This chapter describes the Core Principles, the preconditions for effective banking supervision, the assessment methodology and criteria for assessing compliance.
The Core Principles for Effective Banking Supervision (Core Principles) are the de facto minimum standard for sound prudential regulation and supervision of banks and banking systems. Originally issued by the Basel Committee on Banking Supervision (the Committee) in 1997, they are used by countries as a benchmark for assessing the quality of their supervisory systems and for identifying future work to achieve a baseline level of sound supervisory practices. The Core Principles are also used by the International Monetary Fund (IMF) and the World Bank, in the context of the Financial Sector Assessment Programme (FSAP), to assess the effectiveness of countries’ banking supervisory systems and practices.
In March 2011, the Core Principles Group1 was mandated by the Committee to review and update the Core Principles. The Committee’s mandate was to conduct the review taking into account significant developments in the global financial markets and regulatory landscape since October 2006 (when the Core Principles had last been revised), including post-crisis lessons2 for promoting sound supervisory systems. The intent was to ensure the continued relevance of the Core Principles for promoting effective banking supervision in all countries over time and changing environments.
| 1 | The Core Principles Group consisted of members from the Committee and the Basel Consultative Group, which comprises representatives from both Committee and non-Committee member countries and regional groups of banking supervisors, as well as the IMF, the World Bank and the Islamic Financial Services Board. |
| 2 | See, for example, the November 2010 Financial Stability Board report on Intensity and Effectiveness of Systemically Important Financial Institution Supervision; the January 2010 Joint Forum report on Review of the Differentiated Nature and Scope of Financial Regulation – Key Issues and Recommendations; and the October 2009 Senior Supervisors Group report on Risk Management Lessons from the Global Banking Crisis of 2008. |
In conducting the 2011 review, the Committee sought to achieve the right balance in raising the bar for sound supervision while retaining the Core Principles as a flexible, globally applicable standard. By reinforcing the proportionality concept, the revised Core Principles and their assessment criteria accommodate a diverse range of banking systems. The proportionate approach also allows assessments of compliance with the Core Principles that are commensurate with the risk profile and systemic importance of a broad spectrum of banks (from large internationally active banks to small, non-complex deposit-taking institutions).
Both the Core Principles and the associated Core Principles Methodology3 (assessment methodology) have served their purpose well in terms of helping countries to assess their supervisory systems and identify areas for improvement. While conscious efforts were made during the 2011 review to maintain continuity and comparability as far as possible, the Committee merged the Core Principles and the assessment methodology into a single comprehensive document. The revised set of twenty-nine Core Principles were also reorganised to foster their implementation through a more logical structure starting with supervisory powers, responsibilities and functions, and followed by supervisory expectations of banks, emphasising the importance of good corporate governance and risk management, as well as compliance with supervisory standards.
| 3 | The Core Principles Methodology was separately developed in 1999 and subsequently revised in 2006 to provide further details and guidance on the assessment criteria and the assessment of compliance with the Core Principles. |
Important enhancements were introduced into the individual Core Principles during the review, particularly in those areas that are necessary to strengthen supervisory practices and risk management. Various additional criteria were upgraded to essential criteria as a result, while new assessment criteria were warranted in other instances. Close attention was given to addressing many of the significant risk management weaknesses and other vulnerabilities highlighted in the last crisis. In addition, the review took account of several key trends and developments that emerged during the last few years of market turmoil: the need for greater intensity and resources to deal effectively with systemically important banks; the importance of applying a system-wide, macro perspective to the microprudential supervision of banks to assist in identifying, analysing and taking pre-emptive action to address systemic risk; and the increasing focus on effective crisis management, recovery and resolution measures in reducing both the probability and impact of a bank failure. The Committee sought to give appropriate emphasis to these emerging issues by embedding them into the Core Principles, as appropriate, and including specific references under each relevant Principle.
In addition, sound corporate governance underpins effective risk management and public confidence in individual banks and the banking system. Given fundamental deficiencies in banks’ corporate governance that were exposed in the last crisis, a new Core Principle on corporate governance was added in this review by bringing together existing corporate governance criteria in the assessment methodology and giving greater emphasis to sound corporate governance practices. Similarly, the Committee reiterated the key role of robust market discipline in fostering a safe and sound banking system by expanding an existing Core Principle into two new ones dedicated respectively to greater public disclosure and transparency, and enhanced financial reporting and external audit.
Previously, the grading of compliance with the Core Principles was based solely on the essential criteria. To provide incentives to jurisdictions, particularly those that are important financial centres, to lead the way in the adoption of the highest supervisory standards, the revised Core Principles allow countries the additional option of voluntarily choosing to be assessed and graded against the essential and additional criteria. In the same spirit of promoting full and robust implementation, the Committee retained the existing four-grade scale of assessing compliance with the Core Principles. This includes the current “materially non-compliant” grading that helps provide a strong signalling effect to relevant authorities on remedial measures needed for addressing supervisory and regulatory shortcomings in their countries.
The revised Core Principles continue to provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector. Given the importance of consistent and effective standards implementation, the Committee stands ready to encourage work at the national level to implement the revised Core Principles in conjunction with other supervisory bodies and interested parties.
The revised Core Principles strengthen the requirements for supervisors, the approaches to supervision and supervisors’ expectations of banks. This is achieved through a greater focus on effective risk-based supervision and the need for early intervention and timely supervisory actions. Supervisors should assess the risk profile of banks, in terms of the risks they run, the efficacy of their risk management and the risks they pose to the banking and financial systems. This risk-based process targets supervisory resources where they can be utilised to the best effect, focusing on outcomes as well as processes, moving beyond passive assessment of compliance with rules.
The Core Principles set out the powers that supervisors should have in order to address safety and soundness concerns. It is equally crucial that supervisors use these powers once weaknesses or deficiencies are identified. Adopting a forward-looking approach to supervision through early intervention can prevent an identified weakness from developing into a threat to safety and soundness. This is particularly true for highly complex and bank-specific issues (eg liquidity risk) where effective supervisory actions must be tailored to a bank’s individual circumstances.
In its efforts to strengthen, reinforce and refocus the Core Principles, the Committee has nonetheless remained mindful of their underlying purpose and use. The Committee’s intention is to ensure the continued relevance of the Core Principles in providing a benchmark for supervisory practices that will withstand the test of time and changing environments. For this reason, this revision of the Core Principles builds upon the preceding versions to ensure continuity and comparability as far as possible.
In recognition of the universal applicability of the Core Principles, the Committee conducted its review in close cooperation with members of the Basel Consultative Group which comprises representatives from both Committee and non-Committee member countries and regional groups of banking supervisors, as well as the IMF, the World Bank and the Islamic Financial Services Board. The Committee consulted the industry and public before finalising the text.
The first Core Principle sets out the promotion of safety and soundness of banks and the banking system as the primary objective for banking supervision. Jurisdictions may assign other responsibilities to the banking supervisor provided they do not conflict with this primary objective.4 It should not be an objective of banking supervision to prevent bank failures. However, supervision should aim to reduce the probability and impact of a bank failure, including by working with resolution authorities, so that when failure occurs, it is in an orderly manner.
| 4 | The banking supervisor might, for instance, in some jurisdictions be tasked with responsibilities for: (i) depositor protection; (ii) financial stability; (iii) consumer protection; or (iv) financial inclusion. |
To fulfil their purpose, the Core Principles must be capable of application to a wide range of jurisdictions whose banking sectors will inevitably include a broad spectrum of banks (from large internationally active banks to small, non-complex deposit-taking institutions). Banking systems may also offer a wide range of products or services and the Core Principles are aligned with the general aim of catering to different financial needs. To accommodate this breadth of application, a proportionate approach is adopted, both in terms of the expectations on supervisors for the discharge of their own functions and in terms of the standards that supervisors impose on banks. Consequently, the Core Principles acknowledge that supervisors typically use a risk-based approach in which more time and resources are devoted to larger, more complex or riskier banks. In the context of the standards imposed by supervisors on banks, the proportionality concept is reflected in those Principles focused on supervisors’ assessment of banks’ risk management, where the Principles prescribe a level of supervisory expectation commensurate with a bank’s risk profile5 and systemic importance.6
| 5 | In this document, “risk profile” refers to the nature and scale of the risk exposures undertaken by a bank. |
| 6 | In this document, “systemic importance” is determined by the size, interconnectedness, substitutability, global or cross-jurisdictional activity (if any), and complexity of the bank, as set out in SCO40, SCO50 and RBC40. |
Successive revisions to existing Committee standards and guidance, and any new standards and guidance will be designed to strengthen the regulatory regime. Supervisors are encouraged to move towards the adoption of updated and new international supervisory standards as they are issued.
