Decision No. 35/2006/QD-NHNN stipulates risk management principles for electronic banking activities applicable to credit institutions in Vietnam. These regulations aim to protect customer rights and ensure the safety of electronic banking operations.
Đối tượng áp dụng
Credit institutions and foreign bank branches in Vietnam conduct electronic banking activities.
Các điểm cốt lõi
- Credit institutions must develop operational plans, risk management policies, delineate scope of responsibility and authority, protect data, monitor, control, and conduct internal audits.
- Measures must be implemented to ensure the integrity and accuracy of information in electronic banking transactions and provide full information to customers.
- Carefully evaluate third parties when hiring or collaborating, particularly regarding security and confidentiality issues.
- Must establish contingency plans to prevent and address incidents, including those arising from external sources.
- Credit institutions must issue internal regulations on risk management in electronic banking activities and report periodically to the State Bank of Vietnam.
🌐 Tác động xã hội từ văn bản này
- Aims to protect customer rights when using electronic banking services and reduce potential risks.
- Enhance cybersecurity and information security in electronic banking activities to prevent external attacks.
- Requires credit institutions to comply with risk management regulations and improve service quality.
❓ Câu hỏi thường gặp
How should credit institutions develop their electronic banking operational plan?
The plan must include the basis for decision-making, specific objectives, potential risks that may arise, corresponding management measures, as well as an evaluation plan for the effectiveness of operations.
What is the maximum level of risk that credit institutions can accept?
Yes, credit institutions must determine the maximum level of risk they can accept and implement appropriate risk management measures.
How should credit institutions protect data?
Data from electronic banking transactions must be securely stored, complete, intact, and accurate. Technical measures must also be applied to prevent unauthorized access.
How should credit institutions establish monitoring, controlling, and internal auditing procedures?
Procedures must be developed and adjusted to fit the characteristics of electronic banking activities. This system must be regularly tested and evaluated to detect and prevent unauthorized access.
How should credit institutions submit periodic reports on electronic banking activities?
By the latest on January 20 and July 20 each year, credit institutions must submit reports to the State Bank of Vietnam on electronic banking activities and assess risk control results.
Toàn văn
Pursuant to …;
Issuing Regulations on Risk Management Principles
in Electronic Banking Activities
________________
GOVERNOR OF THE STATE BANK OF VIETNAM
Pursuant to the Law on the State Bank of Vietnam 1997; the Law Amending and Supplementing Certain Provisions of the Law on the State Bank of Vietnam 2003;
Pursuant to the Law on Credit Institutions 1997; the Law Amending and Supplementing Certain Provisions of the Law on Credit Institutions 2004;
Pursuant to the Law on Electronic Transactions 2005;
Pursuant to Decree No. 52/2003/ND-CP dated May 19, 2003, issued by the Government, detailing the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Department of Banks and Non-Bank Credit Institutions,
DECISION:
Article 1. These Regulations on Risk Management Principles in Electronic Banking Activities are hereby issued together with this Decision.
Article 2. The Standard Measurement Quality Control Department shall be responsible for organizing and guiding the implementation of the Regulations adopted herein.
Article 3. The Head of the Office, the Director of the Department of Banks and Non-Bank Credit Institutions, the Heads of relevant units under the State Bank of Vietnam, the Governors of the State Bank of Vietnam Branches in provinces and centrally governed cities, and the Chairmen of the Boards of Directors, General Managers (Directors) of credit institutions shall be responsible for implementing this Decision./.
|
DIRECTOR DEPUTY DIRECTOR (Signed)
Dang Thanh Binh |
REGULATIONS
ON RISK MANAGEMENT PRINCIPLES IN ELECTRONIC BANKING ACTIVITIES
(Issued together with Decision No. 35/2006/QD-NHNN dated July 31, 2006 of the Governor of the State Bank of Vietnam)
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation and Applicability
These Regulations determine risk management principles in electronic banking activities.
Credit institutions and foreign bank branches in Vietnam (hereinafter referred to collectively as credit institutions) that conduct electronic banking activities must comply with the risk management principles set forth in these Regulations.
Article 2. Purpose
Risk management principles in electronic banking activities serve as the basis for credit institutions to establish internal regulations on risk management in electronic banking activities.
Article 3. Explanation of Terms
In this Regulation, the following terms shall be understood as follows:
Electronic banking activities are banking activities conducted through electronic distribution channels.
