BOT published a notification on the regulations on information technology risk of financial institutions and the guidelines on risk management from third-parties. The notification is effective from November 15, 2019. The notification shall apply to commercial banks registered in the country, commercial banks registered in foreign countries, credit foncier companies, and finance companies. The key points in the notification include that domestic systemically important banks (D-SIBs) and financial institutions that have a high level of cyber inherent risk must have a senior executive responsible to manage information technology security of financial institutions (Chief Information Security Officer: CISO). Commercial banks must report significant information technology projects for the year to BOT.
Related Link (in Thai): Notification
Effective Date: November 15, 2019
Keywords: Asia Pacific, Thailand, Banking, Cyber Risk, Governance, Third-party Arrangements, Fintech, D-SIBs, Operational Risk, Systemic Risk, BOT
Across 35 years in banking, Blake has gained deep insights into the inner working of this sector. Over the last two decades, Blake has been an Operating Committee member, leading teams and executing strategies in Credit and Enterprise Risk as well as Line of Business. His focus over this time has been primarily Commercial/Corporate with particular emphasis on CRE. Blake has spent most of his career with large and mid-size banks. Blake joined Moody’s Analytics in 2021 after leading the transformation of the credit approval and reporting process at a $25 billion bank.
The Australian Prudential Regulation Authority (APRA) released the final Prudential Practice Guide on management of climate change financial risks (CPG 229) for banks, insurers, and superannuation trustees.
The European Council adopted its position on two proposals that are part of the digital finance package adopted by the European Commission in September 2020, with one of the proposals involving the regulation on markets in crypto-assets (MiCA) and the other involving the Digital Operational Resilience Act (DORA).
The Prudential Regulation Authority (PRA) is proposing, via the consultation paper CP21/21, to apply group provisions in the Operational Resilience Part of the PRA Rulebook (relevant for the Capital Requirements Regulation or CRR firms) to holding companies.
The European Commission (EC) has adopted a package of measures related to the Capital Markets Union.
The European Banking Authority (EBA) published the final report on draft regulatory technical standards for the calculation of risk-weighted exposure amounts of collective investment undertakings or CIUs, in line with the Capital Requirements Regulation (CRR).
The Board of Governors of the Federal Reserve System (FED) published a report that summarizes banking conditions in the United States, along with the supervisory and regulatory activities of FED.
The Australian Prudential Regulation Authority (APRA) recently completed two pilot initiatives in its 2020-2024 Cyber Security Strategy, which was published in November 2020.
The Basel Committee on Banking Supervision (BCBS) published further information related to its 2021 assessment of global systemically important banks (G-SIBs), with additional details to help understand the scoring methodology.
The Financial Accounting Standards Board (FASB) is consulting on an Accounting Standards Update and the associated taxonomy improvements for requirements on troubled debt restructurings and vintage disclosures under the credit losses standard (for financial instruments) topic 326.
US Agencies issued a statement that summarizes the work undertaken during the interagency policy sprints focused on crypto-assets and provides a roadmap of future work related to crypto-assets.