In the aftermath of the crisis, much attention has been focused on systemically important banks (SIBs), and the regulations and supervisory powers needed to deal with them effectively. Consideration was given by the Committee during the 2011 review to including a new Core Principle to cover SIBs. However, it was concluded that SIBs, which require greater intensity of supervision and hence resources, represent one end of the supervisory spectrum of banks. Each Core Principle applies to the supervision of all banks. The expectations on, and of, supervisors will need to be of a higher order for SIBs, commensurate with the risk profile and systemic importance of these banks. Therefore, it is unnecessary to include a specific stand-alone Core Principle for SIBs.
The crisis highlighted the interface between, and the complementary nature of, the macroprudential and microprudential elements of effective supervision. In their application of a risk-based supervisory approach, supervisors and other authorities need to assess risk in a broader context than that of the balance sheet of individual banks. For example, the prevailing macroeconomic environment, business trends, and the build-up and concentration of risk across the banking sector and, indeed, outside of it, inevitably impact the risk exposure of individual banks. Bank-specific supervision should therefore consider this macro perspective. Individual bank data, where appropriate, data at sector level and aggregate trend data collected by supervisors should be incorporated into the deliberations of authorities relevant for financial stability purposes (whether part of, or separate from, the supervisor) to assist in identification and analysis of systemic risk. The relevant authorities should have the ability to take pre-emptive action to address systemic risks. Supervisors should have access to relevant financial stability analyses or assessments conducted by other authorities that affect the banking system. This broad financial system perspective is integral to many of the Core Principles. For this reason, the Committee has not included a specific stand-alone Core Principle on macroprudential issues.
In supervising an individual bank which is part of a corporate group, it is essential that supervisors consider the bank and its risk profile from a number of perspectives: on a solo basis (but with both a micro and macro focus as discussed above); on a consolidated basis (in the sense of supervising the bank as a unit together with the other entities within the “banking group”7 ) and on a group-wide basis (taking into account the potential risks to the bank posed by other group entities outside of the banking group). Group entities (whether within or outside the banking group) may be a source of strength but they may also be a source of weakness capable of adversely affecting the financial condition, reputation and overall safety and soundness of the bank. The Core Principles include a specific Core Principle on the consolidated supervision of banking groups, but they also note the importance of parent companies and other non-banking group entities in any assessment of the risks run by a bank or banking group. This supervisory “risk perimeter” extends beyond accounting consolidation concepts. In the discharge of their functions, supervisors must observe a broad canvas of risk, whether arising from within an individual bank, from its associated entities or from the prevailing macro financial environment.
| 7 | In the BCP standard, “banking group” includes the holding company, the bank and its offices, subsidiaries, affiliates and joint ventures, both domestic and foreign. Risks from other entities in the wider group, for example non-bank (including non-financial) entities, may also be relevant. This group-wide approach to supervision goes beyond accounting consolidation. The scope of consolidation used as the basis for all other Basel requirements is set out in the SCO standard. |
Supervisors should also remain alert to the movement, or build-up, of financial activities outside the regulated banking sector (the development of “shadow banking” structures) and the potential risks this may create. Data or information on this should also be shared with any other authorities relevant for financial stability purposes.
Although it is not a supervisor’s role to prevent bank failures, supervisory oversight is designed to reduce both the probability and impact of such failures. Banks will, from time to time, run into difficulties, and to minimise the adverse impact both on the troubled bank and on the banking and financial sectors as a whole, effective crisis preparation and management, and orderly resolution frameworks and measures are required. Such measures may be viewed from two perspectives:
To reflect, and to emphasise, the importance of crisis management, recovery and resolution measures, certain Core Principles include specific reference to the maintenance and assessment of contingency arrangements.
Corporate governance shortcomings in banks, examples of which were observed during the crisis, can have potentially serious consequences both for the bank concerned and, in some cases, for the financial system as a whole. Similarly, the crisis served to underline the importance of disclosure and transparency in maintaining confidence in banks by allowing market participants to understand better a bank’s risk profile and thereby reduce market uncertainties about the bank’s financial strength.
The Core Principles establish a level of sound supervisory practice that can be used as a benchmark by supervisors to assess the quality of their supervisory systems. They are also used by the IMF and the World Bank, in the context of the FSAP, to assess the effectiveness of countries’ banking supervisory systems and practices.
The assessment methodology for the Core Principles includes both essential and additional assessment criteria for each Principle.
In the past, countries were graded only against the essential criteria, although they could volunteer to be assessed against the additional criteria too and benefit from assessors’ commentary on how supervisory practices could be enhanced. In future, countries undergoing assessments by the IMF and/or the World Bank can elect to be graded against the essential and additional criteria. It is anticipated that this will provide incentives to jurisdictions, particularly those that are important financial centres, to lead the way in the adoption of the highest supervisory standards. As with the essential criteria, any assessment against additional criteria should recognise the concept of proportionality as discussed above.
It is important to bear in mind that some tasks, such as a correct assessment of the macroeconomic environment and the detection of the build-up of dangerous trends, do not lend themselves to a rigid compliant/non-compliant structure. Although these tasks may be difficult to assess, supervisors should make assessments that are as accurate as possible given the information available at the time and take reasonable actions to address and mitigate such risks.
While the publication of the assessments of jurisdictions affords transparency, an assessment of one jurisdiction will not be directly comparable to that of another. First, assessments will have to reflect proportionality. Thus, a jurisdiction that is home to many SIBs will naturally have a higher hurdle to obtain a “Compliant” grading8 versus a jurisdiction which only has small, non-complex deposit-taking institutions. Second, with this version of the Core Principles, jurisdictions can elect to be graded against essential criteria only or against both essential criteria and additional criteria. Third, assessments will inevitably be country-specific and time-dependent to varying degrees. Therefore, the description provided for each Core Principle and the qualitative commentary accompanying the grading for each Core Principle should be reviewed in order to gain an understanding of a jurisdiction’s approach to the specific aspect under consideration and the need for any improvements. Seeking to compare countries by a simple reference to the number of “Compliant” versus “Non-Compliant” grades they receive is unlikely to be informative.
From a broader perspective, effective banking supervision is dependent on a number of external elements, or preconditions, which may not be within the direct jurisdiction of supervisors. Thus, in respect of grading, the assessment of preconditions will remain qualitative and distinct from the assessment (and grading) of compliance with the Core Principles.
Core Principle 29 dealing with the Abuse of Financial Services includes, among other things, supervision of banks’ anti-money laundering/combating the financing of terrorism (AML/CFT) controls. The Committee recognises that assessments against this Core Principle will inevitably, for some countries, involve a degree of duplication with the mutual evaluation process of the Financial Action Task Force (FATF). To address this, where an evaluation has recently been conducted by the FATF on a given country, FSAP assessors may rely on that evaluation and focus their own review on the actions taken by supervisors to address any shortcomings identified by the FATF. In the absence of any recent FATF evaluation, FSAP assessors will continue to assess countries’ supervision of banks’ AML/CFT controls.
The banking sector is only a part, albeit an important part, of a financial system. The Committee has sought to maintain consistency, where possible, between these Core Principles and the corresponding standards for securities and insurance, as well as those for AML and transparency. Differences will, however, inevitably remain as key risk areas and supervisory priorities differ from sector to sector. In implementing the Core Principles, supervisors should take into account the role of the banking sector in supporting and facilitating productive activities for the real economy.
