This Chapter details risk management in the operations of credit organizations, including general requirements for risk management, responsibilities of related parties, and specifically credit risk management. The main contents include: 1. General requirements for risk management: - Establishing policies and procedures for risk management in accordance with the State Bank's regulations. - Establishing a risk management department if total assets reach VND 300 billion or more. 2. Responsibilities of related parties: - Board of Directors, Board of Members: Fulfill functions and tasks related to risk management activities as prescribed. - General Director/Manager: Develop and implement risk management policies. 3. Credit risk management: - Implement credit risk management throughout the process of consideration, evaluation, and decision-making on granting credit. - Issue a credit risk management strategy with objectives regarding credit quality and credit limits.
적용 범위
Applies to all credit organizations, including cooperative banks, microfinance institutions, and people's credit funds.
핵심 사항
- General risk management requirements
- Responsibilities of related parties in risk management
- Details on credit risk management
- Establish a risk management department when total assets reach VND 300 billion or more.
- Issue a credit risk management strategy
🌐 이 문서의 사회적 영향
- Enhance the operational quality of credit organizations
- Minimize risks in credit granting activities
- Strengthen transparency and compliance with laws in risk management.
❓ 자주 묻는 질문
Which credit organizations must establish a risk management department?
Credit organizations with total assets reaching VND 300 billion or more at the end of the fiscal year must establish a Risk Management Department within thirty days from the end of the fiscal year.
What are the credit quality objectives in the credit risk management strategy?
Minimum credit quality objectives must include non-performing loan ratios, loan-to-short-term capital ratios, and other indicators related to credit quality.
전문
|
STATE BANK OF VIETNAM VIETNAM _________ Number: 62/2025/TT-NHNN |
SOCIALIST REPUBLIC OF VIET NAM Independence - Freedom - Happiness ________________________ Hanoi, December 31, 2025 |
CIRCULAR
Regulations on the internal control system of credit organizations that are cooperatives,
microfinance institutions
Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12;
Based on the Law on Credit Institutions No. 32/2024/QH15 amended and supplemented by Law No. 96/2025/QH15;
Pursuant to Decree No. 26/2025/NĐ-CP of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;
At the proposal of the Director of the Credit Institution System Safety Department;
The Governor of the State Bank of Vietnam issues this Circular to regulate the internal control system of credit organizations that are cooperatives and microfinance institutions.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Circular regulates the internal control system of credit organizations that are cooperatives and microfinance institutions (hereinafter referred to as credit organizations).
Article 2. Applicability
1. Credit organizations that are cooperatives include cooperative banks and people's credit funds.
2. Microfinance institutions.
3. Organizations and individuals related to the internal control system of credit organizations.
Article 3. Explanation of Terms
In this Circular, the following terms are understood as follows:
1.Internal control systemis a set of mechanisms, policies, procedures, internal regulations, organizational structure of credit organizations and is organized for implementation to ensure prevention, detection, and timely handling of risks.
2.Control activitiesinvolve monitoring, tracking, inspecting, and self-controlling by individuals and departments in carrying out the operations of credit organizations according to mechanisms, policies, procedures, internal regulations, and professional ethical standards to comply with legal provisions, manage conflicts of interest, detect and promptly handle violations, establish and maintain a control culture within credit organizations. Control activities include oversight by senior management and internal control.
3. Senior managementincludes the Board of Directors, Board of Members; General Director (Director); Audit Committee.
4. Risk management (risk governance)involves identifying, measuring, monitoring, and controlling risks in the operations of credit organizations.
5Internal auditinvolves independently and objectively reviewing and evaluating the appropriateness and compliance of mechanisms, policies, procedures, and internal regulations of credit organizations; making recommendations to enhance the effectiveness of systems, procedures, and regulations, contributing to ensuring safe, efficient, and lawful operations of credit organizations.
6. Control culturerepresents the cultural values of credit organizations reflecting a unified understanding of the importance of control and risk management activities for the Board of Directors, Board of Members, Audit Committee, General Director (Director), and individuals and departments within credit organizations to proactively identify and control risks in their own operations and those of the organization.
7. Riskis the possibility of loss (financial loss, non-financial loss) or the possibility of an unfavorable outcome that may negatively impact the income, capital, liquidity of credit organizations. Types of risks include credit risk, operational risk, concentration risk, liquidity risk, and other risks that need to be managed in the operations of credit organizations.
8. Risk statusis the level of risk of a credit organization at a given point in time reflected through the value after being converted according to the risk of risky assets, risky liabilities, and risky off-balance-sheet items.
9. Credit risk includes:
a) Customer credit risk is the risk arising from customers not fulfilling or not having the ability to fulfill part or all of their debt obligations under contracts or agreements with credit organizations.
Customers are individuals, legal entities (including other credit organizations, foreign bank branches) having credit relationships or deposit transactions with credit organizations;
b) Counterparty credit risk is the risk arising from counterparties not fulfilling or not having the ability to fulfill part or all of their payment obligations prior to or upon maturity of proprietary trading transactions; repurchase transactions and reverse repurchase transactions; foreign exchange and financial asset transactions to serve customer and counterparty needs and transactions to offset these transactions.
Counterparties are individuals, other credit organizations, foreign bank branches, legal entities engaging in transactions with credit organizations including proprietary trading transactions; repurchase transactions, reverse repurchase transactions; derivative product transactions to hedge risks; foreign exchange and financial asset transactions with the purpose of serving customer and counterparty needs and transactions to offset these transactions.
10. Liquidity riskarises from:
a) The credit organization not having the ability to fulfill its financial obligations when due;
b) The credit organization having the ability to fulfill its financial obligations when due but having to pay higher costs than the average market cost as stipulated by the credit organization's internal regulations.
11. Operational riskarises from incomplete or erroneous internal rules, regulations, procedures, human factors, errors, failures of systems, or external factors causing financial losses or negative non-financial impacts on credit organizations. Operational risk includes legal risk and does not include reputation risk or strategic risk.
12. Legal riskarises from the credit organization possibly having to bear penalties (including both financial and non-financial responsibilities) arising from violations of legal provisions or breaches of obligations and agreements with related parties.
13. Reputation riskarises from customers, counterparties, investors, and the public having negative reactions regarding the reputation of credit organizations.
14. Strategic riskarises from the credit organization lacking a strategy or having an ineffective strategy to respond promptly to business environment changes, thereby reducing the likelihood of achieving business strategies and profit targets of the credit organization.
15Concentration riskarises from the credit organization concentrating its business activities on one customer; one customer and related parties; one or several customers, counterparties, products, transactions, economic sectors to a significant extent affecting the income and risk status of the credit organization.
16. Significant riskincludes:
a) Credit risk, liquidity risk, operational risk, concentration risk;
b) Other risks as stipulated by the credit organization's internal regulations.
17. Significant activitiesis an activity determined internally by credit institutions based on quantitative criteria (such as own capital, total assets, income, expenses) or qualitative criteria.
18. Conflict of interestis a situation where an individual or department making decisions within their authority creates interests that are inconsistent with or contrary to the interests of the credit institution.
19. Risk decisionis a decision made by an authorized level of the credit institution that generates risk or changes the risk status of the credit institution.
20. Credit risk decisionis a risk decision made by the credit institution in its lending activities according to internal regulations of the credit institution, at a minimum including: loan granting decisions, credit limit setting decisions, loan granting decisions exceeding credit limits, restructuring repayment term decisions, loan classification transfer decisions.
21. Problem loan facilityis a loan facility classified into group 2 or higher according to the State Bank of Vietnam's (hereinafter referred to as the State Bank) regulations on asset classification in credit institution operations, and other loan facilities according to internal regulations of the credit institution.
22. Outsourcing activityis the agreement in writing between the credit institution and an individual, organization, another credit institution, or a foreign bank branch (hereinafter referred to as the third party) for data processing; customer identification; performing one or several stages of the credit institution's business process (excluding credit institution risk decisions) on behalf of the credit institution in accordance with the law.
23. Internal auditoris a person conducting internal auditing under the internal audit department of the credit institution.
24. Proprietary tradingis the purchase, sale, or exchange transaction conducted by a cooperative bank in accordance with the law for the purpose of buying, selling, or exchanging within one year to earn from market price differences for the cooperative bank regarding financial instruments, including:
a) Financial instruments in the money market;
b) Various currencies;
c) Securities in the capital market;
d) Derivative products.
25. Repurchase Agreement (Repo) transactionis a transaction in which one party sells and transfers ownership of a financial asset to another party, while committing to repurchase and reclaim ownership of the financial asset after a specified period at a predetermined price.
26. Reverse Repurchase Agreement (Reverse repo) transactionis a transaction in which one party buys and receives the transfer of ownership of a financial asset from another party, while committing to resell and transfer ownership of the financial asset after a specified period at a predetermined price, including term purchases of negotiable instruments and other securities in accordance with the State Bank's regulations on discounting activities of credit institutions and foreign bank branches for customers.
27. Liquidity stress testingis a predictive risk management tool to assess the potential impact of fluctuations and adverse changes on liquidity in different scenarios to determine the cooperative bank's ability to withstand liquidity risks.
Article 4. Requirements for the internal control system
1. The internal control system of credit organizations must meet the following requirements:
a) Comply with the provisions of the Law on Credit Institutions and amendments and supplements thereto (hereinafter referred to as the Law on Credit Institutions), this Circular, and other relevant legal documents; handle and rectify according to the requirements and recommendations of the State Bank, independent auditors, and other competent authorities;
b) Be appropriate to the scale, nature, and level of complexity in the business operations of credit institutions;
c) Have sufficient financial resources, human resources, and information systems to ensure the effectiveness of the internal control system;
d) Establish and maintain an internal control culture for credit institutions;
đ) Have a management information system that complies with the provisions of the Law on Credit Institutions, Clause 8 of this Circular, and related legal regulations to ensure the reliability, completeness, and timeliness of management information.
2. The internal control system must have three independent lines of defense as follows:
a) The first line of defense includes departments generating risks such as revenue-generating departments, departments implementing risk-taking decisions, departments allocating risk limits for each business activity, specific operational activities; and other risk-generating departments. The first line of defense has the function of identifying, implementing control measures, monitoring, and mitigating risks;
b) The second line of defense consists of at least the Compliance Department or Deputy General Director (Deputy Director) directly performing the duties of the Compliance Department as stipulated in Article 16 of this Circular and the Risk Management Department or Deputy General Director (Deputy Director) directly performing the duties of the Risk Management Department as stipulated in Article 26 of this Circular. The second line of defense has the function of developing risk management policies, internal regulations on risk management; measuring, monitoring, controlling risks across the entire credit institution, and complying with legal regulations;
c) The third line of defense has the function of internal auditing performed by the internal audit department in accordance with the Law on Credit Institutions and this Circular.
