This topic focuses on credit risk management in banking activities, including requirements and strategies for credit risk management as well as credit risk limits. Credit risk management must be implemented throughout the process of reviewing, assessing, approving, and managing credit to ensure compliance with the regulations of the State Bank and relevant laws.
Đối tượng áp dụng
Commercial banks and foreign bank branches
Các điểm cốt lõi
- Credit risk management throughout the process of reviewing, assessing, approving, and managing credit
- The minimum credit risk management strategy shall include the target non-performing loan ratio, principles for determining credit risk compensation costs in interest rate calculation methods, and pricing of credit products based on customer risk levels
- Credit risk limits must be adhered to to ensure the safety of banking operations.
- Requirements for target non-performing loan ratios, target bad credit issuance according to customer categories, industries, and economic sectors.
- Principles for applying measures to reduce credit risks
🌐 Tác động xã hội từ văn bản này
- Reducing credit risks in banking activities
- Ensuring financial safety for banks and customers
- Strengthening credit quality management
❓ Câu hỏi thường gặp
What stages does credit risk management include?
Credit risk management is carried out throughout the process of reviewing, assessing, approving, and managing credit.
What contents should the credit risk management strategy include?
The minimum credit risk management strategy must include the target non-performing loan ratio, principles for determining credit risk compensation costs in interest rate calculation methods, and pricing of credit products based on customer risk levels.
Why is it necessary to have credit risk limits?
Credit risk limits help banks control transactions, credit activities, and ensure compliance with regulations on safety in operations.
Toàn văn
|
STATE BANK OF VIETNAM |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 13/2018/TT-NHNN |
Hanoi, May 18, 2018 |
CIRCULAR
Regulations on the internal control system of commercial banks,
foreign bank branches
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010 and the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to Government Decree No. 16/2017/NĐ-CP dated February 17, 2017 on the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of Banking Inspection and Supervision;
The Governor of the State Bank of Vietnam issues this Circular to regulate the internal control system of commercial banks and foreign bank branches.
PART I
GENERAL PROVISIONS
This Circular regulates the internal control system of commercial banks and foreign bank branches.
Article 2. Applicability
1. Commercial banks include state-owned commercial banks, joint-stock commercial banks, joint venture banks, and wholly foreign-owned banks.
2. Branches of foreign banks.
In this Circular, the following terms are understood as follows:
1. Internal control system is a set of mechanisms, policies, procedures, internal regulations, organizational structure of commercial banks and foreign bank branches established in accordance with the Law on Credit Institutions, this Circular, and relevant laws, and implemented to monitor, prevent, detect, and promptly address risks and achieve the required standards. The internal control system implements high-level management supervision, internal control, risk management, internal capital adequacy assessment, and internal audit.
2. High-level management supervision is the oversight by the Board of Directors, Board of Members, General Director (Director), and parent bank over internal control, risk management, internal capital adequacy assessment, and the Supervisory Board's oversight of internal audit for commercial banks and parent banks, and the General Director (Director)'s oversight of internal audit for foreign bank branches.
3Internal control involves monitoring and supervising individuals and departments in implementing mechanisms, policies, internal regulations, professional ethics standards, and control culture to manage conflicts of interest, control risks, ensure that the operations of commercial banks and foreign bank branches meet their objectives while complying with legal requirements.
4. Risk management is the identification, measurement, monitoring, and control of risks in the operations of commercial banks and foreign bank branches.
5. Internal capital adequacy assessment is the self-assessment of capital adequacy to comply with the State Bank of Vietnam's regulations on capital adequacy ratios and to meet the required standards of commercial banks and foreign bank branches.
6. Control culture is the corporate culture of commercial banks and foreign bank branches reflecting a unified understanding of the importance of control and risk management activities by the Board of Directors, Board of Members, Supervisory Board, General Director (Director), and individuals and departments. Control culture is formed through ethical standards, internal regulations, reward and punishment systems to encourage and ensure that individuals and departments proactively identify and control risks in their own activities and those of commercial banks and foreign bank branches.
7. Economic capital is the level of capital determined by commercial banks and foreign bank branches based on calculating the necessary capital to offset significant risks and ensure capital adequacy ratios under adverse scenarios.
8. Stress testing is the evaluation of the impact of fluctuations and unfavorable changes on capital adequacy ratios and liquidity in different scenarios to determine the risk tolerance of commercial banks and foreign bank branches.
9. Risk is the possibility of financial loss (financial loss, non-financial loss) reducing income, equity, leading to a decrease in capital adequacy ratios or limiting the ability to achieve business goals of commercial banks and foreign bank branches.
10. Risk appetite is the level of risk that commercial banks and foreign bank branches are willing to accept during the implementation of their business strategies, expressed by the ratios and indicators specified in point a, Clause 2, Article 24 of this Circular.
11. Risk status is the value of risky assets, risky liabilities, and off-balance-sheet items with risks of commercial banks and foreign bank branches.
12Significant activities are activities determined by commercial banks and foreign bank branches based on the scale of such activities compared to one of the financial indicators (shareholders' equity, total assets, income, expenses, or other financial indicators) according to the internal regulations of commercial banks and foreign bank branches.
13. Significant risk including:
b) Liquidity risk, concentration risk;
c) Other risks arising from significant activities.
14. Liquidity risk is risk due to:
a) Commercial banks and foreign bank branches not having the ability to fulfill debt obligations when due; or
b) Commercial banks and foreign bank branches having the ability to fulfill debt obligations when due but at higher costs than the average market cost according to the internal regulations of commercial banks and foreign bank branches.
15. Concentration risk is the risk arising from commercial banks and foreign bank branches concentrating their business activities on a single customer (including related parties), partner, product, transaction, industry, economic sector, or currency to a degree significantly affecting income and risk status according to the internal regulations of commercial banks and foreign bank branches.
16. Conflict of interest is a situation where an individual or department makes decisions within their authority that create interests inconsistent with or contrary to the interests of commercial banks and foreign bank branches.
17. Risk decision is the decision-making by authorized levels of commercial banks and foreign bank branches that generate risks or change the risk status of commercial banks and foreign bank branches.
18. Credit risk decision is a risky decision of commercial banks and foreign bank branches in credit activities, at minimum including: credit granting decisions; credit limit setting decisions; credit granting decisions exceeding limits; loan restructuring decisions; loan classification decisions.
19. Problem loan facility The minimum guarantee for commercial banks and foreign bank branches to classify credit facilities into at least group 2 or higher according to the State Bank of Vietnam's regulations on asset classification, provisioning levels, risk provisioning methods, and the use of provisions to address risks.
20. Outsourcing activity It refers to the agreement in writing (outsourcing service contract) between commercial banks and foreign bank branches and another enterprise or credit institution or foreign bank branch (referred to as the outsourcing enterprise) to perform one or more activities (including data processing or certain stages of business processes) instead of the commercial banks and foreign bank branches, in accordance with the law.
21. Internal auditor An internal auditor who belongs to the internal audit department of commercial banks and foreign bank branches.
22. Parent Bank A foreign bank that has been granted permission to operate a branch in Vietnam.
Article 4. Application of relevant regulatory legal documents
The internal control system of commercial banks and foreign bank branches shall be implemented in accordance with the Law on Credit Institutions, this Circular, and other relevant regulatory legal documents.
Article 5. Requirements for the internal control system
1. The internal control system of commercial banks and foreign bank branches must meet the following requirements:
a) The requirements set forth in Clause 2 of Article 40 of the Law on Credit Institutions;
b) Be appropriate to the scale, conditions, and complexity of the business operations of commercial banks and foreign bank branches;
c) Have sufficient financial, human, and information technology resources to ensure the effectiveness of the internal control system;
d) Establish and maintain an internal control culture and professional ethics standards for commercial banks and foreign bank branches.
2. Commercial banks and foreign bank branches must have internal compliance regulations in accordance with Article 93 of the Law on Credit Institutions, which must ensure the following requirements:
a) Comply with the provisions of this Circular and relevant legal regulations;
b) Authority to issue:
(i) For commercial banks: The Board of Directors, Board of Members shall issue regulations on the organization, governance, and operation of commercial banks, except for matters within the authority of the General Shareholders' Meeting or shareholders; The Supervisory Board shall issue internal regulations of the Supervisory Board; The General Director (Director) shall issue internal procedures, operational procedures (hereinafter referred to as internal procedures);
(ii) For foreign bank branches: The General Director (Director) shall issue internal regulations of foreign bank branches in accordance with the regulations of the parent bank or use internal regulations issued by the parent bank;
c) Meet the requirements and contents of risk management activities prescribed in Article 14, Clause 1 and 2 of Article 15 of this Circular;
d) Be evaluated periodically in accordance with this Circular and the regulations of commercial banks and foreign bank branches on suitability, compliance with legal provisions, and amendments (if necessary).
3. The internal control system must have three independent lines of defense as follows:
a) First Line of Defense having the function of identifying, controlling, and mitigating risks performed by the following departments:
(i) Business departments (including product development departments), other revenue-generating departments; departments responsible for implementing risk-taking decisions;
(ii) Departments responsible for allocating risk limits, risk control, and risk mitigation (belonging to business departments or independent departments) for each type of transaction and business activity;
(iii) Human Resources Department, Accounting Department;
b) Second Line of Defense having the function of establishing risk management policies, internal regulations on risk governance, risk measurement, monitoring, and compliance with legal provisions performed by the following departments:
(i) The department complying with Article 18 of this Circular;
(ii) The risk management department as prescribed in Article 22 of this Circular;
c) Third Line of Defense having the function of internal auditing performed by the internal audit department in accordance with the Law on Credit Institutions and this Circular.
4. The discussion opinions (agreed and disagreed opinions) and conclusions about the internal control system in meetings of the Board of Directors, Board of Members, Supervisory Board, Risk Management Committee, Human Resources Committee, Risk Oversight Committee, Capital Management Committee, Asset/Liability Management Committee (ALCO Committee) must be recorded in writing.
5. Independent assessment of the internal control system shall be carried out in accordance with the State Bank of Vietnam's regulations on independent audit of commercial banks and foreign bank branches.
Article 6. Archiving of internal control system records and documents
1. Commercial banks and foreign bank branches shall have internal regulations on managing and archiving records and documents related to the internal control system.
2. The management and archiving of records and documents related to the internal control system of commercial banks and foreign bank branches must ensure:
a) Compliance with legal provisions and the State Bank's regulations on the retention period for documents and records in the banking sector;
b) Adequate storage to provide access upon request for internal audit, independent auditors, and authorized agencies during internal audit, independent audit, inspection, and supervision processes.
Article 7. Reporting to the State Bank on the internal control system
2. The report on the internal control system includes:
a) Annual report on the results of self-inspection and evaluation of internal controls according to Appendix No. 01 issued together with this Circular;
b) Annual report on risk management according to Appendix No. 02 issued together with this Circular;
c) Annual report on internal assessment of capital adequacy according to Appendix No. 04 issued together with this Circular;
d) Annual report on internal audit according to Appendix No. 05 issued together with this Circular, and ad hoc internal audit reports.