The Core Principles are a framework of minimum standards for sound supervisory practices and are considered universally applicable.9 National authorities should apply the Core Principles in the supervision of banking organisations within their jurisdictions.10 The Committee issued the Core Principles as its contribution to strengthening the global financial system. Weaknesses in the banking system of a country, whether developing or developed, can threaten financial stability both within that country and internationally. The Committee believes that implementation of the Core Principles by all countries would be a significant step towards improving financial stability domestically and internationally, and provide a good basis for further development of effective supervisory systems. The vast majority of countries have endorsed the Core Principles and have implemented them.
| 9 | The Core Principles are conceived as a voluntary framework of minimum standards for sound supervisory practices; national authorities are free to put in place supplementary measures that they deem necessary to achieve effective supervision in their jurisdictions. |
| 10 | In countries where non-bank financial institutions provide deposit and lending services similar to those of banks, many of the Principles set out in this document would also be appropriate to such non-bank financial institutions. However, it is also acknowledged that some of these categories of institutions may be regulated differently from banks as long as they do not hold, collectively, a significant proportion of deposits in a financial system. |
The Core Principles define 29 principles that are needed for a supervisory system to be effective. Those principles are broadly categorised into two groups:
The 29 Core Principles are:
| 11 | In this standard, “banking group” includes the holding company, the bank and its offices, subsidiaries, affiliates and joint ventures, both domestic and foreign. Risks from other entities in the wider group, for example non-bank (including non-financial) entities, may also be relevant. This group-wide approach to supervision goes beyond accounting consolidation. |
| 12 | The activities of authorising banks, ongoing supervision and corrective actions are elaborated in subsequent principles. |
| 13 | Principle 3 is developed further in the Principles dealing with “Consolidated supervision” (12), “Home-host relationships” (13) and “Abuse of financial services” (29). |
| 14 | This standard refers to a governance structure composed of a board and senior management. The Committee recognises that there are significant differences in the legislative and regulatory frameworks across countries regarding these functions. Some countries use a two-tier board structure, where the supervisory function of the board is performed by a separate entity known as a supervisory board, which has no executive functions. Other countries, in contrast, use a one-tier board structure in which the board has a broader role. Owing to these differences, this document does not advocate a specific board structure. Consequently, in this document, the terms “board” and “senior management” are only used as a way to refer to the oversight function and the management function in general and should be interpreted throughout the document in accordance with the applicable law within each jurisdiction. |
| 15 | While the term “supervisor” is used throughout Principle 6, the Committee recognises that in a few countries these issues might be addressed by a separate licensing authority. |
| 16 | In the context of this Principle, “prudential reports and statistical returns” are distinct from and in addition to required accounting reports. The former are addressed by this Principle, and the latter are addressed in Principle 27. |
| 17 | Please refer to footnote 11. |
| 18 | Please refer to footnote 14. |
| 19 | For the purposes of assessing risk management by banks in the context of Principles 15 to 25, a bank’s risk management framework should take an integrated “bank-wide” perspective of the bank’s risk exposure, encompassing the bank’s individual business lines and business units. Where a bank is a member of a group of companies, the risk management framework should in addition cover the risk exposure across and within the “banking group” (see footnote 11) and should also take account of risks posed to the bank or members of the banking group through other entities in the wider group. |
| 20 | To some extent the precise requirements may vary from risk type to risk type (Principles 15 to 25) as reflected by the underlying reference documents. |
| 21 | It should be noted that while, in this and other Principles, the supervisor is required to determine that banks’ risk management policies and processes are being adhered to, the responsibility for ensuring adherence remains with a bank’s Board and senior management. |
| 22 | The Core Principles do not require a jurisdiction to comply with the capital adequacy regimes of Basel I, Basel II and/or Basel III. The Committee does not consider implementation of the Basel-based framework a prerequisite for compliance with the Core Principles, and compliance with one of the regimes is only required of those jurisdictions that have declared that they have voluntarily implemented it. |
| 23 | Principle 17 covers the evaluation of assets in greater detail; Principle 18 covers the management of problem assets. |
| 24 | Credit risk may result from the following: on-balance sheet and off-balance sheet exposures, including loans and advances, investments, inter-bank lending, derivative transactions, securities financing transactions and trading activities. |
| 25 | Counterparty credit risk includes credit risk exposures arising from derivative contracts and other financial instruments. |
| 26 | Reserves for the purposes of this Principle are “below the line” non-distributable appropriations of profit required by a supervisor in addition to provisions (“above the line” charges to profit). |
| 27 | Connected counterparties may include natural persons as well as a group of companies related financially or by common ownership, management or any combination thereof. |
| 28 | Related parties can include, among other things, the bank’s subsidiaries, affiliates, and any party (including their subsidiaries, affiliates and special purpose entities) that the bank exerts control over or that exerts control over the bank, the bank’s major shareholders, Board members, senior management and key staff, their direct and related interests, and their close family members as well as corresponding persons in affiliated companies. |
| 29 | Related party transactions include on-balance sheet and off-balance sheet credit exposures and claims, as well as, dealings such as service contracts, asset purchases and sales, construction contracts, lease agreements, derivative transactions, borrowings, and write-offs. The term transaction should be interpreted broadly to incorporate not only transactions that are entered into with related parties but also situations in which an unrelated party (with whom a bank has an existing exposure) subsequently becomes a related party. |
| 30 | Country risk is the risk of exposure to loss caused by events in a foreign country. The concept is broader than sovereign risk as all forms of lending or investment activity whether to/with individuals, corporates, banks or governments are covered. |
| 31 | Transfer risk is the risk that a borrower will not be able to convert local currency into foreign exchange and so will be unable to make debt service payments in foreign currency. The risk normally arises from exchange restrictions imposed by the government in the borrower’s country. (Reference document: IMF paper on External Debt Statistics – Guide for compilers and users, 2003.) |
| 32 | Wherever “interest rate risk” is used in this Principle the term refers to interest rate risk in the banking book. Interest rate risk in the trading book is covered under Principle 22. |
| 33 | The Committee has defined operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. The definition includes legal risk but excludes strategic and reputational risk. |
| 34 | In assessing independence, supervisors give due regard to the control systems designed to avoid conflicts of interest in the performance measurement of staff in the compliance, control and internal audit functions. For example, the remuneration of such staff should be determined independently of the business lines that they oversee. |
| 35 | The Committee is aware that, in some jurisdictions, other authorities, such as a financial intelligence unit, rather than a banking supervisor, may have primary responsibility for assessing compliance with laws and regulations regarding criminal activities in banks, such as fraud, money laundering and the financing of terrorism. Thus, in the context of this Principle, “the supervisor” might refer to such other authorities, in particular in Essential Criteria 7, 8 and 10. In such jurisdictions, the banking supervisor cooperates with such authorities to achieve adherence with the criteria mentioned in this Principle. |
The Core Principles are neutral with regard to different approaches to supervision, so long as the overriding goals are achieved. They are not designed to cover all the needs and circumstances of every banking system. Instead, specific country circumstances should be more appropriately considered in the context of the assessments and in the dialogue between assessors and country authorities.
A high degree of compliance with the Core Principles should foster overall financial system stability; however, this will not guarantee it, nor will it prevent the failure of banks. Banking supervision cannot, and should not, provide an assurance that banks will not fail. In a market economy, failures are part of risk-taking.
The Committee stands ready to encourage work at the national level to implement the Core Principles in conjunction with other supervisory bodies and interested parties. The Committee invites the international financial institutions and donor agencies to use the Core Principles in assisting individual countries to strengthen their supervisory arrangements. The Committee will continue to collaborate closely with the IMF and the World Bank in their monitoring of the implementation of the Committee’s prudential standards. The Committee also remains committed to further enhancing its interaction with supervisors from non-member countries.
An effective system of banking supervision needs to be able to effectively develop, implement, monitor and enforce supervisory policies under normal and stressed economic and financial conditions. Supervisors need to be able to respond to external conditions that can negatively affect banks or the banking system. There are a number of elements or preconditions that have a direct impact on the effectiveness of supervision in practice. These preconditions are mostly outside the direct or sole jurisdiction of banking supervisors. Where supervisors have concerns that the preconditions could impact the efficiency or effectiveness of regulation and supervision of banks, supervisors should make the government and relevant authorities aware of them and their actual or potential negative repercussions for supervisory objectives. Supervisors should work with the government and relevant authorities to address concerns that are outside the direct or sole jurisdiction of the supervisors. Supervisors should also, as part of their normal business, adopt measures to address the effects of such concerns on the efficiency or effectiveness of regulation and supervision of banks.
