Article 7
Operational risk management process
1. Competent authorities shall assess the efficacy of an institution's AMA framework for the governance and management of operational risk and that a clear organisational structure with well-defined, transparent and consistent lines of responsibility exists by confirming at least the following:
(a) |
that the institution's management body discusses and approves the governance of operational risk, the operational risk management process and the operational risk measurement system; |
(b) |
that the institution's management body clearly defines and determines the following on at least an annual basis:
|
(c) |
that the institution's management body monitors the institution's compliance with the operational risk tolerance statement referred to in point (b) (ii) on a continuous basis; |
(d) |
that the institution applies an on-going operational risk management process to identify, assess and measure, monitor and report operational risk, including misconduct events, and is able to identify the staff responsible for the management of operational risk process; |
(e) |
that the information resulting from the process referred to in point (d) is transmitted to the relevant committees and executive bodies of the institution, and that the decisions arising from those committees are communicated to those responsible within the institution for the collection, control, monitoring and management of operational risk and to those responsible for managing activities that give rise to operational risk; |
(f) |
that the institution evaluates the effectiveness of its operational risk governance, operational risk management process and operational risk measurement system on at least an annual basis; |
(g) |
that the institution notifies the relevant competent authority of the findings of the evaluation referred to in point (f) on at least an annual basis. |
2. For the purposes of the assessment referred to in paragraph 1, competent authorities shall take into account the impact of the operational risk governance structure on the level of engagement in operational risk management and culture by the staff of the institution, including at least the following:
(a) |
the level of awareness, on behalf of the staff of the institution, of operational risk policies and procedures; |
(b) |
the institution's internal process for challenging the design and the effectiveness of the AMA framework. |