This Circular stipulates risk management and internal control in insurance companies, reinsurance companies, and foreign branches. It includes the allocation of responsibilities among the Board of Directors/Board of Members, General Director/Manager, and relevant departments; provisions on the organization of risk management and internal control; as well as risk management reporting. This Circular takes effect from January 1, 2023.
适用范围
This applies to insurance companies, reinsurance companies, and foreign branches operating in Vietnam.
要点
- Provisions on the organizational structure for risk management
- Allocation of responsibilities between the Board of Directors/Board of Members and the General Director/Manager
- Provisions on internal control and risk management reporting
- Effective date from January 1, 2023.
- Requirements for enterprises to comply with risk management and internal control regulations to ensure stable and effective operations.
🌐 本文件的社会影响
- Enhance transparency in enterprise operations
- Minimize financial risks for enterprises and insurance participants
- Ensure customer rights are respected
❓ 常见问题
When does this Circular take effect?
This Circular takes effect from January 1, 2023.
Who is primarily responsible for risk management and internal control?
The Board of Directors/Board of Members is responsible for approving policies and plans; the General Director/Manager implements the organization of these regulations.
Does this Circular apply to foreign branches?
Yes, this Circular also stipulates risk management and internal control for foreign branches.
全文
MINISTRY OF FINANCE
SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness
-----------------------------
Number: 70/2022/TT-BTC
Hanoi, November 16, 2022
CIRCULAR
Regulations on risk management, internal control, and internal audit
of insurance companies, reinsurance companies,
branches of non-life insurance companies from foreign countries,
branches of reinsurance companies from foreign countries
Pursuant to the Insurance Business Law dated June 16, 2022,
Pursuant to the Law on Enterprises dated June 17, 2020;
Pursuant to Decree No. 87/2017/NĐ-CP dated July 26, 2017, issued by the Government, stipulating the functions, tasks, powers, and organizational structure of the Ministry of Finance;
The Minister of Finance issues this Circular stipulating risk management, internal control, and internal audit for insurance companies, reinsurance companies, branches of non-life insurance companies from foreign countries, and branches of reinsurance companies from foreign countries.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Circular stipulates Article 84, Article 85, and Clause 1, Clause 2 of Article 86 of the Insurance Business Law.
Article 2. Applicability
1. Life insurance companies, non-life insurance companies, health insurance companies (hereinafter referred to as insurance companies), reinsurance companies.
2. Branches of non-life insurance companies from foreign countries, branches of reinsurance companies from foreign countries (hereinafter referred to as foreign branches).
3. Organizations and individuals related to risk management, internal control, and internal audit of insurance companies, reinsurance companies, and foreign branches.
Article 3. Explanation of Terms
In this Circular, the following terms are understood as follows:
1. Parent company of foreign branches is a non-life insurance company from a foreign country, a reinsurance company from a foreign country having branches in Vietnam.
2. Risk is the possibility of loss (financial loss, non-financial loss) that reduces income, equity capital leading to a decrease in the capital adequacy ratio or limits the ability to achieve business objectives of insurance companies, reinsurance companies, and foreign branches.
3. Risk appetite is the capacity of insurance companies, reinsurance companies, and foreign branches to accept various types of risks and levels of each type of risk consistent with their business strategy and financial capability.
4. Risk limit is the boundary of each type of risk that individuals or departments within insurance companies, reinsurance companies, and foreign branches can undertake at any point in time and in each business process.
5. Significant risk includes groups of insurance risk, market risk, operational risk, counterparty risk, and other risks assessed by insurance companies, reinsurance companies, and foreign branches as having a significant impact on financial safety and operational efficiency of these entities.