3. Opinions discussed and concluded regarding the internal control system in meetings of the Board of Directors, Board of Members; Supervisory Board; Committees, Boards as prescribed in this Circular must be recorded in writing.
Article 5. Mechanisms, Policies, Procedures, Internal Regulations
1. Requirements for mechanisms, policies, procedures, and internal regulations of credit institutions:
a) Comply with the provisions of this Circular and relevant legal regulations;
b) The delegation of decision-making authority must be based on the level of trustworthiness of the authorized level and the capability of individuals or departments executing the tasks. Decision-making authority must be expressed through criteria concerning the scale, complexity of transactions, risk limits, and other limits as stipulated in the internal regulations of the credit institution;
c) The definition of functions and responsibilities of individuals and departments from the lowest to the highest level in all transactions and operational processes within the credit institution must ensure the principle:
(i) Members of the Board of Directors, Board of Members shall not participate in reviewing and approving decisions involving risks within the functions and responsibilities of the General Director (Director). In cases where members of the Board of Directors, Board of Members concurrently hold the position of General Director (Director), the credit institution must apply control measures to ensure that conflicts of interest do not arise and that independent oversight is maintained;
(ii) Members of the Board of Directors, Board of Members shall not concurrently hold other positions or titles within the credit institution, except for the position of General Director (Director) as prescribed in the Law on Credit Institutions, positions or titles in the Risk Management Committee established by the Board of Directors, Board of Members;
(iii) For credit facilities within the approval and decision-making authority of the Board of Directors, Board of Members as stipulated in Articles 74, 79, and 88 of the Law on Credit Institutions, the credit institution must fully implement the credit granting process as if it were for credit facilities outside the aforementioned authority of the Board of Directors, Board of Members, and must be proposed and submitted to the Board of Directors, Board of Members by the General Director (Director) or Deputy General Director (Deputy Director) authorized by the General Director (Director);
(iv) Clearly separate functions and responsibilities in transactions and operational processes to prevent and control conflicts of interest; ensure that no individual controls an entire transaction or operational process; do not assign to one individual tasks that could lead to conflicts of interest; establish pre-, during-, and post-transaction control principles;
(v) Have independent individuals within the same department or independent departments to conduct periodic and ad hoc reviews as stipulated in the internal regulations of the credit institution;
(vi) In cases where the implementation of points c(iv) and c(v) of this clause still poses a risk of conflict of interest or violation of internal regulations, the credit institution must identify the cause, take measures to minimize risks in operations, and conduct more frequent independent monitoring and evaluation;
d) The delegation of responsibility for asset management (including both financial assets and tangible assets) must be clearly defined for each individual or department based on the value of the assets or specific limits as stipulated in the internal policy of the credit institution. The scope of delegation includes activities of receiving, storing, transporting, inspecting, and inventorying assets;
đ) Professional ethics standards (excluding professional ethics standards for members of the Supervisory Board and internal auditors) must be issued by the Board of Directors, Board of Members of the credit institution to ensure the principle:
(i) Staff at all levels perform their duties and powers honestly for the benefit of the credit institution; they shall not take advantage of their positions, use information, trade secrets, business opportunities, and assets of the credit institution to gain personal benefits or harm the interests of the credit institution;
(ii) Individuals and departments responsible for promptly reporting to the competent authority when detecting violations as stipulated in point đ(i) of this clause and internal regulations of the credit institution, as well as violations of the law;
e) Must be evaluated periodically or unexpectedly according to the credit institution's regulations on suitability, compliance with legal provisions, and amendments;
g) Internal regulations regarding the control activities of the credit institution over branches and affiliated units must include provisions on functions, tasks, reporting mechanisms, salaries, rewards, disciplinary actions, staff rotation, and other mechanisms for individuals and departments performing branch and affiliated unit control activities;
h) Internal regulations regarding risk management activities as prescribed in Article 19 of this Circular;
i) Internal regulations regarding internal auditing as prescribed in Article 51 of this Circular;
k) Internal regulations regarding internal reporting must ensure contents including: data collection time for report preparation; completion time of the report; individuals and departments preparing, approving, receiving the report; responsibility for handling proposals and recommendations in the report (if any);
2. The issuing authority of the credit institution:
a) The Board of Directors, Board of Members issues regulations on the organization, governance, and operations of the credit institution, except for matters within the authority of the Member Assembly, owner;
b) The Audit Committee issues internal regulations of the Audit Committee;
c) The General Director (Director) issues internal rules, procedures, and operational processes within his/her authority to operate the business management system, management information system (hereinafter referred to as internal procedures), except for matters within the authority of the Member Assembly, owner, Board of Directors, Board of Members, Audit Committee;
Article 6. Organizational Structure of the Internal Control System
1. The organizational structure of the internal control system at the credit institution includes: Board of Directors, Board of Members; Audit Committee; General Director (Director); individuals and departments as prescribed in this Article;
2. The Board of Directors, Board of Members of the credit institution have responsibilities and authorities as prescribed by the Law on Credit Institutions and consistent with the provisions of this Circular. The Board of Directors, Board of Members must establish the following committees:
a) Risk Management Committee and Human Resources Committee:
(i) The organizational structure of the Risk Management Committee and Human Resources Committee of the cooperative bank is decided by the Board of Directors but each committee must have at least three members and must ensure that at least half of the voting members of each committee are non-executive members. The Chairman is a member of the Board of Directors. Each member of the Board of Directors can only be the Chairman of one committee. The Chairman and other members of both committees are appointed and relieved of duty by the Board of Directors according to the regulations of the cooperative bank. The Risk Management Committee and Human Resources Committee of the cooperative bank perform functions and tasks as prescribed in point d of Clause 2 of this Article;
(ii) The Risk Management Committee and Human Resources Committee of microfinance organizations operate according to the State Bank's regulations on licensing, organization, and operation of microfinance organizations;
(iii) The Risk Management Committee and Human Resources Committee of people's credit funds operate as follows:
- People's credit funds with total assets reaching 300 billion VND or more at the end of the fiscal year must establish the Risk Management Committee and Human Resources Committee within thirty days from the end of the fiscal year. The organizational structure of both committees is decided by the Board of Directors but each committee must have at least two members to perform the functions and tasks prescribed in point d of Clause 2 of this Article. Each member of the Board of Directors can only be the Chairman of one committee. The Chairman and other members of both committees are appointed and relieved of duty by the Board of Directors according to the regulations of the people's credit fund;
- People's credit funds with total assets under 300 billion VND at the end of the fiscal year do not need to establish committees and the Board of Directors must assign different members of the Board of Directors to perform the tasks of each committee prescribed in point d of Clause 2 of this Article. In case of establishing committees, the people's credit fund operates according to the provisions of this point and points b, c, d of Clause 2 of this Article;
b) The Board of Directors of the cooperative bank and people's credit funds with total assets reaching 300 billion VND or more issue working regulations, define the functions and tasks of the Human Resources Committee and Risk Management Committee. Within ten days from the date of issuance or amendment of the working regulations, the cooperative bank must submit these internal regulations to the State Bank (through the Credit Institution Supervision Department), and the people's credit fund must submit these internal regulations to the State Bank branch in the region where its headquarters is located;
c) Working regulations of the committees must include the following contents:
(i) Number of committee members and responsibilities of each member;
(ii) Regular meetings of the committee;
(iii) Extraordinary meetings of the committee;
(iv) Decision-making process of the committee;
d) Regulations on the functions and tasks of the committees:
(i) Risk Management Committee:
- Advising the Board of Directors on issuing risk management policies, procedures, and internal regulations on risk management in accordance with the law and the charter of the credit institution which is a cooperative;
- Analyzing and warning about the safety level of the cooperative credit institution against potential risks that may affect it and preventive measures for these risks in the short and long term;
- Reviewing and assessing the suitability and effectiveness of current risk management processes and policies of credit cooperatives to provide recommendations and proposals to the Board of Directors regarding requirements for changes to existing procedures, policies, and strategies;
- Advising the Board of Directors on decisions to approve investments, related transactions, risk management policies, and risk handling plans within the scope of functions and tasks assigned by the Board of Directors;
(ii) The Human Resources Committee:
- Advising the Board of Directors on the size and structure of the Board of Directors and suitable managers in accordance with the scale of operations and development strategy of credit cooperatives;
- Advising the Board of Directors on personnel issues arising during the process of conducting election, appointment, removal, and dismissal procedures for members of the Board of Directors, members of the Supervisory Board, and managers of credit cooperatives in compliance with legal regulations and the Charter of credit cooperatives;
- Studying and advising the Board of Directors on issuing internal regulations of credit cooperatives within the Board's authority concerning salary systems, remuneration, bonuses, recruitment and selection rules, training programs, and other incentive policies for managers, staff, and employees of credit cooperatives;
3. The Supervisory Board has duties and powers as prescribed in the Law on Credit Institutions and consistent with the provisions of this Circular. The Supervisory Board defines the organizational structure, functions, tasks, and authorities of the Internal Audit Department as stipulated in the Law on Credit Institutions and this Circular;
4. The General Director (Director) of credit institutions has duties and powers as prescribed in the Law on Credit Institutions and consistent with the provisions of this Circular. The General Director (Director) of credit institutions has an assisting department as provided for in Article 16 and Article 26 of this Circular. The General Director of cooperative banks also establishes an advisory council as provided for in Clause 5 of this Article;
5. The General Director of cooperative banks shall establish a Risk Management Council and an Asset/Liability Management Council (hereinafter referred to as the ALCO Council) to propose and advise the General Director on risk management and asset/liability management content as prescribed in Point a, Clause 2 and Clause 3, Article 25 of this Circular, with an organizational structure ensuring:
a) The Risk Management Council consists of: The Chairman being a manager at the main office (not the General Director) who specializes in risk management, having experience, knowledge, and expertise in risk management, and other members from relevant departments as prescribed internally. The Chairman of the Risk Management Council cannot concurrently be the Chairman of the ALCO Council as prescribed in Point b, Clause 5 of this Article and the head of the Risk Management Department as prescribed in Article 26 of this Circular;
b) The ALCO Council consists of: The Chairman being the General Director or another manager at the main office and other members from relevant departments as prescribed internally;
c) The operating regulations of the councils are issued by the General Director and must minimally include the functions and tasks of the councils, the number of members and their functions and tasks; decision-making mechanisms; regular meetings (ensuring that the Risk Management Council and the ALCO Council meet at least once every quarter); extraordinary meetings and other contents.
