This Circular stipulates the internal control system and internal audit for non-bank credit institutions, to take effect from October 1, 2024. It includes provisions on the responsibilities of the Board of Directors, Board of Members, and General Director in establishing and implementing the internal control system; regulations on the organization and operation of internal audit; and necessary conditions to ensure the effectiveness of this system.
적용 범위
Non-bank credit institutions
핵심 사항
- The internal control system includes policy mechanisms, risk management regulations, and internal control regulations;
- Responsibilities of the Board of Directors and Board of Members in establishing the internal control system;
- Regulations on the organization and operation of internal audit;
- Requirements for necessary resources to implement internal control and internal audit;
- Implementation clauses and organizational responsibility for implementation;
🌐 이 문서의 사회적 영향
- Enhance risk management efficiency in non-bank credit institutions;
- Strengthen transparency and compliance with laws;
- Minimize the risk of legal violations and errors in business operations;
❓ 자주 묻는 질문
When does this Circular take effect?
This Circular takes effect from October 1, 2024;
What must non-bank credit institutions do to comply with this Circular?
Non-bank credit institutions must establish and implement an appropriate internal control system in accordance with the regulations, including identifying risk levels, necessary resources, and internal audit plans;
Which Circular does this replace?
This Circular amends and supplements Circular No. 44/2011/TT-NHNN dated December 29, 2011, issued by the Governor of the State Bank of Vietnam on the internal control system and internal audit of credit institutions and foreign bank branches.
전문
|
STATE BANK OF VIETNAM |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 14/2023/TT-NHNN |
Hanoi, November 20, 2023 |
CIRCULAR
Regulations on the internal control system of non-bank credit institutions
Pursuant to the Law on the State Bank of Vietnam dated June 16, 2010;
Pursuant to the Law on Credit Institutions dated June 16, 2010; the Law Amending and Supplementing Certain Articles of the Law on Credit Institutions dated November 20, 2017;
Pursuant to Decree No. 102/2022/NĐ-CP dated December 12, 2022 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of Banking Inspection and Supervision;
The Governor of the State Bank of Vietnam issues this Circular to regulate the internal control system of non-bank credit institutions.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Circular regulates the internal control system of non-bank credit institutions.
Article 2. Applicability
1. Non-bank credit institutions include finance companies and financial leasing companies.
2. Organizations and individuals related to the internal control system of non-bank credit institutions.
Article 3. Explanation of Terms
In this Circular, the following terms are understood as follows:
1. Internal control system is a set of mechanisms, policies, procedures, internal regulations, organizational structure of non-bank credit institutions established in accordance with the Law on Credit Institutions, this Circular, and relevant laws and regulations, and implemented to monitor, prevent, detect, and promptly address risks and achieve the required objectives. The internal control system implements oversight by senior management, internal control, risk management, and internal audit.
2. Oversight by senior management is the supervision by the Board of Directors, Board of Members, General Director (Director) over internal control, risk management, and the supervision by the Audit Committee of non-bank credit institutions over internal audit.
3. Internal controlis the monitoring and supervision of individuals and departments in implementing mechanisms, policies, internal regulations, professional ethics standards, and control culture to manage conflicts of interest and risks.
4. Risk managementis the identification, tracking, and control of risks in the operations of non-bank credit institutions.
5. Control culture is the corporate culture value of non-bank credit institutions reflecting a unified understanding of the importance of control activities and risk management by the Board of Directors, Board of Members, Audit Committee, General Director (Director), and individuals and departments. Control culture is formed through professional ethics standards, internal regulations, reward and punishment systems to encourage and ensure that individuals and departments proactively identify and control risks in their own activities and those of the non-bank credit institution.
6. Risk is the possibility of loss (financial loss, non-financial loss) reducing income, capital, leading to a decrease in the capital adequacy ratio or limiting the ability to achieve business goals of non-bank credit institutions.
7. Risk status is the value of risky assets, risky liabilities, and off-balance sheet items of non-bank credit institutions.
8. Credit risk includes:
a) Credit risk is the risk arising from customers not performing or being unable to perform part or all of their debt repayment obligations under contracts or agreements with non-bank credit institutions, except for cases stipulated in point b of this Clause. In which, customers (including credit institutions, foreign bank branches) have relationships with non-bank credit institutions in receiving credit (including receiving credit through agency), depositing money, issuing corporate bonds;
b) Counterparty credit risk is the risk arising from counterparties not performing or being unable to perform part or all of their pre-payment or payment obligations at maturity of proprietary trading transactions; repo and reverse repo transactions; derivative product transactions for risk mitigation; foreign currency and financial asset buying and selling transactions to meet customer and counterparty needs. In which, counterparties (including credit institutions, foreign bank branches) engage in proprietary trading transactions; repo and reverse repo transactions; derivative product transactions for risk mitigation; foreign currency and financial asset buying and selling transactions to meet customer and counterparty needs.
9. Operational risk is the risk arising from incomplete or erroneous internal processes, human factors, system errors or external factors causing financial losses or negative non-financial impacts on non-bank credit institutions (including legal risks). Operational risk does not include:
a) Reputation risk is the risk arising from customers, counterparties, shareholders, investors, or the public having a negative reaction to the reputation of non-bank credit institutions;
b) Strategic risk is the risk arising from non-bank credit institutions having or not having timely strategies or policies to respond to changes in the business environment, thereby reducing the ability to achieve business strategies and profit targets of non-bank credit institutions.
10. Conflict of interest is a situation where an individual or department makes decisions within their authority that create inappropriate or conflicting interests with the interests of non-bank credit institutions.
11. Risk decision are decisions made by authorized bodies of non-bank credit institutions that generate risks or change the risk status of non-bank credit institutions.
12. Credit risk decision are risk decisions in credit activities, at least including: credit granting decisions; credit limit setting decisions; credit granting decisions exceeding limits; restructuring repayment term decisions; loan classification decisions.
13. Problem loan facility is defined by non-bank credit institutions to ensure that at least loans classified as substandard or worse according to the State Bank of Vietnam's (State Bank) regulations on asset classification, provisioning levels, provisioning methods, and the use of provisions to address risks in the operations of credit institutions and foreign bank branches.
14. Outsourcing activity is the arrangement by non-bank credit institutions to hire another organization, enterprise, credit institution, or foreign bank branch (referred to as the outsourced entity) to perform one or more activities (including data processing or certain stages of business processes) instead of the non-bank credit institution in accordance with the law.
15. Internal auditor is an internal auditor belonging to the internal audit department of non-bank credit institutions.
Article 4. Requirements for the internal control system
1. The internal control system of non-bank credit institutions must meet the following requirements:
a) Requirements for the internal control system as prescribed by the Law on Credit Institutions;
b) Be appropriate to the scale, conditions, and complexity of the business operations of the non-bank credit institution;
c) Have sufficient financial, human, and information technology resources to ensure the effectiveness of the internal control system;
d) Establish and maintain a culture of control and professional ethics standards for non-bank credit institutions.
2. Non-bank credit institutions must have internal regulations as prescribed by the Law on Credit Institutions, including ensuring:
a) Comply with the provisions of this Circular and relevant legal regulations;
b) The Board of Directors, Board of Members issue regulations on the organization, management, and operation of non-bank credit institutions, except for issues within the authority of the Shareholders' Meeting, owners; the Supervisory Board issues internal regulations of the Supervisory Board; the General Director (Director) issues internal rules, procedures, operational processes (hereinafter referred to as internal procedures);
c) Be periodically evaluated according to the provisions of this Circular and the regulations of the non-bank credit institution regarding appropriateness, compliance with legal provisions, and amendments and supplements (if necessary).
3. The internal control system must have three independent lines of defense as follows:
a) The first line of defense has the function of identifying, controlling, and mitigating risks carried out by the following departments: Business departments (including product development departments), other revenue-generating departments; departments responsible for implementing risk decisions; Departments responsible for allocating risk limits, risk control, and risk reduction (belonging to the business department or an independent department) for each type of transaction, business activity; Human Resources Department, Accounting Department;
b) The second line of defense has the function of establishing contents related to risk management, internal regulations on risk governance, monitoring risks, and compliance with legal provisions carried out by the following departments: Compliance Department as stipulated in Article 16 of this Circular; Risk Management Department as stipulated in Article 18 of this Circular;
c) The third line of defense has the function of internal auditing performed by the internal audit department in accordance with the Law on Credit Institutions and this Circular.
4. Opinions discussed and conclusions about the internal control system in meetings of the Board of Directors, Board of Members, Supervisory Board, Risk Management Committee, Human Resources Committee must be recorded in minutes, specifying the consensus and dissenting opinions of each member.
5. Independent assessment of the internal control system shall be conducted in accordance with the State Bank's regulations on independent audit of credit institutions and foreign bank branches.
Article 5. Archiving of Documents and Records on Internal Control System
1. Non-bank credit institutions must have internal regulations on managing and archiving documents and records on the internal control system.
2. Managing and archiving documents and records on the internal control system of non-bank credit institutions must ensure:
a) Compliance with legal regulations;
b) Adequate storage to provide access upon request for internal audit, independent auditors, and authorized agencies during internal audit, independent audit, inspection, and supervision processes.
Article 6. Reporting to the State Bank on the Internal Control System
1. Non-bank credit institutions must prepare reports on the internal control system according to the appendices issued together with this Circular, including:
a) Annual report on internal control and risk management (Appendix No. 01);
b) Annual report on internal audit (Appendix No. 02);
c) Ad hoc report on internal audit.
2. Reports on the internal control system must update existing issues, limitations, and emerging risks (if any) throughout the non-bank credit institution (including departments at headquarters; branches and other affiliated units of the non-bank credit institution).
3. Deadline for submitting reports:
a) Report as stipulated in point a, Clause 1 of this Article: Within 45 days from the end of the fiscal year;
b) Report as stipulated in point b, Clause 1 of this Article: Within 60 days from the end of the fiscal year;
c) Report as stipulated in point c, Clause 1 of this Article: Within 15 working days from the end of the ad hoc internal audit (including approval by the Supervisory Board).
4. The cut-off date for report data is the end of the fiscal year.
5. Reports must be prepared in writing and sent directly or through postal services to the State Bank (Bank Inspection and Supervision Authority).
Article 7. Internal report on internal control system
1. Internal reports on the internal control system include:
a) Internal report on internal control;
b) Internal report on credit risk.
c) Internal report on operational risk.
d) Internal report on the results of internal audit.
2. The internal report on internal control includes an assessment of control activities according to the contents prescribed in Article 14 of this Circular and other contents as prescribed internally by the non-bank credit institution.
3. The internal report on credit risk must at least include the following contents:
a) Credit quality for loan portfolios, loan categories by customer type and by product;
b) Problem loans, measures to handle problem loans.
c) Customers with actual credit balances exceeding the credit risk limits prescribed in point a, Clause 2, Article 20 of this Circular;
d) The situation of provisioning for risks, using risk provisions to handle credit risks;
đ) Early warning of potential breaches of credit risk limits;
e) Violations in credit risk management and reasons for such violations;
g) Recommendations and suggestions for credit risk management;
h) Results of implementing requirements and suggestions for credit risk management from internal audit, State Bank, independent auditors, and other competent authorities.
4. The internal report on operational risk must at least include the following contents:
a) Cases of operational risk arising during the reporting period and reasons.
b) Loss data due to operational risks, measures to address losses and maintain continuous operations (if applicable);
c) Events, external impacts affecting operational risks of the non-bank credit institution;
d) The situation of outsourcing activities and operational risk management for outsourcing activities;
đ) Changes in technology applications (if applicable) and the situation of operational risk management in technology applications;
e) Recommendations and suggestions for operational risk management;
g) Results of implementing requirements and suggestions for operational risk management from internal audit, State Bank, independent auditors, and other competent authorities.
5. The internal report on the results of internal audit (annual periodic internal audit and ad hoc internal audit) includes the following contents:
a) Implementation status of the scope and content of internal audit during the fiscal year;
b) Compliance with mechanisms, policies, and internal regulations on supervision by senior management, internal control, and risk management by the Board of Directors, Board of Members, General Director (Director), individuals, and departments;
c) The appropriateness and compliance with laws and regulations set forth in this Circular of mechanisms, policies, and internal regulations on supervision by senior management, internal control, and risk management;
d) Issues, limitations identified during the implementation of internal audit and recommendations to those with authority and relevant departments;
đ) Other contents as prescribed internally by the Supervisory Board of the non-bank credit institution.
6. Reporting deadlines:
a) Internal report on internal control: Annually or ad hoc as prescribed internally by the non-bank credit institution;
b) Internal report on credit risks: At least quarterly or ad hoc as prescribed internally by the non-bank credit institution;
c) Internal report on operational risks: At least semi-annually or ad hoc as prescribed internally by the non-bank credit institution;
d) Internal report on the results of internal audit: After completing the internal audit, the internal audit department submits the internal audit result report to the Supervisory Board for approval before sending it to the Board of Directors, Board of Members, General Director (Director) according to the internal regulations of the Supervisory Board of the non-bank credit institution.
7. Individuals and departments receiving reports:
Board of Directors, Board of Members, Supervisory Board, General Director (Director) and individuals and departments related as prescribed internally by the non-bank credit institution.
Chapter II
SUPERVISION BY SENIOR MANAGEMENT
Article 8. Requirements for high-level management supervision
1. To have organizational structure, tasks, and powers of the Board of Directors, Board of Members, Supervisory Board, General Director (Director) in accordance with the Law on Credit Organizations for non-bank credit institutions and consistent with the provisions of this Circular.
2. To ensure internal control, risk management, and internal audit are effectively implemented and meet the requirements set forth.
3. To clearly understand the risk status and the implementation of risk management policies of non-bank credit institutions.
4. To have measures to prevent and promptly address losses to enhance efficiency and safety in the operations of non-bank credit institutions.
Article 9. Organizational Structure of High-Level Management Supervision of Non-Bank Credit Institutions
1. The organizational structure of the Board of Directors and Board of Members of non-bank credit institutions must ensure:
a) Having a Risk Management Committee and Human Resources Committee in accordance with the State Bank's regulations on granting licenses, organization, and operation of non-bank credit institutions;
b) Having other committees (if necessary) to assist the Board of Directors and Board of Members in performing high-level management supervision.
2. The organizational structure of the Supervisory Board shall be carried out in accordance with the Law on Credit Organizations and internal regulations of the Supervisory Board.
Article 10. High-Level Management Supervision over Internal Control
1. The Board of Directors and Board of Members of non-bank credit institutions supervise the General Director (Director) in the following matters:
a) Organizing the implementation of internal control activities, operation, and maintenance of management information systems and communication mechanisms;
b) Maintaining the internal control culture stipulated in Clause 5, Article 3 of this Circular and professional ethics standards stipulated in Clause 4, Article 14 of this Circular within the non-bank credit institution;
c) Addressing and rectifying deficiencies and limitations in internal control according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
d) Handling violations of laws, internal regulations, and professional ethics standards;
đ) Other contents prescribed by the Board of Directors and Board of Members.
2. The General Director (Director) of non-bank credit institutions supervises individuals and departments in the following matters:
a) Implementing internal control regulations, maintaining the internal control culture; evaluating the implementation of professional ethics standards (except for professional ethics standards of Supervisory Board members and internal auditors);
b) Operating the management information system, assessing (accuracy, completeness, timeliness, and appropriateness), upgrading, and perfecting the management information system to meet the requirements stipulated in Article 17 of this Circular;
c) Implementing directives from the Board of Directors and Board of Members to address and rectify deficiencies and limitations in internal control according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
d) Other contents prescribed by the non-bank credit institution.
Article 11. High-Level Management Supervision over Risk Management
1. The Board of Directors and Board of Members of non-bank credit institutions supervise the General Director (Director) based on proposals and advice from the Risk Management Committee in the following matters:
a) Establishing and implementing risk management;
b) Addressing and rectifying deficiencies and limitations in risk management according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
c) Other contents prescribed by the Board of Directors and Board of Members.
2. The General Director (Director) of non-bank credit institutions supervises individuals and departments based on proposals and advice from the Risk Management Department in the following matters:
a) Developing procedures for establishing and implementing risk management;
b) Conducting evaluations of risk management-related content to propose adjustments to the Board of Directors and Board of Members;
c) Establishing and implementing risk limits, proposing risk limit allocations for each business activity and operational activity; implementing measures when risk limits are not met;
d) Implementing directives from the Board of Directors and Board of Members to address and rectify deficiencies and limitations in risk management according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
đ) Self-inspecting and evaluating risk management and proposing measures to address and rectify to the Board of Directors and Board of Members;
e) Other contents prescribed by the non-bank credit institution.
Article 12. Supervision of internal audit by senior management
The supervisory board of non-bank credit institutions shall carry out supervision over the internal audit including:
1. Supervising and evaluating the implementation of professional ethics standards by members of the supervisory board and internal auditors;
2. Supervising the internal audit department in the following matters:
a) Conducting internal audits;
b) Reviewing and assessing the effectiveness and results of the tasks performed by the internal audit;
c) Handling and rectifying any existing issues and limitations of the internal audit according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities.
3. Other contents as specified by the supervisory board.
Chapter III
INTERNAL CONTROL
Article 13. Requirements for internal control
1. Internal control shall be implemented for all activities, business processes, and departments within non-bank credit institutions (including headquarters, branches, and other affiliated units) to ensure the following requirements:
a) Activities of non-bank credit institutions comply with legal regulations and internal rules;
b) Controlling and preventing conflicts of interest, promptly detecting and handling violations of legal regulations and internal rules of non-bank credit institutions;
c) Enhancing awareness about the role and responsibility of individuals and departments in internal control to build and maintain the internal control culture of non-bank credit institutions as stipulated in this Circular.
2. Internal control shall be carried out through control activities, management information systems, and communication mechanisms.
Article 14. Control Activities
1. Control activities of non-bank credit institutions shall be conducted through at least the following contents:
a) Approval authority must be based on the level of trust in the approving authority and the capability of the individual or department executing the task. Approval authority must be expressed through criteria regarding transaction scale, risk limits, and other limits as stipulated in the internal rules of non-bank credit institutions;
b) Allocation of human resources suitable for each business activity and control activity (including replacement personnel when staff are absent, recruitment, rotation, and appointment of officials);
c) Accounting records must comply with accounting standards and accounting regulations; consolidation, preparation, and submission of financial reports as required by law and internal rules of non-bank credit institutions; preparation of statistical reports in accordance with legal provisions. Accounting records and statistical reports must be checked and reconciled to ensure timely detection and handling of errors and must be reported to the approving authority as stipulated in the internal rules of non-bank credit institutions;
d) Measures to prevent and promptly address any violations, illegal acts, and breaches of legal regulations and internal rules within non-bank credit institutions (including headquarters, branches, and other affiliated units);
đ) Handling and rectifying any existing issues and limitations in internal control according to the requirements and recommendations of the State Bank, independent auditing organizations, and other competent authorities;
e) Implementation, operation, control, and maintenance of information technology systems and communication mechanisms must comply with legal provisions; regulations on ensuring the security and confidentiality of information technology systems in banking operations and online banking services; phased plans for the application of information technology by non-bank credit institutions; and internal rules of non-bank credit institutions.
2. The definition of functions and responsibilities of individuals and departments from the lowest to the highest level in all transactions and business processes within non-bank credit institutions (including headquarters, branches, and other affiliated units) must ensure the principle that:
a) Members of the Board of Directors and Board of Members shall not participate in reviewing and approving decisions involving risks within the functions and responsibilities of the General Director (Director), except when the member of the Board of Directors or Board of Members is also the General Director (Director) and/or Deputy General Director (Deputy Director);
b) Functions and responsibilities in transactions and business processes must be separated to avoid conflicts of interest or to control and prevent conflicts of interest; one individual cannot control an entire transaction or process; one individual cannot simultaneously be assigned conflicting interests;
c) There must be independent individuals within the same department or independent departments to conduct periodic and ad hoc reviews as stipulated in the internal rules of non-bank credit institutions.
3. Control activities of the headquarters of non-bank credit institutions towards branches and other affiliated units must ensure:
a) The headquarters can monitor and control transactions and activities of branches and other affiliated units, including monitoring and controlling through individuals and departments conducting control activities at branches and other affiliated units;
b) Regulations on functions, responsibilities, reporting mechanisms, salaries, rewards, disciplinary actions, official rotations, and other mechanisms to ensure the independence and absence of conflicts of interest of individuals and departments conducting control activities at branches and other affiliated units relative to other individuals and departments within those units;
c) Mechanisms allowing customers to review, inspect, and reconcile transactions conducted at branches and other affiliated units with the headquarters of non-bank credit institutions.
4. The Board of Directors and Board of Members of non-bank credit institutions shall issue professional ethics standards (excluding professional ethics standards for members of the supervisory board and internal auditors) ensuring the principles that:
a) Staff at all levels perform their duties and granted authorities honestly for the benefit of non-bank credit institutions; they shall not take advantage of their positions, use information, trade secrets, business opportunities, and assets of non-bank credit institutions for personal gain or harm the interests of non-bank credit institutions.
b) Individuals and units responsible for promptly reporting to the competent authority when discovering violations as stipulated in point a Clause of this Article and internal regulations of non-bank credit institutions, as well as violations of laws.
Article 15. Supervisory Activities for Credit Granting Operations
1. Supervisory activities for credit granting operations of non-bank credit institutions must comply with the provisions of Clause 1 and 2 of Article 14 of this Circular.
2. Credit granting activities must be subject to conflict of interest control according to the principle of delineating responsibilities between the appraisal stage and the loan approval stage as prescribed by the State Bank.
Article 16. Compliance Department
Depending on the scale, conditions, and complexity of business operations, non-bank credit institutions shall determine the organizational structure of the Compliance Department, ensuring the implementation of at least the following functions:
1. Assisting the General Director (Director) in:
a) Implementing the assessment of the content stipulated in point c Clause 2 of Article 4 of this Circular;
b) Reporting to the Board of Directors, Board of Members, Audit Committee serious violations in compliance with legal regulations, changes in related legal regulations according to internal regulations of non-bank credit institutions;
c) Reviewing and evaluating the regulations on the duties and authorities of the Compliance Department to submit to the General Director (Director) for necessary amendments and supplements.
2. Periodically and urgently reporting to the General Director (Director) on the situation of compliance with legal regulations; reporting to the General Director (Director) and notifying relevant departments about changes in related legal regulations according to internal regulations of non-bank credit institutions.
3. Supporting relevant departments in building and reviewing internal regulations to ensure compliance with legal regulations; handling difficulties in compliance with legal regulations according to internal regulations of non-bank credit institutions.
Article 17. Information Management System and Information Exchange Mechanism
1. Non-bank credit institutions shall have an information management system to provide internal reports and information to the Board of Directors, Board of Members, Audit Committee, General Director (Director), and relevant individuals and units to perform functions and tasks to ensure compliance with this Circular.
2. The minimum information management system includes:
a) Internal reports and other management information as prescribed by internal regulations of non-bank credit institutions;
b) Organizational structure for managing and operating the information management system, specifying the specific responsibilities of individuals and units in using the information management system;
c) Collecting, processing, storing, and providing information; building, sending, receiving, and processing reports.
3. The management information system must ensure:
a) Supporting the implementation of the information exchange mechanism as stipulated in Clause 4 and 5 of this Article;
b) Providing complete, accurate, and timely information and data to meet management requirements as prescribed in this Circular and internal regulations of non-bank credit institutions;
c) Updating the compliance with legal regulations and internal regulations of non-bank credit institutions;
d) Being reviewed, evaluated, upgraded, and updated regularly to meet the information management needs in business operations of non-bank credit institutions;
đ) Ensuring confidentiality, security of information and data, and having backup systems to ensure safe, effective storage and use of information without interruption.
4. Non-bank credit institutions shall have an information exchange mechanism through the information management system and other information exchange mechanisms, ensuring that all individuals at all levels and relevant units are informed, disseminated, and publicized about the internal control system to understand clearly, consistently, and fully about policies, procedures, business objectives, and perform their duties, responsibilities, and authorities effectively.
5. Non-bank credit institutions shall promptly report to competent authorities about violations of laws, internal regulations, and professional ethics standards of individuals and units ensuring information confidentiality and protecting information providers in accordance with internal regulations of non-bank credit institutions.
Chapter IV
RISK MANAGEMENT
Article 18. Risk Management Unit
Depending on the scale, conditions, and complexity of business operations, non-bank credit institutions shall determine the organizational structure of the Risk Management Unit to ensure the performance of at least the following functions:
1. Assist the General Director (Director) in proposing and advising on the contents stipulated in Clause 2, Article 11 of this Circular.
2. Coordinate with the first line of defense to fully identify and monitor emerging risks.
3. Analyze and issue warnings about the level of safety of the non-bank credit institution against potential risks that may affect it and propose preventive measures for these risks in both short-term and long-term perspectives.
4. Participate in risk-related content during the process of making decisions involving corresponding risks according to the authority levels specified in the internal regulations of the non-bank credit institution.
5. Implement internal reports on risk management in accordance with the internal regulations of the non-bank credit institution.
Section 1
CREDIT RISK MANAGEMENT
Article 19. Requirements and Risk Management Strategy for Credit Risks
Non-bank credit institutions must develop a minimum credit risk management strategy including the following contents:
1. Target non-performing loan ratio, target bad credit grant ratio.
2. Principles for determining the cost of risk compensation in interest rate calculation methods and pricing of credit products based on the level of credit risk of customers.
3. Principles for applying risk mitigation measures (including approval authority for risk mitigation measures).
Article 20. Credit Risk Limits
1. Non-bank credit institutions must establish credit risk limits to ensure compliance with restrictions to ensure safety in the operation of non-bank credit institutions as prescribed in the Law on Credit Institutions and the State Bank's regulations.
2. The minimum credit risk limit shall include the following limits:
a) Credit limit for customer objects based on the customer's repayment capacity;
b) Credit limit by product.
3. Credit risk limits must be reviewed and re-evaluated (adjusted if necessary) at least once every year according to the internal regulations of the non-bank credit institution.
Article 21. Monitoring and Controlling Credit Risks
1. Non-bank credit institutions must monitor and control credit risks for each credit grant and the entire portfolio of credit grants and take measures when credit quality deteriorates, ensuring at least the following requirements:
a) Monitor the results of loan classification for each credit grant;
b) Evaluate the adequacy of risk provisions as prescribed by the State Bank.
2. The monitoring and controlling of credit risks must include the following contents:
a) Roles and responsibilities of individuals and units responsible for monitoring and controlling credit risks;
b) Implementation of loan classification, establishment of risk provisions, and utilization of risk provisions to address credit risks;
c) Control of credit risks within credit risk limits allocated to portfolios of credit grants by customer categories and products;
d) Criteria for evaluating and methods for determining the degree of deterioration in credit quality of each credit grant portfolio; early warning mechanisms when there is a risk of deterioration in customer credit quality.
Article 22. Credit Granting Appraisal
1. Non-bank credit institutions shall conduct credit granting appraisals, which must include at least the following contents:
a) Identifying specific related parties of the customer, total outstanding credit granted to the customer, and total outstanding credit granted to the customer and related parties;
b) Evaluating credit granting conditions in accordance with relevant laws;
c) Assessing the completeness of the application file, the legal status, and the recoverability of collateral for cases where credit is granted with collateral, in accordance with internal regulations of non-bank credit institutions;
d) Appraising the ability to fulfill committed obligations of the guarantor for credit grants with third-party guarantees.
2. During the appraisal process, if external information channels outside the non-bank credit institution are used, the non-bank credit institution must verify the quality of the information and the independence of the information channel from the customer.
Article 23. Approval of Risky Credit Decisions
Non-bank credit institutions shall implement the approval of risky credit decisions, ensuring the following:
1. The authority to approve risky credit decisions must be determined based on quantitative and qualitative criteria.
2. In cases of approval through a committee mechanism, the approval committee must have a record of approval or equivalent form, clearly stating the reasons for approval or disapproval and recording (or attaching) the opinions of committee members. Committee members approving must bear responsibility for their decision.
3. Information provided for the approval of risky credit decisions must be complete and appropriate to the scale, type of credit grant, and internal regulations of the non-bank credit institution. Regulations regarding the list of information serving as the basis for approving risky credit decisions must be evaluated by the risk management department to ensure effective credit risk management.
Article 24. Credit Management
1. Non-bank credit institutions shall implement credit management meeting the following requirements:
a) Specifying the responsibilities and authorities of individuals and departments in establishing and storing credit files to ensure that credit files are complete in accordance with the law;
b) Disburse funds in accordance with the purpose of capital usage and the type of credit provision;
c) Monitoring the credit grant after disbursement must ensure the principle of: Checking the use of borrowed funds and implementing other terms in the customer's credit grant contract; Evaluating factors affecting the customer's debt repayment capability; Tracking the repayment schedule, reminding customers to fulfill their repayment obligations when due, and promptly reporting to competent authorities when there is a risk of non-compliance or delay in fulfilling repayment obligations;
d) Clearly defining criteria and methods for identifying problematic credit grants, managing problematic credit grants to take timely measures.
2. Non-bank credit institutions must store credit files and other related information in accordance with the law.
Section 2
OPERATIONAL RISK MANAGEMENT
Article 25. Requirements for Operational Risk Management
Minimum operational risk management includes the following contents:
1. Establishing principles for operational risk management implementation.
2. Establishing principles for using outsourcing activities, purchasing insurance, and applying technology.
3. Developing plans to maintain continuous operations at a minimum level in cases of loss of important documents, information technology system failures, and other force majeure events as prescribed by law. Continuous operation plans must meet the following minimum requirements:
a) Having backup systems for personnel, information technology systems, and information databases;
b) Having measures to minimize losses due to cessation of operations;
c) Restoring interrupted business activities.
Article 26. Identification, monitoring, and control of operational risks
1. Non-bank credit organizations must fully identify operational risks in business activities, business processes, information technology systems, and other management systems. The identification of operational risks shall be carried out in the following cases:
a) Internal fraud caused by acts of deception, property theft, violation of strategies, policies, and internal regulations related to at least one individual of the non-bank credit organization (including acts of dereliction of duty, exceeding authority, theft, and misusing internal information for personal gain);
b) External fraud caused by acts of deception and property theft committed by external parties without assistance or collusion from individuals or departments within the non-bank credit organization (including acts of theft, robbery, counterfeit cards, documents, and unauthorized access to information technology systems to steal data and money);
c) Labor policies and workplace safety that are not consistent with labor contracts, laws on labor, health protection, and workplace safety;
d) Inadvertent violations of regulations related to customers, product delivery processes, and product characteristics when performing assigned functions and tasks with customers (including acts of violating customer information confidentiality and providing services contrary to regulations);
đ) Violations of laws on anti-money laundering;
e) Damage, loss of assets, tools, and equipment due to force majeure events, human actions, and other incidents;
g) Business interruption due to failures in the information technology system;
h) Limitations and inadequacies in transaction procedures, transaction controls, and transaction management;
i) Other cases as stipulated internally by the non-bank credit organization.
2. Non-bank credit organizations implement monitoring and control of operational risks through the regulatory control activities specified in Article 14 of this Circular and other measures as stipulated internally by the non-bank credit organization.
Article 27. Management of operational risks for outsourcing activities
1. Outsourcing activity management shall minimally include:
a) Determining the scope of outsourcing activities;
b) Delegating approval and decision-making authority for outsourcing activities;
c) Assessing the capability of the outsourcing company to meet the requirements and objectives set for the outsourcing activity before signing the outsourcing contract; evaluating the outsourcing company's ability to perform the contract during its execution;
d) Ensuring that the outsourcing contract is thorough and comprehensive, protecting ownership rights and customer information confidentiality, and allowing termination of the outsourcing contract without damaging the reputation of the non-bank credit organization; the extent and scope of outsourcing activities; specific responsibilities of the non-bank credit organization and the outsourcing company; and dispute resolution clauses in accordance with the law;
đ) For outsourcing activities involving information technology services, compliance with legal regulations on managing third-party information technology services must be ensured according to legal provisions on ensuring the security and confidentiality of information technology systems in banking operations;
2. Non-bank credit organizations manage operational risks associated with outsourcing activities through:
a) Managing outsourcing activities as prescribed in Clause 1 of this Article;
b) Identifying, monitoring, and controlling operational risks arising from outsourcing activities as prescribed in Article 26 of this Circular.
Article 28. Management of operational risks in technology application
1. The management of technology application activities must comply with the State Bank's regulations on electronic transactions in the banking industry; information security for online banking service provision and related legal provisions. Technology application management shall minimally include the following contents:
a) The scope of minimum management of technology application for information technology systems and databases;
b) Tasks, responsibilities, and authorities of individuals and units responsible for managing technology applications;
c) Authentication systems ensuring customer information security, transaction safety, and information technology systems.
2. Non-bank credit organizations manage operational risks arising from electronic transactions, online transactions, automated transactions, mobile transactions, and other technologies (hereinafter referred to as technology applications) through:
a) Managing technology applications in accordance with Clause 1 of this Article;
b) Identifying, monitoring, and controlling operational risks arising from technology applications in accordance with Article 26 of this Circular, at least ensuring: Identification of potential risks associated with internal and external network connection systems, hardware, software, applications, transaction interfaces, operations, and human factors; Monitoring and assessing the ability to maintain stable operations before operational risks arise from technology applications; Controlling and implementing measures to mitigate operational risks (if necessary) during technology application activities.
Article 29. Purchasing insurance to reduce losses from operational risks
1. Non-bank credit organizations may purchase insurance to reduce losses arising from operational risks in accordance with legal provisions, ensuring compatibility with their financial capacity and compensating for losses of non-bank credit organizations.
2. Non-bank credit organizations shall not use insurance purchases to replace operational risk management, must evaluate the effectiveness of reducing losses arising from operational risks through insurance purchases, assess the capability of insurance companies in fulfilling insurance contracts, and new risks (if any).
Chapter V
INTERNAL AUDIT
Article 30. Principles of Internal Audit
1. Independence Principle:
a) Internal auditors and internal audit departments shall not concurrently undertake tasks and responsibilities of other individuals or units;
b) Internal audit shall not be subject to any influence or interference from other individuals or units;
c) Internal auditors shall not audit internal regulations on internal audit, internal audit plans developed by such internal auditors; shall not audit units or departments where the heads are related to such internal auditors; shall not audit activities or departments where such internal auditors have performed and been responsible for within one year from the date they ceased performing such duties; shall not audit criteria for setting salaries and other benefits for positions within the internal audit department that must be separated from business results and activities of other units or departments.
2. Objectivity Principle:
a) Audit records in internal audit reports must be carefully analyzed and based on collected data, information;
b) Internal auditors must be honest when reporting, evaluating during the internal audit process;
c) Internal auditors have the right and obligation to report to competent authorities about issues related to objectivity during the internal audit process.
3. Professionalism Principle:
a) Non-bank credit organizations providing electronic transaction services to 10,000 customers or more must have an information technology auditor;
b) Non-bank credit organizations not falling under the circumstances stipulated in point a of this clause shall choose whether to have an information technology auditor based on the scale, conditions, and complexity of their business operations, or hire an external information technology auditor (rented or owned);
c) Internal auditors must meet the standards prescribed in Article 32 of this Circular.
4. Internal audit must implement measures to verify compliance with the principles prescribed in Clauses 1, 2, and 3 of this Article during the internal audit process (including the preparation and submission of internal audit reports). The Head of Internal Audit must promptly report to the Supervisory Board when violations or potential violations of the principles prescribed in Clause 1 of this Article are discovered.
Article 31. Coordination Mechanism
1. Non-bank credit organizations must have a coordination mechanism between:
a) The Board of Directors, Board of Members with the Supervisory Board, internal audit department as prescribed in Clause 2 of this Article;
b) General Director (Director), departments and the Supervisory Board, internal audit department as prescribed in Clause 3 of this Article. Add
2. The coordination mechanism of the Board of Directors, Board of Members and the Supervisory Board, internal audit department of non-bank credit organizations must ensure:
a) The Board of Directors, Board of Members coordinate with the internal audit department when conducting internal audit on the supervision of senior management over the Board of Directors, Board of Members;
b) The Board of Directors, Board of Members implement recommendations of the Supervisory Board to the Board of Directors, Board of Members in the internal audit report and notify the Supervisory Board about the implementation results of the recommendations.
3. The coordination mechanism of the General Director (Director), departments and the Supervisory Board, internal audit department of non-bank credit organizations must ensure:
a) The General Director (Director) coordinates with the internal audit department when conducting internal audit on the supervision of senior management over the General Director (Director); directs relevant departments to provide complete information on risks for the internal audit department to plan internal audits; organizes the implementation of recommendations of the Supervisory Board to the General Director (Director) in the internal audit report (if any) and reports to the Supervisory Board on the implementation results of the recommendations;
b) Departments not belonging to the Supervisory Board, internal audit department provide complete, truthful, accurate information, documents, files upon request of the internal audit department during internal audit; promptly notify the internal audit department when discovering existing issues, violations, losses or loss risks; facilitate the internal audit department to conduct internal audit; implement recommendations of internal audit in the internal audit report and report on the implementation results of the recommendations to internal audit.
Article 32. Standards for Members of the Supervisory Board, Internal Auditors
1. Members of the Supervisory Board of non-bank credit organizations must meet the standards and conditions as prescribed in the Law on Credit Institutions.
2. Non-bank credit organizations must establish standards for internal auditors that meet the following requirements:
a) Hold a bachelor's degree or higher in economics, business administration, law, accounting, auditing;
b) Have at least two years of direct work experience in banking, finance, accounting, auditing for internal auditors and at least three years for Chief Internal Auditor.
3. Non-bank credit organizations must establish standards for internal auditors in information technology that meet the following requirements:
a) Hold a bachelor's degree or higher in information technology or a relevant specialty;
b) Have at least two years of work experience in information technology.
Article 33. Professional Ethics Standards for Members of the Supervisory Board, Internal Auditors
Professional ethics standards for members of the Supervisory Board, internal auditors (including Chief Internal Auditor and other positions within the internal audit department) must minimally include the following rules:
1. Integrity: performing assigned tasks honestly and truthfully.
2. Objectivity: perform assigned tasks objectively; evaluate fairly without personal interest or the interest of others.
3. Confidentiality: comply with regulations on information confidentiality as prescribed by law and internal regulations of non-bank credit organizations.
4. Responsibility: ensuring the progress and quality of assigned work.
5. Prudence: performing assigned tasks prudently based on the assessment of the following factors:
a) The complexity and importance of the content being internally audited;
b) The possibility of serious errors occurring during the internal audit process.
Article 34. Organizational structure, tasks, powers, and responsibilities of the internal audit department
1. The organizational structure, tasks, and powers of the internal audit department of non-bank credit institutions shall be decided by the Supervisory Board in accordance with the Law on Credit Institutions and this Circular.
2. The minimum tasks of the internal audit department include the following contents:
a) Conducting annual or ad hoc internal audits of the main office, branches, and other affiliated units of non-bank credit institutions;
b) Establishing, reviewing, and submitting to the Supervisory Board for issuance, amendment, and supplementation of ethical standards for members of the Supervisory Board and internal auditors in accordance with Article 33 of this Circular; internal regulations of the Supervisory Board; internal audit plans;
c) Monitoring and evaluating the implementation of recommendations made by the Supervisory Board to the Board of Directors, Board of Members, General Director (Director), individuals, and departments;
d) Implementing recommendations from the State Bank, independent auditing organizations, and other competent authorities regarding internal audits;
đ) Preparing internal reports on internal audits in accordance with Article 7 of this Circular.
3. The minimum powers of the internal audit department include the following contents:
a) Being equipped with necessary resources (human resources, finance, assets, and other tools);
b) Receiving necessary information, documents, and files for internal audit work, including all texts and meeting minutes of the Board of Directors, Board of Members, General Director (Director);
c) Interviewing individuals related to internal audit matters; recommending appropriate authorities to handle according to internal regulations the behavior of non-cooperation by individuals or departments during the internal audit process;
d) Attending internal meetings in accordance with the Charter and internal regulations of non-bank credit institutions.
4. The minimum responsibilities of the internal audit department and internal auditors include:
a) Safeguarding documents and information in accordance with laws and internal regulations of non-bank credit institutions;
b) Being accountable to the Supervisory Board for the performance of assigned tasks;
c) Internal auditors being accountable under the law and to the Head of the Internal Audit Department for assigned audit tasks.
Article 35. Internal Regulations of the Supervisory Board
The internal regulations of the Supervisory Board must include provisions on internal auditing at a minimum comprising:
1. The organizational structure, tasks, and powers of the internal audit department; standards for internal auditors; ethical standards for members of the Supervisory Board and internal auditors as stipulated in this Circular.
2. Criteria for determining risk levels, materiality levels, and frequency of conducting internal audits of activities, processes, departments; contents of internal audits as stipulated in this Circular.
3. Procedures for drafting and implementing the internal audit plan.
4. Reviewing and evaluating internal audit regulations, handling recommendations about internal audits from the State Bank, independent auditing organizations, and other competent authorities.
5. Regulations on hiring experts and external organizations to conduct internal audits (if applicable).
6. Internal reporting systems on internal audits as prescribed in this Circular.
Article 36. Internal Audit Plan
1. Internal audits are conducted regularly annually and ad hoc in accordance with the internal regulations of the Supervisory Board.
2. The annual internal audit plan is issued by the Supervisory Board upon the proposal of the Head of Internal Audit after consulting the opinions of the Board of Directors, Board of Members, and General Director (Director). The preparation of the internal audit plan must ensure compliance with:
a) Risk-oriented principle: Activities, processes, and departments must be assessed for risk levels (high, medium, and low) in accordance with the internal regulations of the Supervisory Board. Activities, processes, and departments with high risk levels will be prioritized for resource allocation and internal audits at least once a year;
b) Ensuring comprehensiveness: All activities, processes, and departments must undergo internal audits. Activities, processes, and departments with significant levels as defined by the internal regulations of the Supervisory Board must be audited at least once a year;
c) Adequate resources and time for conducting ad hoc internal audits;
d) Annual periodic audit plans must be adjusted when there are significant changes in the scale of operations or internal audit resources according to the internal regulations of the Supervisory Board.
3. The annual internal audit plan must be issued before December 15th of the previous year and include the following contents: scope of audit, audit subjects, audit objectives, audit period, audit resources (including hiring experts and external organizations), and other contents specified by non-bank credit institutions.
4. Within ten working days from the date of issuance or amendment, non-bank credit institutions must submit their internal audit plan to the State Bank (Bank Inspection and Supervision Authority).
Article 37. Contents of Internal Audit
Non-bank credit organizations shall conduct internal audit in accordance with the Law on Credit Institutions based on the following contents:
1. Independently examine and evaluate compliance with internal control mechanisms, policies, and internal regulations regarding risk management by the Board of Directors, Board of Members, General Director (Director), individuals, and departments, including identifying existing issues, limitations, and causes.
2. Independently review and evaluate the appropriateness and compliance with legal provisions of internal control mechanisms, policies, and internal regulations regarding risk management, including identifying existing issues, limitations, and causes.
3. Proposing recommendations to competent authorities and relevant departments to address existing issues and limitations.
4. Other contents as prescribed by the Supervisory Board's internal regulations on internal audit.
Chapter VI
IMPLEMENTING PROVISIONS
Article 38. Implementation Provisions
1. This Circular takes effect from October 1, 2024.
2. Amend and supplement Circular No. 44/2011/TT-NHNN dated December 29, 2011 of the Governor of the State Bank of Vietnam on the internal control system and internal audit of credit institutions, including foreign bank branches, as follows:
a) Amend and supplement Article 1 as follows:
“Article 1. Scope of Regulation
This Circular stipulates the internal control system and internal audit of credit institutions (excluding commercial banks and non-bank credit institutions).”
b) Repeal the phrase "foreign bank branches" throughout this Circular.
3. Repeal Clause 3 of Article 73 of Circular No. 13/2018/TT-NHNN dated May 18, 2018 of the Governor of the State Bank of Vietnam on the internal control system of commercial banks and foreign bank branches.
Article 39. Responsibility for Implementation
The Chief of the Office, the Chief of Banking Inspection and Supervision, Heads of Units under the State Bank of Vietnam, non-bank credit institutions, and related organizations and individuals are responsible for implementing this Circular./.
Appendix No. 01
(Issued together with Circular No. 14/2023/TT-NHNN dated November 20, 2023 of the Governor of the State Bank of Vietnam on the internal control system of non-bank credit institutions)
|
NAME OF CREDIT ORGANIZATION NON-BANK No.: …../…….. |
SOCIALIST REPUBLIC OF VIET NAM Independence – Freedom – Happiness ..., day ... month ... year ... |
REPORT
ON INTERNAL CONTROL AND RISK MANAGEMENT
(Year ...)
Respected: State Bank of Vietnam
(Banking Inspection and Supervision Authority)
A. INTERNAL CONTROL
I. Situation of Implementing Internal Control
1) For internal control activities:
a) Internal regulations:
(i) List internal regulations issued according to the provisions of the Law on Credit Institutions;
(ii) Suitability and compliance of internal regulations with the State Bank’s regulations and relevant laws (self-assessment results); (iii) Compliance with internal regulations by individuals and departments;
b) Results of self-inspection and evaluation of internal control activities
2. For the management information system and information exchange mechanism:.
a) Description of the management information system;
b) Information exchange mechanism;
c) Evaluation of the management information system and information exchange mechanism in meeting the requirements of Article 17 of Circular No. /2023/TT-NHNN of the Governor of the State Bank on the internal control system of non-bank credit institutions.
3. Limitations and weaknesses of internal control: II. Results of handling and rectifying internal control deficiencies as recommended by the State Bank, independent auditors, and other competent authorities, reasons for not implementing recommendations, and expected completion dates for unimplemented recommendations.
B. RISK MANAGEMENT
1. Credit Risk Management:
a) Credit risk management strategy, changes during the reporting period (if any) and reasons for change;
b) Credit risk limits, changes during the reporting period (if any) and reasons for change;
c) Implementation of the credit risk management strategy and credit risk limits during the reporting period;
d) Assessment of monitoring and controlling credit risks;
d) Cases of violations in credit risk management, reasons for violation;
đ) Limitations and difficulties in credit risk management and their causes;
e) Results of implementing recommendations of the State Bank, independent auditors, and other competent authorities on credit risk management, reasons for not implementing recommendations, and expected completion dates for unimplemented recommendations.
2. Operational Risk Management:
a) Assessment of identification, monitoring, and controlling operational risks;
b) Cases of violations in operational risk management, reasons for violation;
c) Assessment of the impact of operational risk events and significant losses; d) Assessment of the effectiveness of business continuity planning;
đ) Limitations and difficulties in operational risk management and their causes;
e) Results of implementing recommendations of the State Bank, independent auditors, and other competent authorities on operational risk management, reasons for not implementing recommendations, and expected completion dates for unimplemented recommendations.
C. PROPOSALS AND RECOMMENDATIONS TO THE STATE BANK
BY NON-BANK CREDIT INSTITUTIONS
(signed and clearly stated name, stamped)
ON INTERNAL AUDIT
|
LEGAL REPRESENTATIVE I. Scope and Content of Internal Audit II. Results of Internal Audit |
1. Accounting regulations for tourism administrative and public service units issued together with Decision No. 1899/1998/QĐ-BTC dated December 19, 1998 of the Minister of Finance;
(Issued together with Circular No. 14/2023/TT-NHNN dated November 20, 2023 of the Governor of the State Bank of Vietnam on the internal control system of non-bank credit institutions)
|
NAME OF CREDIT ORGANIZATION NON-BANK No.: …../…….. |
SOCIALIST REPUBLIC OF VIET NAM Independence – Freedom – Happiness ..., day ... month ... year ... |
REPORT
1. Compliance with internal control mechanisms, policies, and internal regulations regarding senior management supervision, internal control, and risk management by non-bank credit institutions.
(Year ...)
Respected: State Bank of Vietnam
(Banking Inspection and Supervision Authority)
2. Appropriateness and compliance with legal provisions of internal control mechanisms, policies, and internal regulations regarding senior management supervision, internal control, and risk management.
3. Existing issues, limitations, and recommendations for the Board of Directors, Board of Members, General Director (Director).
4. Other contents (if any).
III. Self-Assessment Results of Internal Audit
1. Evaluation of the implementation of internal audit in the reporting year.
2. Evaluation of the internal regulations of the Supervisory Board (including the results of reviewing and evaluating the appropriateness and compliance with legal provisions of the internal regulations of the Supervisory Board) in the reporting year.
3. Recommendations of the Board of Directors, Board of Members, General Director (Director), individuals, and departments for internal audit that have been implemented, not implemented in the reporting year, and reasons for not implementing recommendations.
1. Evaluation of the results of internal audit implementation in the reporting year.
2. Assessment of the internal regulations of the Audit Committee (including the review results, evaluation of the appropriateness and compliance with legal provisions of the internal regulations of the Audit Committee) in the reporting year.
3. Recommendations of the Board of Directors, Board of Members, General Director (Director), individuals, departments for internal audit that have been implemented, not yet implemented in the reporting year, reasons for not implementing the recommendations.
IV. RESULTS OF IMPLEMENTING THE INTERNAL AUDIT RECOMMENDATIONS OF THE STATE BANK, INDEPENDENT AUDITING ORGANIZATIONS, AND OTHER COMPETENT AUTHORITIES
1. RECOMMENDATIONS THAT HAVE BEEN IMPLEMENTED.
2. RECOMMENDATIONS THAT HAVE NOT BEEN IMPLEMENTED, REASONS FOR NOT IMPLEMENTING THE RECOMMENDATIONS, AND PROJECTED COMPLETION DATES FOR IMPLEMENTATION OF THE UNIMPLEMENTED RECOMMENDATIONS.
V. PROPOSALS AND RECOMMENDATIONS TO THE STATE BANK
|
CHIEF OF THE AUDIT BOARD II. Results of Internal Audit |
LEGAL REPRESENTATIVE I. Scope and Content of Internal Audit II. Results of Internal Audit |
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.