3. Deadline for submitting reports:
a) For the reports specified in points a, b, and c of Clause 2 of this Article: Within 45 days from the end of the fiscal year, commercial banks and foreign bank branches shall submit their annual reports;
b) For the report specified in point d of Clause 2 of this Article:
(i) Within 60 days from the end of the fiscal year, commercial banks shall submit their annual internal audit reports;
(ii) Within 60 days from the end of the internal audit, foreign bank branches shall submit their annual internal audit reports. In cases where there is no internal audit conducted during the fiscal year, foreign bank branches are not required to submit reports;
(iii) Within seven working days from the end of the ad hoc internal audit, commercial banks and foreign bank branches shall submit their ad hoc internal audit reports.
4. Reports on the internal control system specified in Clause 2 of this Article must update any existing issues, limitations, and newly emerging risks of the internal control system throughout the entire commercial bank (including all departments at headquarters, branches, and other units affiliated with the commercial bank as defined by the State Bank's regulations on the operational network of commercial banks (hereinafter referred to as other affiliated units)) and foreign bank branches.
Chapter II
SUPERVISION BY SENIOR MANAGEMENT
Article 8. Requirements for supervision by senior management
1. To have an organizational structure, tasks, and authorities of the Board of Directors, Board of Members, Supervisory Board, General Director (Director) in accordance with the Law on Credit Institutions and consistent with the provisions of this Circular for commercial banks.
2. To have an organizational structure, tasks, and authorities of senior management supervision in accordance with the parent bank's regulations to ensure that the General Director (Director) implements high-level supervision over foreign bank branches in accordance with this Circular.
3. To ensure that internal control, risk management, internal assessment of capital adequacy, and internal audit are effectively carried out and meet the set requirements.
4. To be fully aware of the risk status and implementation of risk management policies of commercial banks and foreign bank branches.
5. To take preventive measures and promptly address losses to enhance the efficiency and safety of operations of commercial banks and foreign bank branches.
Article 9. The organizational structure for supervising senior management of commercial banks
1. The organizational structure for supervising the Board of Directors and the Board of Members of commercial banks must ensure:
a) There is a Risk Management Committee and a Human Resources Committee in accordance with the State Bank's regulations on granting licenses and the organization and operation of commercial banks and foreign bank branches, and each committee must have at least half (1/2) of its voting members be non-executive members;
b) Other committees (if necessary) to assist the Board of Directors and the Board of Members in performing supervisory functions for senior management.
2. The organizational structure for supervising the Supervisory Board shall be carried out in accordance with the Law on Credit Institutions and internal regulations of the Supervisory Board.
3. The General Director (Director) must establish a Risk Management Council, an ALCO Council, and a Capital Management Council to advise and assist the General Director (Director) in accordance with Clause 2, Clause 3 of Article 11 and Clause 2 of Article 12 of this Circular, ensuring the following organizational structure:
a) The Risk Management Council includes: The Chairman is a person in charge at headquarters (not the General Director (Director)) who specializes in risk management, has experience, knowledge, and expertise in risk management, and other members from relevant departments according to the internal regulations of the commercial bank;
b) The ALCO Council includes: The Chairman is the General Director (Director) or another person in charge at headquarters and other members from relevant departments according to the internal regulations of the commercial bank;
c) The Capital Management Council includes: The Chairman is the General Director (Director) or another person in charge at headquarters specializing in finance, having experience, knowledge, and expertise in accounting and finance, and other members from relevant departments according to the internal regulations of the commercial bank;
d) The operating rules of the councils shall be issued by the General Director (Director) and must minimally include the functions and responsibilities of the councils, the number of members and their functions and responsibilities; decision-making mechanisms; regular meetings (ensuring that the Risk Management Council and the ALCO Council meet at least once every quarter, and the Capital Management Council meets at least once every six months); extraordinary meetings, and other contents.
Article 10. Senior Management Oversight of Internal Control
1. The Board of Directors and the Board of Members of commercial banks supervise the General Director (Director) in the following matters:
a) Organizing the implementation of internal control activities, operations, and maintenance of management information systems and information exchange mechanisms;
b) Maintaining the internal control culture stipulated in Clause 6 of Article 3 of this Circular and professional ethics standards stipulated in Clause 3 of Article 15 of this Circular within the commercial bank;
c) Addressing and rectifying deficiencies and limitations in internal controls as required and recommended by the State Bank, independent auditors, and other competent authorities;
d) Handling violations of laws, internal regulations, and professional ethics standards;
đ) Other matters specified by the Board of Directors and the Board of Members.
2. The General Director (Director) of commercial banks supervises individuals and departments in the following matters:
a) Implementing internal control regulations, maintaining the internal control culture; evaluating compliance with professional ethics standards (excluding professional ethics standards for members of the Supervisory Board and internal auditors);
b) Operating the management information system, assessing (accuracy, completeness, timeliness, and appropriateness), upgrading, and improving the management information system to ensure compliance with requirements stipulated in Article 20 of this Circular;
c) Implementing directives from the Board of Directors and the Board of Members to address and rectify deficiencies and limitations in internal controls as required and recommended by the State Bank, independent auditors, and other competent authorities;
d) Conducting periodic annual or extraordinary self-assessment of the effectiveness of internal controls, minimally including:
(i) Self-inspection and evaluation of the implementation of internal control regulations by each unit and department in operational activities and business processes;
(ii) Reviewing and evaluating internal regulations on internal controls;
(iii) Proposing solutions to address deficiencies and limitations in internal controls to the Board of Directors and the Board of Members;
đ) Other matters specified by the commercial bank.
3. The General Director (Director) of foreign bank branches supervises individuals and departments in accordance with the parent bank's regulations in the following matters:
a) Implementing internal controls;
b) Addressing and rectifying deficiencies and limitations in internal controls as recommended by the State Bank, independent auditors, and other competent authorities.
Article 11. Supervision by senior management over risk management
1. The Board of Directors, Board of Members of commercial banks shall supervise the General Director (Director) based on the proposals and advice of the Risk Management Committee in the following matters:
a) To build and organize the implementation of risk management policies;
b) Handling and rectifying deficiencies and limitations in risk management according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
c) Other contents prescribed by the Board of Directors, Board of Members.
2. The General Director (Director) of commercial banks shall supervise individuals and departments based on the proposals and advice of the Risk Management Committee in the following matters:
a) Establishing procedures for formulating and implementing risk management policies;
b) Implementing risk management policies and evaluating such policies in accordance with Clause 3, Article 24 of this Circular to propose adjustments to the Board of Directors, Board of Members;
c) Establishing and implementing risk limits, proposing risk limit allocations for each business activity and operational activity; implementing measures when risk limits are not met;
d) Organizing the implementation of directives from the Board of Directors, Board of Members regarding handling and rectifying deficiencies and limitations in risk management according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
đ) Conducting self-inspection and evaluation of risk management and proposing measures to handle and rectify deficiencies and limitations to the Board of Directors, Board of Members;
e) Other contents prescribed by commercial banks.
3. The General Director (Director) of commercial banks shall supervise individuals and departments in asset/debt management based on the advice and proposals of the ALCO Board, including:
a) Effectively managing the balance sheet in line with risk management policies;
b) Reviewing and proposing plans for capital raising, capital utilization plans, principles for internal transfer pricing;
c) Establishing interest rate frameworks and pricing for other products to manage financial assets and financial debts;
d) Controlling business activities to ensure compliance with liquidity risk limits and interest rate risk limits on the bank's books, total assets calculated based on interest rate risk on the bank's books;
đ) Other matters specified by the commercial bank.
4. The General Director (Director) of foreign bank branches shall supervise individuals and departments in accordance with the parent bank's regulations in the following matters:
a) Implementing risk management;
b) Handling and rectifying deficiencies and limitations in risk management according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities.
Article 12. Supervision by senior management over internal assessment of capital adequacy
1. The Board of Directors and the Board of Members of commercial banks supervise the General Director (Director) in the following matters:
a) Organizing the implementation of internal assessments of capital adequacy;
b) Handling and rectifying deficiencies and limitations in internal assessments of capital adequacy according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
c) Other contents prescribed by the Board of Directors, Board of Members.
2. The General Director (Director) of commercial banks shall supervise and direct individuals and departments based on the proposals and advice of the Capital Management Committee in the following matters:
a) Implementing internal assessments of capital adequacy;
b) Implementing directives from the Board of Directors, Board of Members regarding handling and rectifying deficiencies and limitations in internal assessments of capital adequacy according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
c) Other contents prescribed by commercial banks.
3. The General Director (Director) of foreign bank branches supervises individuals and departments in accordance with the parent bank's regulations in the following matters:
a) Implementing internal assessments of capital adequacy;
b) Handling and rectifying deficiencies and limitations in internal assessments of capital adequacy according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities.
Article 13. Supervision of internal audit by senior management
1. The supervisory board of commercial banks shall carry out supervision over internal audit including:
a) Monitoring and evaluating the implementation of professional ethics standards by members of the Supervisory Board, internal auditors;
b) Supervising the internal audit department in the following areas:
(i) Conducting internal audits;
(ii) Reviewing and assessing the effectiveness of internal audits and the performance of the Head of Internal Audit;
(iii) Handling and rectifying deficiencies and limitations of internal audits according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
c) Other contents as prescribed by the supervisory board.
2. The General Director (Director) of foreign bank branches shall supervise individuals and departments in accordance with the mother bank's regulations in the following areas:
a) Conducting internal audits;
b) Handling and rectifying deficiencies and limitations of internal audits according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities.
Chapter III
INTERNAL CONTROL
Article 14. Requirements for internal control
1. Internal control shall be implemented for all activities, business processes, and departments at commercial banks (including headquarters, branches, and other affiliated units) and foreign bank branches to ensure the following requirements:
a) Activities of commercial banks and foreign bank branches comply with legal provisions;
b) Conflict of interest control; timely detection and handling of violations;
c) Enhancing awareness about the role and responsibility of individuals and departments in internal control to build and maintain the internal control culture of commercial banks and foreign bank branches.
2. Internal control shall be carried out through control activities, information exchange mechanisms, and management information systems.
Article 15. Control Activities
1. Control activities of commercial banks and foreign bank branches shall be conducted through the following minimum contents:
a) Approval authority delegation must be based on the reliability of the approving authority and the capability of the individual or department executing the task. Approval authority must be expressed through criteria regarding transaction scale, risk limits, and other limits as stipulated internally by commercial banks and foreign bank branches;
b) Defining functions and responsibilities of individuals and departments from the lowest level to the highest level in all transactions and business processes at commercial banks (including headquarters, branches, and other affiliated units) and foreign bank branches ensuring the principle that:
(i) Members of the Board of Directors and members of the Board of Members do not participate in reviewing and approving decisions involving risks within the functions and responsibilities of the General Director (Director), except when the member of the Board of Directors or the member of the Board of Members is also the General Director (Director);
(ii) Separating functions and responsibilities in transactions and business processes to avoid conflicts of interest or to prevent and control conflicts of interest; one individual does not dominate an entire transaction or the process of implementing a transaction; one individual is not simultaneously assigned tasks that involve conflicts of interest;
(iii) Having independent individuals within the same department or independent departments to conduct periodic and ad hoc reviews as stipulated internally by commercial banks and foreign bank branches;
(iv) In cases where the implementation of provisions at point b(ii) and b(iii) still poses a risk of conflict of interest or violation of internal regulations, commercial banks and foreign bank branches must identify the cause, take measures to minimize risks in operations, and closely monitor and independently assess more frequently;
c) Delegating management responsibilities (including custody, storage, transportation, inspection, and inventory) of each individual and department for assets (including financial and tangible assets) based on the value of the asset or specific limits as stipulated internally by commercial banks and foreign bank branches;
d) Accounting entries must comply with accounting standards and regulations; consolidating, preparing, and submitting financial reports as required by law and internal regulations of commercial banks and foreign bank branches. Accounting entries must be reviewed and reconciled to ensure timely detection and handling of errors and must be reported to the approving authority as stipulated internally by commercial banks and foreign bank branches;
đ) Implementing preventive and timely corrective measures for violations and illegal acts at commercial banks (including headquarters, branches, and other affiliated units) and foreign bank branches;
e) Allocating human resources appropriately for each business activity and control activity (including replacement personnel when staff are absent, recruitment, rotation, and appointment of officials).