Article 7. Implementation of internal control system
Credit organizations shall implement the internal control system through the following activities:
1. Control activities as prescribed in Chapter II of this Circular.
2. Risk management activities as prescribed in Chapter III of this Circular.
3. Internal audit activities as prescribed in Chapter IV of this Circular.
Article 8. Management Information System
1. Credit organizations must establish a management information system to collect, process, store, and provide information for management, operation, and decision-making in their operations.
2. The management information system of credit organizations must at least include:
a) Organizational structure for managing and operating the management information system, with specific internal regulations on the responsibilities of individuals and departments in managing, operating, and using the system.
b) Procedures for collecting, processing, storing, and providing information.
c) Data for management, operation, and decision-making in the organization's activities, including risk data managed as prescribed in Article 24 of this Circular.
d) Internal reports and other management information that are sent, received, and processed according to the internal regulations of the credit organization.
đ) Information technology infrastructure (hardware, software) suitable for the requirements of the management information system.
e) Backup systems to ensure safe, effective, and uninterrupted storage and use of data and information.
3. The management information system must ensure:
a) Data and information are complete, accurate, timely, and meet the management requirements of the credit organization as prescribed in this Circular and internal regulations of the organization; input data and information sources must be verified for reliability.
b) Ensuring the security and confidentiality of data and information in accordance with laws and internal regulations of the credit organization.
c) The Board of Directors, Board of Members, Supervisory Board, General Director (Director), and related individuals and departments are provided with sufficient and timely information to perform their functions, duties, and powers.
d) A mechanism for promptly reporting to authorized levels within the credit organization about violations of laws, internal regulations, and professional ethics standards by individuals and departments to ensure information security and protect information providers.
đ) Regularly reviewed and evaluated annually and ad hoc when necessary; upgraded and updated regularly to meet the information management needs, scale, structure, and complexity of business operations of the credit organization, ensuring compliance with legal provisions and internal regulations of the organization.
Article 9. Internal Reports on the Internal Control System
1. Internal reports on the internal control system include:
a) Internal report on control activities.
b) Internal report on credit risk.
c) Internal report on operational risk.
d) Internal report on liquidity risk.
đ) Internal report on concentration risk.
e) Internal report on internal audit.
2. The internal report on control activities includes evaluations of control activities as prescribed in Article 12 of this Circular and other contents as prescribed in the internal regulations of the credit organization.
3. The internal report on credit risk must at least include the following contents:
a) Credit quality for loan amounts, loan portfolios by customer type; products.
The internal report on credit risk of cooperative banks must also include the credit quality for loan amounts, loan portfolios by economic sector.
b) Problem loans, measures to handle problem loans.
c) Customers with actual credit balances exceeding the credit risk limits prescribed in point a, clause 2, Article 28 of this Circular.
The internal report on credit risk of cooperative banks must also include the economic sectors with actual credit balances exceeding the credit risk limits prescribed in point a, clause 2, Article 28 of this Circular.
d) Value of collateral, collateral portfolio by type of collateral as prescribed in Article 34 of this Circular.
đ) Situation of provisioning for risk, use of risk provisions to handle credit risks.
e) Early warning of potential breaches of credit risk limits.
g) Violations in credit risk management and reasons for such violations.
h) Recommendations and suggestions for credit risk management.
i) Results of implementing requirements and suggestions for credit risk management from internal audit, State Bank, independent auditors, and other competent authorities.
4. The internal report on operational risk must at least include the following contents:
a) Cases of operational risk arising during the reporting period and reasons.
b) Loss data due to operational risk, measures to handle losses and maintain continuous operations (if applicable).
c) Development and improvement of plans for maintaining continuous operations, activation results, testing, and drill results, review results of these plans (if applicable).
d) External events and impacts affecting operational risk of the credit organization.
đ) Situations of outsourcing activities and operational risk management for outsourcing activities (if applicable).
e) Changes in technology applications (if applicable) and management of operational risk in technology applications.
g) Recommendations and suggestions for operational risk management.
h) Results of implementing requirements and suggestions for operational risk management from internal audit, State Bank, independent auditors, and other competent authorities.
5. The internal report on liquidity risk must at least include the following contents:
a) Assessment of market liquidity situation.
b) Structure of the balance sheet; new capital-raising products generated during the reporting period; depositors; term and interest rates of deposits.
c) Sources of liquidity, cash flow differences, term of capital sources, compliance with liquidity risk limits.
d) Results of liquidity stress tests during the reporting period.
đ) Recommendations and suggestions for liquidity risk management.
e) Results of implementing internal audit requests, recommendations on liquidity risk management from the State Bank, independent auditing organizations, and other competent authorities.
6. The internal report on concentration risk shall include at least the following contents:
a) Credit structure by credit product; customer.
The internal report on concentration risk of a cooperative bank must also include the credit structure by economic sector.
b) Portfolio transaction structure by trading partner, transaction product;
c) Implementation status of concentration risk limits, reasons for exceeding limits (if any);
d) Recommendations and suggestions for managing concentration risk;
đ) Results of implementing internal audit requests, recommendations on concentration risk management from the State Bank, independent auditing organizations, and other competent authorities.
7. The internal report on internal audit shall include at least the following contents:
a) Implementation status of the scope and content of internal audit during the fiscal year;
b) Compliance with internal mechanisms, policies, and regulations on oversight by senior management, internal control, and risk management by the Board of Directors, Board of Members, General Director (Director), individuals, and departments;
c) Appropriateness and compliance with laws and regulations set forth in this Circular of internal mechanisms, policies, and regulations on oversight by senior management, internal control, and risk management;
d) Identified deficiencies and limitations during the implementation of internal audit, their causes; recommendations to competent authorities and relevant departments;
đ) Other contents as stipulated internally by the Supervisory Board of the credit institution.
8. Reporting deadlines:
a) Internal report on internal control: Annually or ad hoc as specified in the internal regulations of the credit institution;
b) Internal report on credit risk: At least quarterly or ad hoc as specified in the internal regulations of the credit institution;
c) Internal report on operational risk: Annually or ad hoc as specified in the internal regulations of the credit institution;
d) Internal report on liquidity risk: At least quarterly or ad hoc as specified in the internal regulations of the credit institution;
đ) Internal report on concentration risk: At least semi-annually or ad hoc as specified in the internal regulations of the credit institution;
e) Internal report on internal audit:
(i) Credit institutions shall submit reports annually or ad hoc as specified in the internal regulations of the Supervisory Board of the credit institution;
(ii) People's Credit Funds (in addition to submitting reports as provided for in point e(i) of Clause 8 of this Article) shall submit quarterly reports on lending activities.
9. Individuals and departments receiving reports:
Board of Directors, Board of Members, Supervisory Board, General Director (Director) and individuals and departments as specified in the internal regulations of the credit institution.
10. Internal reporting for microfinance organizations and people's credit funds shall be carried out as follows:
(i) Microfinance organizations are not required to prepare internal reports on concentration risk as provided for in point đ of Clause 1 of this Article and must ensure timely information about concentration risks that affect the operations of microfinance organizations to relevant departments and individuals as stipulated in this Circular;
(ii) People's Credit Funds, microfinance organizations with total assets under VND 300 billion at the end of the fiscal year must prepare at least the internal reports as provided for in points a, b, and e of Clause 1 of this Article for the next reporting period and must ensure timely information about operational risks, liquidity risks, and concentration risks that affect the operations of people's credit funds and microfinance organizations to relevant departments and individuals as stipulated in this Circular.
Article 10. Report to the State Bank on the internal control system
1. Credit organizations must prepare reports on the internal control system in accordance with the provisions of Clauses 2, 3, 4, 5, 6, and Clause 7 of this Article. In case of discovering missing, erroneous, incorrect, or unclear reports, the State Bank may require credit organizations to submit, explain, or meet directly according to the procedures and formalities for banking supervision.
2. The report on the internal control system includes:
a) Annual report on the results of self-inspection and evaluation of control activities as set out in Appendix I attached hereto;
b) Annual report on risk management as set out in Appendix II attached hereto;
c) Annual report on internal audit as set out in Appendix III attached hereto, and ad hoc internal audit report.
3. Deadline for submitting reports:
a) For the reports prescribed in points a and b of Clause 2 of this Article: Within ninety days from the end of the fiscal year, credit organizations shall submit the annual report;
b) For the report prescribed in point c of Clause 2 of this Article:
(i) Within sixty days from the end of the fiscal year, credit organizations shall submit the annual internal audit report;
(ii) Within seven working days from the completion of the ad hoc internal audit, credit organizations shall submit the ad hoc internal audit report.
4. Time of data cut-off for reporting:
a) For the annual report prescribed in Clause 2 of this Article, it is the end of the fiscal year;
b) For the ad hoc internal audit report prescribed in point c of Clause 2 of this Article, it is the time required for conducting the ad hoc internal audit.
5. Authority to approve the report:
a) The Board of Directors or Board of Members shall be responsible for approving the report prescribed in point a of Clause 2 of this Article;
b) The General Director (Director) of the credit organization shall be responsible for approving the report prescribed in point b of Clause 2 of this Article;
c) The Audit Committee shall be responsible for approving the report prescribed in point c of Clause 2 of this Article.
6. The report on the internal control system must update any existing issues, limitations, and risks arising (if any) throughout the entire credit organization.
7. The reports prescribed in Clause 2 of this Article shall be submitted to the State Bank (Credit Institution Management and Supervision Department) for cooperative banks and microfinance organizations, and to the State Bank branch in the region where the main office is located for people's credit funds, through one of the following methods:
a) Submitting directly to the State Bank;
b) Send through postal service;
c) Submitting online (if available).
Article 11. Archiving of Documents and Records on the Internal Control System
1. Credit organizations shall have internal regulations governing the management and archiving of documents and records related to the internal control system.
2. The management and archiving of documents and records related to the internal control system of credit organizations must ensure:
a) Compliance with legal provisions and the State Bank's regulations on the retention period for documents and records in the banking sector;
b) Adequate storage to provide access upon request for internal audit, independent auditors, and authorized agencies during internal audit, independent audit, inspection, and supervision processes.
Chapter II
INTERNAL CONTROL ACTIVITIES
Article 12. Requirements for control activities
1. Control activities must be carried out for all operations, business processes, individuals, and departments at credit organizations, ensuring compliance with the provisions of this Circular and internal regulations of the credit organization.