6. Insurance risk consists of risks arising from fluctuations in technical factors related to insurance premium setting and reserve provisioning for insurance operations, including:
a) Risks related to premium setting: Inappropriate assumptions in premium setting lead to calculated premiums insufficient to cover promised insurance benefits during the contract period and to offset operating costs of insurance companies, reinsurance companies, and foreign branches. Premium assumptions include: Mortality rate, longevity rate, claim ratio, expense ratio, investment interest rate, policy lapse rate, and other assumptions used in the premium calculation model;
b) Risks related to reserve provisioning for non-life insurance claims: Insufficient reserve provisioning to cover claim payments for the portion of liability of non-life insurance companies, foreign branches of non-life insurance companies;
c) Risks related to disasters: Risks when actual claim ratios are high, exceeding premium assumptions due to disease outbreaks or disasters.
7. Market risk consists of risks arising from the investment market affecting the investment and business activities of insurance companies, reinsurance companies, and foreign branches, including:
a) Risks related to unfavorable interest rate fluctuations in the market affecting the value of securities, interest-bearing financial instruments, derivatives, and investment assets of insurance companies, reinsurance companies, and foreign branches;
b) Risks related to unfavorable exchange rate fluctuations in the market affecting the activities of accepting and ceding reinsurance, and foreign investments;
c) Risks related to unfavorable stock price fluctuations in the market affecting the value of stocks and derivative securities of insurance companies, reinsurance companies, and foreign branches;
d) Mismatch risk between the term of investment assets and the contractual commitments of insurance companies, reinsurance companies, and foreign branches.
8. Operational risk consists of risks arising from the establishment and implementation of operational processes of insurance companies, reinsurance companies, and foreign branches, including:
a) Risks related to incomplete and non-compliant internal regulations and business procedures of insurance companies, reinsurance companies, and foreign branches;
b) Legal risks;
c) Risks related to inadequate and inappropriate underwriting activities increasing the proportion of high-risk insured individuals;
d) Risks related to unsuitable design of insurance benefits for the market;
e) Risks related to employee policies and workplace safety;
f) Risks related to the quality of outsourced activities not meeting requirements, outsourcing partners failing to fulfill their contractual obligations;
g) Risks related to information technology systems, personal data security, and cybersecurity;
h) Risks related to business cycles;
i) Fraud risks;
j) Other risks related to the operations of insurance companies, reinsurance companies, and foreign branches.
9. Counterparty risk is the risk associated with counterparties failing to fulfill payment commitments for investment and reinsurance activities of insurance companies, reinsurance companies, and foreign branches.
10. Liquidity risk is the risk that the insurance company, reinsurance company, or foreign branch does not have sufficient funds to meet its payment obligations for due liabilities of the insurance company, reinsurance company, or foreign branch.
11. Risk management is the process of identifying, measuring, monitoring, and controlling risks in the operations of the insurance company, reinsurance company, or foreign branch.
12. Risk management culture is the cultural value of the insurance company, reinsurance company, or foreign branch, reflecting a unified understanding of the importance of risk management activities by the Board of Directors, Board of Members, General Director (Director), and individuals and departments within the insurance company, reinsurance company, or foreign branch.
Chapter II
SPECIFIC PROVISIONS
Section 1
RISK MANAGEMENT
Article 4. Organization of risk management
1. The insurance company, reinsurance company, or foreign branch must organize risk management with three independent lines of defense as follows:
a) First line of defense: Business units, which are the units directly responsible for identifying, accepting, assessing, controlling, reporting, and monitoring risks arising from business operations.
b) Second line of defense: The risk management unit, compliance control unit, and other units with functions to control risks related to the first line of defense.
c) Third line of defense: Internal audit unit.
2. Depending on the scale, conditions, and complexity of business operations, the insurance company, reinsurance company, or foreign branch shall establish the organizational structure of the second line of defense to ensure the following tasks are fully carried out:
a) Advising the General Director (Director) to issue internal regulations on risk management.
b) Cooperating with business units in the first line of defense to identify and monitor significant risks arising.
c) Developing and using models to assess and measure risks to warn and detect early risks and breaches of risk limits, proposing measures to control, prevent, and mitigate emerging risks (if any).
d) Preparing scenarios to test the resilience of the insurance company, reinsurance company, or foreign branch against risks.
