Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
SCA50

Financial conglomerate supervision

This chapter outlines principles for the supervision of financial conglomerates.
  • Published: 01 Jan 2026

Guidelines

This chapter outlines principles on the necessary powers and authority for supervisors of financial conglomerates. It focuses on supervisory responsibilities and guidance for supervisors on the governance, capital, liquidity and risk management frameworks of financial conglomerates.

The contents of this chapter are based on:

Related standards

Other related publications

Foreword

50.1

Financial conglomerates may increase systemic risks and present challenges for sector specific supervisory oversight due to their interlinkages with the broader financial system and their mix of regulated and unregulated entities (such as special purpose entities and unregulated holding companies) across sectoral boundaries.

50.2

It is important that supervisors consider risks arising from the activities of unregulated entities that are not directly prudentially regulated. Each unregulated entity may present different risks to a financial conglomerate and each may require separate consideration and treatment. In deciding which unregulated entities are relevant, consideration should, at a minimum, be given to:

  1. operating and non-operating holding companies (including intermediate holding companies),
  2. unregulated parent companies and subsidiaries, and
  3. special purpose entities.1
1

Refer to the Joint Forum, Report on Special Purpose Entities, September 2009.

50.3

The lack of direct supervisory authority over a particular entity does not preclude supervisors from reflecting in the assessment and supervision of the conglomerate, the risks arising from such entities and their concomitant impact on the regulated entities within the conglomerate. These risks include at a minimum: (i) the direct or indirect participation, influence and/or other contractual obligations; (ii) interconnectedness; (iii) risk exposure, risk concentration, risk transfer and risk management; (iv) intra-group transactions and exposures; (v) strategic risk; and (vi) reputation risk.

Key terms

50.4

The following terms are used throughout this chapter and have the meaning given below:

  1. Board and senior management: refers to the oversight function and the management function in general and should be interpreted throughout this document in accordance with the applicable law within each jurisdiction.
  2. Company(ies) and corporate(s): include all types of legal entities and agreements (eg partnerships).
  3. Corporate governance: broadly describes the processes, policies and laws that govern how a company or group is directed, administered or controlled. It defines the set of relationships between a company’s management, its board, its shareholders, and other recognised stakeholders.2 Corporate governance also provides the structure through which the objectives of the company are set, and the means of attaining those objectives and monitoring performance are determined.
  4. Explanatory comments: are background details, descriptive in nature, which are intended to help authorities, supervisors, and assessors better understand the Principle and Implementation criteria to which they relate.
  5. Financial conglomerate: refers to any group of companies under common control or dominant influence, including any financial holding company, which conducts material financial activities in at least two of the regulated banking, securities, insurance sectors or pension funds. A group of entities with activities in only one of the regulated banking, securities, insurance sectors or pension funds, combined with commercial (ie non-financial) activities does not fall within the definition of a financial conglomerate.
  6. Group: means “financial conglomerate”; “group-wide” means “financial conglomerate-wide”.
  7. Group-wide supervision: is achieved by the group-level supervisor and the sectoral supervisors of the financial conglomerate acting in coordination. Group- wide supervision includes supervision of the constituent entities of the financial conglomerate (and also considers interactions and relationships of these entities with entities external to the financial conglomerate but belonging to the wider group to which the financial conglomerate belongs).
  8. Group-level supervisor: means the supervisor responsible for group-level supervision where “group-level supervision” comprises all areas of group-wide supervision not covered by sectoral supervision. It also includes coordination among the sectoral supervisors of a financial conglomerate. In many cases, the coordinator would be the supervisor that carries out consolidated supervision or which is responsible for the largest part of the financial conglomerate.
  9. Head or Head of the financial conglomerate (or group): unless otherwise specified means the entity which controls or exerts dominant influence over the financial conglomerate (the head of the financial conglomerate may be the ultimate parent, or may be the head of a financial conglomerate that is a subset of the wider group).
  10. Implementation criteria: are the steps which should be taken by authorities and supervisors to implement the Principles.
  11. Sectoral supervision: means either insurance, banking or securities supervision.
  12. Sectoral supervisor: means either an insurance, banking or securities supervisor.
  13. Significant owners: are owners whose holdings in aggregate are above specified thresholds or who exercise a material influence because of direct or indirect participation, influence or other contractual relationship.
  14. Supervisors: includes sectoral supervisors and other supervisors relevant to the individual, or collective, or coordinated oversight of the financial conglomerate. It generally includes the Group-level Supervisor (unless separate specific reference is made to distinguish the “Group-level Supervisor”).
  15. Ultimate parent: means the parent of the “wider group” (ie the top parent company).
  16. Unregulated entity(ies): means entities that are not directly prudentially regulated by sectoral supervisors or the Group-level Supervisor.
  17. Wider group: means the broader group to which the financial conglomerate belongs - eg in cases where the financial conglomerate is part of a larger diversified conglomerate with both financial and non-financial entities.
2

The legal and regulatory system in a country determines the formal responsibilities institutions have to shareholders and other relevant stakeholders. This document will use the phrase “recognised stakeholders” to reflect the fact that responsibilities in this regard vary across jurisdictions and sectors.

Principles for the supervision of financial conglomerates

50.5

This chapter is intended to provide national authorities, standard setters, and supervisors with a set of internationally agreed principles that support consistent and effective supervision of financial conglomerates, particularly those financial conglomerates active across borders. The Principles constitute a supervisory framework for financial conglomerates which is supplementary to, and does not replace, banking, insurance or securities supervisory frameworks. They aim to close regulatory gaps, eliminate supervisory “blind spots” and ensure effective supervision of risks arising from unregulated financial activities and entities. The framework does not provide guidance regarding who should provide supervisory oversight of financial conglomerates in a given jurisdiction, how supervisory powers should be derived, or which regulator, supervisor, or authority should be responsible for implementation or for monitoring compliance.

50.6

The Principles should be applied in a proportionate manner to complexity and scale of operations as well as the risks posed and at least be applied to large internationally active financial conglomerates on a group-wide basis. Jurisdictions should consider the application of the Principles to other financial groups which conduct activities in one of these regulated sectors while also conducting material activities in any other financial sector, where these financial activities are not subject to comprehensive group-wide supervision under the sectoral frameworks. Supervisors should apply every effort to avoid creating undue burden through duplication and conflicts between the sectoral standards applied at the conglomerate level. It is acknowledged that a degree of national discretion may be required in approaches to conglomerate supervision using these Principles.

Comprehensive group-wide supervision

50.7

Principle 1 – The legal framework for the supervision of financial conglomerates should grant supervisors (including the Group-level Supervisor) the necessary powers and authority to enable comprehensive group-wide supervision.

Implementation criteria
50.8

The legal framework should grant the necessary power and authority to supervisors (including the Group-level Supervisor) to:

  1. identify or set the parameters for the identification of a financial conglomerate and the entities within the scope of supervision;
  2. require appropriate standards for significant owners of financial conglomerates;
  3. require that financial conglomerates have a sufficiently transparent group structure so as to not impede effective supervision, recovery or resolution;
  4. enable, in relation to the wider group, an assessment of the risks and support provided by the wider group to the financial conglomerate;
  5. access the board and senior management of the head of the financial conglomerate and of the other material and relevant entities related to the financial conglomerate, to assess the risks and support available to the financial conglomerate;
  6. enable a comprehensive range of supervisory tools to be used to ensure timely corrective actions including but not limited to, actions necessary to address deficiencies in corporate governance or risk management, capital and liquidity shortfalls, large exposure concentration limits, and inappropriate group transactions; and
  7. deal with a crisis situation including to address concerns or issues related to resolution and recovery.
Explanatory comments
50.9

To assess the risk profile of the financial conglomerate the legal framework should provide clear legal authority to collect information in respect of the head and the constituent entities of the financial conglomerate including records, prudential reports and statistical returns. It should also provide the authority to collect information that is necessary to assess the level of risk and support from the wider group. Assessing support could include an assessment of risks, intra-group transactions, risk concentrations, corporate governance and enterprise risk management.

