OSFI Updates Address BCAR Reporting, Basel Reforms, and Cyber Risk
The Office of the Superintendent of Financial Institutions (OSFI) updated the 2023 Basel Capital Adequacy Reporting (BCAR) manual as well as the 2023 BCAR return. OSFI also published a series of frequently asked questions (FAQs) regarding the implementation of Basel III banking reforms. Additionally, OSFI released the final Guideline B-13, which sets out its expectations for how federally regulated financial institutions should manage technology and cyber risks such as data breaches, technology outages, and more.
BCAR reporting manual and return. The BCAR reporting manual provides guidance on how to complete the full BCAR return. The BCAR return collects data to calculate the risk-based capital ratio of reporting institutions as well as details of the calculation. For domestic systemically important banks (D-SIBs), this return also collects the data to calculate the risk-based Total Loss Absorbing Capacity (TLAC) ratio of the reporting D-SIB, along with the details of the calculation. The return must be completed on a quarterly fiscal basis and filed within 30 days of the quarter-end date.
FAQs on Basel III Reforms. The FAQs offer guidance on certain aspects of the Basel III-related changes to the Capital Adequacy Requirements Guideline, the Liquidity Adequacy Requirements Guideline, and the Leverage Requirements Guideline. With respect to the Capital Adequacy Requirements Guideline, OSFI has published FAQs on the risk-based capital targets, definition of capital, operational risk, standardized approach for credit risk, internal ratings-based approach to credit risk, settlement and counterparty risk, and credit valuation adjustment (CVA) risk. With respect to the Liquidity Adequacy Requirements Guideline, OSFI has published FAQs related to the liquidity coverage ratio and the net cumulative cash flow while, for the Leverage Requirements Guideline, OSFI has published FAQs related to the leverage ratio buffer.
Guideline on technology and cyber risk management. The guideline, which will be effective as of January 01, 2024, has been organized into three domains: governance and risk management, technology operations and resilience, and cyber-security. Each domain has a desired outcome for the federally regulated financial institutions to achieve through managing risks that contribute to developing their resilience to technology and cyber risks. The guideline sets out the following key principles under each domain:
- Senior Management should assign responsibility for managing technology and cyber risks to senior officers. It should also ensure an appropriate organizational structure and adequate resourcing are in place for managing technology and cyber risks across the federally regulated financial institution.
- Federally regulated financial institutions should define, document, approve, and implement a strategic technology and cyber plan(s). The plan(s) should align to business strategy and set goals and objectives that are measurable and evolve with changes in the federally regulated financial institution’s technology and cyber environment.
- Federally regulated financial institutions should establish a technology and cyber risk management framework. The framework should set out a risk appetite for technology and cyber risks and define federally regulated financial institution’s processes and requirements to identify, assess, manage, monitor, and report on technology and cyber risks.
- Federally regulated financial institutions should maintain an updated inventory of all technology assets supporting business processes or functions. Federally regulated financial institution’s asset management processes should address classification of assets to facilitate risk identification and assessment, record configurations to ensure asset integrity, provide for the safe disposal of assets at the end of their life cycle, and monitor and manage technology currency.
- Federally regulated financial institutions should establish and maintain an Enterprise Disaster Recovery Program (EDRP) to support its ability to deliver technology services through disruption and operate within its risk tolerance.
- Federally regulated financial institutions should maintain a range of practices, capabilities, processes and tools to identify and assess cyber security for weaknesses that could be exploited by external and insider threat actors.
- Federally regulated financial institutions should design, implement and maintain multi-layer, preventive cyber security controls and measures to safeguard its technology assets.
Related Links
- BCAR Reporting Manual
- BCAR 2023 Return (XLSX)
- FAQs on Basel III Reforms
- News Release on Guideline on Technology and Cyber Risk Management
- Guidelines on Technology and Cyber Risk Management
Keywords: Americas, Canada, Banking, Basel, BCAR, Reporting, Capital Adequacy, Regulatory Capital, Credit Risk, Operational Risk, FAQ, Technology Risk, Cyber Risk, Regtech, CVA Risk, OSFI
Featured Experts
María Cañamero
Skilled market researcher; growth strategist; successful go-to-market campaign developer
Nicolas Degruson
Works with financial institutions, regulatory experts, business analysts, product managers, and software engineers to drive regulatory solutions across the globe.
Patrycja Oleksza
Applies proficiency and knowledge to regulatory capital and reporting analysis and coordinates business and product strategies in the banking technology area
Previous Article
CBIRC Issues Notice on Management of Online Lending for BanksNext Article
ECB Announces Croatia to Join Euro Area Next YearRelated Articles
BIS and Central Banks Experiment with GenAI to Assess Climate Risks
A recent report from the Bank for International Settlements (BIS) Innovation Hub details Project Gaia, a collaboration between the BIS Innovation Hub Eurosystem Center and certain central banks in Europe
Nearly 25% G-SIBs Commit to Adopting TNFD Nature-Related Disclosures
Nature-related risks are increasing in severity and frequency, affecting businesses, capital providers, financial systems, and economies.
Singapore to Mandate Climate Disclosures from FY2025
Singapore recently took a significant step toward turning climate ambition into action, with the introduction of mandatory climate-related disclosures for listed and large non-listed companies
SEC Finalizes Climate-Related Disclosures Rule
The U.S. Securities and Exchange Commission (SEC) has finalized the long-awaited rule that mandates climate-related disclosures for domestic and foreign publicly listed companies in the U.S.
EBA Proposes Standards Related to Standardized Credit Risk Approach
The European Banking Authority (EBA) has been taking significant steps toward implementing the Basel III framework and strengthening the regulatory framework for credit institutions in the EU
US Regulators Release Stress Test Scenarios for Banks
The U.S. regulators recently released baseline and severely adverse scenarios, along with other details, for stress testing the banks in 2024. The relevant U.S. banking regulators are the Federal Reserve Bank (FED), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC).
Asian Governments Aim for Interoperability in AI Governance Frameworks
The regulatory landscape for artificial intelligence (AI), including the generative kind, is evolving rapidly, with governments and regulators aiming to address the challenges and opportunities presented by this transformative technology.
EBA Proposes Operational Risk Standards Under Final Basel III Package
The European Union (EU) has been working on the final elements of Basel III standards, with endorsement of the Banking Package and the publication of the European Banking Authority (EBA) roadmap on Basel III implementation in December 2023.
EFRAG Proposes XBRL Taxonomy and Standard for Listed SMEs Under ESRS
The European Financial Reporting Advisory Group (EFRAG), which plays a crucial role in shaping corporate reporting standards in European Union (EU), is seeking comments, until May 21, 2024, on the Exposure Draft ESRS for listed SMEs.
ECB to Expand Climate Change Work in 2024-2025
Banking regulators worldwide are increasingly focusing on addressing, monitoring, and supervising the institutions' exposure to climate and environmental risks.