2. Control activities of the headquarters of commercial banks over branches and other affiliated units must ensure:
a) The headquarters can monitor and control transactions and activities of branches and other affiliated units, including monitoring and controlling through individuals and departments conducting control activities at branches and other affiliated units;
b) Regulations on functions, responsibilities, reporting mechanisms, salaries, rewards, disciplinary actions, official rotations, and other mechanisms to ensure the independence and absence of conflicts of interest of individuals and departments conducting control activities at branches and other affiliated units relative to other individuals and departments within those units;
c) Mechanisms allowing customers to review, inspect, and reconcile transactions conducted at branches and other affiliated units with the headquarters of commercial banks.
3. Professional ethics standards (excluding professional ethics standards for supervisory board members and internal auditors) must be issued by the Board of Directors and Board of Members of commercial banks and the General Director (Director) of foreign bank branches to ensure the following principles:
a) Staff at all levels perform their duties and powers honestly for the benefit of commercial banks and foreign bank branches; they shall not abuse their positions, use information, trade secrets, business opportunities, and assets of commercial banks and foreign bank branches to gain personal benefits or harm the interests of commercial banks and foreign bank branches;
b) Individuals and departments responsible for reporting promptly to competent authorities when detecting behaviors as prescribed in point a of this clause and violations of internal regulations and laws.
4. Commercial banks and foreign bank branches must submit internal reports on internal control to competent authorities annually or at any time as stipulated in their internal regulations. Internal reports on internal control include evaluations of internal control activities according to the contents prescribed in Clauses 1, 2, and 3 of this Article and other contents as stipulated in the internal regulations of commercial banks and foreign bank branches.
Article 16. Control over credit granting activities
1. The control over credit granting activities of commercial banks and foreign bank branches must comply with the provisions of Clause 1 and 2 of Article 15 of this Circular.
2. Credit granting activities must be controlled to ensure conflict of interest management based on the principle that individuals and departments responsible for credit assessment must be independent from those responsible for:
a) Customer relations;
b) Re-assessment (if applicable);
c) Approving credit granting decisions;
d) Controlling credit risk limits; managing problematic credit grants; setting aside and using reserves to address credit risks.
Article 17. Control over proprietary trading activities
1. The control over proprietary trading activities of commercial banks and foreign bank branches must comply with the provisions of Clause 1 and 2 of Article 15 of this Circular.
2. Proprietary trading activities must be controlled to ensure compliance with the following minimum principles:
a) There must be a dedicated unit to conduct proprietary trading (hereinafter referred to as the proprietary trading unit); specific authority levels for individuals and departments within the proprietary trading unit must be defined; proprietary traders and departments conducting transactions must be independent from those controlling proprietary trading and those handling proprietary trading settlements;
b) Proprietary trading must be conducted within specified limits, commitments to execute transactions (including cancellations, changes, or additions to transaction terms), and accounting records must comply with relevant legal provisions for such proprietary trading;
c) Information, documents, and files related to proprietary trading must be provided fully and promptly to individuals and departments controlling proprietary trading;
d) There must be internal procedures for conducting proprietary trading as prescribed in Clause 3 of this Article and internal procedures for settling proprietary trading transactions as prescribed in Clause 4 of this Article.
3. Internal procedures for conducting proprietary trading must meet the following requirements:
a) Traders may only conduct transactions according to the type of transaction, counterparties, and assigned authority;
b) In cases where proprietary trading is conducted via telephone, trader conversations must be recorded and stored for a minimum of two months from the date of the conversation. In cases where proprietary trading is conducted through computer systems, traders are only permitted to enter proprietary trading data into the internal transaction management system using their own trader codes. The computer system automatically records the date and time of the transaction, the proprietary trading code, and does not allow traders to change these details;
c) Prices in proprietary trading must be independently verified to ensure they are consistent with market prices.
4. Internal procedures for settling proprietary trading must meet the following requirements:
a) Individuals and departments responsible for proprietary trading settlements must send and receive confirmations for completed proprietary trading transactions in accordance with appropriate legal confirmation methods (including monitoring and checking customer transaction confirmations, notifying customers if confirmations are not received or are incomplete or contain errors);
b) Transaction confirmations must include terms and transaction information. In cases where proprietary trading is conducted through brokers, confirmation content must include broker information;
c) Any discrepancies discovered during settlement must be promptly addressed by the department responsible for proprietary trading settlements.
Article 18. Compliance Department
1. Depending on the scale, conditions, and level of complexity of business operations, commercial banks and foreign bank branches shall determine the organizational structure, tasks, and authorities of the compliance department to ensure its independence and non-conflict of interest.
2. The tasks and authorities of the compliance department shall be decided by the General Director (Director) of commercial banks and foreign bank branches, ensuring that the compliance department has at least the following tasks:
a) Assist the General Director (Director) in:
(i) Implementing the provisions set out in point d, Clause 2, Article 5 of this Circular;
(ii) Reporting to the Board of Directors, Board of Members, parent bank, Audit Committee on serious violations in compliance with legal regulations, changes in relevant legal regulations according to internal regulations of commercial banks and foreign bank branches;
(iii) Reviewing and evaluating the provisions regarding the tasks and authorities of the compliance department to submit to the General Director (Director) for necessary amendments and supplements;
b) Regularly and urgently reporting to the General Director (Director) on the situation of compliance with legal regulations; reporting to the General Director (Director) and informing related departments about changes in relevant legal regulations according to internal regulations of commercial banks and foreign bank branches;
c) Supporting related departments in establishing and reviewing internal regulations to ensure compliance with legal regulations; handling issues related to compliance with legal regulations according to internal regulations of commercial banks and foreign bank branches.
Article 19. Information Exchange Mechanism
1. Commercial banks and foreign bank branches shall have an information exchange mechanism to ensure that all individuals at all levels and related departments are informed, disseminated, and publicized about the internal control system to understand clearly and consistently about policies, procedures, business objectives, and perform their duties, tasks, and authorities well.
2. The information exchange mechanism shall be implemented through management information systems and other information exchange mechanisms decided by commercial banks and foreign bank branches.
3. The information exchange mechanism shall ensure the following principles:
a) Information on objectives, strategies, policies, and procedures shall be exchanged from higher levels to lower levels and to related individuals and departments;
b) Information on the internal control system and operational results shall be exchanged from lower levels to higher levels (including the Board of Directors, Board of Members, parent bank, Audit Committee, General Director (Director)) and from branches and dependent units of commercial banks to the headquarters to grasp risk statuses and business operation situations of commercial banks and foreign bank branches;
c) Information on new products, activities in new markets, losses, fraud, and potential losses and fraud shall be promptly exchanged with the risk management department, internal audit department, and other related departments;
d) There shall be a direct, independent, and timely reporting mechanism to competent authorities regarding violations of laws, internal regulations, and professional ethics standards by individuals and departments to ensure confidentiality and protection of information providers;
đ) The frequency of information exchange shall ensure that the higher the risk, the more frequent the information exchange.
Article 20. Management Information System
1. Commercial banks and foreign bank branches shall have a management information system to provide internal information and reports to the Board of Directors, Board of Members, parent bank, Supervisory Board, General Director (Director), and related individuals and departments to perform functions and tasks ensuring compliance with this Circular.
2. The minimum management information system shall include:
a) Internal reports (at least including internal reports on internal control, risk management, internal assessment of capital adequacy, and internal audit as prescribed in Clause 4, Article 15, Articles 37, 40, 47, 52, 55, 58, 63, and 72 of this Circular) and other management information as prescribed internally by commercial banks and foreign bank branches;
b) Organizational structure for managing and operating the management information system, specifying the specific responsibilities of individuals and departments in using the management information system;
c) Collection, processing, storage, and provision of information; construction, sending, receiving, and processing of reports;
d) Appropriate information technology infrastructure.
3. The management information system must ensure:
a) Support the implementation of the information exchange mechanism as prescribed in Clause 1 and 3, Article 19 of this Circular;
b) Information and data provided must be complete, accurate, timely, and meet management requirements as prescribed in this Circular and internally by commercial banks and foreign bank branches; sources of information and data must be verified for reliability;
c) Update compliance with legal regulations and internal regulations of commercial banks and foreign bank branches;
d) Ensure security, safety of information and data, and have backup systems to ensure safe, effective, and uninterrupted storage and use of information;
đ) Be reviewed and evaluated at least annually and on an ad hoc basis; upgraded and updated regularly to meet the needs of management information, scale, structure, and complexity of business operations of commercial banks and foreign bank branches.
Chapter IV
RISK MANAGEMENT
Section 1
GENERAL PROVISIONS ON RISK MANAGEMENT
Article 21. Requirements for Risk Management
1. Commercial banks and foreign bank branches shall implement risk management to ensure the following requirements:
a) Manage significant risks in the business operations of commercial banks and foreign bank branches;
b) Fully identify, accurately measure, and continuously monitor to promptly prevent and mitigate significant risks;
c) Controlling risk status to ensure compliance with risk limits;
d) Decisions involving risks must be transparent, clear, and consistent with the risk management policy and risk limits.
Article 22. Risk Management Department
1. Depending on the scale, conditions, and complexity of business operations, commercial banks shall independently decide on the organizational structure of the second-line-of-defense risk management department and shall have at least the following functions:
a) Assist the Risk Committee in:
(i) Proposing and advising on the contents prescribed in Clause 2, Article 11 of this Circular;
(ii) Monitoring risk status against risk limits to warn and detect early risks and breaches of risk limits;
b) Coordinate with the first-line-of-defense to fully identify and monitor emerging risks;
c) Develop and use methods and models for assessing and measuring risks;
d) Control, prevent, and propose measures to mitigate emerging risks;
đ) Participate in risk-related content during the process of making risk decisions corresponding to each level of authority as prescribed internally by commercial banks and foreign bank branches;
e) Prepare stress testing scenarios as prescribed in point a, Clause 2, Article 28 of this Circular based on coordination with the business department, compliance department, and other relevant departments;
g) Conduct internal reporting on risk management as prescribed internally by commercial banks.
2. The organizational structure, functions, and tasks of the risk management department of foreign bank branches shall be decided by the parent bank.
Article 23. Internal regulations on risk management
1. The internal regulations on the internal control system of commercial banks and foreign bank branches stipulated in Clause 2, Article 5 of this Circular must include internal regulations on risk management, which shall at least contain the following contents:
a) The establishment, issuance, and implementation of risk management policies;
b) The establishment, issuance, and implementation of risk limits for each significant type of risk (including methods for establishing risk limits, individuals or departments responsible for establishing risk limits, allocation of risk limits, and handling violations of risk limits);
c) Identification, measurement, monitoring, and control of risks for each significant type of risk (including methods and models for measuring and controlling risks);
d) Stress testing;
đ) An internal reporting mechanism on risk management;
e) Risk management for new products and activities in new markets;
g) Other necessary contents according to the requirements for managing each significant type of risk;
2. Internal regulations on risk management must ensure the following principles:
a) Must be established in accordance with the business strategy, control culture, human resources, information technology conditions, and management information systems of commercial banks and foreign bank branches;
b) Risk statuses and violations in risk management must be reported promptly and fully to the Board of Directors, Board of Members, Supervisory Board, and parent bank; there must be mechanisms to handle violations in risk management.
