The Basel Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector.
This chapter sets out the foreword to the Core Principles.
The Core Principles for effective banking supervision (Core Principles) are the de facto minimum standard for sound prudential regulation and supervision of banks and banking systems. The Core Principles are considered universally applicable and should be applied by national authorities in the supervision of banks within their jurisdictions.
The Committee issues the Core Principles as its contribution to strengthening the global financial system. Weaknesses in the banking system of a country, whether developing or developed, can threaten financial stability both within that country and internationally. The Committee believes that implementation of the Core Principles by all countries would be a significant step towards improving financial stability domestically and internationally and that it would provide a good basis for further development of effective supervisory systems. The vast majority of countries have endorsed the Core Principles and have committed to fully implement them.
The Core Principles are used by countries as a benchmark to assess the effectiveness of their supervisory systems, to identify future work to achieve a baseline level of sound supervisory practices and to upgrade supervisory systems and practices (as appropriate) in line with the evolution of their respective banking systems. They are also used by the International Monetary Fund (IMF) and the World Bank in the context of the Financial Sector Assessment Program (FSAP) to assess the effectiveness of countries' banking supervisory systems and practices.
Each iteration of the Core Principles builds upon the preceding versions and seeks to achieve the right balance in raising the bar for sound supervision while retaining the Core Principles as a flexible, globally applicable standard. To ensure the universal applicability of the Core Principles, reviews are conducted by a group composed of both Committee and non-Committee member countries and regional groups of banking supervisors, as well as the IMF and World Bank. The Committee also consults with industry and the public before finalising revisions to the standard.
Given the importance of consistent and effective standards implementation, the Committee is ready to encourage work at the national level to implement the Core Principles in conjunction with other supervisory bodies and interested parties. The Committee invites international financial institutions and donor agencies to use the Core Principles to assist individual countries to strengthen their supervisory arrangements. The Committee also remains committed to further enhancing its interaction with supervisors from non-member countries.
This chapter outlines the objectives of the Core Principles and describes how to read the standard.
The Core Principles are conceived as a framework of minimum standards for sound supervisory practices. The Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector. They set out the powers that supervisors should have to address safety and soundness concerns, promote a forward-looking and risk-based approach to supervision, and encourage early intervention and timely supervisory actions to mitigate threats to the safety and soundness of banks and the banking system.1
| 1 | National authorities are free to implement any supplementary measures that may be needed to achieve effective supervision in their jurisdictions. |
The Core Principles are considered universally applicable, irrespective of the complexity of banks and banking systems, and should be applied by national authorities in the supervision of banking organisations within their jurisdictions.2 A high degree of compliance with the Core Principles should foster overall financial system stability; however, banking supervision cannot, and should not, provide an assurance that banks will not fail.
| 2 | In countries where non-bank financial institutions provide deposit and lending services similar to those of banks, many of the principles set out in this document would also be appropriate to apply to such non-bank financial institutions. Some of these institutions may be regulated differently from banks, as long as they do not collectively hold a significant proportion of the deposits in a financial system. |
The Core Principles standard is structured as follows:
The banking sector is only one, albeit important, part of a financial system. The Committee has sought to maintain consistency, where possible, between these Core Principles and, for example, the corresponding standards for securities and insurance, as well as the standards for anti-money laundering (AML) and combatting the financing of terrorism (CFT) and transparency. Differences will inevitably remain, however, as key risk areas and supervisory priorities differ from sector to sector.
At a minimum, the Committee expects its members to fully implement the Basel Framework for their internationally active banks. The Core Principles are also a Basel standard, but they are applicable to all banks in all jurisdictions.
Each Core Principle applies to the supervision of all banks and banking groups. The intensity of supervision will need to be commensurate with the risk profile and systemic importance of banks.
In supervising an individual bank which is part of a corporate group, it is essential that supervisors consider the bank and its risk profile from a number of perspectives: on a solo basis (but with both a micro and macro focus); on a consolidated basis (in the sense of supervising the bank as a unit together with the other entities within the "banking group") and on a group-wide basis (taking into account the potential risks to the bank posed by other group entities outside of the banking group). Group entities (whether inside or outside the banking group) may be a source of strength but they may also be a source of weakness capable of adversely affecting the financial condition, reputation and overall safety and soundness of the bank. Supervisors should carefully consider the risks posed to a bank where it is part of a group or financial conglomerate with a mix of regulated and unregulated entities across different sectors. In the discharge of their functions, supervisors must observe a broad canvas of risk, whether arising from an individual bank, from its associated entities (regulated or not) or from the prevailing macro-financial environment.
Banks will from time to time run into difficulties, so effective crisis preparation and management and orderly resolution frameworks and measures are required to minimise the adverse impact on the broader banking and financial sectors. These include measures to be adopted by banks, such as recovery plans, and those to be adopted by supervisory, resolution and other authorities to coordinate the orderly restructuring or resolution of a troubled bank. Compliance with the Core Principles does not require the supervisory authority to also be the resolution authority.
The concept of proportionality ensures that applicable rules and supervision practices are consistent with banks' systemic importance and risk profiles, as well as appropriate for the broader characteristics of a particular financial system. The objective of proportionality is not to dilute the robustness of standards but to reflect jurisdictions' circumstances and supervisory capacity.3
| 3 | For further information on practical considerations in implementing proportionality, see the Committee’s High-level considerations on proportionality (July 2022) and Guidance on the application of the Core Principles for effective banking supervision to the regulation and supervision of institutions relevant to financial inclusion (September 2016). |
The Core Principles recognise that the appropriate intensity of supervision for banks varies, with more time and resources devoted to larger, more complex or riskier banks. Supervisors should assess the risk profile of banks in terms of the risks they run, the efficacy of their governance and risk management, and the risks they pose to banking and financial systems. This process focuses supervisory resources where they can be utilised optimally, concentrating on outcomes and moving beyond passive assessment of compliance with rules.
To fulfil their purpose, the Core Principles must be capable of application to a wide range of jurisdictions, whose banking sectors may include a broad spectrum of banks (from large internationally active banks to small, non-complex deposit-taking institutions). To accommodate this breadth of application, a proportionate approach is adopted, both in terms of expectations of supervisors in the discharge of their own functions and in terms of the requirements that supervisors impose on banks. The concept of proportionality underpins the assessment and implementation of the Core Principles, even if it is not always directly referenced.
While all banks must observe minimum capital and liquidity standards, and establish effective governance and risk management frameworks and practices, the principle of proportionality allows supervisors to better match the level of regulatory and supervisory requirements to different banks and banking systems. In the context of the Core Principles, this is reflected in the expectation that requirements imposed by supervisors on banks will be commensurate with the risk profile and systemic importance (including, but not limited to, size and complexity) of banks.
The Core Principles allow for different approaches to supervision, as long as the overriding goals are achieved. Specific country circumstances and the context in which supervisory practices are applied should be considered during implementation and assessments, and in the dialogue between assessors and country authorities.
The revised Core Principles reflect regulatory and supervisory developments, structural changes in banking, and lessons learnt in FSAP assessments since the last revision in 2012. The current review has been informed by several thematic topics: (i) financial risks; (ii) operational resilience; (iii) systemic risk and macroprudential supervision; (iv) new risks, such as climate-related financial risks and the digitalisation of finance; (v) non-bank financial intermediation; and (vi) risk management practices.
The post-Great Financial Crisis (GFC) period has seen banks continue to build their resilience to financial risks, underpinned by stronger regulatory and supervisory frameworks, including the Basel III standards. The Core Principles have been strengthened to reflect key elements of many of the post-GFC reforms introduced by the Committee. In particular, the importance of a non-risk-based measure to complement risk-based approaches in constraining leverage in banks and the banking system (eg a leverage ratio); enhancements to credit risk management practices; the introduction of expected credit loss approaches to provisioning; and more stringent requirements for managing large exposures and related party transactions. More recent crises, such as the Covid-19 pandemic and episodes of bank distress, have reinforced the importance of bank and banking system resilience to a range of different shocks, as well as the need for effective supervision.
Beyond financial risks, significant efforts have been directed at strengthening operational resilience to ensure that banks are better able to withstand, adapt to and recover from severe operational risk-related events, such as pandemics, cyber incidents, technology failures and natural disasters. The Core Principles enhance the focus on governance, operational risk management, business continuity planning and testing, the mapping of interconnections and interdependencies, third-party dependency management, incident management, and resilient cyber security and information and communication technology (ICT).
The last 10 years have reaffirmed the importance of applying a system-wide macro perspective to the supervision of banks to assist in identifying and analysing systemic risks and taking pre-emptive action to address them. Adopting a broad financial system perspective is integral to many of the Core Principles, and so the Committee has not included a specific standalone principle on macroprudential issues but has sought to strengthen the existing requirements based on lessons learnt. This includes the value of capital buffers that can be increased or released as risks build and crystallise or dissipate (eg a countercyclical capital buffer).
