Business Continuity & Disaster Recovery in the Financial Services Sector Aspects of Risk Mitigation in the Financial Services Joseph Demanuele 25 June.

Slides:



Advertisements
Similar presentations
Solvency ii: an overview Lloyds May © LloydsSolvency II May Contents Solvency II: key features Legislative process Solvency II implementation.
Advertisements

The Benefits and Challenges of Implementation of Basel II in Europe José María Roldán | 27 Sept 2005.
Presentation of the ECB Framework Regulation Organisational aspects
SEMINAR NAIC/ASSAL/SVS REGULATION & SUPERVISION OF MARKET CONDUCT © 2014 National Association of Insurance Commissioners Overview and Purpose of Market.
Corporate Governance Reform Professor Blanaid Clarke Trinity College Dublin Law Reform Commission Annual Conference 11th December 2012.
Transitional Demands on Regulatory Resources and Focus The Trinidad and Tobago experience A Presentation at the World Bank Conference on Aligning Supervisory.
Code of Corporate Governance for Listed Companies in China
Managed Funds Association’s Sound Practices for Hedge Fund Managers 2009 Edition.
Off shoring From the perspective of a Financial Regulator Jean Moorhouse Financial Services Authority.
1 Licensing Pension Funds and Trustees Conference on Supervision of Pension Systems Warsaw September 2006 Ross Jones Deputy Chairman Australian.
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
The Development of Enterprise Risk Management and Supervision for Insurance Companies in Taiwan Dr. Huang, Tien-Mu Director General, Insurance Bureau Financial.
The ROLE of the ACTUARY in INSURANCE PRUDENTIAL SUPERVISION Yangon, Myanmar 14 July 2014 Chi Cheng Hock, FFA.
1 The insurance industry and the financial crisis London Insurance Institute London, 17 March 2010 Prof. Karel VAN HULLE Head of Insurance and Pensions.
1 Supplement to the Guideline on Prevention of Money Laundering Hong Kong Monetary Authority 8 June 2004.
* Latest developments in EU legislation concerning the financial services are 10th edition * Brussels, 8 December 2005 FEDERATION BANCAIRE DE L’UNION EUROPEENNE.
1 Solvency II Part 1: Background Vesa Ronkainen Insurance Supervisory Authority, Finland
Internal Control and Internal Audit
The European Commission's Approach to Responsible Business: Towards a strategy on Corporate Social Responsibility.
1 Business Continuity and Compliance Working Together Kristy Justice, AVP WaMu Card Services 08/19/2008.
BASEL COMMITTEE ON BANKING SUPERVISION 1 Cross-Border Supervisory Cooperation under the Revised Basel Core Principles and Basel II 6th Annual International.
1 Solvency II Part 3: Other pillars Vesa Ronkainen Insurance Supervisory Authority, Finland
After the crisis: Changes in Regulation in Europe... - the most important trends and influences upon the insurance market Michaela Koller, director general,
1 Financial Services Commission Presentation to Financial Journalists 13 June 2007 Marcus Killick Chief Executive Officer.
1 Regulatory framework for Insurance in Gibraltar London Insurance Seminar 12 th February 2008 Marcus Killick Chief Executive Officer Financial Services.
BCP of Japanese Securities Industry July 5, 2007 Japan Securities Clearing Corporation.
Approaches for forest certification System versus performance ? Presentation prepared by Pierre Hauselmann for the WWF / WB Alliance Capacity building.
1 Basel II – The Implementation Phase Simon Topping Hong Kong Monetary Authority / City University of Hong Kong 9 March 2005 Banking & Finance Technology.
OECD Guidelines on Insurer Governance
Corporate governance: Asia Pacific. JAPAN  The Japan corporate governance committee published its revised code in The Code had six chapters, which.
CORPORATE GOVERNANCE Regulatory expectations and current good practice Charles Cattell The Cattellyst Consultancy.
ADB Project TA 3696-PAK, Regulation for Corporate Governance 1 REGULATION FOR CORPORATE GOVERNANCE IN PAKISTAN CAPITAL MARKETS.
Implications of the Markets in Financial Instruments Directive (“MIFID”) Richard Thompson.