Article 24. Risk Management Policy
1. The risk management policy of commercial banks is issued, amended, and supplemented by the Board of Directors and Board of Members. The authority to issue, amend, and supplement the risk management policy of foreign bank branches is implemented according to the provisions of the parent bank.
2. The minimum risk management policy includes the following contents:
a) Risk appetite including:
(i) Target capital adequacy ratio;
(ii) Profitability indicators: Return on Equity (ROE); Risk-Adjusted Return on Capital (RAROC);
(iii) Other indicators as prescribed internally by commercial banks and foreign bank branches;
b) List of significant risks as prescribed in this Circular;
c) Risk management strategy for each significant risk.
3. The risk management policy must ensure the following requirements:
a) Established for a minimum period of three years but not exceeding five years, reviewed periodically at least once a year, and reviewed urgently when changes occur in the business environment or legal framework to achieve risk management objectives;
b) In line with the interests of shareholders, owners, and contributors of commercial banks and parent banks as stipulated by law;
c) Consistent with the level of own capital and the availability of sources to increase own capital;
d) Continuous and consistent to ensure feasibility through economic cycles.
Article 25. Risk Limits
1. Risk limits of commercial banks are issued, amended, and supplemented by the General Director (Director) (including adjustments to risk limits). The authority to issue, amend, and supplement risk limits of foreign bank branches is implemented according to the provisions of the parent bank.
2. Risk limits must ensure:
a) Comply with restrictions to ensure safety in the operations of credit institutions and foreign bank branches as stipulated in the Law on Credit Institutions and the regulations of the State Bank;
b) Have risk limits for significant risks;
c) Comply with risk appetite, risk management strategy, and total assets allocated to that risk;
d) Be comprehensive and specific to control risks arising from business activities and departments involved in risky transactions;
đ) Must be reviewed and re-evaluated (adjusted if necessary) at least once a year or when significant changes affect the risk status according to the internal regulations of commercial banks and foreign bank branches. In cases where commercial banks loosen risk limits, the General Director (Director) must report to the Board of Directors and Board of Members after adjustment;
e) Be disseminated to relevant individuals and departments;
3. In cases where an activity, transaction, or product has different risk limits for different types of risks, commercial banks and foreign bank branches must apply more cautious risk limits.
Article 26. Risk Management for New Products and Activities in New Markets
1. Risk management for new products and activities in new markets of permitted business operations must ensure the following requirements:
a) There are criteria to identify new products and activities in new markets;
b) The process of providing new products and activities in new markets must comply with the principle that:
(i) For commercial banks, the Board of Directors, Board of Members approve the policy on providing new products and activities in new markets based on the proposal of the General Director (Director). The General Director (Director) approves the plan for providing new products and activities in new markets;
(ii) For foreign bank branches, the approval of policies and plans for providing new products and activities in new markets shall be carried out in accordance with the regulations of the parent bank.
2. The plan for providing new products and activities in new markets must be reviewed by the risk management department regarding risks, risk management measures, and specifically determine at least the following contents:
a) The scale, trial period for providing new products and activities in new markets based on the assessment of potential risks arising from the provision of new products and activities in new markets, their impact on capital and income to ensure compliance with the risk control capability of commercial banks and foreign bank branches;
b) The official provision time for new products and activities in new markets based on the evaluation of trial results against risk management indicators of commercial banks and foreign bank branches.
3. When officially providing new products and activities in new markets, commercial banks and foreign bank branches must issue regulations and procedures for providing new products and activities in new markets and manage significant risks of new products and activities in new markets.
Article 27. Identification, Measurement, Monitoring, and Control of Risks
1. Risk Identification:
Commercial banks and foreign bank branches must identify significant risks and interactions between these risks in transactions, products, activities, business processes, sources of risk, and determine the causes of risk.
2. Risk Measurement:
a) Commercial banks and foreign bank branches measure the level of risk based on the short-term and long-term impact of such risk on income, capital adequacy ratio, and the ability to achieve business objectives of commercial banks and foreign bank branches;
b) Risk measurement is conducted using methods and models (including internal credit rating systems). These risk measurement methods and models must be regularly tested and evaluated for accuracy and reasonableness according to the internal regulations of commercial banks and foreign bank branches. Data used in risk measurement methods and models must ensure reliability and verifiability;
c) Risk measurement ensures timely and accurate monitoring and effective risk control.
3. Risk Monitoring:
a) Commercial banks and foreign bank branches must monitor risk status and promptly assess and early warn about the possibility of exceeding risk limits to ensure safety in operations;
b) Internal reports on risk monitoring must be timely, accurate, comprehensive, and sent to relevant individuals and departments.
4. Risk Control:
a) Commercial banks and foreign bank branches must control risk statuses, transactions, and activities within corresponding risk limits;
b) Commercial banks and foreign bank branches have preventive, mitigating, and timely handling measures for risks to ensure compliance with risk limits and operational restrictions to ensure safety, and have mechanisms to supervise and inspect the implementation of these measures.
Article 28. Stress Testing
1. Commercial banks and foreign bank branches shall conduct stress testing to ensure:
a) Liquidity stress tests at least every six months and on an ad hoc basis;
b) Capital stress tests annually and on an ad hoc basis.
2. Stress testing shall be carried out as follows:
a) Develop at least two scenarios, including a business-as-usual scenario and a stress scenario for the next stress testing period. The selected scenarios must reflect the likelihood based on past events and macroeconomic forecasts;
b) Calculate the impact of assumptions on liquidity and capital adequacy ratios in each scenario;
c) Prepare a report on the results of stress testing (including quantitative data and qualitative analyses and assessments).
3. Based on the results of stress testing, commercial banks and foreign bank branches must:
a) Evaluate compliance with liquidity coverage ratio, loan-to-deposit ratio, short-term funding usage for medium- and long-term lending, and other restrictions to ensure safety in operations according to internal regulations of commercial banks and foreign bank branches;
b) Develop contingency plans in case of non-compliance with liquidity requirements;
c) Calculate economic capital in the stress scenario to determine target capital.
Section 2
CREDIT RISK MANAGEMENT
Article 29. Requirements, Risk Management Strategies, Credit Risk Limits
1. Credit risk management shall be implemented throughout the process of considering, assessing, approving, and managing credit to comply with the State Bank's regulations and relevant laws.
2. A minimum credit risk management strategy shall include the following contents:
a) Target non-performing loan ratio, target bad credit ratio by customer category, industry, and economic sector;
b) Principles for determining credit risk compensation costs in interest rate calculation and product pricing methods based on the level of credit risk of customers;
c) Principles for applying measures to mitigate credit risks (including approval authority for such measures).
3. Minimum credit risk limits shall include the following limits:
a) Credit limits for customer categories, industries, and economic sectors based on their repayment capacity and credit risk;
b) Credit limits by product and guarantee form based on the corresponding credit risk of products and guarantee forms.
Article 30. Internal Credit Rating System
1. Commercial banks and foreign bank branches must have an internal credit rating system in accordance with the State Bank's regulations on asset classification, provisioning levels, risk provisioning methods, and the use of provisions to address risks in the operation of credit institutions and foreign bank branches.
2. The internal credit rating system must meet the following requirements:
a) The rating model must quantify criteria to assess the probability of customers failing to fulfill their debt repayment obligations (including macroeconomic and business environment factors affecting the ability to repay);
b) Have a database and data management methods to quantify credit risk as required;
c) The results of the internal credit rating system must be independently evaluated;
d) Provide complete information about the internal credit rating system upon request for internal audit, independent audit organizations, and other competent authorities when conducting internal audits, inspections, supervision, and independent audits.
Article 31. Measurement, Monitoring, and Control of Credit Risk
1. Commercial banks and foreign bank branches must use internal credit rating systems, methods, and models to measure losses for measuring credit risk.
2. Commercial banks and foreign bank branches must monitor and control credit risk for each loan and the entire loan portfolio, and take measures to address when credit quality deteriorates, ensuring at least the following requirements:
a) Monitor the results of loan classification;
b) Evaluate the adequacy of risk provisions as prescribed by the State Bank;
c) Control actual credit risk status to comply with loan limits and credit risk levels as prescribed by law and internal regulations of commercial banks and foreign bank branches.
3. The monitoring and control of credit risk shall include at least the following contents:
a) The roles and responsibilities of individuals and departments responsible for monitoring and controlling credit risk;
b) Implementing loan classification, establishing risk provisions, and using risk provisions to handle credit risks;
c) Evaluating and monitoring credit risk for each loan and loan portfolio;
d) Controlling credit risk according to allocated credit risk limits for each loan and loan portfolio, including: Minimum frequency of remote and on-site inspections to collect information for credit risk monitoring;
đ) Criteria for evaluating and methods for determining the degree of deterioration in credit quality for each loan and loan portfolio; early warning mechanisms when there is a risk of customer credit quality deterioration.
Article 32. Credit Approval Review
1. Commercial banks and foreign bank branches must ensure that credit approval reviews include at least the following contents:
a) Specifically identify related parties of customers, total credit debt of customers and related parties;
b) Base on the credit rating results of customers (if available), including credit ratings from other financial institutions and foreign bank branches;
c) Assess the completeness of documentation, legal status, and recoverability of collateral for loans secured by collateral;
d) Review the ability of third-party guarantors to fulfill their commitment obligations for guaranteed loans.
2. During the review process, if other information channels outside commercial banks and foreign bank branches are used for customers, commercial banks and foreign bank branches must verify the quality of the information and the independence of the information channel from the borrower.
Article 33. Approval of Decisions Involving Credit Risk
Commercial banks and foreign bank branches must ensure that decisions involving credit risk approvals include:
1. Approval authority for decisions involving credit risk and cases transferred to higher authorities for approval must be determined based on quantitative and qualitative criteria.
2. In cases of approval through a committee mechanism, the approval committee must have a record of approval or equivalent form, clearly stating the reasons for approval or non-approval and recording (or attaching) all opinions of committee members. Committee members must be responsible for their decisions.
3. Information provided for approving decisions involving credit risk must be complete and appropriate to the scale and type of credit. The list of information serving as the basis for approving decisions involving credit risk must be evaluated by the risk management department to ensure effective credit risk management.
Article 34. Credit Management
1. Commercial banks and foreign bank branches shall implement credit management to meet the following requirements:
a) Specify the responsibilities and authorities of individuals and departments in establishing and storing credit files to ensure that credit files are complete as prescribed by law;
b) Disburse funds in accordance with the purpose of capital usage and the type of credit provision;
c) Supervise credit disbursements after they have been disbursed to ensure compliance with the following principles:
(i) Verify the use of borrowed funds and the implementation of other terms in the customer's credit agreement;
(ii) Evaluate factors affecting the customer's ability to repay debts;
(iii) Manage collateral assets in accordance with Article 36 of this Circular;
(iv) Monitor repayment schedules, remind customers to fulfill their repayment obligations when due, and promptly report to competent authorities when there is a risk that customers will not fulfill or delay fulfilling their repayment obligations.
2. Commercial banks and foreign bank branches must store credit files, information on the ability to fulfill repayment obligations and repayment history of customers, and other related information as prescribed by law.
Article 35. Management of Problem Credit Disbursements
1. Commercial banks and foreign bank branches must manage problem credit disbursements to take timely measures.
2. The management of problem credit disbursements must meet the following requirements:
a) Clearly define criteria and methods for identifying problem credit disbursements;
b) Strengthen assessment of the customer's ability to repay debts and debt recovery from security measures;
c) Measures to handle and restructure problem credit provisions, and plans for debt recovery;
d) Strengthen monitoring, supervision, and debt recovery;
d) Determine the responsibility of individuals and departments related to bad credit disbursements (if any) to take appropriate measures.
Article 36. Collateral Asset Management
Commercial banks and foreign bank branches must manage collateral assets to meet the following requirements:
1. Specifically identify types of collateral assets that commercial banks and foreign bank branches accept as security in accordance with legal provisions.
2. Have a method to determine the value of assets in accordance with legal provisions on valuation or engage an organization with appraisal functions to determine market value, recovery value, and time to auction and dispose of each type of collateral asset as a basis for internal collateral asset management of commercial banks and foreign bank branches; determine collateral assets meeting conditions for deduction and deduction ratio when setting aside provisions as prescribed by the State Bank.
3. Regularly or irregularly evaluate collateral assets according to the principle that collateral assets with greater value fluctuations must be evaluated more frequently, as stipulated internally by commercial banks and foreign bank branches.
4. Have regulations on receiving and safely storing collateral assets.
Article 37. Internal Reports on Credit Risk
1. At least quarterly or irregularly, commercial banks and foreign bank branches shall prepare internal reports on credit risk as prescribed in Clause 2 of this Article.
2. Minimum contents of internal reports on credit risk include the following:
a) Credit quality for credit disbursements, credit portfolios by customer category, industry, economic sector;
b) Problem loans, measures to handle problem loans.
c) Customers, industries, economic sectors with actual credit balances higher than the credit risk limits prescribed at point a, Clause 3, Article 29 of this Circular;
d) Value of collateral assets, collateral asset portfolios by type of collateral asset;
đ) Situation of provisioning for risk, use of risk provisions to handle credit risks.
e) Early warning of potential breaches of credit risk limits.
g) Violations in credit risk management and reasons for such violations.
h) Recommendations and suggestions for credit risk management to the reporting authority;
i) Results of implementing requirements and recommendations on credit risk management from internal audit, the State Bank, independent auditors, and other relevant agencies.
Section 3
MARKET RISK MANAGEMENT
Article 38. Market Risk Management Strategy, Market Risk Limits
1. The minimum market risk management strategy shall include the following contents:
a) The level of market risk status of the trading book that must implement market risk prevention measures;
c) Principles for applying market risk prevention measures (including specific market risk prevention tools and approval authority for such measures).
2. Minimum market risk limits shall include:
a) Interest rate risk limit: Interest rate risk limit for the product portfolio, transaction officer limit, stop-loss limit, total interest rate risk position limit on the trading book;
d) Commodity price risk limit: Limit for the product portfolio; transaction officer limit; stop-loss limit.
Article 39. Measurement, Monitoring, and Control of Market Risk
1. Commercial banks and foreign bank branches shall implement measurement, monitoring, and control of market risk to ensure:
a) There are independent individuals or departments responsible for measuring, monitoring, and controlling market risk from the trading department;
b) Information technology infrastructure and databases for measuring, monitoring, and controlling market risk;
c) Specific authorization levels for approving and implementing market risk prevention measures;
(i) Fully assess factors affecting the value of proprietary trading transactions and underlying asset values;
(ii) Be estimated based on market information and data collected from reliable sources. Market information and data must be independently evaluated for reliability and appropriateness according to the internal regulations of commercial banks and foreign bank branches;
(iii) Be reviewed and assessed at least annually or as needed to determine the accuracy and limitations of the pricing model for appropriate adjustments.
2. Methods and models for measuring and monitoring market risk according to interest rate risk, foreign exchange risk, stock price risk, and commodity price risk must meet the following requirements:
a) Measure and monitor market risk status associated with each type of financial asset, financial liability, and off-balance-sheet items;
b) Parameters and assumptions must be tested and adjusted based on comparisons between actual developments and results obtained from these methods and models.
3. Market risk control must ensure:
a) Early warning about potential breaches of market risk limits;
b) At the end of each trading day, commercial banks and foreign bank branches must evaluate compliance with market risk limits based on actual market risk status (including hedging transactions) and adjust market risk limits if necessary;
c) Adjustments to market risk limits must be promptly communicated to transaction officers, trading units, and relevant individuals or departments to conduct proprietary trading and manage market risk for the next trading day.
Article 40. Internal Report on Market Risk
1. By the end of each business day at the latest, commercial banks and foreign bank branches shall prepare an internal daily report on market risk for trading accounts, which shall include at least the following contents:
a) The total status of market risk for the day;
b) Discoveries from monitoring activities related to proprietary trading transactions;
c) Actual profit (loss) and projected profit (loss) based on market value of proprietary trading transactions;
d) Daily transaction limits and the usage of these limits up to the end of the trading day.
2. At least every six months, commercial banks and foreign bank branches shall prepare an internal report on market risk, which shall include at least the following contents:
a) The total status of market risk compared to the market risk limit at the reporting time;
b) Results of reviewing and evaluating methods, models for measuring, monitoring market risk (if applicable);
c) Actual profit (loss) and projected profit (loss) based on market value of proprietary trading transactions;
d) Violations in market risk management and reasons for such violations (if applicable);
đ) Abnormal cases in proprietary trading activities, changes in key assumptions of market risk measurement methods;
e) Recommendations and suggestions on market risk management to the report recipient;
g) Results of implementing requirements and suggestions on market risk management, proprietary trading activities from internal audit, State Bank of Vietnam, independent auditors, and other competent authorities.
Section 4
OPERATIONAL RISK MANAGEMENT
Article 41. Operational Risk Management Strategy, Operational Risk Limits
1. The operational risk management strategy shall include at least the following contents:
a) Principles for implementing operational risk management;
b) Principles for using outsourcing, insurance purchases, and technology applications;
c) Cases requiring plans to maintain continuous operations, including:
(i) Loss of important documents, databases;
(ii) Information technology system failures;
(iii) Force majeure events (war, natural disasters, fire, explosion...).
2. Operational risk limits shall include the following limits:
b) Non-financial loss limits (including reputation, legal obligations).
Article 42. Identification, Measurement, Monitoring, and Control of Operational Risks
1. Commercial banks and foreign bank branches must fully identify operational risks in all products, business activities, business processes, information technology systems, and other management systems.
2. The identification of operational risks shall be carried out in the following cases:
a) Internal fraud due to fraudulent acts, theft of assets, violation of internal strategies, policies, and regulations involving at least one individual of the commercial bank or foreign bank branch (including improper conduct, exceeding authority, theft, exploiting internal information for personal gain);
b) External fraud due to fraudulent acts, theft of assets caused by external parties without assistance or collusion from individuals or departments of the commercial bank or foreign bank branch (including theft, robbery, counterfeit bank cards, bank documents, unauthorized access to information technology systems to steal data, money);
c) Labor policy and workplace safety not in compliance with labor contracts, laws on labor, health protection, and workplace safety;
d) Inadvertent violation of regulations related to customers, product delivery procedures, and product characteristics when performing assigned functions and tasks within their authority towards customers (including violation of customer information confidentiality, anti-money laundering regulations, providing services contrary to regulations);
đ) Damage, loss of property, tools, equipment due to force majeure events, human actions, and other incidents;
e) Business interruption due to information technology system failures;
g) Limitations and inadequacies in transaction procedures, transaction controls, and transaction management;
h) Other cases as stipulated internally by commercial banks and foreign bank branches.
a) Using findings from internal and independent audits (Audit findings);
b) Collecting and analyzing internal and external loss data to determine internal losses and those of the entire commercial banking system, foreign bank branches;
c) Conducting self-assessment of operational risk controls (Risk Control Self Assessment - RCSA) to assess the effectiveness of operational risk control before and after implementation;
d) Mapping business processes (Business Process Mapping - BPM) to determine the level of operational risk for each business process, overall operational risk of business processes, and the relationship between these risks;
đ) Key performance indicators and risk indicators to monitor factors affecting operational risk and identify limitations, issues, and potential losses;
e) Scenario analysis to identify sources of operational risk and control, mitigation requirements for operational risk in possible scenarios and events.
4. Commercial banks and foreign bank branches shall control operational risks through the control activities stipulated in Article 15 of this Circular and other measures as stipulated internally by commercial banks and foreign bank branches. In cases where actual losses exceed operational risk limits, commercial banks and foreign bank branches must take enhanced measures to control and mitigate such operational risks in the future.
Article 43. Management of operational risks for outsourcing activities
1. Management of operational risks in outsourcing activities shall be carried out through:
a) Managing outsourcing activities as prescribed in Clause 2 of this Article;
b) Identify, measure, monitor, and control operational risks arising from outsourcing activities in accordance with Article 42 of this Circular.
2. Management of outsourcing activities shall include, at a minimum:
a) Determine the scope of outsourcing activities;
b) Delegating approval and decision-making authority for outsourcing activities;
c) Assess the capability of the outsourcing service provider to meet the requirements and objectives set out for outsourcing activities before signing the outsourcing contract; evaluate the outsourcing service provider's ability to perform the contract during its implementation;
d) Establish principles for negotiating outsourcing contracts that ensure strictness, completeness, protection of ownership rights and data security, customer information confidentiality, and the right to terminate outsourcing contracts; the extent and scope of outsourcing activities; specific responsibilities of commercial banks, foreign bank branches, and outsourcing service providers; and dispute resolution clauses in accordance with the law;
đ) Develop or require the outsourcing service provider to develop a continuity plan for outsourcing activities in accordance with Article 46 of this Circular.
Article 44. Management of operational risks in technology applications
1. Commercial banks, branches of commercial banks manage operational risks in the application of electronic transactions, online transactions, automated transactions, mobile transactions, and other technologies (hereinafter referred to as technology applications) through:
a) Managing technology application in accordance with Clause 2 of this Article;
b) Identifying, measuring, monitoring, and controlling operational risks arising from technology applications in accordance with Article 42 of this Circular, ensuring at least the following:
(i) Identifying potential risks related to internal and external network systems, hardware, software, applications, transaction interfaces, operations, and human factors;
(ii) Measuring risk based on estimating losses when operational risks occur in business operations;
(iii) Monitoring and assessing the ability to maintain stable operations in the face of potential operational risks arising from technology applications;
(iv) Controlling and implementing measures to mitigate operational risks (if necessary) in technology application activities to ensure operational risk limits.
2. The management of technology applications by commercial banks, foreign bank branches must comply with the following requirements:
a) Having minimum regulations on managing technology applications including the following contents:
(i) The scope of minimum management of technology applications for information technology systems and databases;
(ii) Tasks, responsibilities, and authorities of individuals and units responsible for managing technology application;
(iii) Effective management during incidents and changes in technology application;
(iv) Authentication systems ensuring customer information security, transaction safety, and information technology systems;
b) Complying with the State Bank's regulations on electronic transactions in the banking sector; ensuring the safety and security of information technology systems for providing online banking services and related legal provisions.
Article 45. Purchasing insurance to reduce losses from operational risks
1. Commercial banks, foreign bank branches may purchase insurance to reduce losses arising from operational risks in accordance with the law, ensuring compatibility with their financial capacity and compensation for losses of commercial banks, foreign bank branches.
2. Commercial banks, foreign bank branches shall not use the purchase of insurance to replace operational risk management, must assess the effectiveness of reducing losses arising from operational risks through purchasing insurance, assess the capability of the insurance company in fulfilling the insurance contract, and any new risks (if any).
Article 46. Continuous Operation Maintenance Plan
1. Commercial banks and foreign bank branches must have a continuous operation maintenance plan in the cases specified in point c, Clause 1, Article 41 of this Circular.
2. The continuous business operations plan must meet at least the following requirements:
a) Suitable for the nature and scale of operations of commercial banks and foreign bank branches;
b) Having a backup system for personnel, information technology systems, and information databases;
c) Containing measures to minimize losses due to cessation of operations;
d) Able to restore interrupted business activities to normal status within the required timeframe;
đ) Subject to testing and periodic review at least annually to determine the effectiveness of the continuous operation maintenance plan and adjustments (if necessary).
Article 47. Internal Report on Operational Risk
1. At least every six months or at any time, commercial banks and foreign bank branches shall prepare an internal report on operational risk as stipulated in Clause 2 of this Article.
2. The minimum contents of the internal report on operational risk include the following:
a) Implementation of policies for managing operational risk, compliance with operational risk limits;
b) Cases of operational risk arising during the reporting period and reasons;
d) Events and external impacts affecting the operational risk of commercial banks and foreign bank branches;
đ) Changes in methods for measuring operational risk;
e) Business outsourcing activities and management of operational risk related to such activities;
g) Changes in technology applications (if any) and management of operational risk in technology applications;
h) Proposals and recommendations for managing operational risk;
i) Results of implementing requirements and recommendations for managing operational risk from internal audit, the State Bank, independent auditing organizations, and other competent authorities.
Section 5
LIQUIDITY RISK MANAGEMENT
Article 48. Requirements and Strategy for Liquidity Risk Management, Liquidity Risk Limits
1. Liquidity risk management must meet the following minimum requirements:
a) Maintaining sufficient liquid assets to meet liquidity needs under both normal and adverse liquidity conditions for commercial banks and foreign bank branches (including determining loss and costs when accessing liquidity in the market);
b) Implementing liquidity management as prescribed in Article 49 of this Circular;
c) Determining the cost of meeting liquidity needs and liquidity risk in internal capital valuation and business performance assessment for key business activities (including on-balance sheet and off-balance sheet activities).
2. The minimum liquidity risk management strategy shall include the following contents:
a) Principles for managing liquidity;
b) A diversification strategy for funding sources and funding maturities to increase stability in liabilities and support daily liquidity;
c) Principles for conducting stress tests on liquidity.
3. Liquidity risk limits include:
a) Risk limits ensuring compliance with legal regulations on liquidity coverage ratio, loan-to-deposit ratio, short-term capital usage for medium- and long-term lending;
b) Other risk limits according to internal regulations of commercial banks and foreign bank branches.
Article 49. Liquidity Management
1. Commercial banks and foreign bank branches shall implement liquidity management for:
a) Commercial banks, branches, and other dependent units of commercial banks and foreign bank branches;
b) Vietnamese dong and foreign currencies (minimum US dollars, including other foreign currencies convertible to US dollars).
2. Minimum liquidity management includes the following contents:
a) Daily liquidity management to ensure monitoring of daily liquidity status, identifying sources of funds and the ability to mobilize these sources to ensure daily liquidity, forecasting situations that abnormally change daily liquidity, and proposing measures to address them;
b) Management of highly liquid assets based on market value and their convertibility into cash to meet liquidity requirements under normal market conditions and liquidity-constrained markets;
c) Management of funding sources to ensure statistical averages of non-interest-bearing deposit balances over a minimum period of 30 days, stable maintainable deposit balances (core deposits), and other funding source indicators according to internal regulations of commercial banks and foreign bank branches;
d) Minimum cash flow management to ensure the establishment of maturity schedules for the next day and specific periods (one week, one month, three months, six months, one year) to determine cash flow discrepancies through comparing outflows and inflows, ensuring compliance with State Bank of Vietnam's regulations on limits and safety ratios in commercial bank operations, foreign bank branches, and other liquidity ratios according to internal regulations of commercial banks and foreign bank branches;
đ) Management of liquidity sources to ensure assessment of access to liquidity sources to meet future liquidity needs under normal market conditions and liquidity-constrained markets.
Article 50. Identification, Measurement, Monitoring, and Control of Liquidity Risk
1. Identification of liquidity risk must ensure:
a) Based on analyzing liquidity needs, liquidity sources of each business activity, asset/debt structure, and cash flows of on-balance-sheet and off-balance-sheet items, and market liquidity accessibility;
b) Identifying liquidity risks arising from credit risk, market risk, operational risk, reputation risk, and other risks.
2. Minimum measurement and monitoring of liquidity risk must ensure the following requirements:
a) Having appropriate tools to measure minimum liquidity risk for:
(i) Future cash flows of assets/debts;
(ii) Unusual liquidity needs and cases where off-balance-sheet obligations must be fulfilled;
(iii) Transaction currency;
(iv) Banking agency, custody, and payment activities;
b) Monitoring compliance with the solvency ratio, loan-to-deposit ratio, short-term capital usage for medium- and long-term loans, and other liquidity ratios (if applicable).
3. Control of liquidity risk must ensure:
a) The state of liquidity risk ensures compliance with liquidity risk limits;
b) Having early warning indicators of liquidity risk to take measures to address temporary and long-term liquidity shortages.
Article 51. Liquidity Stress Testing
1. Commercial banks and foreign bank branches shall have methods for calculating the impact of assumptions to ensure the ability to fulfill obligations, commitments, and comply with liquidity risk limits. The assumptions and methods for calculating the impact of these assumptions on liquidity must be reviewed and self-assessed for appropriateness.
2. The adverse scenarios prescribed in point a, Clause 2, Article 28 of this Circular shall include at least assumptions regarding deposits and credit quality.
3. The contingency plan prescribed in point b, Clause 3, Article 28 of this Circular shall minimally include the following contents: anticipated measures for handling sources of funds, fund usage, future cash flows to ensure compliance with the requirements stipulated in Clause 1 of this Article.
Article 52. Internal Report on Liquidity Risk
1. At least quarterly or at any time deemed necessary, commercial banks and foreign bank branches shall prepare internal reports on liquidity risk as prescribed in Clause 2 of this Article.
2. The internal report on liquidity risk shall minimally include the following contents:
a) Assessment of the credit rating index of commercial banks, foreign bank branches and the liquidity situation in the market;
b) Structure of the balance sheet; new capital raising products; depositors; term and interest rates of deposits;
c) Sources of liquidity, cash flow differences, term of capital sources, compliance with liquidity risk limits.
d) Results of liquidity stress testing (if applicable) during the reporting period;
đ) Recommendations and suggestions for managing liquidity risk to the reporting authority;
e) Results of implementing the requirements and recommendations for managing liquidity risk from internal audit, State Bank, independent auditors, and other competent authorities.
Chapter 6
CONCENTRATED RISK MANAGEMENT
Article 53. Concentration Risk Management Strategy, Concentration Risk Limits
1. The concentrated risk management strategy shall apply at minimum to:
a) Credit activities;
b) Proprietary trading activities.
2. The minimum concentrated risk management strategy shall include the following contents:
a) For credit activities:
(i) Principles for determining concentration limits by credit product, customer, industry, economic sector;
(ii) Criteria for identifying related parties of customers in accordance with the provisions of the law;
(iii) Principles for determining the level of diversification and interaction between credit products, industries, and economic sectors;
b) For proprietary trading activities:
(i) Principles for determining concentration limits for proprietary trading activities by trading partner, trading product, currency type;
(ii) Criteria for identifying the proprietary trading portfolio to apply concentration limits for proprietary trading activities ensuring diversification and interaction as prescribed by commercial banks and foreign bank branches;
3. Minimum concentrated risk limits include:
a) For credit activities:
(i) Credit limit for one customer, customer and related party compared to total outstanding balance;
(ii) Concentration limits for credit products and economic sectors based on the proportion of outstanding credit balances of credit products and economic sectors compared to total outstanding balances;
b) For proprietary trading activities: concentration limits for trading partners, trading products, and currency types based on the proportion of balances of trading partners, trading products, and currency types compared to total proprietary trading balances.
Article 54. Identification, Measurement, Control of Concentration Risk
1. Commercial banks and foreign bank branches must identify minimum concentration risks in lending activities and proprietary trading activities, including:
a) Items recorded as on-balance-sheet and off-balance-sheet items of commercial banks and foreign bank branches;
b) Items not recorded in accordance with accounting laws.
2. Commercial banks and foreign bank branches shall measure concentration risk based on assessing the impact on income of each lending activity and proprietary trading activity with concentration risk.
3. Commercial banks and foreign bank branches shall control concentration risk as follows:
a) Monitor, check credit outstanding balances, proprietary trading balances according to concentrated risk limits; issue early warnings for balances, transactions approaching concentrated risk limits;
b) Take timely measures for cases exceeding concentration risk limits.
Article 55. Internal Report on Concentrated Risk
1. Commercial banks and foreign bank branches shall prepare internal reports on concentrated risk at least every six months or at any time as specified in Clause 2 of this Article.
2. The minimum contents of the internal report on concentrated risk include the following:
a) Credit structure by credit product, customer, industry, and economic sector;
b) Portfolio trading transaction structure by trading partner, transaction product, currency type;
c) Implementation status of concentration risk limits, reasons for exceeding limits (if any);
d) Proposals and recommendations for managing concentrated risk to the reporting level;
đ) Results of implementing requirements and recommendations for managing concentrated risk from internal audit, State Bank of Vietnam, independent auditors, and other competent authorities.
Section 7
MANAGEMENT OF INTEREST RATE RISK ON THE BALANCE SHEET
Article 56. Interest Rate Risk Management Strategy on the Balance Sheet, Interest Rate Risk Limits on the Balance Sheet
1. The minimum contents of the interest rate risk management strategy on the balance sheet include the following:
a) Minimum principles for managing interest rate risk on the balance sheet based on the following indicators:
(i) Repricing gap profile: the difference between the value of financial assets and financial liabilities with interest rates reset at the same time;
(ii) Measurement indicators of the impact of interest rate changes including one or two of the following indicators:
- Change in Net Interest Income (ΔNII): the degree of change in net interest income due to changes in interest rates from financial assets, financial liabilities, and off-balance-sheet items with interest rates on the balance sheet;
- Change in Economic Value of Equity (ΔEVE): the degree of change in the present value of cash inflows from financial assets and cash outflows from financial liabilities due to changes in interest rates;
b) Principles for using interest rate risk mitigation tools (including approval authority for such tools).
2. The minimum interest rate risk limits include:
a) Limit on the difference between the value of financial assets and financial liabilities with interest rates reset at the same time;
b) Limit on the change in net interest income due to interest rate changes and/or limit on the change in economic value of equity due to interest rate changes according to the interest rate risk management strategy on the balance sheet.
Article 57. Identification, Measurement, Monitoring, and Control of Interest Rate Risk on the Balance Sheet
1. Commercial banks and foreign bank branches shall implement identification, measurement, monitoring, and control of interest rate risk on the balance sheet in accordance with the following minimum requirements:
a) A process for identifying, measuring, monitoring, and controlling interest rate risk on the balance sheet at least quarterly and at any time as stipulated internally by commercial banks and foreign bank branches;
b) Departments responsible for measuring, monitoring, and controlling interest rate risk on the balance sheet must be independent from departments generating interest rate risk on the balance sheet;
c) Information technology infrastructure and databases to measure, monitor, control, and produce internal reports on interest rate risk on the balance sheet.
2. Identification of interest rate risk on the balance sheet must determine the causes and factors leading to interest rate risk on the balance sheet (including new risks arising from the implementation of interest rate risk mitigation activities);
3. Measurement and monitoring of interest rate risk on the balance sheet must ensure:
a) Tracking the times of new interest rate setting and interest rate repricing of financial assets and financial liabilities;
b) Having appropriate methods for measuring interest rate risk on the balance sheet consistent with the interest rate risk management principles specified in Point a, Clause 1, Article 56 of this Circular and based on capital stress testing as stipulated in Article 60 of this Circular;
c) Measuring items with interest rates recorded as on-balance-sheet items, off-balance-sheet items, VND-denominated items, or foreign currency items with a value of 5% or more of total assets of commercial banks and foreign bank branches;
d) Tracking the times of new interest rate setting and interest rate repricing of financial assets and financial liabilities. In cases where the maturity period cannot be determined, the time of new interest rate setting may be assumed, and the assumption must be approved by authorized personnel according to internal regulations of commercial banks and foreign bank branches.
4. Control of interest rate risk on the balance sheet must ensure:
a) The status of interest rate risk on the balance sheet complies with interest rate risk limits on the balance sheet;
b) Early warning for cases approaching interest rate risk limits on the balance sheet and timely measures for cases exceeding interest rate risk limits on the balance sheet.
Article 58. Internal Report on Interest Rate Risk in Banking Books
1. At least quarterly or at any time deemed necessary, commercial banks and foreign bank branches shall prepare internal reports on interest rate risk in banking books as specified in Clause 2 of this Article.
2. The minimum contents of the internal report on interest rate risk in banking books shall include the following:
a) Interest rate differential status, net income change index, economic value of equity change index (if applicable);
b) Compliance with interest rate risk limits in banking books;
c) Interest rate risk management tools in banking books and the results of implementing such tools;
d) Proposals and recommendations for managing interest rate risk in banking books to the reporting level;
đ) Results of implementing requirements and recommendations for managing interest rate risk in banking books from internal audit, State Bank of Vietnam, independent auditors, and other competent authorities.
Chapter V
INTERNAL ASSESSMENT OF CAPITAL ADEQUACY
Article 59. Requirements and Contents of Internal Assessment of Capital Adequacy
1. The internal assessment of capital adequacy must ensure:
a) Compliance with the State Bank of Vietnam's capital adequacy ratio regulations;
b) Maintaining the target capital adequacy ratio under normal operating scenarios and adverse scenarios;
c) Alignment with risk appetite and based on the development of significant risks;
d) Serving as a basis for developing and adjusting business plans of commercial banks and foreign bank branches;
đ) Conducting at least annually and at any time when there are changes in the business environment that may affect risks and capital sources, leading to non-compliance with risk appetite capital targets.
2. Commercial banks and foreign bank branches shall conduct internal assessments of capital adequacy for a minimum of three years but not more than five consecutive years according to the following steps:
a) Measuring risks for significant types of risks and determining economic capital based on business plans as guided in Appendix No. 03 issued together with this Circular;
b) Conducting stress tests to determine economic capital under adverse scenarios;
c) Determining target capital and expected own capital as guided in Appendix No. 03 issued together with this Circular;
d) Developing a capital plan;
đ) Monitoring capital adequacy to manage capital according to target capital and adjust the capital plan (if necessary);
e) Reviewing the internal assessment process of capital adequacy.
Article 60. Stress Testing
a) For interest rate assumptions: Calculating the impact on the capital adequacy ratio based on corresponding changes in total assets calculated according to operational risk, market risk (interest rate risk), and interest rate risk in banking books according to interest rate assumptions;
b) For exchange rate assumptions: Calculating the impact on the capital adequacy ratio based on corresponding changes in total assets calculated according to operational risk, market risk (foreign exchange risk) according to exchange rate assumptions;
c) For credit quality assumptions: Calculating the impact on the capital adequacy ratio based on corresponding changes in total assets calculated according to operational risk and credit risk according to credit quality assumptions.
2. The assumptions and methods to calculate the impact of these assumptions on the capital adequacy ratio as stipulated in Clause 1 of this Article must be reviewed and self-assessed for appropriateness according to the internal regulations of commercial banks and foreign bank branches.
Article 61. Capital Planning
1. Commercial banks and foreign bank branches must establish a minimum capital plan including the following contents:
a) A plan to increase capital in cases where expected own capital is not sufficient to meet the target capital, including:
(i) Sources of capital to increase Tier 1 and Tier 2 capital ensuring feasibility and compliance with legal regulations;
(ii) Timeframe for implementing the capital increase plan;
b) Dividend and profit distribution policies ensuring that expected own capital will be sufficient to meet the target capital;
c) Allocation of target capital according to risk-weighted assets for significant risks as a basis for determining risk limits;
d) Early warning levels to monitor and supervise compliance with risk-weighted assets allocation to take timely measures.
2. The commercial bank's capital plan shall be approved by the Board of Directors or the Board of Members upon proposal by the General Director (Director). The capital plan of foreign bank branches shall comply with the provisions of the parent bank.
Article 62. Reviewing Internal Assessment Procedures on Capital Adequacy
1. Internal assessment procedures on capital adequacy must be reviewed at least annually or ad hoc by an independent department from the department responsible for establishing and implementing internal assessment procedures on capital adequacy.
2. The review of internal assessment procedures on capital adequacy shall include at least the following contents:
a) The reasonableness of internal regulations on internal assessment of capital adequacy (including organizational structure, functions, and responsibilities of individuals and departments);
b) Consistency between risk appetite and business plans, and between risk-weighted assets and risk limits;
c) Accuracy and completeness of input data;
d) Reasonableness of assumptions used in stress testing scenarios;
đ) Feasibility of capital increase plans;
e) Recommendations and suggestions to competent authorities regarding internal assessment of capital adequacy (if any).
Article 63. Internal Report on Internal Assessment of Capital Adequacy
1. Annually, commercial banks and foreign bank branches shall prepare an internal report on internal assessment of capital adequacy as stipulated in Clause 2 of this Article.
2. The internal report on internal assessment of capital adequacy shall include at least the following contents:
a) Target capital, economic capital;
b) Results of stress testing on capital;
c) Capital plan;
d) Results of capital allocation;
đ) Results of reviewing internal assessment procedures on capital adequacy as prescribed in Article 62 of this Circular;
e) Results of implementing requirements and recommendations on internal assessment of capital adequacy from internal audit, State Bank, independent auditors, and other competent agencies.
Chapter VI
INTERNAL AUDIT
Article 64. Principles of Internal Audit
1. Internal audit shall be conducted based on the following principles:
(i) Internal auditors and the internal audit department shall not concurrently undertake tasks and responsibilities of individuals and departments in the first and second lines of defense;
(ii) Internal audit shall not be subject to any influence or interference from individuals and departments in the first and second lines of defense;
(iii) Internal auditors shall not conduct audits of:
- Internal regulations on internal audit and internal audit plans established by such internal auditors;
- Units and departments where the head is related to such internal auditors;
- Activities and departments where such internal auditors have performed and been responsible for within three years from the date they ceased performing and being responsible for such activities and departments;
(iv) Criteria for setting remuneration for the Head of Internal Audit and internal auditors must be separate from business results and operational outcomes of units and departments in the first and second lines of defense;
b) Objectivity principle:
(i) Audit findings in internal audit reports must be carefully analyzed and based on collected data and information;
(ii) Internal auditors must be honest when preparing and evaluating during the internal audit process;
(iii) Internal auditors have the right and obligation to report to competent authorities about issues related to objectivity during the internal audit process;
c) Professionalism principle:
(i) The internal audit department must have at least one internal auditor to conduct IT and technology application audits (hereinafter referred to as technology auditors);
(ii) Internal auditors must meet the standards prescribed in Article 66 of this Circular.
2. Internal audit must have measures to ensure compliance with the principles prescribed in Clause 1 of this Article during the internal audit process (including the process of drafting and submitting internal audit reports). The Head of Internal Audit shall promptly report to the Supervisory Board when violations or risks of violating the principles prescribed in Clause 1 of this Article are discovered.
Article 65. Coordination Mechanism
1. Commercial banks must have coordination mechanisms between:
a) The Board of Directors, Board of Members and the Supervisory Board, internal audit department as provided for in Clause 2 of this Article;
b) The General Director (Director), departments in the first and second lines of defense, the Supervisory Board, and the internal audit department as prescribed in Clause 3 of this Article.
2. The coordination mechanism of the Board of Directors, Board of Members, and the Supervisory Board, internal audit of commercial banks must ensure:
a) The Board of Directors, Board of Members cooperate with the internal audit department when conducting internal audit on high-level management supervision of the Board of Directors, Board of Members;
b) The Board of Directors, Board of Members implement recommendations of the Supervisory Board to the Board of Directors, Board of Members in the internal audit result report (if any) and inform the Supervisory Board of the implementation results.
3. The coordination mechanism of the General Director (Director), departments in the first and second lines of defense, and the Supervisory Board, internal audit department of commercial banks must ensure:
a) The General Director (Director) performs:
(i) Coordinate with the internal audit department when conducting internal audits on the supervision of senior management over the General Director (Director);
(ii) Directing the risk management department and relevant departments to provide complete information on risks for the internal audit department to draft internal audit plans.
(iii) The General Director (Director) shall receive internal audit reports, organize the implementation of recommendations made by the Audit Committee to the General Director (Director) in the internal audit report (if any), and report to the Audit Committee on the results of implementing such recommendations.
b) Departments under the first and second lines of defense perform:
(i) Provide full, truthful, and accurate information and documents upon request of the internal audit department during internal audits;
(ii) Promptly notify the internal audit department when discovering any deficiencies, violations, losses, or potential losses.
(iii) Facilitate the internal audit department in conducting internal audits.
4. A foreign bank branch must have a coordination mechanism between the General Director (Director) and the internal audit department of the foreign bank branch.
Article 66. Standards for Members of the Audit Committee and Internal Auditors
1. Members of the Audit Committee of commercial banks must meet the standards and conditions stipulated in the Law on Credit Institutions.
2. Commercial banks must establish standards for internal auditors that meet the following requirements:
a) Hold a bachelor's degree or higher in one of the fields of economics, business administration, law, accounting, auditing; hold a bachelor's degree or higher in information technology or a relevant specialty for technology auditors.
b) Have at least two years of direct work experience in the banking, finance, accounting, or auditing sectors for internal auditors, and at least three years for the Head of Internal Auditing; have at least two years of work experience in the information technology sector for technology auditors.
3. The standards for internal auditors of foreign bank branches shall be implemented according to the regulations of the parent bank.
Article 67. Professional Ethics Standards for Members of the Audit Committee and Internal Auditors
1. The professional ethics standards for members of the Audit Committee and internal auditors (including the Head of Internal Auditing and other positions within the internal audit department) of commercial banks must minimally include the following rules:
a) Integrity: perform assigned tasks honestly and truthfully.
b) Objectivity: perform assigned tasks objectively; evaluate fairly without personal interest or the interest of others.
c) Confidentiality: comply with laws and internal regulations of commercial banks and foreign bank branches regarding information confidentiality.
d) Responsibility: ensure the progress and quality of assigned tasks.
đ) Prudence: perform assigned tasks carefully based on evaluating the following factors:
(i) The complexity and importance of the content being internally audited.
(ii) The possibility of serious errors occurring during the internal audit process.
2. The professional ethics standards for internal auditors of foreign bank branches shall be implemented according to the regulations of the parent bank.
Article 68. Organizational Structure, Duties, Authorities, and Responsibilities of the Internal Audit Department
1. The organizational structure, duties, and authorities of the internal audit department of commercial banks shall be decided by the Audit Committee in accordance with the Law on Credit Institutions and this Circular.
2. The duties of the internal audit department of commercial banks must minimally include the following contents:
a) Conduct internal audits of the main office, branches, and other affiliated units of commercial banks.
b) Develop, review, and submit to the Audit Committee for issuance, amendment, or supplementation:
(i) Professional ethics standards for members of the Audit Committee and internal auditors as stipulated in Clause 1, Article 67 of this Circular.
(ii) Internal regulations of the Supervisory Board;
(iii) Internal audit plans;
c) Monitor and assess the implementation of recommendations made by the Audit Committee to the Board of Directors, Board of Members, General Director (Director), individuals, and departments.
d) Implement recommendations from the State Bank, independent auditing organizations, and other competent agencies regarding internal auditing.
đ) Prepare internal audit reports in accordance with Point d, Clause 2, Article 7 and Article 72 of this Circular.
3. The authorities of the internal audit department of commercial banks must minimally include the following contents:
a) Being equipped with necessary resources (human resources, finance, assets, and other tools);
b) Be provided with necessary information, documents, and files for internal auditing, including all texts and meeting minutes of the Board of Directors, Board of Members, General Director (Director).
c) Interview individuals related to internal auditing; recommend appropriate actions against individuals or departments who fail to cooperate during the internal audit process, in accordance with internal regulations of the commercial bank.
d) Attend internal meetings in accordance with the Charter and internal regulations of the commercial bank.
4. The responsibilities of the internal audit department and internal auditors of commercial banks must minimally include the following contents:
a) Maintain confidentiality of documents and information in accordance with laws and internal regulations of the commercial bank.
b) Be accountable to the Audit Committee for the performance of assigned tasks.
c) Internal auditors are accountable under the law and to the Head of Internal Auditing for assigned auditing tasks.
5. The organizational structure, duties, authorities, and responsibilities of the internal audit department and internal auditors of foreign bank branches shall be implemented according to the regulations of the parent bank.
Article 69. Internal Audit Regulations
The internal audit regulations of the Supervisory Board of commercial banks must include at least the following contents:
1. Organizational structure, tasks, and authorities of the internal audit department as stipulated in Article 68 of this Circular; standards for internal auditors as stipulated in Article 66 of this Circular; ethical standards for members of the Supervisory Board and internal auditors as stipulated in Article 67 of this Circular.
2. Criteria for determining risk levels, materiality levels, and frequency of conducting internal audits of activities, processes, and departments specified in point a, b Clause 2 Article 70 of this Circular; contents of internal audits as stipulated in Article 71 of this Circular.
3. Procedures for drafting and implementing the internal audit plan.
4. Procedures for reviewing and evaluating internal audit regulations, handling recommendations on internal audits from the State Bank, independent auditing organizations, and other competent agencies.
5. Regulations on hiring external experts and organizations to conduct internal audits.
6. Internal reporting system on internal audits as stipulated in Article 72 of this Circular.
Article 70. Internal Audit Plan
1. Internal audits of commercial banks are conducted annually and ad hoc according to the internal regulations of the Supervisory Board.
2. The annual internal audit plan of commercial banks is issued by the Supervisory Board upon the proposal of the Head of the Internal Audit Department after consulting with the Board of Directors, Board of Members, and General Director (Director). The preparation of the internal audit plan must ensure compliance with:
a) Risk-oriented principle: Activities, processes, and departments must be assessed for risk levels (high, medium, and low) according to the internal regulations of the Supervisory Board. High-risk activities, processes, and departments should be prioritized for internal audits and audited at least once a year.
b) Comprehensive coverage: All activities, processes, and departments must undergo internal audits. Activities, processes, and departments deemed significant according to the internal regulations of the Supervisory Board must be audited at least once a year.
c) Adequate resources and time for conducting ad hoc internal audits;
d) The annual internal audit plan must be adjusted when there are significant changes in the scale of operations, risk status, or internal audit resources according to the internal regulations of the Supervisory Board.
3. The annual internal audit plan of commercial banks must be issued before December 15 of the previous year and must include the scope of the audit, audit subjects, audit objectives, audit time, audit resources (including hiring experts and external organizations) to conduct internal audits, and other contents prescribed by the commercial bank.
4. The internal audit plan of foreign bank branches is decided by the parent bank.
5. Within ten working days from the date of issuance (amendment, supplementation), commercial banks and foreign bank branches must submit their internal audit plans to the State Bank (Bank Inspection and Supervision Agency).
Article 71. Contents of Internal Audits
1. Internal audits of commercial banks are carried out based on the provisions of Clause 2 Article 41 of the Law on Credit Organizations, including the following contents:
a) Independent examination and evaluation of compliance with mechanisms, policies, and internal regulations regarding high-level supervision and management, internal control, risk management, and internal assessment of capital adequacy by the Board of Directors, Board of Members, General Director (Director), individuals, and departments, including identifying existing issues, limitations, and causes.
b) Independent review and evaluation of the appropriateness and compliance with laws of mechanisms, policies, and internal regulations regarding high-level supervision and management, internal control, risk management, and internal assessment of capital adequacy, including identifying existing issues, limitations, and causes.
c) Recommendations and suggestions to competent authorities and related departments to address existing issues and limitations.
d) Other contents as stipulated by the internal audit department's internal regulations.
2. The contents of internal audits of foreign bank branches are implemented according to the regulations of the parent bank.
Điều 72. Báo cáo nội bộ về kiểm toán nội bộ
1. Ngân hàng thương mại phải lập báo cáo kết quả kiểm toán nội bộ theo quy định tại khoản 2 Điều này và báo cáo kết quả tự đánh giá kiểm toán nội bộ theo quy định tại khoản 3 Điều này như sau:
a) Sau khi kết thúc kiểm toán nội bộ, bộ phận kiểm toán nội bộ trình Ban kiểm soát phê duyệt báo cáo kết quả kiểm toán nội bộ để gửi Hội đồng quản trị, Hội đồng thành viên, Tổng giám đốc (Giám đốc) theo quy định nội bộ của Ban kiểm soát của ngân hàng thương mại;
b) Trong thời hạn 30 ngày kể từ ngày kết thúc năm tài chính, bộ phận kiểm toán nội bộ trình Ban kiểm soát báo cáo kết quả tự đánh giá kiểm toán nội bộ theo quy định nội bộ của Ban kiểm soát.
2. Nội dung báo cáo kết quả kiểm toán nội bộ (kiểm toán nội bộ định kỳ hằng năm và kiểm toán nội bộ đột xuất) bao gồm các nội dung sau đây:
a) Tình hình thực hiện nội dung, phạm vi kiểm toán trong năm tài chính;
b) Việc tuân thủ cơ chế, chính sách, quy định nội bộ về giám sát của quản lý cấp cao, kiểm soát nội bộ, quản lý rủi ro và đánh giá nội bộ về mức đủ vốn của Hội đồng quản trị, Hội đồng thành viên, Tổng giám đốc (Giám đốc), cá nhân, bộ phận;
c) Sự phù hợp, tuân thủ quy định của pháp luật và quy định tại Thông tư này của cơ chế, chính sách, quy định nội bộ về giám sát của quản lý cấp cao, kiểm soát nội bộ, quản lý rủi ro và đánh giá nội bộ về mức đủ vốn;
d) Các tồn tại, hạn chế được phát hiện khi thực hiện kiểm toán nội bộ và các kiến nghị đối với cấp có thẩm quyền và các bộ phận liên quan;
đ) Các nội dung khác.
3. Nội dung báo cáo kết quả tự đánh giá kiểm toán nội bộ bao gồm các nội dung sau đây:
a) Đánh giá kết quả thực hiện nhiệm vụ kiểm toán nội bộ trong năm báo cáo; rà soát, đánh giá lại (bao gồm đề nghị sửa đổi, bổ sung) quy định nội bộ của Ban kiểm soát; đề xuất và kiến nghị (nếu có);
b) Tình hình thực hiện các kiến nghị của Hội đồng quản trị, Hội đồng thành viên, Tổng giám đốc (Giám đốc), cá nhân, bộ phận đối với kiểm toán nội bộ trong năm báo cáo;
c) Tình hình thực hiện các kiến nghị của Ngân hàng Nhà nước, tổ chức kiểm toán độc lập và các cơ quan chức năng khác đối với kiểm toán nội bộ trong năm báo cáo;
d) Các nội dung khác.
4. Nội dung báo cáo nội bộ về kiểm toán nội bộ của chi nhánh ngân hàng nước ngoài thực hiện theo quy định của ngân hàng mẹ.
Chương VII
ĐIỀU KHOẢN THI HÀNH
Điều 73. Hiệu lực thi hành
1. Thông tư này có hiệu lực thi hành kể từ ngày 01 tháng 01 năm 2019, trừ nội dung quy định tại khoản 2 Điều này.
2. Ngân hàng thương mại, chi nhánh ngân hàng nước ngoài thực hiện các quy định về đánh giá nội bộ về mức đủ vốn tại Chương V Thông tư này kể từ ngày 01 tháng 01 năm 2021.
a) Sửa đổi Điều 1 như sau:
b) Sửa đổi cụm từ “tổ chức tín dụng, chi nhánh ngân hàng nước ngoài” thành “tổ chức tín dụng” tại Thông tư số 44/2011/TT-NHNN ngày 29 tháng 12 năm 2011 của Thống đốc Ngân hàng Nhà nước quy định về hệ thống kiểm soát nội bộ và kiểm toán nội bộ của tổ chức tín dụng, chi nhánh ngân hàng nước ngoài.
“Thông tư này quy định về hệ thống kiểm soát nội bộ và kiểm toán nội bộ của tổ chức tín dụng (trừ ngân hàng thương mại, chi nhánh ngân hàng nước ngoài)”.
Điều 74. Tổ chức thực hiện
Chánh Văn phòng, Chánh Thanh tra, giám sát ngân hàng, Thủ trưởng các đơn vị thuộc Ngân hàng Nhà nước; Giám đốc Ngân hàng Nhà nước chi nhánh tỉnh, thành phố trực thuộc Trung ương; Chủ tịch Hội đồng quản trị, Chủ tịch Hội đồng thành viên và Tổng giám đốc (Giám đốc) ngân hàng thương mại, chi nhánh ngân hàng nước ngoài chịu trách nhiệm tổ chức thực hiện Thông tư này./.
|
Nơi nhận: |
KT. THỐNG ĐỐC |
Văn bản gốc (PDF)
Tải văn bản
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.