Climate change may result in physical and transition risks that could affect the safety and soundness of individual banks and have broader implications for the banking system and financial stability. Targeted changes have been introduced to explicitly reference climate-related financial risks and to promote a principles-based approach to improving supervisory practices and banks' risk management. Banks should understand how climate-related risk drivers may manifest through financial risks, recognise that these risks could materialise over varying time horizons (which may go beyond their traditional capital planning horizon), and implement appropriate measures to mitigate these risks. Supervisors are also expected to consider climate-related financial risks in their supervision of banks, to assess banks' risk management processes, and to require banks to submit information that makes it possible to assess the materiality of climate-related financial risks. Both bank and supervisory practices may consider climate-related financial risks in a flexible manner, given the degree of heterogeneity and evolving practices in this area.
Technology-driven innovation and the digitalisation of finance are changing both customer behaviours and the way that banking services are provided. New products, new entrants and the use of new technologies present both opportunities and risks for supervisors, banks and the banking system. Digitalisation may amplify traditional risks (eg liquidity, operational and strategic risks), while digital communication channels can more rapidly propagate banking stress. Banks are also increasingly relying on third parties for the provision of technology services, which creates additional points of cyber risk as well as potential system-wide concentrations and further highlights the importance of operational resilience. For supervision to remain effective, supervisors need to ensure that they can continue to access relevant information (irrespective of where records are located) and review the overall activities of the banking group, including those undertaken by third parties that are supporting critical operations of banks.
Financial intermediation has evolved significantly since the last revision of the Core Principles, prompted by rapid advances in financial technology and the proliferation of non-bank financial intermediation. Non-bank financial institutions supplement banks in providing financial services, but their activities can also affect the stability of the financial system and increase the potential for contagion risks through their interconnections with banks. While the Core Principles are designed to apply to those institutions designated as banks, supervisors should remain alert to the risks arising from non-bank financial institution activities and their potential impact on the banking system. The revised Core Principles reinforce the group-wide approach to supervision and strengthen requirements for supervisors to monitor risks to banks from the range of different non-bank financial institutions and for banks to manage their counterparty risks.
Reflecting evolving risks and broader medium- and long-term trends, it is critical that banks institute a sound risk culture, maintain strong risk management practices and adopt and implement sustainable business models. The concept of bank business model sustainability reflects the expectation that banks design and implement sound and forward-looking strategies that generate sustainable returns over time. Both bank risk management and supervisory approaches have been strengthened in this respect. While responsibility for designing and implementing sustainable business strategies lies with a bank's board, supervisors have an important role to play, as assessing the robustness of banks' risk culture and business models is a key component of effective supervision.
This chapter provides an explanation of certain key terms that are used throughout the Core Principles.
This section provides an explanation of certain key terms that are used throughout the Core Principles. These explanations should be read only in the context of this document, and they do not apply across, or modify any aspect of, the Basel Framework.
| 4 | While branches are not considered intragroup providers as they are not separate legal entities, it may also be appropriate to consider risks arising from the provision of services from a head office to its overseas branches, or between branches. |
This chapter describes the assessment methodology.
The Core Principles are intended mainly to help countries assess the quality of their systems and to provide input into their reform agenda. Assessing a country's compliance with the Core Principles is a useful tool for promoting the implementation of an effective system of banking supervision. To promote objectivity and comparability of compliance with the Core Principles in the different country assessments,5 supervisors and assessors should refer to this assessment methodology, which does not eliminate the need for both parties to use their judgment in assessing compliance. Such an assessment should identify weaknesses in the existing system of supervision and regulation, and form a basis for remedial measures by government authorities and banking supervisors.
| 5 | Ranking supervisory systems is not one of the aims of the assessments. |
While the publication of the assessments of jurisdictions affords transparency, an assessment of one jurisdiction will not be directly comparable with that of another. First, assessments have to reflect proportionality. Thus, a jurisdiction that is home to many systemically important banks will naturally have a higher hurdle to clear to obtain a "compliant" grading than a jurisdiction which only has small, non-complex deposit-taking institutions. Second, jurisdictions can elect to be graded against essential criteria only or against both essential criteria and additional criteria. Third, assessments will inevitably be country-specific and time-dependent to varying degrees. Therefore, the description provided for each Core Principle and the qualitative commentary accompanying the grading for each Core Principle should be reviewed to gain an understanding of a jurisdiction's approach to the specific component under consideration and the need for any improvements. Seeking to compare countries by simply referring to the number of "compliant" and "non-Compliant" grades they receive is unlikely to be informative.
From a broader perspective, effective banking supervision is dependent on a number of external elements, or preconditions, which may not be within the direct jurisdiction of supervisors. The review of the preconditions is qualitative and distinct from the assessment (and grading) of compliance with the Core Principles.
The assessment methodology can be used in multiple contexts:
| 6 | The regular reports by the IMF and the World Bank on the lessons learnt from assessment experiences as part of FSAP exercises constitute a useful source of information, which has been used to improve the Core Principles. |
Whatever the context, the following factors are crucial:
The primary objective of an assessment is to identify the nature and extent of any weaknesses in banking supervision. While the process of implementing the Core Principles starts with the assessment of compliance, assessment is a means to an end, not an objective in itself. The assessment allows the supervisory authority (and in some instances the government) to initiate a strategy to improve the banking supervisory system, as necessary.
The assessment methodology for the Core Principles includes both essential and additional assessment criteria:
Countries undergoing assessment by the IMF and/or the World Bank have the following three assessment options:
For assessments of the Core Principles by external parties,7 the following four-grade scale will be used. A "not applicable" grading can be used under certain circumstances as described in BCP20.10.
| 7 | While gradings of self-assessments may provide useful information to the authorities, these are not mandatory, as the assessors will arrive at their own independent judgment. |
| 8 | For the purpose of grading, references to the term “essential criteria” in this paragraph would include additional criteria in the case of a country that has volunteered to be assessed and graded against the additional criteria. |
In addition, a principle will be considered "not applicable" if, in the view of the assessor, the principle does not apply given the structural, legal and institutional features of the country. In some instances, countries have argued that in the case of certain embryonic or immaterial banking activities, which were not being supervised, an assessment of "not applicable" should have been given, rather than "non-compliant". This is an issue for judgment by the assessor, although activities that are relatively insignificant at the time of assessment may later assume greater importance and authorities need to be aware of and prepared for such developments. The supervisory system should permit such activities to be monitored, even if no regulation or supervision is considered immediately necessary. "Not applicable" would be an appropriate assessment if the supervisors are aware of the phenomenon and capable of taking action, but there is realistically no chance that the activities will grow sufficiently in volume to pose a risk.
Grading is not an exact science, and the Core Principles can be met in different ways. The assessment criteria should not be seen as a checklist approach to compliance but as a qualitative exercise. Compliance with some criteria may be more critical for effective supervision, depending on the situation and circumstances in a given jurisdiction. Hence, the number of criteria complied with is not always an indication of the overall compliance rating for any given principle. Emphasis should be placed on the commentary that should accompany each principle's grading, rather than on the grading itself. The primary goal of the exercise is not to apply a "grade" but rather to direct authorities towards areas needing attention to set the stage for improvements and develop an action plan that prioritises the improvements needed to achieve full compliance with the Core Principles.
The assessment should also include the assessors' opinion of how weaknesses in the preconditions for effective banking supervision, as discussed in BCP30, hinder effective supervision and of how effectively supervisory measures mitigate these weaknesses. In particular, the assessment of compliance with individual Core Principles should clearly mention how compliance is likely to be primarily affected by preconditions that are considered to be weak. This opinion should be qualitative rather than providing any kind of graded assessment. To the extent that shortcomings in preconditions are material to the effectiveness of supervision, they may affect the grading of the affected Core Principles.
While the Committee does not provide detailed guidelines on the preparation and presentation of assessment reports, it believes there are a few considerations that assessors should consider when conducting an assessment and preparing the assessment report.9
When conducting an assessment, the assessor must have free access to a range of information and interested parties. The required information may include not only published information, such as the relevant laws, regulations and policies, but also more sensitive information, such as any self-assessments, operational guidelines for supervisors and, where possible, supervisory assessments of individual banks. This information should be provided as long as it does not violate supervisors' legal obligations to keep such information confidential. Experience from assessments has shown that secrecy issues can often be solved through ad hoc arrangements between the assessor and the assessed authority. The assessor will need to meet a range of individuals and organisations, including the banking supervisory authority or authorities, other domestic supervisory authorities, any relevant government ministries, bankers and bankers' associations, auditors and other financial sector participants. Special note should be made of instances when required information is not provided and of the impact this might have on the accuracy of the assessment.