The preconditions include:
Sound macroeconomic policies (mainly fiscal and monetary policies) are the foundation of a stable financial system. Without sound policies, imbalances such as high government borrowing and spending, and an excessive shortage or supply of liquidity, may arise and affect the stability of the financial system. Further, certain government policies36 may specifically use banks and other financial intermediaries as instruments, which may inhibit effective supervision.
| 36 | Examples of such policies include accumulation of large quantities of government securities; reduced access to capital markets due to government controls or growing imbalances; degradation in asset quality after loose monetary policies; and government-directed lending or forbearance requirements as an economic policy response to deteriorating economic conditions. |
In view of the impact and interplay between the real economy and banks and the financial system, it is important that there exists a clear framework for macroprudential surveillance and financial stability policy formulation. Such a framework should set out the authorities or those responsible for identifying systemic and emerging risks in the financial system, monitoring and analysing market and other financial and economic factors that may lead to accumulation of systemic risks, formulating and implementing appropriate policies, and assessing how such policies may affect the banks and the financial system. It should also include mechanisms for effective cooperation and coordination among the relevant agencies.
A well developed public infrastructure needs to comprise the following elements, which, if not adequately provided, can contribute to the weakening of financial systems and markets, or frustrate their improvement:
Effective crisis management frameworks and resolution regimes help to minimise potential disruptions to financial stability arising from banks and financial institutions that are in distress or failing. A sound institutional framework for crisis management and resolution requires a clear mandate and an effective legal underpinning for each relevant authority (such as banking supervisors, national resolution authorities, finance ministries and central banks). The relevant authorities should have a broad range of powers and appropriate tools provided in law to resolve a financial institution that is no longer viable and where there is no reasonable prospect of it becoming viable. There should also be agreement among the relevant authorities on their individual and joint responsibilities for crisis management and resolution, and how they will discharge these responsibilities in a coordinated manner. This should include the ability to share confidential information among one another to facilitate planning in advance to handle recovery and resolution situations and to manage such events when they occur.
Deciding on the appropriate level of systemic protection is a policy question to be addressed by the relevant authorities, including the government and central bank, particularly where it may result in a commitment of public funds. Supervisors will have an important role to play because of their in-depth knowledge of the financial institutions involved. In handling systemic issues, it is necessary to balance several factors: addressing the risks to confidence in the financial system and contagion to otherwise sound institutions and, minimising the distortion to market signals and discipline. A key element of the framework for systemic protection is a system of deposit insurance. Provided such a system is transparent and carefully designed, it can contribute to public confidence in the system and thus limit contagion from banks in distress.
Effective market discipline depends, in part, on adequate flows of information to market participants, appropriate financial incentives to reward well managed institutions, and arrangements that ensure that investors are not insulated from the consequences of their decisions. Among the issues to be addressed are corporate governance and ensuring that accurate, meaningful, transparent and timely information is provided by borrowers to investors and creditors. Market signals can be distorted and discipline undermined if governments seek to influence or override commercial decisions, particularly lending decisions, to achieve public policy objectives. In these circumstances, it is important that, if governments or their related entities provide or guarantee the lending, such arrangements are disclosed and there is a formal process for compensating financial institutions when such loans cease to perform.
The Core Principles are mainly intended to help countries assess the quality of their systems and to provide input into their reform agenda. An assessment of the current situation of a country’s compliance with the Core Principles can be considered a useful tool in a country’s implementation of an effective system of banking supervision. In order to achieve objectivity and comparability of compliance with the Core Principles in the different country assessments,37 supervisors and assessors should refer to this assessment methodology, which does not eliminate the need for both parties to use their judgment in assessing compliance. Such an assessment should identify weaknesses in the existing system of supervision and regulation, and form a basis for remedial measures by government authorities and banking supervisors.
Although Committee members individually collaborate in assessment missions, these are conducted primarily by the IMF and the World Bank. The Committee has decided not to make assessments of its own to maintain the current division of labour between the Committee’s standard-setting and the international financial institutions’ assessment functions. However, the Committee, together with the Financial Stability Institute, is prepared to assist in other ways, for example by providing training.
The methodology can be used in multiple contexts:
| 38 | The Committee has issued guidelines for performing self-assessments: Conducting a supervisory self-assessment – practical application, Basel, April 2001. |
| 39 | The regular reports by the IMF and the World Bank on the lessons drawn from assessment experiences as part of FSAP exercises constitute a useful source of information which has been used as an input to improve the Principles. |
Whatever the context, the following factors are crucial:
The primary objective of an assessment should be the identification of the nature and extent of any weaknesses in the banking supervisory system and compliance with individual Core Principles. While the process of implementing the Core Principles starts with the assessment of compliance, assessment is a means to an end, not an objective in itself. Instead, the assessment will allow the supervisory authority (and in some instances the government) to initiate a strategy to improve the banking supervisory system, as necessary.
To assess compliance with a Principle, this methodology proposes a set of essential and additional assessment criteria for each Principle. By default, for the purposes of grading, the essential criteria are the only elements on which to gauge full compliance with a Core Principle. The additional criteria are suggested best practices that countries having advanced banks should aim for. Countries have the following three assessment options:
For assessments of the Core Principles by external parties,40 the following four-grade scale will be used. A “not applicable” grading can be used under certain circumstances as described in BCP01.52.
| 40 | While gradings of self-assessments may provide useful information to the authorities, these are not mandatory as the assessors will arrive at their own independent judgment. |
| 41 | For the purpose of grading, references to the term “essential criteria” in this paragraph would include additional criteria in the case of a country that has volunteered to be assessed and graded against the additional criteria. |
In addition, a Principle will be considered “not applicable” when, in the view of the assessor, the Principle does not apply given the structural, legal and institutional features of a country. In some instances countries have argued that in the case of certain embryonic or immaterial banking activities, which were not being supervised, an assessment of “not applicable” should have been given, rather than “non-compliant”. This is an issue for judgment by the assessor, although activities that are relatively insignificant at the time of assessment may later assume greater importance and authorities need to be aware of, and prepared for, such developments. The supervisory system should permit such activities to be monitored, even if no regulation or supervision is considered immediately necessary. “Not applicable” would be an appropriate assessment if the supervisors are aware of the phenomenon, and would be capable of taking action, but there is realistically no chance that the activities will grow sufficiently in volume to pose a risk.
Grading is not an exact science and the Core Principles can be met in different ways. The assessment criteria should not be seen as a checklist approach to compliance but as a qualitative exercise. Compliance with some criteria may be more critical for effectiveness of supervision, depending on the situation and circumstances in a given jurisdiction. Hence, the number of criteria complied with is not always an indication of the overall compliance rating for any given Principle. Emphasis should be placed on the commentary that should accompany each Principle grading, rather than on the grading itself. The primary goal of the exercise is not to apply a “grade” but rather to focus authorities on areas needing attention in order to set the stage for improvements and develop an action plan that prioritises the improvements needed to achieve full compliance with the Core Principles.
The assessment should also include the assessors’ opinion on how weaknesses in the preconditions for effective banking supervision, as discussed in BCP01.37 to BCP01.44, hinder effective supervision and how effectively supervisory measures mitigate these weaknesses. In particular, the assessment of compliance with individual Core Principles should mention clearly how it is likely to be primarily affected by preconditions that are considered to be weak. This opinion should be qualitative rather than providing any kind of graded assessment. To the extent shortcomings in preconditions are material to the effectiveness of supervision, they may affect the grading of the affected Core Principles.
The Core Principles are minimum standards to be applied by all banking supervisors. In implementing some of them, supervisors will need to take into account the risk profile and systemic importance of individual banks, particularly for those Core Principles where supervisors have to determine the adequacy of banks' risk management policies and processes.
While the Committee does not have a specific role in setting out detailed guidelines on the preparation and presentation of assessment reports, it believes there are a few considerations that assessors should take into account when conducting an assessment and preparing the assessment report. By way of example, BCP01.135 to BCP01.155 includes the format developed by the IMF and the World Bank for conducting their own assessments of the state of implementation of the Core Principles in individual countries. This section also includes structured guidance to the assessors on how to form an opinion on the preconditions for effective banking supervision, how weaknesses in these external elements may hinder supervision, as mentioned in BCP01.54 and how effective supervisory measures can mitigate shortcomings in the preconditions for effective banking supervision.
First, when conducting an assessment, the assessor must have free access to a range of information and interested parties. The required information may include not only published information, such as the relevant laws, regulations and policies, but also more sensitive information, such as any self-assessments, operational guidelines for supervisors and, where possible, supervisory assessments of individual banks. This information should be provided as long as it does not violate legal requirements for supervisors to hold such information confidential. Experience from assessments has shown that secrecy issues can often be solved through ad hoc arrangements between the assessor and the assessed authority. The assessor will need to meet with a range of individuals and organisations, including the banking supervisory authority or authorities, other domestic supervisory authorities, any relevant government ministries, bankers and bankers’ associations, auditors and other financial sector participants. Special note should be made of instances when any required information is not provided, as well as of what impact this might have on the accuracy of the assessment.
