Skip to main content

PFMI implementation database

This is an online data repository of jurisdictions' implementation measures for the Principles for financial market infrastructures and associated CPMI and IOSCO assessment principle ratings. It complements the Level 2 assessment programme on the extent to which jurisdictions' implementation measures are complete and consistent with the international standards for payment systems, central securities depositories, securities settlement systems, central counterparties and trade repositories.

Note that authorities may have updated their rules, regulations and policies since the assessment. For current implementation measures, please contact the relevant authority.

Please provide first name.
Looks good!
Brazil TR
BR-BCB,CVM
  • Principle ID 15.3
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify, monitor, and manage its general business risk and hold sufficient liquid net assets funded by equity to cover potential general business losses so that it can continue operations and services as a going concern if those losses materialise. Further, liquid net assets should at all times be sufficient to ensure a recovery or orderly wind-down of critical operations and services.

Implementation measures

As above, and in addition: Circular BCB 3.743, Annex, Article 2. Circular BCB 3057, Article 2; Annex Article 11-A CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013) Article 27; Article 31; Article 63; Article 75; Resolution CMN 2,554, Article 2; Article 3

Assessment comments (key conclusions and recommendations)

The pre-existing regulations do not require TRs to hold sufficient liquid net assets funded by equity to implement their recovery or orderly wind-down plan; neither they require those liquid net assets to be funded by equity equal to at least six months of current operating expenses. This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 15.4
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify, monitor, and manage its general business risk and hold sufficient liquid net assets funded by equity to cover potential general business losses so that it can continue operations and services as a going concern if those losses materialise. Further, liquid net assets should at all times be sufficient to ensure a recovery or orderly wind-down of critical operations and services.

Implementation measures

As above, and in addition: Circular BCB 3.743, Annex, Article 2. Circular BCB 3057, Article 2; Annex Article 11-A CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013) Article 27; Article 31; Article 63; Article 75; Resolution CMN 2,554, Article 2; Article 3

Assessment comments (key conclusions and recommendations)

The pre-existing regulations do not specify requirements to address this Key Consideration. This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 15.5
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify, monitor, and manage its general business risk and hold sufficient liquid net assets funded by equity to cover potential general business losses so that it can continue operations and services as a going concern if those losses materialise. Further, liquid net assets should at all times be sufficient to ensure a recovery or orderly wind-down of critical operations and services.

Implementation measures

As above, and in addition: Circular BCB 3.743, Annex, Article 2. Circular BCB 3057, Article 2; Annex Article 11-A CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013) Article 27; Article 31; Article 63; Article 75; Resolution CMN 2,554, Article 2; Article 3

Assessment comments (key conclusions and recommendations)

The pre-existing regulations do not specify requirements to address this Key Consideration. This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 17.0
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

BCB Policy Statement 25,097 BCB Policy Statement 30,516 CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013); Article 110, Paragraphs 4 and 5 Law No. 12,810, Article 28. Law No. 13,506, Article 1; Article 3 Resolution CMN 2,882, Article 1; Article 5, Subparagraphs II and III; Article 6, Subparagraphs II and III

Assessment comments (key conclusions and recommendations)

The consistent rating for this Principle is driven by the BCB’s policy statements 25,097 and 30,516, supported by an analysis of how FMIs are required to observe the PFMI Principle and KCs. These measures cover the gap created by the overlap between the pre-existing and new implementation measures for some parts of this Principle. The relevant authorities may want to consider making it formally and publicly explicit that, in the absence of adequate or sufficiently detailed rules or of overlapping rules, the PFMI will apply in full.

Brazil TR
BR-BCB,CVM
  • Principle ID 17.1
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

As above, and in addition: Circular BCB 3.743, Article 3; Article 11; Annex Article 2; Annex Article 3. Circular BCB 3057, Article 2; Annex Article 2; Annex Article 15 CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013) Article 27; Article 31; Article 63; Article 75 Law 10,214, Article 4 Resolution CMN 2,554, Article 2 Resolution CMN 2,882, Article 3; Article 8

Assessment comments (key conclusions and recommendations)

Although the pre-existing regulations establish a general requirement for internal controls to identify and evaluate internal and external factors that may adversely affect the attainment of a TR’s objectives, as well as a requirement for TRs to “maintain risk control systems adequate to the risks inherent to their activities”, the definition of operational risk in the pre-existing regulations refers only to “losses resulting from human error or failure in an equipment, software or communication, necessary for the functioning of a system”. This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 17.2
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

As above, and in addition: CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013), Article 24; Article 63 Resolution CMN 2,554, Article 2 Resolution CMN 2,882, Article 8

Assessment comments (key conclusions and recommendations)

The pre-existing regulations do not clearly require the Board to endorse the TR's operational risk management framework (the Board is required to approve the annual report related to internal control of operating risks, but there is no clear requirement for the Board to approve the TR's operational risk management framework); and there are no clear requirements for systems, operational policies, procedures, and controls to be tested periodically and after significant changes (although the pre-existing regulation indicate that internal controls shall be periodically revised and updated). This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 17.3
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

Resolution CMN 2,882, Article 1, Article 5, Subparagraphs II and III, and Article 6, Subparagraphs II and III Law No. 12,810, Article 28. BCB Policy Statement 25,097 CVM Instruction No. 461, Article 110, Paragraphs 4 and 5 Law No. 13,506, Article 1, and Article 3

Brazil TR
BR-BCB,CVM
  • Principle ID 17.4
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

As above, and in addition: Circular BCB 3.743, Annex Article 2 Circular BCB 3057, Annex Article 2 CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013), Article 110, Paragraph 3

Assessment comments (key conclusions and recommendations)

The pre-existing regulations do not require TRs to ensure they have scalable capacity, as foreseen under this Key Consideration (although the pre-existing regulations include a general requirement for TRs to provide evidence, during the authorization process, on its “capability to reach the operational, organizational, managerial and financial objectives”, including “a detailed description of the management tools and risk mitigation measures”). This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 17.5
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

As above, and in addition: Circular BCB 3.743, Annex Article 11 Law 10,214, Article 4 Resolution CMN 2,554, Article 2 Resolution CMN 2,882, Article 3; Article 8

Assessment comments (key conclusions and recommendations)

The language in the pre-existing regulation is broad, requiring TRs to have an operational infrastructure with adequate reliability and security levels, with contingent plans and data recovery procedures. However, it is not clear whether this requirement specifically covers physical and information security. This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Brazil TR
BR-BCB,CVM
  • Principle ID 17.6
  • Rating Consistent

Implementation measure cut-off date: 30-May-2020
Assessment rating date: 30-May-2018

Principle

An FMI should identify the plausible sources of operational risk, both internal and external, and mitigate their impact through the use of appropriate systems, policies, procedures, and controls. Systems should be designed to ensure a high degree of security and operational reliability and should have adequate, scalable capacity. Business continuity management should aim for timely recovery of operations and fulfilment of the FMI’s obligations, including in the event of a wide-scale or major disruption.

Implementation measures

As above, and in addition: Circular BCB 3.743, Annex Article 3; Annex Article 11; Annex Article 14 Circular BCB 3057, Annex Article 15; Annex Article 29 CVM Instruction 461, Article 63 CVM Instruction No. 461 (amended by CVM Instruction No. 544 of December 2013) Article 63 Resolution CMN 2,882, Article 3;

Assessment comments (key conclusions and recommendations)

The language in the pre-existing do not include clear requirements regarding the regularly testing of those arrangements (instead, the pre-existing regulations require internal controls to be regularly revised and updated); and the language in the pre-existing regulations do not specifically refer to “critical” IT systems (instead, they make a general reference to equipment or software or information in the computer systems). This gap is covered by the BCB’s policy statements 25,097 and 30,516, supported through the relevant supervisory evidence that provided context on how FMIs are required to observe the PFMI Principle and KCs.

Description of filters

Jurisdiction

This filter limits the search results to selected jurisdictions. The available jurisdictions represent assessments that have been completed to date. The table below provides also a pdf of key conclusions and recommendations for all Principles of a given jurisdiction.

Laptop displaying a database on screen, a mobile phone, and a notebook on top of a table

FMI type

This filter limits the search results to the selected FMI types. FMIs may be subject to different regulatory, supervisory and oversight regimes depending on their organisation, function and design.

PS: Payment system

A set of instruments, procedures and rules for the transfer of funds between or among participants; the system includes the participants and the entity operating the arrangement.

CSD/SSS: Central securities depository / Securities settlement system

CSDs are entities that provide securities accounts, central safekeeping services and asset services, which may include the administration of corporate actions and redemptions, and play an important role in helping to ensure the integrity of securities issues (that securities are not accidentally or fraudulently created or destroyed or their details changed). The precise activities of a CSD vary based on jurisdiction and market practices.

SSS are entities that enable securities to be transferred and settled by book entry according to a set of predetermined multilateral rules. Such systems allow transfers of securities either free of payment or against payment. Typically, a CSD also operates an SSS.

CCP: Central counterparty

An entity that interposes itself between counterparties to contracts traded in one or more financial markets, becoming the buyer to every seller and the seller to every buyer and thereby ensuring the performance of open contracts.

TR: Trade repository

An entity that maintains a centralised electronic record (database) of transaction data.

Principle or key consideration ID

This filter limits the search results to selected principles and key considerations.   Each principle includes a headline standard and a list of key considerations that further explain the headline standard.  The principles are listed below. A detailed list of key considerations is available in the CPMI-IOSCO Principles for financial market infrastructures.

Principle rating

This filter limits the search results to selected principle rating(s) used in the L2 assessments. The ratings reflect conditions at the time of the assessment, and are built on key conclusions that reflect CPMI and IOSCO's collective expert judgment regarding the impact of identified gaps and/or shortcomings. Ratings are determined for each principle after the jurisdiction's legislative and regulatory framework, including policy statements, as relevant, was compared against the corresponding content of the PFMI.

The jurisdiction’s regulatory framework is consistent with the Principle. The assessment has identified no gaps or shortcomings, or only a few gaps and/or shortcomings that have no material impact on completeness and/or consistency.

The jurisdiction’s regulatory framework is broadly consistent with the Principle. The assessment has identified gaps and/or shortcomings that have a minor impact on completeness and/or consistency.

The jurisdiction’s regulatory framework is partly consistent with the Principle. The assessment has identified gaps and/or shortcomings that have a significant impact on completeness and/or consistency.

The jurisdiction’s regulatory framework is not consistent with the Principle. The assessment has identified gaps and/or shortcomings that have a major impact on completeness and/or consistency.

This status corresponds to the case where no relevant FMI exists that is within the scope of the Principles. A rating of “NA” will be indicated only if no relevant regulatory measures are being taken and no such FMI is expected to develop within the jurisdiction.

You might also be interested in