0% found this document useful (0 votes)
7 views51 pages

Mozambique Risk Management Guidelines

The Bank of Mozambique has issued guidelines for risk management in credit institutions to standardize practices and improve supervision. These guidelines, designated as DGR, cover various risk categories and require institutions to submit their Risk Management Programs annually. The notice also emphasizes the importance of effective risk measurement, monitoring, and internal controls to ensure financial stability.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views51 pages

Mozambique Risk Management Guidelines

The Bank of Mozambique has issued guidelines for risk management in credit institutions to standardize practices and improve supervision. These guidelines, designated as DGR, cover various risk categories and require institutions to submit their Risk Management Programs annually. The notice also emphasizes the importance of effective risk measurement, monitoring, and internal controls to ensure financial stability.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Wednesday, September 18, 2013 I SERIES — Number 75

BULLETIN OF THE REPUBLIC


OFFICIAL PUBLICATION OF THE REPUBLIC OF MOZAMBIQUE

NATIONAL PRESS OF MOZAMBIQUE, E.P. In view of improving risk management practices


current in credit institutions, as well as to standardize the
respective terminology, the Bank of Mozambique decided to issue
ADVISO
a set of guidelines based on best practices
The material to be published in the 'Bulletin of the Republic' must
internationally oils.
to be sent in a duly authenticated copy, a The issuance of these guidelines is also in accordance
for each subject, where it is stated, in addition to the indications
with the intention of the Bank of Mozambique to make its
necessary for this purpose, the following annotation, supervision activity, both on-site and off-site, increasingly
signed and authenticated: For publication in the 'Bulletin' but more focused on risk, in response to the increasing number
of the Republic. of supervised institutions and the constant innovation in
provision of financial services by these.
Intheseterms,theBankofMozambique,intheuse
from the authority granted to it by line d) of paragraph 2
SUMMARY
of article 37 of Law No. 1/92, of January 3 – Organic Law
from the Bank of Mozambique, determines:
Bank of Mozambique:
Notice No. 4/GBM/2013: ARTICLE 1
Establishes the Risk Management Guidelines, abbreviated (Object)
designated by DGR.
This Notice establishes the Risk Management Guidelines,
Notice No. 5/GBM/2013: abbreviatedly designated as DGR, attached to this Notice
and that they are an integral part of it:
Approves the Regulation of the Market Operations System.
a) Annex I - Risk Management Guidelines; and
Notice No. 6/GBM/2013: b) Annex II - Risk Management Guidelines - Risk
Approves the Regulation on Operations with a buy-back agreement of Information Technologies.
for the purchase and resale of fixed income securities.
ARTICLE2
Notice No. 7/GBM/2013:
Scope of application
Approves the Regulation of the Interbank Money Market. This Notice applies to all credit institutions with
Notice No. 8/GBM/2013: headquarters in Mozambican territory and branches in Mozambique
of credit institutions based abroad.
Approves the Regulation on Emission and Transaction
of Treasury Bills. ARTICLE 3
Notice No. 9/GBM/2013: Deadline for the submission of Risk Management Programs

Names José Frederico da Cruz Viola Cabral, President 1. Credit institutions must send to the Bank
from the Directive Committee of the Deposit Guarantee Fund. from Mozambique its Risk Management Programs
(PGR) within thirty days, counted from the date of publication
of this Notice and, subsequently, until the day of March 31
of each year.
BANK OF MOZAMBIQUE 2. Whenever the PGRs are not in compliance with
as DGR or those that appear misaligned with nature and complexity
Notice No. 4/GBM/2013 from the activity of the institution, the Bank of Mozambique will leave a
September 18 deadline for the necessary adjustment.
The credit institutions, in the development of their ARTICLE 4
activities, assume risks likely to cause impacts
negatives in expected returns. Thus, the existence of (Clarification of doubts)
a management structure capable of optimizing the relationship between the The doubts that arise from interpretation and application
maximization of return and minimization of risks constitutes a This Notice will be clarified by the Department
essential prerequisite for the solidity of these institutions. of the Banking Supervision of the Bank of Mozambique.
608 I SERIES — NUMBER 75

ARTICLE 5 [Link]. Measurement – once identified, the risks must


are measured in order to determine their impact on the result
Entry into force
the capital of the institution. This can be done using several
This Notice comes into effect on the date of its publication. techniques, from the simplest to the most sophisticated models.
Mozambique Bank, in Maputo, May 24, 2013. The timely and accurate measurement of risks is an essential condition.
The Governor, Ernesto Gouveia Gove. for risk management systems to be effective. A
an institution that does not have a risk measurement system has
limited capacity to control or monitor the levels
of risk to which it is exposed. At a minimum, an institution must,
periodically, conduct tests to ensure that the instruments
1. General Provisions the measurement employed are variables. A good measurement system
1.1. Objectives of risks evaluates both the risks of individual transactions as
1.1.1. The present guidelines aim to contribute to the global wallet.
the establishment of a uniform language among institutions [Link]. Control - after measuring the risk, the institution must
of credit and the supervisor in risk management matters, what, establish and communicate risk limits through policies,
in turn, will contribute to the harmonization of practices standards and procedures that define responsibilities and lines
risk management in the banking industry, referring to the of authority. These limits should serve as elements of
control of exposures to the various risks associated with activities
international best practices in this domain.
of the institution. Institutions can also employ various
1.2 Risk Categories mitigation tools to minimize your exposure to risks.
1.2.1. The present Risk Management Guidelines (RMG) In addition, they must have a process to authorize exceptions.
understand the nine most relevant categories of risks in or changes to the limits, when justified.
banking activity in the country, namely: [Link]. Monitoring – institutions must establish
an effective Management Information System (MIS) for
a) Credit risk;
monitor the risk levels and facilitate the timely review of the
b) Liquidity risk; risk positions and exceptions. The monitoring reports
c) Interest rate risk; they must be frequent, timely, accurate, and informative,
d) Exchange rate risk; and must be distributed to the people responsible for ensuring
e) Operational risk; the undertaking of actions, if necessary.
f) Strategic risk; 1.5. Conceptual Framework for Risk Management
g) Reputation risk;
1.5.1. A conceptual framework for risk management includes
h) Risk of non-compliance; and
the scope of the risks to be managed, the processes, systems
i) Risk of Information Technology (IT)1). the procedures for managing such risks, as well as the assignments
1.3. Risk Management Programs and the responsibilities of the individuals involved in its management.
1.3.1. Institutions must develop a Program The conceptual framework must be broad enough to capture
of Risk Management (PGR) detailed, tailored to the dimension and all the risks to which an institution is exposed and to have
complexity of their activities. The PGRs must be reviewed, Flexibility to accommodate any changes in activities
of the institution.
at least annually, and it is expected that they will cover, at a minimum, the
1.5.2. The key elements of a conceptual management framework
nine risks contained in these guidelines. of risks and effects are:
1.4. Risk Management Process Active monitoring by the administration and management body
1.4.1. Risk management is a fundamental discipline in from the top;
all institutions and understand the activities that affect b) Policies, procedures, and appropriate limits;
your risk profile. Risk management, as is commonly c) Appropriate measurement and monitoring systems
understood, does not mean risk minimization; on the contrary, the and management information; and
the same aims to optimize the risk-return relationship d) Comprehensive internal controls.
with which institutions are confronted. This objective can be 1.5.3. Supervision by the Administrative Body2
achieved by institutionalizing a conceptual framework of management Top Management3:
at risk to capture and manage, adequately, all the risks to which [Link]. The governing bodies hold, ultimately
an institution is exposed. instance, the responsibility for the level of risks assumed in the
1.4.2. Risk management involves four (4) processes- institution. Consequently, they must approve the strategies
key: business globals and the policies, including those related to
[Link]. Identification – to properly manage risks, a the taking and management of risks and should, likewise, ensure that
the institution must be able to identify existing risks or the top management is fully capable of managing the activities that
that can arise from both existing business initiatives the institution develops. While it is required that all bodies
as well as new initiatives, for example, inherent risks related to of management should be responsible for understanding the nature
credit activity, which includes credit ones, liquidity ones, of
interest rate and operational. The identification of risks must be a
continuous process and must occur both at the individual level as well 2
It is the Board of Directors, Management Board, the Council
of the Board or other body with analogous functions, in accordance with paragraph 11
global (i.e., in each transaction and in the wallet as a whole). of article 2 of Notice 8/GBM/2007.
3
They are people who have authority and responsibility for planning,
direction and control of activities, directly or indirectly, including any
1 Subject dealt with in specific document. administrator (executive or other).
September 18, 2013 609

of the risks to which the institution is exposed and to ensure that the management 1.5.5. Measurement, Monitoring and Systems
carry out the necessary procedures to identify, measure, control of Risk Management Information:
and to monitor such risks, the level of technical knowledge required Effective risk monitoring requires that
the members of the management body may vary, depending on the institutions identify and measure all exposures to
the particular circumstances of the institution. risk that they are materials. Consequently, the activities
[Link]. The members of the management body must risk monitoring should be supported by systems
to have a clear understanding of the risks to which the institution is exposed of information provided to top management and members
exposed and should receive reports that identify the dimension the administrative body reports timely on the situation
the materiality of these risks. Additionally, they must execute financial, operational performance and exposure to risk, well
actions aimed at providing them with an adequate understanding as regular and sufficiently detailed reports for
from the risks through meetings with auditors and experts the line managers involved in the daily management of activities
external to the institution. Using this knowledge and information, of the institutions.
the members of the management body must provide a [Link]. Institutions must have monitoring systems.
clear guidance regarding acceptable levels of exposure risk assessment and management that provide administrators
for the institution and to ensure that top management implements and senior management a clear understanding of the exposures
the procedures and controls necessary for compliance with to the risk.
adopted policies. [Link]. To ensure effective measurement and monitoring
[Link]. Top management is responsible for the implementation of risks and management information systems, it should be
of strategies that limit the risks associated with each strategy observed the following:
specific and ensure the permanent observance of the laws (i) The practices and reports for monitoring risks
the regulations, both in the short and long term. Likewise The institution must reflect all its risks.
Thus, management must be fully involved in the activities. materials;
from the institution and have sufficient knowledge of all the lines (ii) The key assumptions, data sources, and procedures
business principles to ensure that policies, controls used in measuring and monitoring risks
the appropriate management systems are implemented and that must be appropriate, adequately documented
the accountability and establishment of lines of authority and your ability verified on a continuous basis;
should be outlined clearly. Top management is also (iii) Reports and other forms of communication must
responsible for establishing and communicating a strong be consistent with the institution's activities
sense of awareness about the need for internal controls and structured to accompany exhibitions and observe
and raised standards of ethics. advance of the limits, goals or objectives established,
[Link]. In order to achieve these objectives, it is necessary that as well as, as necessary, compare
the current performance with the expected; and
top management has a broad understanding of the activities
banking and financial markets, as well as knowledge (iv) Reports for management or administration
detailed activities that the institution carries out, including The institution's reports must be accurate and timely.
the nature of the internal controls necessary to limit the and have sufficient information for decision-makers
related risks. can identify any adverse trends
and properly assess the level of risk taken
1.5.4. Policies, Procedures, and Limits:
by the institution.
[Link]. The members of the governing body and management
1.5.6. Internal Controls:
the top of an institution must conceive policies
the risk management procedures adjusted to the risks that The internal control structure is crucial for
emerge from the activities they develop. Once such the safe and robust operation of an institution, in general,
risks have been adequately identified, the policies and for the risk management system, in particular. One of
one of the most important responsibilities of management is to create and maintain a
the procedures must provide detailed guidelines for
implementation, in day-to-day life, of global business strategies, sistema de controlo e caz, incluindo o enforcement das linhas
and must include limits designed to safeguard the institution of formal authorities and the appropriate segregation of such functions
of excessive risks, as well as those not taken based on the like trading, custody, and back-office.
better criteria. Management must also ensure the update [Link]. Indeed, the appropriate segregation of functions is a
the same, whenever necessary, in order to respond to the essential element of a solid management and control system
significant changes in business activities or conditions internal risks. The failure in implementation and maintenance
of the institution. of an appropriate system of segregation of functions can lead to
[Link]. For the policies, procedures, and limits of a substantial losses or otherwise compromise integrity
the institution must be adequate, at a minimum: institution's financial.
Ensure identification, measurement, control [Link]. When structured appropriately, the system
the monitoring of risks arising from activities internal control promotes effective operations, reporting
institution data; financial and prudential controls safeguard assets and assist
Be consistent with the complexity and the dimension the observance of laws, regulations, and institutional policies
of the business, the goals, the targets and the robustness relevant. To ensure the suitability of the procedures
financial institution; of auditing and internal controls, must be observed
(iii) Define lines of authority and accountability the following:
clear accountability at the level of activities a) The internal control system must be appropriate to the type
of the institution; and and the level of risks raised by the nature and scope
Encourage the review of new activities the activities of the institution;
in the institution, in order to ensure that the infra- b) Internal controls must be tested by
necessary structures to identify, control an independent auditor who reports directly
and monitor the risks associated with a particular to the governing body of the institution or to the Committee
activities should be created before it starts. of the Audit;
610 I SERIES — NUMBER 75

c) The results of audits or reviews, whether they are 1.5.8. Independent Review:
conducted by an internal auditor or by other personnel, [Link]. Institutions must have independent reviewers
they must be properly documented, and must to evaluate the effectiveness and adherence to policies and procedures
the same happening with the management's reaction to of risk management. The reviewers can be internal auditors,
these results. external auditors or any other independent entities
d) The organizational structure of the institution must establish the risk-taking areas and must report directly
clear lines of authority and responsibility, for to the governing body or committee designated by it.
monitor adherence to policies and procedures [Link]. To be effective, independent reviewers must
the limits; with sufficient authority, proficiency, and corporate status
e) The reporting lines must ensure independence. suitable for identifying and reporting findings without any
the control areas in relation to the lines of business impediments.
(such as trading, custody, back-office), ensuring [Link]. The independent reviewer must, among other aspects,
thus an appropriate segregation of functions at the level evaluate if:
of the institution; a) The risk management system is appropriate for
f) Institutional structures must reflect practices the nature, scope, and complexity of the institution
effective operations; and their activities;
g) The financial, operational, and prudential reports b) The governing body and top management are
they must be accurate, reliable, and timely. In actively involved in the management process
applicable cases, the exceptions must be noted of risks;
and promptly investigated; c) The policies, procedures and management controls
There must be appropriate procedures in place to ensure risks are adequately documented
the observance of norms and regulations; and strictly observed;
i) Internal auditing or other internal review functions d) The assumptions of the risk measurement system are
they must ensure independence and objectivity; valid and properly documented;
j) The internal controls and information systems e) The aggregation and processing of data are accurate,
they must be properly tested and reviewed; appropriate and usable;
the scope, procedures, findings, and responses The institution has adequate personnel to carry out
the results of the audits and review tests must a solid risk management process.
to be properly documented; the weaknesses 1.5.9. Integration of Risk Management:
identified materials must have appropriate attention [Link]. Risks must be considered and evaluated in a manner
it is at its highest level. Likewise, the integrated, because a transaction has several underlying risks
management actions to address material weaknesses and because one type of risk can trigger others. Once
must be objectively reviewed; and that the interaction of various risks may result in the reduction
k) The Audit Committee or the administrative body With the increase in risk profile, the risk management process must
the institution must review the effectiveness of the audits
recognize and reflect, as appropriate, the interactions of
internal (and other review activities of the risks in all activities.
internal controls) on a regular basis. [Link]. When assessing and managing risks, management must have a
1.5.7. Risk Management Function: overview of the risks to which the institution is exposed.
[Link]. Institutions must establish a functional area This requires the existence or establishment of a structure that
responsible for scaling the management of intrinsic risks allow to capture the interrelations existing between the different types
in its operations. Such unit may have the nature of a committee, of risks throughout the institution.
risk department or manager, depending on the size 1.5.10. Contingency Plan:
the complexity of the institution. The staff assigned to the function
of comprehensive risk management should be independent of that which [Link]. Institutions must have mechanisms to
takes or accepts risks on behalf of the institution. identify, in advance, situations of effort (stress)
[Link]. The risk management function is responsible for regarding all types of risks and contingency plans4
ensure the existence of effective processes for: to deal with these situations in a timely and effective manner.
a) Identify the present and future risks; These plans should be reviewed regularly to ensure that
b) Develop measurement and evaluation systems I cover reasonably likely events that may produce
of risks; adverse impacts on the institution.
c) Estabelecer políticas, procedimentos, práticas e outros [Link]. The plans must be tested for plausibility
mechanisms for risk management; the responses, escalation and communication channels and your
d) Develop risk tolerance limits for approval impact on other areas of the institution.
by the administrative body; 2. Credit Risk Management Guidelines
e) Monitor the positions taken, based on
2.1. Introduction
the approved tolerance limits; and
f) Report the results of risk monitoring 2.1.1. Credit risk is the possibility of occurrence
to the top administration and management body. of negative impacts on results or on capital, due to
[Link]. However, risk management is not restricted to individuals. the inability of a counterpart to fulfill its commitments
affects the function of comprehensive risk management. The business areas
are equally responsible for the risks they take and any 4
Contingency planning activities include, for example,
the absence of responsibility can cause problems. The staff the planning of disaster recovery, the control of damage in relationships
of these areas, more than any other, must understand the risks public, the litigation strategy, responses to the regulator's recommendations,
of the business. the liquidity crisis, etc.
18 DE SETEMBRO DE 2013 611

financial obligations to the institution, including possible restrictions on i) Review exhibitions to collaborators and parties
transfer of payments from abroad. The credit risk exists, related, including the policies pertaining to them
mainly, in credit exposures (including the titled), related;
credit lines, guarantees, and derivatives. This risk emerges Justify the exhibitions that exceed the level of authority
of the institution's relationship with individuals, companies, institutions delegate in management and be alert to the exposures that,
financial and sovereign. although worthy of consideration, they are not
2.1.2. Credit risk does not necessarily arise from within the existing credit policies in
isolated form. The same source that originates the credit risk institution;
it can also expose the institution to another type of risks. With k) Review the trends in the quality of the credit portfolio
a low-quality wallet can trigger problems of the institution and the adequacy of the respective provisions
of liquidity.
2.1.3. The most common sources of problems in the portfolio
for losses;
l) Define the content and frequency of management reports
of credit are:
to submit to the administrative body regarding the management
a) Credit concentrations - are seen as any
of credit risk; and
exhibition where potential losses are greater
m) Ensure effective communication of the strategy and the
to capital, total assets or any other measures
credit risk policies in the institution. All the
adequate. The concentrations can take the
form of (i) loans to a single individual relevant people must understand clearly the
institutional approach to concession and management of
or to a counterpart, to a group of counterparts
related to sectors or industries such as credit and must be held accountable for compliance
commerce, agriculture, etc., or (ii) common factors or of the established policies and procedures.
related; and 2.2.2. Oversight by Top Management
b) Questions related to the credit process - Many [Link]. The management of the institutions is responsible for
problems with credit reveal basic deficiencies implementation of risk management strategies and policies
in the processes of granting and monitoring.
of credit as well as by ensuring that they are applied
Although the gaps in the terms of adhesion (contracting)
procedures consistent with these strategies and policies,
and the management of credit facilities represents
with the purpose of managing and controlling credit risk and the
important sources of losses in institutions, many
credit problems can be avoided or credit portfolio quality.
mitigated by a strong internal management process. It especially falls to top management:
2.2. Supervision by the Administration Body a) Develop management policies and procedures
Top Management credit for approval by the administrative body,
2.2.1. Supervision by the Administrative Body as part of the global risk management framework
The administration body has a crucial role credit;
on the scaling of credit granting processes and management b) Implement policies for credit risk management;
of credit risk. c) Ensure the development and implementation of a system
[Link]. It is especially the responsibility of the administrative body: of adequate reporting regarding content, format
a) Approve the strategy and policies related to risk the frequency of information related to the portfolio
of credit and its management, which should be of credit and at the level of credit risk, in order to
in line with the global business strategy to allow a precise analysis and healthy management
of the institution. The global strategy and policies must be prudent, as well as the control of exposures
to be reviewed at least once a year; to credit risk, effective and potential;
b) Establish the institution's tolerance levels regarding d) Monitor and control the nature and composition
to credit risk; from the institution's wallet;
c) Ensure that the institution is significantly exposed e) Monitor the quality of the credit portfolio
that credit risk is kept at prudent levels and to ensure that it is assessed in a robust manner
and consistent with the available capital; conservative, the uncollectible exposures are cleaned up/
d) Establish competence levels for granting write-offs and probable losses are properly
of credit and explicitly delegate in top management
provisioned;
and in the credit committee the authority to apply
Establish internal controls, including institutionalization
sanctions, whenever appropriate;
e) Ensure that top management and individuals of clear lines of responsibility and authority for
responsible for credit risk management, have ensure an effective risk management process
reasonable knowledge and proficiency to materialize of credit; and
the attributions of the risk management function; g) Develop communication lines to ensure
f) Ensure that the institution implements principles the timely dissemination of policies, procedures
solid fundamentals that facilitate identification, and other information on credit risk management
measurement, monitoring and control of risk to all individuals involved in the process.
of credit; 2.3. Strategy, Policies, Procedures, and Limits
g) Ensure a proper implementation of the policies
the approved procedures; 2.3.1. Credit Strategy
h) Ensure that the internal audit verifies the operations [Link]. The main objective of the credit strategy
credit to assess whether the policies and procedures of an institution is to determine its risk appetite. A
the institution's standards are appropriate and respected; Once determined, the institution can develop a plan to
612 I SERIES — NUMBER 75

optimize the return while keeping credit risk within limits 2.3.3. Procedures
predetermined. Thus, the credit risk strategy of a [Link]. Credit Origination:
the institution must state: [Link].1. The establishment of granting criteria
a) The institution's plan to grant credit with Robust and well-defined credit is essential for approval.
based on various customer segments and products, of credits safely and healthily. The criteria must
economic sectors, geographical location, currencies establish who is eligible and for what amounts, the types
and maturities; available credit and the terms and conditions under which it is granted
The market has a wide range in each segment of loans must be granted.
and the level of diversification/concentration; and
[Link].2. Institutions must obtain sufficient information
c) The pricing strategy. to allow for a thorough assessment of the actual risk profile
[Link]. It is essential that, when developing the risk strategy of the borrower or counterparty. At a minimum, the factors to be
de crédito, as instituições dêem a devida atenção ao seu mercado- considered and documented in credit approval are:
target. The credit granting procedures must have as a) The purpose of the credit, as well as the source of repayment
goal of obtaining a deep understanding of the customers, bag
your credentials and business. b) The suitability and reputation of the borrower or counter-
[Link]. The strategy must provide a basis for continuity part;
in your approach and take into account cyclical aspects of the economy
c) The current risk profile (including the nature
of the Country and the consequent changes in composition and quality and the total amounts of risks) of the borrower
of the resulting global credit portfolio. Although the strategy oucontraparteesuasensibilidadeaosdesenvolvimentos
can be reviewed periodically and changed when necessary economic and market;
necessary, it must be viable in the long term and in various d) The history and current repayment capacity
economic cycles. of the borrower, based on financial trends
2.3.2. Policies historical and projected cash flows;
[Link]. The credit policies establish a framework e) An analysis of repayment capacity, focused on
for investment and granting decision making the future, based on various scenarios;
of loans and reflect the tolerance for credit risk by f) The legal capacity of the borrower or counterparty of
part of the institution. take responsibility;
g) For commercial credits, the execution expertise of
[Link]. It is necessary for policies to be communicated
businesses and the state of the borrower's economic sector
timely reform, implemented at all levels of the institution
and its position within this sector;
through appropriate procedures and periodically reviewed
h) The proposed credit terms and conditions, including
to take into account the changes in internal circumstances and
the clauses that aim to limit future changes
external. Any significant deviation or exception to the policies no risk for the borrower; and
must be communicated to the administration body and the subject of
If that is the case, the adequacy and enforceability
corrective measures. the guarantees or collateral.
[Link]. Credit policies must, at a minimum, include:
[Link].3. This information can also serve as a basis
a) General areas of credit in which the institution is for credit classification, within the framework of the rating system
ready to penetrate or is prevented from participating, internal of the institution.
such as the type of credit facilities, the type of [Link].4. Institutions must know the borrower to whom
guarantees, types of borrowers, geographical areas they intend to grant the credit. Before entering into any
or economic sectors in which the institution can credit relationship, the institution must familiarize itself with
focus the borrower or counterparty must be aware that it is the same
b) Detailed and formalized evaluation process or enjoy a good reputation and credibility. In particular, they must be
review, management and documentation of credits; implement strict policies to avoid involvement
c) Credit approval authority at different levels with individuals related to fraudulent activities and others
hierarchical, including exceptions such as granting of crimes. This can be materialized in various forms,
credit beyond the prescribed limits; including the request for references of known parties, access
d) Limits of individual concentration and groups of to the credit registry centers, familiarization with people
correlated counterparts, industries or sectors responsible for the management of the company and verification of references
specific economic, geographical areas and products personal and financial condition. However, the institutions do not
specific. Institutions must ensure that they must grant credit only because the borrower or counterparty
your internal limits of risk exposure is known or is regarded as being highly reputable.
they respect any restrictions or prudential limits [Link].5. Institutions must have procedures to
established by the Bank of Mozambique; identify situations in which, in credit analysis, it is appropriate
e) Authority to approve the establishment of reserves or classify a group of borrowers as related parties
provisions for probable losses and clean-ups; and, in this way, as a single borrower. This includes aggregating
f) Fixação de preços para os créditos; exposures to groups of accounts with financial interdependence,
g) Role and responsibilities of the area/personnel involved in corporate or non-corporate, under the same ownership or
granting and management of credit; control or with strong ties (such as common management, ties
h) Guidelines for managing troubled loans; and relatives, among others).
i) Explicit guidance for internal notation systems In syndicated loans, the participants must
(rating), including the definition of each category carry out your own credit risk assessment and review of
of risk, criteria to be observed when assigning union terms, before adherence. Each institution must
the notation, as well as the circumstances in which analyze the risk and return of syndicated loans, of the same
Deviations from the criteria may occur. mode that other loans.
18 DE SETEMBRO DE 2013 613

The pricing of credits must be such that [Link].5. The granting of credit to related entities,
cover all embedded costs and compensate the institution for whether they are companies or individuals, it constitutes an area with
risks incurred. When evaluating credit and the terms under which it will be potential for abuse. The institutions that grant credit to these
Granted, institutions must evaluate the risk-return relationship. entities must do so under conditions of full competition
expected, taking into account, as much as possible, the conditions and monitor the amount of credit granted. The controls
financial and non-financial (for example, guarantees, clauses must be implemented requiring that the terms and conditions
restrictive, etc.). In the risk assessment, institutions must these credits are no more favorable than those applicable
also assess likely adverse scenarios and their possible to other borrowers in similar circumstances and imposing
impacts on borrowers or counterparts. strict limits on such credits.
[Link].8. When considering potential credits, the institutions Related party transactions must be
they must recognize the need to create provisions for
submitted for approval by the governing body. Any
expected losses and maintain a sufficient level of capital to
member of the management body who comes to benefit from this type
absorb the risks and unexpected losses. The institution must
always keep these considerations in mind when making granting decisions The transaction should not be part of the approval process.
of credit, as well as in the monitoring of the total portfolio. 2.3.4. Setting limits
[Link].9. Institutions may use risk mitigants [Link]. One of the important elements in risk management
credit such as guarantees, collateral, credit derivatives credit is to establish limits of exposure to a single borrower
or other elements to mitigate the inherent risks of credit the group of borrowers, encompassing elements both from the assets
individually. However, credit transactions must patrimonial, wants extrapatrimonial.
to be assumed first about the robustness of the capacity [Link]. When developing their own limits,
of the borrower refund. The mitigants of credit risk
the institutions must be aware of the limits defined by the Bank
should not be a substitute for a comprehensive assessment
of the borrower or counterparty, nor can they compensate for the lack from Mozambique.
of information. It must be recognized that any measure The setting of limits must be based on robustness
the execution of the credit contract typically eliminates the margin creditworthiness of the counterpart, in the legitimacy of the credit request,
of profit on the operation. Furthermore, the institutions must be on the economic conditions and the institution's risk tolerance.
aware that the value of the guarantee may be affected by Limits should also be defined for the respective
the same factors that led to the reduction of possibilities of products, specific industry or economic sectors and regions
credit recovery. geographical, in order to avoid the risk of concentration.
[Link].10. Institutions must have policies that cover [Link]. Credit limits must be reviewed regularly,
criteria for the acceptance of various forms of guarantee at least once a year, or more frequently, if
the procedures for continuous evaluation of such guarantees the credit quality of the counterparty deteriorates. All requests
and its feasibility. Additionally, institutions must requests for credit limit increases must be substantiated.
assess the level of coverage in relation to credit quality
and legal capacity of the borrower. In the credit decision process, 2.4. Measurement, Monitoring and Systems
institutions should only consider explicit guarantees Risk Management Information
and not those that can be considered implicit, such as 2.4.1. Measurement and Monitoring
the Government's early support.
[Link]. Institutions must have methodologies that allow them
[Link]. Approval of New Credits and Extension allow to quantify the risk involved in individual exposures
of Existing Credits: to borrowers or counterparts. Institutions must also be
[Link].1. To maintain a healthy credit portfolio, the capable of analyzing credit risk at the product level and of
the institution must have a formal evaluation and approval process total wallet, to identify any potential sensitivities or
of credit. The approvals must be made in accordance with the concentrations.
institution's policies and procedures. The documents and the
[Link]. The process of measuring credit risk must have in
records must be organized in such a way that they facilitate
the audit will verify to what extent the procedures of contains the nature of specific credit (loans, derivatives,
etc.) and contractual and financial conditions (maturity, interest rate of
approval was fulfilled and identify all stakeholders
of the credit process, from the individual(s) and/or committee(s) interest, etc.); (ii) the behavior of the exposure profile against the
that provided the input data to those who were part of the potential market movements; (iii) the existence of collateral5
decision making. or guarantees6the potential for non-compliance based on the
[Link].2. Each credit proposal must be subject to analysis internal risk notation.
careful by a credit analyst with compatible experience [Link]. Institutions must use measurement techniques that
with the size and complexity of the operation. An effective process are appropriate to the complexity and levels of risks involved
of evaluation observes the minimum information requirements in the in their activities.
what should be the basis for the analysis. [Link]. The analysis of data on credit risk must be
[Link].3. Credit policies must establish requirements carried out with adequate frequency and the results reviewed and
for the approval of new credits, renewal of credits compared to the relevant limits, such analysis should be
existing and/or alteration of the terms and conditions of the credits carried out based on robust data and subject to validation
previously approved. The information received serves as periodic.
basis for any internal assessment assigned to credit and its
accuracy and adequacy are crucial for the granting decision
of credit.
5
Collateral - guarantees the fulfillment of a certain obligation through
[Link].4. The credit grant approval process
about the value or income from certain assets of the debtor (consignation of income,
an institution must assign responsibility for decisions pledge, mortgage, credit privileges, and right of retention.
take credit and appoint personnel with authority to approve credits 6
Guarantee - ensures the fulfillment of a specific obligation through
or change their conditions. of other assets, other than those of the debtor (guarantee and surety).
614 I SERIES — NUMBER 75

The management of institutions must carry out regularly e) Ensure, if applicable, that the collateral or guarantees
stress tests of the main concentrations provide adequate coverage in relation to
of credit risks and analyze their results, to the current situation of the debtor; and
identify and respond to potential changes in conditions f) Identify and classify potential problematic credits
of the market (economic cycles, interest rates, conditions in due time.
of liquidity) that may have a negative impact on your [Link].7. Institutions must have a system that
performance. allow monitoring of the quality of the credit portfolio
[Link]. Credit Administration: on a daily basis and the taking of corrective measures always
if there is any sign of deterioration. Such a system
[Link].1. Credit management is a critical element
it must allow the institution to verify (i) to what extent the
in maintaining the security and solidity of an institution.
loans are being repaid in accordance with the terms
Once credit is granted, it is the responsibility of the function contractual, (ii) the adequacy of the provisions, (iii) whether the overall profile
in business, sometimes in conjunction with a team
risk is within the limits established by management and (iv)
credit administration support, ensure that the credit
compliance with regulatory limits.
is properly managed. This includes keeping the credit file
[Link].8. The establishment of a monitoring system
updated, obtain current financial information, send
effective assists senior management in monitoring quality
renewal notifications and prepare various documents, such as
global of the total portfolio and its trend. Consequently,
like loan contracts.
management can adjust or reassess its strategy and policy
[Link].2. In credit administration, institutions must
credit compliance before facing major
garantir:
contradictions. The institution's credit policy must include,
a) The efficiency and effectiveness of operations management explicitly, guidelines related to monitoring
of credit, including the control of documentation, the credit risk and establish, at a minimum:
contractual requirements, guarantees, among others;
a) Assignments and responsibilities of the people in charge
b) The accuracy and timeliness of the information provided
for the monitoring of credit risk;
to management information systems;
b) Need for evaluation and analysis techniques (for
c) The adequacy of controls over all procedures
individual loans and global portfolio;
back-office; e
c) Follow-up frequency;
d) Compliance/observance of policies and procedures
d) Periodic reassessment of guarantees and collateral;
prescribed, as well as applicable laws and regulations.
e) Frequency of visits to the client; and
[Link].3. For the different components of the administration f) Identification of any deterioration in any
for credit to function properly, top management must loan.
understand and demonstrate that it recognizes the importance of this
element of monitoring and control of credit risk. [Link]. Internal Risk Notation and Provisioning:
[Link].4. Credit processes must include all of the [Link].1. An important tool for monitoring
necessary information to assess the current financial situation of the quality of individual credits, as well as for the portfolio
of the borrower or counterparty, as well as to track the decisions global, it is the use of an internal risk notation system.
taking and the credit history, namely: [Link].2. A good internal risk notation system
a) Credit request; structured allows to differentiate the level of credit risk in
b) Evidence of approval; different exhibitions of an institution, as well as determine,
c) Updated financial information; more precisely, the general characteristics of the portfolio of
d) Records and dates of all credit revisions; credit, the concentration and problematic credits, and adjust the
e) Records of all guarantees offered (properly provisions for losses. In determining provisions for losses,
evaluated and formalized; institutions must ensure that the minimum requirements
f) Credit contract; and
established by the Bank of Mozambique are observed.
g) Internal risk notation.
[Link].3. As a rule, an internal risk notation system
[Link].5. Institutions must develop and implement adds credits in various risk classes, defined both
comprehensive procedures and information systems for internally as well as externally by supervisory entities and
monitor the condition of your credit portfolio by transactions
others. Simpler systems can encompass various categories,
individuals and by borrowers. These procedures must define
criteria for identification and reporting of potentially problematic credits ranging from satisfactory to unsatisfactory; however, more systems
problematic and other transactions to ensure that the complexes still have credit gradations within each
they are subject to more frequent monitoring, category, in order to truly differentiate the relative risk of
as well as possible corrective actions, classification and/or credit that they represent.
provisioning. [Link].4. When developing their systems, institutions
[Link].6. An efficient credit monitoring system they must decide whether to assign a risk rating to the borrower
must include measures for: or counterpart, to the risks associated with a specific operation,
a) Ensure that the institution understands the current situation or to both.
borrower's financial institution or counterparty; [Link].5. Internal risk notations are an important
b) Ensure that all credits are in compliance instrument of scaling and credit risk control.
with the existing clauses; To facilitate timely identification, the notation system
c) Monitor the client's use of credit lines The institution's risk internal should respond flexibly.
approved; to the indicators of real or potential deterioration of the risk of
d) Ensure that the projected cash flows, related credit (for example, financial position and business situation of
large credits meet service requirements borrower, account behavior of the borrower, compliance
of the debt; of the contractual terms, value of the guarantees, etc.).
18 DE SETEMBRO DE 2013 615

[Link].6. Credits with deteriorating ratings must c) Review of Guarantee Documents and Titles
to be the object of increased supervision and monitoring Institutions must verify the recoverable amount.
for example, through more frequent visits from officials of of the loan updating the values of the guarantees
credit and inclusion in a list that should be regularly reviewed available through a formal assessment. The
by the direction). warranty documents must also be reviewed
[Link].7. Internal risk notations may be used to ensure the authenticity and enforceability of
by line managers in various departments to track the the same and respective contracts;
current characteristics of the credit portfolio and help to determine d) Monitoring and Review Report – The
the necessary changes to the institution's credit strategy. problematic credits should be subject to review
Consequently, the governing body and top management the more frequent monitoring. The review
they should also receive periodic reports on the state of it must allow for the update of the status and progress
credit wallet based on such notations. of credits, as well as the progress of the plan
[Link].8. The classifications assigned to each of the borrowers recovery. The progress made must be
you counterparts at the moment the credit is granted must communications to the governing body.
be magazines periodically and reclassified. 2.4.2. Management Information Systems
[Link].9. To ensure that the internal notations are
[Link]. The effectiveness of the credit risk measurement process
consistent and adequately reflect the quality of credit
the quality of an institution largely depends on
on an individualized basis, the responsibility to establish
two management information systems. The information generated
To confirm such notations, it must be assigned to a function.
from these systems allow the administrative body
of credit review, regardless of the one that originated it.
and at all levels of management the compliance with the respective
The consistency and rigor of the notations must be examined
supervisory functions, including the determination of the level
periodically by a functional area, namely a group
appropriate capital that the institution must maintain. Therefore,
regardless of credit review.
the quality, the detail, the relevance, and timeliness of
[Link]. Management of Problematic Credits: information is a crucial element. In particular, the information
[Link].1. Institutions must establish a system that about the composition and quality of the various portfolios, including
allow them to identify potentially problematic credits, on a consolidated basis, it should allow management to quickly assess
as long as there are options to remedy them. The credits and with accuracy, the level of credit risk to which the institution
problematic issues must be managed within the scope of a process is exposed and to determine if the performance of the institution
specific corrective. Are you or are you not achieving the objectives of your risk strategy?
[Link].2. The responsibility for the management of credits of credit.
problems can be attributed to the business unit that [Link]. Institutions must have information systems.
to a specialized recovery section, of management that allow for the identification of any concentrations
or the combination of the two, depending on the size and nature. of risk in the credit portfolio and exposures close to the limits
of credit, as well as the causes of the problems. When established. The adequacy of the scope of information must be
if the problematic credits in an institution are significant, subject to periodic review by line managers, senior management
the credit origination function should be separated from the function the governing body to ensure that it is in
of recovery. The additional resources, expertise, and greater focus consonance with the complexity of the business.
concentrate from a specialized recovery section [Link]. The information system must be able to aggregate the
usually improve the results of collection. credit granted to individual borrowers and economic groups
[Link].3. The management process for problematic credits must and allow the reporting of exceptions to credit risk limits
to encompass the following basic elements: on a timely and realistic basis.
Negotiation and Follow-up - When dealing with 2.5. Internal Controls
borrowers in the sense of implementing the plans 2.5.1. Risk Review
in recovery, institutions must undertake [Link]. Institutions must establish a mechanism
proactive efforts, maintaining frequent contact of continuous and independent evaluation of the management process
and internal records of follow-up actions. of credit risk. The objective of this review is to assess the process
Rigorous efforts made in the initial phase often credit administration, the accuracy of the notations, including
we prevent litigation and losses in loans; the adequacy of provisions for losses and the quality of the portfolio
b) Development of Corrective Strategies - Measures total credit.
appropriate corrective actions, such as restructuring [Link]. All credits must be subject to review
loan, increase in credit limit of risk, at least, quarterly. More frequent reviews
or reduction of interest rates, sometimes allow, should be carried out for new credits, in which the institutions
improve the borrower's repayment capacity. they may not be familiar with the borrower, and for
Meanwhile, this effect depends on the state of the business. the credits with unfavorable ratings and higher probability
of the borrower, the nature of the problems faced and, of non-compliance.
The results of this review must be properly
but more importantly, of commitment and dedication
documented and communicated directly to the agency
of the borrower to settle the loan. Although of the administration or a committee designated by it.
the corrective measures sometimes produce results [Link]. Institutions must carry out credit reviews
positive, institutions must be very cautious with updated information on the financial conditions
in your adoption and ensure that they do not and the business affairs of the borrower, as well as the evolution of the account.
incentivem os devedores a entrarem em incumprimento The exceptions observed in the monitoring process
intentionally. the competent authority must approve credit must be equally assessed, in order to measure the
the action plans before their implementation; impact on the debtor's solvency.
616 I SERIES - NUMBER 75

[Link]. The credit assessment must be carried out on a basis ii. Increasing concentration of assets and liabilities;
consolidated at the group level, to assess the connections between iii. Decrease in results or their projections;
entities of the group in which the borrower is included. iv. Deterioration of the quality of the credit portfolio;
v. Accelerated growth of financed assets by
3. Guidelines for Liquidity Risk Management
potentially volatile liabilities;
3.1. Introduction vi. High amounts of extra-patrimonial exposures;
3.1.1. The liquidity risk is the possibility of an institution vii. Deterioration of the evaluation made by third parties (rating
facing difficulties in honoring your obligations (especially, external to the institution;
in the short term) as they mature or in ensuring the viii. Negative advertising;
refinancing of the assets held on its balance sheet, without incurring ix. Significant increase in withdrawals from deposits
in significant costs or losses (funding liquidity risk). When retail;
the market conditions in which the institution operates do not allow x. Increases in currency mismatches;
that it disposes of certain assets at market prices, but xi. Elimination or reduction by the correspondent banks,
only below these, one is faced with what is designated as risk of credit lines;
market liquidity risk. xii. Frequent incidents of approach or violation of
3.1.2. The liquidity risk is considered one of the greatest risks. internal or regulatory limits;
to which institutions are exposed and arises when the xiii. Unsustainable practice of competitive pricing that
liquidity reserves provided by liquid assets do not can jeopardize the stability of the institution; and
are sufficient to cover the obligations as they mature. xiv. Difficulties in accessing long-term financing
In such circumstances, institutions turn to the market deadline.
to meet your liquidity needs. Meanwhile, the 3.1.8. The management of liquidity risk is not limited to only
financing conditions through the market depend on the analysis of the institutional asset and non-asset position
liquidity existing in it and the ability to take on credit. (to make projections of future cash flows), but also
On the other hand, an institution with a short liquidity position. the way the institution responds to your needs of
may be forced to carry out transactions at high costs, financing. The latter includes stages such as (i) identifying
resulting in losses and, in the worst-case scenario, insolvency of markets in which the institution has access to financing; (ii)
institution, if it is unable to carry out transactions even understand the nature of these markets; (iii) assess the frequency
current market prices. actual and future use of such markets; and (iv) monitor the
3.1.3. The institutions have high extra-patrimonial exposures signs of a breach of trust.
or that largely rely on large depositors and/or that 3.1.9. The formality and sophistication of management processes
they register a rapid growth of assets, they carry risk established risks to manage liquidity risk must reflect
of relatively higher liquidity. For this reason, in these the nature, dimension, and complexity of the activities of a
conditions, institutions must focus their attention on institution. A solid management of liquidity risk employed in
liquidity. measurement, monitoring and control is crucial for viability
3.1.4. The liquidity risk should not be viewed in isolation, of any institution. Institutions must have a
since financial risks are not mutually exclusive deep understanding of the factors that can give rise to risk
and the same is, in most cases, triggered by others of liquidity and implement mitigation controls.
risks, such as credit risk and market risk. For example, a 3.2. Supervision by the Administration Body
institution that increases credit risk through concentration Top Management
of assets, may be increasing, simultaneously, the risk of
3.2.1. Supervision by the Administrative Body
liquidity. Similarly, the entry into default of a
high amount credit or a change in the interest rate [Link]. The prerequisites for effective risk management
it can have an adverse impact on the institution's liquidity position. of liquidity comprise (i) an administrative body
Furthermore, if the management misjudges the impact on informed and enabled; (ii) capable management; (iii) staff
liquidity, resulting from its entry into a new line of business with relevant experience and skills; and (iv) systems
the product, the strategic risk of the institution may increase. and efficient procedures.
[Link]. The governing body must understand the profile
3.1.5. An incipient liquidity problem
the liquidity risk of the institution and the tools used
can manifest itself, at first, in the system of
for your management.
monitoring of the institution as a declining trend
[Link]. The responsibilities of the management body
two indicators defined for the purpose, with potential include:
long-term consequences on results, capital and in
continuity of it. a) Approve the relevant strategy and policies
3.1.6. Management must monitor on liquidity management;
carefully the early warning indicators7and to carry out analyses b) Provide guidance on the level of tolerance
substantial whenever necessary. These indicators to the liquidity risk;
do not always indicate or lead, necessarily, to existence c) Establish an appropriate structure for management
of liquidity problems in an institution, but they have the potential of liquidity risk and define lines of authority
to trigger. and responsibility for managing exposure to risk
3.1.7. The early warning indicators may be of a nature of liquidity;
quantitative or qualitative. Examples of such indicators are: d) Appoint top managers with skills to manage
i. Decreasing trend or significant increase in risk the liquidity risk, delegating authority to them
in any area or line of business or activity; necessary to perform their tasks;
e) Continuously monitor performance
of the institution and the global profile of liquidity risk
7 Early Warning Indicators - EWI through the reading and review of several reports;
18 DE SETEMBRO DE 2013 617

f) Ensure that top managers take the steps [Link]. The liquidity risk strategy defined by the body
necessary to identify, measure, monitor of administration, it should state concrete policies about aspects
and to control liquidity risk; and specifics of liquidity risk management, namely:
g) Review the adequacy of the contingency plans a) Composition of Assets and Liabilities - The strategy
from the institution for liquidity management. should prioritize the diversification of assets and liabilities
3.2.2. Oversight by Top Management in order to maintain liquidity. Risk management
of liquidity and that of assets and liabilities must be
[Link]. Top management is responsible for the implementation
integrated, in order to avoid high associated costs
of appropriate policies and procedures, always keeping in mind
to a potential need for quick reconfiguration
the strategic line and the risk appetite defined by the body of the assets and liabilities, changing the paradigm
of management. of maximizing profitability for increment
[Link]. To effectively oversee daily management of liquidity.
And in the long term regarding liquidity risk, top management must: b) Diversification and stability of Liabilities - An
a) Develop and implement procedures and practices concentration of funding8exists when a decision
that they translate the goals, objectives, and tolerance to or a single factor has the potential to result in a
risks defined by the administrative body in sudden and significant fundraising.
operational standards that are well assimilated Given that such a situation may result in a risk still
by the institution's collaborators and consistent with greater, the governing body and top management
the intention of this body; must establish guidelines related to
b) Adhere to the lines of command and responsibilities funding sources and ensure that the institution
approved by the governing body for management have diversified sources to meet the needs
of liquidity risk; liquidity daily rates.
c ) To o v e r s e e t h e i m p l e m e n t a t i o n a n d m a i n t e n a n c e c) An institution can be immune to conditions of scarcity.
de sistemas de informação de gestão e outros sistemas of liquidity in the market if your liabilities are
of identification, measurement, monitoring and control derivatives from relatively stable sources. For
of the liquidity risk of the institution; analyze in detail the stability of liabilities
d) Establish effective internal controls of the process and from the sources of funding, the institution needs
of liquidity risk management and ensure that the identify the liabilities, which can be:
i. Maintained in the institution, in any circumstances-
the same are communicated to all employees; and
e) Ensure the review of contingency plans stances;
timely liquidity. ii. Gradually withdrawn, in case problems arise; and
3.2.3. Liquidity Management Structure iii. Immediately removed at the first sign
of problems.
[Link]. The responsibility for managing global liquidity
d) Liquidity management in various currencies - The institution
the institution should be delegated to a specific group, well
must have a liquidity management strategy in
identified within the institution. This can be instituted under the
various currencies.
form of an Asset and Liability Management Committee
e) Strategy for dealing with liquidity breaks–
Liability Committee – ALCO), composed of top managers
The institution must implement a strategy to
the functional area of treasury.
lidar with potential liquidity breaks whether they are
[Link]. Given that liquidity management is a function
temporary, whether long-term. The strategy
strictly technical, requiring expertise and knowledge
must take into account that, in situations
specialized, it is important that the responsible technicians for
during a crisis, access to the interbank market can be
this task requires not only relevant knowledge, but difficult and burdensome.
also a good understanding of the nature and level of risk of
[Link]. The liquidity strategy must be documented in a
liquidity incurred by the institution, as well as the mechanisms
liquidity policy is communicated to senior management, to the ALCO
for your management.
and to the units that deal with this matter in the institution. The same
[Link]. It is crucial to have links or proximity
must be reviewed at least annually, in order to ensure that
among the individuals responsible for liquidity management and the
stay updated.
in charge of monitoring market conditions, and
still with other individuals with access to critical information. This 3.3.2. Liquidity Policies
is particularly important in the construction and analysis of scenarios [Link]. The governing body must ensure the existence
of effort (stress). of appropriate policies that guide the risk management process
3.3. Strategy, Policies, Procedures, and Limits of liquidity in the institution. Although the specific details may
vary from institution to institution, depending on the nature
3.3.1. Liquidity Risk Strategy
from your activity, the liquidity policy must have the following
[Link]. Each institution must have an appropriate strategy elements:
for daily liquidity management. The strategy should state
a) General liquidity strategy (short and long term), goals
the general approach that the institution should adopt to face
the specific objectives regarding risk management
to your liquidity needs, indicating the quantitative targets
of liquidity, strategy formulation process
and qualitative. The strategy must also enshrine
the level at which it is approved within the institution;
the objective of safeguarding the financial solidity of the institution
and its ability to withstand adverse shocks that affect
drastically the market conditions. 8 Source of resources or financing.
618 I SERIES — NUMBER 75

b) Attributions and responsibilities of individuals who 3.4.2. The management of the institution must be able to identify
perform liquidity risk management functions, and to correctly and promptly cite the main sources
including the management of the balance sheet structure, formulation of liquidity risk. To appropriately identify
of prices (pricing), product sales techniques and the management must understand the current and future risks
serviços, plano de contingência, informação a reportar to which the institution may be exposed. Management must always be
to management, lines of authority and responsibilities for alert about the emergence of new sources of liquidity risk at the level
decisions about liquidity; the transactions and the wallets.
c) Risk management tools to identify, measure, 3.4.3. Regarding the management information system,
monitor and control liquidity risk (including the various areas or functional units related to the
the types of limits and ratios that exist and rationality treasury activity and the risk management function must
to establish these same limits and ratios); be integrated. Additionally, management must ensure that
d) Contingency plan to deal with crisis scenarios proper and timely manner, the flow of information between the
of liquidity; front office, back office, and middle office, in an integrated manner.
e) Approach to liquidity management in different However, the respective reporting lines must be separate.
coins; and to ensure the independence of these functions.
f) Daily liquidity management approach. 3.4.4. Periodic reviews must be conducted to assess whether
[Link]. To be effective, the liquidity policy must be the institution complies with its policies and procedures
communicated to senior management, to the ALCO and the units of the of liquidity risk. The periodic reviews of the management process
institution that deal with this matter. risk should encompass any significant changes in
[Link]. The liquidity policy must be reviewed at least once. nature of the acquired instruments, the limits and the controls
once a year and whenever there are any material changes interns introduced since the last review. The positions
no risk of current and future liquidity of the institution. Such those that exceed the established limits must receive prompt
changes may result from internal circumstances (such as management intervention, which should be resolved according to the process
changes in business focus) or external circumstances (such as described in the approved policies.
changes in economic conditions). 3.4.5. Measurement and Monitoring of Risk
[Link]. The review represents an opportunity for the institution of Liquidity:
adjust the liquidity policy in light of your management experience [Link]. The institution must have a measurement system
in this matter and the evolution of your business. Any exception the monitoring of liquidity risk.
material or frequent in politics is an important indicator for [Link]. At a more elementary level, measuring liquidity involves
medir a sua e cácia e impacto no per l de risco de liquidez da the assessment of all cash inflows and outflows of the institution,
institution. in order to identify the potential of any debt power
3.3.3. Procedures and limits last for a long time. This also includes funding
[Link]. Institutions must establish procedures, of extrapatrimonial commitments.
appropriate processes and limits to implement your policy [Link]. Several techniques can be used to measure
of liquidity. The procedures manual must describe the liquidity risk, from simple calculations and static simulations
explicitly the operational processes and procedures (based on existing positions) to sophisticated techniques
necessary to carry out the relevant risk controls of of modeling. Once all institutions are affected
liquidity. due to changes in economic and market conditions,
The manual must be reviewed and updated periodically, The monitoring of the trend of these conditions is crucial.
at least annually, to include new activities, changes in the management of liquidity risk.
in the systems and in the risk management approach. [Link]. Formulating hypotheses about needs
[Link]. In addition to maintaining liquidity as defined by future defunding constitutes an important aspect of management
Bank of Mozambique, the governing body and management of of liquidity. Although certain cash inflows may be anticipated
topos must establish limits on the nature and magnitude or calculated easily, institutions should adopt
of liquidity risk they are willing to take on. The limits hypotheses about future liquidity needs for the short term
should be reviewed and adjusted periodically and whenever the in the long term. One of the factors to consider is the crucial role that
risk tolerance levels change. the institution's reputation plays in the ability to access
[Link]. By imposing risk exposure limits, management promptly to financing resources and at reasonable costs.
The top must take into account the nature of the activity For this reason, the staff responsible for managing global liquidity
and the institution's strategy, past performance, level must be aware of any public information or any
of results, existing capital to absorb potential losses another nature (e.g., announcement of a decrease in results or of
and the risk tolerance established by the governing body. risk rating assigned to the institution by rating agencies
The complexity of the balance determines how much and what type of limits that may have an impact on the market and on public perception
the institution must establish for the day-to-day and long term. about the institution's financial condition.
[Link]. Although the limits do not prevent liquidity crises, [Link]. An effective measurement and monitoring system
exceptions to them may signal excessive risk, a The risk of liquidity is not only useful in times of crisis.
inadequate risk management or need for review of goals liquidity, but also maximizes results through
the limits. efficient use of resources.
[Link]. The following are some measurement techniques
3.4. Measurement, Monitoring and Systems
and liquidity monitoring commonly used by
de Informação de Gestão de Risco
institutions.
3.4.1. In addition to the above-mentioned institutional structure, a
effective liquidity management should include information systems for 3.4.6. Contingency Liquidity Plans:
management that allows to identify, measure, monitor, and control [Link]. In order to develop a management framework
the present and future liquidity risk, and report to top management detailed liquidity, institutions must have a plan for
and to the administrative body. lidar com cenários de esforço (stress). Tal plano, comummente
18 DE SETEMBRO DE 2013 619

known as the Liquidity Contingency Plan d) Counter clear policies and procedures that allow
Funding Plan – CFP encompasses a set of policies, for the bank's management to make timely decisions and
procedures and action plans to respond to a breakdown with sufficient information, take measures
serious in the institution's ability to finance some of its of contingency quickly and proficiently,
activities in a timely manner and at reasonable costs. including:
[Link]. A CFP is a projection of cash flows i. Clear specification of functions and responsibilities,
and sources of financing of an institution in scenarios including authority to trigger the plan.
adverse (of effort). To be effective, the CFP must represent Establishment of a formal 'crisis team'
the best estimate of management on the changes in the balance that can facilitate internal coordination and decision making
may result from liquidity or credit events. The CFP may be of decision during the liquidity crisis;
a useful platform for managing liquidity risk both in the short term, ii. Names and contacts of team members
long-term care. Additionally, it allows the institution to ensure responsible for the implementation of the CFP
financial management of routine situations in a prudent and efficient manner and the location of them; and
and extraordinary liquidity. iii. Designation of alternatives for the functions
[Link]. For the integration of daily liquidity risk management, main.
The liquidity scenarios ensure that the institution is better e) Indicate the management information system between the ALCO,
prepared to respond to an unexpected problem. In this traders, the Bank of Mozambique and the public in
In essence, the CFP is an extension of the continuous management process.
general.
of liquidity and formalizes the objectives of this management, ensuring:
[Link]. To facilitate the management of severe liquidity breakdowns
a) Maintaining a reasonable level of assets in a timely manner, the plan must clearly establish the process
liquids; of decision making regarding what actions to take, in which
b) The measurement and projection of funding needs moment, who can take them, what matters need
throughout various scenarios; and be escalated to the highest level of the institution's management, who
c) The management of access to funding sources. it must be noted that reports need to be produced and
[Link]. Liquidity crises do not always manifest. for whom, and what steps can be taken to
gradually. In cases of sudden liquidity disturbances, it is improve liquidity or to compensate cash flows. The plan
It is important for the institution to present itself as organized, calm, and efficient. should include how and in what situations they should be contacted
in meeting its obligations to its stakeholders. external parts such as the Bank of Mozambique.
Since these situations require a spontaneous action, the [Link]. The CFP must include a strategy on both sides
institutions that have plans to deal with them can assets like two liabilities. The strategy on the asset side must
face the liquidity problem in a more efficient and effective way. include (i) situations in which the surpluses can be settled
The CFP ensures that management and key personnel are two monetary market assets, (ii) situations in which the assets
ready to respond to such situations. liquids or long-term can be sold, etc. The strategy
[Link]. The liquidity of the institution is highly sensitive on the liabilities side, it specifies policies such as the policy of
the negative trends in credit, capital, or reputation. prices for financing, the institution or the dealer that can
A deterioration in the institution's financial conditions provide assistance in times of liquidity crises, policy for
(based on the quality indicators of assets, early redemption at the request of clients, use of the facilities of
yield, or capital), in the composition of management and others Bank of Mozambique, etc..
concerns may result in decreased access [Link]. Top management must review, update, and test
aofunding. The CFP at least once a year, for approval by
[Link]. The sophistication of the CFP depends on the dimension, nature,
administrative body, or more frequently when the
business complexity, exposure to risk and structure business or market circumstances change. The test must
of the institution, but at a minimum, it must: ensure that the functions and responsibilities are appropriate and
a) Anticipate all funding and liquidity needs understood, confirm if the contacts are updated, prove the
through: transferability of funds and collateral (especially between countries
i. Analysis and realization of quantitative projections and entities) and check if there is legal and operational documentation.
of all the flows of assets resources
necessary to execute the plan in a reduced time.
significant patrimonial and extrapatrimonial
[Link]. The CFP must be consistent with the plan
as well as all related effects;
business continuity of the institution and being operational
[Link] of potential origins and applications whenever the business continuity arrangements are
of funds; and driven. Thus, the institution must ensure that
iii. Establishment of alert indicators for there is a need for coordination and clarity among the teams that manage issues
management for potential risk levels related to liquidity and business continuity.
default
3.4.7. Cumulative Escalation of Maturities
b) Project the funding position of the institution in situations Residuals:
changes in liquidity, both temporary and of
long term. [Link]. The scheduling of residual maturities is a
c) Identify, quantify, and explicitly classify, important tool for comparing cash inflows and outflows
all sources of funding by preference, such quer numa base diária, quer por uma série de períodos especí cos.
like: The time horizon in the scheduling of maturities is
i. Reduction of assets; extreme importance and, in some way, depends on nature
ii. Modification or increase of the liabilities structure; and and the sources of resources of the institution. The institutions that
iii. Use of alternatives to control fluctuations deposits with confidence in short-term funding sources tend to
in the balance. to focus mainly on liquidity management of very
620 I SERIES - NUMBER 75

short term. In contrast, other institutions may manage c) Other Ratios Based on Balance Sheet Information
actively your resource needs for a period These are examples of ratios commonly used by
relatively long. institutions to monitor liquidity levels
[Link]. In the short term, the cash flow can be estimated current and potential the following: total credit/
with greater accuracy and such estimates are of greater importance, /total deposits, liquid assets/liabilities payable,
once they indicate actions to be taken promptly. loans contracted/total assets.
Additionally, analyses for relatively long periods [Link]. In addition to the prudential requirements required by the Bank
allow the institution to maximize the opportunity to manage from Mozambique the administrative body and top management
anticipate the gap before it crystallizes. Thus, they must establish limits on the nature and extent of the risk
institutions should use short time bands to measure of liquidity that they are willing to assume. The limits must be
short-term and longer-term exhibitions for exhibitions of periodically reviewed and adjusted whenever conditions and
medium and long terms. It is suggested that institutions calculate the levels of risk tolerance change.
gaps (i) daily (for one or two weeks following); (ii) [Link]. By limiting exposure to risk, top management must
monthly (for the following semester or year); and (iii) quarterly, consider the strategy and activities of the institution,
subsequently. the performance in previous years, the existing capital for
[Link]. When estimating cash flows, the aspects that are absorbing unexpected losses and the level of tolerance defined by the
the following must be taken into consideration: administration body. The complexity of the balance determines
a) Necessidades de recursos decorrentes de compromissos the number and type of limits that the institution must establish
extrapatrimonial for day-to-day and long term. Although the limits do not prevent
b) Customer behavior, instead of restricting themselves that liquidity crises occur, exceptions to the limits can
at contractual maturity. In this aspect, the experience be indicators of excessive risks or inadequate management
past plays a fundamental role in of liquidity risk.
definition of assumptions; 3.4.9. Foreign Currency Liquidity Management:
c) Seasonal and cyclical cash flows; and
[Link]. Each institution must have a system to measure,
d) Increases or decreases in liquidity susceptible
to monitor and control your main liquidity positions
to occur during various phases of the economic cycle.
coins in which it is active.
[Link]. Institutions must have sufficient liquidity to
[Link]. The institution must assess its needs.
respond to situations regarding credits and deposits, and as a measure
As a precaution, they should maintain a reasonable margin of excess.
of liquidity in foreign currency and of mismatch
(mismatch) acceptable in combination with your commitments
of liquidity. To ensure that such excess is maintained, the
in national currency, and perform separate analyses of your strategy
management must estimate liquidity needs in different
for each currency.
scenarios.
[Link]. The size of mismatches in foreign currency
3.4.8. Ratios and Liquidity Limits: must take into account:
[Link]. Institutions can use a variety of ratios a) The institution's ability to raise funds in the market
to quantify your liquidity positions. These ratios exchange
can also be used as limits for management of b) The possibility of extending the existing facilities
liquidity. However, they have no meaning at all of obtaining resources in foreign currency
unless they are used regularly and interpreted having
in the domestic market;
take qualitative factors into account. The ratios must always be
c) The ability to transfer excess liquidity into a
used in connection with more qualitative information about currency for another and between jurisdictions and entities; and
of indebtedness, such as the possibility of
unexpected increase in withdrawals, decrease in lines of d) The convertibility of the currency in which the institution is
credit, the size of transactions or long-term funds find active.
available to the institution. [Link]. The institution must have the care and the capacity
[Link]. Once asset and liability management decisions to manage exposure to liquidity risk arising from the use
of the institution are based on financial ratios, the managers of deposits in foreign currency and short-term lines of credit
they must understand how the ratios are computed, deadline for financing assets in national currency, as well as
the set of alternative information that can be used as of financing foreign currency assets by resources
numerator or denominator and the scope of conclusions that in national currency. The institution must take into account
can be extracted from these ratios. Once the components the risks of a sudden change in exchange rates or of
two ratios (as calculated by the institutions) are some liquidity in the market, or both, which can worsen the mismatch
inconsistent times, the comparison between institutions based existing and change the effectiveness of instruments and strategies
in ratios or even comparisons of different periods in a of foreign exchange risk coverage.
the institution can be deceptive. [Link]. Additionally, the institution must evaluate
[Link]. The ratios and limits that can be used by the possibility of losing access to foreign exchange markets, well
as the convertibility of the currencies in which it conducts its
institutions are:
activity.
a) Raciocínio e Limites de Concentração de Passivos – Ajudam
to prevent the institution from relying excessively on a 3.4.10. Market Access:
reduced number of financiers and sources of funding. [Link]. An essential component to ensure
Os limites são geralmente expressos em percentagem The diversification of funding is to maintain access to the market. Access
two deposits or liabilities; the market is crucial for the management and reduction of liquidity risk, given
b) Cumulative Cash Flow Mismatches that affects the institution's ability to obtain new resources
Contractual - It is a limit of cumulative mismatches such as liquidating assets. Top management must ensure
of contractual cash flows as a percentage that market access is actively managed, monitored
of total liabilities, over various time horizons; It has been tested by appropriate personnel.
18 DE SETEMBRO DE 2013 621

[Link]. Managing market access may include [Link]. In general, a typical market crisis scenario
the development of markets for the sale of assets or the is what affects the liquidity of the largest number of institutions in a
strengthening of agreements by which the institution can incur or more markets.
loans with or without collateral. The institution must maintain a [Link]. Institutions must detail the assumptions
active presence in the relevant markets for your strategy underlying the behavior of the cash flows of their assets,
of funding. This requires commitment and ongoing investment in liabilities and extrapatrimonial elements in plausible scenarios
infrastructure, processes, and information collection. of the crisis. The timing and the dimension of cash flows are factors
[Link]. Normally, funding markets can be important to consider. The assumptions may differ from
seriously affected when placed under stress. The institution accentuated form of scenario for scenario, given that the timing and
must identify and create strong relationships with investors the size of cash flows can behave in a way
existing and potential, even in markets whose access different in different situations. Institutions must take
it is facilitated by correctors or other intermediaries.
considering the settlement period or the time required
[Link]. Although it is important to develop and maintain
strong relationships with funding providers, the institution must to liquidate assets.
be cautious, as these relationships may be affected in [Link]. The main underlying assumption of scenarios
the typical crises of each institution is the fact that many of the liabilities
situations of effort. The institutions that under normal conditions
Infallibly provide resources may not do so in periods that the institution cannot be renegotiated or replaced,
of severe effort due to the uncertainty of their own resulting in a refund at the required maturity, in such a way
liquidity needs. In formulating stress scenarios that the institution would have to contract, to some extent, its portfolio
and contingency plans, the institution must consider these of assets.
second order effects and take into account that sources [Link]. The minimum requirements for the use of different
resources may run out and the market may close. scenarios in conducting liquidity stress tests are
[Link]. The institution must identify alternative sources. the following:
of resources that strengthen your ability to resist variety a) The assumptions must be consistent and reasonable for
of severe, but plausible shocks specific to the institution each scenario;
and the liquidity of the market as a whole.
b) The assumptions must be verified and supported
3.4.11. Review of the Assumptions Used in Management for specific evidence, past experience
of Liquidity: your performance, instead of being merely
[Link]. Once the future liquidity position arbitrary;
the institution is affected by factors that are not always able to be c) Institutions must document the assumptions
accurately anticipated, the liquidity management assumptions behavioral in your policy statement
should be reviewed frequently to determine their of liquidity management. The type of analysis carried out
continuous validity, especially considering the speed of within the scope of each assumption it should also be
changes in the markets. documented to facilitate periodic review; and
3.4.12. Stress Tests: d) Top management must ensure that the assumptions
[Link]. The Institutions, with active involvement fundamentals should be evaluated at least annually,
from top management, they should regularly conduct tests to test your reasonableness.
of effort, considering various rigorous and challenging scenarios, [Link]. In a scenario of widespread crisis in the market,
even in moments when liquidity is abundant it is assumed that an institution may have less control over
their positions, to ensure that they maintain sufficient liquidity to the level and timeliness of future cash flows. The
resist to situations of effort (stress). characteristics of this scenario may include a strong decrease
[Link]. The extent and frequency of the tests must be of liquidity, counterparty default, the need for
proportional to the size of the institution and its exposure to risk make substantial discounts to liquidate assets and large
of liquidity, as well as the relative importance of it in the system differences in access to funding between institutions, due to
financial. Institutions must create conditions to increase the uncertainties in the market.
the frequency of tests in special circumstances (for example,
at the request of the Bank of Mozambique. [Link]. When conducting scenario analyses, institutions
they can include the support they can receive at the intragroup level or
[Link]. The governing bodies and top management must
from headquarters. This support will be extremely important in situations of
analyze the results of the stress tests and formulate strategies
suitable for addressing the revealed liquidity needs crises that only affect domestic operations (due to limitations
through the analysis of the scenario. For example, there may be a need of a territorial and jurisdictional nature), but it may reveal itself
reducing liquidity risk by obtaining more financing how the crises will affect the group as a whole. In addition
in the long term or restructuring the composition of assets. Thus, institutions must document:
[Link]. When conducting liquidity stress tests, a) The assumptions of cash flows in crisis scenarios
it is important that institutions do so with adverse scenarios specifics of the institution and the market; and
plausible, and analyze the liquidity needs that arise from them
result them. Institutions are encouraged to cover different b) The estimates of the minimum number of days required
types and levels of adversity, should, however, prioritize to mobilize emergency financial support
the following scenarios: from other sources.
a) Typical crisis scenarios for each institution; and [Link]. Scenarios must be subject to regular review
b) Typical crisis scenarios in the market. to ensure that the nature and severity of the scenarios
[Link]. The typical scenarios of each institution cover tests remain appropriate and relevant to the institution.
situations where there is perception or existence of problems The revisions must take into account the changes in
at an institutional level, such as operational problems, market conditions, in nature, dimension and complexity of
concerns about solvency and adverse changes in rating business model and activities of the institution and experiences
of credit. current in effort scenarios.
622 I SERIES — NUMBER 75

3.4.13. Management Information Systems: c) The establishment of control activities, such as


[Link]. A Management Information System (MIS) is... policies and procedures;
it is essential for liquidity management decision-making in a d) Appropriate information systems; and
sustainable base. Information must be available to the Continuous review of adherence to policies
day-to-day management and control of liquidity risk, as well as the procedures.
during periods of exertion. 3.5.3. Regarding policies and procedures
[Link]. The data must be consolidated, comprehensive, control, attention must be given to appropriate processes
concise, objective and available in a timely manner. In of approval, limits, review, and other mechanisms intended
under normal conditions, the periodic reports generated allow for to provide a reasonable assurance that management's objectives
the institution monitors liquidity during crises; such reports the institution's liquidity risk will be reached.
They should be prepared more frequently in a crisis situation. 3.5.4. The attributes of a good risk management process,
When developing liquidity management information systems, including the function of measurement, monitoring and control
managers must always keep in mind the monitoring of risks, are fundamental aspects of an effective system
of the crisis. of internal control. Institutions must ensure that all
There is always a trade-off between accuracy the aspects of the internal control system are effective, including
and timeliness. Liquidity problems can arise very the aspects that do not directly part of the process
quickly and liquidity management may require reports of risk management.
internally daily. Once liquidity is greatly affected 3.5.5. Other important elements in the control system
measured by the aggregated cash flows, it proves to be irrelevant internal of an institution, in the risk management process
analyze detailed information about each operation, due to the fact of liquidity, are the periodic assessment and the review. This includes
of not being able to improve the analysis. ensure that employees are complying with the policies
[Link]. The management information system must be used the established procedures, as well as ensure that the
to verify compliance with the policies, procedures, and limits the procedures that were established really comply
established by the institution, as well as the prudential requirements the intended objectives. These reviews and assessments must
on liquidity established by the Bank of Mozambique. address, likewise, any significant change that may
The report of risk measures must be made in a timely manner. to impact the effectiveness of the controls.
and the current liquidity positions should be compared 3.5.6. The administrative body must ensure that all
with any fixed limits. The information system must Reviews and evaluations are conducted regularly by people.
equally allow management an assessment of the trend of the level independent of the function to be reviewed. When the revisions or
global exposure to liquidity risk in the institution. improvements to internal controls are justified, there should be
[Link]. Management must develop systems that allow a mechanism to ensure that these are implemented
capture meaningful information. The content and the format of in a timely manner.
reports depend on liquidity management practices, risks 4. Guidelines for Interest Rate Risk Management
and other characteristics of the institution. The routine reports
4.1. Introduction
can include a list of the main sources of resources,
cash flow, etc. 4.1.1. The interest rate risk is the possibility of occurrence
[Link]. Day-to-day management may require more information. of negative impacts on results or on capital, due to
detailed, depending on the complexity of the institution and the to adverse movements in interest rates, through lag effects
incurred risks. Line management must regularly consider of maturities or deadlines for the relaxation of interest rates, of
the best way to summarize detailed and complex issues for absence of perfect correlation between the operation rates
top managers or governing body. Furthermore, another active and passive in different instruments, or of existence
type of important information for activity management of embedded options in financial instruments on the balance sheet or
for day-to-day and for the understanding of the liquidity risk profile extrapatrimonial elements.
inherent to the institution include: 4.1.2. Exposure to this risk is part of the normal course.
of financial intermediation activity and can be a
a) Quality of assets and their evolution;
important source of profitability and value creation for
b) Projection of results;
the shareholders. However, excessive interest rate risk can
c) General reputation of the institution in the market and the conditions
represent a significant threat to the profit base
of the market itself;
the capital of an institution.
d) Overall composition of the balance sheet structure; and
4.1.3. How interest rate variations affect the results
e) Type of deposits (new products) to be raised,
from an institution through the change of the financial margin
as well as its source, maturity, and price.
and the level of other sensitive operating income and costs
3.5. Internal Controls
The variations in the interest rate also affect the value
3.5.1. Institutions must have internal controls. underlying assets, liabilities, and off-balance-sheet instruments
to ensure the integrity of your risk management process of an institution, given that the current value of cash flows
of liquidity. These controls should be an integral part of futures (and in some cases, the cash flows themselves) varies
global internal control system of the institution, which must whenever there are variations in interest rates. Thus, the
promote the efficiency and effectiveness of operations, reports institutionalization of an effective risk management process that
financial and regulatory compliance with the keeping interest rate risk at prudent levels is important
laws, regulations and institutional policies. to ensure the security and solidity of the institutions.
3.5.2. The internal control system for liquidity risk
4.2. Sources and Effects of Interest Rate Risk
must include:
a) Strong control environment; 4.2.1. Sources of Interest Rate Risk
b) Appropriate process for risk identification and assessment [Link]. The main forms of interest rate risk to which the
of liquidity; institutions are normally exposed to understand the risk
18 DE SETEMBRO DE 2013 623

interest rate repricing risk, curve risk types of obligations and securities with options to buy or sell,
of yields (yield curve risk)9), risk of indexing and risk loans that grant the borrower the right to prepay
of option (basis risk and optionality risk), each of which the payment of the debt, and several other types of instruments
is addressed in detail below: of deposit without specified maturity that grants
a) Repricing Risk to the depositor the right to make withdrawals of funds
The principal and most discussed form of interest rate risk at any time and at no charge.
of interest, emerges from the mismatches between maturities [Link]. If not managed properly, the advantage
(for fixed rates) or adjustment (for variable rates) asymmetry that the instruments with options present can
two assets, liabilities and extrapatrimonial positions of represent a significant risk, especially for those who
institution. Although such gaps in relaxation sells, once the options held, both explicit and
that the rates (repricing mismatches) are fundamental The embedded powers are generally exercised for the benefit of the holder.
para a intermediação nanceira, eles podem expor os (at a disadvantage to the seller).
results and the underlying economic value of a 4.2.2. Effects of Interest Rate Risk
institution to unexpected situations as [Link]. Variations in interest rates can have impacts
interest rates vary. For example, an institution that negatives both in results and in economic value
granted a long-term loan at the rate from an institution. This gave rise to two optics or perspectives
the middle of a short-term deposit) can register a different, but complementary, assessment of exposure of
decrease in both future earnings (resulting from institution at interest rate risk.
the positions taken), as well as the respective value, [Link].Optics of Results - From the point of view
if interest rates increase. This decrease of results, the focus of the analysis centers on the impact of the
it happens because the cash flows from credit are low, variations in interest rates on earnings. This is the approach
during its validity, while the interest paid on traditional assessment of interest rate risk conducted by
the financing is variable and increases after many institutions. Variations in revenues represent a
the maturity of the short-term deposit. important focal point for interest rate risk analysis,
b) Yield Curve Risk – The lags in the rate relaxation because the decrease in income or absolute losses can
they can also expose the institution to changes put into question the financial stability of an institution through
in the shape and slope of the yield curve. This risk of the impact on capital or the reduction of confidence levels
arises when unexpected changes occur in the yield curve in the market.
create an adverse impact on the results of [Link]. In light of this, the component of the object revenues
institution or its underlying economic value. of greater attention is the financial margin, i.e., the difference between
c) Basis Risk – This risk arises from the interest and equated profits and interest and equated costs.
of the non-existence of perfect correlation between the rates This approach reflects both the importance of financial margin
received and paid in different instruments, in the banking product as your direct connection (and easily
motivated by differences in interest rate indexes understandable) to variations in interest rates. However, a
of interest. When interest rates fluctuate, they as institutions become largely involved in activities
Differences can give rise to unexpected variations. that generate commissions and other complementary margins, there is
in cash flows and margins (spreads) common tornado adopt a broader approach centered on
of benefits between assets, liabilities, and instruments global net result. Even the traditional sources of the margin
extrapatrimonial with maturity or frequency complementary, such as the commissions resulting from
of relaxation of similar interest rates. For example, operation processing is becoming more sensitive to
a strategy to finance a credit with maturity variations in interest rates. This increase in sensitivity should
for one year (whose interest rate is adjusted or fixed to lead the management of an institution to consider an approach
monthly, based on the MAIBOR or any broader potential effects of the variations in the rates of
another reference rate) for a deposit of equal I swear by the market on the institution's profits and incorporate them
maturity (whose rate is reflected monthly in effects on your revenue estimates in different scenarios
base of the monthly rate of a Treasury Bill} exposes of interest rates.
the institution at the risk of the spread between the two rates [Link].Optics of Economic Value - Variations in rates
Market interest rates can also affect the economic value.
if the indexing changes unexpectedly.
d) Optionality Risk - This risk results two assets, liabilities and extrapatrimonial elements of a
the existence of embedded options in instruments institution. Thus, the sensitivity of the economic value of
financial elements of the balance sheet or extrapatrimonial elements, the institution of interest rate fluctuations deserves due attention
such as redemption or amortization options consideration by the administrative body and by management
advanced in deposits or loans. of institutions.
[Link]. From a formal point of view, an option gives its holder [Link]. The economic value of an instrument represents
the right, but not the obligation, to buy, sell or any the evaluation of the present value of your net cash flows
how to change the cash flow of a contract or instrument expected, discounted to reflect market rates.
financial. An option can be an instrument of the "stand" type Similarly, the economic value of an institution can be
alone" or embedded in other standardized instruments. understood as the present value of net cash flows
Although institutions use options for both trading and expected, defined as expected cash flows
for other purposes, instruments with embedded options two assets deducted from the expected cash flows
are generally more important in activities whose intention of of liabilities and added of the expected net cash flows
management is not negotiation. This category includes the various in extrapatrimonial operations. In this sense, the effect of
from the economic value perspective, it reflects another approach of
sensitivity of the institution's net worth to fluctuations
9Risk of the yield curve or interest rate. of interest rates.
624 I SERIES — NUMBER 75

[Link]. Embedded Losses - The effects on results and value f) Maintain appropriate systems and standards for measurement
The previously discussed economic aspects focus on how the of risk;
variations in future interest rates may affect performance g) Maintain a detailed reporting system and a process
financial institution. When assessing the level of exposure to of the review of interest rate risk management;
interest rate risk, an institution must consider the impact h) Maintain an internal control system and ethical standards
what impact past interest rates can have on future performance. eakes;
In particular, the instruments that are not accounted for i) Ensure that the interest rate risk reports for
at fair value may contain embedded gains and losses top managers provide aggregated information,
due to past movements in interest rates. These gains as well as sufficient details to allow this
Losses can, over time, be reflected in the results. assess the institution's sensitivity to variations in
from the institution. market conditions and other important factors
4.3. Supervision by the Administrative Body of risk;
Top Management j) Review policies and procedures periodically
4.3.1. Effective oversight by the administration body of interest rate risk management of the institution for
The top management of an institution is crucial for effective management. ensure that they remain appropriate
solid of interest rate risk. It is important that these bodies and robust;
be aware of your responsibilities towards k) Ensure that the analyses and risk management activities
management of interest rate risk and perform adequately related to interest rate risk are carried out
your functions of scaling and managing this category of risk. by competent personnel, with technical knowledge
4.3.2. Oversight by the Administrative Body: the experience consistent with the nature and scope of
activities of the institution; and
[Link]. It is especially the responsibility of the administrative body:
l) Ensure that there is enough staff to manage
a) Approve the business strategies and policies that the activities related to risk and accommodate
govern or influence interest rate risk temporarily the absence of key personnel.
from the institution;
4.4. Policies, Procedures, and Limits
b) Review the overall objectives of the institution in relation to
to the interest rate risk; 4.4.1 Policies and Procedures
c) Provide clear guidelines on the acceptable level [Link]. Institutions must have policies and procedures
interest rate risk for the institution; clearly defined and consistent with their nature,
d) Approve policies that establish lines of authority complexity and activities to limit and control risk
and responsibility for managing exposure to risk of interest rate.
of the interest rate; [Link]. The policies and procedures must detail:
e) Ensure that top management has knowledge a) Lines of responsibility and accountability regarding
adequate, be competent and able to lead the interest rate risk management decisions;
activities related to the interest rate and b) Risk hedging strategies; and
take the necessary measures to identify, measure, c) Quantitative parameters that define the appropriate level
monitor and control this risk category; and acceptable risk for the institution. In cases
f) Ensure that the administration or a specific committee where appropriate, such limits should
periodically review information to be specified for certain types of instruments,
sufficiently detailed and updated to allow wallets and activities.
understand and evaluate management performance
[Link]. The policies must also identify:
at the top of monitoring and control of this
risk, taking into account the policies approved by a) The types of instruments and activities that the institution
administrative body. Such a review must be can employ or develop, being a way
carried out regularly, and with greater frequency to communicate the level of risk tolerance
still, in institutions with significant positions in from the institution;
complex instruments; and b) The permitted instruments, identifying them either by
g) Ensure that the administration or a specific committee names, whether by characteristics, should describe them
periodically reassess risk management policies purposes or objectives for which they can be used
of interest rates, as well as the overall strategy that affects (for example, assume and/or cover positions); and
the institution's exposures to this risk category. c) The set of institutional procedures for acquisition
4.3.3. Oversight by Top Management: of specific instruments, portfolio management, good
as for the control of the aggregate exposure to risk
[Link]. Top management is responsible for:
of interest rate.
a) Develop and establish policies and procedures for
manage interest rate risk on a daily basis, as well as [Link]. All interest rate risk policies must be
in the long term; magazines at least annually and updated whenever possible
b) Maintain clear lines of authority and responsibility necessary.
to manage and control interest rate risk; [Link]. The institution's management must define procedures
c) Implement strategies to limit risks and specific approvals for the application of exceptions
associated with each of the specific strategies to the policies, limits, and authorizations.
and to ensure compliance with or observance of the laws [Link]. Products and services that are new to
the regulations; the institution must be subjected to careful scrutiny
d) Maintain standards to assess positions and measure before your introduction, in order to ensure that the institution
the performance; understand the characteristics of interest rate risk
e) Maintain appropriate limits for risk-taking; and incorporate it into the risk management process.
18 DE SETEMBRO DE 2013 625

[Link]. When analyzing whether a product or activity introduces 4.5.2. The measurement systems must:
new elements of exposure to risk, the institution must be a) Evaluate all the material interest rate risks associated
pay attention to the fact that changes in the maturity of the instruments, to assets, liabilities, and extrapatrimonial elements
relaxation of interest rates or repayment conditions may of an institution;
materially affect the characteristics of interest rate risk b) Use risk measurement techniques and financial concepts
of the product. usually oils; and
[Link]. Before introducing a new product, an instrument c) Have well-documented assumptions and parameters.
of coverage, a strategy for taking positions, the management 4.5.3. As a general principle, it is desirable that any system
the institution must ensure that policies are in place and of measurement incorporate interest rate risk exposures
adequate procedures. The administrative body or the committee resulting from all the activities of the institution, including the
for this designated must approve the main instruments sources of trading like those that are not from trading. This is not
of coverage or risk management initiatives before your excludes the use of different measurement systems and approaches
implementation. of risk management for various activities; however,
[Link]. Proposals for the introduction of new products or management must have an integrated view of interest rate risk
business strategies should enshrine the following aspects: in all products and sectors of activity.
a) Description of the product or relevant strategy; 4.5.4. The interest rate risk measurement system of a
b) Identification of the resources needed to establish the institution must consecrate all the material sources of this category
a solid and effective management of interest rate risk of risk, including exposures to the risk of revaluation, day yield
associated with the product or activity; curve, option, and index. In many cases, the characteristics
c) Analysis of the reasonableness of the proposed activities of interest rates of the significant positions of an institution
regarding the global financial situation of the institution they dominate your global risk profile. Despite all positions
and of the levels of capital; and of the institution must receive adequate treatment, the systems
measurement must evaluate such concentrations with special
d) Policies and procedures to be used for measuring,
rigor. Interest rate risk measurement systems must
monitor and control the risks associated with the product
also provide strict treatment of those instruments
or proposed activity. that can significantly affect the global position of
4.4.2. Limits an institution, even if they do not represent a concentration
[Link]. Institutions must implement guidelines that Principal. The significant instruments with embedded options.
the focus on risk-taking, aiming to maintain exposure And explicit ones should receive special attention.
to the risk of interest rate within the pre-determined parameters, 4.5.5. There is a varied set of techniques available for
taking into account possible changes. measure exposures to interest rate risk, both of the results
[Link]. The aforementioned guidelines must establish limits. as the economic value of an institution. The complexity
of interest rate risk applicable to different portfolios it varies from simple calculations to static simulations
(individually), activities or lines of business, and adjusted using existing positions, dynamic modeling techniques
to the dimension, complexity, and levels of adequacy of the capital of highly sophisticated that reflect potential businesses
institution, as well as its capacity for measurement and management of
futures.
4.5.6. The simplest techniques to measure exposure to risk
risks. of an interest rate of an institution begins with the construction
[Link]. An appropriate limits system must allow of a frame (of maturities or rate reflection) that makes
to the management of the institution the control of exposure to interest rate risk
the distribution of active, passive, and extrapatrimonial positions
of interest and the monitoring of existing exhibitions in relation to sensitive to interest rate variations by 'time bands'
pre-established tolerance levels. The limits must ensure band) according to their maturities (interest rates) or period
that positions exceeding the pre-determined levels receive residual until the next re-fixation (variable rates).
immediate attention from management. 4.5.7. These frameworks can be used to generate indicators
[Link]. The limits for interest rate risk must be approved. simple sensitivity of profits and economic value
by the management body and periodically reassessed. to the interest rate risk. When this approach is used for
[Link]. Exceptions to the limits must be prompt determine the current level of interest rate risk of revenues
communicated to top management. There should be clear policies is referred to as Gap Analysis. The size of the 'gap' for a
about how top management should be informed and the actions that certain time band – i.e., assets minus liabilities plus
extrapatrimonial exposures that reflect or mature within
must be taken in such cases.
from the same time band - gives an indication of exposure to
[Link]. The guidelines must specify whether the limits are risk of interest rate reaction of an institution.
absolutes or if, in certain clearly defined circumstances, The maturity or rate reflection framework can,
overtaking can be tolerated for a short period likewise, to be used to evaluate the effect of variations
of time. In this context, the conservative nature of the limits the interest rates on the economic value of an institution through
selected can be an important factor. of applying sensitivity weights to each band
4.5. Measurement, Monitoring and System temporal. In general, such weights are based on estimates.
Risk Management Information active and passive durations that fit into each
temporal band, where duration is a measure of variation
4.5.1. Institutions must have measurement systems for percentage of the economic value of the position that occurs given a
interest rate risk consistent with its complexity and range slight variation in the level of interest rates. The weightings
of activities, to assess the effect of the changes in rates of based on duration can be used in combination with
I swear by the results and the economic value. These systems must the maturity/re-fixation frameworks, aimed at providing
provide concrete measures of the actual levels of exposure to risk an elementary approach to the variation of economic value
of the interest rate of an institution and be able to identify of an institution that can occur given a specific set
any excessive exposure that may arise. of changes in market interest rates.
626 I SERIES - NUMBER 75

4.5.9. The most sophisticated systems for interest rate risk measurement 4.6. Stress Tests
of interest include simulation techniques. The simulation techniques 4.6.1. The risk measurement system must allow for a
typically involve detailed assessments of the potentials real assessment of the effect, on the institution, of adverse changes
effects of changes in interest rates, on results and on value in market conditions. The stress test must be designed
economic through the simulation of possible behavior in order to provide information about the type of conditions
future of interest rates and their impact on cash flows. In susceptible to making vulnerable the positions or strategies of
static simulations, only the box flows that result institution, thus being able to adapt to the characteristics
the current positions of assets and extrapatrimonial elements of the institution's risk.
are evaluated. 4.6.2. The possible scenarios of effort may include:
4.5.10. In a dynamic simulation approach, the simulation
is based on detailed assumptions about behavior a) Sudden changes in the general level of interest rates;
future of interest rates and expected changes in the course of b) Changes in the relationship between the main interest rates
activities of the institution during the relevant period. These market (index risk);
more sophisticated techniques allow for a dynamic interaction of c) Changes in the slope and shape of the curve
flow of payments and interest rates and better fundraising of yields (yield curve risk);
of the effect of embedded or explicit options. d) Change in the liquidity of the main financial markets
Regardless of the measurement system, the utility or in the volatility of market interest rates; and
the validity of the assumptions made depends on each technique e) Conditions under which the main parameters and assumptions
and the accuracy of the basic methodologies used for modeling the business loses consistency.
the exposures to interest rate risk. 4.6.3. Institutions must conduct stress tests.
4.5.12. When designing risk measurement systems for interest rates
the assumptions and parameters used for the instruments
by law, institutions must ensure that the level of detail
illiquid and those with contractual maturity not specified to obtain
about the nature of positions sensitive to interest rate variations
The interest rate is commensurate with the complexity and intrinsic risk. an understanding of your risk profile. In conducting tests
in these positions. For example, using the gap analysis technique, special attention should be paid to the instruments or
the accuracy of the measurement of interest rate risk depends, in part, markets where there are concentrations, to the extent that such
of the number of time bands in which the positions are positions may be more difficult to liquidate or offset in
added. Certainly, the aggregation of positions/flows of stress situations. Institutions must consider scenarios
box in wide temporal bands implies, in some way, loss extremes in addition to the most likely events.
of precision. In practice, the institution must assess the relevance of 4.6.4. The management and the governing body of the institution
potential loss of accuracy in determining the aggregate measure they must periodically review the model and the results
the simplification to be incorporated into the measurement approach. from stress tests, and ensure that action plans are put into practice
4.5.13. Estimates of exposure to interest rate risk appropriate contingency.
they are linked to the results, whether to the economic value, they use, 4.7. Management Information System
in some way, predictions of probable future behavior
the interest rates. For risk management purposes, institutions 4.7.1. Institutions must have an information system
they must incorporate sufficiently large variations in the rates of management is precise, informative, and timely, to manage exhibitions
I swear to consecrate the risks related to your positions. to the interest rate risk and inform management, as well as to
4.5.14. Institutions may consecrate the use of multiple assist in the enforcement of the policies approved by the body
scenarios, including potential effects on changes in relationships of administration.
between interest rates (i.e., risk yield curve and risk of The reporting of risk measures must be regular,
indexer) as well as changes in the general level of interest rates. having to compare, clearly, the current exhibitions with
4.5.15. To determine probable variations in the interest rate, the limits fixed in the policies. Moreover, previous forecasts
institutions can employ simulation techniques. Analyses risk estimates should be compared with the results
statistics can also play an important role observed (real) to identify any inconsistencies
in the assessment of the assumptions regarding the risk of indexation in modeling.
or the 'yield curve'. 4.7.3. The reports that present details about exposures
4.5.16. When evaluating the results of the measurement systems the interest rate risk of the institution should be reviewed by the
of risk, it is necessary that: administrative body regularly. Although the types of
a) The underlying assumptions of the system should be clearly reports prepared for the administrative body and for others
understood by risk and management managers management levels may vary according to the interest rate risk profile
from the top; of the institution's interest, they must, at a minimum, contain:
b) The sophisticated simulation techniques are used a) Summaries of the institution's aggregated exposure to risk
carefully so that they do not become 'boxes' of interest rate;
black,” producing numbers that seem to be b) Degree of compliance with policies and limits
exactly when in fact they are not, in cases where of the institution;
that their specific parameters and assumptions are c) Main assumptions (for example, behavior
revealed; two deposits without maturity and information about
c) The main assumptions should be recognized by advance payments);
top management and risk managers and reviewed, by d) Results of the stress tests including those that evaluate
less, on an annual basis; the loss of consistency of parameters and assumptions
d) The main assumptions should be well documented main; and
and its understood scope; and e) Summary of the findings from the policy reviews
e) The assumptions used in the sensitivity assessment of interest rates, procedures and adequacy
two complex instruments (with uncertain maturity) two risk measurement systems, including any
the interest rate shall be subject to documentation findings of internal and external auditors or of
the rigorous review. another independent reviewer.
18 DE SETEMBRO DE 2013 627

4.8. Internal Controls [Link]. Management must also ensure that there are safeguards
4.8.1. The institutions must have control systems sufficient to minimize the potential that individuals who
adequate internal measures to ensure the integrity of the process we start the risk-taking operations that influence, in a way
interest rate risk management. These controls should be part of inappropriate, the main control functions of the process of
member of the institution's global internal control system. risk management, such as (i) development and execution of
They must promote: policies and procedures, (ii) risk reporting to top management
the execution of back-office operations.
a) Effective and efficient operations;
[Link]. The nature and scope of such security mechanisms
b) Financial and regulatory reportable;
must be in accordance with the size and structure of the institution.
c) Compliance with laws, regulations, and policies
These must be commensurate with the volume and complexity of
relevant institutions.
interest rate risk incurred by the institution and the complexity
4.8.2. An effective internal control system for interest rate risk your transactions and commitments.
by law must ensure the existence of:
5. Guidelines for Exchange Rate Risk Management
a) A strong control environment;
b) An appropriate process for identification and evaluation 5.1 Introduction
of risk; 5.1.1. The exchange rate risk consists of the possibility
c) Appropriate control tools such as policies, of negative impacts on the results or on the capital,
procedures and methodologies; and due to adverse movements in exchange rates, caused by
d) An efficient management information system. due to changes in the price of instruments that correspond
4.8.3. Institutions must have their functions or areas open positions in foreign currency or by change
measurement, monitoring, and risk control functions of the institution's competitive position due to variations
regularly reviewed by independent counterparts such as significant exchange rates. This involves the risk
internal or external auditor. It is essential that any reviewer of liquidation that arises when an institution incurs in
independently ensure that the risk measurement system of financial losses due to the foreign exchange positions assumed as well
institution is sufficient to capture all material elements of in the trading wallet as in the bank wallet.
interest rate risk, whether resulting from asset elements, 5.2. Supervision by the Administrative Body
about extrapatrimonial activities. Top Management
4.8.4. When conducting the assessment, the reviewer must consider
5.2.1. The governing body and top management hold,
the following aspects:
ultimately, the responsibility to understand
a) The amount of interest rate risk, for example: the nature and level of exchange rate risk assumed by the institution
The degree of price sensitivity of various and the subsequent management of it.
products; 5.2.2. The scaling by the management body may be
delegated to an appropriate subcommittee, such as the Management Committee
ii. The vulnerability of results and capital
of Assets and Liabilities (ALCO – Asset and Liability Committee)
to the various changes in interest rates, including
or the Risk Management Committee.
changes in the yield curve; and 5.2.3. The responsibilities of the administrative body
iii. The presentation of results and economic value and top management are:
to several other forms of interest rate risk,
a) Define the strategy for managing exchange rate risk and the levels
including the risk of the index and the option.
of tolerance;
b) The quality of interest rate management, for example: b) Ensure that management systems are implemented
i. Existence (or not) of an adequate internal system of risks and internal controls and effectiveness;
of measurement in function of nature, scope and c) Monitor significant risk exposures
complexity of the institution's activities; change;
d) Ensure that foreign exchange operations in the institution
ii. Existence (or not) of a control unit comply with the foreign exchange control regulations
responsible for development and administration
current
of measurement and monitoring functions e) Ensure that currency operations are supported
and risk control; for appropriate management information systems
iii. Grau de envolvimento do órgão de administração complementary to the risk management strategy; and
and top management in risk control; f) Regularly review the policies, procedures
iv. Existence of policies, controls, and procedures the limits per currency in accordance with the changes
related to interest rate risk properly in the economic environment.
documented and respected; and 5.3. Políticas e Procedimentos
v. Existence of suitable personnel to conduct 5.3.1. Institutions must have policies and procedures
the risk management process. writings to identify, measure and control interest rate risk
4.8.5. In cases where independent review is conducted exchange, which are consistent with the strategies, conditions
by an internal auditor, institutions must have the function of financial resources and the institution's risk tolerance levels.
measurement, monitoring and control periodically reviewed 5.3.2. Policies and procedures must be supplemented
by an external auditor. with ethics and adherence to the established standards by
employees involved in foreign currency trading.
4.8.6. Lines of Responsibility and Authority: They must also identify exchange rate risks.
[Link]. The institutions must ensure that there is segregation inherent to the services and activities to ensure that the
of functions in the key elements of the risk management process, risk characteristics are perceived in such a way as to be
with a view to reducing potential conflicts of interest. incorporated into risk management processes.
628 I SERIES — NUMBER 75

5.3.3. The policies and procedures must: 5.4.3. Risk Limits


a) Define lines of responsibility and identify individuals [Link]. In addition to observing the limits on Positions
or committees responsible for developing strategies Exchanges established by the Bank of Mozambique, the institutions
they must have a comprehensive conceptual framework of limits
of foreign exchange risk management, to make management decisions
of exchange risk and to make the scaling; to control the foreign exchange risk positions at different levels
b) Identify the different types of financial instruments of report.
allowed and risk hedging strategies; [Link]. At a minimum, institutions must have the following
c) Describe a set of control strategies limits of currency operations:
of the exposure added to the exchange rate risk a) Limits on open foreign exchange positions, by currency, for
of the institution; to which institutions have a material exposure, to the
Define the quantitative limits of the acceptable level of risk long of the day or from one day to the next (overnight).
change it for the institution, including limits by currency, b) Global limits on open foreign exchange positions for
on the other hand, by dealer, concentration limits positions taken during the day and from one day to
the limits of accumulated losses (stop loss); and the other;
c) Limits of open foreign exchange positions by each center
e) Define procedures and conditions for dealing with the
from which the institution conducts operations;
exceptions to policies, limits, and authorizations.
d) Limits for accumulated losses and/or limits for
5.4. Identification, Measurement, Monitoring unleash the management intervention; and
Risk Control e) Limits for the risk of compensation for all
5.4.1. Risk Identification as counterparts.
[Link]. Exchange rate risk exposures fit into [Link]. The limits must be reviewed annually or with
in the following categories (structural and negotiation): greater frequency according to environmental variations
of business.
a) Conversion Risk – arises from changes in value
accounting for the conversion to the currency of 5.4.4. Stress Tests
writing of open positions in foreign currency, [Link]. Credit institutions must conduct tests
caused by changes in exchange rates; of the effort of your exchange positions, to assess the impact
b) Transaction Risk - arises when there are changes in of changes in exchange rates on profitability and value
exchange rates at the time of incurring economic of your own capital. In the establishment of
in the obligation and the moment in which it is settled, effort scenarios should take into account the effects of changes
consequently affecting cash flows significant movements in exchange rates (including
cash; and sharp reductions in the liquidity of a certain currency.
c) Economic Risk – Reflects the changes in the current value [Link]. The results of the stress tests must be
expected cash flows of an institution incorporated into the review of business strategies, policies
as a result of unexpected changes in the rates the limits of exchange rate risk. The assumptions used
of change or alteration of the competitive position of In the stress test model, it must be clearly documented.
institution due to significant variations in the rates they are continuously reviewed, in order to reflect the changes
in the business environment.
of exchange.
5.4.5. Risk Monitoring and Control
5.4.2. Measurement of Risk
[Link]. Institutions must establish monitoring processes
[Link]. Credit institutions must have systems
management of exchange rate risk, evaluate performance
of measurement that take into account all sources of interest rate risk
the risk strategies, policies, and procedures in achieving
of exchange. of their overall objectives. The function or department
[Link]. Measurement systems must: Monitoring should be independent of the units.
a) Evaluate the effect of exchange rate changes ou áreas que assumem riscos e deve reportar directamente à gestão
on the profitability and economic value of institutions; of top or administrative body.
b) Evaluate all exchange rate risks by maturity, [Link]. Omiddle-of-cedeve performs the review function
on a gross and net basis, resulting from all about the risks related to day-to-day activities. It is also the responsibility
the range of positions of assets, liabilities, and elements to this unit:
extrapatrimonial assets of the institution; a) Prepare reports for top management as well as for
c) Use recognized financial models or methods the ALCO; and
to measure the risk of foreign exchange options; b) Regularly reconcile positions taken by the
d) Be able to calculate the sensitivity of risk factors traders to ensure that these are within
comprehensive with the purpose of capturing the nature not of the assigned limits.
linear risk of exchange position prices. [Link]. Because it is a highly specialized function, omiddle-
e) To have correct and up-to-date data; To have staff with experience and knowledge
f) Incorporate periodic revaluations of fair value relevant.
the trading positions; and [Link]. Institutions must have information systems
g) Enable institutions to monitor in real time. management that provides correct and up-to-date information. Reassessments
real, of the risk of exchange rate compensations, periodic and frequent to current market rates must
in order to ensure that the compensation limits allow monitoring of gains or losses in the portfolio
are not exceeded. of the institution's foreign exchange positions.
18 DE SETEMBRO DE 2013 629

5.4.6. Risk Report the monitoring and control of this risk category. It is also important
[Link]. The types of reports vary depending on the profile. that the definition considers the complete range of material elements
of the operational risk that an institution faces and include the most
global foreign exchange risk of the credit institution. At a minimum, the
reports must contain: important causes of serious operational losses.
6.1.4. Operational risk may arise from various sources, such as
a) Individual foreign exchange risk exposures
for example:
and added;
b) Information about the level of adherence to the limits a) People: Actions that may result in substantial losses
and policies; and include frauds (such as the provision of reports
c) Findings from the policy review activity falsified), employee thefts, insider dealings,
the procedures for foreign exchange risk, including theft, forgery, issuing checks without
the findings of internal/external auditors. coverage and computer piracy. Some of the factors
5.5. Internal Control and Independent Audits Taxpayers are:
5.5.1. Institutions must conduct periodic reviews [Link] of appropriate skills and knowledge;
of your units or internal control functions and processes of ii. Insufficient training and development;
foreign exchange risk management. Such reviews should be conducted by iii. Compensation and incentive schemes
independent parts of the function or unit to be reviewed. inappropriately aligned;
5.5.2. The revisions must, among other things, ensure: iv. Lack of understanding of standards or expectations
of performance; and
a) Accuracy and completeness of the record of all v. Inadequate control of human resources
the operations; (including the supervision and segregation of duties
b) Effective segregation of duties among the units incompatible).
detrading, compensation/settlement and accounting; and b) Internal Processes and Systems: Business interruptions and
c) Effectiveness and accuracy of overtaking reports hardware and software system failures, problems
of limits and other exceptions. telecommunications, service interruptions of
5.5.3. Greater attention must be paid to irregularities public utility, data entry errors, failures
in profits and losses, trends or abnormal patterns in trading in collateral management, access assignment not
frequent deviations (excesses) from the limits. authorized to customer accounts, weak performance and
Internal auditors must ensure that such incidents are litigations with suppliers and service providers are
properly accompanied. Any questions regarding the examples of operational risk resulting from processes
trading area control must be appropriate and timely interns and systems. Some of the contributing factors
forwarded to top management. are
5.5.4. Institutions must respond promptly i. Destruction of physical assets;
on the findings regarding potential violations of the procedures ii. Inadequate or obsolete technology;
established and to ensure that there are adequate procedures iii. Lack of appropriate documentation;
to deal with the deficiencies or irregularities detected by iv. Lack or inadequacy of policies, procedures
risk control functions, internal or external auditors the controls;
the supervisory authorities. v. Poor management information system; and
5.5.5. Internal audit and other control functions vi. Lack or inadequacy of contingency plans.
risk areas must be equipped with specialized personnel, with c) External Events: Terrorism, vandalism, earthquakes,
experience and authority to review business operations. fire and floods.
6.1.5. Operational risk differs from other risks to the extent
6. Guidelines for Operational Risk Management
in which is normally not directly taken in exchange for a
6.1. Introduction expected reward, but occurs in the normal course of the activity
6.1.1. Operational risk is the likelihood of occurrence , and this affects the risk management process. At the same
of negative impacts on results or on capital, arising from time, the inability to adequately manage operational risk
of failures in the analysis, processing or settlement of the operations, It may result in an inaccuracy of the institution's risk profile.
of internal and external frauds, that the activity is affected and expose it to significant losses.
due to the use of resources in an outsourcing regime, 6.2. Supervision by the Administrative Body
due to the existence of insufficient or inadequate human resources Top Management
or from the inoperability of the infrastructures. 6.2.1. The inability to understand and manage risk
6.1.2. Globalization, alongside the growth of innovation operational, present in all transactions and activities,
of financial products and services, is making activities can increase the likelihood of ignoring and losing control
the banking institutions, as well as their risk profiles (this of some risks. The management body and top management
is, the level of risk underlying the activities of the institution and/or are responsible for creating an organizational culture that
more complex risk categories. As a consequence of these places high priority on the management and mitigation of operational risk
As developments progress, operational risk becomes more evident. adherence to an adequate operational control.
6.1.3. Operational risk is a term that has a variety 6.2.2. Operational risk management is more effective when the
of senses in the banking sector and throughout the service industry the institution's culture highlights high standards in behavior
financial, hence banking institutions may choose to ethical at all levels of the entity. The governing body
adopt your own definitions. Whatever the definition may be top management must promote an organizational culture
exact, a clear understanding by credit institutions of that establishes, through actions and words, the expectations of
understanding operational risk is essential for management integrity of all workers in conducting business.
630 I SERIES — NUMBER 75

6.2.3. Oversight by the Administrative Body: d) Evaluate the adequacy of the scaling process in the light of
[Link]. The governing body has, ultimately, intrinsic risks to the business unit policies;
responsibility for the level of operational risk taken by the e) Ensure that the institution's activities are
institution. carried out by qualified personnel, with the necessary
[Link]. It is the responsibility of the administrative body: experience, technical capacity and access to resources,
and that the people responsible for monitoring and enforcing
a) Approve the institutional framework to manage the risk the compliance with the institution's risk policies
operational as a distinct risk to security have authority and be independent of the units
the strength of the institution.
that supervises;
b) Establish a management structure capable of implementing f) Ensure that the operational risk management policy
the conceptual framework of operational risk management that the institution is conveyed to all employees
of the institution. Once the establishment of strong at all levels and units exposed to risk
internal control is an important aspect of management operational; and
of operational risk, it is of particular importance that g) Ensure that the institution's compensation policies
the administrative body establishes clear lines be consistent with the appetite for risk. Policies
management responsibilities, accountability of remuneration that rewards employees who
the report. not observing the policies weakens the process
c) Provide top management with clear guidelines regarding of risk management.
to the underlying principles of the conceptual framework [Link]. Special attention must be given to quality
and approve the respective policies developed by of document controls and the way transactions are
top management. executed. In particular, the policies, processes and procedures
d) Regularly review the conceptual framework for: related to high processing technologies
i. Ensure that the institution is managing risks high transaction volumes must be well documented
operational associated with new products, and disclosed to the appropriate parties.
services or systems; and 6.3. Policies, Procedures, and Limits
ii. Evaluate the best practices in risk management 6.3.1. The institution must establish a management policy
operational in the industry suitable for activities, of operational risk that includes, at a minimum:
systems and processes of the institution. a) The strategy outlined by the governing body;
[Link]. The conceptual framework of operational risk must: b) The systems and procedures to establish a framework
a) Rely on an appropriate definition that clearly conceptual framework for operational risk management; and
articulate what constitutes operational risk c) The structure of the operational risk management function
at the institution; the assignments and responsibilities of the people
b) To encompass the institution's appetite and tolerance towards involved.
to operational risk, as specified through 6.3.2. The policy must establish a process that ensures
of risk management policies; that any new or modified operations, such as new
c) Prioritize the activities of operational risk management, products or system conversion should be evaluated in relation to the
including the dimension and the way in which risk intrinsic operational risk before they are implemented.
operational is transferred outside the institution; 6.3.3. The policy must be documented and approved by
administrative
d) Include institutional policies that are consistent with an approach body and shall be reviewed and updated annually,
for identification, evaluation, monitoring in order to ensure that it continues to reflect the environment in which
and control/mitigation of risk; and the institution operates.
6.3.4. It is the responsibility of top management to ensure that the policy is
e) Articulate the key processes that the institution needs to have
communicated and understood throughout the institution.
to manage operational risk.
[Link] policy must foresee the management of associated risks.
[Link]. The degrees of formality and sophistication of the framework
to outsourcing (subcontracting) of activities. Outsourcing
the conceptual management of the institution's operational risk must of activities can reduce the institution's risk profile through
be compatible with the global risk profile. of the transfer of activities to other institutions more
[Link]. To avoid conflicts of interest, there must be separation specialized to manage the risks associated with such activities.
of responsibilities and reporting lines between the functions However, the use of third parties by the institution does not exempt the
on operational risk control, business lines, and functions responsibility of the management body and top management
of support. to ensure that outsourced activities are carried out
6.2.4. Oversight by Top Management: safely, in compliance with applicable regulations. The
[Link]. Is the responsibility of top management: outsourcing agreements must establish a clear division of
responsibilities between service providers and the institution.
a) Translate the conceptual framework of risk management
In addition, institutions must manage residual risks.
operational established by the administration body
associated with outsourcing agreements, including termination of
in specific policies, processes, and procedures
services.
that can be implemented in the different units
business; 6.3.6. Business Continuity and Recovery Plan
b) Clearly assign authority, responsibility Disaster Operations:
the reporting lines to encourage and maintain [Link]. For reasons that may be beyond your control,
accountability; a serious event may result in the institution's incapacity
c) Ensure that the necessary resources are available fulfill some or all of your obligations, especially
to effectively manage operational risk; when your physical, telecommunications, or infrastructures
18 DE SETEMBRO DE 2013 631

of information technology have been damaged or made is conducted internally and often incorporates
inaccessible. This can, in turn, result in significant checklists and/or lectures (workshops) for
financial losses for the institution, as well as disturbances identify the strengths and weaknesses of the environment of
in the financial system, through channels such as the system operational risk. A similar process, called
of payments. Risk Control Self-Assessment (RCSA) evaluates
[Link]. Institutions must establish recovery plans. the intrinsic risk (the risk before considering the
disaster recovery and business continuity operations that lead to controls), the effectiveness of the control environment and the
details different types of possible scenarios to which the institution residual risk (the exposure to risk after consideration
it can be vulnerable, considering the dimension and complexity of the controls). The Scorecards on the RCSA,
of its operations. for example, they provide a way to translate reviews
[Link]. Institutions must identify critical processes. qualitative into quantitative metrics that assign
of business, including those in which there is dependency relative scoring of different types of exposure
of external suppliers, for whom a quick recovery is to operational risk. The classification may refer to
essential. For these processes, institutions must identify to the inherent risks, as well as to the controls for
mecanismos alternativos para retomar os serviços em caso de to mitigate. Additionally, the scorecards can
failures. Special attention should be given to the ability to restore to be used to allocate economic capital to areas
electronic or physical records that are necessary for the of business based on performance in management and
business retreatment. Whenever such records have a copy control of various aspects of operational risk.
for security in a remote installation, or when operations b) Risk Mapping: in this process, various units
if the institution has to be transferred to a new location, of business, organizational process flows or
All care must be taken to ensure that these places are functions are mapped by the type of risk. This exercise
at a sufficient distance to minimize the impact of the risk of can reveal areas of weakness and help prioritize
unavailability of primary and backup records, as well as subsequent management actions.
two pairs of installations. c) Risk and Performance Indicators: the indicators of
[Link]. Business continuity and recovery plans risk and performance are metrics and/or statistics,
disaster management plans must be reviewed at least annually, to ensure often financial, which can provide
maintain consistency with current operations and strategies information about the risk position of an institution.
business of the institution. Furthermore, these plans must be Risk indicators, usually referred to as
periodically tested to ensure they can be executed Key Risk Indicators (KRI) are used to
in the event of a severe disruption of activity. monitor the main factors of exposure
[Link]. Institutions must follow the specific guidelines associated with the main risks. The indicators of
of business continuity management issued in document performance, generally referred to as Indicators
separated by the Bank of Mozambique. Performance Key (KPI), provide information
about the state of operational processes, that
6.4. Risk Identification, Assessment, Monitoring in turn can provide information about
Monitoring, Control and Management of Systems
operational vulnerabilities, failures and losses
Information
potential. These indicators tend to be revised
6.4.1 Risk Identification and Assessment on a periodic basis (for example, monthly or
[Link]. Institutions must identify and assess the risk quarterly) to alert institutions of the changes
intrinsic operational to all products, services, processes that can be indicators of risk. Such indicators
the significant systems. Furthermore, before introducing new you can include the number of unsuccessful transactions,
products, services, processes, and systems, operational risk staff turnover rates and attendance and/or
intrinsic must be subject to appropriate procedures severity of errors and omissions. They can be indexed
of assessment. limits to these indicators, so that, when
[Link]. Risk identification is fundamental to the design- outdated, may alert management about the areas
subsequent development of a viable monitoring system of potential problems.
and control of operational risk. The identification and effectiveness of the risk d) Scenario Analysis: scenario analysis is a
consider both internal factors (for example, the structure of processo de obtenção de opinião dos gestores séniores
institution, the nature of its activities, the quality of of business and risk to identify potentials
human resources, organizational changes and turnover of operational risk events and assess their impact.
employees) as external factors (for example, changes in This process represents an effective tool for
industry and technological advancements) that may adversely affect identification of the main sources of operational risk
the achievement of the institution's objectives. and control measures or mitigation solutions for its
[Link]. Once the potentially identified risks management. Given the subjectivity of the analysis process
but adverse, institutions must assess their level of the scenario, it is essential to establish a framework
of vulnerability in relation to them. An effective evaluation robust governance to ensure its integrity
of the risks allows the institution to better understand its and consistency.
risk profile and, more effectively, direct resources towards e) Measurement: The use of data about the history
your management. losses of an institution can provide information
[Link]. Institutions may use the following tools relevant for the assessment of your exhibition
for identification and assessment of operational risk: to operational risk, which, in turn, allow
a) Self-assessment or Risk Assessment: an institution the development of policies to mitigate such risk.
assesses the processes that support its operations
against a library of threats and vulnerabilities
potential and considers its impacts. This process 10 Scorecards - methodology for measuring and managing performance.
632 I SERIES - NUMBER 75

An effective way to make good use of this information [Link]. To ensure the usefulness and reliability of these reports,
it is through the establishment of a framework for the management must regularly verify the relevance, accuracy and
systematic collection and recording of frequency, severity relevance of communication systems and internal controls
and other relevant information concerning events in general. Management can also use reports prepared by
of individual losses. Additionally, the external sources (auditors, supervisors) to assess usefulness
institutions can combine data on internal losses the reliability of internal reports. Reports must be
with external loss data (from other institutions), analyzed with a view to improving management performance of the
scenario analyses and risk assessment factors. current risks, as well as the development of new policies
Comparative Analysis: the comparative analysis consists of of risk management, procedures and practices.
in the comparison of results from various tools [Link]. The governing body must receive information
for evaluation to provide a more comprehensive view high level, allowing you to understand the risk profile
of the institution's operational risk profile. operational and focus attention on materiality and implications
example, the comparison of frequency and severity of in the business strategy.
internal data with RCSA can help the institution
6.4.3. Risk Mitigation/Control
to determine if the self-assessment processes
they operate effectively. The scenario data [Link]. Institutions must have policies, processes
can be compared to internal and external data for the procedures to control and/or mitigate operational risks.
a better understanding of the severity of the exposure They should also periodically review the limits.
to potential risk events. of risk, control strategies and adjust their risk profiles
6.4.2. Risk Monitoring and System operational in accordance with the appropriate strategies,
Management Information in light of your global risk profile and appetite.
[Link]. Institutions must implement a process [Link]. The control activities are designed to meet
to regularly monitor operational risk profiles the operational risks that have been identified. For all the
the exposure to significant losses. There must be a presentation significant operational risks that have been identified,
regulate information pertinent to top management and the body the institution must decide whether to use the appropriate procedures
of administration, which ensures the proactive management of risk to control and/or mitigate them. For the risks that cannot be
operational. controlled, the institution must decide whether to take them on, whether to reduce
[Link]. A process of monitoring and evaluation is essential the volume of business involved or whether it is completely withdrawn
for the proper management of operational risk. The monitoring of this activity.
Regular activities can offer the advantage of speed [Link]. Depending on the size and nature of the activity,
detection and correction of deficiencies in policies, processes and institutions must be aware of the potential impact on
operational risk management procedures. The rapid detection its operations and its clients of any deficiencies
the treatment of these anomalies can substantially reduce the of services provided by third parties, or service providers
frequency and/or severity of operational nature events. intragrupo, including both operational failures and potential
[Link].Additionally, for the monitoring of events of business failures or defaults by the external counterparty. The
operational nature, institutions must identify indicators
the governing body and top management must ensure that
adequate measures that provide advance notice of increased risk
the expectations and obligations of each party are clearly
of future losses. These indicators (often referred to
as main risk indicators or warning indicators defined, understood and fulfilled.
they must be focused on the future and can reflect potentials [Link]. The dimension of responsibility and capacity
sources of operational risk, such as rapid growth, financial from the external part to compensate the institution for
introduction of new products, employee rotation, break in errors, negligence and other operational failures must be
transactions, system interruption and so on. When explicitly considered as part of the assessment of
the limits were directly linked to these indicators, risks. Initially, institutions should conduct tests (due
a monitoring and evaluation process can help identify diligence) and monitor the activities provided by third parties,
relevant material risks transparently and allow for the especially those with no experience in the regulated environment
the institution acts on these risks appropriately. from the banking industry, as well as review this process (including
The monitoring frequency must reflect the due diligence reassessments), on a regular basis. For the
the risks involved, as well as the nature of the changes critical activities, the institution may require plans for
in the operational environment. Monitoring should be part contingency, including the availability of external partners,
member of the institution's activities. The results of these the costs and resources necessary to change external partners,
monitoring activities should be included in the management in the very short term.
current and in the administration reports, as well as analyses
[Link]. Some significant operational risks have little
of compliance carried out by internal audit and by the function
probability of occurring, but potentially have an impact
of risk management.
[Link]. Top management must receive periodic reports. very high financial. In addition, not all events
the respective areas, such as business units, group of operational nature can be controlled (for example,
functions, operational risk management unit and auditing natural disasters). Mitigation tools or programs for
internal. risks can be used to reduce exposure, frequency
[Link]. The operational risk reports must contain and/or the severity of such occurrences. For example, policies of
financial, operational, and compliance information, as well as they can certainly be used to 'externalize' the risk of losses
external information available in the market, about events and in events of 'low frequency and high severity' that may
relevant conditions for decision making. The reports occur as a result of events such as complaints of
they must still fully reflect all the problematic areas third parties resulting from errors and omissions, physical losses of values
identified and should motivate corrective and timely action securities, fraud by employees or third parties, and disasters
regarding outstanding issues. natural.
18 DE SETEMBRO DE 2013 633

[Link]. However, risk mitigation tools should 6.5.5. Operational risk may be more pronounced when
to be seen as complementary, not substitutes for a meticulous institutions engage in new services or develop
internal control of operational risk. There are mechanisms for new products (especially if these services or products do not
quickly recognize and correct operational risk errors are compatible with the main business strategy), enter
exposure can be greatly reduced. Special attention in unknown markets or participate in businesses that
are geographically distant from the headquarters. It is therefore incumbent on,
it must be given to the extent that the mitigation instruments
to the institutions to ensure that special attention is given
of risks, such as insurance, really reduce the risk or the
on internal control activities, including policy review
transfer to another sector or business area, or even
the procedures to incorporate such conditions.
they create a new risk (for example, legal or counterparty).
6.5.6. Institutions must have an internal audit.
[Link]. Investments in processing technologies qualified to verify if the policies and procedures
adequate and in information technology security operational measures have been implemented effectively. The agency
they are also important for risk mitigation. However, of administration (directly or through the audit committee)
institutions must be aware that the increment must ensure that the scope and frequency of the programs
Automation can transform operational nature events audits should be appropriate to the risk exposures. The audit
of high frequency and low gravity, at low frequency must periodically certify the conceptual framework of management
and high severity. The latter may be associated with losses or the operational risk of the institution is effectively applied
prolonged interruption of services caused by internal factors in every institution.
or outside the immediate control of the institution (for example, factors 6.5.7. As far as the audit function is concerned
external). Such problems can cause serious difficulties involved in overseeing the conceptual framework of management
and compromise the institution's ability to ensure operational risk, management must ensure that its
the management of the main activities of a business. The institutions independence should be maintained. This independence can be
the auditing function is compromised if it is directly
they must therefore establish disaster recovery plans
involved in the process of managing operational risk. The function of
and business continuity that focus on this risk.
auditing can provide a valuable contribution to those responsible
6.5. Internal Control for operational risk management, but it should not itself have
6.5.1. Institutions must have a control environment direct responsibilities in the management of operational risk. In
robust internal that uses policies, procedures, and systems practice, it is recognized that auditing in some institutions
adequate risk mitigation controls and/or strategies (especially the smaller ones) may have responsibility
of transfer. The internal control systems must be initial for the development of a risk management program
designed to provide a reasonable assurance of execution of operational. If this is the case, institutions must verify
efficient and effective operations constitute a safeguard the responsibility of day-to-day operational risk management
of the heritage, produce viable financial reports and comply with is transferred in a timely manner.
applicable regulation. 6.5.8. An effective internal control system also requires
6.5.2. An internal control system consists of five that there is proper segregation of duties and that personnel do not
components, which are an integral part of the management process Responsibilities that may create conflict should be assigned.
of risk: (i) control environment, (ii) risk assessment; (iii) of interest. The assignment of constant functions to individuals
control activities; (iv) information and communication; and (v) or teams can allow them to hide losses, mistakes or execute
monitoring activities. inappropriate actions. Thus, the areas of potential conflicts
6.5.3. The internal control processes and procedures must interests must be identified, minimized, and subjected to
include a system to ensure compliance with the policies. an independent control and careful review.
The main elements of this system include: 6.5.9. Beyond the segregation of functions, the institutions
they must ensure that other internal practices suitable for control
a) Review at the highest level of the institution's progress risk management should be established. Examples of these include
in the face of established objectives; practices:
b) Verification of compliance with management controls; a) Clear definition of the competencies for the process
c) Policies, processes, and procedures related to analysis. of approvals;
treatment and resolution of issues of lack of b) Strict monitoring of compliance with limits
compliance; of established risk;
d) A mechanism for approvals and authorizations c) Maintenance of protections on accesses and use
documented to ensure accountability to of assets and records of the institution;
an appropriate level of management; and d) Guarantee that the staff has competence and training
e) Report on approved exception verifications adequate
regarding the established limits, substitutions Identification of business lines or products whose
of management and other policy deviations. return appears to be outside of reasonable expectations
6.5.4. Although the formal conceptual framework of policies (for example, in cases where an activity
the properly documented procedures are crucial, it is supposedly low risk and with low margin
generates high returns that can put into
important to reinforce it through a strong control culture,
the strict adherence to internal controls
that promotes good risk management practices. Both the agency in these transactions);
top management is responsible for Regular verification and reconciliation of accounts
establish a strong internal control culture in which the the transactions; and
control activities are an integral part of the activities Establishment of vacation policies that provide for the
institution's regulations. Controls that are an integral part of managers and employees holding relevant positions
Regular activities allow for quick responses to changes if they are absent (on disciplinary leave) for a period
of conditions and avoid unnecessary costs. no less than two consecutive weeks.
634 I SERIES — NUMBER 75

7. Guidelines for Strategic Risk Management and collaborators. The collaborators must possess
7.1. Introduction expertise and training required for conducting the
your tasks efficiently and effectively. The absence
7.1.1. Strategic risk is the possibility of occurrence.
the necessary levels of competence of the staff
of negative impacts on the results or on capital, resulting from
of inadequate strategic decisions, of deficient implementation can increase exposure to risk, harm
the decisions or the inability to respond to changes financial performance and damage the reputation
from the institution;
of the surrounding environment (internal and external) of the institution. This risk
it is a function of the compatibility of the strategic objectives d) Information: the existence of adequate information,
of an institution, of the business strategies developed, of the accurate and timely provides a clear understanding
resources used to achieve such strategic objectives and of the institution and its market niche, affecting
of the quality of their implementation. positively the formulation of strategic plans
7.1.2. Strategic risk can arise from two main sources: and business, as well as management decisions; and
internal and external risk factors. e)Tecnologia: os sistemas tecnológicos devem servir
and support complex transactions and needs
7.1.3. External risk factors are difficult and sometimes
of all customers, as well as maintaining the competition
impossible to control by the institution and affect or
activity and support of new business lines.
they impede the achievement of the objectives set out in the plan
strategic. Such factors include: 7.1.5. Risk mitigation factors assist in the implementation of
a) Competition: the strategic plan and the business plan implementation of strategic plans. Such factors include
must be in line with current competition the existence of a qualified administration body, preparation
in the future. Competitiveness factors must be adequate strategic and business plans, the quality
of personnel and their continuous training, an effective management system
taken into account in the pricing practices of
institution and in the development of new products; risk, adequate access to information, and timely introduction
b) Changes in the market niche: the changes and efficient in new products and services.
demographics and consumption profiles can 7.1.6. Strategic risk, if not properly managed,
affect the customer base, the profits and the sources can gradually manifest in different units of a
of the financing of capital of an institution; institution. This risk tends to interfere
c) Technological changes: an institution may face In 'institutional culture', it may not be easily recognized.
risks arising from technological changes, because and it can still affect the institution's position in the market.
your competitors can develop systems and 7.2. Supervision by the Administrative Body
more efficient services at low costs. The institution Top Management
you must ensure that your technological level is 7.2.1. Supervision by the Administrative Body
sufficient to retain its customer base;
d) Economic factors: the global economic conditions, [Link]. The administration body is responsible for providing
regional or national factors affect the level of profits of a the strategic direction of the institution, which must be included in the plan
institution. Thus, assessments and monitoring strategic. The vision and mission of the institution must reflect
continuous trends and forecasts are necessary; the direction it intends to follow in the medium and long term.
e [Link]. A strategic plan is a document that reflects
e) Regulation: changes in laws and regulations the mission and strategic objectives of an institution, generally
of supervisor, of the authorities related to fisheries, of the authorities for a period of at least three [Link] strategic plan
local and other authorized agencies may affect it must be clear, consistent with the objectives, flexible and adjustable
the implementation of the strategic and business plan to changes in the environment. A strategic plan must contain,
established to achieve institutional objectives at least the following:
and may require adjustments to the plans so that a) Analysis of the external environment in which the institution operates,
to ensure compliance.
including the PESTEL analysis;
7.1.4. The internal risk factors are controlled by b) Critical review of institutional performance, including
institution, however they can affect the implementation of the plan the SWOT analysis;
strategic. Such factors include:
c) Institutional strategic goals and objectives;
a)Estrutura organizacional: para uma boa implementação Description of the institutional risk management system;
two strategic and business plans and scope e) Mission, goals, and operational plans for each of the
two global objectives in a more efficient manner,
operational units; and
it is important that the institution establish a
understandable, consistent organizational structure f) Quantitative projection of financial statements for
with the plans and that prevents conflicts of interest the planned period.
among the administrators, managers, shareholders [Link]. Based on the approved strategic plan, the body
and collaborators; of administration must, among others:
b) Work processes and procedures: these factors a) Establish the governance structure of the institution, which
allow for a timely and accurate implementation
two business plans. The governing body and the must clearly define the lines of responsibility
top management must establish responsibilities and and accountability;
clear guidelines, policies, and procedures in order to b) Establish the appropriate communication channels
prevent from breaches in internal controls; the effective implementation of the plans;
c) Staff: the success of the implementation of strategic plans c) Approve the strategic risk management policies;
and business depends on knowledge, experience d) Ensure that top management is sufficiently
and the vision of the governing body, top management qualified and experienced; and
18 DE SETEMBRO DE 2013 635

e) Ensure that the strategic plan is implemented effectively [Link]. The goals of the operational plans must be
It is revised, at least, annually. consistent with the strategic plan and global objectives
[Link]. The administrative body must receive reports of the institution, as well as with the budget allocation.
relevant, precise and timely, that can be used The institution must establish goals (for example, regarding
appropriately in the decision-making process. The the quality of the credit portfolio) consistent with its
everyone must be adequately informed about the dynamics capacity, market share and competitive environment.
economic, market and competitive conditions
of the institution. [Link]. Institutions must periodically assess their
current performance in relation to the strategic plan in order to
7.2.2. Oversight by Top Management
to monitor and adjust your plans appropriately
[Link]. The management of the institution is responsible for
and consistent with the changes. The assessment must be measurable
implementation of the approved strategic and business plans. and with the appropriate frequency.
The creation of suitable conditions for implementation, including
the design and adoption of management policies and procedures [Link]. To assess the adequacy of monitoring
of strategic risk, as well as of duties and responsibilities the reports of strategic risk, as well as the system
The different units is the most important step aimed at efficiency. of information from the institution, each business unit must
implementation of strategic and business plans. It is also consider the following factors:
of crucial importance, in the effective implementation of the plan a) Contents of the reports submitted for support
strategic, the architecture of the internal infrastructure, including to high-level decision-making;
an effective organizational structure, qualified personnel, b) Frequency of reports;
robust budgeting process, availability of resources, c) The style of presenting information should facilitate
Management information system is timely and systems the understanding; and
de acompanhamento e controlo que realizem os objectivos
efficient and effective business. d) The reports must emphasize the material risks
[Link]. Management must translate strategic objectives into and the strategies established to counter them.
achievable operational objectives, establishing priorities 7.4.2. Management Information System
due to its strategic importance. The objectives [Link]. For an effective monitoring of strategic risk,
strategic plans should be broken down into smaller pieces and a Management Information System (MIS) must be established
attributed to the different business units within the structure robust. Such SIG should assist the institution in the implementation
of the institution.
two strategic plans through:
[Link]. The plans and objectives must be compatible with
the nature, dimension, and complexity of the institution and the a) Provision, collection, and processing of data;
activities that it performs, as well as the market niche of b) Reduction of operational costs;
your performance. c) Improvement of communication among employees; and
d) Timely identification and measurement of strategic risk
7.3 Políticas, Procedimentos e Limites
and generation of data and reports for use by the agency
7.3.1. Strategic risk management must be based on of administration and management.
policy, procedures and limits compatible with the policy
global risk management in the institution. [Link]. The effectiveness of risk monitoring depends
7.3.2. The strategic risk management policy must provide of the ability to identify and measure all factors
general guidelines for strategic risk management. Therefore, they are of risk and should be supported by an appropriate SIG, I need.
the following minimum elements are expected: and timely, allowing for the conduct of analyses and decision making
a) Definition of strategic risk; of decisions. Consequently, management must develop
b) Sources of strategic risk (internal and external factors) and update your information system to identify and measure
of risk); risks in a precise and timely manner.
c) Mitigating factors of strategic risk; The SIG must be consistent with the complexity
d) Strategic risk management approach; e the diversities of business operations of the institution. For
e) Acceptable tolerance for exposure to strategic risk. For example, institutions that have many transactions
7.4. Measurement, Monitoring and Systems complexes must have a reporting system and a system of
Management Information on Risks risk monitoring that can measure the overall level of risk.
7.4.1. Identification, Measurement and Monitoring It must have the capacity to collect, store and retrieve
do Risco Estratégico both internal and external data, including financial data,
[Link]. An effective process for measurement and monitoring about the economic conditions, about the competition, requirements
is essential for proper strategic risk management. technological and regulatory.
identification and measurement of this risk can be done via [Link]. The SIG must ensure timely monitoring.
of strategic planning. The strategic plan, the plans and the ongoing control of strategic risk, as well as
operational and budgetary aspects must be consistent with the scope
the report to the top management and administration body regarding
business, complexity, external environment and internal factors
of the institution, including its size and resources. the implementation of the strategic risk management process.
Additionally, the SIG must provide data and information
[Link]. Top management must participate in the process
appropriate regarding the business activities of the institution.
of planning fully and, carefully, deciding
based on the available information regarding feasibility [Link]. An effective ISMS must adequately support
the adequacy of business and strategic plans. Management the objectives, the goals and the provision of services
must ensure good communication and cooperation among everyone In addition, you must be able to report promptly
the collaborators and departments involved in the process in the desired format, and specify appropriately the levels
of strategic planning. of access to information.
636 I SERIES — NUMBER 75

7.5. Control of Strategic Risk 8.1.5. Institutions, with a view to mitigating risk
7.5.1. The administrative body and top management must of compliance, must take appropriate actions that include:
monitor market changes and advancements in technology (i) reductions in exposures to compliance risk sources;
to conceive new services and products that maintain (ii) an appropriate risk management process; and (iii) designation
the competitiveness of the institution and allow a response of an effective compliance function.
adapted to the needs of the customers. 8.1.6. Institutions must identify the sources of risk
of compliance, the most common being the following:
7.5.2. However, the provision of new services
and products may increase the risk for the institution, if a) Violations or non-compliance with laws and regulations
appropriate measures are not taken. Thus, the body prescribed;
management and top management must formulate a plan b) Failure to comply with contractual obligations
and inadequate legal documentation;
strategic for all new products.
c) Inadequate identification of rights and responsibilities
7.5.3. In order to fully comply with the strategic plan, between the institutions and clients;
institutions must: d) Customer complaints and other counterparts;
a) Review the performance of top management in relation to e) Damage against the interests of third parties;
goals set at least once a year. The Involvement in money laundering, violation
The review must determine if the performance is satisfactory. the rules of taxation, forgery and damages caused
and if the management is able to achieve the goals; by unauthorized collaborators in the system
b) Establish a succession policy or plan for (computer hacking), its intermediaries and clients; and
the management. Such policy or plan must be reviewed by g) Limited knowledge and delayed response from the management
less annually, be consistent with the structure in the implementation of legal risk management
organizational and with the terms of reference of the and reputational.
positions, and cover necessary training and qualifications 8.2. Oversight by the Administrative Body
minimum requirements for each position and professional career; Top Management
c) Monitor and control the performance of the agreements
8.2.1. Oversight by the Administrative Body
deoutsourcing;
d) Establish guidelines and compensation methods for [Link]. The administrative body must understand
the management and various collaborators. The compensation should the nature and level of compliance risk to which
be appropriate to the institution's financial robustness; and
the institution is exposed and what its risk profile is
fits within the global business strategy. They are
e) Establish a training plan and a budget
responsibilities of the administrative body:
suitable for its execution. Additionally, they must
a) Approve the compliance policy, including a
establish retention plans for employees who a formal document that establishes permanently
they have appropriate knowledge and understanding and it is the compliance function;
about the institution's business and operations.
b) Establish a capable management structure for
8. Guidelines for compliance risk management the implementation of risk management processes
8.1. Introduction of compliance;
c) Ensure that management takes necessary measures to
8.1.1. Compliance Risk is the possibility of occurrence identify, measure, monitor and control risk of
of negative impacts on the results or on the capital, arising from compliance, and to ensure that the compliance function
of violations or non-compliance with laws, regulations, it should be reviewed by internal audit;
contracts, codes of conduct, established practices or principles d) Periodically review the risk management policies of
ethical issues, as well as incorrect interpretation of the laws in force or
compliance to ensure proper guidance for
regulations. Institutions are exposed to compliance risk its effective management; and
due to the relationships with a large number of stakeholders e) Monitor the implementation of the compliance policy,
(shareholders, regulators, customers, etc.) and tax authorities including ensuring that compliance issues are
and places. resolved efficiently and swiftly.
8.1.2. The compliance risk can translate into sanctions
8.2.2. Oversight by Top Management
of a legal or regulatory nature, in the limitation of opportunities of
business,inreducingthepotentialforexpansionoranimpossibility [Link]. Top management is responsible for management and efficiency
to demand the fulfillment of contractual obligations. It can also of the institution's compliance risk, by establishing policies
to translate into the reduction of reputation resulting from a perception written that include the basic principles to be followed by
negative image of the institution by the stakeholders. institution, as well as explain the main processes through
8.1.3. The laws and regulations to be complied with by the of which the compliance risk must be identified and managed
institutions have various sources, including primary legislation, all levels of the organization.
rules and regulations established by lawmakers and supervisors [Link]. Top management, assisted by the compliance function,
of the market, conventions, codes of good practices promoted must
through the industry associations and applicable codes of conduct to a) Implement the compliance risk management system
staff or collaborators of the institutions. Consequently, the risk approved by the administration body;
compliance goes beyond what is legally binding and b) Establish an effective organizational structure of
covers the broadest standards of integrity and ethical conduct. compliance risk management and maintaining contacts
8.1.4. Compliance risk is difficult to measure, but it can be regularly with the collaborators directly affected
defined, understood and controlled within the capacity and readiness to the sector (technicians and lawyers);
from the institution to tackle cases of non-compliance. This risk Identify and assess the main associated problems
It can occur deliberately or not. to the compliance risks faced by the institution
18 DE SETEMBRO DE 2013 637

and the plans to manage potential failures, well b) Define the compliance risk and objectives
as the need for any other policies of your management;
or procedures to deal with the new risks c) Establish procedures to identify, evaluate,
of compliance; monitor, control and manage compliance risk;
d) Ensure that the conceptual framework for risk management d) To delineate responsibilities and establish that
the institution's compliance presents clear lines the governing body and top management must
of authority, reporting, and communication; to be fully aware of the scale of the events
e) Report periodically to the governing body associated with compliance;
or a designated committee on risk management e) Clearly define the tolerance limits of exposure
on compliance; to the risk of compliance;
f) Promptly inform the governing body or Establish the relationship with other management functions
the committee appointed on any relevant failures of risk within the institution and with the function
no compliance (for example, failures that may of internal audit;
to expose oneself to significant risk of legal sanctions g) Define the way compliance responsibilities are established
regulatory issues, high financial losses should be distributed among the departments, in the
or loss of reputation); cases where the compliance function is performed by
g) Ensure that there are human resources with knowledge collaborators from different departments; and
profound and skills to manage legal risk Establish the right of access to information
and compliance, and ensure that they are working necessary for the performance of their responsibilities,
to protect the reputation of the institution; and of the corresponding duty, of the institution's staff,
h) Ensure ongoing training for all lines to cooperate in providing this information.
of business, that covers the fulfillment of the requirements 8.4. Measurement, Monitoring and Systems
decompliance, especially when the institution enters Management Information
in new markets or offer new products;
i) Provide reasonable assurance, through the audit function, 8.4.1. Identification, Measurement and Monitoring
Compliance Risk
that all activities and all aspects of risk
legal and compliance are covered by the process [Link]. An effective measurement and monitoring process
of risk management; it is essential for the proper management of compliance risk.
j) Carry out an evaluation at least once a year, to understand its compliance risk profile, the institution
about the risk of compliance; and must identify the sources of risk to which it is exposed and assess its
k) Periodically review the conceptual structure of management vulnerability to these risks. Thus, the institution must identify
of compliance risk, to ensure that it continues and assess the inherent compliance risk of all products (new
adequate and healthy. and already existing), rules and procedures, internal processes
and activities.
[Link]. The scope of the compliance function and the necessity
[Link]. Institutions must define appropriate methods
the personnel (number and skills) depends on the size
for the evaluation of each identified risk source. There are
and the complexity of the institution's business. This function
various instruments used to identify and assess risk
it can be exercised by different collaborators in various
of compliance, such as:
departments, which must report to a manager who does not
have direct responsibilities in risk-taking. a) Self-assessment or Risk Assessment: an institution
[Link]. Regardless of how the function assesses the processes that support your operations
the compliance is organized within the institution, it must be against a library of threats and vulnerabilities
independent, with sufficient resources and clearly defined activities potentials, and considers their impacts. This process
defined. The responsible manager should not be in a position is conducted internally and often incorporates
of interest, that is, of executor and escalator. checklists to identify strengths
the weaknesses of the compliance risk environment;
[Link]. The compliance function must be separated
from internal auditing to ensure that its activities are b) Risk Mapping and Process Flow: These
subject to an independent review. However, the function two tools are widely used by
The audit must keep the compliance manager informed internal audits and can be very useful for reviewing
regarding your findings. the risk of compliance. These tools consist of
[Link]. The compliance risk must be included in the methodology in graphic summaries and diagrams that help
of risk assessment of the internal audit function, and must be the institution to identify, discuss, understand
and addressing the risks, as they represent sources, types
an audit program has been established that covers its adequacy
effectiveness, including a testing of controls compatible with of risks and the business areas involved. The review
the perceived levels of risk. two risk maps and the flow of processes by function
compliance allows for the risk of compliance
8.3. Policies, Procedures, and Limits be identified and appropriate procedures
8.3.1. The risk management policies and procedures of mitigation should be implemented. The maps
Compliance must be clearly defined and consistent with of risks also contribute to development
the nature and complexity of the institution's activities. of procedures and mitigation measures for
8.3.2. Compliance policies must be formulated the identified risks; and
in writing and to be part of the global risk management policy c)Indicadores de Risco: são estatísticas ou matrizes que
of the institution. They must: can you provide the institution's risk position.
a) Accurately determine all processes Such indicators may include the volume and/or
the important procedures to minimize frequency of law violations, the frequency of
the exposure to the institution's compliance risk; reclamações,númerodeprocessosjudiciaisefrequência
638 I SERIES - NUMBER 75

of fraud (real or suspected) or activities f) Monitor the compliance risk profiles in a way
of money laundering. They can provide regular; e
still good incentives, indexing the risk to capital g) Analyze the timeliness and accuracy of the reports
necessary for desirable improvement in compliance fromcompliancetotopmanagementandthegoverningbody
of the function. of administration.
[Link]. The institution must consider measurement methods 8.5. Process ManagementTools
of compliance risk using performance indicators, of Compliance
such as: (i) increase in the number of customer complaints; (ii)
corrective measures taken against the institution; and (iii) processes 8.5.1. Compliance Program
litigious for noncompliance with laws and regulations. [Link]. To control the compliance process, institutions
[Link]. The compliance risk can be measured through they must prepare a program or an agenda. The program must
regular reviews of legislation in different institutions, present all the aspects and specific activities of the
products, services, and relevant documentation, in order to compliance function for a determined period. In addition
ensure that all contracts are in compliance with thus, it should describe how, when, and by whom the program
the laws and regulations. This review may occur at each will be executed.
operation individually or may cover the legal adequacy of 8.5.2. Awareness, Training and Communication
documentation and standardized procedures.
[Link]. Awareness, training, and regular communication are
[Link]. The institutions are responsible for monitoring their
three essential elements of an effective compliance system.
risk compliance profile on a continuous assessment basis
Good awareness ensures that people understand the
fulfillment of the indicators of nests, aiming to provide
relevant topics. The training ensures that people who have to
an early management of risks. The monitoring must
being an integral part of the institution's activities, with the fact that performing compliance tasks encompasses how your work
your results should be included in periodic reports it is inserted in a broader context and know how to execute
of management. the necessary functions.
[Link]. Institutions must have processes and procedures [Link]. Compliance training is necessary for those
for the control of compliance risk. There should be a review whose work includes specific tasks or responsibilities of
constant progress of the institution in relation to compliance compliance. The compliance staff must receive training
dos objectivos legais e veri cação do cumprimento de políticas specific about the type of monitoring techniques used
the procedures, duties, and responsibilities defined. by the internal audit. In addition, they may require training
in matters such as compliance activity planning,
8.4.2. Sistemas de Informação de Gestão communication and effectiveness, notions of law and management skills.
[Link]. For effective compliance risk monitoring, The resolution of conflicts can also often be a
institutions must have a robust GIS that allows them to identify useful training area.
and measure your compliance risk in a timely manner and generate data
8.5.3. Effective Monitoring
the reports for management.
The effectiveness of risk control depends on the ability [Link]. The effective monitoring aims to verify
Identifying and measuring all risk factors must be supported. if people comply with their terms of reference and
for an appropriate and precise GIS that allows for analysis and decision making ensure that the system functions properly. A part
on timely decision-making. The SIG must be consistent with the importance of monitoring is to identify the main
the complexity of the institution's business and operations. potential risk areas and pay special attention to them,
[Link]. The institution must establish a database. regularly. Besides these objectives, the monitoring has
of your legal documents that includes: (i) types of documents as a purpose:
- contracts, memoranda of understanding, etc.; (ii) period a) Ensure that critical procedures are being
of document validation; and (iii) units or departments correctly observed;
responsible for the documentation. b) Help to solve difficulties still in the internship
8.4.3. Controlos Internos initial; and
c) Serve as an alert device.
[Link]. Institutions must have control systems
interno apropriados que integrem a gestão do risco de compliance 8.5.4. Effective Complaints System
in the global risk management process. The management audit [Link]. A complaints system that keeps records
the compliance risk must be incorporated into the annual plan of The cases are a valuable part of the compliance system. It is about
internal audit function. of a device for invaluable alert.
[Link]. The internal audit function, within its scope 8.5.5. Certifications
of activities, it should cover the following aspects of management
of compliance risk: [Link]. Certifications consist of a mechanism that subjects
certain business processes and activities for approval
a) Check if the management policies and procedures preview by the compliance function, in order to minimize risks in this
do risco de compliance foram implementados de forma area. The certifications have the following advantages:
effective in the institution;
b) Evaluate the effectiveness of controls for mitigation a) Draw attention to a possible occurrence of
of frauds and attacks on reputation; problems in areas that otherwise could not
c) Determine if top management takes action happen in an operational activity environment
appropriate corrective actions when failures are identified intense;
of compliance; b) Ensure maximum coverage and protection in areas in
d) Ensure that the scope and frequency of the audit plan that it is not practical to carry out independent verifications
are appropriate to risk exposures; regularly;
e) Determine the level of compliance of the management c) Direct the staff's mindset towards compliance
regarding the rules established by the Bank of organizational standards and/or requirements
from Mozambique; regulatory; and
18 DE SETEMBRO DE 2013 639

d) If the compliance system ever has to be c) Risks of 'Governance' and Control - These risks arise from
recognized in court, to demonstrate that always of losses resulting from poor execution or failure
there was an intention to ensure that all areas of internal procedures, personnel, and systems.
covered, as much as possible, even though These may also include the losses caused
the total coverage is not feasible. for failures of an organization in the observance of
9. Guidelines for Reputation Risk Management applicable laws, regulations, standards, and practices
9.1. Introduction industrial, which create a negative impact
9.1.1. The reputational risk consists of the probability in the market and in the perception of institutional integrity
of occurrence of negative impacts on the results or on the capital, by the customers.
resulting from a negative perception of the institution's image, 9.2. Supervision by the Administrative Body
founded or not, by clients, suppliers, Top Management
financial analysts, collaborators, investors, bodies of 9.2.1. The responsibility for managing reputation risk
press or by public opinion in general. This risk can affect
ultimately lie with the administration body. This must
the institution's ability to establish new relationships with the
your clients, counterparts, collaborators, investors, thus to address reputational risk in a clear, distinct, and manageable way
in order to ensure the security and robustness of the institution.
how to maintain existing relationships, being able to lead
9.2.2. It is especially the responsibility of the management body:
not only direct and immediate financial losses, but also
litigious processes, erosion of the customer base, difficulties a)Approve a reputational risk strategy and establish
in obtaining resources or the departure of key collaborators. a management structure capable of implementing it; and
9.1.2. The risk of reputation can emerge in all areas b) Conduct regular reviews of the strategy to ensure that
of business and has the following main components: the institution manages reputational risk effectively
a) Corporate reputation risk: which refers to and incorporate industry innovations into the processes
to performance, strategy and service delivery the management systems of reputational risk.
of an institution. This aspect is intrinsically 9.2.3. Top management must have an understanding
linked to the ability of management to create value for deep understanding of all aspects of operational risk and demonstrate
the shareholders and to manage the appreciation of their capital;
clear commitment to its fulfillment. The commitment must
b) Operational or business reputation risk: where be communicated throughout the institution.
an activity, action, or attitude taken by a 9.2.4. The responsibility for corporate reputation must be
institution, its allies or its collaborators harms it is the responsibility of top management and requires a multifunctional team
your image with one or more of your stakeholders, to create and implement the protection strategy.
resulting in loss of business and/or decrease Top management must ensure that a
significant value of the institution. crisis management procedure to manage potential events
9.1.3. The risk of reputation can emerge from a liable to affect the institution's reputation. Furthermore, it should
variety of causes, namely: ensure that there is no disclosure of information to the public or
a) Fraud and non-compliance or breach of the provisions- to the press without the proper authorization from management.
statutory or regulatory provisions; 9.2.6. Top management must implement a solid process
b) Breach of confidentiality or failures in the preservation of information and comprehensive risk management to identify, monitor,
confidential information of the institution's clients through control and report all risks that may cause harm to
of outsourcing relationships; institution's reputation.
a high volume of customer complaints 9.2.7. The audit and risk management committee of an institution
or regulatory sanctions; and they must be responsible for analyzing the adequacy and effectiveness of
d)Occurrences in other categories of risks that internal control systems, including those related to
they can threaten the image of an organization reputation risk and the means through which exposures
and the consideration of stakeholders. related to reputation risk are managed.
9.1.4. Categories of Reputation Risk: 9.3. Policies, Procedures, and Limits
[Link]. Institutions must pay special attention to three 9.3.1. The institution must have policies, processes
general categories of events or circumstances that give rise the procedures to mitigate material reputational risk. The
to the risk of reputation. However, the management methodologies
institutional privacy policies must consider aspects
employees must be sufficiently comprehensive to cover
legal and litigious.
all risks in each category.
9.3.2. Top management must translate the strategy
a) Intrinsic or Inherent Risk - This is the risk that arises of reputational risk established by the governing body
starting from products and services or the way of their
in policies, processes, and procedures that may be
supply, which produces a negative impact on
implemented and verified.
customer and market satisfaction. Thus, the risk
9.3.3. Notwithstanding the responsibility for adequacy
inherent mainly derives from shortcomings in material
the effectiveness of policies, processes, procedures, and controls
operational risk, quality control and satisfaction
of the client. each level of management must assign top management
b) Business Environment Risk - Includes the risks clearly authority, responsibility and reporting lines for
resulting from the way business is conducted encourage accountability. This responsibility includes
(for example, in a geographical, industrial area, ensure that the necessary resources are available for
politics, social), which, although it is not related a proper management of reputational risk.
with the quality of products or services, it may have 9.3.4. Top management must establish non-indicators
a negative impact on the market and on acceptance financial for reputation risk, in order to manage the transmission
of the brand by the customers. of information in the market.
640 I SERIES — NUMBER 75

9.4. Identification and Measurement of Risk transversal to various functional areas, on the other hand an activity
9.4.1. The administrative body must adopt a model can involve many inherent risks. Furthermore, it is common
of risk developed specifically to identify that a certain risk activates others. Consequently,
the structure of the control environment, as well as the specific type institutions must prepare a functional risk matrix
of risk controls and metrics that can be implemented to ensure that all relevant intrinsic risks for
throughout the institution. The administrative body must conceive,
their activities are captured.
10.2. The most common activities developed by
specifically, controls and metrics to deal with the category
institutions include loan granting, treasury,
of reputational risk from a qualitative perspective.
investments, foreign exchange market, mobilization of deposits, etc.
9.4.2. Risk identification is crucial for later
For the purpose of preparing the functional risk matrix,
development of metrics, monitoring and control
these activities must be derived from the items of the balance sheet
viable options for reputational risk. The institution must have a
and extrapatrimonial aspects of the institution, as well as the major sources
clear understanding of the main threats to your reputation, which
of profits, organizational structure, business plan
they can manifest through sustained media coverage,
for new and expansion activities and/or others
sudden drop in stock prices and loss of confidence in
activities of the institution. Below is an example of a matrix
customers. These can be caused by factors such as activism,
discrimination in the workplace, unethical business practices, failures functional risks:
demarketing, or other more traditional risks such as failures in Intrinsic Risks
products/services.
9.4.3. Once identified, the risks must be prioritized.
to help managers allocate efforts and resources.
This prioritization process should be linked to the strategies
institutional risk management.
9.5. Monitoring and Information System Loans x x x x x x
Risk Management 2. Deposits x x x x x
9.5.1. Each institution must conduct a review 3. Treasury and investment activities:
risk diagnosis to identify potential risk areas
Investments x x x x x x
of reputation. The governing body must require that the management
utilize proven analysis methodologies, as well as reviews Applications in the interbank market x x x x x x
independent and objective, designed to detect and analyze Liquidity management x x x x
risk factors, both quantitative and qualitative, and points Financial participations x x x x
of critical controls within the institution. Foreign exchange market x x x x x x
9.5.2. The examination of the probability and impact of the risk
4. Management information system x x x x x x
reputational only shows one side of the coin. The other side
requires an assessment of the institution's ability to prevent 5. Banking operations x x x x x
the risk or to assume it if it occurs. Index
9.5.3. Once the important risks have been mapped, the institution
must establish procedures to monitor warning signs I Introduction..................................................................... 1
previous in relation to its occurrence or worsening. A post [Link]..1
The important listening in the institution is the service department. 1.2. Applicability of the Risk Management Guidelines of.......
to the client, who can establish prior warning signals of certain Information Technologies...................................................... 2
trend before the problem reaches the public domain. A 1.3. Glossary......................................................... 2
The frequency of monitoring should reflect the risks involved II Guidelines for Technological Risk Management and
and the frequency and nature of changes in the operating environment.
The results of this monitoring should be included in the of Internet Banking 4
reports to top management and to the board of directors. 2.1. Risk Management Framework...................................... 4
9.5.4. There must be a system to ensure that 2.2. Type of Internet-Based Financial Services. 7
the identified sciences are timely managed and that 2.3. Security and Control Objectives ......................... 8
corrective actions and causes are implemented. The programs 2.4. Principles and Practices of Security............................ 12
training should be effective and resources made available 2.5. Development and Testing of Systems ...................... 16
necessary to ensure compliance. 2.6. Recovery and Business Continuity ................. 18
9.5.5. This process should help the institution to unravel 2.7. Outsourcing Management ................................. 19
the main risk factors with a high probability of giving 2.8. Distributed Denial of ServiceAttacks (DDOS) 21
origin to the risk of reputation. Each institution must ensure that 2.9. Disclosure of the Credit Institution........................ 22
the analysis methodology used is highly sensitive to your 2.10. Educação de Clientes .............................................. 23
specific needs and requirements, as well as the aspects
of risk posed by the industry. The review process must III Business Continuity Management Principles. 26
be totally objective. 3.1. Principle 1: The Board of Directors and the
10. Mapping of Intrinsic Risk to Functional Areas Senior Management should be Responsible for Management
10.1. The activities that institutions develop of the Institution's Business Continuity..................... 26
they encompass a vast array of intrinsic risks, such as the risks 3.2. Principle 2: Institutions must incorporate the
of credit, of liquidity, of the market (interest rate and exchange rate), Business Continuity Management in its Operations 26
operational, strategic compliance and reputation. The level 3.3. Principle 3: Institutions Must Test Their
The types of risks inherent to a certain activity depend Regular Business Continuity Plan, Ple-
of its nature and scope. If, on one hand, a risk can be Mentally and Significantly........................................... 27
18 DE SETEMBRO DE 2013 641

3.4. Principle 4: Institutions Must Develop the b) In the reinforcement of the security system, reliability,
your Recovery Strategies and Establish RTO availability and recovery capability
for the Critical Business Functions ............................... 28 and the resumption of critical business functions;
3.5. Principle 5: Institutions Must Perceive c) In the implementation of robust mechanisms of
Adequately Mitigate Interdependence Risks cryptography and authentication for data protection
dências das Funções Críticas do Negócio ................ 29 the customers' transactions.
3.6. Princípio 6:As Instituições Devem Planear Interrupções 1.2. Applicability of the Management Guidelines
of Vast Areas On the Risks of Information Technologies
3.7. Principle 7: Institutions Must Establish
a Segregation Policy to Mitigate Risk 1.2.1. The guidelines are statements of best practices
Concentration on the Critical Functions of the Business from the industry that institutions are encouraged to adopt. They
.................................................................................. 31 do not affect and should not be considered as statements
IV Appendices............................................................. 32 of the standard of care owed by credit institutions to
4.1. Appendix A: Disruption of Man-In- your clients. Where appropriate, credit institutions may
-The-Middle................................................................ 32 adapt the guidelines, taking into account their various
4.2. Appendix B: System Security Test ............ 33 activities, the markets in which transactions are conducted and their
risk profile. It is expected that credit institutions read
the guidelines together with the regulatory requirements
I Introduction relevant and industry standards.
1.1. Risk Management Associated with Technologies 1.2.2. The administration and top management of the institution
of Information credit is responsible for risk management, including
1.1.1. The continuous technological development has an impact the technological risks, which are becoming increasingly complex,
significant in the interaction of credit institutions dynamic and ubiquitous. The risk management process requires from
with your customers, suppliers, and related entities, well top management and administration review and evaluation of cost-
this is how they operate. benefit regarding investment in control measures and
The Internet, in particular, offers great opportunities security concerning computerized systems, networks, centers
for credit institutions to reach new markets and of data, operations, and alternative recovery facilities.
expand the range of products and services they offer to 1.2.3. The objectives of these guidelines are the promotion of
adoption of solid processes in the management of technological risks and
your clients. However, its great accessibility and dynamism
they bring both benefits and risks. of business continuity and the implementation of practices of
1.1.3. How credit institutions are increasingly dependent security, for which the Bank of Mozambique will incorporate them
but of information technologies (IT) and the Internet for the in your supervision process with the purpose of verifying if the
operationalization of your business and interaction with the markets, controls related to technological risks and security measures
the recognition of the magnitude and intensity of risks adopted by credit institutions are adequate.
technological inherent, both at the individual level of the institutions of 1.3. Glossário
Credit, like the entire financial system, must be increased.
For this, it is critical that credit institutions have processes Definitions (in the context of the present
risk management that allows for: Terminology
document)
a) Identify, assess, and classify the relevant risks for Business Continuity Management
your operations and systems; of Business Continuity.
b) Develop documented plans containing policies, Refers to a comprehensive framework that
practices and procedures that control these risks includes policies, norms and procedures
and ensure the continuity of the business; BCM that promote the continuity of functions of the
c) Implement and test the plans regularly; institution in the face of operational disruptions.
d) Monitor the risks and the effectiveness of the plans in a It must be compatible with the nature of
continuous base; institutions, dimension and complexity of
e) Periodically update the plans to take into account business activities.
the changes in the technological and business environment, Business Continuity Plan
as well as in legal requirements, including the threats of Business Continuity.
external and internal security vulnerabilities. It is an action plan that defines the
1.1.4. The objective of this set of guidelines is to assist the procedures and establishes the processes
BCP
credit institutions: necessary systems for restoration
a) In establishing a solid and robust framework the institution to the state of operation
in an organized and expedited manner, in case
of technological risk management and continuity
of the business; of interruption.
BusinessImpactAnalysis
of Impact on Business).
1Technological risk is related to any adverse result (damage,
It is the process of evaluation (quantitative
loss, interruption, breach, irregularity or failure) resulting from the use
and qualitative) of the impact on the business or loss
or dependence on hardware, software, electronic devices, networks and
telecommunication systems. These risks may also be associated BIA for the institution in the face of an interruption.
system failures, processing errors, software defects, errors of The BIA is useful for identifying priorities
operação, falhas de hardware, deficiência de capacidade, vulnerabilidade of recovery, the resource requirements
network, control weaknesses, security gaps, internal sabotage
of recovery, the recovery strategies
espionage, malicious attacks, hacking incidents, fraudulent conduct
and poor recovery capabilities. and the critical people.
642 I SERIES — NUMBER 75

Definitions (in the context of the present thoroughly evaluated and they should be assigned a character
Terminology a priority, with a view to allowing the development of a
document)
strategy for your treatment and mitigation.
It is the course of action for reconstruction
Due to the open and complex nature of the Internet,
of support functions for the condition in which
Recovery of the risks associated with the use of this infrastructure for banking
can process data or information. This
Negócio electronic are emphasized. Credit institutions must
condition must be at a sufficient level
take this factor into consideration in your management processes
to fulfill the business obligations. of risk. A clear understanding of the interaction between applications
Itistheplacementoffunctionsaftertheir based on the Internet, the back-end support systems
Returned recovery, in the condition of fitness for it is necessary to ensure that management and operational controls
Business to assume tasks and activities aimed at fulfilling the technicians are effective and suitable.
new business obligations. 2.1.3. Aspects of risk related to internet banking
Strategies of the defined, approved, and tested course of action and with the launch of new products or services they must be
Recovery for response to operational disruptions. evaluated and resolved during the conceptualization phases
Recovery Time Objective. and development. Procedures must be established
of risk control and security measures before or during
It is the time required to recover a
the implementation phase.
specific function of the business. It is composed of
2.1.4. Within the organizational structure, the management
two elements: (1) the time that passes since
the top management must scale all management functions
the moment of interruption and the declaration of
of risk. On a centralized, delegated, or distributed basis, this
activation of the BCP; (2) and the time that passes
since the activation of the BCP and the moment
scaling should involve the business, operational and
RTO of relevant support that have management responsibilities of the
in what the specific function of the business
technological risk at line or functional level. The monitoring
is recovered. the report on the effectiveness and compliance of risk management
Indicatethemaximumacceptabletimefor should ultimately escalate to the chairman of the committee
the recovery of a specific function executive and for the administration.
of the business, after which the non-recovery [Link],procedures,andpracticestodefine
would result in a significant impact on the risks, stipulate the responsibilities, specify the requirements
business and serious losses for the institution. of security, implementing measures to protect the systems
It is the risk that remains after the application. de informação, administrar os controlos internos e impor
Residual Risk
of mitigating measures. compliance must be defined as specifications
It is the risk of the failure of an institution essentials of the risk management framework. Management must lead
in fulfilling your obligations committing periodic risk assessments to identify internal threats
the fulfillment of obligations of the others and external factors that may weaken the integrity of the systems,
Systemic Risk financialsysteminstiutions, interfere with the service or result in the interruption of operations.
empoweringcreditproblemsand/ The assessment of threats and vulnerabilities can assist
/or liquidity and threatening stability the management in decision-making regarding the nature and extent
of the financial market. of the necessary security controls. They must be conducted,
internally and externally, awareness actions about
the security to promote and mature an environment
Guidelines for Managing Technological Risks of conscious security.
and Internet Banking 2.1.6. As part of the risk control framework, recovery
2.1. Risk Management Framework disaster management and business continuity planning are
2.1.1. A solid and robust risk management framework requires crucial in the development of contingency plans for
that the administration and management be responsible for the management the restoration of critical business operations after a
and control of technological risks. This responsibility requires disaster at primary processing facilities. None
the system is infallible or immune to misfortunes. Consequently, it is
the credit institutions conducting risk analyses through the
identification of information system assets, determination It is critical that there are effective means for timely recovery.
of security threats and vulnerabilities, estimate A credit institution must broadly identify
What types of disasters are eligible for the recovery plan.
of probability of exploitation or attacks, assessment of losses
Disasters can range from a total loss of service due to
potentials associated with these risk events and adoption of
to natural events to a catastrophic system failure caused by
security measures and appropriate controls for protection due to system failures, hardware malfunctions or errors
of assets. The risk analysis consists of the process of examination
of operation. A substantial task in the recovery planning
the technological infrastructures and systems to identify The purpose of disaster management is to compile a set of reliable procedures.
possible exposures, and in the consequent weighing of the pros contingency plans that cover various disruption scenarios
and the pros and cons of different risk mitigation actions. This step of operations or system failure.
requires an assessment of the damages that may occur to the assets 2.1.7. The requirements for site recovery and readiness
and the respective sources or causes. Controls are necessary. alternative processing must be periodically
security measures of information systems to ensure tested and validated, as well as evaluated regarding
the confidentiality, integrity, and availability of resources of the adaptation, effectiveness, and capacity of the personnel for
information technologies and the respective associated data. execute the contingency procedures and restore capacity
These assets must be adequately protected from access. of operation.
unauthorized, deliberate misuse or modification, insertion, The accentuated rhythm of technological innovations has changed
elimination, substitution, suppression or fraudulent revelation. the scope, complexity, and magnitude of the risks that institutions
The risks that are deemed material to the institution must be credit cards face in the provision of internet banking.
September 18, 2013 643

Credit institutions are required to have operations a person with potential to cause harm by taking advantage of a
and resilient processes that allow them to manage the inherent risks, vulnerability in a system. The source of threat can be natural,
respond to the same and adjust to new risks. human or environmental. Humans with motivation and ability
2.1.9. Risk management process: to carry out attacks are serious sources of threats through
deliberate acts or omissions that can cause immense harm
[Link]. The first step in any management process
to the institution and its information systems. An understanding
of risk is to assess the value of information systems assets
of the motivation, resources and capacity that may be required
deinstitutionalization that must be protected. This quantitative evaluation
to successfully carry out attacks must be developed when
can allow the institution to classify and prioritize the assets of
sources of threats and related vulnerabilities had been
information by value, so that management can make decisions
identified. A particular threat does not pose a danger
business supported by the control measures that should
when not associated with a vulnerability that can be
to be implemented to protect the assets. At the same time,
explored in the system. The matrix of threats and vulnerabilities
it is essential for the institution to have clear commitment in
may differ between institutions.
regarding the asset protection policy and its objectives of
security. Different types of systems will have different values 2.1.12. Risk management:
for the institution, depending on its impact in case of loss [Link]. For each type of identified material risks and
of confidentiality, integrity, and availability resulting from analyzed, management must develop and implement strategies
attacks, exploitation of vulnerabilities or adverse incidents. of mitigation and control consistent with the value of the asset of
[Link]. A comprehensive IT security strategy is a information and with the institution's risk tolerance level
vital component of an effective risk management process, that credit. Risk mitigation involves a methodical approach
should not be considered merely as a technical function in the establishment of priorities, evaluation and implementation
to be relegated to IT specialists. It is an essential function risk reduction controls and security measures
of management, which must have the support of top management. This function appropriate, arising from the risk assessment process. A
it involves identifying, measuring, and assessing risks, as well as formulating combination of technical controls and operational procedures
a plan to mitigate risks to an acceptable level. can probably provide a more vigorous way of reduction
2.1.10. Risk identification: of security risks. As it may not be practical
simultaneously addressing all identified risks, should
[Link]. With internet banking systems, the different
a priority is to be assigned to threat pairing
manifestations of risks, their magnitude and consequences
and vulnerabilities with a high risk classification,
assume new dimensions. The identification of risks implies
that can cause significant damage or impact. The management
the determination of all types of threats, vulnerabilities
and the exhibitions present in the configuration of the internet system it must also assess the amount of damage and loss that it may
support in the eventuality of the materialization of an event of
banking, consisting of components such as internal networks and
risk-related. The costs of risk controls must be
externals, hardware, software, applications, system interfaces
balanced according to the benefits derived.
operations and human elements.
[Link]. It is imperative that credit institutions are
[Link]. During the risk identification process,
able to manage and control risks in order to be able to absorb
it is necessary to take into account both the internet applications
any related losses that may occur without jeopardizing
and its interfaces, as well as the support systems
its financial capacity and stability. In the decision for
back-end. The risks and threats covering both sides and the
adoption of alternative controls and security measures, the
their respective interdependencies must be considered. This
management must be aware of the costs and effectiveness in relation to
aspect is important, as it establishes the fundamentals
risks to be addressed or mitigated. Where the risk to security and
for the understanding of risk and security posture of
the robustness of the system cannot be adequately controlled, the
aplicações de internet de uma forma mais abrangente.
credit institution must refrain from implementing and using
[Link]. Security threats as manifested in
the precarious system.
denial of service attacks, internal sabotage and infestation
[Link]. In view of the constant changes occurring in
Malware can cause severe disruptions to operations of
internet environment and online distribution channels, management must
a credit institution, with consequent losses for all
establish a monitoring and compliance regime on a basis
the affected parties. Continuous monitoring of these risks in continuous, to assess the performance and effectiveness of the process
mutation and growth is a crucial step in the exercise of
of risk management. When risk parameters change, the
risk containment. risk management process must be updated and improved from
2.1.11. Risk assessment: compliance. Reevaluations of equations must be conducted.
[Link]. Following the risk identification task, there are of previous risks, renewed tests and compliance audit
to be analyzed and quantified the potential effect and consequences the effectiveness of the risk management process and controls
of the same in the business and operations. In the event subordinate security measures.
of certain risks not being quantifiable, management still has it [Link]. The impact of internet banking on risk management
to define and take measures to understand its potential is complex and dynamic. Management must, on a constant basis,
impact and consequences in case of incidents occurrence. reassess and update your control and mitigation approaches
With this information, the management will be able to establish of risk to take into account variable circumstances and
priority for risks, carry out cost-benefit analyses changes to your risk profile in the Internet environment.
and make mitigation decisions. 2.2. Type of Financial Services Based
[Link]. The risk impact amplitude is a function on the Internet
of the probability of the conjunction or parity of various threats 2.2.1. Due to the open and dynamic nature of the Internet, the risks
the vulnerabilities capable of causing harm to the institution in associated with the provision of online services through this channel are
case of occurrence of adverse events. A threat can be larger and far more extensive than in closed networks and
regardless of any condition, circumstance, incident, or proprietary distribution channels.
644 I SERIES — NUMBER 75

2.2.2. Controls and security measures must be formulated dealing with and controlling these types of security risks and threats. The
specifics aligned with the risk management process. It is credit institutions must ensure that online access and
It is important that credit institutions establish controls. transactions made via the Internet are adequately
appropriate security benchmarks for your operations protected and authenticated. This requires the establishment of a
deInternet. security strategy to allow the achievement of the following
The level of Internet risks is directly related objectivos:
to the type of services provided by credit institutions. a) Data confidentiality;
Typically, internet-based financial services can b) System integrity;
classified in information services, interactive exchange c) Availability of systems;
of information and transactional. d) Customer and transaction authenticity;
2.2.4. Information service: e) Customer protection.
[Link]. This is the elementary form of online service on the Internet. 2.3.2. Data confidentiality:
It is a unidirectional communication through which one can [Link]. Data confidentiality refers to the protection
make available information, advertising or promotional material of sensitive information from curious eyes and access permission
to customers. Many small credit institutions choose authorized. The online systems of the credit institution must
just make information available on the Internet, configuring use an appropriate level of encryption according to the type and extent of
standalone servers or buying advertising spaces in risk present in your networks, systems, and operations.
other websites hosted by third parties. [Link]. Notwithstanding the absence of a robustness prescription
[Link]. Although the risks associated with such online services
specific or of a certain type of encryption, it is expected that
be low, these websites are frequent targets of hacking, that
the credit institutions evaluate appropriately the
vandalism and mutilate the original information. An institution of
security requirements associated with your Internet systems
credit may suffer reputational damage as a result of a and adopt an encryption solution appropriate to the level of
attack and vulgarization of your website.
confidentiality and integrity required. Additionally, the
[Link]. When a credit institution buys a space
credit institutions must only select algorithms
the advertiser of a third party must carry out monitoring
that are internationally accepted standards and that have
regular not only in the advertising of the credit institution, but
subjected to rigorous scrutiny by a community
also, from the associated content of the service provider.
international cryptographers or approved by agencies
Reputational damage can be caused by association with
official professionals, reputable security vendors or
defamatory advertising being hosted on the same service.
government agencies.
2.2.5. Interactive information exchange services: The most important aspect of data encryption is
[Link]. This form of Internet service offers a bit the protection and confidentiality of the cryptographic keys used,
more interaction between the credit institution and the client, whether master keys, main encryption keys
when compared to the previous one. Customers are able to or encryption keys of data. No individual should
communicate with the credit institution, check your accounts and to fully know what the keys are or to have access to all
fill out application forms for additional services or purchase the components that make the keys. All keys must
the products offered. The risks related to these websites to be created, stored, distributed, or altered under the most
depend on the existence or not of direct connections to the internal network rigorous conditions. The sensitivity of data and criticality
from the credit institution. These risks range from low to moderate, operational should determine the frequency of change of the
depending on the connectivity between the Internet and the internal network and keys.
the applications that customers can access. [Link]. The main application of cryptography consists
2.2.6. Transactional services: in the protection of data integrity and privacy by a
fixed term, instead of an indefinite period.
[Link]. This category of internet banking services allows
No encryption process is more secure than the systems.
to customers execute online transactions, such as the transfer of
hosts that run it. hardware security modules
funds, bill payments, and other financial transactions.
and similar tamper-resistant devices provide
[Link]. This is the highest risk category that
the safest way to execute encryption functions
requires stronger controls, given that online transactions are
decryption. Other methods can also be considered
normally irrevocable, once executed. The systems of
acceptable if they provide sufficient protection
The credit institution's internet may be exposed to attacks.
of encryption keys and confidential data in an operation
internals or externals if the controls are inadequate. A
end-to-end encryption.
the added risk element consists of the fact that attacks
against internet systems do not require physical presence on site [Link]. The security encryption in relation to the PIN of
to be attacked. At times, it is not clear or detectable client and other sensitive data must be kept secure
when and how attacks are launched from multiple the endpoint at the application layer. This means that the
places. the encryption process is kept intact from the point of entry
from data to the final recipient system where the decryption is
2.3. Objectives and Security and Control
or authentication occurs.
The Internet is an intrinsically insecure global network.
2.3.3. System integrity:
Security threats resulting from denial attacks
services, spamming, spoofing, sniffing, hacking, keylogging [Link]. The integrity of systems refers to accuracy,
phishing, middleman interception, mutant viruses, worms ability and totality of the information processed, stored
and other forms of malware represent high levels or transmitted between the credit institution and its clients.
of technological risk that credit institutions face A high level of system and data integrity must be
with increasing frequency. It is imperative that the institutions achieved consistently with the type and complexity of
implement strong security measures that can online services provided
18 DE SETEMBRO DE 2013 645

[Link]. With an Internet connection, anyone can [Link]. It is expected that management establish procedures and
potentially access, from anywhere and at any time ferramentas de monitorização para acompanhar o desempenho dos
moment, to the internal networks of credit institutions. Additionally systems, server processes, traffic volumes, duration of
therefore, transaction errors and operational failures resulting from transactions and utilization capacity on a continuous basis for
processing or transmission may remain latent and ensure a high level of availability of your services
undetectable for indefinite periods, as long as internet banking.
Internet systems generally employ more processes 2.3.5. Authenticity of the customer and the transaction:
more automated than other less complex systems. [Link]. In internet banking, encryption technologies
[Link]. Credit institutions must install systems of play an important role in ensuring the
monitoring or surveillance capable of alerting them about any confidentiality, authenticity and integrity. The clients are
wandering activities of systems or about online transactions not required to provide your combination of User ID and PIN or a
usual that occur. one-time use password (OTP) 5), dynamic access code
[Link]. Control determinants that are relevant for the the digital signature, so that the identity and authenticity
integrity of systems includes: can be verified before access to their accounts is
a) Logical access security2; guaranteed. In basic terms, this authentication process
b) Physical access security3; it is used to validate the customer's identity, checking 'what the
customer knows" (usually a password or personal number of
c) Processing and transmission controls4.
identification) and "what the customer has" (such as a device of
2.3.4. System availability: hardware that generates OTP at predetermined time intervals
[Link]. Um nível elevado de disponibilidade de sistemas or a USB token that contains a digital certificate and your
it is required to maintain public trust in an environment of associated private key.)
online network. All security components and controls [Link]. Two-factor authentication for login to
previous ones are of little value if an online service is not systems and transaction authorization can be based on two
available when needed. In general terms, users of any factors that follow:
of banking services expect to be able to access a) What you know (for example, PIN);
to the online systems 24 hours a day, every day of the year, b) What it has (for example, OTP token);
equivalent to almost zero system unavailability. c) Who is (for example, biometrics).
[Link]. Important factors associated with maintenance [Link]. Given the proliferation and diversity of attacks
high system availability includes: adequate capacity, cyber incidents, credit institutions must implement
performance, fast response time, scalability and two-factor authentications at the time of login for everyone
quick recovery capacity. The credit institutions, the types of internet banking systems and for authorization
your service providers and vendors who provide of transactions. The main objectives of authentication of
internet banking services must ensure they have resources Two factors are protecting the confidentiality of data from
broad and capacity in terms of hardware, software and customer accounts and transaction details, as well as
other operational capabilities to provide services improve trust in internet banking, combating phishing,
consistently achievable. keylogging, spyware, malware, man-in-the-middle attacks and others
[Link]. In the context of online banking services, the systems forms of fraud through the Internet, targeting the
Interface support is as important as the system. credit institutions and their clients.
host. In the provision of applications that run on the [Link]. Credit institutions must also require
the repetitive use of the second factor of authentication (for example,
Internet, the credit institutions will also be using
OTP) for high value transactions or for changes to
existing mainframes or backend host systems. The
sensitive customer data (for example, the address of the location
even per availability for both systems facing
of work and residence of a client, contact details of
end and back-end may be necessary to provide the level of
email and telephone) during a login session.
reliability and consistency of service expected by customers. An authenticated session, together with its protocol of
[Link]. Processing via the Internet typically involves a encryption must remain intact throughout the interaction with
number of interdependent complex systems and components the client. In case of interferences, the session must be terminated
of the network. A system can become inoperable when a and the affected transactions canceled. The customer must be promptly
critical hardware component or software module to function notification of the incident that occurred while the session is taking place
bad or damaged. Therefore, the credit institutions terminated or subsequently by email, telephone
they must maintain the hardware, software, and network components or by other means.
necessary for a timely recovery. [Link]. Authentication requirements are normally
achieved by the use of cryptography or related protocols
and strong functions, such as Triple DES, AES, RC4, IDEA,
2
Logical security is associated with how data is accessed and RSA, ECC, OATH and RFC 2104 HMAC. Cryptographic functions,
stored in a system or storage medium. Access controls
logically, they are preventive and detective measures that restrict access to
algorithms and protocols must be used for authentication
user to permitted data/information. logins and protect the communication sessions between the client and the
3Physical access security is related to the location and how resources credit institution. The robustness of the figures largely depends on
two systems, data assets and storage media are located of your design, construction, and size of your keys.
and protected. Physical access controls include preventive measures that
they grant selective physical access to specific individuals.
[Link]. The constant advances in computer hardware,
4The processing and transmission controls are associated with data. computational number theory, cryptanalysis and brute force techniques
["input","processing","communication","transmission","output","storage"]
and data acquisition. The controls can be preventive, detective or
corrective actions in the treatment of errors, irregularities or deviations. 5OTP:One-time password
646 I SERIES — NUMBER 75

distributed brute force can induce the use of larger keys integral to a two-factor authentication architecture,
length in the future. Some contemporary algorithms of credit institutions must implement measures
figures may need improvement or replacement when appropriate to minimize exposure to man-in-the-middle attacks,
lose their power in the face of the progressive increase in speed which are commonly known as the attacks
the power of computers. -in-the-middle(MITMA) 7man-in-the-browser
[Link]. Besides the obvious application of encryption in authentication application (annex A for details).
the privacy of online transactions, strong encryption [Link]. The distribution of software via the internet is becoming
provides the basis for access control enforcement, increasingly popular. However, in the context of internet banking,
transaction authorization, data integrity and responsibility. download and run software code, plugins, applets, programs
To increase security in online processing, a channel ActiveX and other executable smells from anonymous sources or not
secundário de con rmação6the procedures must be applied verifiable is possibly one of the riskiest actions that
in relation to transactions above predetermined values, creation
a client can take on their personal computer. The threats
new account linkages, payment detail registration
to entities, changing account details or review associated with downloads is significant if the customer cannot
of transfer limits. In the organization of these functionalities legitimize the source. Many incidents occur where users
for security, the credit institution must take into consideration on the internet are deceived by hackers into downloading Trojan horses,
its effectiveness and the different preferences of customers regarding backdoors, viruses, and other malicious software that causes damage
concerns online protection. the harmful consequences.
[Link]. Based on mutual authentication protocols, [Link]. Credit institutions should not distribute software
clients will be able to authenticate on the institution's website for customers via the Internet or through a system based
of credit through security mechanisms such as unless they can provide appropriate measures
personal certification messages/images, response to codes of security and protection. This implies that customers must
of security of challenge mechanisms, verification being able to verify the provenance and integrity of the software
of the secure sockets layer (SSL) server certificate. To highlight
downloaded and authenticate the digital signature of the credit institution
that SSL is only used to encrypt data in transit
incorporated in the provided software, through a certificate
in the transport layer of the network, not providing security
end-to-end decryption at the layer level digital provided by the credit institution. On the other hand,
of application. the credit institution must be able to verify the authenticity
2.3.6. Customer protection: and the integrity of the software in use by the clients.
[Link]. Internet banking has become a fundamental means 2.4. Principles and Practices of Security
and even in a primary electronic distribution channel for 2.4.1. The principles and practices of security can limit
a large number of banks. Customers regularly the risk of external and internal threats to security
access the websites of your banks to check and the integrity of internet-based systems. When
their respective accounts and to carry out a varied range adequately implemented and observed, these also
of bank transactions for personal or professional purposes. we safeguard the authenticity and confidentiality of the data
However, popularity and accessibility on a global scale and of the operational processes.
Internet banking faces a growing number of threats
2.4.2. Security practices usually involve
dehacking
combinations of hardware and software tools,
[Link]. Customer protection is of great importance
in internet banking. The credit institution must ensure that administrative procedures and personnel management functions
the customer is properly identified and authenticated, before that contribute to building secure systems and operations.
to be granted access to sensitive customer information These security principles, practices, and procedures are
or bank functions. Sensitive client information includes collectively known as the functions of politics and process
particular or account details that can be used to of the security of an institution.
identify a client. 2.4.3. Human resources management:
In past years, security threats [Link]. Ultimately, for safety on the internet, with
of the Internet were normally passive in nature, involving -in a small group of specialists, who must
mainly eavesdropping and password guessing.
are subject to appropriate controls. Their activities and access
Currently, direct attacks on banking systems and PINs
resources of systems for any reasons must be subject to
of clients intensified. Through targeted attacks
a thorough examination. It is important that strict criteria
phishing, fake websites, spamming, viruses, worms, horses
and meticulous care should be taken in the selection of personnel for
trojan, trapdoors, keylogging, spyware, middleman infiltration
Customer PINs are under constant threat from various the internet operations security functions. The staff
types of system vulnerabilities, security flaws involved in development, maintenance, and operation
scams. The website systems must be properly formatted.
[Link]. The essence of two-factor authentication technology in principles and practices of security.
factors is the availability of a range of tools
of security, devices, techniques, and procedures to contain
the cyber threats and attacks described above. As part
7 In a man-in-the-middle attack, the intruder is able to read, insert
and modify messages between two parties in communication without the
participants became aware that the connection between them was compromised.
6The second channel is any separate communication mechanism. Possible points of MITM attacks can be client computers,
of the internet banking system and its availability channel. It can be internal networks, information service providers, web servers
telephone, SMS, email or a manual process involving or anywhere on the internet along the way between the user
forms and handwritten signatures. and the server of the credit institution.
18 DE SETEMBRO DE 2013 647

[Link]. Three of the most basic internal security principles8 could potentially jeopardize customer confidence in the systems
for the protection of systems are: of internal control and processes of the credit institution.
a) Principle never alone: [Link]. No one should have simultaneous access to the systems.
of production and backup, particularly to the data smells
Certain functions and procedures of systems are
so sensitive that they must be treated and to the computing centers. Anyone who needs
together by more than one person or to access backup scents or recovery resources
executed by one person and immediately the system must be properly authorized for a purpose
verified by another. These functions include specific and for a determined period. Accesses that are not
the initialization of systems, configurations for a specific purpose and for a determined period of time not
network security, system installation must be granted.
access controls, parameter changes [Link]. Sellers and service providers, including
of operating systems, implementation consultants, to whom access to the resources has been granted
the critical network and computational systems of the institution represent
firewalls of prevention systems
ofintrusion,modifcationofplans similar risks. This external personnel must also be subject to
of contingency, invocation of procedures strict supervision, monitoring, and restriction of access in a way
emergency, obtaining access to resources similar to the internal staff.
backup creation of master passwords and keys [Link]. Some of the common tactics used by insiders
cryptographic. include the deployment of logical bombs, installation of scripts
b) Principle of segregation of duties: stealthy, creation of backdoors in systems to gain unauthorized access
authorized, sniffing and cracking passwords. The administrators
The segregation of duties is an essential element of systems9IT security officers, programmers
of internal control. The responsibilities and people who perform critical tasks invariably have,
and tasks that must be separated and executed the ability to inflict severe damage on internet systems
by different groups of people are the function of banking that maintains or operates by virtue of its functions
system operation, design and development and privileged access.
of systems, maintenance programming [Link]. People with high access to the systems must be
of systems, computer operation, strictly supervised and all their activities of
database management, administration systems must be registered, as they know the systems by
access control, data security, inside and have resources to circumvent system controls
custody of data backup libraries. the security procedures. Below are listed some
It is also desirable to establish a rotation of recommended controls and security practices:
tasks and cross-training for the functions
of security management. The processes of a) Implement two-factor authentication for
transactions must be designed in such a way that privileged users;
no one can individually initiate, approve, b) Establish strong controls over remote access by
execute and introduce transactions in a system privileged users;
in a way that allows for the perpetration c) Restrict the number of privileged users;
of fraudulent actions and the concealment of details d) Grant privileged access based on
of processing. in need;
e) Maintain audit records of system activities
c) Access control principle:
carried out by privileged users;
Access rights and system privileges must be f) Ensure that privileged users do not have
based on the responsibilities of each position and in access to the system records in which your
need to carry out allocated tasks. No one activities are captured;
must, by the category or position it occupies, have any g) Conduct regular audits or management reviews
intrinsic right to access confidential data, the audit trails;
applications, system resources or installations. Only h) Prohibit the sharing of privileged IDs and their respective
to the collaborators with appropriate authorization, one must access codes;
consent to access confidential information and use i) Do not allow suppliers and vendors to have
of system resources, only for the purposes privileged access to systems without strict supervision
legitimized. and monitoring; and
[Link]. Internal sabotage, espionage or attacks j) Protect backup data from unauthorized access.
sneaky actions by employees with suppliers and vendors 2.4.4. Security practices:
is potentially among the most serious risks that an institution [Link]. Credit institutions must comply with
credit faces. Current and separated employees, the following security practices:
suppliers, sellers and those who have knowledge a) Implement robust operating systems:
deep understanding of the internal workings of the institution's systems Software firewall systems must be
of credit, operations and internal controls have an advantage configured for security parameters
significant about external attackers. A successful attack higher, consistent with the level of

8 These internal control principles can be adapted depending on


from the separation of responsibilities, division of tasks, environmental variables, 9For the purposes of this document, system administrators are

system settings and compensatory controls. Where relevant, aquelas pessoas a quem se tenha concedido acesso privilegiado para manter
physical security is attributed to principles and control practices or operate systems, computing equipment, network devices,
applicable. security tools, database and applications.
648 I SERIES — NUMBER 75

required protection, keeping up with the v) Implement a multi-layer application architecture,


updates, patches, and recommended improvements what differentiates session control from logic
by system vendors. Aspasswordspor of presentation, the validation of inputs on the side
defects must be changed immediately after of the server, the business logic, and access to the database
the installation of new systems. of data.
w) Implement two-factor authentication for login to
b) Install firewalls between the internal and external networks and between
geographically separated sites. all types of internet banking OTP systems
c) Install intrusion detection-prevention devices specific or digital signatures for each transaction
(including security devices against attacks) above a predetermined value set by the client or by the
of the DoS type). credit institution.
d) Develop embedded redundancies for single points x) Implement strong encryption and encryption at the layer
of failures, which can damage the network. end-to-end application to protect the PIN
e) Carry out security reviews of systems using two clients, user passwords and other data
a combination of source code review, sensitive on the network and on storage devices
stressloadinge teste de excepção para identi car of data.
insecure coding techniques and vulnerabilities y) Encrypt customer accounts and transaction data
of systems. when transmitted, transported, delivered
f) Hire independent security specialists10 or distributed by mail to external entities or
to assess the robustness and weaknesses of the applications in various locations, taking everyone into account
based on the Internet, systems and networks before the the intermediate moments and transit points.
initial implementation and at least annually, z) Implement strong user authentication in local networks
after the implementation, preferably without notification wirelessly protect sensitive data with encryption
preview for the internal staff who operate or respond to the the strong integrity controls.
systems or activities. 2.5. Development and Testing of Systems
g) Conduct penetration tests, at least on a basis Many systems fail due to design problems
annual. the inadequacy of the tests conducted. The deficiencies of systems
Establish network supervision and procedures should be detected as early as possible, during design or testing. For
monitoring using network scanners, for large-scale projects, a committee should be established
intrusion detectors and security alerts. of management, consisting of the management of various areas, elements
i) Implementar programas antivírus. from the development team and key users. To this committee
j) Conduct regular reviews of system configurations It will be the responsibility of scaling and monitoring of
and data integrity checks of the network. progress of the projects, including deliverables and milestones
k) Maintain access records and audit trails. to be achieved according to the project plan.
l) Analyze the audit logs regarding traffic 2.5.2. System development life cycle:
suspect and attempts of intrusions. [Link]. Management framework of the development life cycle
m) Implement an incident management and plans of systems, the tasks and processes for development
of response. the acquisition of new systems must include the assignment
n) Test the predetermined response plans outline of responsibilities for deliverables and milestones
of security incidents. of projects. The functional requirements, the specifications of
o) Install network monitors that can observe design and techniques and the performance expectations of the systems
in determining the nature of an attack and helping they must be properly documented and approved by a
in your containment. competent management body.
p) Develop and maintain a recovery strategy [Link]. Additionally to the business functionalities,
the business continuity plan based security requirements related to access control
in the entirety of the needs of technologies to the system, authentication, transaction authorization, integrity
of information, operational and business. data, system activity log, audit trail,
Maintain a fast recovery capacity. security event logging and exception handling
They must be clearly specified. Verification is expected.
Conduct educational awareness programs
in compliance with the system with security standards of
of security.
credit institution and with the regulatory requirements.
s) Request frequent IT audits to be conducted
[Link]. The methodology approved by the management must establish
by security professionals or by internal auditors how are you testing11of the system must be conducted. The scope
that have the skills for this purpose. the tests should cover the business logic, security controls
t) Consider hiring insurance for insurable risks, the system's performance across various effort scenarios
including the costs of recovery and restitution. and recovery conditions. A complete regression test
u) Create physically or logically separate environments for must be carried out before the implementation of corrections or
the development, testing, and production of systems. of significant improvements. The test results must be reviewed
Connect only the production environment to the Internet. and oil used by users whose systems and operations are
affected by the new changes (see appendix B for details)
10Throughout this document, independence has a meaning
related to system security testing
functional, as a review or evaluation can be carried out by
proficient and competent specialists or auditors who are not
11The tests generally include unit testing, the test
operationally responsible for the function, task or activity to be
magazine, audited or assessed. of integration, the system test and the user acceptance test.
18 DE SETEMBRO DE 2013 649

[Link]. Penetration tests must be conducted beforehand of errors and verbose banners, hard-coded operations
the introduction of a new system that offers data, files and directories must be
accessibility through the Internet and open network interfaces. scrutinized to detect inappropriate disclosure
Its complementarity with vulnerability scanning of information.
of external and internal network components that support the new b) Evaluate the resilience against input manipulations
The system constitutes an expected logical outcome. The scanning (input):
Vulnerability assessments should be conducted at least quarterly. The test must review all validation routines.
with penetration tests at least annually. of entries and evaluate their effectiveness against
[Link]. To control the migration of new systems or known vulnerabilities.
changes to the production environment, it is important that they are c) Identify unsafe programming practices:
established separate physical or logical environments for testing
The test must identify unsafe practices
unit, integration, system, and user acceptance.
of programming such as the use of
The access of suppliers and developers to the environment of
of vulnerable function calls, the management
User Acceptance Testing (UAT) must be monitored.
inadequate memory, the passage does not
strictly.
argument verification, logging comments
2.5.3. Source code review: inadequate, the use of relative paths
[Link]. There are different ways of encoding (relative paths), logging of passwords and credentials
of programs that can hide vulnerabilities and gaps of authentication, and the inappropriate assignment
intentional or unintentional security loopholes. System testing of access privileges.
and user acceptance criteria are not effective in detection d) Detect deviations from specifications
malicious code, trojan horses, backdoors, logic bombs from drawing:
and other types of malware. No test set for the box- The implementation oversight is one of the most common.
-black is able to identify or detect these vulnerabilities sources of vulnerabilities in a well-built application
of security. designed. Critical modules containing functions
[Link]. Source code review is a methodical examination of authentication and session management must be
of the source code of an application with the aim of finding controlled in relation to discrepancies between
security defects that are due to coding errors, the design of the code and its implementation.
unsafe coding practices or malicious attempts.
e) Evaluate exception handling:
It is designed to detect security vulnerabilities,
gaps and errors (related to the control structure, When exceptions or abnormal conditions occur,
security, input validation, exception handling, appropriate controls must be established
the update of the file, the verification of function parameters, to ensure that the resulting errors do not
the availability, integrity, resilience, and execution) in the phase may allow users to escape from the
of development and correct them before implementation of security checks or obtain core
system. Simultaneously, the quality of the code and practices of dumps. Sufficient processing details
programming can also be improved. The convenience of must be recorded at the source of the exception for
direct processing from highly integrated systems to assist in diagnosing the problem. However,
frontend on the internet coupled with backend hosts can create system or application details, such as
opportunities for corrupted data or malicious codes stack pointers should not be revealed.
propagate between contiguous systems, passing from one segment f) Evaluate the cryptographic implementation:
from network to network. These types of infections and spread can
there are systemic repercussions. Only standard-based cryptographic modules
[Link]. A high degree of integrity of systems is required authorized and well-established protocols
and data for all applications with Internet access. must be installed. Functions involving
The credit institutions are expected to take the necessary steps. cryptographic algorithms and configurations
to ensure that these applications have security controls cryptographic keys must be controlled
appropriate, taking into consideration the type and complexity regarding deficiencies and security gaps.
of the online services they provide. This review should also assess the choice
[Link]. Based on the risk analysis of the credit institution, from the figure, key sizes, protocols
módulos aplicacionais especí cos e suas protecções de segurança key exchange control, functions
must be rigorously tested with a combination dehashing random number generators.
of source code review, exception testing, and revisions 2.6. Recovery and Business Continuity
in compliance to identify errant coding practices 2.6.1. Given that no computerized system is
and system vulnerabilities, which can lead to incidents indestructible or possessing impenetrable security, the need
of security and violations. Although they may diverge into various
contingency planning and recovery capacity
applications, the security testing methodologies must cover It is critical. The priorities for recovery and business continuity
o seguinte: they must be defined and the contingency procedures must
a) Identify information leaks: to be tested and practiced, so that they are minimized
Sensitive information such as cryptographic keys, the interruptions resulting from serious incidents. The plan
account details and passwords, settings recovery and incident response procedures
system and connection instructions to the database they must be evaluated periodically and updated always
data should not be disclosed. Sources that changes in business operations and systems are observed
potential information leakage with messages and networks.
650 I SERIES — NUMBER 75

2.6.2. During a system outage, institutions 2.7.3. Outsourcing risk management:


creditors should avoid adopting recovery measures [Link]. The board of directors and senior management
improvised and untested at the expense of actions they must fully understand the associated risks
predetermined recovery plans that have been tested outsourcing your internet banking operations. Before
and endorsed by management. Ad-hoc recovery measures that a service provider is chosen, must be carried out
pose a high operational risk, given that their effectiveness the necessary diligences to determine its viability,
it was not verified through rigorous tests and validations. capacity, reliability, history and financial position.
2.6.3. A recovery center must be established The terms and conditions governing the roles,
geographically separated from the primary processing center relationships, obligations, and responsibilities of the parties must
to ensure the restoration of critical systems and continuity be careful and appropriately defined in written agreements.
the business operations in the event of occurrence The substance covered in the agreements must, in general, cover objectives.
of interruption in the primary center. It must be established and maintained performance, service levels, availability, reliability,
a fast recovery capability, through a hot site12. scalability, compliance, audit, security, planning
The required recovery speed will depend on the criticality. contingency, disaster recovery capability
resumption of business operations, of the type of online services backup processing installation.
and the existence of alternative paths and processing methods [Link]. Unless there are mutually acceptable agreements,
to maintain adequate levels of service continuity. the service provider must be required to provide access
2.6.4. It is vital that credit institutions include in their to all entities indicated by the credit institution to its
incident response procedures a pre-action plan systems, operations, documentation and installations so that they can
determined to address issues of public relations. conduct regulatory compliance reviews or assessments
It is of great importance for the reputation and solidity of the institution or audit. Notwithstanding the exception mentioned above,
of credit that this can maintain customer trust during the agreements must provide for conducting inspections of the paper,
the period of crisis or emergency situation. responsibilities, obligations, functions, systems and facilities
2.6.5. The preparations for incident response and recovery by the Bank of Mozambique.
Disaster and business continuity plans must be reviewed [Link]. Credit institutions and service providers
regularly updated and tested to ensure your must observe the secrecy obligation requirements set forth in the Law
effectiveness and the capability of the responsible personnel to of Credit Institutions and Financial Companies. The contracts
carry out emergency and recovery procedures service providers must take into account
when necessary. The recovery readiness must anticipate the need for protection of information confidentiality
totally shut down or incapacitation of the center two clients, as well as the need for compliance with laws
primary processing. the applicable regulations.
2.6.6. Banks that have their network and systems connected 2.7.4. Monitoring of outsourcing arrangements:
service providers and vendors must conduct tests [Link]. The credit institution must request that the provider
of bilateral or multilateral recovery and ensure that of services implement security policies, procedures and
the interdependencies are equally met. We control that we meet contractual requirements. Additionally,
2.6.7. The possession of action plans is of utmost importance must review and monitor security practices and processes
predetermined to counter and contain denial attacks from the service provider on a regular basis, including the
of services. The ability to restore normal operations commissioning or obtaining periodic reports from experts
quickly and effectively after a denial of service attack regarding the adequacy of security and compliance in relation to
must be an integral part of the process of reconciliation and recovery to the service provider's operations. It must be established a
of the system. continuous review process of service provision, in terms
of reliability, performance, and processing capacity
2.7. Outsourcing Management
with the purpose of verifying compliance with service levels
In internet banking, it has become common that agreed upon and the viability of their operations.
credit institutions outsource part of [Link]. As outsourcing relationships
or of all computational processing, of systems and of and as the dependencies increase in complexity and importance,
administrative operations to service providers, companies A rigorous risk management approach must be adopted.
telecommunications, specialized companies and others to ensure that responsibilities are not dissipated
operators (generically and collectively referred to as providers from the management for the protection of nuclear operations and services
of services). from the credit institution.
2.7.2. Regardless of the reasons for outsourcing, which 2.7.5. Contingency and continuity planning
of the business:
they can include rapid development of technologies and access
the competencies not available internally, it is up to the institutions [Link]. The management must require the provider
of credit to ensure that your service providers are develop and establish a contingency framework
able to provide the level of performance and reliability the disaster recovery procedures that define your
of service, capacity, and security necessary for your business paper and responsibilities in documentation, maintenance, and testing
of Internet banking. The responsibility and accountability two contingency plans and recovery procedures.
Since human error has a greater contribution to the number
the credit institution's activities are not reduced by outsourcing its
operations to third parties.
of failures and downtime of the systems, all parts
and the involved personnel should receive regular training in
activation of the contingency plan and execution of the procedures
12The replica of the primary processing center must have capabilities
for recovery. This plan must be reviewed, updated, and tested.
operational and resources that allow achieving a time objective of regularly according to the conditions of technological evolution
recovery of 4 hours or less. and with the operational requirements.
18 DE SETEMBRO DE 2013 651

[Link]. The credit institution must also establish 2.8.5. Selection of Internet Service Providers:
a contingency plan based on the worst credible scenarios of [Link]. Without the cooperation of service providers
service interruption, to prepare for the possibility of Internet (ISP), many organizations view as frightening
that your current service provider is unable to continue the task of prevention against DDoS-type attacks. A counter-
the operations or providing the necessary services. The plan must effective measure may depend on ISP to cushion a
incorporate the identification of viable alternatives to proceed DDoS attack on upstream networks.
your internet banking from another location. [Link]. Given that credit institutions and their
2.8. Distributed Denial of Service Attacks ISPs must adopt a collaborative approach, it is important.
(Ddos) that incorporate considerations about DDoS type attacks
2.8.1. Despite the distributed denial attacks in your ISP selection process. To do this, you must investigate:
service (DDoS) have always posed a great threat a) If the ISP provides protection against DDoS attacks
for internet banking systems, the proliferation of botnets13 or cleaning services to assist in detection
the advent of new attack vectors along with the rapid and the diversion of malicious traffic;
global adoption of broadband has increased in recent years b) The ISP's ability to expand bandwidth
the power of such attacks. from the network when necessary;
2.8.2. The normal size of bandwidth and capacity c) The adequacy of the ISP's incident response plan; and
of any organization's system, no matter how large it may be, d) The capability and readiness of the ISP to quickly
they probably cannot withstand a DDoS attack respond to an attack.
supported by a considerable botnet or by a group of botnets. 2.8.6. Incident response planning:
The immense amount of accumulated computational resources
[Link]. It must be ideally conceived and routinely validated a
botnets to quickly unleash an attack would deplete
incident response framework to facilitate a quick response
the bandwidth of the network and the computational resources of a
DDoS attacks or an imminent attack. This framework should
target system, causing, inevitably, a massive disruption
include a plan that details the immediate steps to follow for
of service or complete cessation.
counter an attack, invoke escalation procedures,
2.8.3. Notwithstanding that most credit institutions have
activate business continuity arrangements, trigger alerts for
established effective protections of its systems against infections
clients and report to the Bank of Mozambique, as well as to others
by Trojan horses e-worms, what makes them less susceptible
authorities.
to integrate botnets, but it must be done to strengthen robustness
from your systems against DDoS attacks. In this regard, it is expected-
Credit institutions must be familiarized
with the incident response plans of the ISP and assimilate them into
It is known that credit institutions have a strategy to
your incident response framework. To facilitate better
address the threats of botnets.
coordination, credit institutions must establish a
2.8.4. Detection and response to attacks: communication protocol with your ISP and conduct exercises
[Link]. Banks with internet banking services must be able to joint incident response reports.
respond to unusual conditions14network traffic, performance 2.9. Disclosure of the Credit Institution
system volatility or sudden increase in resource usage of
2.9.1. Credit institutions must provide information
system, as they may be symptomatic of a DDoS attack.
clear to your clients about the risks and benefits of use
Consequently, the success of any preventive actions
internet banking before subscribing to these services.
the reactivates depend on the development of tools
Customers must be informed clearly and precisely.
appropriate for effectively detecting, monitoring about the rights, obligations, and responsibilities (of the client and of the
and analyze anomalies in networks and systems.
credit institution) in all matters related to the
[Link]. As part of the defense strategy, the institutions
online transactions, particularly, any issues that
credit should install and configure firewalls, systems
may arise from processing errors and security vulnerabilities.
intrusion detection/prevention, routers and other equipment
Information written in a non-synthetic manner and/or using
network specialist to alert security personnel and divert
Technical terminology can cause readability difficulties
and/or filter network traffic in real time as soon as an attack
understanding of clients.
for suspect or confirmed. Due to the significant volume
2.9.2. The terms and conditions applicable to products and services
the traffic that needs to be processed must be considered
online banking must be available to customers through the
the use of custom-built and designed devices for
internet banking application. At the initial login or subscription
provide high levels of performance. The goal here is to remove
a specific service or product must be required
malicious packages, so that legitimate traffic to the system
positive recognition of the terms and conditions by customers.
Internet banking can!
2.9.3. Credit institutions must make their public.
[Link]. Potential bottlenecks and single points
customer security and privacy policy. The way
the failures vulnerable to DDoS attacks can be
regarding dispute resolution with customers, the reporting and the
identified through source code review, analysis
of the network design and configuration testing. The elimination of these
procedures for its resolution, including the expected time
from the response of the credit institution, must be clearly
Weaknesses can enhance the resilience of the system.
defined. All this information must be available on the website
of the credit institution. The disclosure of information can be
13Botnets are collections of computers (or bots) infected with
useful for customers to make informed decisions.
malicious software, operating under a command and control infrastructure 2.9.4. On websites, credit institutions must guide
common – obotnet master or obotnet originator. The obotnet master is capable of your customers regarding safety measures and precautions
to leverage compromised machines to launch a DDoS attack. reasonable measures to take when accessing online accounts. The procedures for
14A baseline for normal system processes, indicators, and standards
precautions should include the following steps for prevention of
Traffic should be used as a guide for identifying behaviors.
uncommon in the system. unauthorized transactions and fraudulent use of your accounts,
652 I SERIES — NUMBER 75

as well as ensuring that no one can observe or steal your j) The customer should not allow anyone to store or handle
access credentials or other security information that no seutokende security OTP;
allow impersonation or unauthorized access The customer should not reveal the OTP generated by their token.
to your online accounts. of security;
2.9.5. In the event of security breaches l) The customer must not disclose the serial number of their
and access and execution of fraudulent transactions from security token;
Regarding the online account of clients, the credit institutions must The client must check their bank account statement.
explain on your websites what processes will be invoked to regularly and report any discrepancies.
resolve the problem or dispute, as well as the conditions 2.10.4. Customers should be advised to adopt
the circumstances in which the losses or damages resulting will be the following precautions and safety practices:
attributed to the credit institution or to the clients. a) Install antivirus software, anti-spyware and firewall
2.10. Customer Education your personal computers, particularly when
2.10.1. The importance of customer education regarding be connected through broadband connections,
the security and reliability of your interaction with the institution DSL15 cable modems;
credit should not be underestimated. The trust of customers b) Regularly update antivirus firewall products
regarding the security and solidity of online products and services security patches or new versions;
the credit institution depends, to a large extent, on its c) Remove "leandprintersharing" from your computers,
understanding and compliance with security requirements especially when they have access to the Internet
associated with the operation of their bank accounts. through cable modems, broadband connections
2.10.2. Customer education can be online based or similar facilities;
naWebou can be defined as a learning approach d) Perform regular backups of critical data;
oriented. Whenever the credit institution introduces e) Consider the use of encryption technology for
new features or operational functions, particularly protect highly sensitive data;
related to security, integrity, and authentication, must f) Log off online and turn off the computer
ensure that customers have sufficient instruction and information when it is not in use;
so that they can use them appropriately. Education g) Do not install software or run programs from unknown sources
continues and the provision of timely information to customers can unknown
help them understand the security requirements and take h) Remove unwanted or chain emails;
appropriate measures in reporting security issues. i) Do not open attachments from emails sent by strangers;
2.10.3. To increase security awareness, Do not disclose personal, financial, or card information
credit institutions must urge customers about credit on little-known or suspicious websites;
the need to protect your PIN, security tokens, k) Do not use a computer or equipment not
personal details and other confidential data. The instructions of confinable;
PIN and OTP security must be displayed prominently l) Do not use public computers or Internet cafe computers
on the login page on the USER ID entry page, PIN to access online banking or execute transactions
financial.
the OTP. The following recommendations may be instructive in
2.10.5. Information on safety precautions and good practices
customer assistance in building robust PINs and in adoption the practices presented above do not intend to be exhaustive nor
of best security procedures: static. It must be presented to clients in a way
a) The PIN must consist of at least 6 digits friendly and regularly updated.
or 6 alphanumeric characters, without the same 2.10.6. Credit institutions are directly responsible.
digit is repeated; for the security and reliability of the services and systems they provide
b) The PIN should not be based on the USER ID, number to their clients. In this regard, they are required to operate
of personal phone, date of birth or other and maintain adequate and effective authentication systems and others
personal information; related to security to protect and verify your
c) The PINs must be kept confidential and never customers before allowing access to bank accounts and execution
disclosed of transactions, in accordance with appropriate procedures
d) PINs must be memorized and not written down; of authorization and validation. Conversely, it is important that
e) PINs must be changed regularly; customers take appropriate security measures to
protect your devices and computer systems and ensure
f) The same PIN should not be used for websites and applications.
or different services, particularly when they are that your hardware or the integrity of the system is not
committed to getting involved in the online bank. The clients
related to different entities;
they should listen to their banks' advice on how to protect
g) The customer should not select the browser option of
the devices or computers you use for access
save or retain the username and password;
to banking services.
The customer must verify the authenticity of the website.
of the credit institution through the comparison of III Principles of Business Continuity Management
URL with the name of the credit institution present 3.1. Principle 1: The Board of Directors
of digital certificate or through the observation of the Senior Management Should Be Responsible for
indicators provided by an extended certificate Business Continuity Management of the Institution
of validation; 3.1.1. The responsibility for ensuring the state of readiness
The customer must verify if the website address the continuity of the institution's business ultimately falls
the credit institution changes from http:// to https:// about the board of directors and senior management.
and if a security icon that resembles appears
lockedwithkey,whenwaitingforauthentication
and encryption; 15DSL: Digital subscriber line.
18 DE SETEMBRO DE 2013 653

3.1.2. Senior management is responsible for the direction 3.3. Principle 3: Institutions Must Test Their
from business continuity management with policies and strategies Business Continuity Plan Regularly,
necessary for the pursuit of critical business functions. Fully and Significantly
Deve demonstrar ter consciência su ciente dos riscos, medidas 3.3.1. The test is a vital element for the implementation
of mitigation and state of readiness through supply of a business continuity management and ecaz. The changes
certificate (related to business continuity preparation) in technology, business processes, functions, and responsibilities
to the board of directors. of personnel can affect the adequacy of the BCPand, ultimately,
3.1.3. The certificate is an internal document addressed to the council. the preparation related to the continuity of the business of the institutions.
from administration for its ratification. It is up to senior management Therefore, it is important to regularly test its functionality.
determine the way in which it best provides the level of effectiveness. On the other hand, the tests provide familiarity with
comfort and the need for additional assurance. The certificate must people with the location of recovery centers, as well as
clearly indicate the following: with the recovery procedures. Institutions must
a) The level of readiness of the institution; and obtain the guarantee through tests of the respective capabilities of,
b) The degree of alignment with the guidelines, which is once their BCPs are activated, they will continue to operate in a way
compatible with the nature and dimension of the institution accountable, responsible and efficient as planned.
and the complexity of the activities performed. 3.3.2. The indication that the tests must be regular means
that institutions are encouraged to carry out different types of
[Link]. The Bank of Mozambique also encourages
tests, taking into account the criticality and complexity of the
the disclosure and inclusion of residual risk in the certificate.
business functions and necessary resources. The tests can be
The certificate must be updated at least once carried out in modules and at different but regular intervals.
per year or more frequently if there are substantial changes Senior management and staff should participate in these exercises
inside the institution. and to be familiar with their functions and responsibilities
3.1.5. The institutions are responsible for deciding on for potential activations.
the contents of the certificate to be disclosed to your clients 3.3.3. The indication that the tests must be complete
and counterparts, if deemed necessary. the significant aims to communicate that all the components
business processes must be tested in a way
3.2. Principle 2: Institutions Must Incorporate
significant. This should include connectivity tests,
the Business Continuity Management in its functionality and capacity of the installed infrastructure
Operations in the recovery locations. The institutions must ensure
3.2.1. Business continuity management is a framework that your testing programs adequately cover both the
focused on the risk that addresses the operational component, qualitative aspects (e.g., response time) as well as quantitative
through the development of clear policies, strategies (e.g., load capacity). They must, critically and regularly,
the responsibilities for the recovery of critical functions test all strategic and planning assumptions for
of the business. It is a proactive process. Institutions must, check its applicability, especially when the scope or
the direction of the business changes. For the observance of fullness, the
therefore, strive to build an organizational culture
tests should also include awareness and preparation
that incorporates business continuity management as part of staff and coordination with external entities, as well as
of their usual business operations and daily management the complete test of all interdependencies, including the
of risk. service providers based outside the country.
3.2.2. Depending on the size and complexity of your 3.3.4. Tests covering the entire institution are also
activities, institutions can adopt good practices incentivized, as they offer a different perspective on the tests
business continuity management that includes the following modular. Institutions should progressively incorporate
components: but challenges in your exercises (tests) and introduce scenarios
different each time they do the same type of exercise.
a) Clear policy, strategy, and budget for management
This will convey greater confidence in relation to your preparation for
continue the business; the continuity of the business. The exercises may include:
b) Well-defined functions and responsibilities for
a) Desktop walkthrough to comprehensively test
the business continuity management program;
the system;
c) BCP understanding detailed tasks and activities; b) Activation of the personnel call tree (with and without
d) Succession plans for critical staff and management mobilization
senior c) Activation of backup sites16(including the invocation
e) BIA or similar process; from external service providers);
f) Program for the development, implementation, testing d) Alternative arrangements for shared services;
and maintenance of the BCP; e) Restoration of backup tapes; and
g) Programs for training and awareness; f) Recovery of vital records.
h) Emergency responses; Ultimately, institutions have to ensure
i) External communication coordination programs that such tests/exercises contribute significantly to the
and crisis management; improvement of your preparation related to business continuity.
3.3.6. The formal documentation for exercises must be prepared,
j) Coordination with external entities (including
list the lessons learned and all mitigation measures of
authorities, interdependent parties, etc. new risks. Senior management must approve the documentation and
3.2.3. The BCP is an important tangible evidence of the initiative agree with the new proposal for mitigation measures.
institutional business continuity management. It should be
executable, regularly reviewed, updated according to the
16Backup sites are understood as alternative spaces both
business changes and significantly tested to ensure
of computer processing as work for the employees
its relevance, effectiveness, and operational feasibility. from other support and business areas.
654 I SERIES — NUMBER 75

3.3.7. Properly sized and coordinated tests 3.5. Principle 5: Institutions Must Perceive
among the main financial service providers17public and Adequately Mitigate the Risks of Interdependencies
the served institutions can raise the level of awareness and the Critical Functions of the Business
confidence in recovery operations. They can also increase There is a growing trend among institutions,
Trust in the financial sector. to share and redistribute risks and processes locally, regionally
3.4. Principle 4: Institutions Must Develop or globally, leading to a greater dependence on entities
Your Recovery Strategies and Establish RTO internal and external. Any mismanagement of these dependencies
For the Critical Business Functions and the risks they incorporate can trigger inefficiencies
3.4.1. The establishment of recovery strategies allows operational or systemic, leading to potential failures.
for institutions to execute their BCP in an organized manner 3.5.2. When planning for the continuity of critical functions
and previously defined, minimizing interruptions and losses In business, institutions must consider interdependencies.
recovery strategies are the foundation for of these functions and assess to what extent they depend on others
definition of RTO of critical business functions. Without these entities. Institutions must also understand
clear guidelines, the scarce resources may be inadequate the business processes of the entities that support their
directed towards less important activities. This can critical functions, including the level of continuity preparedness
negatively affect the reputation of institutions and their capacity business and recovery priorities.
of survival. 3.5.3. Examples of the mentioned dependencies:
Critical Business Functions a) Units within the institution (e.g., treasury, services
3.4.2. In the face of a crisis, it may not be feasible to recover of custody, etc.
all business functions simultaneously. Institutions must, b) Public financial service providers (e.g.,
therefore, identifying the critical business functions (including clearing and settlement service providers,
support operations and related IT systems) and the losses etc.
potential (in monetary and non-monetary terms). A c) Suppliers (e.g., IT service providers or
a common process for obtaining this information is the analysis of of disaster recovery, etc.;
business impact (BIA). This process also serves to d) Infrastructure providers (e.g., services
highlight the relative priorities among the various critical functions of telecommunications, etc.).
to assist institutions in determining their strategies 3.5.4. Institutions must mitigate the risks arising from
recovery and RTO. the dependencies, as much as possible and consider such
3.4.3. The critical functions of the negotiation differ considerably.
dependencies in your recovery strategies and RTO.
from one institution to another due to differences in focus
3.5.5. Despite the complete mitigation of some risks
of the business and customer expectations. Some of the functions
of interdependencies being outside the direct control of the institutions
business criticisms may include: compliance with instructions
(e.g., unavailability of telecommunications networks, etc.), this
of payment, compensation, and settlement of transactions,
não pode diluir as expectativas dos seus clientes e contrapartes
compliance with financing obligations and guarantees,
about the services and obligations of institutions. It is responsibility
management of clients' risk positions and maintenance of trust
of clients, investors, and the public. that institutions take reasonable measures (e.g., start
discussions with telecommunications service providers
Recovery Time Objectives about redundancy capabilities, etc.) to ensure that the
3.4.4. The RTOs can vary from minutes to hours, with your main service providers are able to support
for some sectors and functions, they can be even longer. By your business, even in the face of interruptions.
reasons previously stated, it is important that the Institutions 3.5.6. Before hiring external service providers,
Significantly Important ("ISI")18recover and resume institutions must ensure that the resulting risk
your critical business functions faster than outsourcing remains within the permitted levels by
the institutions that depend on them. its operational risk management policies and does not compromise
3.4.5. The transparency and sharing of RTO can help the preparation related to business continuity. They must ensure
to improve expectations of the level of service and understanding that your providers have BCPs equal to or better than
between institutions and contribute to the improvement of mitigation yours. Additionally, institutions must proactively
of interdependence risks. to seek to ensure that the BCP of your providers are
Determination of RTO for Critical Business Functions regularly tested.
3.4.6. The institutions are responsible for determining
3.5.7. É fundamental que as instituições monitorizem
the respective critical business functions, strategies
continuously your financial situation and gain experiences
of recovery and the corresponding compatible RTOs
of the market that allow them to detect warning signs
with the nature, dimension, and complexity of its functions
and obligations.
of potential problems.
3.5.8. Institutions must mitigate the risk of cessation.
It is unlikely that all critical business functions
the unexpected liquidation of your main suppliers
share the same RTO. The RTO of the different functions of
business should be proportional to the institution's obligations of services, of which their critical business functions
regarding the market, customers, and industry. depend. This situation is related to the fact that institutions
they can take a long time to implement solutions
alternatives. For this purpose, they must take reasonable measures to
17 Public financial service providers are organizations that to maintain an adequate level of control and reserve the right
provides specialized financial services, such as compensation to intervene with appropriate measures to continue its
of checks and settlement. critical business operations.
18
For the purpose of these guidelines, those from which others are ISI 3.5.9. Ultimately, the risk of interdependence
credit institutions of the national financial system depend to the point of
that your difficulties in recovering from adverse events may contribute stays with the institutions and this responsibility cannot
for the amplification of systemic risk. be a delegate. The institutions are still responsible for finding
18 DE SETEMBRO DE 2013 655

balance between risks and costs, manage risks appropriately and of multiple critical functions due to a rupture in a
take measures proportional to the criticality of business functions, zone. Likewise, by diversifying by locations the
as well as with the size and nature of operations. critical business functions, ensuring that the other
3.6. Principle 6: Institutions Must Plan working group is capable of taking on the functions
Interruptions of Vast Areas during breakups, one can eliminate dependency
of a single working group.
The incident of September 11, 2001 demonstrated
3.7.4. These approaches have different cost implications and,
that institutions must plan for interruptions that affect
Although these are an important factor, institutions must
a vast area/zone. Due to the diversity of factors, such as to design and determine the most appropriate approach or to combine them
different sizes and complexities of business operations
approaches to better balance costs and exposure to risks,
among financial system institutions, it would not be appropriate,
in order to provide an adequate level of comfort and assurance.
not practical, to standardize a criterion that defines a 'zone' for
uniform application across the entire financial sector.
The mitigation solution must be proportional to the nature,
3.6.2. The Bank of Mozambique expects from the institutions
dimension and complexity of business functions.
3.7.5. Institutions are encouraged to be innovative
the demonstration of having planned and taken measures in their
and explore the various possibilities for mitigation
business continuity management regarding interruptions from the concentration of risk.
covering vast areas. Some planning parameters that
The institutions can consider are: geographical concentration IV Appendices
of institutions, transactional processing activities 4.1. Appendix A: Disruption of Man-Type Attacks
and dependencies of internal and external service providers. In the Middle
3.6.3. Dependent operational configuration of the institutions, 4.1.1. As part of the two-factor authentication infrastructure
such interruptions covering vast areas can amplify factors, credit institutions must also consider
the risks of interdependence between critical functions and providers and, if deemed appropriate, implement the following controls and
of services within the same area. This may be due to security measures to minimize exposure to attacks of
the widespread interruption of critical services such as failure man-in-the-middle
of telecommunications or inaccessibility of critical personnel. Such
a) Specific OTPs for the addition of new beneficiaries:
risks must be properly mitigated.
Each new beneficiary must be authorized by the client.
3.6.4. Institutions are responsible for deciding on
based on an OTP from a second channel that,
the need to address multiple interruption scenarios,
similarly, show the beneficiary details or
considering your critical activities and management policies
the handwritten signature of the client, verified on
at risk. Additionally, they should consider the expansion
credit institution from a procedure
the deepening of the scope of your continuity management
manual.
business to address prolonged operational disruptions.
b) Individual OTPs for value transactions (payments)
3.7. Principle 7: Institutions Must Establish and the transfer of funds) :
a Segregation Policy to Mitigate the Risk of Each value transaction or an approved list of
Concentration on the Critical Business Functions
transactions of amounts above a certain limit
3.7.1. The centralization of critical business functions determined by the client must require a new
and support services, such as treasury, back-office, IT, and centers OTP. All payments and transactions of
of data brings economic benefits. However, the institutions funds transfer must be encrypted
risk losing the ability to recover these functions in in the application layer.
eventuality of an incident or disaster. c) OTP time window:
3.7.2. Personnel and critical information are important assets. OTP challenge-based time-based for better supply
that are difficult to replace quickly. Many institutions security, because of its validity period
they assume that the same range of personnel will be available for is entirely controlled by the institution
recover your critical business functions, but this assumption of credit and does not depend on behavior
it is not always true, as the ruptures can result in of the user. Due to the problems of
unavailability of critical personnel. On the other hand, identify time synchronization, the use of OTP
alternatives to critical personnel do not always reduce the risk,
time-based requires a time window on the side
especially if both, critical and alternative personnel, are present
of the server. Credit institutions should not
lodged in the same place or area.
allow the OTP time window to exceed
3.7.3. It is important, therefore, to find the right balance.
100 seconds. The smaller the time window,
between the mitigation of concentration risk and preservation of
lessen the risk of OTP abuse.
sciences obtained from the centralization of business processes and of
critical personnel. To mitigate the risk of concentration of functions d) Payment security and fund transfers:
business criticism, institutions may consider the following Digital signatures and codes can be used.
approaches: based on key for authentication
of message (KMAC19), with a view to detection
a) Separation of primary and secondary locations: when separating in
of unauthorized modifications or injection
different areas the primary and secondary locations of
of transactional data in attacks of the type
critical business functions can mitigate the risk of
man-in-the-middle. Para que esta solução de
loss of both locations in the event of a breach
security works effectively, a client
that covers a vast area.
using hardware token must be able to
b) Separation of critical business functions and separation
intra-function: when separating the critical functions of the business
in different zones one can mitigate the risk of loss KMAC: key-based message authentication codes.
19
656 I SERIES — NUMBER 75

distinguish the process of OTP generation from etc.) are correctly implemented and that the
digital signature process of a transaction. protection of security functions and keys
What the client signs digitally as well cryptographic is robust.
it must be meaningful to you. This means that d) Authorization:
ostokens must, at a minimum, show in a way After user authentication and the subsequent
state the beneficiary's account number access to the system, the authorization helps to ensure
and the payment amount, from which a that a certain user only has
value hash can be derived for the purpose to be allowed to view, write, execute,
to create a digital signature. Keys modify, create and/or delete data and invoke the
different cryptographic methods must be used for functions within your permissions. They must be
generate OTP and to sign transactions. conducted tests to verify if the matrix of
e) Notification/confirmation through a second channel: security access works correctly in
The credit institution must notify the client. several permutations.
through a second channel, in relation to all e) Data input validation:
the payments or transfer transactions The most common weakness in applications is failure.
of funds above a certain amount of appropriate input data validation
specified by the client. of users. This weakness can create greater
f) Session time limit: vulnerabilities such as script injection and
An online session should be terminated after a buffer overflow. An appropriate validation
fixed period of time, unless the client data must include the following:
be re-authenticated so that the current session is All inputs in an application must be
maintained. This prevents an attacker from being able to validated;
keep an active internet banking session ii. All forms of data (such as text boxes,
indefinitely. selection boxes and hidden fields must be
g) SSL server certificate notice: verified;
Internetbankingclientsmustbe iii. The treatment of null input data or
aware and instructed on how incorrect ones must be verified;
react to the SSL server certificate warning. iv. The formatting of content must be verified;
They must finish the session of logins. v. The maximum size of each input field must
the SSL certificate does not belong to the institution to be validated.
of credit and a notice must be given to the f) Exception/Error Handling:
effect. Customers must inform the institution
of credit immediately after log off. The rigorous handling of exceptions/errors can facilitate
the error-free processing in a situation of
4.2. Appendix B: System Security Test various errors and in exceptional conditions. The escape of
4.2.1. The system security test must include sensitive information should not result from a failure
the following specifications: of the system.
a) Information leak: Session management:
The collection of information about a system The manipulation of application session management can
is usually the first step that a hacker lead to security issues. To ensure
through scanning, it is a survey of the perimeter a secure session management, the following conditions
of the network and the limits of the system. At your disposal
must be observed:
are public search engines, scanners of
i. Sensitive information passed through cookies
network and messages specially created, that
can be used to discover gaps must be encrypted;
or security vulnerabilities that may ii. The session identifier must be random
to be explored to access the system. They must it's unique;
tests are conducted to detect prolixity iii. The session must expire after a pre-defined time
the promiscuity in network systems. determined.
b) Business logic: h) Cryptography:
Errors made in the implementation of the logic of Cryptography must be used to protect data
businesses can lead to security gaps, sensitive. The resistance of cryptography not only
through which users can execute functions it depends on the algorithm and key size,
unauthorized. For example, an operation of but also of its implementation. From this
the transaction must be executed in a sequence, the implementation must be strictly
but the user can ignore the controls tested, covering all cryptographic functions
through the shuffling of the sequence of steps (encriptação, desencriptação,hashing, assinatura)
as an appetizer. the key management procedures (generation,
c) Authentication: ["distribution","installation","renewal","repeal"]
The most common example of an authentication scheme and expiration).
it is the logon process using passwords i)Logging:
static or dynamic. The authentication test Ologging must be properly implemented
must ensure that the security requirements to avoid security defects, as well as
(credential expiration, revocation, reuse, to facilitate follow-up investigations
18 DE SETEMBRO DE 2013 657

and troubleshooting when an incident occurs 2. Communications between the Bank of Mozambique
of the system. The following must be applied and the participating institutions in the SOM are generally established
requirements and specifications: electronically, through a software application
i. Sensitive data such as passwords and credentials (Meticalnet) that works 'online' or another means of communication
Authentication should not be registered to be indicated by the Bank of Mozambique.
in transaction or activity files 3. The Bank of Mozambique issues certificates
of the system; the operations performed.
ii. The maximum data extension for logging must
ARTICLE2
to be pre-determined;
All attempts must be recorded Participating institutions
of authentication, whether they have been good or bad Institutions that are eligible to participate in SOM for this purpose.
succeeded; forms authorized by the Bank of Mozambique.
All events must be recorded.
of authorization, whether they have been good or bad ARTICLE3
events. Requisitos de adesão ao SOM
j) Performance and stability: The requirements for joining the SOM are:
The performance and stability of a system in a) To be linked to the reserve constitution regime
irregular conditions, such as abnormal ratios mandatory;
of traffic or frequent reboots, must be b) Subscribe to the Market Code of Conduct
verified. Tests must be conducted Interbank
effort beyond the established limits in
systems, to ensure that the application maintains ARTICLE 4
a correct functioning, although with levels Procedures for joining the SOM
deteriorated services.
1. The authorization to use the SOUND and intervene in the
various segments of the markets must be requested through
of a letter addressed to the Markets Department of the Bank
from Mozambique.
Notice No. 5/GBM/2013 2. The Department of Markets must communicate the decision
regarding the requests referred to in the previous number within the timeframe
September 18
maximum of 5 business days, counting from the date of receipt of
There is a need to update annexes 1 and 2 same.
of the Market Operations System Regulations 3. The entities adhering to the SOM must request from the Bank
totheInterbankMonetaryandExchangeMarkets, from Mozambique, through the Department of Legal Affairs,
the Bank of Mozambique, in the exercise of its competencies that it the update of account opening forms, in a way
are granted by number 1 of article 21 of Law no. 1/92, of 3 to include the names of the people with powers
of January - Organic Law of the Bank, determines: to move the accounts, within the scope of the operations carried out
in MCI and MMI, observing the model contained in Annex 1.
The System Operations Regulation is approved. 4. No annex referred to in the final part of the previous number,
of the Market, which is part of this Notice is an integral part the entities adhering to the SOM must mention the name
the same. of the individuals authorized to carry out the operations to be performed
2. This Notice comes into effect on the date of its publication no MCI and MMI.
and repeals the Regulation approved by Notice No. 2/GBM/2009, 5. For the purpose of carrying out operations electronically,
February 26. through the computer application of MCI and MMI, the Bank
The doubts that arise in the interpretation and application Mozambique communicates the access codes to each institution.
This Notice must be submitted to the Department to assign to the people referred to in no.s3 and 4 of this article.
of Markets of the Bank of Mozambique.
ARTICLE 5
Bank of Mozambique, in Maputo, June 6, 2013.
The Governor, Ernesto Gouveia Gove. Duty of the participating institutions
The adhering entities must comply with the rules regarding the
markets in which they participate, as well as the operational rules
established regarding the functioning of the SOM.
Regulations of the Operations System
of the Market ARTICLE 6
Forms that cover the operations in the SOM
ARTICLE1
1. The operations carried out through the SOM that aim to
Object Treasury Bills or securities issued by the Bank
1. The Market Operations System, hereinafter referred to as from Mozambique, in written form, are exempt from numbering
SOM is composed of a set of rules and procedures of order and are materialized by their mere inscription in accounts-
to observe by the Bank of Mozambique and by the institutions accounts opened at the Bank of Mozambique in the name of the respective
authorized to participate in the Interbank Foreign Exchange Market and in headlines.
Interbank Monetary Market, hereinafter referred to as MCI 2. In order to reflect the various asset situations of
the MMI, respectively, regarding the operations carried out registered titles in each title account, as many can be opened
in these markets. sub-accounts as many as necessary.

You might also like