2. Accounting entries must comply with the prescribed accounting standards and accounting systems; consolidation, preparation, and submission of financial reports according to the laws and internal regulations of the credit organization. Accounting entries must be checked and reconciled to ensure timely detection and resolution of errors and must be reported to the competent authority as stipulated in the internal regulations of the credit organization.
3. Measures must be taken to promptly prevent and address violations of legal provisions and internal regulations of the credit organization.
4. Human resources must be allocated appropriately based on the nature and complexity of each business activity and control activity, including contingency staffing plans when staff are absent, recruitment procedures, rotation, and appointment of officials to maintain control activities and continuity in operations.
5. The head office of the credit organization's control activities over branches and other affiliated units must ensure:
a) The head office monitors and controls transactions and activities of branches and affiliated units, including monitoring and controlling through individuals or departments responsible for control activities of those branches and units;
b) The head office decides on functions, tasks, reporting mechanisms, salaries, rewards, disciplinary actions, rotation of officials, and other mechanisms for individuals or departments responsible for control activities;
c) Individuals or departments responsible for control activities of branches and affiliated units must ensure independence and avoid conflicts of interest with other individuals or departments within those branches and units.
6. Annually and periodically, the credit organization must submit internal reports on control activities as specified in Clause 2, Article 9 of this Circular to the competent authorities according to the internal regulations of the credit organization.
7. The credit organization must establish regulations for control activities related to electronic transactions to ensure compliance with the provisions of this Circular and relevant laws.
Article 13. Oversight by senior management
1. Oversight by senior management must meet the requirements stipulated in Article 12 of this Circular.
2. Oversight by senior management at credit organizations shall be conducted as follows:
a) The Board of Directors or Management Board of the credit organization oversees the General Director (Director) in implementing the provisions of Clause 2, Article 15 and Clause 2, Article 25 of this Circular;
b) The General Director (Director) of the credit organization oversees individuals and departments in implementing the provisions of Clause 3, Clause 4, Article 15 and Clause 3, Clause 4, and Clause 5, Article 25 of this Circular;
c) The Audit Committee of the credit organization oversees internal auditing as stipulated in Articles 54 and 55 of this Circular.
Article 14. Internal Control
1. Internal control must meet the requirements stipulated in Article 12 of this Circular.
2. Internal control is implemented through self-control activities of individuals and departments in business processes and activities of individuals and departments with oversight and inspection functions over other individuals and departments in adhering to mechanisms, policies, procedures, internal regulations, and legal provisions.
Article 15. Responsibilities of the Board of Directors, Board of Members, General Director (Director), individuals, and departments in internal control activities
1. The Board of Directors and Board of Members of credit organizations shall perform functions and tasks related to internal control activities as prescribed in this Circular and internal regulations of the credit organization.
2. The General Director (Director) of credit organizations shall be responsible for organizing the implementation of:
a) Internal control activities within their authority;
b) Operation and maintenance of management information systems to meet the requirements stipulated in Article 8 of this Circular;
c) Maintaining the internal control culture as prescribed in Clause 6, Article 3 of this Circular and professional ethics standards as prescribed in Point d, Clause 1, Article 5 of this Circular;
d) Handling violations of internal regulations and professional ethics standards (excluding professional ethics standards of members of the Supervisory Board and internal auditors); transferring cases of law violations to competent authorities for timely handling;
đ) Implementing other contents as prescribed by the credit organization.
3. The Compliance Department or Deputy General Director (Deputy Director) assigned to perform the duties of the Compliance Department shall carry out tasks as prescribed in Clause 3, Article 16 of this Circular.
4. Individuals and other departments of credit organizations shall be responsible for:
a) Implementing internal regulations on internal control, maintaining the internal control culture; implementing professional ethics standards (excluding professional ethics standards of members of the Supervisory Board and internal auditors);
b) Operating, evaluating, upgrading, and updating management information systems according to internal regulations of the credit organization to meet the requirements stipulated in Article 8 of this Circular;
c) Implementing other contents as prescribed by the credit organization.
Article 16. Compliance Department
1. Credit organizations with total assets reaching 300 billion VND or more at the end of the fiscal year must establish a Compliance Department within thirty days from the end of the fiscal year to perform the functions and tasks prescribed in Clause 3 of this Article.
2. Credit organizations not falling under the circumstances prescribed in Clause 1 of this Article are not required to establish a Compliance Department. In case of not establishing a Compliance Department, the credit organization assigns a Deputy General Director (Deputy Director) to directly perform the duties of the Compliance Department as prescribed in Clause 3 of this Article.
3. The tasks and powers of the Compliance Department shall be decided by the General Director (Director) of the credit organization, ensuring that the Compliance Department has at least the following tasks:
a) Identifying compliance issues related to the operations of the credit organization as prescribed by law;
b) Periodically assessing internal regulations according to the credit organization's regulations on suitability and compliance with laws and proposing amendments and supplements (if necessary);
c) Assessing regulations on the tasks and powers of the Compliance Department and proposing amendments and supplements (if necessary);
d) Reporting to the General Director (Director):
(i) Compliance with laws periodically and urgently;
(ii) Violations in compliance with laws, changes in relevant laws according to the credit organization's internal regulations;
(iii) Remediation of existing and limited internal control issues (if any);
đ) Directly reporting to the Board of Directors, Board of Members when necessary (including when the General Director (Director) commits violations) according to the credit organization's internal regulations;
e) Monitoring and inspecting individuals and departments in compliance with laws, mechanisms, policies, procedures, and internal regulations;
g) Supporting related departments in building and reviewing internal regulations to ensure compliance with laws; coordinating to resolve issues regarding compliance with laws according to the credit organization's internal regulations; notifying related departments about changes in relevant laws according to the credit organization's internal regulations.
Article 17. Supervisory activities for credit granting operations
1. The supervisory activities for credit granting operations of credit institutions must comply with the provisions set forth in Article 12 of this Circular.
2. Credit granting operations, except for the provisions stipulated in Clause 3 of this Article, shall be subject to conflict of interest control through the principle that individuals or departments responsible for credit assessment functions must be independent from those approving credit decisions.
a) Approving credit decision;
b) Controlling credit risk limits; managing problematic credit grants; setting aside provisions for credit risks and using provisions to address credit risks;
c) Customer relationships in accordance with internal regulations of credit institutions.
3. Credit institutions that conduct credit approval via electronic means must control conflicts of interest through the principle of clearly defining the responsibilities of each individual or department involved in establishing and operating the information system serving the credit assessment and decision-making process. In case of any risks arising, the credit institution must have mechanisms to identify the responsible individuals or departments and promptly address any emerging issues and risks to ensure the effectiveness and safety of electronic credit approval operations.
Chapter III
RISK MANAGEMENT ACTIVITIES
Section 1
GENERAL PROVISIONS ON RISK MANAGEMENT ACTIVITIES
Article 18. Requirements for Risk Management
1. Credit institutions must implement risk management to meet the following requirements:
a) Managing risks in the operations of credit institutions in accordance with this Circular and internal regulations of credit institutions;
b) Fully identifying, reasonably measuring, and continuously monitoring to timely prevent and mitigate significant risks; the measurement requirement herein applies at least to the types of significant risks specified in Point a, Clause 16, Article 3 of this Circular;
c) Controlling risk status to ensure compliance with risk limits;
d) Having a system of information to carry out risk management, wherein data must meet the requirements set forth in Article 24 of this Circular;
đ) Decisions involving risks must be transparent, clear, and consistent with the risk management policy and risk limits;
e) Specifically delegating approval authority and implementing preventive measures for each type of significant risk.
2. Microfinance organizations are not required to implement risk management contents related to customer credit limit restrictions and concentration risks.
3. People's Credit Funds and microfinance organizations are not required to implement risk management contents related to economic sector credit risks and foreign currency liquidity risks.
4. For credit institutions with subsidiaries, credit institutions must direct and supervise through capital representatives to ensure that subsidiary risk management aligns with the credit institution’s risk management policies and maintain the minimum consolidated capital adequacy ratio in accordance with the State Bank of Vietnam’s regulations.
Article 19. Internal Regulations on Risk Management Activities
1. Credit institutions must establish internal regulations on risk management activities, which must include at least the following contents:
a) The establishment, issuance, and implementation of risk management policies;
b) The establishment, issuance, and implementation of risk limits for at least each type of significant risk specified in Point a, Clause 16, Article 3 of this Circular (including methods for establishing risk limits, individuals or departments responsible for establishing risk limits, allocation of risk limits, and handling violations of risk limits);
c) Identifying, measuring, monitoring, and controlling risks for each type of significant risk specified in Point a, Clause 16, Article 3 of this Circular;
d) Internal reporting mechanisms for risk management;
đ) Risk management for new products and activities in new markets;
e) Cooperative banks must perform liquidity stress testing as prescribed in Article 38 of this Circular;
g) Risk data management;
h) Other necessary contents according to the risk management requirements for each type of significant risk.
2. Internal regulations on risk management must ensure the following principles:
a) Being developed in line with business strategies, control culture, human resources, information technology conditions, and management information systems of credit institutions;
b) Risk statuses and violations of risk management must be reported promptly and fully to the Board of Directors, Board of Members, and Audit Committee; there must be mechanisms to handle risk management violations;
c) Complying with the provisions of Clause 2 and Clause 3 of Article 18 of this Circular.
Article 20. Risk Management Policy
1. The risk management policy of credit organizations shall be issued, amended, and supplemented by the Board of Directors or the Board of Members.
2. The risk management policy shall include at least the following contents:
a) Risk appetite including:
(i) Target capital adequacy ratio;
(ii) Income indicators: Return on Equity (ROE) ratio;
(iii) Other qualitative risk acceptance indicators according to internal regulations of credit organizations;
b) List of significant risks as prescribed in this Circular;
c) Risk management strategy for each significant risk.
3. The risk management policy must ensure the following requirements:
a) Established for a minimum period of three years but not exceeding five consecutive years, reviewed annually at least once and reviewed promptly when there are changes in the business environment or legal framework;
b) Consistent with the interests of shareholders and contributing members of credit organizations as stipulated by law;
c) Consistent with the level of own capital and the availability of sources to increase own capital;
d) Continuous and inheritable to ensure feasibility through economic cycles.