The assessment of compliance with each principle requires the evaluation of a chain of related requirements which, depending on the principle, may encompass laws, prudential regulations, supervisory guidelines, on-site examinations and off-site analyses, supervisory reporting and public disclosures, and evidence of enforcement or non-enforcement. The assessment must ensure that the requirements are put into practice, which entails assessing whether the supervisory authority has the necessary operational autonomy, skills, resources and commitment to implement the Core Principles. The assessment must confirm that the supervisor has the relevant powers and exercises them, where appropriate.10
| 10 | The Core Principles require that the supervisor has adequate powers and that these powers are exercised through the appropriate supervisory tools. For example, Principle 1, essential criterion 6 requires that the supervisor has the power to take timely corrective action or to impose a range of sanctions when, in its judgment, a bank is not complying with laws or regulations, while Principle 11 refers to the supervisor acting to take timely corrective action or to impose sanctions expeditiously. |
It is important to bear in mind that some tasks, such as assessing the macroeconomic environment and detecting the build-up of dangerous trends, do not lend themselves to a rigid compliant/non-compliant structure. Although these tasks may be difficult to undertake, supervisors should aim for assessments that are as accurate as possible given the information available at the time and take reasonable actions to address and mitigate such risks.
Assessments should not focus solely on deficiencies but should also highlight specific achievements. This approach will provide a better picture of the effectiveness of banking supervision.
There are certain jurisdictions where non-bank financial institutions that are not part of a supervised banking group engage in some bank-like activities. These institutions may make up a significant portion of the total financial system and may be largely unsupervised. Since the Core Principles deal specifically with banking supervision, they cannot be used for formal assessments of these institutions. However, the assessment report should, at a minimum, mention any activities in which non-bank financial intermediation has an impact on supervised banks and the potential problems that may arise as a result of such activities.
The development of cross-border banking leads to increased complications when conducting Core Principles assessments. Improved cooperation and information-sharing between home and host country supervisors is of central importance, both in normal times and in crisis situations. The assessor must therefore determine whether such cooperation and information-sharing actually takes place to the extent needed, bearing in mind the size and complexity of the banking links between the two countries.
For the purposes of assessing risk management by banks in the context of Principles 15 to 25, a bank's risk management framework should take an integrated bank-wide perspective of its risk exposure, encompassing individual business lines and business units. Where a bank is a member of a group, the risk management framework should also cover the risk exposure across and within the banking group and take account of risks posed to the bank or banking group by other entities in the wider group.
Assessment of Principle 29 (Abuse of financial services) will, for some countries, involve a degree of duplication with the mutual evaluation process of the Financial Action Task Force (FATF). To address this overlap, where an evaluation has recently been conducted by the FATF on a given country, FSAP assessors may rely on that evaluation and focus their own review on the actions taken by supervisors to address any shortcomings identified by the FATF. In the absence of any recent FATF evaluation, FSAP assessors should continue to assess countries' supervision of banks' AML/CFT controls.
This chapter describes the preconditions for effective banking supervision.
An effective system of banking supervision needs to be able to effectively develop, implement, monitor and enforce supervisory policies under normal and stressed economic and financial conditions. Supervisors need to be able to respond to external conditions that can negatively affect banks or the banking system. There are a number of elements or preconditions that have a direct impact on the effectiveness of supervision in practice. These preconditions are mostly outside the direct or sole jurisdiction of banking supervisors. Where supervisors have concerns that the preconditions could impact the efficiency or effectiveness of bank regulation and supervision, supervisors should make the government and relevant authorities aware of this and the actual or potential negative repercussions for supervisory objectives. Supervisors should work with the government and relevant authorities to address concerns that are outside the direct or sole jurisdiction of the supervisors. Supervisors should also, as part of their normal business, adopt measures to address the effects of such concerns on the efficiency or effectiveness of bank regulation and supervision.
The preconditions include:
Sound macroeconomic policies (mainly fiscal and monetary policies) are the foundation of a stable financial system. Without sound policies, imbalances such as high government borrowing and spending or an excessive shortage or supply of liquidity may arise and affect the stability of the financial system. Furthermore, certain government policies11 may specifically use banks and other financial intermediaries as instruments, which may inhibit effective supervision.
| 11 | Examples of such policies include accumulation of large quantities of government securities; reduced access to capital markets due to government controls or growing imbalances; degradation in asset quality due to loose monetary policies; and government-directed lending or forbearance requirements as an economic policy response to deteriorating economic conditions. |
In view of the interplay between the real economy and banks and the financial system, it is important that there is a clear framework for macroprudential surveillance and financial stability policy formulation. Such a framework should set out the authorities or those responsible for identifying systemic and emerging risks in the financial system; for monitoring and analysing market and other financial and economic factors that may lead to accumulation of systemic risks; for formulating and implementing appropriate policies; and for assessing how such policies may affect the banks and the financial system. It should also include mechanisms for effective cooperation and coordination among the relevant agencies.
Inadequacies in public infrastructure can contribute to the weakening of financial systems and markets or make it difficult to improve them. A well developed public infrastructure needs to comprise the following elements:
Effective crisis management frameworks and resolution regimes help to minimise potential disruptions to financial stability arising from banks and financial institutions that are in distress or failing. A sound institutional framework for crisis management and resolution requires a clear mandate and an effective legal basis for each relevant authority (such as banking supervisors, national resolution authorities, finance ministries and central banks). The relevant authorities should have a broad range of powers and appropriate tools set out in law to resolve a financial institution that is no longer viable and that has no reasonable prospect of becoming viable. There should also be agreement among the relevant authorities on their individual and joint responsibilities for crisis management and resolution, and how they will discharge these responsibilities in a coordinated manner. This should include the ability to share confidential information with each other to facilitate planning in advance to handle recovery and resolution situations and to manage such events when they occur.
Deciding on the appropriate level of systemic protection is a policy question to be addressed by the relevant authorities, including the government and central bank, particularly where it may result in a commitment of public funds. Supervisors will have an important role to play because of their in-depth knowledge of the financial institutions involved. In handling systemic issues, it is necessary to address the risks to confidence in the financial system and of contagion to otherwise sound institutions while minimising the distortion to market signals and discipline. A key element of the framework for systemic protection is a system of deposit insurance. Provided that such a system is transparent and carefully designed, it can contribute to public confidence in the system and thus limit contagion from banks in distress.
Effective market discipline depends in part on adequate flows of information to market participants, appropriate financial incentives to reward well managed institutions and arrangements that ensure that investors are not insulated from the consequences of their decisions. The issues to be addressed include corporate governance and ensuring that accurate, meaningful, transparent and timely information is provided by borrowers to investors and creditors. Market signals can be distorted and discipline undermined if governments seek to influence or override commercial decisions, particularly lending decisions, to achieve public policy objectives. In these circumstances, it is important that, if governments or their related entities provide or guarantee the lending, such arrangements are disclosed and there is a formal process for compensating financial institutions when such loans cease to perform.
This chapter describes the criteria for assessing compliance with the Core Principles.
The Core Principles establish 29 principles that are needed for a supervisory system to be effective and can be categorised into two groups:
This chapter lists the assessment criteria for each of the 29 Core Principles under two separate headings: "essential criteria" and "additional criteria".
The individual assessment criteria are based on international standards and sound supervisory practices that are already established, even if they have not yet been fully implemented. Where appropriate, the documents on which the criteria are founded have been cited as "reference documents". These documents include more detailed explanations of supervisory expectations and practices. There is the expectation that guidelines issued by the Committee will be observed by Committee member jurisdictions.
Principle 1:12 An effective system of banking supervision has clear responsibilities and objectives for each authority involved in the supervision of banks and banking groups. A suitable legal framework for banking supervision is in place to provide each responsible authority with the necessary legal powers to authorise banks, conduct ongoing supervision, address compliance with laws and undertake timely corrective actions to address safety and soundness concerns.
| 12 | Reference documents: BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Report on the impact and accountability of banking supervision, July 2015; BCBS, Principles for the supervision of financial conglomerates, September 2012; SCO40. |
Essential criteria:
| 13 | If countries have shared or transferred prudential tasks to a supranational supervisor, the roles and responsibilities that have been shared or transferred are clearly set out in law and publicly disclosed. Any residual powers or responsibilities that are retained must be publicly disclosed so that there is clarity on the division of responsibility. |
| 14 | For this purpose, “access” includes supervisory access in person to the bank’s premises, and to senior executive staff and the board (both individual members and as a whole) in person or virtually as needed. |
Principle 2:15 The supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy, and adequate resources, and is accountable for the discharge of its duties and use of its resources. The legal framework for banking supervision includes legal protection for the supervisor.
| 15 | Reference document: BCBS, Report on the impact and accountability of banking supervision, July 2015. |
Essential criteria:
| 16 | The term “supervisor and its staff” is to be understood as covering the head of the authority, the governing body, employees and any professional service providers who carry out tasks for the supervisory authority. As the protection is provided in respect of actions taken and/or omissions made while discharging duties in good faith, it is not removed when the term of appointment, engagement or employment is ended. |
Principle 3: Laws, regulations or other arrangements provide a framework for cooperation and collaboration with relevant domestic authorities and foreign supervisors. These arrangements reflect the need to protect confidential information.17
Essential criteria:
Principle 4: The permissible activities of institutions that are licensed and subject to supervision as banks are clearly defined, and the use of the word "bank" in names is controlled.
