Rule
Rule and Statement of Guidance – Internal Controls for Regulated Entities
In forceIn force effective 2023-10-14, gazetted in Rule and Statement of Guidance - Internal Controls for Regulated Entities. (EX27, S3) (computed: published 2023-04-14 + 6 months)
View on CIMA's website Source document
Summary
This is a CIMA Rule and Statement of Guidance, effective April 2023, that sets out mandatory rules (marked "R") and accompanying guidance on the internal control systems that regulated entities must maintain. It applies broadly to all entities regulated by CIMA under the regulatory acts, subject to proportional application based on size, complexity, structure, nature of business and risk profile.
Structure of the Document
- Part I – General Rules: Covers the five components of internal control: Control Environment, Risk Identification and Assessment, Control Activities and Segregation of Duties, Information and Communication, and Monitoring Activities and Correcting Deficiencies.
- Part II – Sector-Specific Rules: Adds rules for trust companies, company managers and corporate services providers, and for securities investment business licensees and registered persons.
General Rules Requirements
The general rules require a regulated entity's Governing Body (its board, general partner, manager, or board of trustees, as applicable) and Senior Management to establish, document and maintain an adequate and effective internal control system.
- A documented organisational structure.
- Clear reporting lines.
- Staff competency and training.
- An ethical control culture.
- Accountability for internal control responsibilities.
Entities may rely on outsourced service providers' or group-wide internal control systems provided the Governing Body can demonstrate to CIMA that these meet the Rule's requirements.
Sector-Specific Obligations
- Trust companies, company managers and corporate services providers: Must segregate client assets and client money, provide written disclosure on how client money is held, reconcile client money accounts promptly, require dual signatories for client money pay-outs, and prevent inappropriate use of client money.
- Securities investment business licensees and registered persons: Must manage conflicts of interest, control discretionary account activity, maintain dealing and trade allocation controls to prevent errors and fraud, and segregate client funds and property from the entity's own.
Breach of any rule exposes the entity to CIMA's enforcement powers under its Enforcement Manual and the Monetary Authority Act.
Key obligations
- The Governing Body must establish, document, and maintain an adequate and effective system of internal control, and demonstrate independence from Management or, where not possible, implement documented policies to manage conflicts of interest.
- A regulated entity must establish and document its organisational structure, including reporting lines, responsibilities, and authority, and keep this current.
- A regulated entity must demonstrate that activities are conducted by persons with sufficient knowledge, skills and experience, and regularly update staff training relevant to internal control and legal/regulatory compliance.
- A regulated entity must hold persons assigned internal control responsibilities accountable for performance of those responsibilities.
- Where relying on an outsourced service provider's or group's system of internal control, the Governing Body must be able to demonstrate to CIMA that such system meets the Rule's requirements.
- Trust companies, company managers and corporate services providers must segregate client assets from other clients' assets and from the entity's own assets.
- Trust companies, company managers and corporate services providers must hold client money in accounts clearly segregated and distinct from other clients' accounts and the entity's own accounts.
- Trust companies, company managers and corporate services providers must provide clients with written disclosure of the terms on which client money is held.
- Trust companies, company managers and corporate services providers must reconcile client money accounts promptly.
- Trust companies, company managers and corporate services providers must implement dual-signatory (at minimum) authorisation for client money pay-outs, subject to client-agreed terms.
- Trust companies, company managers and corporate services providers must implement policies and procedures to prevent inappropriate use of client money, including for settling the entity's own fees.
- Securities investment business licensees and registered persons must establish policies and procedures to minimise conflicts of interest and ensure clients are fully informed of unavoidable conflicts.
- Securities investment business licensees and registered persons exercising discretionary authority over client accounts must establish procedures ensuring terms are communicated to clients and only suitable transactions are effected.
- Securities investment business licensees and registered persons must maintain effective dealing and review procedures to prevent or detect errors, fraud and unauthorised activity, and ensure fair and timely trade allocation.
- Securities investment business licensees and registered persons must ensure client funds and property are clearly segregated from the entity's own funds and property.
Applies to
all entities regulated by CIMA under the regulatory acts, trust companies, company managers, corporate services providers, securities investment business licensees, registered persons (market makers, broker-dealers, securities arrangers, securities advisors, securities managers)
Deadlines
- within six months of the date it is published in the Gazette: Effective date of the Rule and Statement of Guidance on Internal Controls for Regulated Entities