đ) Reporting periodically quarterly and annually, and ad hoc reports to the General Director (Director) on the risk management situation of the insurance company, reinsurance company, or foreign branch; promptly reporting to the Board of Directors, Board of Members of the insurance company, reinsurance company, and parent company of the foreign branch in case of discovering risks that may significantly impact financial safety and operational effectiveness. Quarterly reports must be sent no later than 30 days from the end of the quarter, annual reports must be sent no later than 90 days from the end of the year.
Article 5. Policies and internal regulations on risk management
The insurance company, reinsurance company, or foreign branch must develop risk management policies and internal regulations on risk management as follows:
1. The risk management policy of the insurance company, reinsurance company, or foreign branch must comply with the provisions at point c clause 2 Article 86 of the Insurance Business Law.
2. Internal regulations on risk management include the following contents:
a) Functions and responsibilities, hierarchical mechanisms, decision-making authority, and accountability of individuals and units in risk management activities of the insurance company, reinsurance company, or foreign branch.
b) Procedures for identifying, measuring, monitoring, and supervising risks related to significant risks; information exchange reporting, feedback on risk changes, and risk handling.
c) Specific risk limits for each type of significant risk and related risks, the correlation between these risks. Risk limits must ensure compliance with risk appetite and internal regulations on risk management; they must be reviewed at least once a year and ad hoc when there are significant changes affecting risks in the operations of the insurance company, reinsurance company, or foreign branch.
d) Measures to control risks arising from business activities and control individuals and units participating in those activities.
đ) Stress testing in accordance with Article 7 of this Circular.
e) Emergency plans for situations to ensure continuity in the business operations of the insurance company, reinsurance company, or foreign branch. This plan must be approved by the Board of Directors, Board of Members of the insurance company, reinsurance company, and parent company of the foreign branch.
g) Internal reporting mechanism on risk management.
Article 6. Identification, measurement, monitoring, and control of risks
Insurance enterprises, reinsurance enterprises, and foreign branches must identify, measure, monitor, and control risks in a timely and accurate manner according to the following regulations:
1. Identify significant risks that insurance enterprises, reinsurance enterprises, and foreign branches may encounter during their business operations.
2. Measure the level of risk based on determining the impact of such risks on the activities, capital, and payment capacity of insurance enterprises, reinsurance enterprises, and foreign branches. Risk measurement is carried out using methods and models. The methods and models for measuring risks must be periodically reviewed and evaluated for accuracy and reasonableness according to the internal regulations of insurance enterprises, reinsurance enterprises, and foreign branches. Data used in these methods and models must ensure reliability and verifiability.
3. Monitor the status of risks and promptly assess and issue early warnings about potential breaches of risk limits, mitigate the risk of risks occurring to ensure safety in operations; prepare internal reports on risk monitoring and send them to relevant individuals and departments.
4. Control the implementation of business processes within corresponding risk limits; conduct stress tests as stipulated in Clause 2 of this Circular, take preventive, mitigating, and timely risk management measures to ensure compliance with risk limits.
Article 7. Stress Testing
1. Annually, insurance enterprises, reinsurance enterprises, and foreign branches must carry out stress testing on capital and payment capacity according to the provisions of Clause 2 of this Article.
2. Stress testing is conducted as follows:
a) Develop at least two scenarios: one scenario with normal operating conditions; one scenario with adverse developments regarding insurance risk ratios, investment activities, operational costs, and other factors assessed by insurance enterprises, reinsurance enterprises, and foreign branches. Selected scenarios must be developed for at least the next five fiscal years and based on statistical analysis, actual operations of insurance enterprises, reinsurance enterprises, and foreign branches, and macroeconomic forecasts.
b) Calculate the impact of assumptions on capital indicators, solvency margins, and financial stability of insurance enterprises, reinsurance enterprises, and foreign branches in each scenario (including quantitative and qualitative analyses).
3. Based on the results of stress testing, insurance enterprises, reinsurance enterprises, and foreign branches determine measures to maintain business operations when adverse developments occur (if any).
Article 8. Risk Management Report
1. The risk management report must include the following contents:
a) Evaluation of the adequacy of risk management activities, determination of the financial resources needed to manage business operations within acceptable risk levels and business plans of insurance enterprises, reinsurance enterprises, and foreign branches;
b) Detailed assessment of significant risks of insurance enterprises, reinsurance enterprises, and foreign branches and changes in risks during operations;
c) Methods of managing significant risks of insurance enterprises, reinsurance enterprises, and foreign branches;
d) Results of stress testing and analysis of continued operation capabilities under adverse situations for business operations.
2. Annually, insurance enterprises, reinsurance enterprises, and foreign branches are responsible for preparing and submitting directly to the Ministry of Finance, through postal service, or online submission according to the guidance of the Ministry of Finance the risk management report no later than 90 days from the end of the fiscal year. The risk management report is prepared according to the form specified in the Appendix of this Circular.
Article 9. Management Information System
1. Insurance enterprises, reinsurance enterprises, and foreign branches must have a management information system to provide internal information and reports to the Board of Directors, Board of Members of the insurance enterprise, reinsurance enterprise, parent company of the foreign branch, General Director (Director), and related individuals and departments to perform functions and tasks ensuring compliance with the provisions of this Circular.
2. The minimum management information system shall include:
a) Internal reports, minutes of meetings, resolutions of the Board of Directors, Board of Members of the insurance enterprise, reinsurance enterprise, or decisions of the parent company of the foreign branch, decisions of the General Director (Director), and other management information as prescribed by the insurance enterprise, reinsurance enterprise, and foreign branch. Internal reports must at least include the following reports: Risk management report; internal audit report, reports from the compliance control department;
b) Organizational structure for managing and operating the management information system, specifying the responsibilities of individuals and departments in using the management information system;
c) Collection, processing, storage, and provision of information; establishment, sending, receiving, and processing of reports;
d) Information technology infrastructure meeting the requirements set out in point c and point d, Clause 3 of this Article.
3. The management information system must ensure:
a) Provision of complete, accurate, and timely information to meet the requirements of risk management, internal control, and internal audit work of the insurance enterprise, reinsurance enterprise, and foreign branch;
b) Updating on compliance with legal regulations and internal regulations of the insurance enterprise, reinsurance enterprise, and foreign branch;
c) Security, ensuring information and data safety, and having backup information systems to ensure safe, effective, and uninterrupted use of information;
d) Being reviewed, evaluated, upgraded, and updated regularly and promptly to meet the needs of management information, scale, structure, and complexity in business operations of the insurance enterprise, reinsurance enterprise, and foreign branch.
Article 10. Risk Management Culture
1. Insurance enterprises, reinsurance enterprises, and foreign branches build a risk management culture through the issuance and implementation of professional ethics standards, internal regulations on risk management, reward and punishment systems.
2. Professional ethics standards must ensure the following principles:
a) Employees carry out assigned duties and authorities honestly for the benefit of the insurance enterprise, reinsurance enterprise, and foreign branch; they do not take advantage of their positions or information of the insurance enterprise, reinsurance enterprise, and foreign branch for personal gain, causing harm to the interests of the insurance enterprise, reinsurance enterprise, and foreign branch;
b) Individuals and departments responsible for reporting promptly to the competent authority when discovering violations as stipulated in point a of this clause and violations of legal regulations and internal regulations of the insurance enterprise, reinsurance enterprise, and foreign branch.
3. Internal regulations on risk management must comply with the provisions of Clause 2, Article 5 of this Circular.
4. Reward and punishment systems must ensure the principles of accuracy, transparency, fairness, and timeliness. The implementation of rewards and punishments must be assessed based on the functions and tasks assigned to each department and individual of the insurance enterprise, reinsurance enterprise, and foreign branch.
Section 2
INTERNAL CONTROL
Article 11. Requirements for business processes
1. To ensure the implementation of internal control activities, insurance enterprises, reinsurance enterprises, and foreign branches must establish business processes. Business processes shall include at least the following processes: premium setting and product development process; acquisition and underwriting process; claims settlement and insurance payment process; reinsurance process; and internal control process.
2. Business processes must ensure clear delegation of authority and approval rights appropriate to the functions and responsibilities of individuals and units executing them; approval rights are determined based on transaction scale, risk limits, and other limits according to the internal regulations of insurance enterprises, reinsurance enterprises, and foreign branches.
Article 12. Internal Control Activities
Internal control activities shall ensure the following principles:
1. Internal control shall be implemented for all activities, business processes, and units of insurance enterprises, reinsurance enterprises, and foreign branches.
2. The compliance control unit must be independent from operational units.
3. An employee of an insurance enterprise, reinsurance enterprise, or foreign branch shall not concurrently hold positions or perform tasks with conflicting purposes or overlapping interests.
4. Employees shall not use information of insurance enterprises, reinsurance enterprises, or foreign branches for personal purposes; they shall not conceal violations of laws and internal regulations of insurance enterprises, reinsurance enterprises, or foreign branches.
5. Cross-checking supervision shall be ensured in the execution of business processes.
6. Financial information systems serving internal control activities must be truthful, reasonable, complete, accurate, and timely.
Article 13. Tasks of the Compliance Control Unit
The tasks of the compliance control unit include:
1. Advising the General Director (Director) or authorized body to issue internal control procedures.
2. Periodically and ad hoc reviewing and evaluating the compliance of individuals and operational units with legal provisions, rules, internal procedures, and professional ethical standards.
3. Supporting related units in establishing and reviewing internal regulations to ensure compliance with legal provisions; proposing improvements to procedures and internal regulations.
4. Preparing quarterly, annual, and ad hoc reports to the General Director (Director) on the compliance of individuals and operational units with legal provisions, rules, internal procedures, and professional ethical standards, and recommending modifications to business processes (if necessary). Quarterly reports must be submitted no later than 30 days after the end of the quarter, and annual reports must be submitted no later than 90 days after the end of the year.
5. Promptly reporting to the Board of Directors, Board of Members of insurance enterprises, reinsurance enterprises, and the parent company of foreign branches upon discovering violations of legal compliance by insurance enterprises, reinsurance enterprises, or foreign branches.
Section 3
INTERNAL AUDIT
Article 14. Tasks of Internal Audit
The tasks of internal audit include:
1. Auditing compliance with laws, procedures, and internal regulations of insurance enterprises, reinsurance enterprises, and foreign branches.
2. Auditing the safety and efficiency in managing and using capital, assets, and resources of insurance enterprises, reinsurance enterprises, and foreign branches.
3. Auditing the accuracy, honesty, and effectiveness of financial information control processes and the preparation of financial reports.
4. Auditing the completeness, accuracy, and security of information technology systems and business software.
5. Auditing other contents as required by the Board of Directors, Board of Members of insurance enterprises, reinsurance enterprises, and parent companies of foreign branches.
Article 15. Principles of Internal Audit
1. Independence:
a) The organization and operation of the internal audit department must be independent from the first-line and second-line units;
b) Individuals engaged in internal audit work shall not concurrently hold positions in the first-line and second-line units;
c) Internal audit shall not be subject to any interference during the determination of the scope and content of audits, when conducting evaluations, and reporting audit results.
2. Objectivity:
a) Individuals engaged in internal audit work must ensure objectivity, honesty, fairness, and lack of bias;
b) Records in internal audit reports must be carefully analyzed and based on collected data and information;
c) Individuals engaged in internal audit work shall not audit internal regulations, policies, procedures, and processes for which they are primarily responsible for establishing such regulations, policies, procedures, and processes;
d) Individuals engaged in internal audit work shall not participate in auditing activities or units for which they have been responsible for implementing activities or managing units within two years from the date of decision not to implement activities or manage those units;
e) Individuals engaged in internal audit work must promptly report to the Head of the internal audit department any issues that may affect objectivity during internal audit activities. In case of discovering that individuals engaged in internal audit work may not ensure adherence to the principle of objectivity in internal audit activities, the Head of the internal audit department must report to the Board of Directors, Board of Members of insurance enterprises, reinsurance enterprises, and parent companies of foreign branches to take appropriate measures;
f) The performance of the Head of the internal audit department must be regularly reviewed, audited, and evaluated by the Board of Directors, Board of Members of insurance enterprises, reinsurance enterprises, and parent companies of foreign branches.
3. Individuals engaged in internal audit work must comply with the law and bear legal responsibility for internal audit activities within the scope of their assigned tasks.
Article 16. Regulations and Procedures for Internal Audit
1. Insurance enterprises, reinsurance enterprises, and foreign branches must issue regulations and procedures for internal audit.
2. The internal audit regulation must include the following contents:
a) Objectives, scope of operations, position, tasks, authorities, responsibilities of the internal audit department in insurance enterprises, reinsurance enterprises, and foreign branches, and relationships with other departments;
b) Basic principles, requirements for professional qualifications, ensuring the quality of internal audit, and related contents.
3. The internal audit procedure provides detailed guidance on the following contents:
a) Methods of assessing and classifying risk levels (low, medium, high) as the basis for developing internal audit plans;
b) Methods of preparing annual internal audit plans, ways of conducting audit work, preparing and submitting audit reports, and monitoring post-audit recommendations;
c) Ways of storing internal audit files and documents.
Article 17. Internal Audit Plan
1. The internal audit department shall develop and implement the annual internal audit plan, including the scope of audit, audit subjects, audit objectives, audit time, and allocation of resources.
2. Business units and operations with high risk levels, as assessed by insurance companies, reinsurance companies, and foreign branches, must be included in the annual audit plan.
3. When developing the internal audit plan, the internal audit department must reserve sufficient time to conduct surprise audits when required.
Article 18. Rights and Responsibilities of the Internal Audit Department
1. During the performance of its duties, the internal audit department has the following rights:
a) To be provided with all necessary information, documents, and records for internal auditing in a timely and complete manner;
b) To access and review all business processes, assets during internal auditing;
c) To interview all employees of insurance companies, reinsurance companies, and foreign branches regarding issues related to the audit content;
d) To receive documents, texts, meeting minutes of the Board of Directors, Board of Members of insurance companies, reinsurance companies, and parent companies of foreign branches relevant to internal auditing work.
2. The internal audit department has the following responsibilities:
a) To maintain confidentiality of documents and information in accordance with current laws, regulations, and internal rules on internal auditing of insurance companies, reinsurance companies, and foreign branches;
b) To immediately report to the Board of Directors, Board of Members of insurance companies, reinsurance companies, parent companies of foreign branches, General Director (Director) if serious violations or high-risk situations that may adversely affect the operations of insurance companies, reinsurance companies, and foreign branches are discovered during the audit process;
c) To promptly prepare, complete, and submit audit reports to the Board of Directors, Board of Members of insurance companies, reinsurance companies, parent companies of foreign branches, General Director (Director), and audited departments after each audit is completed;
d) To monitor, evaluate, and follow up on corrective actions taken in response to issues identified and recommendations made by internal auditing;
đ) To notify the Board of Directors, Board of Members of insurance companies, reinsurance companies, and parent companies of foreign branches if issues noted in the audit report are not corrected and resolved in a timely manner;
e) To properly store internal audit documents and records in writing according to procedures for authorized individuals and organizations to access.
Article 19. Responsibilities of Audited Departments
1. To provide complete and timely information, documents, and records as requested by the internal audit department to carry out audit activities.
