Consultation Paper
Consultation Paper - Proposed Adoption of the Revised Operational Risk Principles for Banks
DraftView on BMA's website Source document
Summary
This consultation paper sets out the Bermuda Monetary Authority's proposal to replace its 2007 Guidance on operational risk with a framework based on the Basel Committee's 2021 Revised Principles for the Sound Management of Operational Risk. It applies to banks (and deposit companies) supervised by the Authority and covers twelve principles spanning risk culture, governance, risk identification and monitoring, ICT risk, business continuity and public disclosures. The Authority is inviting industry feedback before finalising and implementing the revised framework.
- Culture and framework: Boards must embed a robust operational risk culture and implement an operational risk management framework (ORMF) integrated across all three lines of defence.
- Governance: Boards and senior management must set and review a risk appetite and tolerance statement, approve the ORMF, and ensure appropriate governance structures and challenge mechanisms.
- Risk environment: Banks must maintain loss event tracking (with a proposed BM$10,000 materiality threshold), conduct self-assessments, scenario analysis and benchmarking, and operate change management, monitoring and reporting, and internal control processes.
- ICT risk: Banks must implement an ICT risk management programme covering identification, mitigation (including cybersecurity), monitoring and compliance with Authority guidance/codes.
- Business continuity and disclosure: Banks must maintain business continuity and disaster recovery plans linked to the ORMF, and adopt a formal public disclosure policy on operational risk subject to independent review.
The Authority proposes an implementation date of 1 January 2023 for the revised principles, and requested stakeholder comments by 31 March 2022 as part of this consultation.
Key obligations
- Provide comments on the proposed adoption of the Revised Principles to banking@bma.bm by close of business on 31 March 2022
- Maintain risk management policies and procedures appropriate to the institution's business profile, keeping operational risk frameworks under regular review
- Implement systems to identify and systematically track all material operational loss events, applying a materiality threshold of BM$10,000
- Establish and maintain an operational risk corporate culture and code of conduct/ethics policy, with compensation aligned to risk appetite
- Implement a fully integrated operational risk management framework (ORMF) reviewed by the board and challenged/reviewed across the three lines of defence
- Establish, monitor and periodically review an operational risk appetite and tolerance statement approved by the board
- Implement comprehensive risk identification and assessment processes including event management, self-assessments, control monitoring, metrics, scenario analysis and benchmarking
- Develop and maintain an effective change management process, including a central register of products and services
- Implement effective monitoring and reporting processes ensuring timely, accurate operational risk reports to the board, senior management and business units
- Maintain a strong internal control environment covering risk assessment, control activities, information and communication, and monitoring activities
- Implement a robust ICT risk management programme covering identification, mitigation (including cybersecurity), monitoring and compliance with Authority guidance/codes
- Formulate and maintain business continuity plans and disaster recovery plans linked to the operational risk management framework, subject to regular board review
- Establish a formal disclosure policy for operational risk information and disclose relevant operational risk information to stakeholders
Applies to
banks, deposit companies
Deadlines
- 31 March 2022: Deadline for industry and stakeholders to submit comments on the consultation paper to banking@bma.bm
- 1 January 2023: Proposed effective/implementation date for the Revised Operational Risk Principles