The Office of the Comptroller of the Currency (OCC) issued a Cease and Desist Order against MUFG Union Bank for deficiencies in technology and operational risk governance. The MUFG Union Bank is based in the United States and is owned by the Japanese banking entity Mitsubishi UFJ Financial Group. This action was the result of the bank's unsafe or unsound practices in this area and for the bank’s non-compliance with the interagency guidelines establishing information security standards. The Order requires the bank to improve longstanding technology and operational risk governance, technology risk assessments, internal controls, and staffing deficiencies to address the unsafe or unsound practices.
Within 90 days of the effective date of this Order, the bank shall develop an acceptable, written action plan detailing the remedial actions necessary to achieve compliance with Articles V through XI of this Order, thereby addressing the unsafe or unsound practices and noncompliance. The bank shall submit the action plan to the Examiner-in-Charge for review and prior written determination of no supervisory objection. The action plan, at a minimum, shall specify a description of the corrective actions needed to achieve compliance with each Article of this Order, reasonable and well-supported timelines for completion of the corrective actions required by this Order, and the person(s) responsible for completion of the corrective actions required by this Order. The Board shall ensure that the bank has timely adopted and implemented all corrective actions required by this Order. The Board shall also verify that the bank adheres to the corrective actions and that these actions are effective in addressing the identified deficiencies. In each instance in which this Order imposes responsibilities upon the Board, it is intended to mean that the Board shall:
- authorize, direct, and adopt corrective actions on behalf of the bank, as may be necessary to perform the obligations and undertakings imposed on the Board by this Order
- ensure the bank has sufficient processes, management, personnel, control systems, and corporate and risk governance to implement and adhere to all provisions of this Order
- require that bank management and personnel have sufficient training and authority to execute their duties and responsibilities pertaining to or resulting from this Order
- hold bank management and personnel accountable for executing their duties and responsibilities pertaining to or resulting from this Order
- require appropriate, adequate, and timely reporting to the Board by bank management of corrective actions directed by the Board to be taken under the terms of this Order
- address any noncompliance with corrective actions in a timely and appropriate manner
Keywords: Americas, US, Banking, Operational Risk, Cease and Desist Order, Regtech, MUFG, Technology Risk, Compliance Risk, Governance, OCC
The Central Bank of the Philippines (BSP) issued communications covering developments related to online lending platforms, open finance framework and roadmap, and on the expected regulations in the area sustainable finance.
The Board of Governors of the Federal Reserve System (FED) published the final rule that amends Regulation I to reduce the quarterly reporting burden for member banks by automating the application process for adjusting their subscriptions to the Federal Reserve Bank capital stock, except in the context of mergers.
The European Banking Authority (EBA) published its assessment of risks through the quarterly Risk Dashboard and the results of the Autumn edition of the Risk Assessment Questionnaire (RAQ).
The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0.
The Hong Kong Monetary Authority (HKMA) published a circular, along with the reporting form and instructions, for self-assessment, by authorized institutions, of compliance with the Code of Banking Practice 2021.
The Financial Conduct Authority (FCA) decided to register European DataWarehouse Ltd and SecRep Limited as securitization repositories under the UK Securitization Regulation, with effect from January 17, 2022.
The European Commission (EC) published the Delegated Regulation 2022/25, which supplements the Investment Firms Regulation (IFR or Regulation 2019/2033) with respect to the regulatory technical standards specifying the methods for measuring the K-factors referred to in Article 15 of the IFR.
The Bank of International Settlements (BIS) published a paper that assesses the ways in which platform-based business models can affect financial inclusion, competition, financial stability and consumer protection.
The Central Bank of Egypt (CBE) published a circular with instructions on emergency liquidity assistance to banks that are unable to meet their liquidity requirements.
The European Supervisory Authorities (ESAs) published the list of identified financial conglomerates for 2021.