Skip to main content

PFMI implementation database

This is an online data repository of jurisdictions' implementation measures for the Principles for financial market infrastructures and associated CPMI and IOSCO assessment principle ratings. It complements the Level 2 assessment programme on the extent to which jurisdictions' implementation measures are complete and consistent with the international standards for payment systems, central securities depositories, securities settlement systems, central counterparties and trade repositories.

Note that authorities may have updated their rules, regulations and policies since the assessment. For current implementation measures, please contact the relevant authority.

Please provide first name.
Looks good!
United States TR
US-CFTC
  • Principle ID 17.0
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

The CEA is available at the following link: http://www.house.gov/legcoun/Comps/COMEX_NEW.pdf 17 C.F.R. 49 is available at the following link: http://www.ecfr.gov/cgi-bin/text-idx?SID=e3f235f58bdc6ba54e03502f82d1d64e&node=17:2.0.1.1.8&rgn=div5

Assessment comments (key conclusions and recommendations)

The implementation measures of the CFTC are partly consistent with Principle 17. The overall rating has been influenced by the absence of measures implementing key consideration 6 and gaps or shortcomings in the implementation measures for key considerations 2, 5 and 7. Recommendation: The CFTC is recommended to implement measures which address the gaps or inconsistencies identified, specifically those related to key considerations 2, 5, 6 and 7.

United States TR
US-CFTC
  • Principle ID 17.1
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CEA Section 21(c)(8) CFTC regulations 17 C.F.R. 49.24(a)-(b)

United States TR
US-CFTC
  • Principle ID 17.2
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CEA Section 21(c)(8) CFTC regulations 17 C.F.R.: 49.20(a)(2), (b)(2)(vi), (c)(1)(i)(C); 49.24(a)(1)-(3), (b), (j)

Assessment comments (key conclusions and recommendations)

A TR is required to conduct regular, periodic, objective testing and review of its automated systems to ensure that they are reliable, secure, and have adequate scalable capacity. It is also required to conduct regular, periodic testing and review of its business continuity-disaster recovery capabilities. The CFTC’s regulations provide that both types of testing should be conducted by qualified, independent professionals and that such qualified independent professionals, while they may be independent contractors or employees of the TR, should not be persons responsible for development or operation of the systems or capabilities being tested. However, a TR’s board is not required to clearly define the roles and responsibilities for addressing operational risk and endorse the FMI’s operational risk-management framework.

United States TR
US-CFTC
  • Principle ID 17.3
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CFTC regulations 17 C.F.R.: 49.24(a)-(d), (j)

United States TR
US-CFTC
  • Principle ID 17.4
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CFTC regulations 17 C.F.R.: 49.24(a)(1), (b), (c), (j)

United States TR
US-CFTC
  • Principle ID 17.5
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CFTC regulations 17 C.F.R. 49.10(a)(1); 49.24(a)(1)-(3), (b), (c)

Assessment comments (key conclusions and recommendations)

A TR is required to have technological protocols which ensure that its mechanisms for swap data acceptance are reliable and secure. However, a TR is not required to have comprehensive physical security policies that address all potential vulnerabilities and threats.

United States TR
US-CFTC
  • Principle ID 17.6
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CFTC regulations 17 C.F.R.: 49.24(a)(1)-(3), (d), (j)

Assessment comments (key conclusions and recommendations)

A TR’s business continuity and disaster recovery plan and resources, emergency procedures, and backup facilities are required to be sufficient to enable timely recovery and resumption of the TR’s operations and resumption of its ongoing fulfillment of its duties and obligations as a TR following any disruption of its operations. A TR’s business continuity and disaster recovery plan and resources generally should enable resumption of operations during the next business day following a disruption whereas the key consideration requirement is that the TR be able to complete operations by the end of the day of the disruption, even in case of extreme circumstances. Moreover, TRs are not specifically required to ensure that critical information technology systems can resume operations within two hours following disruptive events.

United States TR
US-CFTC
  • Principle ID 17.7
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

CFTC regulations 17 C.F.R. 49.10(a), (c); 49.11(a); 49.24(k)

Assessment comments (key conclusions and recommendations)

A TR is required to regularly review the risks that other entities might pose to its operations and develop appropriate risk-management tools to address these risks. In particular, TRs are required to establish and maintain a program of risk analysis and oversight to identify and minimize sources of operational risk and appropriate controls and procedures to manage such risk. Such arrangements are only required in respect of operational risk, however this is the primary source of risk for a TR. TRs are also required to establish and maintain emergency procedures, back-up facilities and a business continuity-disaster recovery plan. However, a TR is only specifically required to identify, monitor and manage the risks its operations might pose to other FMIs in the context of business continuity and disaster recovery plans.