Corporate Governance: Basel II and Beyond Corporate Governance Program for Bank Directors of Indian Banks Mumbai December 14, 2005.
Financial Conglomerates, What are the Inherent Risks? 2006 CIAB Conference Port-of-Spain, Trinidad & Tobago November 16, 2006 Thordur Olafsson, CARTAC.
Investment Funds Conference “Collective Investment Funds in the Qatar Financial Centre – Confidence and Opportunity” November 26-27, 2007 Michael Webb.
MiFID – GENERAL PRESENTATION (practical example of Lamfalussy process)
CEBS in Brief. The Lamfalussy approach The Lamfalussy approach was first implemented in the securities field following the recommendations of the Committee.
Impact of the Financial Crisis and Lessons Learnt Impact of the Financial Crisis and Lessons Learnt Rob Curtis Regional Information Session, Cape Town.
1 IFRS in the Banking Sector A supervisor’s perspective REPARIS Workshop Marc Pickeur Vienna CBFA March 2006 Belgium.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Corporate Governance Yoshi Kawai Secretary General, IAIS IAIS-ASSAL Regional Seminar Buenos Aires, Argentina, November 2011 PUBLIC.
European Commission, Technical Assistance Information Exchange Unit (TAIEX), DG Enlargement in co-operation with The Bulgarian Chamber of Commerce and.
SUERF Annual Lecture Risk Management – A supervisor’s approach Gabriel Bernardino EIOPA Chairman Helsinki, 22 September 2011.
Code of Practice 13/ DC Regulatory Guidance. Agenda Background Code of Practice 13 v. DC Regulatory Guidance DC Focus areas Action: Timeline 2.
1 Presentation to Legislative Council Panel on Financial Affairs Progress of Implementation of Basel II in Hong Kong Hong Kong Monetary Authority 4 May.
FSA - The Financial Supervision Authority Nele Piir, Marge Laan, Kadri Toks.
Undertakings for collective investment in transferable securities (UCITS) Worldbank Global Development Learning Network The Advanced Program in Accounting.
Operational Risk Ruth Hanna Strong FIRMA Conference San Francisco March 31, 2010 © 2010 Wells Fargo Bank, N.A. All rights reserved. For public use.
1 Regulatory framework for Gibraltar- domiciled funds Munich Presentation 19 November 2007 Marcus Killick Chief Executive Officer Financial Services Commission.
1 Regulatory framework for Gibraltar- domiciled funds London Funds Seminar 13 th February 2008 Marcus Killick Chief Executive Officer Financial Services.
Financial Services Commission1 International Insurance Regulation Michael Oliver Director of Insurance Financial Services Commission British Virgin Islands.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
© Copyright Allianz IIS Redefining the industry: Regulation, Risk & Global Strategy July 9, 2007 Berlin Helmut Perlet, Allianz SE The Emergence of Solvency.
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
Internal/External Audit Corporate Governance part 5.
Page 1 Overview of the Internal Control Requirements for the Maltese Insurance Industry Dr. Marisa Attard Malta, 8 April 2010.
Governance, Risk and Ethics. 2 Section A: Governance and responsibility Section B: Internal control and review Section C: Identifying and assessing risk.
Legal Aspects of Finance Slide Set 4 The Single European Financial Market Free Movements and Basics of Regulation The Supervisory Bodies Matti Rudanko.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 6 – Company Law Bilateral screening:
1 Vereniging van Compliance Officers The Compliance Function in Banks Amsterdam, 10 June 2004 Marc Pickeur CBFA CBFA.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 31 – Common Foreign and Security Policy.
Ukraine (nr 46514): Expert Mission on Supervision of Investment Funds` Activities - TAIEX Risk management under UCITS IV. Organizational requirements.
Montenegro Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 6 – Company Law Bilateral screening: Chapter.
1 FINANCIAL SUPERVISION: MEASURING UP TO GLOBAL STANDARDS Lee Jang-Yung Assistant Governor Financial Supervisory Service.
Critical Infrastructure Protection Policy Priorities
Investor protection and MIFID
International Insurance Regulation
Neopay Practical Guides #2 PSD2 (Should I be worried?)
Presentation transcript:

Business Continuity & Disaster Recovery in the Financial Services Sector Aspects of Risk Mitigation in the Financial Services Joseph Demanuele 25 June 2007

Agenda The MFSA – Organisation, functions and obligations Business Continuity Compliance – current position and future considerations High Level Principles of Business Continuity – published by a Forum of Financial Services Supervisors Business Continuity in the UK Financial Services – challenges for 2007 Survey on Business Continuity - in the global Financial Services Sector by a leading risk magazine 25 June 2007 ISACA / MFSA

The MFSA “Ensure high standards of conduct and management in financial services and promote the legitimate expectations of consumers” Public Authority set up by the MFSA Act with functions to:- Regulate & supervise financial services -Single Regulator Inform, promote and protect interests of consumers of financial services Promote fair competition practices / consumer choice Monitor legislation / advise Govt on formulation of policies Ensure high standards of conduct / management in sector 25 June 2007 ISACA / MFSA

The Main Organs 25 June 2007 ISACA / MFSA

The Organisational Units 25 June 2007 ISACA / MFSA

Conduct & Management MFSA Act. Article 4 (1) (g) states that: “Without prejudice to any other power or function conferred to it by this Act or any other law, it shall be the function of the Authority ……… to ensure high standards of conduct and management throughout the financial system” How is this function carried out? Ensure that licence holders have a Business Continuity Plan (BCP) in place which has been tested and is being continuously updated Periodic on site Compliance visits 25 June 2007 ISACA / MFSA

Other Obligations Besides the MFSA Act, the Authority ensures compliance with:- Other local legislation regulating financial services EU legislation and other international treaties Transpose EU legislation into local legislation Adopt new Directives, such as MiFID, Solvency II, CRD, and others 25 June 2007 ISACA / MFSA

On Site Compliance MFSA Units carrying regular on-site compliance visits:- Securities Unit Insurance Business Unit Company Compliance Unit Banking Unit Last year 98 compliance visits were conducted on site. Moving towards the adoption of risk-based approach supervision. 25 June 2007 ISACA / MFSA

Securities Unit – Current Position Investment Services Guidelines (based on current ISD 2) – Part CI of SLC 3.07(l) in the Conduct of Business Rules section states: “The Licence Holder shall organise and control its affairs in a responsible manner and shall have adequate operational, administrative and financial procedures and controls……… and to enable it to be effectively prepared to manage, reduce and mitigate the risks to which it is exposed……..   For this purpose, the Licence Holder shall have an appropriate Disaster Recovery and Business Continuity Plan which is regularly tested and updated” Therefore, it is a standard licence condition to have a DRP and a BCP MFSA checks adherence through compliance visits 25 June 2007 ISACA / MFSA

Securities Unit - Current Position (cont..) Compliance Team shall:- Check and see evidence that there is a proper BCP and procedures for disaster recovery Ensure that the BCP is proportionate and adequate for the size of business and activities See evidence that proper tests are being carried out e.g. record of fire drills, IT shutdowns No BCP in place – in breach of licence conditions. Compliance Team may give guidance regarding compliance. 25 June 2007 ISACA / MFSA

Securities Unit – New Requirements under MiFID EU’s Markets in Financial Instruments (MiFID) – a comprehensive regulatory regime governing financial trading and intermediation in Europe. Replaces ISD (1993) and follows the Lamfalussy four level approach Dir. 2004/39/EC is the MiFID framework directive under Level I - Art.13 (4) – Organisational Requirements states: “An investment firm shall take reasonable steps to ensure continuity and regularity in the performance of investment services and activities.  To this end the investment firm shall employ appropriate and proportionate systems, resources and procedures.” 25 June 2007 ISACA / MFSA

Securities Unit – MFSA’s Draft MiFID Rules Commission Directive 2006/73/EC is the implementing directive to 2004/39/EC – organisational and operating conditions for investment firms – forms part of Level 2 and Art 5 (3) states: “Member states shall require investment firms to establish, implement and maintain an adequate business continuity policy aimed at ensuring, in the case of an interruption to their systems and procedures, the preservation of essential data and functions and the maintenance of investment services and activities on where this is not possible, the timely recovery of such data and functions and the timely resumption of their investment services and activities.” Draft MiFID rules issued by the MFSA in draft form for consultation in Jan 2007 - become applicable from 1 Nov 2007 Business Continuity section of MiFID transposed in Part C rule 1.18(b) – practically identical to Dir. 2006/73/EC Draft MiFID Rules on www.mfsa.com.mt 25 June 2007 ISACA / MFSA

Insurance Business Unit -Current Position BCP is not currently a specific requirement under any insurance legislation or regulation, However BCP is still included in compliance visit procedures as “best practice” Enquires during on-site visits include: Is there a BCP? Includes a DRP? Current and operational? Regularly tested? Procedures for recovery of data? Back-up procedures? Restoration of backups? 25 June 2007 ISACA / MFSA

Insurance Business – Impact of Solvency II Solvency II - complete overhaul of the supervision of insurance business within the EU introducing a new solvency regime with an integrated risk approach reflecting risks taken by insurers better than the current Solvency I regime. Currently in consultation process, through CEIOPS. Directive expected by end 2007 Implementation by EU Member States - scheduled for 2010. Three pillar structure (as in Basel II and CRD) – Pillar I - Quantitative capital requirements Pillar II - Qualitative supervisory review Pillar III - Market discipline Employs Lamfalussy 4 level approach arrangements 25 June 2007 ISACA / MFSA

Insurance Business - Solvency II – Pillar II Pillar II - outlines the obligations of the Supervisory Authority and the Insurers’ general governance including organisational structure and internal control mechanisms and processes to manage material risk as may be appropriate within the nature, scale and complexity of the firm Risk management, including business continuity functions - ultimately responsibility of management Written and clear policies in respect of internal control, outsourcing and risk management 25 June 2007 ISACA / MFSA

Company Compliance Unit CCU is responsible to authorise and supervise companies offering fiduciary services including mandatory and trustee services in terms of the Trusts and Trustees Act (TTA). Also responsible to consider applications for Listing in terms of the Listing Rules. TTA Art.47 empowers the MFSA to conduct compliance visits Clause 9.4 of the Code of Practice for Trustees states: “Trustees should have effective management and systems that are commensurate with the scale and complexity of the trust business to be undertaken. They must also have appropriate management resources to control the company’s affairs (or in the case of individual trustees their business affairs), including ensuring compliance with legal obligations and standards under this Code. BCP compliance is included in the new draft checklist for on-site visits by the CCU Compliance Team 25 June 2007 ISACA / MFSA

Banking Unit – Current Position On-site compliance for credit & financial institutions Verify completeness of the BCP Establish that BCP is a comprehensive document providing guidance in the event of major incidents that may include - inability to access premises, systems outage, unavailability of key personnel, occurrences that may preclude the institution from carrying out routine operations.  BCP to include a disaster recovery simulation performed at least once annually. Test results are documented and weaknesses identified - to be rectified within stipulated timeframes.  Ensure that a full IT system backup is taken daily  BCP to outline employees’ training procedures for its operation   Plan to be commensurate with the institution’s business dimensions. 25 June 2007 ISACA / MFSA

Capital Requirements Directive (CRD) CRD applies Basel II requirements for credit institutions and investment firms across EU. There are three pillars under the new Basel II accord:- Pillar I - involves the measurement of risk, Pillar II - involves the supervisory review process, Pillar III - deals with market discipline by developing a set of disclosure requirements   Pillar II - enhances the link between a credit institution’s risk profile, its risk management, its risk mitigation systems, and its capital CEBS guidelines on Pillar II – BCP is encouraged as a “best practice” requirement and is part of the risk assessment process under Pillar II.  As “best practice” the Basel Committee on Banking Supervision in a forum with other supervisors came up with high level principles on business continuity. 25 June 2007 ISACA / MFSA

High Level Principles of Business Continuity JOINT FORUM, based in Basel made up of BASEL COMMITTEE ON BANKING SUPERVISION (BCBS) INTERNATIONAL ORGANIZATION OF SECURITIES COMMISSIONS (IOSCO) INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS (IAIS) concluded in Feb 2005 that high-level principles on business continuity would contribute to the resilience of the global financial system Defined effective business continuity management to incorporate business impact analyses, recovery strategies and business continuity plans as well as programmes for testing, training and awareness, and communication and crisis management The 7 high level principles developed for two distinct but related audiences – financial industry participants (include unlicensed providers to the financial services industry) and financial authorities. 25 June 2007 ISACA / MFSA

The 7 High Level Principles of Business Continuity Principle 1: Board and senior management responsibility for the organisation’s business continuity. Principle 2: Major operational disruptions – affecting operations of the financial system within their responsibility to be addressed in the BCP Principle 3: Recovery objectives – developed reflecting the risk they represent to the operation of the financial system. Principle 4: Communications - procedures for communicating within their organisations and with relevant external parties to form part of the BCP Principle 5: Cross-border communications – procedures for communications with financial authorities in other jurisdictions in the event of major operational disruptions with cross-border implications. Principle 6: Testing - their BCP’s, evaluate their effectiveness, and update their business continuity management, as appropriate. Principle 7: Business continuity management reviews by financial authorities – who should incorporate business continuity management reviews for the ongoing assessment of the financial industry participants for which they are responsible. 25 June 2007 ISACA / MFSA

High Level Principles of Business Continuity – Case Studies US-Canadian electrical power grid outages in August 2003 The impact of the 2003 SARS outbreak on Hong Kong SAR’s securities markets The impact of the 2003 SARS outbreak on the Canadian securities industry The 2004 Japan Niigata Chuetsu earthquake measuring 6.8 on the Richter scale The London terrorist attacks on 7 July 2005 - 50 killed and 700 injured - the public transportation system in London was at a complete standstill for a significant period. 25 June 2007 ISACA / MFSA

Business Continuity issues for UK Financial Sector 2007 - FSA Business continuity firmly on FSA’s agenda Priority Risk Report – agenda for compliance visits – represents a barometer of risk issues from both regulator and regulated firms. Cross-sectoral risks highlighted:- Pandemic flu – tap reports by larger corporations Terrorism – still a real threat Sectoral issues:- Outsourcing in retail financial services (banks, Ins.), especially offshore – emerging operational and reputation risk Investment banks and Securities firms:- MiFID implementation challenges Credit & equity derivatives – volume growth - back office backlogs Asset fund management – change in processes Hedge Funds – are now subject to regulation by the FSA 25 June 2007 ISACA / MFSA

Survey on BCP in Financial Services Firms (by OpRisk & Comp) Firms not taking BCP seriously as they should Board/SM not giving importance to BCP – 68% Lack funds/resources - 49% Difficulties to communicate BCP internally –32% Difficulties to co-ordinate with external stakeholders –24% BCP regarded as an IT issue – 89% Employ specialised risk managers – 29% Compliance mentality to BCP Updating of BCP’s – annually 46% Concern that BCP not given priority due to compliance projects for MiFID, Basel II, SOX issues etc 25 June 2007 ISACA / MFSA

References Capital Requirements Directives Other MiFID   Directive 2006/48/EC:  http://eur-lex.europa.eu/LexUriServ/site/en/oj/2006/l_177/l_17720060630en02010255.pdf Directive 2006/49/EC:     MiFID Framework Directive - Directive 2004/39/EC: http://europa.eu.int/eur-lex/pri/en/oj/dat/2004/l_145/l_14520040430en00010044.pdf Implementing Directive - Directive 2006/73/EC:            http://eur-lex.europa.eu/LexUriServ/site/en/oj/2006/l_241/l_24120060902en00260058.pdf High Level Principles for Business Continuity Source: Bank for International Settlements website available at: http://www.bis.org/publ/joint14.pdf Other Malta Financial Services Authority (MFSA) - www.mfsa.com.mt UK Financial Services Authority (FSA) - www.fsa.gov.uk 25 June 2007 ISACA / MFSA