2. To immediately inform the internal audit department upon discovering signs of violations or risks that could impact the operations of insurance companies, reinsurance companies, and foreign branches.
3. To promptly implement recommendations in the internal audit report and directives from the Board of Directors, Board of Members of insurance companies, reinsurance companies, parent companies of foreign branches, and General Director (Director) (if applicable).
Article 20. Internal Audit Report
1. The internal audit department must submit the internal audit report to the Board of Directors, Board of Members of the insurance company, reinsurance company, and the parent company of the foreign branch within a maximum period of ninety days from the end of each audit.
2. The internal audit report must clearly present:
a) The content and scope of the audit;
b) Evaluations and conclusions on the audited content and the basis for these opinions;
c) Existences, violations, and explanations provided by the auditee;
d) Recommendations for corrective measures to address errors and handle violations; measures aimed at improving business processes, perfecting risk management policies, and organizational structures of the insurance company, reinsurance company, and foreign branch (if applicable).
Section 4
RESPONSIBILITIES OF THE BOARD OF DIRECTORS, BOARD OF MEMBERS, PARENT COMPANY OF FOREIGN BRANCH AND GENERAL MANAGER (MANAGER)
ENTITY, PARENT COMPANY OF THE FOREIGN BRANCH AND GENERAL DIRECTOR (DIRECTOR)
GENERAL DIRECTOR (DIRECTOR)
Article 21. Responsibilities of the Board of Directors, Board of Members, Parent Company of Foreign Branch
The Board of Directors, Board of Members of the insurance company, reinsurance company, and parent company of the foreign branch shall be responsible for:
1. Deciding on the organizational structure of the insurance company, reinsurance company, and foreign branch to implement risk management, internal control, and internal auditing.
2. Issuing risk management policies for each period; principles for implementing internal controls; internal audit procedures of the insurance company, reinsurance company, and foreign branch.
3. Approving internal regulations on risk management before the General Manager (Manager) issues them; approving and adjusting the annual internal audit plan.
4. Directing and supervising the General Manager (Manager) in:
a) Addressing and rectifying existences and limitations regarding organizational risk management and implementing requirements and recommendations from independent auditors, internal auditors, and competent authorities;
b) Handling violations and breaches of professional ethics and internal regulations by individuals and related departments.
5. The Board of Directors, Board of Members of the insurance company, reinsurance company shall be responsible for approving the risk management report of the insurance company, reinsurance company before reporting to the Ministry of Finance. The authority to approve the risk management report of the foreign branch before reporting to the Ministry of Finance shall be carried out according to the operational regulations of the foreign branch and the regulations of the parent company.
Article 22. Responsibilities of the General Manager (Manager)
The General Manager (Manager) of the insurance company, reinsurance company, and foreign branch shall be responsible for:
1. Issuing business procedures (including internal control procedures), professional ethics standards; internal regulations on risk management; reward and punishment systems; implementing risk limit allocation according to each procedure and business activity.
2. Organizing the implementation of internal control activities and risk management as stipulated in Section 1 and Section 2 of this Chapter.
3. Inspecting and evaluating the implementation of internal control activities and risk management and deciding on adjustment and remediation measures (if necessary).
4. Organizing the operation and improvement of the management information system.
5. Directing first-line and second-line defense units to cooperate with internal auditing according to the internal audit regulations of the insurance company, reinsurance company, and foreign branch.
6. Directing the implementation of recommendations in the internal audit report and carrying out directives of the Board of Directors, Board of Members (if any), and informing the internal audit department about the results of implementation.
Chapter III
IMPLEMENTING PROVISIONS
Article 23. Effectiveness of the Circular
1. This Circular takes effect from January 1, 2023.
2. During implementation, if there are difficulties or obstacles, they should be promptly reported to the Ministry of Finance for consideration and resolution./.
原始文件(PDF)
关系图
点击文件即可打开。红色边框=改变效力的关系。
译本
本文件提供以下语言版本: