans for its operational feasibility during stress situations.

Principle 28: Disclosure and transparency (ECs 1 and 2)

20.102

Supervisors should consider potential limitations in the technical capacity of, and resources available to, NBFIs as well as their potential need for more intensive and detailed guidance and orientation on the preparation of public disclosures.

20.103

When establishing disclosure requirements, supervisors should consider differences in risk sources and exposures associated with different financial institutions, products and channels targeting unserved and underserved customers. For example, for institutions engaged in traditional microlending, the shorter terms of the microloans and the potential for more rapid deterioration in the quality of loan portfolios should be considered. For e-money issuers, disclosure regarding how customer funds are being held (eg in a trust account with a bank) as well as the different actors involved in the provision of services (eg account administrators, IT providers, agent networks) will be relevant. Disclosure on business models, geographical, sector or customer base concentration, and governance structures are also important for financial institutions tending to unserved and underserved customers; as well as disclosure of related parties (EC3), including non-financial firms (eg retail stores or MNOs) and third parties with an agency or other third-party relationship. Disclosure requirements should strike an appropriate balance between the need for meaningful disclosure (for market conduct and consumer protection purposes) and the protection of proprietary and confidential information.

20.104

In accordance with EC5, supervisors may publish information on the banking system on their website for easy access by the general public and/or distribute to other actors who can then transmit this information to the wider public (eg consumer organisations, research institutes and journalists). Such disclosures by the supervisors can serve as inputs to the supervised institutions for their risk management and business strategies. Supervisors may also publish guidance notes or have direct conversations with such actors to expand outreach and improve understanding of market information.

Principle 29: Abuse of financial services

20.105

AML/CFT regulation should follow a proportionate or “risk-based approach” – consistent with the FATF standards – requiring financial institutions to adopt enhanced consumer due diligence (CDD) measures for transactions or products that present higher AML/CFT risks and permitting them to use simplified CDD measures where risks are lower.24

24

Regulation should require financial institutions to assess their money laundering and terrorist financing risk. See examples of higher- and lower-risk activities articulated in the Interpretive Note to FATF Recommendation 10, The FATF Recommendations, February 2025.

20.106

Subject to a jurisdiction’s assessment of its money laundering and terrorist financing risks, financial inclusion products and services may present lower risk if they are subject to appropriate restrictions such as:

  1. low-value limits, whether for account balances, individual transactions or total value of transactions in a given period;
  2. geographical restrictions (eg no or limited international transactions); or
  3. restrictions on the customer who may be offered and use the products and services (eg only individuals).

Where risks are proven to be low, the regulator should have the option to grant limited exemptions from AML/CFT obligations, and should do so where appropriate.

20.107

Regulation that requires documentation to verify identity can potentially create barriers to access to financial services and products. It is therefore important to consider the purpose and design of the verification measures and to accept non-standard identity verification – provided that it uses reliable and independent source documents, data or information – in jurisdictions that lack a reliable national identity document or other widespread means of identity verification. For services that involve remote account opening via mobile phone or agent, explicit permissibility of non-face-to-face CDD by agents or mobile device is essential. This may include the use of biometric technologies.

20.108

Appropriate understanding and employment by banks and NBFIs of simplified CDD is especially important as overly strict compliance with CDD rules can prevent unserved and underserved customers from accessing formal financial services and products and potentially increase the risk of money laundering and terrorist financing by shifting transactions to the informal economy. Supervisors should provide appropriate guidance as to what the risk-based approach to CDD entails – including with respect to ongoing due diligence and monitoring – and communicate the importance of managing the risks of individual account holders when applying such a risk-based approach. Supervisors should also understand the drivers of and reasons for a financial institution not applying simplified CDD to lower-risk products, where allowed. Consistent with FATF standards, where there is an actual suspicion of money laundering or terrorist financing risk, enhanced due diligence should be applied regardless of any threshold or exemption.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in