Essential criteria:
| 18 | The Committee recognises the existence of non-bank financial institutions that take deposits but may be regulated differently from banks. These institutions should be subject to a form of regulation commensurate to the type and size of their business and, collectively, should not hold a significant proportion of deposits in the financial system. |
Principle 5:19 The licensing authority has the power to set criteria for licensing banks and to reject applications where the criteria are not met. At a minimum, the licensing process consists of an assessment of the ownership structure and governance (including the fitness and propriety of board members and senior management) of the bank and its wider group, its strategic and operating plan, internal controls, risk management and projected financial condition (including capital base). Where the proposed owner or parent organisation is a foreign bank, the prior consent of its home supervisor is obtained.
| 19 | Reference documents: BCBS, Corporate governance principles for banks, July 2015; BCBS, Shell banks and booking offices, January 2003. |
Essential criteria:
Principle 6:23 The supervisor24 has the power to review, reject and impose prudential conditions on any proposals to transfer significant ownership or controlling interests held directly or indirectly in existing banks to other parties.
| 23 | Reference documents: BCBS, Parallel-owned banking structures, January 2003; BCBS, Shell banks and booking offices, January 2003. |
| 24 | While the term “supervisor” is used throughout Principle 6, the Committee recognises that in a few countries these issues might be addressed by a separate licensing authority. |
Essential criteria:
Principle 7: The supervisor has the power to: (i) approve or reject (or recommend to the responsible authority the approval or rejection of) and impose prudential conditions on major acquisitions or investments by a bank (including the establishment of cross-border operations), against prescribed criteria; and (ii) determine that corporate affiliations or structures do not expose the bank to undue risks or hinder effective supervision.
Essential criteria:
| 25 | The supervisor may consider whether the acquisition or investment creates obstacles to the orderly resolution of the bank. |
Principle 8:26 An effective system of banking supervision requires the supervisor to develop and maintain a forward-looking assessment of the risk profile of individual banks, proportionate to their systemic importance; identify, assess and address risks emanating from banks and the banking system as a whole; have a framework in place for early intervention; and have plans in place, in partnership with other relevant authorities, to take action to resolve banks in an orderly manner if they become non-viable.
| 26 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Frameworks for early supervisory intervention, March 2018; BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Guidelines for identifying and dealing with weak banks, July 2015; SRP10, SRP20, SCO50. |
Essential criteria:
The methodology and processes address (among other things): banks' group structure (including risks posed by entities in the wider group); risks around banks' business models, including business model sustainability;27 banks' risk profile with a forward-looking view;28 their internal control environment; and their resolvability. The methodology permits relevant comparisons between banks, and the nature, frequency and intensity of supervision reflect the outcome of this analysis.
Principle 9:29 The supervisor uses an appropriate range of techniques and tools to implement the supervisory approach and deploys supervisory resources on a proportionate basis, considering the risk profile and systemic importance of banks.
| 29 | Reference document: BCBS, High-level considerations on proportionality, July 2022. |
Essential criteria:
Additional criterion:
Principle 10:31 The supervisor collects, reviews and analyses prudential reports and statistical returns32 from banks on both a solo and a consolidated basis, and independently verifies these reports through either on-site examinations or use of external experts.
| 31 | Reference documents: BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Sound Practices: implications of fintech developments for banks and bank supervisors, February 2018; BCBS, Principles for effective risk data aggregation and risk reporting, January 2013; BCBS, Principles for the supervision of financial conglomerates, September 2012. |
| 32 | In the context of this principle, “prudential reports and statistical returns” are distinct from and required in addition to mandatory accounting reports. The former are addressed by this principle, and the latter are addressed in Principle 27 BCP40.61. |
Essential criteria:
Principle 11:33 The supervisor acts at an early stage to address unsafe and unsound practices or activities that could pose risks to banks or to the banking system. The supervisor has at its disposal an adequate range of supervisory tools, that it can apply at its discretion, to bring about timely corrective actions. This includes the ability to revoke the banking licence or to recommend its revocation.
| 33 | Reference document: BCBS, Parallel-owned banking structures, January 2003. |
Essential criteria:
Principle 12:35 The supervisor supervises the banking group on a consolidated basis, adequately monitoring and, as appropriate, applying prudential standards to all aspects of the business conducted by the banking group worldwide.
| 35 | Reference documents: BCBS, Principles for the supervision of financial conglomerates, September 2012; BCBS, Home-host information sharing for effective Basel II implementation, June 2006; BCBS, The supervision of cross-border banking, October 1996; BCBS, Principles for the supervision of banks’ foreign establishments, May 1983; BCBS, Consolidated supervision of banks’ international activities, March 1979; SCO10. |
Essential criteria:
Additional criterion:
Principle 13:37 Home and host supervisors of cross-border banking groups share information and cooperate for effective supervision of the group and group entities, and effective handling of crisis situations. Supervisors require the local operations of foreign banks to be conducted to the same standards as those required of domestic banks.
| 37 | Reference documents: Financial Stability Board (FSB), Key attributes of effective resolution regimes for financial institutions, October 2014; BCBS, Principles for effective supervisory colleges, June 2014; BCBS, Home-host information sharing for effective Basel II implementation, June 2006; BCBS, High-level principles for the cross-border implementation of the New Accord, August 2003; BCBS, Shell banks and booking offices, January 2003; BCBS, The supervision of cross-border banking, October 1996; BCBS, Information flows between banking supervisory authorities, April 1990; BCBS, Principles for the supervision of banks’ foreign establishments, May 1983. |
Essential criteria:
Principle 14:38 The supervisor determines that banks have robust corporate governance policies and processes covering, for example, corporate culture and values, strategic direction and oversight, group and organisational structure, the control environment, the suitability assessment process, the responsibilities of the banks' boards and senior management, and compensation practices. These policies and processes are commensurate with the risk profile and systemic importance of the bank.
| 38 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; FSB, Strengthening governance frameworks to mitigate misconduct risk: a toolkit for firms and supervisors, April 2018; FSB, Supplementary Guidance to the FSB Principles and Standards on Sound Compensation Practices, March 2018; BCBS, Corporate governance principles for banks, July 2015; FSB, Guidance on supervisory interaction with financial institutions on risk culture: a framework for assessing risk culture, April 2014; FSB, Principles for Sound Compensation Practices, April 2009. |
Essential criteria:
| 39 | Independent director refers to a non-executive member of the board who does not have any management responsibilities within the bank and is not under any other undue influence, internal or external, political or ownership, that would impede the board member’s exercise of objective judgment. |
| 40 | The Committee defines: (i) “duty of care” as the duty of board members to decide and act on an informed and prudent basis with respect to the bank. This is often interpreted as requiring board members to approach the affairs of the company the same way that a “prudent person” would approach his or her own affairs; and (ii) “duty of loyalty” as the duty of board members to act in good faith in the interest of the company. The duty of loyalty should prevent individual board members from acting in their own interest, or the interest of another individual or group, at the expense of the company and shareholders. |
| 41 | This includes whistleblowing policies and procedures that protect employees from reprisals or other detrimental treatment. |
Principle 15:42 The supervisor determines that banks have a comprehensive risk management process (including effective board and senior management oversight) to identify, measure, evaluate, monitor, report and control or mitigate all material risks43 (which can include risks related to digitalisation, climate-related financial risks and emerging risks) on a timely basis and to assess the adequacy of their capital, their liquidity and the sustainability of their business models in relation to their risk profile and market and macroeconomic conditions. This extends to the development and review of contingency arrangements (including robust and credible recovery plans where warranted) that consider the specific circumstances of the bank. The risk management process is commensurate with the risk profile and systemic importance of the bank.44
Essential criteria:
| 45 | This includes, where relevant, risks not directly addressed in the subsequent principles, such as reputational, step-in and strategic risks. |
| 46 | Banks should include climate-related financial risks assessed as material over relevant time horizons, including in their stress testing programmes where appropriate. |
| 47 | New products include those developed by the bank or by a third party and purchased or distributed by the bank. |
Principle 16:48 The supervisor sets prudent and appropriate capital adequacy requirements for banks that reflect the risks undertaken and presented by a bank in the context of the markets and macroeconomic conditions in which it operates.49 The supervisor defines the components of capital, bearing in mind their ability to absorb losses. At least for internationally active banks, capital requirements are not less stringent than the applicable Basel standards.
| 48 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Guiding principles for the operationalisation of a sectoral countercyclical capital buffer, November 2019; SCO10, SCO30, CAP10, CAP30, CAP50, CAP99, RBC20, RBC30, RBC40, LEV10, LEV20, LEV30, SRP10, SRP20. |
| 49 | Implementation of the Basel Framework is not a prerequisite for compliance with the Core Principles. Compliance with the Basel Framework capital adequacy regimes is only required of those jurisdictions that have declared that they have voluntarily implemented it. |
Essential criteria:
| 50 | Capital adequacy requirements for internationally active banks should be applied on a fully consolidated basis, including any holding company that is the parent entity within a banking group. The framework will apply to all internationally active banks at every tier within a banking group, on a fully consolidated basis. As an alternative to full sub-consolidation, the application of this framework to the standalone bank (ie on a basis that does not consolidate assets and liabilities of subsidiaries) would achieve the same objective, providing the full book value of any investments in subsidiaries and significant minority-owned stakes is deducted from the bank’s capital. Supervisors must also test that individual banks are adequately capitalised on a standalone basis. |
Additional criteria:
Principle 17:52 The supervisor determines that banks have an adequate credit risk management process that considers their risk appetite, risk profile, market conditions, macroeconomic factors and forward-looking information. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate credit risk53 (including counterparty credit risk54) on a timely basis. The full credit life cycle is covered, including credit underwriting, credit evaluation and the ongoing management of the bank's loan and investment portfolios.
| 52 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Guidance on credit risk and accounting for expected credit losses, December 2015; FSB, Principles for sound residential mortgage underwriting practices, April 2012; CRE20, CRE40, CRE45, CRE50, CRE51, CRE54, MGN10, MGN20. |
| 53 | Credit risk may result from: on-balance sheet and off-balance sheet exposures, including loans and advances; investments; interbank lending; derivative transactions; securities financing transactions; and trading activities. |
| 54 | Transactions that give rise to counterparty credit risk include: OTC derivatives, exchange-traded derivatives, long settlement transactions and securities financing transactions that are bilaterally or centrally cleared. Counterparty credit risk may result from (but is not limited to) transactions with banks, non-financial corporates and non-bank financial institutions. |
Essential criteria:
approving new exposures (including prudent underwriting standards), and ensuring a thorough understanding of the risk profile and characteristics of the borrowers (and in the case of securitisation exposures all features of securitisation transactions)55 that would materially impact the performance of these exposures;
renewing and refinancing existing exposures; and
identifying the appropriate approval authority for the size and complexity of the exposures;
| 55 | Securitisation includes both traditional and synthetic securitisations (or similar structures that contain features common to both). Where appropriate, supervisors should provide guidance about whether a given transaction should be considered a securitisation. |
Principle 18:56 The supervisor determines that banks have adequate policies and processes for the early identification and management of problem exposures57 and the maintenance of adequate provisions58 and reserves.59
| 56 | Reference documents: BCBS, Prudential treatment of problem assets – definitions of non-performing exposures and forbearance, April 2017; BCBS, Guidance on credit risk and accounting for expected credit losses, December 2015. |
| 57 | For banks’ internal risk management purposes, a problem exposure is an exposure for which there is reason to believe that all amounts due, including the principal and interest, may not be collected in accordance with the contractual terms of the agreement with the counterparty. |
| 58 | Principle 18 covers all provisioning approaches (eg incurred loss models, expected credit loss models, calendar provisioning) that are used for prudential purposes. In some jurisdictions, cumulative provisions are referred to as loss allowances. |
| 59 | Reserves for the purposes of this principle are “below the line” non-distributable appropriations of profit required by a supervisor in addition to provisions (“above the line” charges to profit). |
Essential criteria:
| 60 | A forborne exposure is an exposure for which a bank’s counterparty is experiencing financial difficulty in meeting its financial commitments and the bank grants a concession that it would not otherwise consider. |
| 61 | Provisions are not limited to problem exposures. Depending on the relevant jurisdiction’s accounting and prudential frameworks, provisions may be required for a wider range of exposures (eg all exposures, including performing exposures, under expected credit loss frameworks). |
Principle 19:62 The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate concentrations of risk on a timely basis. Supervisors set prudential limits to restrict bank exposures to single counterparties or groups of connected counterparties.63 At least for internationally active banks, large exposure requirements are not less stringent than the applicable Basel standard.
| 62 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; Joint Forum, Cross-sectoral review of group-wide identification and management of risk concentrations, April 2008; BCBS, Principles for the management of credit risk, September 2000; LEX10, LEX20, LEX30, LEX40. |
| 63 | Connected counterparties may include natural persons as well as legal persons. Two or more natural or legal persons shall be deemed a group of connected counterparties if at least one of the following criteria is satisfied: (a) control relationship: one of the counterparties, directly or indirectly, has control over the other(s); or (b) economic interdependence: if one of the counterparties were to experience financial problems, the other(s), as a result, would also be likely to encounter financial difficulties. |
Essential criteria:
| 64 | Concentration risk may result from credit, market and other risk where a bank is overly exposed to particular asset classes, products, collateral, currencies or funding sources, and is broader than exposures subject to large exposure requirements. Credit concentrations include exposures to: single counterparties (including collateral credit protection and other commitments provided); groups of connected counterparties; counterparties in the same industry, economic sector or geographic region; and counterparties whose financial performance is dependent on the same activity or commodity. |
| 65 | The measure of credit exposure for large exposures should reflect the maximum possible loss from counterparty failure (ie it should encompass actual and potential exposures as well as contingent liabilities). The risk weighting concept adopted in the Basel Framework should not be used in measuring credit exposure for this purpose, as its use for measuring credit concentrations could significantly underestimate potential losses. |
Additional criterion:
Principle 20:66 To prevent abuses arising in transactions with related parties67 and to address the risk of conflicts of interest, the supervisor requires banks to: enter into any transactions with related parties on an arm's length basis;68 monitor these transactions; take appropriate steps to control or mitigate the risks; and write off exposures to related parties in accordance with standard policies and processes.
| 66 | Reference documents: BCBS, Corporate governance principles for banks, July 2015; BCBS, Principles for the management of credit risk, September 2000. |
| 67 | Related parties should include: (a)the bank’s subsidiaries and affiliates (including their subsidiaries, affiliates and special purpose entities) and any other party that the bank exerts control over or that exerts control over the bank; (b)the bank’s major shareholders, including beneficial owners; (c)the bank’s board members, senior management and key staff, corresponding persons in affiliated companies, and parties that can exert significant influence on board members or senior management; and (d)for the natural persons identified in (a) to (c), their direct and related interests and their close family members. |
| 68 | Related party transactions include on-balance sheet and off-balance sheet credit exposures; dealings such as service contracts, asset purchases and sales, construction contracts and lease agreements; derivative transactions; borrowings; and write-offs. The term “transaction” should be interpreted broadly to incorporate not only transactions that are entered into with related parties but also situations in which an unrelated party (with whom a bank has an existing exposure) subsequently becomes a related party. |
| 69 | Exceptions may be appropriate for certain transactions between entities within a banking group when the supervisor considers this to be consistent with sound group-wide risk management. An exception may also be appropriate for beneficial terms that are part of overall remuneration packages. |
| 70 | For this purpose, exposures should be calculated consistently with Principle 19 BCP40.43. |
| 71 | The supervisor may exclude banks’ exposures to certain entities within the banking group where the supervisor considers this to be consistent with sound group-wide risk management. |
Principle 21:72 The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate country risk73 and transfer risk74 in their international lending and investment activities on a timely basis.
| 72 | Reference documents: IMF, External debt statistics – guide for compilers and users, 2013; BCBS, Management of banks’ international lending: country risk analysis and country exposure measurement and control, March 1982. |
| 73 | Country risk is the risk of exposure to loss caused by events in a foreign country. The concept is broader than sovereign risk as all forms of lending or investment activity involving individuals, corporates, banks or governments are covered. |
| 74 | Transfer risk is the risk that a borrower will not be able to convert local currency into a foreign currency and so will be unable to make debt service payments in a foreign currency. The risk normally arises from exchange restrictions imposed by the government in the borrower’s country. |
Principle 22:75 The supervisor determines that banks have an adequate market risk management process that considers risk appetite, risk profile, market and macroeconomic conditions, and the risk of a significant deterioration in market liquidity. This includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate market risks on a timely basis.