Second, the assessment of compliance with each Core Principle requires the evaluation of a chain of related requirements which, depending on the Principle, may encompass law, prudential regulation, supervisory guidelines, on-site examinations and off-site analysis, supervisory reporting and public disclosures, and evidence of enforcement or non-enforcement. Further, the assessment must ensure that the requirements are put into practice. This also requires assessing whether the supervisory authority has the necessary operational autonomy, skills, resources and commitment to implement the Core Principles.
Third, assessments should not focus solely on deficiencies but should also highlight specific achievements. This approach will provide a better picture of the effectiveness of banking supervision.
Fourth, there are certain jurisdictions where non-bank financial institutions that are not part of a supervised banking group engage in some bank-like activities; these institutions may make up a significant portion of the total financial system and may be largely unsupervised. Since the Core Principles deal specifically with banking supervision, they cannot be used for formal assessments of these non-bank financial institutions. However, the assessment report should, at a minimum, mention those activities where non-banks have an impact on the supervised banks and the potential problems that may arise as a result of non-bank activities.
Fifth, the development of cross-border banking leads to increased complications when conducting Core Principles assessments. Improved cooperation and information sharing between home and host country supervisors is of central importance, both in normal times and in crisis situations. The assessor must therefore determine that such cooperation and information sharing actually takes place to the extent needed, bearing in mind the size and complexity of the banking links between the two countries.
This section lists the assessment criteria for each of the 29 Core Principles under two separate headings: “essential criteria” and “additional criteria”. As mentioned in BCP01.50, essential criteria are those elements that should be present in order to demonstrate compliance with a Principle. Additional criteria may be particularly relevant to the supervision of more sophisticated banking organisations, and countries with such institutions should aim to achieve them. By and large, the compliance grading will be based on the essential criteria; the assessor will comment on, but not grade, compliance with the additional criteria unless the country undergoing the assessment has voluntarily chosen to be graded against the additional criteria too.
The individual assessment criteria are based on sound supervisory practices already established, even if they are not yet fully implemented. Where appropriate, the documents on which the criteria are founded have been cited.
Principle 1: an effective system of banking supervision has clear responsibilities and objectives for each authority involved in the supervision of banks and banking groups. A suitable legal framework for banking supervision is in place to provide each responsible authority with the necessary legal powers to authorise banks, conduct ongoing supervision, address compliance with laws and undertake timely corrective actions to address safety and soundness concerns.
Essential criteria:
| 42 | Such authority is called “the supervisor” throughout this chapter, except where the longer form “the banking supervisor” has been necessary for clarification. |
| 43 | In this chapter, “risk profile” refers to the nature and scale of the risk exposures undertaken by a bank. |
| 44 | In this chapter, “systemic importance” is determined by the size, interconnectedness, substitutability, global or cross-jurisdictional activity (if any), and complexity of the bank, as set out in SCO40. |
Principle 2: the supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy and adequate resources, and is accountable for the discharge of its duties and use of its resources. The legal framework for banking supervision includes legal protection for the supervisor.
Essential criteria:
Principle 3: laws, regulations or other arrangements provide a framework for cooperation and collaboration with relevant domestic authorities and foreign supervisors. These arrangements reflect the need to protect confidential information.
Essential criteria:
Principle 4: the permissible activities of institutions that are licensed and subject to supervision as banks are clearly defined and the use of the word “bank” in names is controlled.
Essential criteria:
| 46 | The Committee recognises the presence in some countries of non-banking financial institutions that take deposits but may be regulated differently from banks. These institutions should be subject to a form of regulation commensurate to the type and size of their business and, collectively, should not hold a significant proportion of deposits in the financial system. |
Principle 5: the licensing authority has the power to set criteria and reject applications for establishments that do not meet the criteria. At a minimum, the licensing process consists of an assessment of the ownership structure and governance (including the fitness and propriety of Board members and senior management) of the bank and its wider group, and its strategic and operating plan, internal controls, risk management and projected financial condition (including capital base). Where the proposed owner or parent organisation is a foreign bank, the prior consent of its home supervisor is obtained.
Essential criteria:
Principle 6: the supervisor has the power to review, reject and impose prudential conditions on any proposals to transfer significant ownership or controlling interests held directly or indirectly in existing banks to other parties.
Essential criteria:
Principle 7: the supervisor has the power to approve or reject (or recommend to the responsible authority the approval or rejection of), and impose prudential conditions on, major acquisitions or investments by a bank, against prescribed criteria, including the establishment of cross-border operations, and to determine that corporate affiliations or structures do not expose the bank to undue risks or hinder effective supervision.
Essential criteria:
| 50 | In the case of major acquisitions, this determination may take into account whether the acquisition or investment creates obstacles to the orderly resolution of the bank. |
Additional criterion:
The supervisor reviews major acquisitions or investments by other entities in the banking group to determine that these do not expose the bank to any undue risks or hinder effective supervision. The supervisor also determines, where appropriate, that these new acquisitions and investments will not hinder effective implementation of corrective measures in the future.51 Where necessary, the supervisor is able to effectively address the risks to the bank arising from such acquisitions or investments.
Principle 8: an effective system of banking supervision requires the supervisor to develop and maintain a forward-looking assessment of the risk profile of individual banks and banking groups, proportionate to their systemic importance; identify, assess and address risks emanating from banks and the banking system as a whole; have a framework in place for early intervention; and have plans in place, in partnership with other relevant authorities, to take action to resolve banks in an orderly manner if they become non-viable.
Essential criteria:
Principle 9: the supervisor uses an appropriate range of techniques and tools to implement the supervisory approach and deploys supervisory resources on a proportionate basis, taking into account the risk profile and systemic importance of banks.
Essential criteria:
| 52 | On-site work is used as a tool to provide independent verification that adequate policies, procedures and controls exist at banks, determine that information reported by banks is reliable, obtain additional information on the bank and its related companies needed for the assessment of the condition of the bank, monitor the bank’s follow-up on supervisory concerns, etc. |
| 53 | Off-site work is used as a tool to regularly review and analyse the financial condition of banks, follow up on matters requiring further attention, identify and evaluate developing risks and help identify the priorities, scope of further off-site and on-site work, etc. |
| 54 | Please refer to Principle 10 BCP01.33(10). |
Additional criterion:
The supervisor has a framework for periodic independent review, for example by an internal audit function or third party assessor, of the adequacy and effectiveness of the range of its available supervisory tools and their use, and makes changes as appropriate.
Principle 10: the supervisor collects, reviews and analyses prudential reports and statistical returns from banks on both a solo and a consolidated basis, and independently verifies these reports through either on-site examinations or use of external experts.
Essential criteria:
| 55 | Please refer to Principle 2 BCP01.33(2). |
| 56 | Please refer to Principle 1, Essential Criterion 5 BCP01.65. |
| 57 | May be external auditors or other qualified external parties, commissioned with an appropriate mandate, and subject to appropriate confidentiality restrictions. |
| 58 | May be external auditors or other qualified external parties, commissioned with an appropriate mandate, and subject to appropriate confidentiality restrictions. External experts may conduct reviews used by the supervisor, yet it is ultimately the supervisor that must be satisfied with the results of the reviews conducted by such external experts. |
Principle 11: the supervisor acts at an early stage to address unsafe and unsound practices or activities that could pose risks to banks or to the banking system. The supervisor has at its disposal an adequate range of supervisory tools to bring about timely corrective actions. This includes the ability to revoke the banking licence or to recommend its revocation.
Essential criteria:
Additional criteria:
Principle 12: an essential element of banking supervision is that the supervisor supervises the banking group on a consolidated basis, adequately monitoring and, as appropriate, applying prudential standards to all aspects of the business conducted by the banking group worldwide.
Essential criteria:
Additional criterion:
For countries which allow corporate ownership of banks, the supervisor has the power to establish and enforce fit and proper standards for owners and senior management of parent companies.
Principle 13: home and host supervisors of cross-border banking groups share information and cooperate for effective supervision of the group and group entities, and effective handling of crisis situations. Supervisors require the local operations of foreign banks to be conducted to the same standards as those required of domestic banks.