An electronic distribution channel is a system of electronic means and automated transaction processing procedures used by credit institutions to communicate with customers and provide banking products and services to them.
Risks in electronic banking activities are the possibilities of losses occurring when conducting electronic banking activities.
Customers are organizations and individuals having transactions with credit institutions.
Third parties are specialized organizations hired or cooperating with credit institutions to provide technical support services for electronic banking activities.
Article 4. Scope of Electronic Banking Activities
Credit institutions may carry out electronic banking activities within the scope of their business content as stipulated in their Licenses for Establishment and Operation and consistent with their Articles of Association.
Article 5. General Principles
Credit institutions are responsible for the safety and effectiveness of electronic banking activities; protecting the legitimate rights and interests of credit institutions, customers, and the state and society in accordance with the law.
To effectively manage risks arising from electronic banking activities, credit institutions need to:
a) Identify potential risks that may arise from current or planned electronic banking activities;
b) Analyze and determine the possible impacts and consequences when risks occur;
c) Categorize types of risks; determine directions and measures to prevent risks, particularly paying attention to cybersecurity management and information protection; determine the maximum acceptable loss level in case of risk occurrence; refrain from implementing types of electronic banking activities requiring preventive measures beyond their current capabilities;
d) Regularly evaluate and check the results and effectiveness of risk management work; audit and update risk management procedures.
PART II
RISK MANAGEMENT PRINCIPLES IN ELECTRONIC BANKING ACTIVITIES
PART 1
INTERNAL RISK MANAGEMENT IN CREDIT INSTITUTIONS
Article 6. Development of Electronic Banking Operation Plan
Prior to implementing electronic banking activities, credit organizations must develop an operation plan ensuring the following basic contents:
The basis for deciding to implement electronic banking activities such as: market demand; the development strategy of the credit organization; the credit organization's capacity to meet requirements regarding capital, technology, technical skills, management capability, risk control, and human resources.
Specific objectives of the credit organization when implementing electronic banking activities.
Potential risks that may arise during the implementation of electronic banking activities and corresponding risk management measures.
A plan to evaluate the effectiveness of electronic banking activities at least once a year through basic criteria such as: income and expenses from electronic banking activities; the number of regular customers using electronic banking services and products; the total number of electronic banking transactions completed and the average cost per transaction; other criteria appropriate to the actual operations of the credit organization.
Article 7. Risk Management Policy
Determine the maximum level of risk that the credit organization can accept;
Specific responsibilities of each department participating in electronic banking activities;
Regulations on periodic reporting and immediate reporting in case of incidents;
Measures to manage specific types of risks arising during the provision of electronic banking products and services; simultaneously requiring third parties to apply similar measures;
Research and assess the level of risk and the ability to control risk, conducting trial operations of new products before supplying them to the market.
Article 8. Definition of Scope of Responsibility and Authority
Credit organizations must clearly define the scope of responsibility and authority of each department and employee involved in an electronic banking activity process:
Review and amend (if necessary) the existing system of authority and responsibility allocation within the credit organization to ensure it aligns with the characteristics and requirements of electronic banking activities.
Define the scope of responsibility between data entry personnel and data verification personnel.
Define the scope of responsibility between the system construction department and the system management department in electronic banking activities.
Regularly check compliance with the hierarchical allocation of responsibility and authority in electronic banking activities.
Article 9. Data Protection
Credit organizations must have appropriate measures to ensure that all data from electronic banking transactions are securely stored, fully, completely, accurately, and in accordance with the principle:
a) All data and databases of electronic banking transactions must be stored, paying particular attention to account opening or closing for customers; financial-related transactions; changes in access rights, access scope, and transaction limits for individuals within the credit organization and customers.
b) Regulations on granting, registering, and securing access rights for each employee and customer in electronic banking activities.
c) Any addition, deletion, or change to the database of an organization, individual, or system must be carried out by an authorized entity. Information about the time of deletion or change to the database and the person performing these actions must be recorded for inspection and control purposes.
Credit organizations must establish a data security control process in electronic banking activities.
a) Apply necessary technical and technological measures to prevent unauthorized access to applications and databases of electronic banking activities;
b) Regularly review and test the effectiveness of data security management measures to make timely adjustments if necessary.
