The Office of the Superintendent of Financial Institutions (OSFI) updated the 2023 Basel Capital Adequacy Reporting (BCAR) manual as well as the 2023 BCAR return. OSFI also published a series of frequently asked questions (FAQs) regarding the implementation of Basel III banking reforms. Additionally, OSFI released the final Guideline B-13, which sets out its expectations for how federally regulated financial institutions should manage technology and cyber risks such as data breaches, technology outages, and more.
BCAR reporting manual and return. The BCAR reporting manual provides guidance on how to complete the full BCAR return. The BCAR return collects data to calculate the risk-based capital ratio of reporting institutions as well as details of the calculation. For domestic systemically important banks (D-SIBs), this return also collects the data to calculate the risk-based Total Loss Absorbing Capacity (TLAC) ratio of the reporting D-SIB, along with the details of the calculation. The return must be completed on a quarterly fiscal basis and filed within 30 days of the quarter-end date.
FAQs on Basel III Reforms. The FAQs offer guidance on certain aspects of the Basel III-related changes to the Capital Adequacy Requirements Guideline, the Liquidity Adequacy Requirements Guideline, and the Leverage Requirements Guideline. With respect to the Capital Adequacy Requirements Guideline, OSFI has published FAQs on the risk-based capital targets, definition of capital, operational risk, standardized approach for credit risk, internal ratings-based approach to credit risk, settlement and counterparty risk, and credit valuation adjustment (CVA) risk. With respect to the Liquidity Adequacy Requirements Guideline, OSFI has published FAQs related to the liquidity coverage ratio and the net cumulative cash flow while, for the Leverage Requirements Guideline, OSFI has published FAQs related to the leverage ratio buffer.
Guideline on technology and cyber risk management. The guideline, which will be effective as of January 01, 2024, has been organized into three domains: governance and risk management, technology operations and resilience, and cyber-security. Each domain has a desired outcome for the federally regulated financial institutions to achieve through managing risks that contribute to developing their resilience to technology and cyber risks. The guideline sets out the following key principles under each domain:
- Senior Management should assign responsibility for managing technology and cyber risks to senior officers. It should also ensure an appropriate organizational structure and adequate resourcing are in place for managing technology and cyber risks across the federally regulated financial institution.
- Federally regulated financial institutions should define, document, approve, and implement a strategic technology and cyber plan(s). The plan(s) should align to business strategy and set goals and objectives that are measurable and evolve with changes in the federally regulated financial institution’s technology and cyber environment.
- Federally regulated financial institutions should establish a technology and cyber risk management framework. The framework should set out a risk appetite for technology and cyber risks and define federally regulated financial institution’s processes and requirements to identify, assess, manage, monitor, and report on technology and cyber risks.
- Federally regulated financial institutions should maintain an updated inventory of all technology assets supporting business processes or functions. Federally regulated financial institution’s asset management processes should address classification of assets to facilitate risk identification and assessment, record configurations to ensure asset integrity, provide for the safe disposal of assets at the end of their life cycle, and monitor and manage technology currency.
- Federally regulated financial institutions should establish and maintain an Enterprise Disaster Recovery Program (EDRP) to support its ability to deliver technology services through disruption and operate within its risk tolerance.
- Federally regulated financial institutions should maintain a range of practices, capabilities, processes and tools to identify and assess cyber security for weaknesses that could be exploited by external and insider threat actors.
- Federally regulated financial institutions should design, implement and maintain multi-layer, preventive cyber security controls and measures to safeguard its technology assets.
- BCAR Reporting Manual
- BCAR 2023 Return (XLSX)
- FAQs on Basel III Reforms
- News Release on Guideline on Technology and Cyber Risk Management
- Guidelines on Technology and Cyber Risk Management
Keywords: Americas, Canada, Banking, Basel, BCAR, Reporting, Capital Adequacy, Regulatory Capital, Credit Risk, Operational Risk, FAQ, Technology Risk, Cyber Risk, Regtech, CVA Risk, OSFI
Previous ArticleSRB Issues Resolvability Assessment and Bail-in Implementation Guide
The Australian Prudential Regulation Authority (APRA) has published the findings of its latest climate risk self-assessment survey conducted across the banking, insurance, and superannuation industries.
The French Prudential Supervisory Authority (ACPR) published a notice related to the methods for calculating and publishing prudential ratios under the Capital Requirements Directive (CRD IV) and the minimum requirement for own funds and eligible liabilities (MREL).
The Financial Stability Institute (FSI) of the Bank for International Settlements recently published a paper proposing a framework for classifying financial stability regulation as either entity-based or activity-based.
The European Insurance and Occupational Pension Authority (EIOPA) published the risk dashboard based on Solvency II data and the final version of the application guidance on climate change materiality assessments and climate change scenarios in the Own Risk and Solvency Assessment (ORSA).
The European Banking Authority (EBA) and the European Central Bank (ECB) published their responses to the consultations of the International Sustainability Standards Board (ISSB) and the European Financial Reporting Advisory Group (EFRAG) on sustainability-related disclosure standards.
A Consultative Group on Risk Management (CGRM) at the Bank for International Settlements (BIS) published a report that examines incorporation of climate risks into the international reserve management framework.
The European Banking Authority (EBA) published the final guidelines on liquidity requirements exemption for investment firms, updated version of its 5.2 filing rules document for supervisory reporting, and Single Rulebook Question and Answer (Q&A) updates in July 2022.
The European Insurance and Occupational Pensions Authority (EIOPA) published Version 2.8.0 of the Solvency II data point model (DPM) and XBRL taxonomy.
The European Union published, in the Official Journal of the European Union, an opinion from the European Economic and Social Committee (EESC); the opinion is on the proposal for a regulation to amend the Capital Requirements Regulation (CRR).
HM Treasury published a draft statutory instrument titled “The Financial Services (Miscellaneous Amendments) (EU Exit) Regulations 2022,” along with the related explanatory memorandum and impact assessment.