Essential criteria:
| 61 | See Principle 3 of the Basel’s Committee’s Principles for effective supervisory colleges for further information on the extent of information sharing expected. |
Principle 14: the supervisor determines that banks and banking groups have robust corporate governance policies and processes covering, for example, strategic direction, group and organisational structure, control environment, responsibilities of the banks’ Boards and senior management, and compensation. These policies and processes are commensurate with the risk profile and systemic importance of the bank.
Essential criteria:
| 62 | The Organisation of Economic Cooperation and Development (OECD) glossary of corporate governance-related terms in “Experiences from the Regional Corporate Governance Roundtables”, 2003, www.oecd.org/dataoecd/19/26/23742340.pdf defines “duty of care” as “The duty of a board member to act on an informed and prudent basis in decisions with respect to the company. Often interpreted as requiring the board member to approach the affairs of the company in the same way that a ’prudent man’ would approach their own affairs. Liability under the duty of care is frequently mitigated by the business judgement rule.” The OECD defines “duty of loyalty” as “The duty of the board member to act in the interest of the company and shareholders. The duty of loyalty should prevent individual board members from acting in their own interest, or the interest of another individual or group, at the expense of the company and all shareholders.” |
| 63 | “Risk appetite” reflects the level of aggregate risk that the bank’s Board is willing to assume and manage in the pursuit of the bank’s business objectives. Risk appetite may include both quantitative and qualitative elements, as appropriate, and encompass a range of measures. For the purposes of this document, the terms “risk appetite” and “risk tolerance” are treated synonymously. |
Additional criterion:
Laws, regulations or the supervisor require banks to notify the supervisor as soon as they become aware of any material and bona fide information that may negatively affect the fitness and propriety of a bank’s Board member or a member of the senior management.
Principle 15: the supervisor determines that banks have a comprehensive risk management process (including effective Board and senior management oversight) to identify, measure, evaluate, monitor, report and control or mitigate all material risks on a timely basis and to assess the adequacy of their capital and liquidity in relation to their risk profile and market and macroeconomic conditions. This extends to development and review of contingency arrangements (including robust and credible recovery plans where warranted) that take into account the specific circumstances of the bank. The risk management process is commensurate with the risk profile and systemic importance of the bank.
Essential criteria:
| 64 | New products include those developed by the bank or by a third party and purchased or distributed by the bank. |
Additional criterion:
The supervisor requires banks to have appropriate policies and processes for assessing other material risks not directly addressed in the subsequent Principles, such as reputational and strategic risks.
Principle 16: the supervisor sets prudent and appropriate capital adequacy requirements for banks that reflect the risks undertaken by, and presented by, a bank in the context of the markets and macroeconomic conditions in which it operates. The supervisor defines the components of capital, bearing in mind their ability to absorb losses. At least for internationally active banks, capital requirements are not less than the applicable Basel standards.
Essential criteria:
| 65 | The Basel Capital Accord was designed to apply to internationally active banks, which must calculate and apply capital adequacy ratios on a consolidated basis, including subsidiaries undertaking banking and financial business. Jurisdictions adopting the Basel II and Basel III capital adequacy frameworks would apply such ratios on a fully consolidated basis to all internationally active banks and their holding companies; in addition, supervisors must test that banks are adequately capitalised on a stand-alone basis. |
| 66 | Reference documents: Enhancements to the Basel II framework, July 2009 and: International convergence of capital measurement and capital standards: a revised framework, comprehensive version, June 2006. |
| 67 | In assessing the adequacy of a bank’s capital levels in light of its risk profile, the supervisor critically focuses, among other things, on (a) the potential loss absorbency of the instruments included in the bank’s capital base, (b) the appropriateness of risk weights as a proxy for the risk profile of its exposures, (c) the adequacy of provisions and reserves to cover loss expected on its exposures and (d) the quality of its risk management and controls. Consequently, capital requirements may vary from bank to bank to ensure that each bank is operating with the appropriate level of capital to support the risks it is running and the risks it poses. |
| 68 | “Stress testing” comprises a range of activities from simple sensitivity analysis to more complex scenario analyses and reverse stress testing. |
Additional criteria:
Principle 17: the supervisor determines that banks have an adequate credit risk management process that takes into account their risk appetite, risk profile and market and macroeconomic conditions. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate credit risk (including counterparty credit risk) on a timely basis. The full credit lifecycle is covered including credit underwriting, credit evaluation, and the ongoing management of the bank’s loan and investment portfolios.
Essential criteria:
| 70 | “Assuming” includes the assumption of all types of risk that give rise to credit risk, including credit risk or counterparty risk associated with various financial instruments. |
Principle 18: the supervisor determines that banks have adequate policies and processes for the early identification and management of problem assets, and the maintenance of adequate provisions and reserves.
Essential criteria:
| 71 | It is recognised that there are two different types of off-balance-sheet exposures: those that can be unilaterally cancelled by the bank (based on contractual arrangements and therefore may not be subject to provisioning) and those that cannot be unilaterally cancelled. |
Principle 19: the supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate concentrations of risk on a timely basis. Supervisors set prudential limits to restrict bank exposures to single counterparties or groups of connected counterparties.
Essential criteria:
| 72 | This includes credit concentrations through exposure to: single counterparties and groups of connected counterparties both direct and indirect (such as through exposure to collateral or to credit protection provided by a single counterparty), counterparties in the same industry, economic sector or geographic region and counterparties whose financial performance is dependent on the same activity or commodity as well as off-balance sheet exposures (including guarantees and other commitments) and also market and other risk concentrations where a bank is overly exposed to particular asset classes, products, collateral, or currencies. |
| 73 | The measure of credit exposure, in the context of large exposures to single counterparties and groups of connected counterparties, should reflect the maximum possible loss from their failure (ie it should encompass actual claims and potential claims as well as contingent liabilities). The risk weighting concept adopted in the Basel capital standards should not be used in measuring credit exposure for this purpose as the relevant risk weights were devised as a measure of credit risk on a basket basis and their use for measuring credit concentrations could significantly underestimate potential losses (see Measuring and controlling large credit exposures, January 1991). |
| 74 | Such requirements should, at least for internationally active banks, reflect the applicable Basel standards. These are described in LEX. |
Additional criterion:
In respect of credit exposure to single counterparties or groups of connected counterparties, banks are required to adhere to the limits below. Minor deviations from these limits may be acceptable, especially if explicitly temporary or related to very small or specialised banks.
Principle 20: in order to prevent abuses arising in transactions with related parties and to address the risk of conflict of interest, the supervisor requires banks to enter into any transactions with related parties on an arm’s length basis; to monitor these transactions; to take appropriate steps to control or mitigate the risks; and to write off exposures to related parties in accordance with standard policies and processes.
Essential criteria:
| 75 | An exception may be appropriate for beneficial terms that are part of overall remuneration packages (eg staff receiving credit at favourable rates). |
Principle 21: the supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate country risk and transfer risk in their international lending and investment activities on a timely basis.
Essential criteria:
Principle 22: the supervisor determines that banks have an adequate market risk management process that takes into account their risk appetite, risk profile, and market and macroeconomic conditions and the risk of a significant deterioration in market liquidity. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate market risks on a timely basis.
Essential criteria:
Principle 23: the supervisor determines that banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book on a timely basis. These systems take into account the bank’s risk appetite, risk profile and market and macroeconomic conditions.
Essential criteria:
Additional criteria:
Principle 24: the supervisor sets prudent and appropriate liquidity requirements (which can include either quantitative or qualitative requirements or both) for banks that reflect the liquidity needs of the bank. The supervisor determines that banks have a strategy that enables prudent management of liquidity risk and compliance with liquidity requirements. The strategy takes into account the bank’s risk profile as well as market and macroeconomic conditions and includes prudent policies and processes, consistent with the bank’s risk appetite, to identify, measure, evaluate, monitor, report and control or mitigate liquidity risk over an appropriate set of time horizons. At least for internationally active banks, liquidity requirements are not lower than the applicable Basel standards.
Essential criteria:
Additional criterion:
The supervisor determines that banks’ levels of encumbered balance-sheet assets are managed within acceptable limits to mitigate the risks posed by excessive levels of encumbrance in terms of the impact on the banks’ cost of funding and the implications for the sustainability of their long-term liquidity position. The supervisor requires banks to commit to adequate disclosure and to set appropriate limits to mitigate identified risks.
Principle 25: the supervisor determines that banks have an adequate operational risk management framework that takes into account their risk appetite, risk profile and market and macroeconomic conditions. This includes prudent policies and processes to identify, assess, evaluate, monitor, report and control or mitigate operational risk on a timely basis.
Essential criteria:
Additional criterion:
The supervisor regularly identifies any common points of exposure to operational risk or potential vulnerability (eg outsourcing of key operations by many banks to a common service provider or disruption to outsourcing providers of payment and settlement activities).
Principle 26: the supervisor determines that banks have adequate internal control frameworks to establish and maintain a properly controlled operating environment for the conduct of their business taking into account their risk profile. These include clear arrangements for delegating authority and responsibility; separation of the functions that involve committing the bank, paying away its funds, and accounting for its assets and liabilities; reconciliation of these processes; safeguarding the bank’s assets; and appropriate independent internal audit and compliance functions to test adherence to these controls as well as applicable laws and regulations.
Essential criteria:
| 76 | The term “compliance function” does not necessarily denote an organisational unit. Compliance staff may reside in operating business units or local subsidiaries and report up to operating business line management or local management, provided such staff also have a reporting line through to the head of compliance who should be independent from business lines. |
| 77 | The term “internal audit function” does not necessarily denote an organisational unit. Some countries allow small banks to implement a system of independent reviews, eg conducted by external experts, of key internal controls as an alternative. |
Principle 27: the supervisor determines that banks and banking groups maintain adequate and reliable records, prepare financial statements in accordance with accounting policies and practices that are widely accepted internationally and annually publish information that fairly reflects their financial condition and performance and bears an independent external auditor’s opinion. The supervisor also determines that banks and parent companies of banking groups have adequate governance and oversight of the external audit function.
Essential criteria:
| 78 | In this Essential Criterion, the supervisor is not necessarily limited to the banking supervisor. The responsibility for ensuring that financial statements are prepared in accordance with accounting policies and practices may also be vested with securities and market supervisors. |
Additional criterion:
The supervisor has the power to access external auditors’ working papers, where necessary.
Principle 28: the supervisor determines that banks and banking groups regularly publish information on a consolidated and, where appropriate, solo basis that is easily accessible and fairly reflects their financial condition, performance, risk exposures, risk management strategies and corporate governance policies and processes.
Essential criteria:
| 79 | In this Essential Criterion, the disclosure requirement may be found in applicable accounting, stock exchange listing, or other similar rules, instead of or in addition to directives issued by the supervisor. |
Additional criterion:
The disclosure requirements imposed promote disclosure of information that will help in understanding a bank’s risk exposures during a financial reporting period, for example on average exposures or turnover during the reporting period.
Principle 29: the supervisor determines that banks have adequate policies and processes, including strict customer due diligence rules to promote high ethical and professional standards in the financial sector and prevent the bank from being used, intentionally or unintentionally, for criminal activities.
Essential criteria:
| 80 | Consistent with international standards, banks are to report suspicious activities involving cases of potential money laundering and the financing of terrorism to the relevant national centre, established either as an independent governmental authority or within an existing authority or authorities that serves as a financial intelligence unit. |
| 81 | These could be external auditors or other qualified parties, commissioned with an appropriate mandate, and subject to appropriate confidentiality restrictions. |
This section presents guidance and a format, recommended by the IMF and the World Bank, for the presentation, and organisation of the Basel Core Principles (BCP) assessment reports by assessors in the context of the FSAP82 and stand-alone assessments. A self-assessment,83 conducted by the country’s authorities prior to IMF-World Bank assessments, is an essential element in the process, and should also follow this guidance and format.
| 82 | The guidance and format are also recommended for targeted or risk-based Reports on the Observance of Standards and Codes (ROSCs). Risk-Based or targeted assessments do not cover all core principles, but selected ones based on previous compliance assessments and on an evaluation of relevant risks and vulnerabilities in each country. See specific guidance on risk-based detailed assessment reports (DARs) and ROSCs: www.imf.org/external/pp/longres.aspx?id=4684 . |
| 83 | Such self-assessment should be made available to assessors well in advance – also considering the possible need for translation - accompanied by the supporting legislation and regulation. |
The BCP assessment report should be divided into seven parts, as listed below. The following paragraphs provide a brief description of each of the seven parts.
A general section provides background information on the assessment conducted, ie, the context in which the assessment is being conducted and the methodology used. This section should:
| 84 | Names are typically avoided, in order to protect individuals and encourage candour. |
| 85 | If the lack of information adversely impacts the quality and depth of the assessment of a particular Principle, assessors should refer to this in the comment section of the assessment template, and document the obstacles encountered, in particular where access to in-depth information is crucial in evaluating compliance. Such issues should be brought to the attention of the mission leaders and when necessary referred to headquarters staff for guidance. |
The second section should provide an overview of the supervisory environment for the financial sector, with a brief description of the institutional and legal setting, in particular the mandate and oversight roles of different supervisory authorities, existence of unregulated financial intermediaries, and the role of self-regulatory organisations. Furthermore, it should provide a general description of the structure of the financial markets and, in particular, the banking sector, mentioning the number of banks, total assets to gross domestic product, basic review of banking stability, capital adequacy, leverage, asset quality, liquidity, profitability and risk profile of the sector, and information on ownership, ie, foreign versus domestic, state-owned versus privately-owned, existence of conglomerates or unregulated affiliates, and similar information.
The third section should provide an overview of the preconditions for effective banking supervision, as described in this BCP standard. Experience has shown that insufficient implementation of the preconditions can seriously undermine the quality and effectiveness of banking supervision. Assessors should aim to give a factual review of preconditions so that the reader of the report is able to clearly understand the environment in which the banking system and the supervisory framework are operating. This will provide the perspective for a better appreciation of the assessment and grading of individual Principles. The review normally should take up no more than one or two paragraphs for each type of precondition, and should follow the headings indicated below.
BCP Assessors should not undertake to assess preconditions themselves, as this is beyond the scope of the individual standard assessments. Assessors should rely to the greatest extent possible on official IMF and World Bank documents and seek to ensure that the brief description and comments are consistent. When relevant, the assessors should attempt to include in their analysis the linkages between these factors and the effectiveness of supervision. As described in the next section, the assessment of compliance with individual Core Principles should mention clearly how it is likely to be primarily affected by preconditions that are considered to be weak. To the extent shortcomings in preconditions are material to the effectiveness of supervision, they may affect the grading of the affected Core Principles. Any suggestions aimed at addressing deficiencies in preconditions are not part of the recommendations of the assessment but can be made into general FSAP recommendations within the scope of the FSAP exercise.
The fourth section contains a detailed principle-by-principle assessment, providing a “description” of the system with regard to each criterion within a principle, a grading or “assessment”, and “comments”. The template for the detailed assessment is structured as follows.
| Principle (x) (repeating verbatim the text of the Principle) | |
| Essential criteria | |
| Description and findings regarding EC1 |
|
| Description and findings regarding EC2 |
|
| Description and findings regarding ECn |
|
| Additional criteria (only if the authorities choose to be assessed and graded against these too) | |
| Description and findings regarding AC1 |
|
| Description and findings regarding ACn |
|
| Assessment of Principle (x) | Compliant / Largely compliant / Materially non-compliant / Non-compliant / Not applicable |
| Comments |
|
The “description and findings” section of the template should provide information on the practice as observed in the country being assessed. It should cite and summarise the main elements of the relevant laws and regulations. This should be done in such a way that the relevant law or regulation can be easily located, for instance by reference to URLs, official gazettes, and similar sources. Insofar as possible and relevant, the description should be structured as follows:
Evidence of implementation and/or enforcement is essential - without effective use of powers vested in the supervisor and implementation of rules and regulations, even a well designed supervisory system will not be effective. Examples of practical implementation should be provided by the authorities, reviewed by the assessors, and mentioned in the report.86
| 86 | For instance: how many times over the past years have the authorities applied corrective action? How frequently have banks been inspected on-site? How many licensing applications have been received, and how many have been accepted/turned down? Have asset quality reports been prepared by the inspectors, and how have the conclusions been communicated to senior bank and banking supervision management? |
The essential criteria set out minimum baseline requirements for sound supervisory practices and are of universal applicability to all countries. An assessment of a jurisdiction against the essential criteria must, however, recognise that its supervisory practices should be commensurate with the risk profile and systemic importance of the banks being supervised. In other words, the assessment must consider the context in which the supervisory practices are applied. As with the essential criteria, any assessment against additional criteria should also adopt the principle of proportionality. This principle should underpin assessment of all criteria even if it is not always explicitly referred to in the criteria. For example, a jurisdiction with many systemically important banks or banks that are part of complex mixed conglomerates will naturally have a higher hurdle to obtain a “Compliant” grading as compared to a jurisdiction which only has small and non-complex banks that are primarily engaged in deposit taking and extending loans.
The “comments” section of the template should be used to explain why a particular grading was given. In case of a less than “compliant” grading, this section should be used to highlight the materiality of the observed shortcomings and indicate which measures would be needed to achieve full compliance or a higher level of compliance. This should also be included in the table on “recommended actions” (see below). This reasoning could be structured as follows:
The “comments” should explain the cases where, despite the existence of laws, regulations and policies, weaknesses in implementation contributed to the Principle being graded less than “compliant”. Conversely, when a “compliant” grading was given, but observance was demonstrated through different mechanisms by the country, this should be explained. The “comments” section should also highlight when and why compliance of a particular criterion could not be adequately reviewed, such as when certain information was not provided, or when key individuals were unavailable to discuss important issues. Requests for information or meetings should be documented in the “comments” section, to clearly demonstrate the assessor’s attempts to adequately assess a principle.
Assessors may also include “comments” where they find particularly good practices or rules in some field, which may serve as examples and best practice to other countries. Planned initiatives aimed at amending existing or adopting new regulations and practices, but which are not yet in effect, can receive favourable mention in this section. Recent legislative, regulatory or supervisory initiatives for which implementation could not be verified should be mentioned in this section as well.
The assessment and accompanying grades should solely be based on the regulatory framework and supervisory practices in place at the time of the assessment, and should not reflect planned initiatives aimed at amending existing or adopting new regulations and practices. This would be applicable in the case where actions are in process that would result in a higher compliance rating, but have not yet been effected or implemented.
When linkages between particular principles are evident, or between preconditions and principles, this section should be used to caution the reader that, although the regulation and practices in principle (x) seem compliant, a “compliant” grading cannot be given because of material deficiencies in the implementation of principle (y) or precondition (z).87 While recognising that there could be common deficiencies which are both relevant and material enough to affect the rating of more than one principle, assessors should avoid double-counting as far as possible. If the deficiencies found in linked Principles or preconditions are not material enough to warrant a downgrade, this should still be brought out in this section of the template.
| 87 | For example, regulation and supervision on capital adequacy may seem compliant, but if material deficiencies are found in another principle, such as provisioning, that will mean capital may be overstated and ratios unreliable. |
Grading to a Principle should be given regardless of the level of development of a country. If certain criteria are not applicable given the size, nature of operations and complexity of a country’s banking system, grading for the Principle should be based on level of compliance with the applicable criteria only. This must be clearly explained in the relevant section of the report so that a future review can reconsider the grading if the situation changes. The same applies to a ‘not-applicable’ grading to a Principle.
The fifth section of the report comprises a compliance table, summarising the assessments, principle-by-principle. This table has two versions: the one that does not include explicit grading (Table 3) is to be used in Reports on the Observance of Standards and Codes (or ROSCs; see BCP01.155),88 the version with grading (Table 2) in the detailed assessment only. This table should convey a clear sense of the degree of compliance, providing a brief description of the main strengths and, especially, weaknesses with respect to each principle. The template is as follows:
| Summary compliance with the Basel Core Principles – Detailed Assessment Report | Table 2 | ||
| Core principle | Grade (column not used in ROSCs) | Comments | |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
|
|
| |
| Summary compliance with the Basel Core Principles – ROSC | Table 3 | |
| Core principle | Comments | |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
| 88 | The ROSC does not include the grading in the table because the grades cannot be fully understood without the description and detailed comments (which are available only in the DAR). |
The sixth section comprises a “Recommended Actions” table providing Principle-by-Principle recommendations for actions and measures to improve the regulatory and supervisory framework and practices. This section should list the suggested steps for improving compliance and overall effectiveness of the supervisory framework. Recommendations should be proposed on a prioritised basis in each case where deficiencies are identified. The recommended actions should be specific in nature. An explanation could also be provided as to how the recommended action would lead to improving the level of compliance and strengthening of the supervisory framework. The institutional responsibility for each suggested action should also be clearly indicated in order to prevent overlap or confusion. Recommendations can also be made with regard to deficiencies in compliance with the additional criteria and to principles which are fully compliant but where supervisory practice can still be improved. The table should indicate only those Principles for which specific recommendations are being made. The template for the recommended actions is as follows.
| Recommended actions to improve compliance with the Basel Core Principles and the effectiveness of regulatory and supervisory frameworks | |
| Reference principle | Recommended action |
| Principle (x) | Example: suggested introduction of regulation (a), supervisory practice (b) |
| Principle (y) | Example: suggested introduction of regulation (c), supervisory practice (d) |
The seventh section describes the authorities’ response to the assessment.89 The assessor should provide the supervisory authority or authorities being assessed with an opportunity to respond to the assessment findings, which would include providing the authorities with a full written draft of the assessment. Any differences of opinion on the assessment results should be clearly identified and included in the report. The assessment should allow for greater dialogue, and therefore the assessment team should have had a number of discussions with the supervisors during the assessment process so that the assessment should also reflect the comments, concerns and factual corrections of the supervisors. The authority or authorities should also be requested to prepare a concise written response to the findings (“right of reply”). The assessment should not, however, become the object of negotiations, and assessors and authorities should be willing “to agree to disagree”, provided the authorities’ views are represented fairly and accurately.
| 89 | If no such response is provided within a reasonable time frame, the assessors should note this explicitly and provide a brief summary of the authorities’ initial response provided during the discussion between the authorities and the assessors at the end of the assessment mission (“wrap-up meeting”). |
The presentation of assessment results in ROSCs is different from the presentation of the outcome of the "Detailed Assessment" described above. Section 4 of the detailed assessment is to be replaced with a section entitled “main findings”. This section should summarise the key findings of the detailed assessment, and the following main groupings may be useful as a guide: responsibilities, objectives, powers, independence, accountability, and cooperation (Principles 1-3); ownership, licensing and structure (Principles 4–7); methods of ongoing banking supervision (Principles 8–10); corrective and sanctioning powers of supervisors (Principle 11); and consolidated and cross-border banking supervision (Principles 12–13); corporate governance (Principles 14); prudential requirements, regulatory framework, accounting and disclosure (Principles 15–29).
This standard describes the scope of application of the Basel Framework.
This standard describes the criteria that bank capital instruments must meet to be eligible to satisfy the Basel capital requirements, as well as necessary regulatory adjustments and transitional arrangements.
This standard describes the framework for risk-based capital requirements.
This standard describes how to calculate capital requirements for credit risk.
This standard describes how to calculate capital requirements for market risk and credit valuation adjustment risk.
This standard describes how to calculate capital requirements for operational risk.
This standard describes the simple, transparent, non-risk-based leverage ratio. This measure intends to restrict the build-up of leverage in the banking sector and reinforce the risk-based requirements with a simple, non-risk-based "backstop" measure.
This standard describes the Liquidity Coverage Ratio, a measure which promotes the short-term resilience of a bank's liquidity risk profile.
The net stable funding ratio requires banks to maintain a stable funding profile in relation to the composition of their assets and off-balance-sheet activities.
Large exposures regulation limits the maximum loss that a bank could face in the event of a sudden counterparty failure to a level that does not endanger the bank's solvency. This standard requires banks to measure their exposures to a single counterparty or a group of connected counterparties and limit the size of large exposures in relation to their capital.
This standard establishes minimum standards for margin requirements for non-centrally cleared derivatives. Such requirements reduce systemic risk with respect to non-standardised derivatives by reducing contagion and spillover risks and promoting central clearing.
The Pillar 2 supervisory review process ensures that banks have adequate capital and liquidity to support all the risks in their business, especially with respect to risks not fully captured by the Pillar 1 process, and encourages good risk management.
This standard sets out disclosure requirements, which aim to encourage market discipline.
The Basel Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector.