BCBS issued principles for operational resilience and revised the principles for sound management of operational risk, following an August 2020 consultation. The principles for operational resilience aim to strengthen banks' ability to withstand operational risk-related events that could cause significant operational failures or wide-scale disruptions in financial markets, such as pandemics, cyber incidents, technology failures or natural disasters. The principles for the sound management of operational risk have been revised to make technical revisions to align the principles with the recently finalized Basel III operational risk framework, update the guidance where needed in the areas of change management and information and communication technologies (ICT), and enhance the overall clarity of the principles.
BCBS had conducted, in 2014, a review of the implementation of the principles for sound management of operational risk. The review was aimed to assess the extent to which banks had implemented the principles, identify significant gaps in implementation, and highlight emerging and noteworthy operational risk management practices at banks not currently addressed by the principles. The 2014 review had identified that several principles had not been adequately implemented and further guidance would be needed to facilitate their implementation in certain areas. The revised principles for sound management of operational risk for banks cover governance, the risk management environment, information and communication technology, business continuity planning,; and the role of disclosures. These elements should not be viewed in isolation; rather, they are integrated components of the operational risk management framework and the overall risk management framework (including operational resilience) of the group. BCBS recommends that banks should take account of the nature, size, complexity and risk profile of their activities when implementing the Principles.
The principles for operational resilience build on the principles for sound management of operational risk and are largely derived and adapted from existing guidance on outsourcing-, business continuity- and risk management-related guidance issued by BCBS or national supervisors over a number of years. By building on the existing guidance and current practices, BCBS is seeking to develop a coherent framework and avoid duplication. The operational resilience principles focus on governance, operational risk management, business continuity planning and testing, mapping interconnections and interdependencies, third-party dependency management, incident management, and resilient cyber security and ICT. The approach draws from the previously issued principles on corporate governance for banks as well as outsourcing-, business continuity- and relevant risk management-related guidance.
Keywords: International, Banking, Basel, Operational Risk, Operational Resilience, Guidance, Outsourcing Risk, Third-Party Risk, Cyber Risk, COVID-19, BCBS
Leading economist; commercial real estate; performance forecasting, econometric infrastructure; data modeling; credit risk modeling; portfolio assessment; custom commercial real estate analysis; thought leader.
Previous ArticleSRB Issues Guidance on Bail-In for International Debt Securities
PRA published the policy statement PS8/21, which contains the final supervisory statement SS3/21 on the PRA approach to supervision of the new and growing non-systemic banks in UK.
EBA published a report that sets out the final draft regulatory technical standards specifying the conditions according to which consolidation shall be carried out in line with Article 18 of the Capital Requirements Regulation (CRR).
EBA updated the list of other systemically important institutions (O-SIIs) in EU.
BCBS published two reports that discuss transmission channels of climate-related risks to the banking system and the measurement methodologies of climate-related financial risks.
UK Authorities (FCA and PRA) welcomed the findings of FSB peer review on the implementation of financial sector remuneration reforms in the UK.
PRA and FCA jointly issued a letter that highlights risks associated with the increasing volumes of deposits that are placed with banks and building societies via deposit aggregators and how to mitigate these risks.
MFSA announced that amendments to the Banking Act, Subsidiary Legislation, and Banking Rules will be issued in the coming months, to transpose the Capital Requirements Directive (CRD5) into the national regulatory framework.
EC finalized the Delegated Regulation 2021/598 that supplements the Capital Requirements Regulation (CRR or 575/2013) and lays out the regulatory technical standards for assigning risk-weights to specialized lending exposures.
OSFI launched a consultation to explore ways to enhance the OSFI assurance over capital, leverage, and liquidity returns for banks and insurers, given the increasing complexity arising from the evolving regulatory reporting framework due to IFRS 17 (Insurance Contracts) standard and Basel III reforms.
ECB published results of the benchmarking analysis of the recovery plan cycle for 2019.