Essential criteria:
Principle 23:76 The supervisor determines that banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book on a timely basis.77 These systems consider the bank's risk appetite, risk profile and market and macroeconomic conditions.
| 76 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; SRP31. |
| 77 | Wherever “interest rate risk” is used in this principle the term refers to interest rate risk in the banking book. Interest rate risk in the trading book is covered under Principle 22 BCP40.50. |
Essential criteria:
Principle 24:78 The supervisor sets prudent and appropriate liquidity requirements (which can include either quantitative or qualitative requirements or both) that reflect the liquidity needs of banks. The supervisor determines that banks have a strategy that enables prudent management of liquidity risk and compliance with liquidity requirements. The strategy considers the bank's risk profile, market and macroeconomic conditions, and includes prudent policies and processes, consistent with the bank's risk appetite, to identify, measure, evaluate, monitor, report and control or mitigate liquidity risk over an appropriate set of time horizons. At least for internationally active banks, liquidity (including funding) requirements are not lower than the applicable Basel standards.
Essential criteria:
Principle 25:79 The supervisor determines that banks have an adequate operational risk80 management framework and operational resilience81 approach that considers their risk profile, risk appetite, business environment, tolerance for disruption to their critical operations,82 and emerging risks. This includes prudent policies and processes to: (i) identify, assess, evaluate, monitor, report and control or mitigate operational risk on a timely basis; and (ii) identify and protect themselves from threats and potential failures, respond and adapt to, as well as recover and learn from, disruptive events to minimise their impact on delivering critical operations through disruption.
| 79 | Reference documents: FSB, Enhancing third-party risk management and oversight: a toolkit for financial institutions and financial authorities, December 2023; BCBS, High-level considerations on proportionality, July 2022; BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Revisions to the principles for the sound management of operational risk, March 2021; BCBS, Principles for operational resilience, March 2021; BCBS, Cyber resilience: range of practices, December 2018; BCBS, Sound practices implications of fintech developments for banks and bank supervisors, February 2018; FSB, Guidance on identification of critical functions and critical shared services, July 2013; BCBS, Recognising the risk-mitigating impact of insurance in operational risk modelling, October 2010; BCBS, High-level principles for business continuity, August 2006; BCBS, Outsourcing in financial services, February 2005. |
| 80 | Operational risk is the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. This definition includes legal risk but excludes strategic and reputational risk. |
| 81 | Operational resilience refers to the ability of the bank to deliver critical operations through disruption. Operational resilience is an outcome that benefits from the effective management of operational risk. |
| 82 | Tolerance for disruption is the level of disruption from any type of operational risk a bank is willing to accept given a range of severe but plausible scenarios. The term “critical operations” encompasses critical functions and includes activities, processes, services and their relevant supporting assets, the disruption of which would be material to the continued operation of the bank or its role in the financial system. Whether a particular operation is critical depends on the nature of the bank and its role in the financial system. |
Essential criteria:
| 83 | Including control functions, risk management and internal audit. |
| 84 | Information and communication technology refers to the underlying physical and logical design of information technology and communication systems, the individual hardware and software components, data and the operating environments. |
| 85 | These include cyber security, ICT response and recovery programmes, ICT change management processes, ICT incident management processes and relevant information transmission to users on a timely basis. |
| 86 | In developing their exit strategies, banks should consider both near-term and long-term disorderly and orderly exits, as this could impact exit strategies and assumptions. |
| 87 | A bank’s operational risk exposure evolves when it initiates change, such as engaging in new activities or developing new products or services; entering into unfamiliar markets or jurisdictions; implementing new business processes or technology systems or modifying existing ones; and/or engaging in businesses that are geographically distant from the head office. Change management should assess the evolution of associated risks across time throughout the full life cycle of a product or service. |
Additional criteria:
Principle 26:88 The supervisor determines that banks have adequate internal control frameworks to establish and maintain an effectively controlled and tested operating environment for the conduct of their business, considering their risk profile. These include clear arrangements for delegating authority and responsibility; separation of the functions that involve committing the bank, paying away its funds, and accounting for its assets and liabilities; reconciliation of these processes; safeguarding the bank's assets; and appropriate independent89 internal audit (including those that are outsourced or co-sourced), compliance and other control functions to test adherence to and effectiveness of these controls as well as applicable laws and regulations.
| 88 | Reference documents: BCBS, Principles for the effective management and supervision of climate-related financial risks, June 2022; BCBS, Corporate governance principles for banks, July 2015; BCBS, The internal audit function in banks, June 2012; BCBS, Compliance and the compliance function in banks, April 2005; BCBS, Framework for internal control systems in banking organisations, September 1998. |
| 89 | In assessing independence, supervisors give due regard to the control systems designed to avoid conflicts of interest in the performance measurement of staff in the compliance, control and internal audit functions. For example, the remuneration of such staff should be determined independently of the business lines that they oversee. |
Essential criteria:
| 90 | The time horizon for establishing a forward-looking view should appropriately reflect climate-related financial risks and emerging risks as needed. |
Principle 27:91 The supervisor determines that banks and banking groups maintain adequate and reliable records, prepare financial statements in accordance with accounting policies and practices that are widely accepted internationally and annually publish information that fairly reflects their financial condition and performance and bears an independent external auditor's opinion. The supervisor also determines that banks and parent companies of banking groups have adequate governance and oversight of the external audit function.
| 91 | Reference documents: BCBS, Supplemental note to external audits of banks – audit of expected credit loss, December 2020; BCBS, External audits of banks, March 2014; BCBS, Supervisory guidance for assessing banks’ financial instrument fair value practices, April 2009. |
| 92 | In this essential criterion, the supervisor is not necessarily limited to the banking supervisor. Responsibility for ensuring that financial statements are prepared in accordance with accounting policies and practices may also be vested with securities and market supervisors. |
Additional criterion:
Principle 28:93 The supervisor determines that banks and banking groups regularly publish information on a consolidated and, where appropriate, solo basis that is easily accessible and fairly reflects their financial condition, performance, risk exposures, risk management strategies and corporate governance policies and processes (including compensation practices). At least for internationally active banks, disclosure requirements are not less stringent than the applicable Basel standards.
| 93 | Reference documents: BCBS, High-level considerations on proportionality, July 2022; BCBS, Corporate governance principles for banks, July 2015; FSB, Enhancing the risk disclosure of banks, October 2012; BCBS, Enhancing bank transparency, September 1998; DIS10, DIS20, DIS21, DIS25, DIS26, DIS30, DIS31, DIS35, DIS40, DIS42, DIS43, DIS45, DIS50, DIS51, DIS60, DIS70, DIS75, DIS80, DIS85, DIS99. |
| 94 | In this essential criterion, the disclosure requirement may be found in applicable accounting, stock exchange listing or other similar rules, instead of or in addition to directives issued by the supervisor. |
Principle 29:95 The supervisor determines that banks have adequate policies and processes, including robust and risk-based96 customer due diligence (CDD) rules and effective compliance functions to promote high ethical and professional standards in the financial sector and prevent the bank from being used intentionally or unintentionally for criminal activities.97
| 95 | Reference documents: FATF Recommendations (February 2012, as amended in November 2023); BCBS, Sound management of risks related to money laundering and financing of terrorism, July 2020; FATF, Guidance on risk-based supervision, March 2021; FATF, Guidance on correspondent banking services, October 2016; FATF, Risk-based approach guidance for the banking sector, October 2014; BCBS, Shell banks and booking offices, January 2003. |
| 96 | Adopting a risk-based approach will enable competent authorities and banks to ensure that measures to prevent or mitigate money laundering and terrorist and proliferation financing are commensurate with the identified risks. |
| 97 | The Committee is aware that, in some jurisdictions, other authorities, such as a financial intelligence unit, may have primary responsibility for assessing compliance with laws and regulations regarding criminal activities in banks, such as fraud, money laundering and terrorist and proliferation financing. Thus, in the context of this principle, “the supervisor” might refer to such other authorities, particularly in essential criteria 7, 8 and 10. In such jurisdictions, the banking supervisor cooperates with such authorities to achieve adherence with the criteria set out in this principle. |
Essential criteria:
| 98 | In accordance with international standards, banks are to report suspicious activities involving cases of potential money laundering, terrorist financing and proliferation financing to the relevant national centre, which is established either as an independent governmental authority or as a department within an existing authority or authorities that serves as a financial intelligence unit. |
This chapter lists Committee standards, guidelines and sound practices that have been published since the last substantive review of the Core Principles.