Credit organizations must apply necessary measures to ensure the confidentiality of information in electronic banking activities. Each specific measure must be commensurate with the importance of the information being transmitted or stored in the database.
Only authorized individuals are permitted to access confidential data of the credit organization;
All confidential information of the credit organization must be securely stored and protected from any risk of modification, unauthorized access, or leakage during data transmission over internal or public networks;
Third parties who have access to confidential information of the credit organization must comply with all standards and inspection and control procedures established by the credit organization;
Credit organizations must implement technical measures to record each access to confidential information and ensure that this stored information cannot be modified.
Article 10. Inspection, Supervision, and Internal Audit
Credit organizations must establish and adjust internal inspection, supervision, and audit procedures to be suitable with the characteristics of electronic banking activities.
The electronic banking system must be regularly checked and evaluated, and periodically or unexpectedly internally controlled and audited to detect and prevent unauthorized access or overstepping authority.
Attention should be paid to copyright issues for software and applications used in the electronic banking system.
Data related to an electronic banking transaction must be fully retained to serve the credit organization's internal inspection, supervision, and audit work. The retention period for electronic transaction documents shall be carried out in accordance with the legal provisions on recordkeeping.
PART 2
MANAGEMENT OF RISKS IN TRANSACTIONS WITH CUSTOMERS
Article 11. Transaction Principles
Ensuring the security and integrity and accuracy of information, data, and databases of transaction figures in electronic banking operations.
Classifying transactions, important transactions must be reviewed and monitored by authorized persons at each department and must be cross-checked and monitored between functional departments within the credit organization.
Ensuring the provision of accurate information to customers to help them understand and assess correctly the capabilities and current status of the credit organization, their rights and obligations before engaging in transactions with the credit organization.
Article 12. Principles in Relations with Customers
Credit organizations must specify the procedures and formalities for establishing relations, accepting, and processing electronic banking transactions with customers.
Ensuring verification of customer identity, access to information, accounts, scope, and permitted transaction limits.
Establishing and clearly publicizing the obligations, responsibilities, and authorities of customers when making transaction proposals; ensuring prevention of customer denial or renunciation of transactions.
When signing contracts to provide electronic banking services to customers and/or during the first use of these services by customers, banks must have the responsibility to publicly explain and clearly detail all possible risks that customers may encounter when using these services.
Preventing and promptly detecting any forgery or alteration of accounting, financial information, and commitments related to the rights and obligations of credit organizations and customers.
PART 3
MANAGEMENT OF RISKS TOWARDS THIRD PARTIES
Article 13. Evaluation of Third Parties
In cases where third parties are hired or cooperated with to provide technical support services for electronic banking activities, credit organizations must:
Carefully and thoroughly evaluate potential risks and have contingency plans for service interruptions provided by third parties.
Scrutinize the technical capabilities and financial capacity of partner entities. Partner entities must have sufficient financial capability, reputation, and potential to bear legal and financial responsibilities that may arise related to the services they provide.
Pay attention to security and confidentiality issues when third-party employees are allowed access to the electronic banking system.
Clearly define the responsibilities, authorities, and obligations of both parties in leasing and cooperation contracts; ensuring that credit organizations have the right to periodically or unexpectedly inspect and monitor third-party technical support service activities and have the right to request third parties to conduct independent audits if necessary.
Regularly evaluate difficulties, incidents, and potential issues in relationships with third parties in electronic banking activities to implement appropriate risk management measures.
Article 14. Data
In cases where a third party is responsible for managing the system processing and storing data, credit organizations must ensure that:
The contract signed with the third party clearly stipulates the credit organization's right to access necessary data.
All data stored by the third party must meet the credit organization's standards and requirements for security.
PART 4
MANAGEMENT OF RISKS IN CASES WHERE INCIDENTS OCCUR
Article 15. Prevention of Incidents
Establish a database storage system and gradually build a backup system for electronic banking transactions.
Conduct regular and spot checks to evaluate: the continuous operation capability of the electronic banking system; current resources and future upgrade potential based on market factors for e-commerce and the expected customer acceptance rate for electronic banking services and products.
Develop contingency plans to control, isolate, and minimize disruptions arising from unexpected events, including incidents originating from both inside and outside the system, during and outside working hours, affecting the electronic banking system and impacting the provision of electronic banking services.
Develop incident control procedures, identify individuals responsible for receiving and handling information when electronic banking operations encounter incidents. Pre-identify personnel for the incident response team to prepare for serious incidents requiring immediate resolution. Credit organizations may pre-agree with third parties about mobilizing personnel into the incident response team in case of serious incidents.
Provide clear documentation defining the scope of responsibility of the credit organization and the third party in the event of an incident. This document must be fully provided to the third party upon signing the contract. If the document contains contents related to the rights and responsibilities of customers in the event of an incident, these contents must be disclosed to customers when they sign the service usage contract or on their first use of electronic banking services.
Article 16. Control and Resolution of Incidents
In the event of an incident in the electronic banking system, credit organizations must apply the following measures:
Implement incident handling measures according to the established incident control procedures and incident resolution plans.
Identify the point of incident occurrence, determine whether the cause of the incident is due to technical error or human factor. Isolate the impact and identify groups of customers potentially affected.
Promptly take measures to publicize and explain to the public, customers, and relevant parties about incidents occurring in the electronic banking system.
Collect and preserve legal evidence to serve the investigation and resolution of incidents concerning the electronic banking system and take measures against organizations and individuals violating the law.
Quickly resolve incidents, address disputes arising in connection with incidents, and compensate for damages within their responsibility to avoid risks to the credit organization's reputation.
Chapter III
IMPLEMENTING PROVISIONS
Article 17. Internal regulations of credit organizations
Based on the nature and characteristics of electronic distribution channels related to electronic banking activities, credit organizations shall be responsible for issuing internal regulations on risk management in electronic banking operations in accordance with current laws and the principles set forth in this Regulation.
Within six months from the date this Regulation takes effect, credit organizations that have implemented electronic banking activities must develop and submit their internal regulations on risk management in electronic banking operations to the State Bank of Vietnam (the State Bank's Inspectorate, the Department of Banks, the Banking Information Technology Department, the State Bank Branches in provinces and centrally-run cities where joint-stock credit organizations are headquartered) for inspection and supervision purposes.
In case credit organizations amend the contents of the aforementioned internal regulations, they must notify the State Bank of Vietnam (the State Bank's Inspectorate, the Department of Banks, the Banking Information Technology Department, the State Bank Branches in provinces and centrally-run cities where joint-stock credit organizations are headquartered) about those changes.
Article 18. Reporting
At the latest on January 20th and July 20th each year, credit organizations must submit reports to the State Bank of Vietnam (the State Bank's Inspectorate, the Department of Banks, the State Bank Branches in provinces and centrally-run cities where joint-stock credit organizations are headquartered) on their electronic banking activities and evaluations of risk control and handling results for the first six months and the entire year.
The report must ensure the following contents:
a) Electronic banking products and services currently being provided;
b) Third parties hired or collaborating to perform electronic banking activities; electronic banking activities involving third parties and the forms of participation of these third parties;
c) The number of customers using electronic banking services and the growth rate of customers compared to the same period last year;
d) Turnover of electronic banking activities;
e) Incidents that occurred during the period. Incidents are reported according to four risk categories as stipulated in Chapter II of this Regulation, damages incurred, and measures taken to address them.
Article 19. Responsibilities of Units under the State Bank
The State Bank's Inspectorate:
a) Conducts inspections and supervises credit organizations' compliance with risk management principles in electronic banking activities within its authority.
b) Handles violations of this Regulation and other current laws within its authority and recommends the Governor of the State Bank to handle cases of violation.
State Bank Branches in provinces and centrally-run cities:
Conduct inspections and checks on compliance with risk management principles in electronic banking activities of joint-stock credit organizations within their jurisdiction and handle violations within their authority.
The Department of Banks and Non-bank Financial Institutions:
a) Studies and submits to the Governor of the State Bank for consideration and amendment of provisions on risk management in electronic banking activities in this Regulation.
b) Cooperates with the State Bank's Inspectorate to monitor compliance with risk management regulations in electronic banking activities of credit organizations.
The Banking Information Technology Department:
Cooperates with the State Bank's Inspectorate to check compliance with risk management regulations in electronic banking activities of credit organizations.
DIRECTOR
DEPUTY DIRECTOR
Signed
Dang Thanh Binh
DEPUTY MINISTER
Văn bản gốc (PDF)
Tải văn bản
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.