Rule
Rule on Operational Risk Management for Banks
Status not confirmedView on CIMA's website Source document
Summary
This is a CIMA regulatory Rule, dated 12 May 2008, setting out mandatory requirements for operational risk management at banks regulated under the Banks and Trust Companies Law (2007 Revision). It was issued under section 34 of the Monetary Authority Law (2004 Revision) and is meant to be read alongside CIMA's related Statement of Guidance on Operational Risk Management for banks.
- General requirement: Every bank must establish, implement and maintain strategies, policies and processes to identify, assess, monitor and mitigate operational risk, scaled to the size, complexity and nature of the bank's activities.
- Board responsibilities: The Board of directors must approve these strategies, policies and processes, oversee their effective implementation, and periodically review them.
Breaches of the Rule will be dealt with under CIMA's Enforcement Manual policies and procedures, in addition to any other powers available to CIMA under the Banks and Trust Companies Law and the Monetary Authority Law. No transition period, effective date beyond the document date, or filing deadlines are specified in the text.
Key obligations
- A bank must establish, implement, and maintain strategies, policies, and processes to identify, assess, monitor, and mitigate operational risk appropriate for the size, complexity, and nature of its activities.
- A bank's Board of directors must approve the operational risk strategies, policies, and processes.
- A bank's Board of directors must oversee management of these policies and processes to ensure effective implementation.
- A bank's Board of directors must periodically review these strategies, policies, and processes.
Applies to
banks