Supervision and supervisory practices are not static. The Committee frequently issues new (and revises existing) standards, guidelines and sound practices. These are designed to strengthen regulatory and supervisory regimes, particularly for internationally active banks in Committee member jurisdictions. Supervisors are encouraged to move towards the adoption of updated and new international supervisory standards as they are issued.
Any standards that are consolidated in the Basel Framework are automatically incorporated into the Basel Core Principles when "Basel Framework" is referred to in the text. Similarly, when the Basel Core Principles refer to "applicable standards", this refers to the most recent BCBS standard or guideline that is effective.
The Committee has included this annex as a resource on supervisory practices and emerging risks that have evolved since the last review of the Basel Core Principles. When the next review of the Basel Core Principles is conducted, it will consider whether and how to embed any specific requirements or learnings from these publications within the text of the Core Principles.
This list is updated biennially.
|
Standards |
Table 1 |
|
Guidelines |
Table 2 |
|
Sound practices |
Table 3 |
|
Other standard-setting bodies' publications |
Table 4 |
This chapter outlines guidance for the preparation of assessment reports by the International Monetary Fund and World Bank.
This section presents guidance and a format recommended by the IMF and the World Bank for the presentation and organisation of the Basel Core Principles (BCP) assessment reports by assessors in the context of the FSAP and standalone assessments. A self-assessment99 conducted by the country's authorities prior to IMF-World Bank assessments is an essential element in the process and should also follow this guidance and format.
| 99 | Such self-assessment should be made available to assessors well in advance – also considering the possible need for translation – accompanied by the supporting legislation and regulation. |
The BCP assessment report should be divided into eight parts:
The following paragraphs provide a brief description of each of the eight parts.
A short "summary and main findings section" should provide an overview of the main findings and main recommendations of the report. It should read as an executive summary, with the main findings for several principles aggregated in a few paragraphs under subtitles. For example, assessors may choose to consolidate findings and recommendations under the subtitles of Responsibility, objectives, powers, independence and accountability (principles 1–2), Ownership, licensing and structure (principles 4–7), Methods of ongoing supervision (principles 8–10), Corrective and sanctioning powers of supervisors (principle 11), Cooperation, consolidated, and cross-border banking supervision (principles 3, 12–13), Corporate governance (principle 14), Prudential requirements, regulatory framework, accounting and disclosure (principles 15–29).
A brief introduction and methodology section which provides background information on the assessment conducted, ie the context in which the assessment is being conducted and the methodology used. This section should:
| 100 | Names are typically avoided, in order to protect individuals and encourage candour. |
| 101 | If the lack of information adversely impacts the quality and depth of the assessment of a particular Core Principle, assessors should refer to this in the comment section of the assessment template and document the obstacles encountered, in particular where access to in-depth information is crucial in evaluating compliance. Such issues should be brought to the attention of the mission leaders and, where necessary, referred to headquarters staff for guidance. |
The third section should provide an overview of the supervisory environment for the financial sector, with a brief description of the institutional and legal setting, in particular the mandate and oversight roles of the different supervisory authorities, the existence of unregulated financial intermediaries and the role of self-regulatory organisations. Furthermore, it should provide a general description of the structure of the financial markets and, in particular, the banking sector, mentioning the number of banks, total assets to gross domestic product, a basic review of banking stability, capital adequacy, leverage, asset quality, liquidity, profitability and risk profile of the sector, and information on ownership, ie foreign versus domestic, state-owned versus privately owned, the existence of conglomerates or unregulated affiliates, and similar information. If the assessment is part of an FSAP, this section can be shorter, summarising and cross-referencing other FSAP documents.
The fourth section should provide an overview of the preconditions for effective banking supervision, as described in this BCP standard. Experience has shown that insufficient implementation of the preconditions can seriously undermine the quality and effectiveness of banking supervision. Assessors should aim to give a factual review of preconditions so that the reader of the report is able to clearly understand the environment in which the banking system and the supervisory framework are operating. This will provide the perspective for a better appreciation of the assessment and grading of individual principles. The review normally should take up no more than one or two paragraphs for each type of precondition and should follow the headings indicated below.
BCP assessors should not assess preconditions themselves, as this is beyond the scope of the individual standard assessments. Assessors should rely to the greatest extent possible on official IMF and World Bank documents and seek to ensure that the brief description and comments are consistent. Where relevant, assessors should attempt to include in their analysis the linkages between these factors and the effectiveness of supervision. As described in the next section, the assessment of compliance with individual Core Principles should mention clearly how it is likely to be primarily affected by preconditions that are considered to be weak. If shortcomings in preconditions are material to the effectiveness of supervision, they may affect the grading of the affected Core Principles. Any suggestions aimed at addressing deficiencies in preconditions are not part of the recommendations of the assessment but can be made into general FSAP recommendations within the scope of the FSAP exercise.
The fifth section contains a detailed principle-by-principle assessment, providing a "description" of the system with regard to each criterion within a principle; a grading or "assessment"; and "comments". The template for the detailed assessment is structured as follows.
|
Principle (x) (repeating verbatim the text of the Principle) |
|
|
Essential criteria (EC) |
|
|
Description and findings regarding EC1 |
|
|
Description and findings regarding EC2 |
|
|
Description and findings regarding EC3 |
|
|
Additional criteria (AC) (only if the authorities choose to be assessed and graded against these too) |
|
|
Description and findings regarding AC1 |
|
|
Description and findings regarding ACn |
|
|
Assessment of Principle (x) |
Compliant / Largely compliant / Materially |
|
Comments |
|
The "description and findings" section of each criterion should provide information on the practice as observed in the country being assessed. It should cite and summarise the main elements of the relevant laws and regulations. This should be done in such a way that the relevant law or regulation can be easily located, for instance by reference to URLs, official gazettes and similar sources. Insofar as possible and relevant, the description should be structured as follows:
Evidence of implementation and/or enforcement is essential: without the effective use of the powers vested in the supervisor and implementation of rules and regulations, even a well designed supervisory system will not be effective. Examples of practical implementation should be provided by the authorities, reviewed by the assessors and mentioned in the report.102
| 102 | For instance: how many times over the past years have the authorities applied corrective action? How frequently have banks been inspected on-site? How many licensing applications have been received, and how many have been accepted/turned down? Have asset quality reports been prepared by the inspectors, and how have the conclusions been communicated to senior bank and banking supervision management? |
The "assessment" section of the template should contain only one line, stating whether the system is "compliant", "largely compliant", "materially non-compliant", "non-compliant" or "not applicable" as described in BCP20.9 and BCP20.10. There are three assessment options:
The essential criteria set out minimum baseline requirements for sound supervisory practices and are universally applicable in all countries. An assessment of a jurisdiction against the essential criteria must, however, recognise that its supervisory practices should be commensurate with the risk profile and systemic importance of the banks being supervised. In other words, the assessment must consider the context in which the supervisory practices are applied. As with the essential criteria, any assessment against additional criteria should also adopt the principle of proportionality. This principle should underpin assessment of all criteria even if it is not always explicitly referred to in the criteria. For example, a jurisdiction with many systemically important banks or banks that are part of complex mixed conglomerates will naturally have a higher hurdle to clear to obtain a "compliant" grading as compared to a jurisdiction which only has small and non-complex banks that are primarily engaged in deposit-taking and extending loans.
The "comments" section of the template should be used to explain why a particular grading was given. In case of a grading below "compliant", this section should be used to highlight the materiality of the observed shortcomings and indicate which measures would be needed to achieve full compliance or a higher level of compliance. This should also be included in the table on "recommended actions" (see below). This reasoning could be structured as follows:
The "comments" should explain the cases where, despite the existence of laws, regulations and policies, weaknesses in implementation contributed to the principle being graded as less than "compliant". Conversely, when a "compliant" grading was given, but observance was demonstrated by the country through different mechanisms, this should be explained. The "comments" section should also highlight when and why compliance with a particular criterion could not be adequately reviewed, such as where certain information was not provided or where key individuals were unavailable to discuss important issues. Requests for information or meetings should be documented in the "comments" section to clearly demonstrate the assessor's attempts to adequately assess a principle.
Assessors may also include "comments" where they find particularly good practices or rules in some field that might serve as examples and best practice to other countries. Planned initiatives aimed at amending existing or adopting new regulations and practices but which are not yet in effect can receive favourable mentions in this section. Recent legislative, regulatory or supervisory initiatives for which implementation could not be verified should be mentioned in this section as well.
The assessment and accompanying grades should solely be based on the regulatory framework and supervisory practices in place at the time of the assessment and should not reflect planned initiatives aimed at amending existing regulations and practices or adopting new ones. This would be applicable in the case where actions are in process that would result in a higher compliance rating but have not yet been effected or implemented.
When linkages between particular principles are evident, or between preconditions and principles, this section should be used to caution the reader that, although the regulation and practices in principle (x) seem compliant, a "compliant" grading cannot be given because of material deficiencies in the implementation of principle (y) or precondition (z).103 While recognising that there could be common deficiencies which are both relevant and material enough to affect the rating of more than one principle, assessors should avoid double-counting as far as possible. If the deficiencies found in linked principles or preconditions are not material enough to warrant a downgrade, this should still be brought out in this section of the template.
| 103 | For example, the regulation and supervision of capital adequacy may seem compliant, but if material deficiencies are found in another principle, such as provisioning, that will mean capital may be overstated and ratios unreliable. |
Grading should be given to a principle regardless of the level of development of a country. If certain criteria are not applicable given the size, nature of operations and complexity of a country's banking system, grading of the principle should be based on the level of compliance with the applicable criteria only. This must be clearly explained in the relevant section of the report so that a future review can reconsider the grading if the situation changes. The same applies to a "not applicable" grading of a principle.
The sixth section of the report comprises a compliance table, summarising the assessments, principle by principle. This table has two versions: the one that does not include explicit grading (Table 2) is to be used in reports on the observance of standards and codes (or ROSCs; see BCP99.22,104 the version with grading (Table 1) is to be used in the detailed assessment only. This table should convey a clear sense of the degree of compliance, providing a brief description of the main strengths and, especially, weaknesses with respect to each principle. The template is as follows:
|
Summary compliance with the Core Principles – Detailed Assessment Report (DAR) |
Table 1 |
||||||
|
Core principle |
Grade (column not used in ROSCs) |
Comments |
|||||
|
1. Responsibilities, objectives and powers |
|
||||||
|
2. Independence, accountability, resourcing and legal protection for supervisors |
|||||||
|
3. Cooperation and collaboration |
|||||||
|
4. Permissible activities |
|||||||
|
5. Licensing criteria |
|||||||
|
6. Transfer of significant ownership |
|||||||
|
7. Major acquisitions |
|||||||
|
8. Supervisory approach |
|||||||
|
9. Supervisory techniques and tools |
|||||||
|
10. Supervisory reporting |
|||||||
|
11. Corrective and sanctioning powers of supervisors |
|||||||
|
12. Consolidated supervision |
|||||||
|
14. Home-host relationships |
|||||||
|
15. Risk management process |
|||||||
|
16. Capital adequacy |
|||||||
|
17. Credit risk |
|||||||
|
18. Problem exposures, provisions and reserves |
|||||||
|
19. Concentration risk and large exposure limits |
|||||||
|
20. Transactions with related parties |
|||||||
|
21. Country and transfer risks |
|||||||
|
22. Market risk |
|||||||
|
23. Interest rate risk in the banking book |
|||||||
|
24. Liquidity risk |
|||||||
|
25. Operational risk and operational resilience |
|||||||
|
26. Internal control and audit |
|||||||
|
27. Financial reporting and external audit |
|||||||
|
28. Disclosure and transparency |
|||||||
|
29. Abuse of financial services |
|
||||||
|
Summary compliance with the Core Principles – ROSC |
Table 2 |
|
Core principle |
Comments |
|
1. Responsibilities, objectives and powers |
|
|
2. Independence, accountability, resourcing and legal protection for supervisors |
|
|
3. Cooperation and collaboration |
|
|
4. Permissible activities |
|
|
5. Licensing criteria |
|
|
6. Transfer of significant ownership |
|
|
7. Major acquisitions |
|
|
8. Supervisory approach |
|
|
9. Supervisory techniques and tools |
|
|
10. Supervisory reporting |
|
|
11. Corrective and sanctioning powers of supervisors |
|
|
12. Consolidated supervision |
|
|
14. Home-host relationships |
|
|
15. Risk management process |
|
|
16. Capital adequacy |
|
|
17. Credit risk |
|
|
18. Problem exposures, provisions and reserves |
|
|
19. Concentration risk and large exposure limits |
|
|
20. Transactions with related parties |
|
|
21. Country and transfer risks |
|
|
22. Market risk |
|
|
23. Interest rate risk in the banking book |
|
|
24. Liquidity risk |
|
|
25. Operational risk and operational resilience |
|
|
26. Internal control and audit |
|
|
27. Financial reporting and external audit |
|
|
28. Disclosure and transparency |
|
|
29. Abuse of financial services |
|
| 104 | The ROSC does not include the grading in the table because the grades cannot be fully understood without the description and detailed comments (which are available only in the DAR). |
The seventh section comprises a "recommended actions" table providing principle-by-principle recommendations for actions and measures to improve the regulatory and supervisory framework and practices. This section should list the suggested steps for improving the compliance and overall effectiveness of the supervisory framework. Recommendations should be proposed on a prioritised basis in each case where deficiencies are identified. The recommended actions should be specific in nature. An explanation could also be provided as to how the recommended action would assist in improving the level of compliance and strengthening the supervisory framework. The institutional responsibility for each suggested action should also be clearly indicated to prevent overlaps or confusion. Recommendations can also be made regarding deficiencies in compliance with the additional criteria and to principles which are fully compliant but where supervisory practice can still be improved. The table should indicate only those principles for which specific recommendations are being made. The template for the recommended actions is as follows.
|
Recommended actions to improve compliance with the Core Principles and the effectiveness of regulatory and supervisory frameworks |
|
|
Reference principle |
Recommended action |
|
Principle (x) |
Example: suggested introduction of regulation (a), supervisory practice (b) |
|
Principle (y) |
Example: suggested introduction of regulation (c), supervisory practice (d) |
The eighth section describes the authorities' response to the assessment.105 The assessor should provide the supervisory authority or authorities being assessed with an opportunity to respond to the assessment findings, which would include providing the authorities with a full written draft of the assessment. Any differences of opinion on the assessment results should be clearly identified and included in the report. The assessment should allow for greater dialogue, and therefore the assessment team should have had a number of discussions with the supervisors during the assessment process so that the assessment should also reflect the comments, concerns and factual corrections of the supervisors. The authority or authorities should also be requested to prepare a concise written response to the findings ("right of reply"). The assessment should not, however, become the object of negotiations, and assessors and authorities should be willing "to agree to disagree", provided the authorities' views are represented fairly and accurately.
| 105 | If no such response is provided within a reasonable time frame, the assessors should note this explicitly and provide a brief summary of the initial response provided by the authorities during their discussion with the assessors at the end of the assessment mission (“wrap-up meeting”). |
The presentation of assessment results in ROSCs is different from the presentation of the outcome of the DAR described above. The ROSC should comprise all of Section 1 and summaries of Sections 2, 3, 4, 7 and 8. There should be no Section 5 (detailed assessment), and the summary table in Section 6 should be amended to remove the "grades" column. All sections should remove references to the grades. An ROSC is a mandatory attachment to the FSAP reports if a full DAR is not published.
This standard describes the scope of application of the Basel Framework.
This standard describes the criteria that bank capital instruments must meet to be eligible to satisfy the Basel capital requirements, as well as necessary regulatory adjustments and transitional arrangements.
This standard describes the framework for risk-based capital requirements.
This standard describes how to calculate capital requirements for credit risk.
This standard describes how to calculate capital requirements for market risk and credit valuation adjustment risk.
This standard describes how to calculate capital requirements for operational risk.
This standard describes the simple, transparent, non-risk-based leverage ratio. This measure intends to restrict the build-up of leverage in the banking sector and reinforce the risk-based requirements with a simple, non-risk-based "backstop" measure.
This standard describes the Liquidity Coverage Ratio, a measure which promotes the short-term resilience of a bank's liquidity risk profile.
The net stable funding ratio requires banks to maintain a stable funding profile in relation to the composition of their assets and off-balance-sheet activities.
Large exposures regulation limits the maximum loss that a bank could face in the event of a sudden counterparty failure to a level that does not endanger the bank's solvency. This standard requires banks to measure their exposures to a single counterparty or a group of connected counterparties and limit the size of large exposures in relation to their capital.
This standard establishes minimum standards for margin requirements for non-centrally cleared derivatives. Such requirements reduce systemic risk with respect to non-standardised derivatives by reducing contagion and spillover risks and promoting central clearing.
The Pillar 2 supervisory review process ensures that banks have adequate capital and liquidity to support all the risks in their business, especially with respect to risks not fully captured by the Pillar 1 process, and encourages good risk management.
This standard sets out disclosure requirements, which aim to encourage market discipline.
The Basel Core Principles provide a comprehensive standard for establishing a sound foundation for the regulation, supervision, governance and risk management of the banking sector.