Article 21. Risk Limits
1. Risk limits of credit organizations shall be issued, amended, and supplemented by the General Director (Director).
2. Risk limits must ensure:
a) Compliance with provisions on restrictions to ensure safety in the operations of credit organizations under the Law on Credit Organizations and regulations of the State Bank;
b) Risk limits to control significant risks as prescribed in point a, Clause 16, Article 3 of this Circular;
c) Consistency with risk appetite, risk management strategy, and total risky assets allocated to that risk;
d) Reviewed and re-evaluated (amended and supplemented if necessary) at least once a year or when there are significant changes affecting the risk status according to internal regulations of credit organizations. In case of amending and supplementing risk limits in a more relaxed direction, the General Director (Director) must report to the Board of Directors or the Board of Members after adjustment;
e) Made available to relevant individuals and departments.
3. Where an activity, transaction, or product has different risk limits for different risks, credit organizations must apply a more cautious risk limit.
Article 22. Identification, Measurement, Monitoring, and Control of Risks
1. Risk Identification:
Credit organizations must identify significant risks in transactions, products, activities, operational processes, and causes of risk and determine the causes of such risks.
2. Risk Measurement:
a) Credit organizations must measure the level of risk based on determining the short-term and long-term impact of that risk on income, capital, and liquidity of the organization;
b) Risk measurement must be timely and must have a risk measurement method. The risk measurement method must be regularly tested and evaluated for accuracy and reasonableness according to internal regulations of credit organizations. Data used in risk measurement methods must comply with the provisions of Clause 1, Article 24 of this Circular.
3. Risk Monitoring: Credit organizations must monitor the risk status and promptly evaluate and warn about the possibility of violating risk limits and restrictions to ensure safety in operations.
4. Risk Control:
a) Credit organizations must control risk statuses, transactions, and activities according to corresponding risk limits;
b) Credit organizations must take preventive, mitigating, and timely handling measures for risks to ensure compliance with risk limits, restrictions to ensure safety in operations, and have a monitoring and inspection mechanism for these measures.
Article 23. Risk Management for New Products and Activities in New Markets
1. The risk management for new products and activities in new markets of permitted business operations of credit organizations must ensure the following requirements:
a) There must be internal regulations specifying criteria to determine new products and activities in new markets;
b) There must be a process for providing new products and activities in new markets that ensures the principle that the Board of Directors, Board of Members approve the policy on providing new products and activities in new markets based on the proposal of the General Director (Director). The General Director (Director) approves the plan for providing new products and activities in new markets.
2. The plan for providing new products and activities in new markets must be reviewed by the Risk Management Department regarding risks, risk management measures, and specifically identify at least the following contents:
a) The scale, testing period for providing new products and activities in new markets based on assessing potential risks arising from providing new products and activities in new markets, impact on equity and income to ensure suitability with the credit organization's risk control capability;
b) The official provision time for new products and activities in new markets based on evaluating the test results against the risk management indicators set by the credit organization.
3. When officially providing new products and activities in new markets, the credit organization must issue regulations and procedures for providing new products and activities in new markets and manage significant risks of new products and activities in new markets.
Article 24. Risk Data Management
Risk data is used to implement risk management activities as stipulated in this Chapter. Credit organizations manage risk data according to internal regulations, ensuring at least the following requirements:
1. Risk data must be accurate and complete, ensuring consistency in data concepts, having internal reporting channels, and a plan to address poor quality data (if any).
2. Credit organizations must collect and aggregate risk data, at least including all risk data from significant risks.
For people's credit funds, minimum risk data must include figures, information to serve the calculation of limits, safety ratios in operations; the time, cause of significant risks occurring, and solutions applied to handle risks and losses.
3. Credit organizations must be able to aggregate risk data to serve risk management activities quickly and timely.
4. Credit organizations must be able to aggregate risk data to meet the requirements of various types of risk management reports.
Article 25. Responsibilities of the Board of Directors, Board of Members, General Director (Director), Individuals, and Departments in Risk Management
1. The Board of Directors, Board of Members of credit organizations perform functions and tasks related to risk management activities as stipulated in this Circular and internal regulations of the credit organization.
2. The General Director (Director) of credit organizations has the responsibility:
a) To build and organize the implementation of risk management policies;
b) To carry out other contents as prescribed by the credit organization.
3. Individuals and departments responsible for managing Assets/Loans Payable of credit organizations have the responsibility:
- Managing the balance sheet effectively and in accordance with risk management policies;
- Reviewing and proposing capital raising plans, capital usage plans, principles for setting internal capital transfer prices;
- Establishing interest rate frameworks; pricing frameworks for other products (if any) to manage financial assets and loans payable;
- Controlling business activities to ensure compliance with liquidity risk limits;
- Other contents as prescribed by the credit organization.
4. The Risk Management Department, Deputy General Director (Deputy Director) assigned to perform the Risk Management Department's tasks of the credit organization shall fulfill the tasks as stipulated in Clause 3, Article 26 of this Circular.
5. Individuals and other departments of credit organizations related to risk management have the responsibility to implement according to internal risk management regulations of the credit organization.
Article 26. Risk Management Unit
1. Credit organizations with total assets reaching 300 billion VND or more at the end of the fiscal year must establish a Risk Management Unit within thirty days from the end of the fiscal year to perform the functions and tasks specified in Clause 3 of this Article.
2. Credit organizations not falling under the provisions of Clause 1 of this Article are not required to establish a Risk Management Unit. In cases where a Risk Management Unit is not established, the credit organization shall assign a Deputy General Director (Deputy Director) to directly undertake the duties of the Risk Management Unit as stipulated in Clause 3 of this Article.
3. The tasks and authorities of the Risk Management Unit shall be decided by the General Director (Director) of the credit organization, ensuring the implementation of the minimum functions and tasks as follows:
a) Assisting the Risk Committee of cooperative banks, the General Director of microfinance institutions, and the Director of people's credit funds in:
(i) Developing, implementing, and evaluating risk management policies in accordance with Clause 3 of Article 20 of this Circular to propose adjustments to the Board of Directors and the Board of Members;
(ii) Developing, implementing, and allocating risk limits;
(iii) Conducting self-assessment and evaluation of risk management and proposing measures for handling and mitigating risks to the Board of Directors and the Board of Members;
b) Assisting the Risk Committee of cooperative banks, the General Director of microfinance institutions, and the Director of people's credit funds in monitoring risk status against risk limits to issue early warnings and identify risks and potential breaches of risk limits;
c) Coordinating with the first line of defense to fully identify and monitor emerging risks;
d) Establishing and using methods for assessing and measuring risks;
đ) Controlling, preventing, and proposing measures to mitigate emerging risks;
e) Participating in risk-related content during the process of making decisions involving corresponding risk levels according to the internal authority levels of the credit organization;
g) Developing methodologies and scenarios for stress testing liquidity based on coordination with business units, compliance units, and other relevant units;
h) Implementing internal reports on risk management in accordance with the internal regulations of the credit organization;
i) Directly reporting to the Board of Directors and the Board of Members on issues related to risk management when necessary, in accordance with the internal regulations of the credit organization;
k) Performing other contents as prescribed by the credit organization.
Section 2
CREDIT RISK MANAGEMENT
Article 27. Requirements, Risk Management Strategy for Credit Risks
1. Credit risk management is carried out throughout the entire process of considering, appraising, deciding, and managing credit disbursement to ensure compliance with the regulations of the State Bank and relevant laws.
2. Credit organizations must issue a credit risk management strategy, which must minimally include:
a) Objectives regarding credit quality (at least including target non-performing loan ratio, target bad credit disbursement ratio) by product; customer; profit, growth in credit disbursement activities;
The credit risk management strategy of cooperative banks must also include objectives regarding credit quality by economic sector;
b) An approach that is continuous and cumulative, wherein the credit risk management strategy must take into account cyclical economic factors and their expected impact on the credit portfolio;
c) Principles for determining risk compensation costs in interest rate calculation and pricing of credit products based on the level of credit risk of customers;
d) Principles for applying measures to reduce credit risks (including approval authority for risk reduction measures);
đ) Principles for conducting stress tests on liquidity risk;
3. Credit organizations must establish credit risk limits, at a minimum in accordance with Clause 2 of Article 28 of this Circular.
Article 28. Credit Risk Limits
1. Credit institutions must establish credit risk limits to ensure compliance with regulations on restrictions to ensure safety in their operations as stipulated in the Law on Credit Institutions and the State Bank's regulations.
2. The minimum credit risk limit shall include the following limits:
a) Credit limit for customers based on their debt repayment capacity.
The credit risk limit of cooperative banks must also include a credit limit for economic sectors based on the credit risk of those sectors;
b) Credit limit by product.
3. Credit risk limits must be reviewed and evaluated (adjusted if necessary) at least once a year according to internal regulations of the credit institution.
Article 29. Measurement, Monitoring, and Control of Credit Risk
1. Credit institutions must have methods to measure credit risk.
2. Credit institutions must monitor and control credit risk, ensuring at least the following requirements:
a) Implement asset classification, provision for credit risk, use provisions for credit risk to address credit risk, monitor the results of asset classification, and assess the adequacy of credit risk provisions as prescribed by law;
b) Monitor and evaluate credit risk for each loan and the entire portfolio of loans, and take measures to address when credit quality deteriorates;
c) Control actual credit risk status according to allocated credit risk limits for each loan, loan portfolios, ensuring compliance with loan limits and credit risk limits as prescribed by law;
d) Conduct remote monitoring and on-site inspections of customers to monitor and control credit risk. For small-value loans, credit institutions implement inspection and supervision measures as prescribed by the State Bank regarding inspection and supervision of small-value loans. The frequency of inspection and supervision is determined by internal regulations of the credit institution;
đ) Establish and implement criteria for evaluating, methods for determining the degree of credit quality deterioration for each loan and loan portfolios, and early warning mechanisms when there is a risk of customer credit quality deterioration.
Article 30. Loan Approval Review
1. Credit institutions must conduct loan approval reviews, which must minimally include the following contents:
a) Review the ability to meet conditions for customers to obtain loans;
b) Identify related parties of the customer who are required to provide related party information under the law on lending; total outstanding loan balance (including the loan balance being requested) of the customer, the customer and related parties of the customer who are required to provide related party information under the law on lending;
c) Utilization of customer rating results, including ratings from other credit institutions, foreign bank branches (if applicable);
d) Evaluate the completeness of the application file, the legal status of collateral, and the recoverability of collateral for cases involving collateralized loans according to internal regulations of the credit institution;
đ) Review the ability to fulfill commitment obligations of guarantors for guaranteed loans.
2. During the review process, if external information channels outside the credit institution are used, the credit institution must verify the quality of the information and the independence of the information channel from the customer.
Article 31. Decisions with Credit Risk
Decisions involving credit risk must be made by credit institutions and must ensure the following:
1. The authority to make decisions and cases where decisions are referred to higher authorities for approval must be determined based on quantitative and qualitative criteria.
2. In cases where decisions are made through a board mechanism, the board must have a record of the decision or equivalent form, clearly stating the reasons for making or not making the decision, and fully recording the opinions of all board members. Board members must bear responsibility for their decisions.
3. Information provided for decision-making must be complete and appropriate to the scale, type of credit, and internal regulations of the credit institution. Regulations regarding the list of information serving as the basis for decision-making must be evaluated by the Risk Management Department to ensure effective management of credit risk.
Article 32. Management of Credit Provisioning
1. Credit institutions must implement credit provisioning management meeting the following requirements:
a) Clearly define the responsibilities and authorities of individuals and departments in establishing and storing credit files to ensure that credit files are complete as required by law;
b) Disburse funds in accordance with the purpose of capital usage and the type of credit provision;
c) Monitor and supervise credit provisions after disbursement must comply with the following principles:
(i) Inspect and monitor the use of borrowed capital according to legal regulations and fulfill other terms stipulated in the customer's credit provision contract;
(ii) Evaluate factors affecting the customer's ability to repay debts;
(iii) Manage collateral assets in cases of credit provision with collateral as specified in Article 34 of this Circular;
(iv) Track repayment schedules, remind customers to fulfill their repayment obligations when due, and promptly report to competent authorities when there is a risk of non-payment or delayed payment by the customer.
2. Credit institutions must store credit files, information about the customer's ability to fulfill repayment obligations, repayment history, and other related information as required by law.
Article 33. Management of Problem Credit Provisions
1. Credit institutions must implement management of problem credit provisions to take timely measures.
2. Management of problem credit provisions must minimally include:
a) Internal regulations clearly defining criteria and methods for identifying problem credit provisions;
b) Strengthen assessment of the customer's ability to repay debts and debt recovery from security measures;
c) Measures to handle and restructure problem credit provisions, and plans for debt recovery;
d) Strengthen monitoring, supervision, and debt recovery;
đ) Determine responsibility to take measures against individuals and departments related to bad debts (if any).
Article 34. Management of Collateral Assets
1. Credit institutions must have minimum internal regulations including:
a) Specifically identify types of collateral assets accepted by the credit institution in compliance with legal regulations;
b) Methods for determining the value of collateral assets according to legal valuation regulations or hiring organizations with appraisal functions to determine the value of collateral assets as the basis for managing collateral assets; determine collateral assets meeting conditions for deduction and deduction ratio when setting aside reserves as required by law;
c) Periodically or unexpectedly assess the degree of fluctuation in the value of collateral assets, with more frequent assessments required for collateral assets experiencing greater value fluctuations;
d) Procedures for receiving and safely storing collateral assets.
2. Credit institutions must manage collateral assets in accordance with their internal regulations and relevant legal regulations.
Section 3
LIQUIDITY RISK MANAGEMENT
Article 35. Requirements, Risk Management Strategy, Liquidity Risk Limits
1. The management of liquidity risk by credit institutions must meet at least the following requirements:
a) Maintaining sufficient high-quality liquid assets as prescribed by the State Bank to meet liquidity needs under normal operating conditions and adverse liquidity developments (including determining losses and costs when accessing liquidity on the market);
b) Determining the cost of meeting liquidity needs and liquidity risk in assessing business results for key business activities.
Credit cooperatives and microfinance organizations must also determine the cost of meeting liquidity needs and liquidity risk in valuing internal capital.
2. The minimum liquidity risk management strategy shall include the following contents:
a) Principles for managing liquidity, at least as provided for in Article 36 of this Circular;
b) A diversification strategy for funding sources and funding maturities to increase stability in liabilities and support daily liquidity;
c) Principles for implementing stress testing on liquidity (applicable to credit cooperatives).
3. Credit institutions must establish liquidity risk limits including:
a) Risk limits ensuring compliance with relevant legal provisions on:
(i) Liquidity coverage ratio;
(ii) Loan-to-deposit ratio, maximum proportion of short-term funds used for medium- and long-term loans (for credit institutions applying such ratios);
(iii) Other ratios as prescribed by law (for credit institutions applying such ratios);
b) Other limits as prescribed internally by the credit institution in accordance with Article 21 of this Circular.
Article 36. Liquidity Management
1. Credit institutions implement liquidity management according to:
a) Credit institutions, branches, and other dependent units of credit institutions;
b) Transaction currencies.
2. Credit institutions implement minimum liquidity management including the following contents:
a) Daily liquidity management: Monitoring liquidity status; identifying sources of funds and the ability to mobilize these sources to ensure liquidity; forecasting situations that abnormally change liquidity and taking measures to address them.
Credit cooperatives must additionally manage high-quality liquid assets based on market value and their convertibility into cash to meet liquidity requirements under normal market conditions and liquidity-constrained markets;
b) Funding source management to ensure statistics on deposits and other indicators comply with the State Bank's regulations on limits, safety ratios, and internal credit institution ratios;
c) Cash flow management to determine cash flow differences through comparing cash inflows and outflows, ensuring compliance with the State Bank's regulations on limits, safety ratios, and other liquidity ratios as prescribed internally by the credit institution;
d) Liquidity source management to ensure assessment of the ability to access liquidity sources to meet future liquidity needs under normal market conditions and liquidity-constrained markets.
Article 37. Identification, Measurement, Monitoring, and Control of Liquidity Risk
1. The identification of liquidity risk by credit organizations must ensure:
a) Conducted on the basis of analyzing liquidity needs, liquidity sources of each business activity, asset/debt structure and cash flow of on-balance sheet and off-balance sheet items, and market liquidity access;
b) Identifying liquidity risks arising from credit risks, operational risks, and other risks.
2. Credit organizations must have a minimum method for measuring liquidity risk that ensures the following requirements:
(i) Future cash flows of assets/debts;
(ii) Unusual liquidity needs and situations requiring fulfillment of off-balance sheet obligations (if any);
(iii) Transaction currency;
(iv) Banking agency, custody, and payment activities (if any).
3. Credit organizations must monitor and control liquidity risk at a minimum to ensure:
a) Monitoring and controlling the state of liquidity risk to comply with liquidity risk limits;
b) Having early warning indicators of liquidity risk to take measures to address temporary and long-term liquidity shortages.
Article 38. Liquidity Stress Testing
1. Cooperative banks shall conduct liquidity stress testing as prescribed in this Article at least once every six months and at random times.
2. Cooperative banks must have methods for calculating the impact of assumptions to assess their ability to fulfill obligations, commitments, and comply with liquidity risk limits. Assumptions and methods for calculating the impact of these assumptions on liquidity must be reviewed and self-assessed for appropriateness.
3. Cooperative banks shall conduct liquidity stress testing as follows:
a) Develop at least two adverse scenarios as follows:
(i) A specific stress scenario for cooperative banks: Liquidity crisis for cooperative banks while overall system liquidity remains stable (such as: Asset quality deteriorates, debt increases sharply, highly liquid assets significantly decrease, liquidity deficit increases, bank credit rating decreases, bank遭受攻击等);
(ii) A systemic stress scenario: Assuming a widespread liquidity crisis that could affect multiple credit institutions or the entire credit institution system (such as: There is a macroeconomic shock, financial market disruption...).
Selected scenarios must ensure the possibility of occurrence based on analysis of past events and macroeconomic forecasts. Selected scenarios must include at least assumptions about deposits and credit quality.
b) Calculate the impact of assumptions on liquidity in each scenario;
c) Prepare a report on the results of liquidity stress testing (including quantitative data and qualitative analyses and assessments).
4. Cooperative banks shall identify factors affecting liquidity risk in the event of the scenarios prescribed in Clause 3 of this Article.
5. Based on the results of stress testing, cooperative banks must:
a) Evaluate compliance with the liquidity coverage ratio, loan-to-deposit ratio, maximum proportion of short-term capital used for medium- and long-term lending, and other restrictions to ensure safety in operations according to internal regulations of cooperative banks;
b) Develop contingency plans in case of non-compliance with liquidity requirements. Contingency plans must include the following contents: anticipated measures for capital sources, capital usage, future cash flows to meet the requirements stipulated in Clause 2 of this Article.
6. Microfinance organizations and people's credit funds are not required to conduct liquidity stress testing.
Section 4
OPERATIONAL RISK MANAGEMENT
Article 39. Requirements and Strategy for Operational Risk Management
1. Credit institutions must issue an operational risk management strategy, at a minimum including:
a) Principles for implementing operational risk management;
b) Principles for using outsourcing activities, purchasing insurance, applying technology, including identifying, assessing, and monitoring risks arising from third parties;
c) Situations where a continuity plan must be maintained, at a minimum including:
(i) Loss of important documents, databases;
(ii) Information technology system failures;
(iii) Unforeseeable events (war, natural disasters, epidemics, fires, explosions...).
2. The classification of activities shall be carried out as follows:
a) Microfinance organizations and people's credit funds must classify activities into the following groups:
(i) Income-generating activities and similar income sources;
(ii) Activities generating interest expenses and similar expenses;
(iii) Service activities;
(iv) Other activities.
b) Cooperative banks must classify activities into the groups specified in point a, Clause 2 of this Article and the group of securities trading and investment activities.
Article 40. Identification, Monitoring, and Control of Operational Risks
1. Credit institutions must fully identify operational risks in business operations, business processes, information technology systems, and risks from third parties.
2. The identification of operational risks shall be carried out in the following cases:
a) Internal fraud due to fraudulent acts, property theft, violations of strategies, policies, and internal regulations related to at least one individual of the credit institution (including actions taken for personal gain such as performing duties incorrectly, exceeding authority, stealing, exploiting internal information);
b) External fraud due to fraudulent acts, property theft caused by external entities without the assistance or collusion of individuals or departments within the credit institution (including theft, robbery, counterfeit card and document fraud, unauthorized access to information systems to steal data and money);
c) Labor policies and workplace safety that are not consistent with labor contracts, laws on labor, health protection, and workplace safety;
d) Products, services, and methods of providing products and services that are inconsistent with regulations, customer rights (including violations of customer information confidentiality, anti-money laundering regulations, and providing products and services beyond authorized limits);
đ) Damage, loss of assets, tools, equipment due to unforeseeable events, human actions, and other incidents;
e) Business interruption due to information technology system failures;
g) Limitations and inadequacies in transaction procedures, transaction controls, and transaction management;
h) Other cases as stipulated in internal regulations of credit institutions.
3. Credit institutions shall monitor and control operational risks through internal control activities as prescribed in this Circular and other measures as stipulated in internal regulations.
Article 41. Management of Operational Risks in Outsourcing Activities
1. Management of operational risks in outsourcing activities shall be carried out through:
a) Managing outsourcing activities as prescribed in Clause 2 of this Article;
b) Identifying, measuring, monitoring, and controlling operational risks arising from outsourcing activities as prescribed in Article 40 of this Circular.
2. Management of outsourcing activities shall include, at a minimum:
a) Determining the scope of outsourcing activities and the level of dependence on third parties;
b) Delegating approval and decision-making authority for outsourcing activities;
c) Assessing the capability of third parties to meet the requirements and objectives of outsourcing activities before signing outsourcing contracts; evaluating the performance of the outsourcing company during contract execution;
d) Ensuring that outsourcing contracts are thorough, complete, protect ownership rights, database security, customer information confidentiality, and the right to terminate outsourcing contracts by credit institutions. Outsourcing contracts must include: the extent and scope of outsourcing activities; specific rights and obligations of credit institutions and outsourcing companies and third parties; dispute resolution clauses in accordance with the law;
đ) For outsourcing activities involving information technology services, ensuring the security and confidentiality of banking information technology systems and compliance with legal regulations on the management and use of third-party information technology services;
e) Establishing or requiring third parties to establish continuity plans for outsourcing activities as prescribed in Article 44 of this Circular;
g) Setting up mechanisms to supervise third parties during the outsourcing period.
3. Credit institutions must ensure that the management of third-party risks arising from outsourcing activities includes, at a minimum:
a) Credit institutions must monitor outsourcing contracts, at a minimum including the following contents: the significance of agreements, the ability to replace third-party services (substitutability), lists of contingent providers, whether or not there is sharing of confidential or exclusive information, service locations;
b) Credit institutions must conduct a comprehensive assessment of potential risks arising from outsourcing activities before signing contracts;
c) Credit institutions must monitor risks arising from outsourcing activities, regularly reporting to authorized bodies according to internal regulations of credit institutions;
d) Credit institutions must develop and regularly review and update continuity plans including recovery measures to ensure uninterrupted operation when outsourcing activities encounter issues.
4. Credit institutions must ensure that outsourcing activities do not change their responsibility in fulfilling obligations towards related parties.
Article 42. Management of operational risks in technology application
1. Credit organizations with total assets reaching VND 300 billion or more at the end of the financial year shall manage operational risks arising from technology application in internal operations and electronic transactions with customers (hereinafter referred to as technology application) through:
a) Managing technology application in accordance with Clause 2 of this Article;
b) Identifying, monitoring, and controlling operational risks arising from technology application to ensure at least the following:
(i) Identifying potential risks related to internal and external network systems, hardware, software, applications, transaction interfaces, operations, and human factors;
(ii) Monitoring and assessing the ability to maintain stable operations in the face of potential operational risks arising from technology application;
(iii) Controlling and implementing measures to mitigate operational risks (if necessary) in technology application activities.
2. The management of technology application by credit organizations with total assets reaching VND 300 billion or more at the end of the financial year must ensure:
a) Having minimum regulations on managing technology application including:
(i) The scope of minimum management for information technology systems;
(ii) Tasks, responsibilities, and authorities of individuals and units responsible for managing technology application;
(iii) Effective management during incidents and changes in technology application;
(iv) A verification system ensuring customer information security, transaction safety, and information systems;
b) Complying with the State Bank's regulations on electronic transactions in the banking industry; ensuring the safety and security of information technology systems for online banking services and relevant legal provisions.
3. Credit organizations with total assets below VND 300 billion at the end of the financial year shall manage operational risks arising from technology application in accordance with the State Bank's regulations and relevant legal provisions on information technology and technology application in operations.
Article 43. Purchasing Insurance to Minimize Losses from Operational Risks
1. Credit organizations may purchase insurance to minimize losses arising from operational risks in accordance with the law, ensuring compatibility with their financial capacity and compensating for losses of the credit organization.
2. Credit organizations shall not use the purchase of insurance to replace operational risk management.
3. When purchasing insurance, credit organizations must evaluate the effectiveness of minimizing losses arising from operational risks through the purchase of insurance.
4. Credit organizations must assess the capability of insurance companies to minimize losses from operational risks.
Article 44. Continuous Business Operations Plan
1. Credit organizations must develop, approve, maintain, and periodically update the continuous business operations plan in cases specified in point c, Clause 1 of Article 39 of this Circular to ensure the ability to respond, recover, and continue to operate and provide banking services in severe disruption situations, consistent with the organization's risk appetite, financial capacity, and business orientation.
2. The continuous business operations plan must meet at least the following requirements:
a) Clearly defining the authority to activate the continuous business operations plan and the roles and responsibilities of individuals and units involved in implementing the plan;
b) Being appropriate to the nature and scale of the credit organization's operations;
c) Identifying important activities, products, services, and critical business processes that need priority maintenance;
d) Having backup systems for personnel, alternative work locations, information systems, and essential infrastructure;
đ) Ensuring timely and effective coordination and information exchange within the organization and with regulatory bodies, customers, and key partners in disruption situations;
e) Implementing measures to minimize losses and adverse impacts from incidents or shutdowns;
g) Ensuring the restoration of disrupted business operations to normal status within the required timeframe;
h) Being reviewed and tested or exercised annually or when there are significant changes in the operating environment, technology, or organizational structure to evaluate the effectiveness of the continuous business operations plan and make adjustments (if necessary).
Section 5
CONCENTRATED RISK MANAGEMENT
Article 45. Concentrated Risk Management Strategy, Concentrated Risk Limits
1. The concentrated risk management strategy shall apply at minimum to:
a) Credit activities;
b) Proprietary trading activities.
2. The minimum concentrated risk management strategy shall include the following contents:
a) For credit activities:
(i) Principles for determining credit concentration limits by credit product; customer.
The concentrated risk management strategy of cooperative banks must also include principles for determining credit concentration limits by economic sector;
(ii) Criteria for identifying related parties of customers in accordance with the provisions of the law;
(iii) Principles for determining the level of diversification and interaction between credit products.
The concentrated risk management strategy of cooperative banks must also include principles for determining the level of diversification and interaction between economic sectors;
b) For proprietary trading activities:
(i) Principles for determining proprietary trading concentration limits by trading partner; trading product;
(ii) Criteria for identifying the proprietary trading portfolio to apply proprietary trading concentration limits ensuring the level of diversification and interaction as prescribed by cooperative banks.
3. Minimum concentrated risk limits include:
a) For credit activities:
(i) Credit limit for one customer, customer and related party compared to total outstanding balance;
(ii) Credit concentration limit for credit products based on the proportion of outstanding balance of credit products to total outstanding balance.
The concentrated risk limit of cooperative banks must also include credit concentration limit for economic sectors based on the proportion of outstanding balance of economic sectors to total outstanding balance;
b) For proprietary trading activities: proprietary trading concentration limit for trading partners, trading products based on the proportion of balances of trading partners, trading products to total proprietary trading balances.
Article 46. Identification, Measurement, Control of Concentrated Risks
1. Credit organizations must identify concentrated risks at minimum in credit activities, proprietary trading activities, including:
a) Items recorded as on-balance sheet items, off-balance sheet items of credit organizations;
b) Items not recorded in accordance with accounting laws.
2. Credit organizations measure concentrated risks based on assessing the impact on income of each credit activity, proprietary trading activity with concentrated risks.
3. Credit organizations control concentrated risks as follows:
a) Monitor, check credit outstanding balances, proprietary trading balances according to concentrated risk limits; issue early warnings for balances, transactions approaching concentrated risk limits;
b) Take timely measures for cases exceeding concentrated risk limits.
Chapter IV
INTERNAL AUDIT
Article 47. Internal Audit Principles
1. Independence Principle:
a) Internal auditors, internal audit departments shall not concurrently undertake tasks, responsibilities of individuals, departments belonging to the first line of defense and the second line of defense;
b) Internal audit shall not be subject to any influence, intervention from individuals, departments belonging to the first line of defense and the second line of defense;
c) Internal auditors shall not conduct internal audits on:
(i) Internal regulations on internal audit, internal audit plans established by that internal auditor;
(ii) Units, departments where the head of the unit, department is a related party of that internal auditor;
(iii) Activities, departments where that internal auditor has performed, been responsible for within three years for cooperative banks and one year for people's credit funds and microfinance organizations since ceasing to perform, be responsible for those activities, departments;
d) Criteria for establishing salaries, other benefits for positions in the internal audit department must be separate from business results, operational results of other units, departments.
2. Objectivity Principle:
a) Audit records in internal audit reports must be carefully analyzed and based on collected data, information;
b) Internal auditors must be honest when reporting, evaluating during the internal audit process;
c) Internal auditors have the right and obligation to report to competent authorities about issues related to objectivity during the internal audit process.
3. Professionalism Principle:
a) Cooperative banks must have at least one internal auditor or hire one to perform internal audit of information technology infrastructure, applications (hereinafter referred to as IT auditor);
b) Internal auditors must meet the standards prescribed in Article 49 of this Circular.
4. Internal audit must take measures to verify the implementation of the principles stipulated in Clauses 1, 2 and Clause 3 of this Article during the internal audit process (including the process of preparing and submitting internal audit reports). The Head of Internal Audit promptly reports to the Supervisory Board upon discovering violations, risks of violating the principles stipulated in Clause 1, 2 and Clause 3 of this Article.
Article 48. Coordination Mechanism
1. Credit organizations must have a coordination mechanism between:
a) The Board of Directors, Board of Members and the Supervisory Board, internal audit department as provided for in Clause 2 of this Article;
b) General Director (Director), departments and the Supervisory Board, internal audit department as provided for in Clause 3 of this Article.
2. The coordination mechanism of the Board of Directors, Board of Members and the Supervisory Board, internal audit department of credit organizations must ensure:
a) The Board of Directors, Board of Members coordinate with the internal audit department when conducting internal audits on the supervision of senior management over the Board of Directors, Board of Members; direct relevant departments and individuals to provide complete information on risks for the internal audit department to prepare the internal audit plan;
b) The Board of Directors, Board of Members implement recommendations of the Supervisory Board regarding the Board of Directors, Board of Members in the internal audit report (if any) and inform the Supervisory Board about the results of implementing the recommendations.
3. The coordination mechanism of the General Director (Director), departments under the first and second lines of defense and the Supervisory Board, internal audit department of credit organizations must ensure:
a) The General Director (Director) performs:
(i) Coordinate with the internal audit department when conducting internal audits on the supervision of senior management over the General Director (Director);
(ii) Direct the Risk Management Department or Deputy General Director (Deputy Director) assigned to perform the tasks of the Risk Management Department and related departments to provide complete information on risks for the internal audit department to prepare the internal audit plan;
(iii) The General Director (Director) receives internal reports on internal audits, organizes the implementation of recommendations of the Supervisory Board regarding the General Director (Director) in the internal audit report (if any) and reports to the Supervisory Board the results of implementing the recommendations;
b) Departments under the first and second lines of defense perform:
(i) Provide full, truthful, and accurate information and documents upon request of the internal audit department during internal audits;
(ii) Promptly notify the internal audit department when discovering limitations, violations, losses, or loss risks;
(iii) Facilitate the internal audit department in conducting internal audits.
Article 49. Standards for Internal Auditors
1. Cooperative banks must establish standards for internal auditors meeting the following requirements:
a) Internal auditors must hold a bachelor's degree or higher in economics, finance, accounting, auditing, banking, and have at least two years of direct work experience in fields related to finance, accounting, auditing, and banking;
b) Internal auditors of technology as stipulated in point a, Clause 3, Article 47 of this Circular must meet the following requirements:
(i) Hold a bachelor's degree or higher in information technology or a relevant major;
(ii) Have at least two years of work experience in the field of information technology;
c) The Head of Internal Audit must hold a bachelor's degree or higher in economics, finance, accounting, auditing, banking, and have at least three years of direct work experience in fields related to banking, finance, accounting, and auditing.
2. People's Credit Funds must establish standards for internal auditors, Heads of Internal Audit meeting conditions and standards as for members of the Supervisory Board, Heads of the Supervisory Board corresponding to the scale of total assets of the People's Credit Fund as prescribed in the Circular of the State Bank of Vietnam on People's Credit Funds.
3. Microfinance organizations must establish standards for internal auditors meeting the following requirements:
a) Internal auditors must hold a bachelor's degree or higher in economics, finance, accounting, auditing, banking, business administration, law, and have at least one year of direct work experience in fields related to finance, accounting, auditing, banking, and microfinance;
b) The Head of Internal Audit must hold a bachelor's degree or higher in economics, finance, accounting, auditing, banking, business administration, law, and have at least three years of work experience in fields related to finance, accounting, auditing, banking, and microfinance.
Article 50. Professional ethics standards for members of the Supervisory Board, internal auditors
The professional ethics standards for members of the Supervisory Board, internal auditors (including the Head of Internal Audit and other positions within the internal audit department) must at least include the following rules:
1. Integrity: performing assigned tasks honestly and truthfully.
2. Objectivity: performing assigned tasks objectively; evaluating fairly without personal interest or the interest of others.
3. Confidentiality: complying with legal and internal regulations of credit organizations regarding information security.
4. Responsibility: ensuring the progress and quality of assigned work.
5. Prudence: performing assigned tasks prudently based on the assessment of the following factors:
a) The complexity and importance of the content being internally audited;
b) The possibility of serious errors occurring during the internal audit process.
Article 51. Internal regulations on internal auditing
The internal regulations of the Supervisory Board must include provisions on internal auditing at a minimum comprising:
1. The organizational structure, duties, and authority of the internal audit department as stipulated in Article 54 of this Circular; the standards for internal auditors as stipulated in Article 49 of this Circular; the professional ethics standards for members of the Supervisory Board and internal auditors as stipulated in Article 50 of this Circular.
2. Criteria for determining the level of risk, materiality, and frequency of internal audits of activities, processes, departments; the content of internal audits as stipulated in Clause 2, Article 52 of this Circular.
3. Procedures for drafting and implementing the internal audit plan.
4. Reviewing and assessing internal audit regulations, handling recommendations on internal audits from the State Bank, independent auditing organizations, and other competent authorities.
5. Regulations on hiring experts and external organizations to conduct internal audits (if applicable).
6. Internal reporting systems on internal audits as prescribed in this Circular.
Article 52. Internal audit plans
1. Internal audits are conducted annually and ad hoc according to the internal regulations of the Supervisory Board. Credit Unions also develop quarterly internal audit plans for lending activities.
2. Annual internal audit plans are issued by the Supervisory Board upon the proposal of the Head of Internal Audit after consulting the views of the Board of Directors, Board of Members, and General Director (Director). The preparation of internal audit plans must ensure compliance with:
a) Risk-oriented principles: Activities, processes, and departments must be assessed for risk levels (high, medium, and low) according to the internal regulations of the Supervisory Board. Activities, processes, and departments with high risk levels are prioritized for internal audits and must be audited at least once a year;
b) Comprehensive coverage: All activities, processes, and departments must undergo internal audits. Activities, processes, and departments deemed significant according to the internal regulations of the Supervisory Board must be audited at least once a year;
c) Adequate resources and time for conducting ad hoc internal audits;
d) Annual periodic audit plans must be adjusted when there are significant changes in the scale of operations or internal audit resources according to the internal regulations of the Supervisory Board.
3. Annual internal audit plans must be issued before December 15 of the previous year and must at least include the following contents: scope of audit, audit subjects, audit objectives, audit period, audit resources (including hiring experts and external organizations), and other contents specified by the credit organization.
4. Within ten working days from the date of issuance or amendment, credit organizations submit their internal audit plans to the State Bank:
a) Cooperative banks and microfinance organizations submit their internal audit plans to the Credit Institution Management and Supervision Department;
b) Credit Unions submit their internal audit plans to the State Bank branch in the region where their headquarters is located.
Article 53. Contents of Internal Audit
The internal audit of credit organizations shall be conducted in accordance with the Law on Credit Organizations based on the following contents:
1. Independently checking and evaluating compliance with mechanisms, policies, and internal regulations on supervision by senior management, internal control, risk management activities of the Board of Directors, Board of Members, General Director (Director), individuals, departments, including identifying existing issues, limitations, and causes.
2. Independently reviewing and evaluating the appropriateness and compliance with legal provisions of mechanisms, policies, and internal regulations on supervision by senior management, internal control, and risk management, including identifying existing issues, limitations, and causes.
3. Proposing recommendations to competent authorities and relevant departments to address existing issues and limitations.
4. Other contents as stipulated internally by the Supervisory Board regarding internal audit.
Article 54. Organizational Structure and Authority of the Internal Audit Department
1. Organizational structure of the internal audit department:
a) The Supervisory Board decides the number of internal auditors in the internal audit department appropriate to the scale, nature, and complexity of internal audit activities and must ensure compliance with the provisions of Clause 47 and Clause 49 of this Circular;
b) Members of the Supervisory Board may concurrently serve as internal auditors directly performing internal audit tasks;
c) In cases where the internal audit department has only one internal auditor, that internal auditor shall be the Head of Internal Audit. The Chairman of the Supervisory Board shall not concurrently serve as the Head of Internal Audit.
2. Authority of the internal audit department of credit organizations includes:
a) Being equipped with necessary resources (human resources, finance, assets, and other tools);
b) Being provided with necessary information, documents, and files for internal audit work, including internal documents related to the operation of the Board of Directors, Board of Members, General Director (Director), minutes of meetings of the Board of Directors, Board of Members, General Director (Director);
c) Interviewing individuals regarding matters related to internal audit; recommending competent authorities to handle non-cooperative behavior of individuals, departments during the implementation of internal audit according to internal regulations;
d) Participating in internal meetings in accordance with the Charter and internal regulations of credit organizations;
đ) Other authority as stipulated internally by the Supervisory Board.
Article 55. Responsibilities of the Supervisory Board, Internal Audit Department, and Internal Auditors
1. The Supervisory Board of credit organizations performs functions and tasks related to internal audit as prescribed in this Circular and internal regulations of the Supervisory Board, at least including:
a) Monitoring and evaluating the implementation of professional ethics standards by members of the Supervisory Board, internal auditors;
b) Monitoring and evaluating the internal audit department, Head of Internal Audit in the performance of their functions and tasks. The Supervisory Board may hire external organizations with expertise to evaluate the quality of the internal audit department's operations.
2. The internal audit department of credit organizations has the following minimum responsibilities:
a) Conducting annual or ad hoc internal audits of the main office, branches, and dependent units of credit organizations. People's Credit Funds conduct quarterly internal audits of lending activities. Preparing reports on the results of internal audits for approval by the Supervisory Board and submission to the Board of Directors, Board of Members, General Director (Director);
b) Reviewing and self-assessing the effectiveness of internal audits;
c) Drafting and reviewing to submit to the Supervisory Board for issuance, amendment, and supplementation:
(i) Professional ethics standards for members of the Supervisory Board, internal auditors as prescribed in Article 50 of this Circular;
(ii) Internal regulations of the Supervisory Board;
(iii) Internal audit plans;
d) Monitoring and evaluating the implementation of recommendations by the Supervisory Board to the Board of Directors, Board of Members, General Director (Director), individuals, departments;
đ) Implementing recommendations from the State Bank's internal audit, independent auditing organizations, and other competent authorities regarding internal audit;
e) Preparing internal audit result reports as prescribed in Article 9 of this Circular;
g) Safeguarding documents and information in accordance with laws and internal regulations of credit organizations;
h) Being accountable to the Supervisory Board for the assigned tasks.
3. Minimum responsibilities of internal auditors include:
a) Implementing regulations related to internal auditors as prescribed in this Circular;
b) Internal auditors are responsible under the law and to the Head of Internal Audit for the assigned internal audit tasks.
Chapter V
IMPLEMENTING PROVISIONS
Article 56. Implementation Provisions
1. This Circular takes effect from January 1, 2027.
2. This Circular abolishes Circular No. 44/2011/TT-NHNN dated December 29, 2011 of the Governor of the State Bank of Vietnam on internal control systems and internal audit of credit organizations and foreign bank branches.
Article 57. Responsibility for Implementation
The heads of units under the State Bank of Vietnam, cooperative banks, people's credit funds, microfinance organizations, and related organizations and individuals are responsible for implementing this Circular./.
|
GOVERNOR DEPUTY DIRECTOR (Signed) Doan Thai Son |
원본 문서(PDF)
다운로드
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.