50.10

The legal framework should provide sufficient enforcement powers to the supervisors to address any concerns or issues related to the financial conglomerate ranging from regulatory compliance to safety and soundness and resolution. Supervisors should have the legal authority to impose corrective action on or to limit activities of the regulated entities within the financial conglomerate, ideally including the head.

50.11

The legal framework should allow supervisors to adopt the measures necessary to manage and/or resolve a crisis to ensure that the financial conglomerate can be resolved safely and in an orderly manner.

Cooperation and information sharing

50.12

Principle 2 – The legal framework should grant the necessary power and authority to supervisors to enable efficient and effective cooperation, coordination and information sharing among supervisors to facilitate group-wide supervision.

Implementation criteria
50.13

The legal framework should provide the authority and power to supervisors to establish and maintain close cooperation, coordination arrangements and efficient communication with other supervisors of the financial conglomerate, including sectoral, cross sectoral, domestic and international.

50.14

The legal framework should ensure that supervisors are not impeded from sharing relevant information with their domestic and foreign counterparts where there are safeguards in place to require counterparts to keep such information strictly confidential and to limit onward disclosure.

Explanatory comments
50.15

Cross-border and cross-sector cooperation and information sharing is critical to effective group-wide supervision, since there may be more than one supervisor responsible for entities within a financial conglomerate, particularly if the conglomerate operates across borders. To efficiently supervise the financial conglomerate, it is necessary to have an established legal framework that provides for appropriate accountability. This enables supervisors to establish and maintain close cooperation and efficient communication and to have in place coordination arrangements with other relevant functional and/or sectoral supervisors.

50.16

The legal framework should provide the authority for supervisors to establish appropriate sharing of information, and to cooperate and coordinate as agreed to facilitate effective group supervision. Such cooperation or coordination may include participating in supervisory colleges, cooperating in on-site and off-site supervision and taking enforcement actions in relation to the financial conglomerate, along with sharing of information to determine the suitability of significant owners, board members, senior managers and key persons in control functions.

Independence and accountability
50.17

Principle 3 – The legal framework should provide supervisors with operational independence while ensuring accountability for the discharge of their duties.

Implementation criteria
50.18

The operational independence, accountability and governance structures of supervisors should be prescribed by law.

50.19

The responsibilities and objectives of supervisors should be clearly defined.

Explanatory comments
50.20

Financial conglomerates are likely to be large, influential and in the public eye. To effectively supervise financial conglomerates, supervisors require operational independence from inappropriate influence. Supervisors should also be subject to clear and public objectives and accountable for the discharge of their duties.

50.21

There should be no interference with the operational independence of supervisors or their ability to obtain and deploy the resources needed to carry out their mandates. The head of a supervisor should be removed from office during his/her term only for reasons specified in a clear, publicly disclosed, legal framework. The legal framework should ensure supervisors are protected from liability for acts taken in good faith, that the supervisors are independently governed (eg an independent board), have adequate and stable funding, and have the ability to create binding rules.

Resources
50.22

Principle 4 – Supervisors of financial conglomerates should be adequately resourced in a manner that does not undermine their independence.

Implementation criteria
50.23

Supervisors should have adequate financial resources to acquire and maintain levels of human, technical, knowledge and informational resources that enable them to carry out effective and comprehensive oversight of financial conglomerates, including identifying and understanding the risks borne by a financial conglomerate.

50.24

Supervisors should be financed in a manner which permits them to conduct effective supervision of financial conglomerates and which does not undermine their independence or their ability to carry out their duties.

Explanatory comments
50.25

Effective and comprehensive oversight of financial conglomerates requires sufficient resources for supervisors to carry out group-wide risk assessments and monitoring that may include more than one sector and may involve coordination and communication with other supervisors of the group.

50.26

Assessing the sufficiency of resources requires consideration of various factors including whether staffing numbers and skills are commensurate with the number, size and complexity of institutions supervised and whether the budget allows for sufficient resources to conduct supervision and to equip its staff with the tools needed to adequately supervise financial conglomerates.

Group-level supervisor
50.27

Principle 5 – Supervisors should ensure there is a clear process in place for coordinating various roles and responsibilities. It should clearly delineate responsibility for ensuring effective and comprehensive group-level supervision, including a coordination process to identify a group-level supervisor.

Implementation Criteria
50.28

There should be a clear and agreed upon coordination process for identifying the Group-level Supervisor.

50.29

The process for identifying a Group-level Supervisor should take account of the powers and authorities available to the relevant supervisors.

50.30

The identified coordination process should result in a single Group-level Supervisor with responsibility for effective group-level supervision and for facilitating coordination between relevant supervisors to enable effective group-wide supervision.

Explanatory comments
50.31

The determination of a Group-level Supervisor should account for the powers and authorities available to the relevant supervisors. In many cases the Group- level Supervisor is likely to be the supervisor that has responsibility for supervision of the head of the financial conglomerate, carries out consolidated supervision or which is responsible for the largest part of the conglomerate.

50.32

The determination of separate responsibilities for a Group-level Supervisor should not create the perception that other supervisors’ responsibilities have shifted to the Group-level Supervisor. That is, group-level supervisory responsibility does not replace sectoral supervisory responsibility. Instead, effective group-level supervision of the financial conglomerate is required, in conjunction with and supplemental to, effective sectoral supervision, to enable effective group-wide supervision of the financial conglomerate.

Supervisory cooperation, coordination and information sharing
50.33

Principle 6 – Supervisors should establish a process to confirm the roles and responsibilities of each supervisor in supervising the financial conglomerate and to ensure efficient and effective information sharing, cooperation and coordination in the supervision of the financial conglomerate.

Implementation criteria
50.34

Supervisors should clarify the objectives, roles and responsibilities of each supervisor relevant to the financial conglomerate to improve the efficiency and effectiveness of the supervision.

50.35

Where possible, Supervisors should clarify arrangements for information flows and any other form of coordination in advance.

50.36

Supervisors should establish coordination arrangements that enable effective group-wide supervision, including, as appropriate, sharing information, participating in supervisory colleges, cooperating in on-site and off-site supervision and stress testing and taking enforcement actions.

50.37

Supervisors should establish appropriate coordination mechanisms to ensure they communicate possible cross-sectoral and cross-border exposures to each other.

50.38

Supervisors should develop, implement and maintain coordination arrangements for normal and stress situations.

50.39

Supervisors should be aware of and respect legal restrictions and onward sharing limitations and should have arrangements in place for protecting the confidentiality of information received from other supervisors.

50.40

Arrangements for resolving differences between supervisors should be developed, agreed to and implemented.

Explanatory comments
50.41

The Group-level Supervisor should take the lead in ensuring supervisory cooperation, coordination and information sharing. Clear distinction in the responsibilities of supervisors and effective coordination is necessary to minimise supervisory gaps and overlaps.

50.42

The process of determining the roles and responsibilities of supervisors in relation to a financial conglomerate should account for:

  1. the structure of the financial conglomerate;
  2. the characteristics of the regulated entities (eg size, sector) and other entities which form part of the financial conglomerate;
  3. the presence and dominance of sectors within the financial conglomerate;
  4. the location of entities and the location of the markets in which the entities operate; and
  5. the powers, authority, resources available to, and location of, each relevant supervisor.

There should be coordination of the regulations and supervision applying to financial conglomerates on a cross border and cross sector basis.

50.43

Supervisors should have well-established mechanisms of supervisory cooperation, coordination and sufficient, relevant, timely and reliable information sharing at cross-sector and cross-jurisdiction levels for both normal and stress situations. Arrangements for stress situations are likely to differ from those for normal situations for reasons of speed or importance. Supervisors should take appropriate steps to maintain confidentiality of information that is shared in relation to financial conglomerates under the information sharing, cooperation and coordination framework.

50.44

Supervisors should promote proactive communication and responses to material risk aggregations (particularly cross-sectoral ones), emerging issues and concerns in a timely manner. Well established and regular communication should alleviate issues such as the potential for differing views across supervisors as to what constitutes a material event or piece of information and for information to be understood in context. Well-established and regular communication should also enable each supervisor to discharge its duties to effectively supervise the financial conglomerate or the regulated entities within the financial conglomerate for which they have responsibility. Supervisory colleges and crisis management groups provide an effective mechanism for supervisory cooperation and coordination, but other (more frequent, less formal) mechanisms are also important.

50.45

Supervisors should communicate possible cross sectoral and cross border risk concentrations to each other to ensure that the conglomerate has considered such risks. For example, a geographical concentration could occur where a bank originates and holds mortgages in the same area that a sister insurer insures houses, or securities firms manage or own real estate. A catastrophic event such as a hurricane or earthquake might create cross-sectoral and interacting effects within a conglomerate. It is important that supervisors are attuned to such possible effects so as to be able to subsequently challenge management on whether such effects are being considered.

50.46

Regular reviews of arrangements for the sharing of information, and supervisory coordination, are necessary to ensure arrangements work in practice and are enhanced where possible.

50.47

Supervisors of different parts of a financial conglomerate should agree to a process for resolving differences between themselves under both normal and stress scenarios for the financial conglomerate. These differences may arise, for example, in relation to the undertaking of specific supervisory actions in relation to entities within the conglomerate or in the identification of the Group-level Supervisor. It is important that there are mechanisms to resolve such differences so that group-wide supervision of the financial conglomerate and the sectoral supervision of entities within the conglomerate are not unduly impeded.

Prudential standards and coverage
50.48

Principle 7 – Supervisors should establish, implement and maintain a comprehensive framework of risk-based minimum prudential standards for financial conglomerates. The framework should be updated as necessary.

Implementation criteria
50.49

Supervisors should ensure that prudential standards adequately address risks that are heightened for financial conglomerates, including double gearing, contagion risk, concentration risk, conflicts of interest and intra-group exposures.

50.50

Supervisors should ensure standards are clear in their application to various entities of the financial conglomerate.

50.51

Supervisors should require adequate public disclosure by the financial conglomerate in relation to its financial condition, governance and risk management in a manner that is easily accessible.

Explanatory comments
50.52

Financial conglomerates require a clear framework of minimum prudential standards within which to operate. Such a framework sets clear expectations for the financial conglomerate and should facilitate the strengthening of its practices in key areas.

50.53

Effective supervision of financial conglomerates also requires a strong framework of minimum prudential standards against which supervisors are able to appropriately assess the financial conglomerates.

50.54

The fundamental components of a prudential framework include requirements on governance, capital adequacy and liquidity and risk management. These components are equally relevant for financial conglomerates. Risks that are heightened for financial conglomerates include (but are not limited to) double gearing, contagion risk, concentration risk, conflicts of interest and intra-group transactions and exposures. These risks need to be adequately addressed in the prudential framework for financial conglomerates.

50.55

To facilitate compliance by and supervision of financial conglomerates, the supervisory framework should be clear as to which elements apply to the head of the financial conglomerate and which apply to other entities within the conglomerate. The framework and standards should supplement existing core principles and prudential requirements of sectoral supervisors that are applied to entities within the financial conglomerate.

50.56

Transparency through adequate disclosure of information related to the financial condition, governance and risk management of a financial conglomerate is important to support market discipline. Such disclosure should be made in a manner that is easily accessible and comprehensive and may include information in relation to the financial conglomerate’s consolidated financial condition and performance, risk exposures, risk management strategies and corporate governance policies and processes.

50.57

As industry and markets evolve and develop over time, regulatory and supervisory approaches should also evolve. Hence the prudential framework needs to be regularly reviewed to ensure that it remains effective and relevant. This review is particularly important in the context of financial conglomerates given their potential diversity and complexity and the likelihood that they will be operating across several jurisdictions and evolving over time.

Monitoring and supervision
50.58

Principle 8 – Supervisors should develop and maintain a sound understanding of the operations of financial conglomerates by undertaking a range of appropriate supervisory activities.

Implementation criteria
50.59

Supervisors, in particular the Group-level Supervisor, should form an assessment of the risks of the financial conglomerate on an integrated basis, including making a forward-looking assessment of the sources of risk to the financial conglomerate.

50.60

Supervisors should collect, review and analyse relevant information from the financial conglomerate and its constituent entities (including any unregulated entities).

50.61

Supervisors should review the consistency of the financial conglomerate’s own assessment of its risks at the sector levels as well as on an aggregated basis.

50.62

Supervisors should have sufficient interaction with the board and senior management of the head of the financial conglomerate, the ultimate parent and material and relevant entities within the financial conglomerate.

50.63

Supervisors should undertake on-site and off-site supervision of financial conglomerates and assess compliance with the prudential framework.

Explanatory comments
50.64

Supervisors should form a comprehensive view of the overall operations, group business strategy, financial position, legal and regulatory position, governance arrangements and risk exposure of the financial conglomerate. Supervisors should establish compliance with the prudential framework. Supervisors should also consider the broader risks to which the financial conglomerate is exposed from the environment in which it operates.

50.65

To form this understanding, supervisors need to access sufficient and timely information (and need to compel further information and greater timeliness when warranted) and conduct on-site and off-site assessments. On-site work is important for broadening and deepening supervisory understanding of the financial conglomerate, verifying the reliability of information provided and for assessing the effectiveness of internal control systems. Regular contact with the board and senior management of the head of the financial conglomerate, the board and senior management of the ultimate parent, and of material and relevant entities within the financial conglomerate ensures access to those who play a key role in driving the direction and protecting the soundness of the financial conglomerate. Regular communication with key persons within the financial conglomerate, such as risk management staff and internal audit, is also important.

50.66

A forward-looking assessment of the sources of risk to the financial conglomerate, including consideration of contagion risks, is important to enable risks to be identified and addressed as they emerge.

Supervisory tools and enforcement
50.67

Principle 9 – Supervisors should, when appropriate, utilise supervisory tools to compel timely corrective actions and/or enforce compliance of financial conglomerates with the prudential framework.

Implementation criteria
50.68

Supervisors should, when appropriate, impose sanctions on or require corrective actions to be taken by the financial conglomerate or its constituent entities, subject to appropriate due process. Sanctions and corrective actions may be qualitative or quantitative.

Explanatory comments
50.69

Having a legal framework of rules and standards that provides the capacity and sufficient authority for supervisors to require a range of timely corrective actions in response to both on-going and emergent situations is insufficient to ensure effective group-wide supervision. Supervisors should be able to demonstrate both an ability and willingness to take timely action when appropriate.

50.70

Sanctions or corrective actions should be used to address sources of risk or issues of non-compliance and may include, but are not limited to, restricting current or future activities, suspending dividends to shareholders of relevant entities within the financial conglomerate and other measures to prevent capital from falling below the required levels. The exercise of sanctions or imposition of corrective actions should be subject to appropriate due process, including mechanisms for appeal where necessary.

Corporate governance in financial conglomerates3

3

When assessing corporate governance across a financial conglomerate, supervisors should apply these principles in a manner that is appropriate to the relevant sectors and the supervisory objectives of those sectors.

50.71

Principle 10 – Supervisors should seek to ensure that the financial conglomerate establishes a comprehensive and consistent governance framework across the group that addresses the sound governance of the financial conglomerate, including unregulated entities, without prejudice to the governance of individual entities in the group.

Implementation criteria
50.72

Supervisors should require that the corporate governance framework of the financial conglomerate4 has minimum requirements for good governance5 of the entities of the financial conglomerate which allow for the prudential and legal obligations of its constituent entities to be effectively met. The ultimate responsibility for the sound and prudent management of a financial conglomerate rests with the board of the head of the financial conglomerate.

4

Financial conglomerates are often complex groups with multiple regulated and unregulated financial and other entities. Given this inherent complexity, corporate governance must carefully consider and balance the combination of interests of recognised stakeholders of the ultimate parent, and the regulated financial and other entities of the group. Ensuring that a common strategy supports the desired balance and that regulated entities are compliant with regulation on an individual and on an aggregate basis should be a goal of the governance system. This governance system is the fiduciary responsibility of the board of directors.

5

Good corporate governance should provide proper incentives for the board and management to pursue objectives that are in the interests of the company and its shareholders and should facilitate effective monitoring. The presence of an effective corporate governance system, within an individual company or group and across an economy as a whole, helps to provide a degree of confidence that is necessary for the proper functioning of a market economy.

50.73

Supervisors should require that the financial conglomerate emphasises a high degree of integrity in the conduct of its affairs.

50.74

Supervisors should seek to ensure that the corporate governance framework appropriately balances the diverging interests of constituent entities and the financial conglomerate as a whole.

50.75

Supervisors should require that the governance framework respects the interests of policy holders and depositors (where relevant) and should seek to ensure that it respects the interests of other recognised stakeholders of the financial conglomerate and the financial soundness of entities in the financial conglomerate.

50.76

Supervisors should require that the governance framework includes adequate policies and processes that enable potential intra-group conflicts of interest to be avoided, and actual conflicts of interest to be identified and managed.

Explanatory criteria
50.77

Where appropriate, the corporate governance framework should address:

  1. alignment to the structure of the financial conglomerate;
  2. financial soundness of the significant owners;
  3. suitability of board members, senior management and key persons in control functions, including their ability to make reasonable and impartial business judgments;
  4. fiduciary responsibilities of the boards of directors and senior management of the head company and material subsidiaries;
  5. management of conflicts of interest, in particular at the intra-group level and remuneration policies and practices within the financial conglomerate; and
  6. internal control and risk management systems and internal audit and compliance functions for the financial conglomerate.
50.78

The group’s corporate governance framework should include a strong risk management framework (refer to the Risk Management section), a robust internal control system, effective internal audit and compliance functions, and ensure that the group conducts its affairs with appropriate independence and a high degree of integrity.

50.79

Group-wide governance applies group-wide to all material activities and entities of the financial conglomerate, not only to the head of the financial conglomerate.

50.80

In the event the local corporate governance requirements applicable to any particular material entity in the financial conglomerate are below the group standards, the more stringent group corporate governance standards should apply, except where this would lead to a violation of local law.

50.81

Supervisors should require that the corporate governance framework of the financial conglomerate includes a code of ethical conduct.

50.82

Supervisors should require that the financial conglomerate have in place policies focused on identifying and managing potential intra-group conflicts of interest, including those that may result from intra-group transactions, charges, up streaming dividends and risk-shifting. The policies should be approved by the board of the head of the financial conglomerate and be effectively implemented throughout the group. The policies should recognise the long-term interest of the financial conglomerate as a whole, the long-term interest of the significant entities of the financial conglomerate, the stakeholders within the financial conglomerate, and all applicable laws and regulations.

Structure of the financial conglomerate

50.83

Principle 11 – Supervisors should seek to ensure that the financial conglomerate has a transparent organisational and managerial structure, which is consistent with its overall strategy and risk profile and is well understood by the board and senior management of the head company.

Implementation criteria
50.84

Supervisors should understand the financial conglomerate’s group structure and the impact of any proposed changes to this structure.

50.85

Supervisors should assess the ownership structure of the financial conglomerate, including the financial soundness and integrity of its significant owners.

50.86

Supervisors should seek to ensure that the structure of the financial conglomerate does not impede effective supervision. If necessary and appropriate, supervisors may seek restructuring to achieve this objective.

50.87

Supervisors should seek to ensure that the board and senior management of the head of the financial conglomerate are capable of describing and understanding the purpose, structure, strategy, material operations, and material risks of the financial conglomerate, including those of unregulated entities that are part of the financial conglomerate structure.

50.88

Supervisors should assess and monitor the financial conglomerate's process for approving and controlling structural changes, including the creation of new legal entities.

50.89

Where the financial conglomerate is part of a wider group, supervisors should require that the board and senior management of the head of the financial conglomerate have governance arrangements that enable material risks stemming from the wider group structure to be identified and appropriately assessed by relevant supervisors.

50.90

Supervisors should seek to ensure that there is a framework governing information flows within the financial conglomerate and between the financial conglomerate and entities of the wider group (eg reporting procedures).

Explanatory notes
50.91

A financial conglomerate may freely set its functional, hierarchical, business and/or regional organisation, provided all entities within the financial conglomerate comply with their relevant sectoral and legal frameworks.

50.92

Elements to consider when assessing the significant ownership structure of the financial conglomerate may include the identification of significant owners, including the ultimate beneficial owners, the transparency of their ownership structure, their financial information, and the sources of their initial capital and all other requirements of national authorities. At a minimum, the necessary qualities of significant owners relate to the integrity demonstrated in personal behaviour and business conduct, as well as to the ability to provide additional support when needed.

50.93

Supervisors should seek to ensure that a financial conglomerate has an organisational and managerial structure that promotes and enables prudent management, and if necessary, orderly resolution aligned with corresponding sectoral requirements. Reporting lines within the financial conglomerate should be clear and should facilitate information flows within the financial conglomerate, both bottom-up and top-down.

50.94

Supervisors should be satisfied that the board and senior management of the head of the financial conglomerate understand and influence the evolution of an appropriate group legal structure in alignment with the approved business strategy and risk profile of the financial conglomerate, and understand how the various elements of the structure relate to one another. Where a financial conglomerate creates many legal entities, their number and, particularly, the interconnections and transactions between them, may pose challenges for the design of effective corporate governance arrangements. This risk should be recognised and managed. This is particularly the case where the organisational and managerial structure of the financial conglomerate deviates from the legal entity structure of the financial conglomerate.

50.95

Supervisors should assess changes to the group structure and how these changes impact its soundness, especially where such changes cause the financial conglomerate to engage in activities and/or operate in jurisdictions that impede transparency or do not meet international standards stemming from sectoral regulation.

Suitability of board members, senior managers and key persons in control functions

50.96

Principle 12 – Supervisors should seek to ensure that the board members, senior managers and key persons in control functions in the various entities in a financial conglomerate possess integrity, competence, experience and qualifications to fulfil their role and exercise sound objective judgment.

Implementation criteria
50.97

Supervisors should be satisfied of the suitability of board members, senior managers and key persons in control functions.

50.98

Supervisors should require financial conglomerates to have satisfactory processes for periodically assessing suitability.

50.99

Supervisors should require that the members of the boards of the head of the financial conglomerate and of its significant subsidiaries act independently of parties and interests external to the wider group; and that the board of the head of the financial conglomerate include a number of members acting independently of the wider group (including owners, board members, executives, and staff of the wider group).

50.100

Supervisors should communicate with the supervisors of other regulated entities within the conglomerate when board members, senior management and key persons in control functions are deemed not to meet their suitability tests.

Explanatory comments
50.101

Board members, senior managers and key persons in control functions need to have appropriate skills, experience and knowledge, and act with care, honesty and integrity, in order to make reasonable and impartial business judgments and strengthen the protection afforded to recognised stakeholders. To this end, institutions need to prudently manage the risk that persons in positions of responsibility may not be suitable. Suitability criteria may vary depending on the degree of influence on or the responsibilities for the financial conglomerate.

50.102

Supervisors of regulated entities of the financial conglomerate are subject to statutory and other requirements in applying suitability tests to these entities in their jurisdiction. The organisational and managerial structure of financial conglomerates adds elements of complexity for supervisors seeking to ensure the suitability of persons. For instance, the management of regulated entities within the financial conglomerate can be extensively influenced by persons who are not directly responsible for such functions. A group-wide perspective regarding suitability of persons is intended to close any loopholes in this respect. Supervisors may rely on assessments made by other relevant supervisors in this area regarding suitability. Alternatively, they may decide on concerted supervisory actions regarding suitability if required.

50.103

To meet suitability requirements, board members, senior managers and key persons in control functions, both individually and collectively, should have and demonstrate the ability to perform the duties or to carry out the responsibilities required in their position. Competence can generally be judged from the level of professionalism (eg pertinent experience within financial industries or other businesses) and/or formal qualifications.

50.104

Serving as a board member or senior manager of a company (from the wider group) that competes or does business with the regulated entities in the financial conglomerate can compromise independent judgment and create conflicts of interest, as can cross-membership on boards. A board’s ability to exercise objective judgment independent of the views of executives and of inappropriate political or personal interests can be enhanced by recruiting members from a sufficiently broad population of candidates. The key characteristic of independence is the ability to exercise objective, independent judgment after fair consideration of all relevant information and views without undue influence from executives or from inappropriate external parties and interests and while considering the requirements of applicable law.

Responsibility of the board of the head of the financial conglomerate

50.105

Principle 13 – Supervisors should require that the board of the head of the financial conglomerate appropriately defines the strategy and risk appetite of the financial conglomerate and ensures this strategy is implemented and executed in the various entities, both regulated and unregulated.

Implementation criteria
50.106

Supervisors should require that the board of the head of the financial conglomerate has in place a framework for monitoring compliance with the strategy and risk appetite across the financial conglomerate.

50.107

Supervisors should require that the board of the head of the financial conglomerate regularly assesses the strategy and risk appetite of the financial conglomerate to ensure it remains appropriate as the conglomerate evolved.

50.108

Where the financial conglomerate is part of a wider group, supervisors should assess whether the head is managing its relationship with the wider group and ultimate parent in a manner that is consistent with the governance framework of the financial conglomerate.

50.109

Supervisors should require that a framework is in place which seeks to ensure resources are available across the financial conglomerate for constituent entities to meet both the group and their own entity’s governance standards.

Explanatory comments
50.110

Supervisors should assess whether the board of directors exercises adequate oversight over the management of the head of the financial conglomerate. This includes assessing the actions taken by the board of the head to define the strategy for the financial conglomerate and ensure the consistency of the operations of the various entities in the financial conglomerate with such strategy. To this end, the head company should set up an adequate corporate governance framework in line with the structure, business and risks of the financial conglomerate and its entities and applicable laws. This framework should ensure that the strategy is implemented and monitored throughout the financial conglomerate and reviewed on a regular basis and following material change including due to growth, increased complexity, geographic expansion, etc.

50.111

The head company should exercise adequate oversight of subsidiaries, both regulated and unregulated, while respecting independent legal and governance responsibilities. Supervisors should satisfy themselves that entities within a financial conglomerate adhere to the same group-wide corporate governance principles or at least apply policies that remain consistent with these principles. The board of a regulated subsidiary of a financial conglomerate will retain and set its own corporate governance responsibilities and practices in line with its own legal requirements or in proportion to its size or business. These should not, however, conflict with the broader financial conglomerate corporate governance framework. Appropriate governance arrangements will address arrangements such that legal or regulatory provisions or prudential rules of regulated subsidiaries will be known and considered by the head company.

50.112

Where the financial conglomerate is part of a wider group structure, the head of the financial conglomerate is responsible for managing the relationship with its wider group. This includes ensuring there are appropriate arrangements for capital and liquidity management, assessing any material risk impact that may come from decisions made at its ownership level, service level agreements, reporting lines and regular top-level consultations with related companies in the wider group and the ultimate parent.

50.113

For smaller institutions within a larger conglomerate, it may be unnecessary to duplicate systems and controls. Such smaller institutions can rely on the systems and controls of the head if they have assessed that this is suitable to address group risks.

50.114

Supervisors should be satisfied with the amount and quality of information they receive from the head company of the financial conglomerate on its strategy, risk appetite and corporate governance framework.

Remuneration in a financial conglomerate

50.115

Principle 14 – Supervisors should require that the financial conglomerate has and implements an appropriate remuneration policy that is consistent with its risk profile. The policy should account for the material risks that organisation is exposed to, including those from its employees’ activities.

Implementation criteria
50.116

Supervisors should require that an appropriate remuneration policy consistent with established international standards is in place and observed at all levels and across jurisdictions in the financial conglomerate. An appropriate policy aligns risk-takers’ variable remuneration with prudent risk taking, promotes sound and effective risk management, and takes into account any other appropriate factors. The overarching objective of the policy should be consistent across the group but can allow for reasonable differences based on the nature of the constituent entities/units and local legal requirements.

50.117

Supervisors should require that ultimate oversight of the remuneration policy rest with the financial conglomerate’s head company.

50.118

Supervisors should require that the remuneration of board members, senior managers and key persons in control functions be determined in a manner that does not incentivise them to disregard the obligations they owe to the financial conglomerate or any of its entities, nor to otherwise act in a manner contrary to any legal or regulatory obligations.

50.119

Supervisors should require that the risks associated with remuneration are reflected in the financial conglomerate’s broader risk management framework. For example, staff engaged in financial and risk control at the group-wide level should be compensated in a manner that is consistent with their control role and should be involved in designing incentive arrangements, and assessing whether such arrangements encourage imprudent risk-taking.

50.120

Supervisors should require that the variable remuneration received by risk management and control personnel is not based substantially on the financial performance of the business units that they review but rather on the achievement of the objectives of their functions (eg adherence to internal controls).

Explanatory comments
50.121

Remuneration is a key aspect of any governance framework and needs to be properly considered to mitigate the risks that may arise from poorly designed remuneration arrangements. The risks associated with remuneration should be reflected in the financial conglomerate’s broader risk management framework.

50.122

Remuneration may serve important objectives, including attracting skilled staff, promoting better organisation-wide and employee performance, promoting retention, providing retirement security and allowing personnel costs to vary with revenues. It is also clear, however, that ill-designed compensation arrangements can provide incentives to take risks that are not consistent with the long-term health of the organisation. Such risks and misaligned incentives are of particular supervisory interest.

50.123

Ultimately, a financial conglomerate’s remuneration policy should aim to ensure effective governance of remuneration, alignment of remuneration with prudent risk- taking, and engagement of recognised stakeholders.

50.124

Supervisors should ensure that the governance system identifies and closes loopholes that allow the circumvention of conglomerate, sectoral or entity-level remuneration requirements.

50.125

Board members, senior managers and key persons in control functions should be measured against performance criteria tied not only to the short-term, but also to the long-term interest of the financial conglomerate as a whole.

Capital management

50.126

Principle 15 – Supervisors should require that the financial conglomerates’ capital management policies and the processes used to devise and implement these policies, are prudent, robust and account for additional risks associated with unregulated activities and additional complexities related to cross-sectoral activities. Supervisors should require that the financial conglomerate:

  1. maintains adequate capital on a group-wide basis to act as a buffer against the risks associated with the group’s activities;
  2. develops capital management policies that are approved and regularly reviewed by the board, and that include a clearly and formally documented capital planning process that ensures compliance with capital requirements on a group-wide and regulated entity basis; and
  3. considers and assesses the group-wide risk profile when undertaking capital management.
Implementation criteria
50.127

Supervisors should require that the financial conglomerate proactively manage its capital through a rigorous, board-approved, comprehensive and well documented process to ensure it maintains adequate capital within the group and its constituent entities.

50.128

Supervisors should require that financial conglomerate's capital management policies include a process to arrive at board and management decisions regarding capital management (including dividend distributions, capital instrument issuances, redemptions and repurchases) and that such decisions reflect robust capital planning and incorporate outcomes of stress scenarios.

50.129

Supervisors should require that the financial conglomerate's capital management policies include a requirement for the board of directors of the head of the financial conglomerate to review and approve the capital management plan at least annually, or more frequently if conditions warrant.

50.130

Supervisors should require that there is an independent review process, eg an internal audit unit within the financial conglomerate to ensure the integrity of the overall capital management process of the financial conglomerate, considering requirements at individual entities within the financial conglomerate.

50.131

Supervisors should require that the capital planning process includes capital adequacy goals with respect to degree and type of risk exposure, accounting for the conglomerate’s strategic focus and business plan.

50.132

Supervisors should require that the capital planning process considers the group-wide risk profile and appetite, and the possible negative impacts to its capital position from the material entities and relevant business risks to which it is exposed.

50.133

Supervisors should require that the capital planning process identifies and measures all material risks potentially requiring capital. The process should consider both on- and off-balance sheet risks as well as the activities and exposures of any unregulated entities within the group. Risks should be considered not only in isolation but also in aggregate.

50.134

Supervisors should require that the capital planning process determines quantifiable internal capital targets, along with practicable plans for achieving and maintaining these targets under both normal and stressed conditions. This should include processes to alert management of potential breaches.

50.135

Supervisors should require that the capital planning process identifies the actions that management is expected to take when its capital position falls below, or is anticipated to fall below, it’s internal capital target.

50.136

Supervisors should require that the capital planning process accounts for the availability of capital across entities within the group. This should include the regulatory, legal and other impediments to the transfer of capital across entities, sectors and jurisdictions in which the financial conglomerate operates.

50.137

Supervisors should require that intra-group guarantees, potential future injections of capital, and future management actions not be included in setting an internal capital target.

50.138

Supervisors should require that the capital planning process account for the current and forecast business and macroeconomic environment. It should incorporate forward-looking stress testing that identifies possible events or changes in market conditions that could adversely impact the group’s capital position.

Capital assessment

50.139

Principle 16 – Supervisors should require that the capital adequacy assessments undertaken by the financial conglomerate consider group-wide risks, including those undertaken by unregulated entities within a financial conglomerate, and that these assessments soundly address third party participations and minority interests.

Implementation criteria
50.140

Supervisors should require that all entities, whether regulated or unregulated, are included in the capital assessment of the group. Unregulated entities should be brought into the group-wide assessment via capital proxy or through deduction.

50.141

When calculating capital requirements, supervisors should, where appropriate and considering sectoral requirements, impose specific additional capital requirements, including for material risk exposures and investments in particular entities.

50.142

Where risk has been transferred from regulated to unregulated entities in a group, supervisors of the regulated entities should look through to the overall quantum and quality of assets in the unregulated entity.

Explanatory comments
50.143

In undertaking its risk assessment, the financial conglomerate and its regulated entities should assess risks across the group. The risks should include those undertaken across the financial conglomerate, including by unregulated entities such as special purpose vehicles and other off-balance sheet entities, holding and intermediate holding companies.

50.144

Supervisors should have the power to impose specific capital requirements on the financial conglomerate for material risks in constituent entities when calculating group-wide capital requirements, particularly in situations where their assessment is that the total requirement for the conglomerate ought to be higher than the sum of that for individual component businesses. Such situations would include, for example, complexity of the group structure, which could lead to contagion risk across entities.

50.145

Principle 17 – Supervisors should require that capital adequacy assessment and measurement techniques consider double or multiple gearing.

Implementation criteria
50.146

Supervisors should require that situations of double or multiple use of capital (eg when a holding company provides regulatory capital to another group entity) are adequately addressed in the capital assessment of the group.

50.147

Supervisors should require participations that confer effective control to be consolidated in full.

50.148

Supervisors should require that the capital adequacy assessments of the group and its components, as appropriate, exclude intra-group holdings of regulatory capital if not performed on a fully consolidated basis.

50.149

Supervisors should be alert to ownership structures that pose prudential concerns (eg sister entities owning capital), and overly complex organisational structures that could obscure instances of double or multiple gearing within the financial conglomerate.

50.150

Supervisors should be aware that problems, similar to those posed by intra-group double or multiple gearing, can also occur when different conglomerates hold cross participations in each other or in each other’s dependants.

Explanatory comments
50.151

Double or multiple gearing occurs within groups that are not fully consolidated at every level and when one entity holds regulatory capital issued by another entity within the same group and the issuer is permitted to include the capital in its own balance sheet.

50.152

In general, where a group is subject to capital requirements on a fully consolidated basis and the subsidiaries are also subject to consolidated capital requirements, the conglomerate derives no regulatory capital benefit from double gearing and, accordingly, supervisory concerns are mitigated. The issue of double or multiple gearing of capital arises where the same capital is used simultaneously as a buffer against risk in two or more legal entities, including situations where this is done via unregulated intermediate holding companies that have participations in dependants or affiliates engaged in financial activities.

50.153

Principle 18 – Supervisors should require that capital adequacy assessment and measurement techniques address excessive leverage and situations where a parent issues debt and down-streams the proceeds in the form of equity to a subsidiary.

Implementation criteria
50.154

Supervisors should require that the assessment of capital adequacy of a financial conglomerate incorporate the effect of the capital structure.

50.155

Supervisors should assess the methods by which the down-streaming of proceeds from parents to subsidiaries occurs, and their potential to produce undetected excessive leverage.

50.156

Capital adequacy measurement techniques should consider the potential for undue pressure to service a parent’s debt (eg the obligation of a regulated subsidiary to pay dividends to its parent).

Explanatory comments
50.157

Excessive leverage can occur when a parent issues debt (or other instruments not acceptable as regulatory capital in the downstream entity) and down-streams or passes the proceeds to a dependant in the form of equity or other elements of regulatory capital. In this situation, the effective leverage of the dependant6 may be greater than its leverage calculated on a solo basis. While this type of leverage is not necessarily unsafe or unsound, excessive use can constitute a prudential risk. For example, if undue pressure is placed on the regulated entity to pay dividends to the parent company so the latter can service its debt. A similar problem can arise where a parent issues capital instruments of one quality and down-streams them as instruments of a higher quality.

6

Where an entity exerts control or dominant influence over a second entity, this second entity is a “dependant” of the first entity.

50.158

While such asymmetrical down-streaming poses significant prudential concerns where the group is not subject to consolidated capital requirements, it can give rise to excessive leverage at the subsidiary level even in groups subject to a consolidated capital requirement, and thus should be subject to significant supervisory monitoring.

50.159

For the head of a financial conglomerate, assessment of group- wide capital adequacy by supervisors will need to include the effect on the group of the capital structure. Supervisors will need to be able to obtain information about the head company to assess its ability to service all external debt.

50.160

Principle 19 – Supervisors should require that assessment and measurement techniques evaluate any limitations on intra-group transfers of capital, accounting for potential impediments to executing such transfers that could constrain their suitability for inclusion in the assessment of group capital.

Implementation criteria
50.161

In their group-wide assessment of participations, supervisors should determine whether there are existing or potential impediments to the effective transfer of capital within the group.

50.162

Supervisors should require that funds treated as available and included in the group- wide capital assessment are legitimately movable within the group should the need arise.

50.163

Supervisors should require that the regulatory capital in a dependant and the corresponding capital requirements are calculated according to the rules applicable to the financial sector and jurisdiction in question, except where the supervisor of the head company deems it necessary to use an alternative measure or proxy.

50.164

Before recognising any excess capital in a dependant on the balance sheet of the head of the financial conglomerate, supervisors should ensure that the excess capital comprises adequate capital elements.

50.165

Supervisors should assess the appropriateness of the distribution of capital resources within the group independent of the group’s ability to transfer capital across entities within the group.

Explanatory comments
50.166

A group-wide assessment of any participation needs to determine whether there are existing or potential impediments to the effective transfer of capital within the group. This may lead supervisors to judge that, although aggregate group-wide capital meets or exceeds capital requirements of the group, impediments or restrictions to intra-group transfers could result in capital shortfall at the group level. Such an assessment should consider restrictions (eg legal, tax, rights of other shareholders’ and policyholders’ interests, restrictions that may be imposed by solo regulation of dependants, foreign exchange, specific local requirements for branch operations) on the transferability of excess regulatory capital (whether by the transfer of assets or by other means) in such dependants.

Liquidity
50.167

Principle 20 – Supervisors should require that the head of the financial conglomerate adequately and consistently identify, measure, monitor and manage its liquidity risks and the liquidity risks of the financial conglomerate. Supervisors should require that liquidity be sufficient across the financial conglomerate to meet funding needs in normal times and periods of stress.

Implementation criteria
50.168

Supervisors should require that the head of the financial conglomerate develops and maintains liquidity management processes and funding programs that are consistent with the complexity, risk profile, and scope of operations of the financial conglomerate.

50.169

Supervisors should require that liquidity risk management processes and funding programs take into full account lending, investment, and other activities, and ensure that adequate liquidity is maintained at the head and each constituent entity within the financial conglomerate. Processes and programs should fully incorporate real and potential constraints, including legal and regulatory restrictions, on the transfer of funds among these entities and between these entities and the head.

50.170

Supervisors should require that liquidity risks are managed with effective governance and management oversight as appropriate; adequate policies, procedures, and limits on risk taking; and strong management information systems for measuring, monitoring, reporting, and controlling liquidity risks.

Explanatory comments
50.171

Where a financial conglomerate is part a wider group, supervisors should have timely access to information concerning the wider group’s liquidity position and risks to that liquidity position, to enable the evaluation of the adequacy of the liquidity position of the financial conglomerate in the context of its relationship to the wider group.

50.172

Conglomerates should develop and maintain liquidity management processes and funding programs that are consistent with their complexity, risk profile and scope of operations. Appropriate liquidity risk management is especially important since liquidity difficulties can easily spread to subsidiaries, particularly in cases of similarly named companies where customers may not always understand the legal distinctions between constituent entities.

50.173

Entities that directly access market sources of funding and/or manage specific funding programs should pay particular attention to:

  1. maintaining sufficient liquidity, cash flow, and capital strength to service debt obligations and cover fixed charges;
  2. assessing the potential that funding strategies could undermine public confidence in the liquidity or stability of constituent entities; and
  3. ensuring the adequacy of policies and practices addressing the stability of funding and integrity of the institution’s liquidity risk profile as evidenced by funding mismatches and the degree of dependence on potentially volatile sources of short-term funding.
50.174

Risks undertaken are expected to be managed with:

  1. effective governance and management oversight as appropriate;
  2. adequate policies, procedures, and limits on risk taking; and
  3. strong management information systems for measuring, monitoring, reporting, and controlling liquidity risks.
50.175

Supervisors should have adequate access to the information necessary to maintain an understanding and assessment of these functions.

Risk management framework
50.176

Principle 21 – Supervisors should require that an independent, comprehensive and effective risk management framework, accompanied by a robust system of internal controls, effective internal audit and compliance functions, is in place for the financial conglomerate.

Implementation criteria
50.177

Supervisors should ensure that the risk management framework is comprehensive, consistent across entities supervised in all sectors and covers the risk management function, risk management processes and governance, and systems and controls.

50.178

Supervisors should:

  1. require that the risk management function is independent from the business units and has a sufficient level of authority and adequately skilled resources to carry out its functions;
  2. require that the risk management function generally has a direct reporting line to the board and senior management of the financial conglomerate; and
  3. where they consider it appropriate, require that a separate risk management committee at the board of directors level is established by the financial conglomerate.
50.179

Supervisors should require that:

  1. the board of the head of the financial conglomerate has overall responsibility for the financial conglomerate’s group-wide risk management, internal control mechanism, internal audit and compliance functions to ensure that the group conducts its affairs with a high degree of integrity;
  2. the financial conglomerate has an established enterprise-wide risk management process for, among others, periodically reviewing the effectiveness of the group-wide risk management framework and for ensuring appropriate aggregation of risks; and
  3. the risk management process cover identification, measurement, monitoring and controlling of risk types (eg credit risk, operational risk, strategic risk, liquidity risk) and these be linked where appropriate to specific capital requirements.
50.180

Supervisors should require that:

  1. financial conglomerates have in place adequate, sound and effective risk management processes and internal control mechanisms at the level of the financial conglomerate, including sound administrative and accounting procedures.
  2. risk management processes and internal control mechanisms of a financial conglomerate are appropriately documented and, at a minimum, consider the:
    1. nature, scale and complexity of its business;
    2. diversity of its operations, including geographical reach ; volume, frequency and size of its transactions;
    3. degree of risk associated with each area of its operation;
    4. interconnectedness of the entities within the financial conglomerate (using intra-group transactions and exposures reporting as one measure); and
    5. sophistication and functionality of information and reporting systems.
Explanatory comments
50.181

Financial conglomerates, irrespective of their particular mix of business lines or financial sectors, are in the business of risk taking. Therefore, strong risk management is of paramount importance.

50.182

The comprehensive risk management framework and process should include board and senior management oversight.

50.183

In identifying, evaluating, monitoring, controlling and mitigating material risks (from regulated and unregulated activities), financial conglomerates should consider the prospect for these to change over time and prepare themselves accordingly.

50.184

The risk management processes and internal control mechanisms of a financial conglomerate should include clear arrangements for delegating authority and responsibility; segregation of the functions that involve committing the financial conglomerate’s funds and accounting for assets and liabilities; reconciliation of these processes; safeguarding of the financial conglomerate’s assets; and appropriate independent internal audit and compliance functions to test adherence to these controls as well as applicable laws and regulations.

Risk management culture
50.185

Principle 22 – Supervisors should require that the financial conglomerate have in place processes and procedures to engender an appropriate group-wide risk management culture.

Implementation criteria
50.186

Supervisors should require that financial conglomerates have in place processes and procedures for promoting an appropriate risk management culture including providing staff with risk management training, independence and appropriate incentives.

50.187

Supervisors should require that a financial conglomerate’s approach to engendering an appropriate risk management culture cover awareness of risks posed by unregulated entities and unregulated financial products.

50.188

Supervisors should require financial conglomerates to provide appropriate risk management training to staff, and in particular to board members, senior management, and key persons in control functions.

50.189

Supervisors should require financial conglomerates have in place whistle-blowing procedures that encourage staff members to come forward when they are aware of non-observance with established risk management and compliance procedures.

Explanatory comments
50.190

The standard for the risk management culture should be directed and led by the board and senior management of the financial conglomerate. It is important that senior management demonstrate an appropriate risk management culture that accounts for the entirety of the financial conglomerate’s business (regulated and unregulated, on and off-balance sheet). The culture should also invite credible challenge by willing and informed board members.

50.191

The governance structure as well as the risk management culture should support the requirement that the risk management function be independent, free from undue or inappropriate influence from the business line. The risk function should have sufficient stature within the organisation to effectively challenge the business line, and to maintain its independent review of the financial conglomerate’s broader risk management controls, processes and systems. Good risk culture attributes also include a strong history of rectifying audit and regulator issues and encouragement to escalate bad news promptly.

50.192

Senior managers should espouse prudent risk taking and respect the independent role of the risk management function.

50.193

Risk management considerations should be part of decision-making at all levels of a financial conglomerate, including at product design stage.

Risk tolerance levels and risk appetite policy
50.194

Principle 23 – Supervisors should require that the financial conglomerate establishes appropriate board approved, group-wide risk tolerance levels and a risk appetite policy.

Implementation criteria
50.195

Supervisors should require that key staff, senior management and the board of the head of the financial conglomerate be aware of and understand the financial conglomerate’s risk tolerance levels and risk appetite policy.

50.196

Supervisors should require that the financial conglomerate identify and measure against risk tolerance limits (and in line with its risk appetite policy) the risk exposure of the financial conglomerate on an on-going basis in order to identify potential risks as early as possible. This may include looking at risks by territory, by line of business, or by financial sector.

Explanatory comments
50.197

Financial conglomerates should establish risk tolerance levels and a risk appetite policy which set the tone for acceptable and unacceptable risk taking. These should be aligned with the financial conglomerate’s business strategy, risk profile and capital plan.

50.198

A financial conglomerate’s risk tolerance should be kept under periodic review to ensure that it remains relevant and takes account of the changing dynamics of the financial conglomerate. The financial conglomerate’s risk appetite policy is re- assessed regularly with respect to new business opportunities, changes in risk capacity and tolerance, and operating environment.

New business
50.199

Principle 24 – Supervisors should require that the financial conglomerate carries out a robust risk assessment when entering into new business areas.

Implementation criteria
50.200

Supervisors should, where they consider it appropriate, review the risk assessment carried out by a financial conglomerate in the context of entering into new business.

50.201

Supervisors should require that financial conglomerates not expand into new products unless they have put in place adequate processes, controls and systems (such as IT) to manage them.

50.202

Supervisors should make sure that a financial conglomerate carries out the ongoing risk assessment after entering into new business areas.

Explanatory comments
50.203

At the time of assessing whether or not to enter into a new business area or product line, it is imperative that financial conglomerates undertake risk assessments and analyses to identify potential risks inherent in the new activity.

50.204

They should seek to understand the potential interaction between the risks of the new activity and the existing risk profile of the financial conglomerate. This should include a consideration of whether the new activity could adversely affect the risk appetite or risk tolerance of the financial conglomerate.

Outsourcing
50.205

Principle 25 – Supervisors should require that the financial conglomerate carries out an assessment of the risks of outsourcing, including the appropriateness of outsourcing a particular function, when considering whether to outsource a function.

Implementation criteria
50.206

Supervisors should require that financial conglomerates have processes and criteria in place to review decisions to outsource a function in order to ensure that such outsourcing does not imply delegation of responsibility for that function.

50.207

Supervisors should be satisfied that the decision to outsource a function does not impede effective group-wide supervision of the financial conglomerate.

Explanatory comments
50.208

It is important that supervisors be satisfied that financial conglomerates have considered the risks involved and the appropriateness of outsourcing a particular function when they are considering whether to outsource a particular function. This includes considering the appropriateness of outsourcing to a particular provider and the cumulative risks of all outsourced functions. The supervisor should require the financial conglomerate to review the provider in advance to ensure it is in a position to provide the services, comply with the contractual terms, and observe all applicable laws and regulations.

50.209

Supervisors should periodically assess the outsourced function with regard to policy compliance, risk management measures and control procedures.

50.210

Outsourcing should never result in a delegation of responsibility for a given function. There may be certain functions within financial conglomerates which should not be outsourced under any circumstances, while there may be some that may only be outsourced if certain safeguards are put in place.

Stress and scenario testing
50.211

Principle 26 – Supervisors should require, where appropriate, that the financial conglomerate periodically carries out group-wide stress tests and scenario analyses for its major sources of risk.

Implementation criteria
50.212

Supervisors should require that stress tests are sufficiently severe, forward looking and flexible. They should cover an appropriate set of business activities and include a variety of different types of tests such as sensitivity analyses, scenario analyses and reverse stress testing.

50.213

Supervisors should require the financial conglomerate to document its stress and scenario tests, including reverse stress tests. Stress tests should be conducted under a robust governance framework that encompasses policies, procedures, and adequate documentation of procedures as well as validation of results.

50.214

Supervisors should require that the group-wide stress tests and scenario analyses conducted by the financial conglomerate are appropriate to the nature, scale and complexity of those major sources of risk and to the nature, scale and complexity of the financial conglomerate’s business.

50.215

Supervisors should require that group-wide stress tests and scenario analyses include a group-wide approach (which takes account of the interaction between different parts of the group and different risk types) and consider the results of sectoral stress tests.

50.216

Supervisors should require that, when carrying out reverse stress tests, a financial conglomerate identifies a range of adverse circumstances which would cause its business to fail and assess the likelihood of such events crystallising.

Explanatory comments
50.217

A financial conglomerate should have a good understanding of correlation between its respective sectors and the heterogeneity of such risks when conducting its stress tests. Stress tests should be robust and should consider sufficiently adverse circumstances. The group-wide stress test analysis should measure and evaluate the potential impact on individual entities.

50.218

Attention should be paid to covering all risks, including off-balance sheet items. For example, a financial conglomerate’s stress tests and scenario analyses should account for the risk that the financial conglomerate may have to bring the assets and liabilities of off-balance sheet entities back on to its consolidated balance sheet as a result of reputational contagion, notwithstanding the appearance of legal risk transfer.

50.219

Where reverse stress tests reveal a risk of business failure that is unacceptably high relative to the financial conglomerate’s risk appetite or risk tolerance, the financial conglomerate should evaluate and adopt, where appropriate, effective arrangements, processes, systems or other measures to prevent or mitigate that risk.

Risk aggregation
50.220

Principle 27 – Supervisors should require that the financial conglomerate aggregate the risks to which it is exposed in a prudent manner.7

7

Refer to Joint Forum report, Developments in Risk Aggregation Modelling, October 2010.

Implementation criteria
50.221

Supervisors should require that financial conglomerates not make overly ambitious diversification assumptions or imprudent correlation claims, particularly for capital adequacy and solvency purposes.

50.222

Supervisors should require financial conglomerates to have adequate resources and systems (including IT) for the purpose of aggregating risks.

Explanatory comments
50.223

Risk aggregation should include a clear understanding of assumptions and be robust enough to support a comprehensive assessment of risk.

50.224

While it is possible that the spread of activities within a financial conglomerate may create diversification effects and reduce correlation, it is also true that membership of a financial conglomerate group may create “group risks” in the form of financial contagion, reputational contagion, ratings contagion (where a subsidiary accesses capital through a parent’s credit rating and then suffers stress following the utilisation of the capital), double/multiple-gearing (use of same capital more than once within a group), excessive leveraging (upgrade in the quality of capital as it moves through a group), and regulatory arbitrage (it is important that risks are assessed at the financial conglomerate level as well as at the level of its constituent parts).

Risk concentrations and intra-group transactions and exposures
50.225

Principle 28 – Supervisors should require that the financial conglomerate has in place effective systems and processes to manage and report group-wide risk concentrations and intra-group transactions and exposures, including for the purposes of monitoring and controlling those concentrations.

Implementation criteria
50.226

Supervisors should require that the financial conglomerate has in place effective systems and processes to identify, assess and report significant intra-group transactions and exposures.

50.227

Supervisors should require the financial conglomerate to report significant risk concentrations and intra-group transactions and exposures at the level of the financial conglomerate on a regular basis.

50.228

Supervisors should consider setting quantitative limits and adequate reporting requirements.

Explanatory comments
50.229

Supervisors should ensure that financial conglomerates are managing their risk concentrations and intra-group transactions and exposures satisfactorily.

50.230

Supervisors should encourage adequate public disclosure of risk concentrations and intra-group transactions and exposures.

50.231

Supervisors should liaise closely with one another to ascertain each other’s concerns and coordinate as deemed appropriate any supervisory action relative to risk concentrations and intra-group transactions and exposures within the financial conglomerate.

50.232

Supervisors should deal effectively with material risk concentrations and intra-group transactions and exposures that are considered to have a detrimental effect on the regulated entities or the financial conglomerate as a whole.

Off-balance sheet activities
50.233

Principle 29 – Supervisors should require that off-balance sheet activities, including special purpose entities, are brought within the scope of group-wide supervision of the financial conglomerate, where appropriate.8

8

Refer to the Joint Forum, Report on Special Purpose Entities, September 2009.

Implementation criteria
50.234

Supervisors should require that there is a process for determining whether the nature of the relationship between the financial conglomerate and a special purpose entity (SPE) requires the SPE to be fully or proportionally consolidated into the financial conglomerate for regulatory purposes.

50.235

Supervisors should require that the financial conglomerate’s stress tests and scenario analyses consider the risk associated with off balance sheet activities.

50.236

Supervisors should require that the overall nature of the relationship between the financial conglomerate and the SPE is considered including the risk of contagion from the SPE. This assessment should go beyond traditional control and influence relationships.

Explanatory comments
50.237

A financial conglomerate’s risk management framework and processes should cover the full spectrum of risks to the financial conglomerate. This includes risks from regulated and unregulated entities, including SPEs and off-balance sheet activities.

50.238

The fact that a financial conglomerate does not own or control the SPE in the traditional sense should not mean that it should not be consolidated. Other channels of contagion should be considered, such as the provision of (actual or contingent) liquidity support, reputational risk, and whether the assets of the SPE previously belonged to the financial conglomerate or were third-party assets.

50.239

Financial conglomerates should assess all economic risks and business purposes of an SPE throughout the life of a transaction, distinguishing between risk transfer and risk transformation. Financial conglomerates should be particularly aware that, over time, the nature of these risks can change. Supervisors should require such assessment to be ongoing and that management has sufficient understanding of the risks.

50.240

Financial conglomerates should have the capability to aggregate, assess and report all their SPE exposure risks in conjunction with all other bank-wide risks.

50.241

Supervisors should regularly oversee and monitor the use of all SPE activity. Supervisors should assess the implications of the activities of SPEs for the financial conglomerate, to identify developments that can lead to systemic weakness and contagion or that can exacerbate pro-cyclicality.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in