United States TR
US-CFTC
  • Principle ID 18.0
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should have objective, risk-based, and publicly disclosed criteria for participation, which permit fair and open access.

Implementation measures

The CEA is available at the following link: http://www.house.gov/legcoun/Comps/COMEX_NEW.pdf 17 C.F.R. 49 is available at the following link: http://www.ecfr.gov/cgi-bin/retrieveECFR?gp=&SID=6b869c925c838bbfb47ee4a8adb078cd&n=17y2.0.1.1.8&r=PART&ty=HTML

Assessment comments (key conclusions and recommendations)

The implementation measures of the CFTC are partly consistent with Principle 18. The overall rating has been influenced by the absence of measures implementing key consideration 3 and gaps or shortcomings in the implementation measures for key consideration 2. Recommendation: The CFTC is recommended to implement measures which address the gaps or inconsistencies identified, specifically those related to key considerations 2 and 3.

United States TR
US-CFTC
  • Principle ID 18.1
  • Rating Partly consistent

Implementation measure cut-off date: 25-Feb-2015
Assessment rating date: 17-Apr-2014

Principle

An FMI should have objective, risk-based, and publicly disclosed criteria for participation, which permit fair and open access.

Implementation measures

CFTC regulations 17 C.F.R.: 49.19(e)(3); 49.27(a), (b)(1)-(2)

Description of filters

Jurisdiction

This filter limits the search results to selected jurisdictions. The available jurisdictions represent assessments that have been completed to date. The table below provides also a pdf of key conclusions and recommendations for all Principles of a given jurisdiction.

Laptop displaying a database on screen, a mobile phone, and a notebook on top of a table

FMI type

This filter limits the search results to the selected FMI types. FMIs may be subject to different regulatory, supervisory and oversight regimes depending on their organisation, function and design.

PS: Payment system

A set of instruments, procedures and rules for the transfer of funds between or among participants; the system includes the participants and the entity operating the arrangement.

CSD/SSS: Central securities depository / Securities settlement system

CSDs are entities that provide securities accounts, central safekeeping services and asset services, which may include the administration of corporate actions and redemptions, and play an important role in helping to ensure the integrity of securities issues (that securities are not accidentally or fraudulently created or destroyed or their details changed). The precise activities of a CSD vary based on jurisdiction and market practices.

SSS are entities that enable securities to be transferred and settled by book entry according to a set of predetermined multilateral rules. Such systems allow transfers of securities either free of payment or against payment. Typically, a CSD also operates an SSS.

CCP: Central counterparty

An entity that interposes itself between counterparties to contracts traded in one or more financial markets, becoming the buyer to every seller and the seller to every buyer and thereby ensuring the performance of open contracts.

TR: Trade repository

An entity that maintains a centralised electronic record (database) of transaction data.

Principle or key consideration ID

This filter limits the search results to selected principles and key considerations.   Each principle includes a headline standard and a list of key considerations that further explain the headline standard.  The principles are listed below. A detailed list of key considerations is available in the CPMI-IOSCO Principles for financial market infrastructures.

Principle rating

This filter limits the search results to selected principle rating(s) used in the L2 assessments. The ratings reflect conditions at the time of the assessment, and are built on key conclusions that reflect CPMI and IOSCO's collective expert judgment regarding the impact of identified gaps and/or shortcomings. Ratings are determined for each principle after the jurisdiction's legislative and regulatory framework, including policy statements, as relevant, was compared against the corresponding content of the PFMI.

The jurisdiction’s regulatory framework is consistent with the Principle. The assessment has identified no gaps or shortcomings, or only a few gaps and/or shortcomings that have no material impact on completeness and/or consistency.

The jurisdiction’s regulatory framework is broadly consistent with the Principle. The assessment has identified gaps and/or shortcomings that have a minor impact on completeness and/or consistency.

The jurisdiction’s regulatory framework is partly consistent with the Principle. The assessment has identified gaps and/or shortcomings that have a significant impact on completeness and/or consistency.

The jurisdiction’s regulatory framework is not consistent with the Principle. The assessment has identified gaps and/or shortcomings that have a major impact on completeness and/or consistency.

This status corresponds to the case where no relevant FMI exists that is within the scope of the Principles. A rating of “NA” will be indicated only if no relevant regulatory measures are being taken and no such FMI is expected to develop within the jurisdiction.

You might also be interested in